Courseiva
Security Engineering →mediumMultiple Choice

CAS-004 Security Engineering Practice Question

A security engineer is configuring a Linux server that hosts a web application. The engineer needs to ensure that the application runs with the least privilege necessary and that any compromise of the application is confined to a limited set of system resources. Which of the following should the engineer implement?

⚠ Common exam trap

Many candidates confuse logging or permissive modes with actual enforcement, or assuming that a chroot or non-root user provides complete isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SELinux in enforcing mode with a targeted policy for the web server

SELinux in enforcing mode enforces a mandatory access control policy that restricts the web server to only the resources it needs, such as specific files and network ports. This provides strong confinement and least privilege. The other options either do not enforce restrictions, provide only partial isolation, or rely on traditional permissions that are insufficient for limiting a compromised process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Running the web server as a non-root user without additional controls

    Why it's wrong here

    Running as a non-root user reduces privileges but does not confine the process to specific resources. If the application is compromised, the attacker inherits the user's permissions and can access any files or services that user can. This does not provide the strong isolation needed to limit the blast radius of a compromise.

  • ✓

    SELinux in enforcing mode with a targeted policy for the web server

    Why this is correct

    SELinux in enforcing mode applies mandatory access controls that confine the web server process to only the resources defined in its policy. This limits the impact of a compromise by preventing the process from accessing files or network ports outside its defined domain, thus achieving least privilege and confinement.

  • ✗

    chroot jail for the web server process

    Why it's wrong here

    A chroot jail restricts the filesystem view of a process but does not limit other resources such as network access or inter-process communication. It can be escaped by a determined attacker with root privileges, and it does not provide mandatory access controls. Therefore, it does not fully meet the least privilege and confinement requirements.

  • ✗

    AppArmor with a complain-mode profile for the web server

    Why it's wrong here

    AppArmor in complain mode only logs violations and does not enforce restrictions, so it does not confine the application. While AppArmor can provide confinement, complain mode is used for profiling and testing, not for production security. Thus it fails to meet the requirement of limiting the impact of a compromise.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.