Courseiva
hardMultiple ChoiceObjective-mapped

CAS-004 Practice Question: A security team needs to automate the enforcement…

A security team needs to automate the enforcement of cloud security policies across multiple accounts in AWS. They want a solution that uses code to define policies and automatically remediate violations. Which approach best meets these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use AWS Config with managed rules and custom Lambda functions for auto-remediation.

AWS Config with managed rules and custom Lambda functions enables automated enforcement of security policies across multiple AWS accounts. This approach uses code to define policies and automatically remediate violations via Lambda, meeting the requirement for automation and code-defined policies. Option A (boto3 scripts) is manual and not fully automated; Option C (GuardDuty) is reactive and focuses on threats, not policy enforcement; Option D (CSPM) is a third-party tool, not a code-defined approach within AWS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Write Python boto3 scripts that run on a schedule to check and update security groups.

    Why it's wrong here

    Scripts are custom and require maintenance; they do not provide a unified policy framework.

  • Use AWS Config with managed rules and custom Lambda functions for auto-remediation.

    Why this is correct

    AWS Config rules are defined in code (JSON) and remediation via Lambda automates enforcement.

  • Enable AWS GuardDuty and rely on its threat detection alerts.

    Why it's wrong here

    GuardDuty detects threats but does not enforce policies or automate remediation.

  • Deploy a third-party cloud security posture management (CSPM) tool like Prisma Cloud.

    Why it's wrong here

    CSPM is effective but is a separate tool, not 'code-defined' policies; the requirement is for code-defined automation.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.