CAS-004 Security Engineering Practice Question
A security engineer is configuring a Linux server that hosts a web application. The engineer needs to ensure that the application runs with the least privilege necessary and that any compromise of the application is confined to a limited set of system resources. Which of the following should the engineer implement?
⚠ Common exam trap
Many candidates confuse logging or permissive modes with actual enforcement, or assuming that a chroot or non-root user provides complete isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SELinux in enforcing mode with a targeted policy for the web server
SELinux in enforcing mode enforces a mandatory access control policy that restricts the web server to only the resources it needs, such as specific files and network ports. This provides strong confinement and least privilege. The other options either do not enforce restrictions, provide only partial isolation, or rely on traditional permissions that are insufficient for limiting a compromised process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Running the web server as a non-root user without additional controls
Why it's wrong here
Running as a non-root user reduces privileges but does not confine the process to specific resources. If the application is compromised, the attacker inherits the user's permissions and can access any files or services that user can. This does not provide the strong isolation needed to limit the blast radius of a compromise.
- ✓
SELinux in enforcing mode with a targeted policy for the web server
Why this is correct
SELinux in enforcing mode applies mandatory access controls that confine the web server process to only the resources defined in its policy. This limits the impact of a compromise by preventing the process from accessing files or network ports outside its defined domain, thus achieving least privilege and confinement.
- ✗
chroot jail for the web server process
Why it's wrong here
A chroot jail restricts the filesystem view of a process but does not limit other resources such as network access or inter-process communication. It can be escaped by a determined attacker with root privileges, and it does not provide mandatory access controls. Therefore, it does not fully meet the least privilege and confinement requirements.
- ✗
AppArmor with a complain-mode profile for the web server
Why it's wrong here
AppArmor in complain mode only logs violations and does not enforce restrictions, so it does not confine the application. While AppArmor can provide confinement, complain mode is used for profiling and testing, not for production security. Thus it fails to meet the requirement of limiting the impact of a compromise.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.