CAS-004 Security Architecture Practice Question
A startup is building a new application on a public cloud and wants to minimize the attack surface of its virtual machines. The security architect recommends replacing SSH key-based administration with a model where no inbound management ports are exposed and access is granted per session with short-lived credentials. Which of the following should be implemented?
⚠ Common exam trap
The trap here is believing that IP-restricted SSH or a bastion host minimizes attack surface, when both still leave inbound management ports and long-lived credentials in place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A just-in-time access broker that issues short-lived certificates and proxies sessions.
A just-in-time access broker removes standing inbound management access by issuing short-lived credentials and proxying sessions only when needed. This eliminates persistent SSH keys and exposed ports, directly minimizing the attack surface on the virtual machines while still allowing controlled administrative access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security groups that allow SSH only from the administrator's home IP address.
Why it's wrong here
Restricting SSH by source IP reduces exposure but still leaves an inbound management port open and uses persistent SSH keys. The requirement to remove exposed inbound ports and use short-lived per-session credentials is not satisfied, so the attack surface is not minimized as intended.
- ✗
A bastion host in a public subnet with SSH restricted to the corporate CIDR range.
Why it's wrong here
A bastion host still exposes an inbound management port and relies on long-lived SSH keys, which increases the attack surface. Although access is restricted by CIDR, the requirement to eliminate exposed inbound ports and use short-lived credentials is not met, so the attack surface is not minimized.
- ✓
A just-in-time access broker that issues short-lived certificates and proxies sessions.
Why this is correct
A just-in-time access broker grants per-session, short-lived credentials and proxies administrative connections without exposing inbound management ports on the virtual machines. This directly reduces the attack surface by removing persistent SSH access and eliminating standing credentials, matching the architect's recommendation.
- ✗
VPN concentrators that place administrators on the same private network as the VMs.
Why it's wrong here
A VPN grants network-level access but still requires the VMs to accept management connections, and it often relies on long-lived user credentials. It does not provide per-session short-lived credentials or eliminate exposed management ports, so the attack surface remains larger than required.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.