CAS-004 Security Architecture Practice Question
A software company is designing an internal developer platform where engineers need short-lived credentials to access production databases. The security architect wants to eliminate long-lived static database passwords, bind access to the identity of the calling workload, and automatically revoke credentials when a deployment is removed. Which of the following should the architect implement?
⚠ Common exam trap
The trap here is equating centralized secret storage with dynamic secrets, when stored passwords remain static and shared regardless of how securely they are delivered.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Issue dynamic, lease-based database credentials through a secrets engine tied to workload identity
Dynamic secrets with workload identity binding issue credentials only after the platform verifies the caller, and the credentials expire automatically with their lease. This removes static passwords from the environment and ensures that deleting a deployment terminates its database access without manual intervention. Secrets storage, mutual TLS, and auditing each address part of the problem but do not deliver identity-bound, automatically revoked credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure database native auditing and alert on anomalous query patterns
Why it's wrong here
Auditing and anomaly detection are detective controls that record and flag suspicious activity after connections occur. They do not eliminate static passwords, bind credentials to workload identity, or revoke access when a deployment is deleted. Detection is valuable but does not satisfy the preventive and lifecycle requirements described in the scenario.
- ✓
Issue dynamic, lease-based database credentials through a secrets engine tied to workload identity
Why this is correct
Dynamic secrets engines generate credentials on demand with a defined lease time and revoke them automatically when the lease expires or the workload is removed. When integrated with workload identity, the credential is issued only after the platform authenticates the calling pod or service, binding access to that identity. This eliminates long-lived passwords and provides automatic revocation, exactly as the scenario requires.
- ✗
Enable TLS client certificate authentication for all database connections
Why it's wrong here
Mutual TLS authenticates clients with certificates, which improves transport security and can bind access to a certificate identity. However, certificates are typically long-lived and revocation depends on CRL or OCSP propagation, so removing a deployment does not instantly revoke access. It also does not produce the short-lived, lease-based credential lifecycle the architect is targeting.
- ✗
Store database passwords in a centralized secrets manager and inject them at runtime
Why it's wrong here
A secrets manager centralizes storage and can rotate credentials, but the injected password remains a shared static secret that is valid until rotation. It is not bound to the workload identity, so any process that reads the secret can use it, and revocation requires an explicit rotation event rather than automatic removal of the deployment. This does not meet the short-lived, identity-bound requirement.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.