CAS-004 Security Architecture Practice Question
A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection of compliance violations
CSPM tools continuously monitor cloud environments for misconfigurations and compliance violations, and they provide remediation guidance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detection of compliance violations
Why this is correct
CSPM identifies violations against frameworks like SOC 2, ISO 27001.
- ✗
Web application firewall (WAF) management
Why it's wrong here
WAF management is typically a separate function.
- ✗
Vulnerability scanning of container images
Why it's wrong here
Container image scanning is typically done by CWPP or container registry scanners.
- ✗
DDoS protection
Why it's wrong here
DDoS protection is provided by services like AWS Shield.
- ✓
Continuous monitoring of cloud resource configurations
Why this is correct
CSPM monitors configurations against best practices and compliance standards.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.