CAS-004 Security Architecture Practice Question
A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)
⚠ Common exam trap
CAS-005 often tests the boundary between CSPM and CWPP — candidates incorrectly attribute workload-level capabilities like container image scanning or WAF management to CSPM, which only covers configuration posture and compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection of compliance violations
Option A (Detection of compliance violations) is correct because CSPM tools continuously assess cloud environments against regulatory and industry benchmarks such as CIS, PCI DSS, HIPAA, and NIST, flagging misconfigurations and policy breaches that constitute compliance violations. Option E (Continuous monitoring of cloud resource configurations) is correct because the core function of CSPM is to continuously discover and monitor cloud resources (e.g., storage buckets, IAM policies, security groups) across providers like AWS, Azure, and GCP, detecting drift and risky configuration changes in near real time. Option B is incorrect because WAF management is a web application protection function typically handled by dedicated WAF services or WAAP platforms, not CSPM. Option C is incorrect because container image vulnerability scanning belongs to container security or vulnerability management tools (e.g., Trivy, Clair, or cloud-native registries), not CSPM. Option D is incorrect because DDoS protection is a network-layer availability control provided by services such as AWS Shield or Azure DDoS Protection, which is outside the CSPM scope of posture and compliance assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detection of compliance violations
Why this is correct
CSPM tools continuously assess cloud configurations against benchmarks and policies, surfacing misconfigurations and regulatory breaches. Detecting compliance violations is a core capability, directly matching the stem's request for typical CSPM functions rather than runtime workload protection.
- ✗
Web application firewall (WAF) management
Why it's wrong here
WAF management protects applications at layer 7 and belongs to web application firewalls or WAAP platforms, not posture tooling. It tempts because both surface in cloud security dashboards, but CSPM assesses configuration against benchmarks and compliance baselines rather than inspecting or filtering HTTP traffic.
- ✗
Vulnerability scanning of container images
Why it's wrong here
Container image vulnerability scanning is performed by container registry scanners or dedicated CNAPP scanning engines, which inspect package layers. It tempts because CSPM also reports misconfigurations in Kubernetes and registries, but it evaluates configuration state, not installed package vulnerabilities within image contents.
- ✗
DDoS protection
Why it's wrong here
DDoS protection is delivered by edge scrubbing services or cloud-native DDoS mitigation, absorbing volumetric and protocol attacks. It tempts because both appear in cloud security portfolios, but CSPM detects misconfigured exposure that could invite attack; it does not absorb or filter malicious traffic itself.
- ✓
Continuous monitoring of cloud resource configurations
Why this is correct
CSPM platforms poll cloud provider APIs to continuously monitor resource configurations, flagging drift, insecure settings and deviations from baselines. This continuous configuration monitoring is a defining CSPM capability, distinct from runtime threat detection or vulnerability scanning of workloads.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.