hardMultiple ChoiceObjective-mapped
CAS-004 Practice Question: A security team needs to automate the enforcement…
A security team needs to automate the enforcement of cloud security policies across multiple accounts in AWS. They want a solution that uses code to define policies and automatically remediate violations. Which approach best meets these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Config with managed rules and custom Lambda functions for auto-remediation.
AWS Config with managed rules and custom Lambda functions enables automated enforcement of security policies across multiple AWS accounts. This approach uses code to define policies and automatically remediate violations via Lambda, meeting the requirement for automation and code-defined policies. Option A (boto3 scripts) is manual and not fully automated; Option C (GuardDuty) is reactive and focuses on threats, not policy enforcement; Option D (CSPM) is a third-party tool, not a code-defined approach within AWS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write Python boto3 scripts that run on a schedule to check and update security groups.
Why it's wrong here
Scripts are custom and require maintenance; they do not provide a unified policy framework.
- ✓
Use AWS Config with managed rules and custom Lambda functions for auto-remediation.
Why this is correct
AWS Config rules are defined in code (JSON) and remediation via Lambda automates enforcement.
- ✗
Enable AWS GuardDuty and rely on its threat detection alerts.
Why it's wrong here
GuardDuty detects threats but does not enforce policies or automate remediation.
- ✗
Deploy a third-party cloud security posture management (CSPM) tool like Prisma Cloud.
Why it's wrong here
CSPM is effective but is a separate tool, not 'code-defined' policies; the requirement is for code-defined automation.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.