Sample questions
CompTIA SecurityX (CAS-005) practice questions
A security audit reveals that Docker containers are built with multiple unnecessary layers and utilities. Which practice reduces the attack surface of the container image?
During a threat hunting exercise, a security analyst hypothesizes that adversaries may be using PowerShell to execute commands in memory. Which threat hunting methodology is being…
A compliance officer is reviewing logs from a web application and finds multiple failed login attempts from a single IP address. Which type of control should be implemented to redu…
A security analyst is collecting evidence from a compromised workstation. Which of the following should be collected first to preserve volatile data?
A multinational organization is adopting a zero trust architecture and needs to align its network segmentation with regulatory requirements. The compliance team has identified that…
Which of the following is the PRIMARY purpose of a business continuity plan (BCP)?
Refer to the exhibit. Which security issue does this cloud storage bucket policy present?
A healthtech startup is developing a mobile app that collects PHI. They plan to use a third-party cloud provider for data storage. What is the most critical compliance requirement…
Which of the following is the correct order of the security policy hierarchy from highest to lowest?
A security architect needs to protect sensitive data in use within a server's memory from other processes. Which technology should be implemented?
A security architect is designing a secure remote access solution for contractors who need temporary access to a few internal applications. Which THREE of the following are best pr…
Which of the following is a primary purpose of using code signing for application deployment?
An enterprise is deploying a multi-factor authentication (MFA) solution. The security team requires a factor that is resistant to phishing and does not rely on shared secrets. Whic…
An application uses a relational database and constructs SQL queries by concatenating user input. Which secure coding practice should be implemented to mitigate SQL injection?
A security team wants to implement a certificate pinning strategy for their mobile application to prevent man-in-the-middle attacks. Which of the following should be pinned in the…
During an incident response, the team identifies that an attacker gained initial access via a phishing email containing a malicious macro. The macro downloaded a payload from a rem…
A security architect is designing a secure boot process for a new line of embedded devices. The boot ROM loads the bootloader, which then loads the OS kernel. To ensure that only s…
A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Wh…
During a security review, a developer discovers that a containerized application runs with root privileges. Which of the following is the most secure approach to mitigate this risk…
A security analyst is investigating a malware sample found on a workstation. The analyst wants to determine the malware's capabilities without executing it. Which type of malware a…
A security team is evaluating the effectiveness of their patching program. Which metric would best indicate how quickly the organization applies critical patches?
A security analyst is reviewing a suspicious file. Which static analysis technique would the analyst use to examine the file without executing it?
A security analyst is writing a script to scan container images for known vulnerabilities before deployment. Which of the following best practices should the analyst implement to e…
A compliance officer is preparing for a GDPR audit. Which THREE of the following are key data subject rights under GDPR that the organization must be able to demonstrate?