Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 1–75

973 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
MCQhard

An organization uses an EDR solution and wants to detect ransomware that encrypts files and then deletes volume shadow copies. Which EDR detection technique would be most effective for this behavior?

A.Signature-based detection using file hashes
B.Behavioral detection for mass file modifications and vssadmin.exe execution
C.Allowlisting of trusted applications
D.Network traffic analysis to detect C2 communication
AnswerB

Ransomware's destructive sequence — rapid mass file encryption followed by vssadmin.exe deleting shadow copies — is a behavioural pattern, not a signature. Detecting that combination of mass modification and shadow-copy deletion catches the attack regardless of malware family, satisfying the requirement to detect this specific behaviour.

Why this answer

Behavioral detection monitors runtime behavior like file encryption and shadow copy deletion, which are indicative of ransomware.

2
MCQmedium

A security administrator is configuring IPsec VPN between two sites. The data transmitted includes sensitive financial records. The administrator wants to ensure both confidentiality and integrity of the data, and also wants to authenticate the source. Which IPsec protocol and mode should be used?

A.ESP in tunnel mode
B.AH in tunnel mode
C.ESP in transport mode
D.AH in transport mode
AnswerA

ESP encrypts the payload and provides integrity plus data-origin authentication, meeting the confidentiality requirement that AH cannot. Tunnel mode encapsulates the whole packet between the site gateways, protecting the sensitive financial records across the untrusted link.

Why this answer

ESP (Encapsulating Security Payload) provides both confidentiality and integrity (optionally authentication). AH only provides integrity and authentication but not confidentiality. Transport mode encrypts only the payload, while tunnel mode encrypts the entire IP packet.

For site-to-site VPN, tunnel mode is typically used.

3
MCQeasy

A newly hired Chief Information Security Officer is establishing a governance structure and wants to define who is accountable for accepting residual risk that exceeds the organization's stated risk appetite. According to common governance practice, which role holds that accountability?

A.The board of directors or an executive risk committee with authority delegated by the board.
B.The internal audit director who reports findings to the audit committee.
C.The third-party managed security service provider under the outsourcing agreement.
D.The security operations center manager who oversees day-to-day monitoring and incident response.
AnswerA

Accountability for risk that exceeds the approved appetite rests with the board or a committee it empowers, since governance ultimately owns organizational risk. Executives and security staff implement and monitor controls, but accepting risk beyond the tolerance level requires the governing body's authority and oversight.

Why this answer

Governance accountability for accepting risk beyond the approved appetite belongs to the board of directors or a delegated executive risk committee. Operational and assurance roles support risk management but do not own the decision to retain risk at the enterprise level.

Exam trap

The trap here is assuming that whoever manages security operations day to day also owns the authority to accept risk that exceeds the organization's appetite.

4
MCQmedium

A security analyst is reviewing a vulnerability scan report for a web application. The report shows a high-severity finding for a SQL injection vulnerability on a login page. The analyst needs to validate the finding before escalating to the development team. Which of the following actions should the analyst take to safely validate the vulnerability?

A.Run a full vulnerability scan with credentials to confirm the finding.
B.Use an automated SQL injection tool to dump the database schema.
C.Review the application source code for parameterized queries.
D.Manually inject a benign SQL payload that returns a database error, such as a single quote.
AnswerD

Injecting a single quote is a safe, non-destructive way to test for SQL injection. If the application returns a database error, it indicates improper input sanitization and potential SQL injection. This method validates the finding without extracting data or modifying the database, making it suitable for a production environment. It is a standard manual validation technique.

Why this answer

Manual injection of a benign payload like a single quote is a safe and effective way to validate SQL injection. It tests the application's input handling without extracting data or causing damage. If a database error is returned, the vulnerability is confirmed.

This approach is minimally invasive and suitable for production systems, allowing the analyst to escalate with confidence.

Exam trap

The trap here is thinking that exploiting the vulnerability (e.g., dumping the schema) is necessary for validation, when a simple error-based test is sufficient and safer.

5
MCQeasy

A security team is implementing deception technology to detect attackers inside the network. They plan to deploy fake systems that appear vulnerable and attract attackers. Which of the following is an example of a honeytoken?

A.A network segment with multiple decoy systems
B.A fake DNS entry for a non-existent domain
C.A virtual machine running a vulnerable web server
D.A fake database credential file that triggers an alert when opened
AnswerD

A honeytoken is a decoy artefact, not a full system, that alerts on unauthorised access. A planted credential file triggers detection the moment an attacker opens or exfiltrates it, satisfying the requirement for a lure that reveals insider intrusion without exposing real assets.

Why this answer

A honeytoken is a piece of decoy data or a credential artifact — such as a fake database credential file, API key, or document — that has no legitimate use, so any access to it signals malicious activity and triggers an alert. Option D describes exactly this: a fake credential file that fires an alert when opened. The other options describe broader deception constructs (honeynets, honeypots, fake DNS records) rather than a discrete token of data.

Exam trap

The trap is conflating honeytokens with honeypots or honeynets — candidates pick the decoy system or decoy network because they sound similar, but a honeytoken is specifically a discrete data artifact (credential, file, key) whose access triggers an alert.

How to eliminate wrong answers

Option A is wrong because a network segment with multiple decoy systems is a honeynet, not a honeytoken — it is an environment of decoys, not a single data artifact. Option B is wrong because a fake DNS entry is a decoy record used for DNS sinkholing or detection of name-resolution abuse, not a honeytoken, which is data meant to be consumed. Option C is wrong because a VM running a vulnerable web server is a honeypot — an entire decoy host designed to attract exploitation — whereas a honeytoken is a smaller, embedded data object.

6
MCQmedium

A security manager is reviewing a set of documents: an organizational security policy, a standard for encryption, a guideline for remote access, and a procedure for incident response. Which document is at the highest level in the policy hierarchy?

A.Remote access guideline
B.Encryption standard
C.Organizational security policy
D.Incident response procedure
AnswerC

The organizational security policy sits at the top of the hierarchy, establishing management's mandatory intent and direction. Standards, guidelines and procedures all derive from and must align with it, so it satisfies the stem's requirement for the highest-level document.

Why this answer

The organizational security policy is the top-level governance document — it states management's intent, scope, and high-level requirements. Standards, guidelines, and procedures all derive from and must align with the policy, making it the highest document in the hierarchy.

Exam trap

The trap is conflating 'most detailed' or 'most operational' with 'highest level'; candidates must remember that the policy is the highest authority even though it is the least specific document.

How to eliminate wrong answers

Option A is wrong because a remote access guideline is advisory and sits below standards and policies in the hierarchy. Option B is wrong because an encryption standard is a mandatory, specific requirement that implements policy but is subordinate to it. Option D is wrong because an incident response procedure is a step-by-step operational document that implements policy and standards at the lowest level of the hierarchy.

7
Multi-Selectmedium

A security architect is designing a hybrid cloud environment where a web application hosted in AWS needs to securely access an on-premises database. The architect wants to minimize exposure to the internet and ensure encryption in transit. Which TWO techniques should the architect consider? (Choose two.)

Select 2 answers
A.Establish an IPsec VPN tunnel between the AWS VPC and the on-premises network.
B.Use AWS Direct Connect to create a dedicated private network connection from on-premises to AWS.
C.Store database credentials in AWS Secrets Manager and retrieve them at runtime.
D.Configure VPC peering between the AWS VPC and the on-premises network.
E.Configure the web application to connect to the database using TLS encryption.
AnswersA, B

An IPsec VPN tunnel encrypts traffic in transit between the AWS VPC and on-premises network, satisfying the encryption requirement. Because it runs over the public internet, it does not fully eliminate internet exposure, but it is a valid technique for secure hybrid connectivity.

Why this answer

Option A is correct because an IPsec VPN tunnel between the AWS VPC and the on-premises network creates an encrypted, private path over the internet, satisfying both the requirement to minimize public exposure and to ensure encryption in transit. Option B is correct because AWS Direct Connect provides a dedicated private network connection from on-premises to AWS that bypasses the public internet entirely, and it can be combined with encryption (e.g., MACsec or VPN over Direct Connect) to meet the in-transit encryption requirement. Option C is not correct here because Secrets Manager handles credential storage and rotation, not the secure network path or encryption in transit between the web app and the database.

Option D is not correct because VPC peering only connects VPCs within AWS (or between AWS VPCs), not an AWS VPC to an on-premises network. Option E is not correct because TLS encrypts the application-to-database session but does not by itself minimize internet exposure, since the traffic could still traverse the public internet.

Exam trap

The trap here is that candidates often confuse VPC peering with hybrid connectivity, not realizing it only works between VPCs within the same AWS region, or they assume TLS alone is sufficient for network-level security without addressing the underlying internet exposure.

8
MCQmedium

A security analyst is investigating a suspected DNS tunneling attack. The analyst observes a high volume of DNS queries to a single domain, with query names that appear to be Base64-encoded strings. Which of the following is the MOST effective way to confirm and analyze this activity?

A.Capture full packet data and decode the query names to look for hidden data
B.Check the reputation of the destination DNS server IP address
C.Monitor for an increase in DNS response time
D.Review firewall logs for allowed outbound DNS traffic
AnswerA

DNS tunneling encodes data in DNS query names or responses. Capturing full packets allows the analyst to extract the query strings, decode them (e.g., Base64), and examine the payload. This confirms tunneling and reveals exfiltrated or command-and-control data. Other methods may indicate tunneling but do not provide the actual content for analysis.

Why this answer

DNS tunneling hides data within DNS queries and responses. To confirm and analyze it, the analyst must capture the actual DNS packets and decode the query names, which often contain Base64 or hex-encoded payloads. This reveals the exfiltrated data or C2 commands.

The other options may provide circumstantial evidence but do not directly analyze the tunneled content.

Exam trap

The trap here is focusing on network-level indicators like IP reputation or response times instead of examining the actual DNS payload for encoded data.

9
MCQhard

A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?

A.SHA-256 hashing of the account number with a per-row salt
B.Deterministic encryption using AES-SIV
C.RSA-4096 OAEP encryption of each account number
D.AES-256-GCM with a random 96-bit nonce per record
AnswerB

AES-SIV is a misuse-resistant AEAD mode that produces a deterministic ciphertext for a given plaintext and associated data, so identical account numbers map to identical ciphertext. This preserves equality searches, joins, and unique indexes while keeping values unreadable to DBAs who lack the key, satisfying the stated business requirement.

Why this answer

The requirement for repeatable ciphertext that still supports equality lookups points to a deterministic authenticated encryption mode. AES-SIV derives its nonce from the plaintext and associated data, so the same input always yields the same output while still providing integrity. Randomized modes and salted hashing break the equality-search property the database design depends on.

Exam trap

The trap here is assuming that any authenticated encryption mode preserves equality lookups, when in fact only deterministic modes do so.

10
Multi-Selecteasy

A penetration tester is planning a test against a web application. The rules of engagement specify that the tester must not disrupt production services. Which TWO reconnaissance techniques are considered passive and would be appropriate for initial information gathering without impacting the target? (Select TWO.)

Select 2 answers
A.Port scanning the target network
B.Vulnerability scanning
C.Social engineering attacks
D.WHOIS lookup on the domain
E.OSINT gathering from public sources
AnswersD, E

A WHOIS lookup queries public registrar databases rather than the target's own infrastructure, so no packets reach the web application and production services remain untouched. This satisfies the rules of engagement constraint prohibiting disruption, making it suitable for initial passive information gathering before any active enumeration begins.

Why this answer

WHOIS lookup on the domain (D) is correct because it queries public registrar databases for registration details such as registrant contacts, name servers, and creation/expiration dates, generating no traffic to the target's own infrastructure and thus causing zero disruption. OSINT gathering from public sources (E) is correct because it collects information from third-party sites, search engines, cached pages, and public records, again without sending packets to the target and therefore remaining passive and non-disruptive. Port scanning (A) is not passive: it sends TCP/UDP probes (e.g., SYN or connect scans) directly to target hosts, which can be logged, rate-limited, or destabilize fragile services.

Vulnerability scanning (B) is also active and intrusive, as it transmits crafted requests and payloads that can crash or overload production systems. Social engineering attacks (C) are neither passive reconnaissance nor non-disruptive, since they involve direct interaction with personnel and can cause operational or security incidents.

Exam trap

The trap here is conflating 'non-intrusive' with 'passive' — candidates often pick vulnerability scanning because it can be run in a low-impact mode, but any technique that sends packets to the target is active by definition.

11
MCQeasy

Which of the following is the BEST definition of a risk register?

A.A list of identified risks with associated attributes such as impact, likelihood, and owner.
B.A report of audit findings and non-conformities.
C.A document that outlines the organization's risk appetite.
D.A tool used to automate risk assessment processes.
AnswerA

A risk register captures each risk along with its characteristics and management status.

Why this answer

A risk register is a foundational document in risk management that systematically catalogs identified risks along with key attributes such as impact, likelihood, risk score, and assigned owner. This structured record enables ongoing tracking, prioritization, and mitigation of risks throughout the system development lifecycle or operational environment. In the context of CAS-004, the risk register is the primary artifact used to support governance and compliance activities, ensuring that risk treatment decisions are documented and auditable.

Exam trap

Candidates often confuse a risk register with a risk appetite statement. The risk register is a living document that lists individual risks with attributes like impact and likelihood, whereas the risk appetite statement is a high-level policy boundary. In CASP+ governance questions, understanding this distinction is key.

How to eliminate wrong answers

Option B is wrong because a report of audit findings and non-conformities is an audit report, not a risk register; it documents past compliance gaps rather than forward-looking risk attributes like likelihood and impact. Option C is wrong because a document outlining the organization's risk appetite defines the amount of risk the organization is willing to accept, which is a strategic policy statement, not a dynamic list of individual risks with owners. Option D is wrong because a tool used to automate risk assessment processes is a risk assessment tool or platform (e.g., a GRC software module), not the risk register itself; the register is the data output, not the automation mechanism.

12
MCQmedium

A security operations center (SOC) analyst receives an alert from the SIEM indicating a user has logged into the corporate VPN from an unusual geographic location at 3 AM, which is outside the user's normal working hours. The user has not previously exhibited this behavior. Which advanced SIEM capability is most likely responsible for generating this alert?

A.User Behavior Analytics (UBA)
B.Correlation rule based on static thresholds
C.Signature-based detection
D.Threat intelligence feed correlation
AnswerA

User Behaviour Analytics baselines each user's normal login patterns — location, time, device — and flags statistically anomalous deviations. The 3 AM foreign VPN login falls outside the established baseline, so UBA generates the alert rather than static correlation rules.

Why this answer

User Behavior Analytics (UBA) uses machine learning to establish a baseline of normal user activity and detect anomalies such as unusual login times and locations. This is a core feature of advanced SIEM platforms.

13
MCQmedium

A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution across 10,000 endpoints. The team wants to ensure that if the EDR agent is disabled or tampered with, the SOC is immediately alerted and the endpoint can be isolated. Which EDR capability should the team prioritize?

A.Full disk encryption with key escrow
B.Tamper protection with automated response actions
C.Continuous signature updates from the vendor
D.Integration with a SIEM for log forwarding
AnswerB

Tamper protection prevents unauthorized disabling of the EDR agent, and automated response actions such as host isolation can be triggered when tampering is detected. This directly addresses the requirement to alert and isolate. Other features like signature updates or forensic analysis do not provide real-time tamper detection and response.

Why this answer

The requirement is to detect tampering and respond by isolating the endpoint. Tamper protection ensures the EDR agent cannot be easily disabled, and automated response actions can isolate the host. Other options focus on detection updates, logging, or encryption, which do not provide the needed tamper detection and immediate isolation.

Exam trap

The trap here is assuming that SIEM integration alone provides tamper detection and response, when it only forwards logs and does not prevent agent disablement.

14
MCQhard

An architect is designing a multi-factor authentication (MFA) solution for remote access. Which of the following is the STRONGEST form of second factor?

A.Email OTP
B.FIDO2 WebAuthn hardware token
C.SMS one-time code
D.Knowledge-based questions
AnswerB

FIDO2 WebAuthn binds authentication to the origin via public-key cryptography, so credentials cannot be phished or replayed. This satisfies the demand for the strongest second factor, since possession-based hardware tokens with origin binding outperform OTP codes and push notifications against real-time relay attacks.

Why this answer

FIDO2 WebAuthn hardware tokens provide the strongest second factor because they use public-key cryptography to generate a unique key pair per service, with the private key stored securely on the token. This eliminates phishing, man-in-the-middle, and replay attacks, as the token signs a challenge from the relying party without ever sharing a shared secret over the network.

Exam trap

CompTIA often tests the misconception that SMS OTP or email OTP is 'strong enough' for remote access, but the trap here is that candidates overlook the fundamental security advantage of hardware-bound private keys over shared-secret OTPs, especially against phishing and relay attacks.

How to eliminate wrong answers

Option A is wrong because email OTPs are delivered over a channel that can be intercepted (e.g., compromised email account, man-in-the-middle on SMTP) and are susceptible to phishing attacks where the user is tricked into entering the code on a fake site. Option C is wrong because SMS one-time codes rely on SS7 protocol vulnerabilities that allow interception or SIM-swap attacks, and they are also phishable. Option D is wrong because knowledge-based questions (e.g., 'What is your mother's maiden name?') rely on static, often publicly discoverable information and are not a true second factor, as they can be guessed or obtained through social engineering.

15
MCQeasy

A retail company is building a new mobile application that will collect customer location data. The legal team asks the security manager to ensure the design follows privacy by design principles from the earliest stages. Which action best demonstrates privacy by design in this scenario?

A.Add a privacy policy link to the application store listing after the application is released
B.Encrypt location data at rest and assume that encryption alone satisfies privacy requirements
C.Perform a privacy impact assessment and design data minimization controls before development begins
D.Collect precise location data continuously so that future marketing features have a rich data set
AnswerC

Privacy by design requires that privacy be considered proactively and embedded into the design rather than added after deployment. Conducting a privacy impact assessment early identifies risks and informs decisions about what data to collect, how long to keep it, and how to protect it. Designing data minimization controls at the start directly implements the principle of limiting collection to what is necessary and demonstrates privacy by design in this scenario.

Why this answer

Privacy by design means embedding privacy into systems and processes from the outset, not retrofitting it later. An early privacy impact assessment combined with data minimization controls during design directly implements that principle. The other actions either collect excessive data, react after release, or rely on a single control that does not address purpose limitation and minimization, so they do not meet the legal team's request.

Exam trap

The trap here is equating privacy by design with encryption alone, when it actually requires proactive minimization and purpose limitation before development begins.

16
MCQmedium

An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?

A.Software-defined WAN (SD-WAN) functionality
B.Network-layer encryption using IPsec
C.Identity-based access with zero trust principles
D.Web content filtering and DLP
AnswerC

SASE couples identity-based, zero trust access with cloud-delivered security inspection, evaluating each session against user identity and device posture rather than granting broad network reach. Traditional VPNs authenticate once and then place the user on the network, which is the gap the stem highlights.

Why this answer

SASE converges networking and security functions into a cloud-delivered service, with zero trust network access (ZTNA) as a core pillar. Unlike traditional VPNs that grant broad network-level access after authentication, SASE enforces identity-based, context-aware access policies per application or resource. This aligns with zero trust principles: never trust, always verify, and least-privilege access.

Exam trap

The trap here is confusing SASE with traditional security or networking features that are components but not the key differentiator; candidates often pick SD-WAN or encryption because they are familiar, missing the zero trust identity-based access emphasis.

How to eliminate wrong answers

Option A is wrong because SD-WAN is a networking capability often integrated into SASE but not unique to it; traditional VPNs can coexist with SD-WAN. Option B is wrong because IPsec network-layer encryption is a standard VPN feature, not a SASE differentiator. Option D is wrong because web content filtering and DLP are security services that can be provided by standalone secure web gateways, not exclusive to SASE.

17
MCQeasy

An organization wants to share threat intelligence with industry peers using a standardized format. Which of the following formats is specifically designed for representing structured threat information in a machine-readable way?

A.CyboX
B.TAXII
C.STIX
D.OpenIOC
AnswerC

STIX (Structured Threat Information Expression) is purpose-built to represent cyber threat intelligence as structured, machine-readable JSON, covering indicators, campaigns, threat actors and relationships. It satisfies the stem's requirement for a standardised, machine-readable sharing format, unlike document-centric or transport protocols such as TAXII, which merely conveys STIX.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language for representing threat intelligence.

18
Multi-Selecthard

A security assessor is reviewing a containerized application. Which three of the following practices help secure the container runtime environment? (Select the three best options.)

Select 3 answers
A.Run the container with a read-only root filesystem
B.Use the latest base image from Docker Hub
C.Drop all Linux capabilities and add only required ones
D.Run the container process as a non-root user
AnswersA, C, D

Why this answer

Running a container with a read-only root filesystem (option A) prevents any writes to the container's filesystem layer, which blocks malware from dropping files, modifying binaries, or persisting changes. This is enforced by the container runtime (e.g., Docker, containerd) by mounting the root filesystem as read-only, typically using the `--read-only` flag. Even if an attacker gains code execution inside the container, they cannot alter system files or install tools, significantly reducing the blast radius of a compromise.

Exam trap

CompTIA often tests the distinction between image security (e.g., using latest images) and runtime security (e.g., read-only filesystem, capability dropping, non-root user), and the trap here is that candidates may incorrectly select 'use the latest base image' because they conflate image freshness with runtime hardening.

Why the other options are wrong

B

This is important for image security, not runtime configuration.

19
Multi-Selecthard

Which THREE of the following are required by the NIST Cybersecurity Framework (CSF) for the 'Protect' function?

Select 3 answers
A.Performing regular maintenance of systems
B.Ensuring data at rest and in transit is encrypted
C.Conducting a risk assessment for critical assets
D.Developing an incident response plan
E.Implementing access controls for authorized users
AnswersA, B, E

Maintenance is under Protect.

Why this answer

Performing regular maintenance of systems is required under the Protect function of the NIST Cybersecurity Framework (CSF) because it directly supports the 'Protective Technology' and 'Maintenance' subcategories (PR.MA). Regular patching, updates, and hardware upkeep ensure that security controls remain effective against known vulnerabilities, reducing the attack surface. This is a proactive measure to sustain the integrity and availability of systems, aligning with the CSF's focus on safeguarding critical infrastructure.

Exam trap

The CAS-004 exam often tests the distinction between CSF functions, and the trap here is confusing the 'Protect' function's maintenance and access control requirements with risk assessment (Identify) or incident response planning (Respond), which are separate pillars of the framework.

20
MCQmedium

An organization uses Ansible to automate server configuration for a hybrid cloud environment. The security team requires that sensitive data such as API keys and passwords are not exposed in the Ansible playbooks or logs. The Ansible control node is shared among several administrators. What is the best approach to protect these secrets?

A.Store secrets in plaintext in a separate file and set restrictive file permissions.
B.Remove all secrets from automation and require manual entry during each playbook run.
C.Use Ansible Vault to encrypt the secret variables and restrict access to the vault password file.
D.Define secrets as environment variables on the control node and reference them in playbooks.
AnswerC

Ansible Vault encrypts variable files at rest with AES-256, so secrets never appear in plaintext playbooks, inventory or logs. Restricting the vault password file to authorised administrators on the shared control node prevents other users from decrypting them.

Why this answer

Ansible Vault encrypts sensitive variables and files so secrets are never stored in plaintext in playbooks or logs. Restricting access to the vault password file ensures only authorized administrators on the shared control node can decrypt the secrets. This satisfies the requirement that secrets not be exposed in playbooks or logs.

Exam trap

CAS-005 often tests the misconception that file permissions or environment variables are sufficient secret protection, when the requirement is encryption at rest and controlled decryption.

How to eliminate wrong answers

Option A is wrong because plaintext secrets in a file, even with restrictive permissions, are still readable by anyone with root or file access and can leak into backups or logs. Option B is wrong because removing secrets and requiring manual entry defeats automation, introduces human error, and does not scale. Option D is wrong because environment variables on a shared control node are visible to other processes and users (e.g., via /proc) and are not encrypted at rest.

21
MCQeasy

A hospital's security manager is aligning internal documents after a policy refresh. The board approved a statement that defines the organization's overall security intent and assigns responsibility to executive leadership, but it deliberately avoids naming specific products or technical settings. Which document type has the board approved?

A.A security standard
B.A security policy
C.A security procedure
D.A security guideline
AnswerB

A policy is a high-level, management-approved statement of intent that defines the organization's security objectives and assigns responsibility without prescribing technical detail. The board's document matches this exactly: it sets overall direction, delegates accountability to executives, and intentionally avoids product-specific or configuration-level content. That places it at the top of the governance hierarchy, above standards and procedures.

Why this answer

A policy is the management-approved, high-level statement that expresses security intent and assigns accountability without dictating products or settings. Standards enforce specific mandatory requirements, procedures describe operational steps, and guidelines offer optional advice. Because the board's document sets direction and delegates responsibility at an enterprise level while avoiding technical specificity, it is a policy sitting at the top of the governance hierarchy.

Exam trap

The trap here is assuming that because the document avoids technical detail it must be a guideline, when the board's formal approval and assignment of responsibility make it a mandatory policy.

22
MCQhard

During a ransomware incident, the organization discovers that all production backups have been encrypted by the attacker. What is the most effective recovery approach?

A.Restore from offline immutable backups
B.Restore from system restore points
C.Use a decryption tool from security vendors
D.Pay the ransom to obtain the decryption key
AnswerA

Offline immutable backups cannot be encrypted or deleted by ransomware because they are not reachable from the production network. Restoring from them recovers clean data without paying, directly addressing the stem's constraint that all production backups were encrypted.

Why this answer

Restoring from offline immutable backups is the most effective recovery approach when production backups have been encrypted by ransomware. Immutable backups cannot be altered or deleted, even by an attacker with administrative credentials, ensuring that a clean copy of data is available for restoration. This approach minimizes downtime and avoids paying the ransom.

Exam trap

CAS-005 often tests the effectiveness of different recovery methods, and candidates may incorrectly choose paying the ransom or using decryption tools due to desperation or lack of awareness of immutable backup capabilities.

How to eliminate wrong answers

Option B is wrong because system restore points are typically local to a system and may also be encrypted or deleted by the attacker, and they do not cover all data. Option C is wrong because decryption tools from security vendors are not guaranteed to work for all ransomware variants and may be ineffective. Option D is wrong because paying the ransom does not guarantee data recovery, encourages further attacks, and may violate legal or ethical guidelines.

23
Multi-Selectmedium

A security architect is designing a microsegmentation strategy for a data center hosting legacy and modern applications. The architect must ensure that workloads can only communicate with explicitly authorized peers and that policy follows the workload even if it is migrated between hosts. Which two of the following controls best meet these requirements? (Choose two.)

Select 2 answers
A.VLAN segmentation with ACLs applied at the core switch.
B.A next-generation firewall with a single perimeter zone for all internal servers.
C.Host-based firewall agents that enforce allow-list rules based on workload identity tags.
D.A software-defined networking overlay that enforces policy based on workload labels.
E.802.1X port-based network access control for all server NICs.
AnswersC, D

Host-based firewall agents enforce policy at the workload level and can use identity tags rather than IP addresses, so rules remain valid when the workload moves between hosts. This satisfies both explicit peer authorization and policy portability, making it a core microsegmentation control.

Why this answer

Microsegmentation requires policy that is based on workload identity and portable across hosts. Host-based firewall agents with identity-tag rules and an SDN overlay enforcing label-based policy both deliver explicit peer authorization and follow workloads during migration. VLAN ACLs, a single perimeter zone, and 802.1X either tie policy to topology or address admission rather than ongoing east-west control.

Exam trap

The trap here is equating VLAN segmentation with microsegmentation, when VLANs tie policy to network location and do not follow a workload that migrates.

24
MCQmedium

A company is deploying IoT sensors that require secure firmware updates over the air (OTA). To ensure integrity and authenticity of the firmware, which of the following should be implemented?

A.Code signing with a trusted certificate
B.Secure boot on the device
C.Hash verification only
D.Encryption of the firmware image
AnswerA

Code signing with a trusted certificate lets each IoT sensor verify the firmware's signature against the vendor's public key before installation, confirming both integrity and origin. Unsigned or tampered images are rejected, satisfying the OTA authenticity requirement.

Why this answer

Code signing with a trusted certificate provides both integrity and authenticity: the firmware is hashed and signed by the vendor's private key, and the device verifies the signature using the vendor's public key. This ensures the firmware has not been tampered with and originates from a trusted source. Hash verification alone only checks integrity, not authenticity.

Exam trap

The trap is confusing integrity (hash) with authenticity (signature); candidates often pick hash verification thinking it covers both, but only code signing proves the source.

How to eliminate wrong answers

Option B is wrong because secure boot ensures the device only boots trusted firmware but does not by itself verify OTA update packages during download; it is a boot-time control, not an update-authenticity mechanism. Option C is wrong because a hash verifies integrity but not authenticity—an attacker could replace both the firmware and the hash. Option D is wrong because encryption provides confidentiality, not integrity or authenticity; an encrypted malicious image could still be installed.

25
MCQeasy

A security analyst is reviewing a packet capture and observes that a client and server negotiate a session key using ephemeral Diffie-Hellman, after which all application data is encrypted with a symmetric cipher. The analyst wants to document which security property the ephemeral key exchange provides that a static RSA key transport would not. Which property is that?

A.Perfect confidentiality of the server certificate, because the certificate is encrypted during the handshake.
B.Forward secrecy, because compromise of the long-term private key does not reveal past session keys.
C.Non-repudiation, because the ephemeral key pair proves the server's identity to the client.
D.Data integrity, because Diffie-Hellman produces a message authentication code over each record.
AnswerB

Ephemeral Diffie-Hellman generates a fresh key pair per session and discards it afterward, so the session key is never derivable from the server's long-term private key. Even if that long-term key is later compromised, previously recorded sessions remain protected. Static RSA key transport encrypts the premaster secret with the long-term key, so its compromise retroactively exposes past sessions, which is exactly the property ephemeral DH adds.

Why this answer

Ephemeral Diffie-Hellman creates a unique shared secret per session and erases the private ephemeral values, so a later compromise of the server's long-term key cannot decrypt previously captured traffic. Static RSA key transport ties the premaster secret to the long-term key, so that compromise exposes all recorded sessions. The distinguishing property is forward secrecy.

Exam trap

The trap here is confusing the authentication and integrity services of TLS with the key-agreement property, when the real benefit of ephemeral key exchange is protection of past sessions.

26
MCQhard

A security engineer is configuring a hardware security module (HSM) to protect a root certificate authority's private key. The requirement is that the key must never exist in plaintext outside the HSM and must be usable by multiple authorized administrators under dual control. Which configuration BEST satisfies these requirements?

A.Generate the CA key on a hardened offline workstation, wrap it with a passphrase-derived AES key, and import the wrapped blob into the HSM.
B.Generate the CA key inside the HSM as an extractable key so that a secure backup can be made, and rely on HSM role-based access control for administrator separation.
C.Generate the CA key inside the HSM and store a passphrase-protected copy in an encrypted configuration management database for disaster recovery.
D.Generate the CA key inside the HSM as a non-extractable key and configure M of N quorum authentication for administrative operations.
AnswerD

Generating the key inside the HSM with the non-extractable attribute ensures the private key material never leaves the cryptographic boundary in plaintext. M of N quorum authentication enforces dual control by requiring multiple smartcards or credentials to authorize sensitive operations, directly meeting both requirements.

Why this answer

The strongest protection is to have the HSM itself generate the key as non-extractable, so the private material is created and used only within the tamper-resistant boundary. Layering M of N quorum authentication ensures that no single administrator can perform sensitive CA operations, providing the dual control the scenario requires.

Exam trap

The trap here is treating encryption or passphrase wrapping of an externally generated key as equivalent to never exposing plaintext, when the key was already in plaintext during generation.

27
MCQeasy

A financial institution is required to comply with PCI DSS. A low-severity vulnerability is found in the cardholder data environment that would cost significant downtime to patch. What is the BEST course of action?

A.Implement compensating controls and formally accept the risk with documented approval
B.Transfer the risk to a third party
C.Accept the risk without documentation
D.Immediately patch the vulnerability
AnswerA

This satisfies PCI DSS requirements and manages risk.

Why this answer

PCI DSS Requirement 6.2 allows organizations to formally accept risk for low-severity vulnerabilities when patching would cause significant operational impact, provided compensating controls are implemented and documented approval is obtained from management. This balances security compliance with business continuity, as the vulnerability is low-risk and the downtime cost outweighs the immediate threat.

Exam trap

The trap here is that candidates assume PCI DSS mandates immediate patching for any vulnerability in the CDE, but the standard explicitly allows risk acceptance for low-severity findings when patching causes significant business impact, provided compensating controls and formal approval are in place.

How to eliminate wrong answers

Option B is wrong because transferring risk to a third party (e.g., via insurance or outsourcing) does not absolve the financial institution of PCI DSS compliance responsibility; the entity remains liable for cardholder data security. Option C is wrong because accepting risk without documentation violates PCI DSS Requirement 12.1.2, which mandates formal risk acceptance with sign-off from authorized personnel. Option D is wrong because immediately patching a low-severity vulnerability that causes significant downtime is not the best course of action; PCI DSS allows for risk acceptance with compensating controls to avoid unnecessary operational disruption.

28
MCQhard

A network administrator is troubleshooting connectivity issues. Based on the exhibit, which of the following is true about the iptables rules?

A.New connections from the internet to 10.0.1.0/24 are allowed.
B.All traffic is allowed by default because the policy is ACCEPT.
C.Traffic from 10.0.1.0/24 to the internet is allowed, but return traffic is only allowed if it is part of an established connection.
D.The rules apply to incoming traffic on the firewall itself.
AnswerC

The OUTPUT chain's stateful rule permits replies only when conntrack marks them ESTABLISHED or RELATED, so outbound sessions from 10.0.1.0/24 succeed while unsolicited inbound packets are dropped. This satisfies the exhibit's requirement that return traffic be tied to connections initiated internally, rather than opening the interface indiscriminately.

Why this answer

The iptables rules show a default FORWARD policy of DROP (as indicated by the 'policy DROP' line), which drops all traffic not explicitly allowed. The rule '-A FORWARD -s 10.0.1.0/24 -j ACCEPT' allows outbound traffic from the 10.0.1.0/24 subnet to the internet. The rule '-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT' ensures that return traffic belonging to an existing connection is permitted back, while new inbound connections from the internet are implicitly dropped by the default DROP policy.

Exam trap

The trap here is that candidates often confuse the FORWARD chain with the INPUT chain, assuming that rules in the FORWARD chain apply to traffic destined for the firewall itself, or they overlook that the default policy for the FORWARD chain is DROP (not ACCEPT) unless explicitly set to ACCEPT in the exhibit.

How to eliminate wrong answers

Option A is wrong because the FORWARD chain's default policy is DROP (not shown but implied by the rules), and there is no rule allowing new connections from the internet to 10.0.1.0/24; only ESTABLISHED,RELATED traffic is allowed back. Option B is wrong because the policy shown is ACCEPT only for the FORWARD chain, but the INPUT chain has a default policy of DROP, and the FORWARD chain's default policy is also DROP (as no default ACCEPT is listed for FORWARD in the exhibit); thus, not all traffic is allowed by default. Option D is wrong because the rules shown are in the FORWARD chain, which applies to traffic being routed through the firewall, not to incoming traffic destined for the firewall itself (which would be handled by the INPUT chain).

29
MCQeasy

Which of the following best describes the primary security benefit of using immutable infrastructure in a containerized environment?

A.It reduces resource consumption by reusing containers.
B.It prevents unauthorized modifications to running containers.
C.It automates patching of container images.
D.It eliminates the need for container security scanning.
AnswerB

Immutable infrastructure replaces rather than patches running containers, so any drift or tampering is discarded when the instance is redeployed from a trusted image. This directly satisfies the scenario's requirement to prevent unauthorised modifications, since no persistent writable state survives for an attacker to alter.

Why this answer

Immutable infrastructure ensures that once a container image is built and deployed, it is never modified in place. If a change is needed, a new image is built and deployed, replacing the old container entirely. This prevents unauthorized or unplanned modifications to running containers, which is the primary security benefit because it eliminates configuration drift and reduces the attack surface from runtime tampering.

Exam trap

The trap here is that candidates confuse immutability with automation of patching or resource efficiency, when in fact immutability is a security control against runtime modification, not a patch management or cost-saving mechanism.

Why the other options are wrong

A

Immutable infrastructure usually increases resource usage due to frequent replacement; reuse is not a security benefit.

C

Immutable infrastructure requires rebuilding images for patches, but it does not automate the patching itself.

D

Immutable infrastructure still requires scanning images for vulnerabilities before deployment.

30
MCQhard

A security architect is evaluating a third-party SaaS provider for a critical business function. The provider will process sensitive customer data and must demonstrate compliance with the organization's security requirements. The architect needs to obtain assurance about the provider's security controls without conducting an on-site audit. Which of the following should the architect request?

A.Self-attestation questionnaire completed by the provider
B.SOC 2 Type II report
C.SOC 2 Type I report
D.Penetration test summary from the provider
AnswerB

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls over a period of time, covering security, availability, and confidentiality. It gives assurance without an on-site audit and is specifically designed for service providers handling sensitive data.

Why this answer

A SOC 2 Type II report provides independent validation of control effectiveness over a period, directly addressing the need for assurance without an on-site audit. It is the standard mechanism for assessing SaaS providers' security and compliance posture.

Exam trap

The trap here is accepting a SOC 2 Type I report or self-attestation as equivalent to a Type II report, which covers operating effectiveness over time.

31
Multi-Selectmedium

A security engineer is evaluating options for securing firmware updates on IoT devices. Which TWO methods provide integrity verification of the update?

Select 2 answers
A.Obfuscation of the firmware code
B.AES encryption of the firmware
C.Hash-based message authentication code (HMAC)
D.Digital signature verification
E.Secure Boot
AnswersC, D

HMAC computes a keyed hash over the firmware image using a shared secret, so the device verifies both integrity and authenticity of the update; any modification without the secret key produces a mismatched tag and the update is rejected.

Why this answer

HMAC (C) is correct because it uses a cryptographic hash function combined with a secret key to produce a message authentication code, allowing the recipient to verify both the integrity of the firmware update and its authenticity, since any modification to the firmware would change the resulting HMAC value. Digital signature verification (D) is correct because it uses asymmetric cryptography (e.g., RSA or ECDSA) to sign the firmware hash with a private key, and the device verifies the signature with the corresponding public key, providing strong integrity and authenticity assurance that the update has not been tampered with. Obfuscation (A) only makes code harder to read and does not provide any cryptographic integrity check, so it cannot detect modification.

AES encryption (B) provides confidentiality, not integrity verification, unless combined with a separate integrity mechanism such as an AEAD mode, which is not stated here. Secure Boot (E) is a boot-time process that verifies the integrity of the boot chain using signatures, but it is not itself a method for verifying the integrity of a firmware update payload during the update process.

Exam trap

CompTIA often tests the distinction between confidentiality and integrity, so candidates mistakenly select AES encryption (Option B) thinking it protects against tampering, when in fact encryption alone does not provide integrity verification.

32
MCQmedium

A security analyst is reviewing the organization's business continuity plan (BCP). The plan specifies a recovery time objective (RTO) of 4 hours for a critical e-commerce application. Which of the following BEST describes the meaning of this RTO?

A.The time required to fully restore the application from backups.
B.The maximum time the application can be down before it significantly impacts the business.
C.The frequency at which backups of the application are performed.
D.The maximum acceptable amount of data loss measured in time.
AnswerB

The recovery time objective (RTO) is the maximum acceptable time that an application or system can be unavailable after a disruption. It defines how quickly the business needs the service restored. In this scenario, an RTO of 4 hours means the e-commerce application must be back online within 4 hours to avoid unacceptable business impact. This is the correct definition.

Why this answer

The recovery time objective (RTO) defines the maximum acceptable downtime for a system after a disruption. In this case, a 4-hour RTO means the e-commerce application must be restored within 4 hours. RTO is distinct from RPO, which deals with data loss.

The other options describe RPO, actual recovery time, or backup frequency, none of which define RTO.

Exam trap

The trap here is mixing up RTO with RPO or actual recovery time; RTO is the target downtime, not the data loss tolerance or backup schedule.

33
MCQmedium

A security engineer is configuring a secure boot process for a Linux server using UEFI. The engineer wants to ensure that only signed bootloaders and kernels are executed. Which of the following components is responsible for verifying the signature of the bootloader?

A.The UEFI signature database (db)
B.The bootloader's own signature check
C.The Key Exchange Key (KEK)
D.The UEFI firmware's Platform Key (PK)
AnswerA

The UEFI signature database (db) contains certificates and hashes of trusted bootloaders and drivers. During boot, the UEFI firmware verifies the signature of the bootloader against the entries in the db. If the bootloader's signature matches a trusted certificate in the db, it is allowed to execute. This is the component directly responsible for verification.

Why this answer

In UEFI Secure Boot, the firmware uses the signature database (db) to validate the bootloader's signature. The db contains trusted certificates and hashes. When the bootloader is loaded, the firmware checks its signature against the db.

If it matches, the bootloader runs; otherwise, boot is halted or an error is shown. This ensures only trusted code executes.

Exam trap

The trap here is thinking the PK or KEK directly verifies the bootloader, but they only establish the trust chain for the db.

34
MCQeasy

Which risk treatment option involves reducing the likelihood or impact of a risk through controls?

A.Mitigate
B.Avoid
C.Accept
D.Transfer
AnswerA

Mitigation applies controls to reduce risk.

Why this answer

Mitigation involves implementing controls to reduce the likelihood or impact of a risk. This is the definition of risk mitigation in risk management frameworks like NIST and ISO 31000. It is distinct from avoidance (eliminating the activity), acceptance (retaining the risk), and transfer (shifting to a third party).

Exam trap

CAS-005 often tests the distinction between risk treatment options, and candidates frequently confuse mitigation with avoidance or transfer, especially when the question mentions 'controls' which could be misconstrued as transfer via insurance.

How to eliminate wrong answers

Option B is wrong because avoidance means eliminating the risk by not performing the activity that introduces it, not reducing it through controls. Option C is wrong because acceptance means acknowledging the risk and deciding to bear it without additional controls. Option D is wrong because transfer shifts the risk to another party, such as through insurance or outsourcing, rather than reducing it.

35
MCQeasy

Which security metric measures the average time it takes to detect a security incident after it has occurred?

A.Mean Time to Detect (MTTD)
B.Mean Time Between Failures (MTBF)
C.Mean Time to Respond (MTTR)
D.Mean Time to Recover (MTTR)
AnswerA

Mean Time to Detect measures the average elapsed time between an incident occurring and its detection, exactly matching the metric described. It isolates detection speed from response or resolution timing, which are covered by separate metrics.

Why this answer

Mean Time to Detect (MTTD) is the metric that specifically measures the average elapsed time between when a security incident actually occurs and when it is detected by monitoring, alerting, or analyst investigation. It is a core SOC efficiency metric used to evaluate detection capabilities.

Exam trap

The trap is the overlapping 'MTTR' acronyms — candidates must distinguish Mean Time to Respond from Mean Time to Recover, and not confuse either with detection (MTTD).

How to eliminate wrong answers

Option B is wrong because MTBF measures reliability — the average time between system failures, not detection speed. Option C is wrong because MTTR (Mean Time to Respond) measures how long it takes to respond after detection, not to detect. Option D is wrong because Mean Time to Recover measures restoration time after an outage, which is a resilience metric, not a detection metric.

36
MCQmedium

A security analyst is analyzing a memory dump from a compromised host using Volatility. Which Volatility plugin would be most useful to identify a malicious process that is hidden from the standard process listing?

A.pstree
B.malfind
C.psxview
D.pslist
AnswerC

psxview cross-references multiple process-listing sources — such as EPROCESS, PspCidTable and CSRSS handles — and highlights discrepancies where a process appears in some lists but not others. That mismatch exposes processes hidden by rootkits, satisfying the requirement to identify a malicious process absent from the standard listing.

Why this answer

The psxview plugin in Volatility cross-references multiple process listing sources (pslist, psscan, thrdproc, pspcid, csrss, session, deskthrd) to detect processes hidden from the standard listing. It is specifically designed to reveal rootkit-hidden processes by comparing discrepancies between these sources.

Exam trap

CAS-005 often tests the difference between Volatility plugins, so candidates confuse malfind (code injection) with psxview (hidden process detection) or pick pslist for hidden processes.

How to eliminate wrong answers

Option A is wrong because pstree displays processes in a tree hierarchy based on the standard process list, so it will not show hidden processes. Option B is wrong because malfind detects injected code or memory regions with suspicious permissions (e.g., RWX), which is useful for malware analysis but not specifically for finding hidden processes. Option D is wrong because pslist only shows processes from the active process list, which is exactly what rootkits hide from.

37
MCQhard

A security architect is designing a network for a hospital that must keep its electronic health record (EHR) servers completely isolated from the internet while still allowing a small group of vendors to perform remote maintenance. The vendors use laptops that are not managed by the hospital. The architect proposes a jump host architecture. Which of the following designs best satisfies the requirement while minimizing risk?

A.Publish the EHR servers through a reverse proxy with client certificate authentication, and let vendors connect directly to the EHR web interface without a jump host.
B.Deploy a hardened jump host in a screened subnet, require vendor laptops to connect through a VPN with MFA, and then RDP to the EHR servers from the jump host after session recording is enabled.
C.Deploy a jump host directly on the same VLAN as the EHR servers, allow vendors to connect to it over RDP from the internet after authenticating with a local account, and disable session logging to protect vendor privacy.
D.Create a site-to-site IPsec tunnel from each vendor's office to the EHR VLAN, and allow the vendors to use their own remote administration tools directly against the EHR servers.
AnswerB

This design places the jump host in a screened subnet so it is reachable from the internet, but the EHR servers remain on an isolated internal segment. Requiring VPN with MFA authenticates the unmanaged vendor laptops, and RDP from the jump host provides a controlled, recorded session. Session recording gives the hospital an audit trail of every vendor action, which is essential for compliance and incident response.

Why this answer

The correct design uses a jump host in a screened subnet, VPN with MFA, and RDP with session recording. This combination isolates the EHR servers, authenticates the unmanaged vendor laptops, and provides an auditable path for maintenance. The other options either place the jump host on the protected VLAN, expose RDP directly, or use a reverse proxy that does not support direct server maintenance, all of which weaken isolation or control.

Exam trap

The trap here is assuming that any remote access method, such as a VPN or reverse proxy, provides the same isolation and auditability as a properly placed jump host with session recording.

38
MCQmedium

A threat hunter wants to identify potential lateral movement within the network. Which data source is LEAST useful for this purpose?

A.Windows Event ID 4624 (Logon) from domain controllers
B.Windows Event ID 4648 (Logon with explicit credentials)
C.Windows Event ID 5140 (File share accessed)
D.DNS query logs
AnswerD

DNS query logs record name resolution, revealing beaconing and domain generation algorithm activity, but they do not capture authentication events, SMB sessions or remote service execution that constitute host-to-host lateral movement. Compared with Windows event logs, EDR telemetry and network flow data, DNS is the least useful source here.

Why this answer

DNS query logs are the least useful data source for identifying lateral movement because they primarily reveal domain name resolution activity, which may indicate command-and-control or data exfiltration but do not directly show authentication or file-share access between internal hosts. Lateral movement is best detected through authentication events (Event ID 4624), explicit credential use (Event ID 4648), and file share access (Event ID 5140).

Exam trap

CAS-005 often tests the distinction between data sources that directly show lateral movement (authentication and file access events) and those that show related but indirect activity (DNS queries), so candidates who overvalue DNS logs for lateral movement pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because Windows Event ID 4624 (Logon) from domain controllers is highly useful for detecting lateral movement, as it records successful logon attempts that may indicate an attacker moving between hosts. Option B is wrong because Windows Event ID 4648 (Logon with explicit credentials) is useful for detecting lateral movement, as it captures attempts to use explicit credentials, often seen in pass-the-hash or remote execution. Option C is wrong because Windows Event ID 5140 (File share accessed) is useful for detecting lateral movement, as it shows access to network shares that may indicate an attacker enumerating or accessing remote resources.

39
MCQmedium

A security engineer is designing a system that must protect data at rest on a database server. The organization requires that the encryption keys never leave a hardware module and that the module be resistant to physical tampering. The engineer deploys a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. Which of the following BEST describes the security property provided by this validation level?

A.It provides zeroization of keys when the module is powered down, but does not require any authentication for administrative access.
B.It provides tamper-evident physical mechanisms and identity-based authentication to access cryptographic keys.
C.It provides the highest level of physical security with environmental failure protection and formal method verification.
D.It provides a software-only cryptographic module that can be deployed on any commodity server without hardware dependencies.
AnswerB

FIPS 140-2 Level 3 requires tamper-evident mechanisms such as epoxy encapsulation or tamper-detection circuitry that zeroizes keys upon intrusion, and it mandates identity-based authentication for all operators accessing the module. This directly meets the requirement that keys never leave the hardware and the module resists physical tampering. Level 3 is the correct validation level for this scenario because it adds physical security and identity-based authentication beyond Level 2's role-based authentication.

Why this answer

FIPS 140-2 Level 3 validation requires tamper-evident physical mechanisms and identity-based authentication, ensuring that keys remain within a hardened hardware boundary and that only authenticated operators can access them. This matches the stated requirements of keys never leaving the module and resistance to physical tampering. Levels 1 and 2 lack these physical protections, while Level 4 adds environmental protections beyond what is needed here.

Exam trap

The trap here is assuming that any HSM automatically provides tamper resistance, when the actual validation level determines the specific physical and authentication protections.

40
Multi-Selectmedium

An organization is implementing a DevSecOps pipeline. Which of the following are essential security controls to include? (Select TWO.)

Select 2 answers
A.Implement SAST in the build phase
B.Conduct annual penetration testing
C.Perform DAST in the staging environment
D.Use network segmentation for production
E.Disable security scanning to speed up deployments
AnswersA, C

Why this answer

SAST (Static Application Security Testing) is essential in the build phase because it analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. Integrating SAST early in the DevSecOps pipeline allows developers to identify and remediate flaws like SQL injection, buffer overflows, or cross-site scripting before the code is compiled and deployed, aligning with the 'shift left' security principle.

Exam trap

The CAS-004 exam often tests the distinction between continuous pipeline-integrated controls (SAST, DAST) and traditional periodic or infrastructure-level controls (annual pen tests, network segmentation), expecting candidates to recognize that only the former are essential within a DevSecOps pipeline.

Why the other options are wrong

B

Annual testing is not frequent enough for a DevSecOps pipeline, which requires continuous testing.

D

Network segmentation is a security control but not specific to the DevSecOps pipeline; it is an operational security measure.

E

Disabling security scanning would defeat the purpose of DevSecOps.

41
Multi-Selectmedium

Which TWO of the following are considered secure design principles for cryptographic systems?

Select 2 answers
A.Implement custom encryption algorithms designed in-house
B.Use the same key for encryption and authentication to reduce complexity
C.Use well-vetted, standard cryptographic algorithms
D.Rely on secrecy of the algorithm for security
E.Generate cryptographic keys using a cryptographically secure random number generator
AnswersC, E

Standard, well-vetted algorithms such as AES and SHA-2 have endured extensive public cryptanalysis, so their weaknesses are known and bounded. Rolling proprietary ciphers hides flaws that attackers may exploit, violating the secure design principle that cryptographic strength must not depend on algorithm secrecy.

Why this answer

Option C is correct because secure cryptographic design requires using well-vetted, standard algorithms such as AES, RSA, or SHA-256, which have undergone extensive public scrutiny and peer review, ensuring their resistance to known attacks. Option E is correct because cryptographic keys must be generated using a cryptographically secure random number generator (CSPRNG), such as /dev/urandom or a hardware security module, to ensure sufficient entropy and unpredictability, preventing attackers from guessing or reproducing keys. Option A is incorrect because custom, in-house encryption algorithms are not peer-reviewed and often contain subtle vulnerabilities, violating the principle of using proven standards.

Option B is incorrect because reusing the same key for both encryption and authentication is cryptographically unsafe, as it can enable cross-protocol attacks and key-recovery attacks; secure systems use separate keys for distinct purposes. Option D is incorrect because relying on algorithm secrecy (security through obscurity) is a flawed principle; secure systems should remain secure even if the algorithm is publicly known, with security resting on the secrecy of the key.

Exam trap

CompTIA often tests the misconception that 'custom algorithms' or 'security through obscurity' can be acceptable in secure design, when in fact they are explicitly rejected in favor of open, peer-reviewed standards and key separation.

42
MCQmedium

A security engineer is designing a secure hybrid cloud connection between an on-premises data center and AWS. Which service provides a dedicated, private network connection that bypasses the public internet?

A.Site-to-Site VPN
B.Transit Gateway
C.Direct Connect
D.VPC Peering
AnswerC

AWS Direct Connect provisions a dedicated 1 Gbps or 10 Gbps fibre cross-connect from your on-premises data centre to an AWS Direct Connect location, carrying traffic over private circuits rather than the public internet. This satisfies the stem's requirement for a private connection that bypasses internet routing entirely, unlike site-to-site VPN, which still traverses the public internet.

Why this answer

AWS Direct Connect provides a dedicated, private physical network connection from an on-premises data center to AWS, bypassing the public internet entirely. It is provisioned through a Direct Connect location or partner and offers consistent latency and higher bandwidth than internet-based options. This is the only option that guarantees a private, non-internet path by design.

Exam trap

The trap is assuming Site-to-Site VPN is 'private' because it is encrypted — candidates forget that IPsec VPN still traverses the public internet, whereas Direct Connect is the only option that physically bypasses it.

How to eliminate wrong answers

Option A is wrong because Site-to-Site VPN tunnels run over the public internet (IPsec over the internet), so they do not bypass it, even though traffic is encrypted. Option B is wrong because Transit Gateway is a regional hub for connecting VPCs, VPNs, and Direct Connect attachments — it is a routing construct, not a private circuit to on-premises. Option D is wrong because VPC Peering connects two VPCs within AWS (or across regions) and has nothing to do with on-premises connectivity.

43
MCQhard

A security analyst is investigating a potential data exfiltration incident. The analyst has a packet capture (PCAP) file from the network segment where the suspected exfiltration occurred. The analyst wants to extract files that were transferred over HTTP and analyze their contents. Which of the following tools should the analyst use to achieve this?

A.tcpdump
B.Wireshark
C.Nmap
D.Metasploit
AnswerB

Wireshark can open PCAP files, reassemble TCP streams, and export objects from HTTP, SMB, and other protocols. Its 'Export Objects' feature allows the analyst to extract files transferred over HTTP, which can then be analyzed. This directly meets the requirement of extracting files from the PCAP for further inspection.

Why this answer

The analyst needs to extract files from a PCAP, specifically from HTTP transfers. Wireshark's 'Export Objects' feature can reassemble and save files from HTTP, SMB, and other protocols. tcpdump is limited to packet capture and display without file extraction. Nmap and Metasploit are not designed for PCAP analysis.

Thus, Wireshark is the correct tool.

Exam trap

The trap here is confusing packet capture tools like tcpdump with analysis tools like Wireshark, assuming tcpdump can extract files.

44
Multi-Selectmedium

A company is adopting container security best practices. Which TWO actions should be implemented to reduce the attack surface of container images? (Select TWO.)

Select 2 answers
A.Set the container filesystem as read-only where possible.
B.Use signed images and verify signatures before deployment.
C.Disable vulnerability scanning to optimize build time.
D.Store secrets in environment variables.
E.Run containers with the root user to simplify permissions.
AnswersA, B

A read-only root filesystem blocks runtime writes to the container's image layers, so an attacker cannot drop malware, alter binaries or persist changes after compromise. This directly reduces the image's exploitable attack surface, satisfying the stem's requirement to harden container images against post-deployment modification.

Why this answer

Option A is correct because mounting the container filesystem as read-only (e.g., via the Docker `--read-only` flag or Kubernetes `securityContext.readOnlyRootFilesystem: true`) prevents an attacker who compromises the container from writing malicious files, modifying binaries, or persisting malware, thereby shrinking the writable attack surface. Option B is correct because using signed images and verifying signatures before deployment (e.g., with Docker Content Trust, Notary, or Sigstore/Cosign) ensures image integrity and provenance, blocking tampered or untrusted images from entering the environment and thus reducing supply-chain attack surface. Option C is wrong because disabling vulnerability scanning removes a key control for detecting known CVEs in image layers, increasing rather than reducing risk.

Option D is wrong because storing secrets in environment variables exposes them via process listings, `docker inspect`, and logs; secrets should instead be mounted from a secrets manager or vault. Option E is wrong because running containers as root violates least privilege and expands the impact of a compromise; containers should run as a non-root user.

Exam trap

The trap here is that candidates may think disabling vulnerability scanning speeds up builds (C) without realizing it directly increases risk, or they may mistakenly believe environment variables are a secure way to handle secrets (D) when they are actually exposed in process listings and logs.

45
MCQmedium

A security engineer is configuring a web application firewall (WAF) to protect against injection attacks. The application uses a relational database and reflects user input in HTML pages. The engineer must choose a WAF rule set that provides the BEST protection with minimal false positives. Which approach should the engineer take?

A.Deploy the WAF in learning mode to baseline normal traffic, then enable targeted rules for SQL injection and XSS with virtual patching for known vulnerabilities.
B.Create custom regular expression rules that block any request containing single quotes, double quotes, or angle brackets.
C.Enable the WAF's generic SQL injection and cross-site scripting (XSS) rules in blocking mode with a default action of deny.
D.Rely solely on the database's parameterized queries and disable all WAF injection rules to avoid false positives.
AnswerA

Learning mode establishes a baseline of legitimate traffic, allowing the engineer to tune rules and reduce false positives. Targeted rules for SQL injection and XSS address the specific threats, and virtual patching protects against known vulnerabilities until code fixes are deployed. This approach balances protection with operational stability.

Why this answer

The best approach is to use learning mode to understand normal traffic, then enable targeted SQL injection and XSS rules along with virtual patching for known vulnerabilities. This minimizes false positives while providing strong protection. Generic blocking rules, overly broad regex, or disabling WAF rules entirely either cause operational issues or reduce defense-in-depth.

Exam trap

The trap here is assuming that the most aggressive blocking configuration always provides the best protection, when in practice tuning and targeted rules are needed to avoid false positives.

46
MCQhard

A security architect is designing a system that must detect tampering with archived audit logs even if an attacker later gains administrative access to the log storage. The logs must remain verifiable for seven years without exposing their contents to the storage provider. Which design BEST meets these requirements?

A.Encrypt each log file with a symmetric key stored alongside the files and rely on file permissions to prevent modification.
B.Upload plaintext logs to object storage with versioning enabled and enable a write-once retention lock on the bucket.
C.Replicate logs to a second region and compare file checksums between regions during quarterly audits.
D.Compute a hash chain over log entries, sign each checkpoint with a private key held in an offline hardware security module, and encrypt logs with keys the provider cannot access.
AnswerD

A hash chain makes any alteration detectable because it breaks subsequent links, while offline hardware security module signing prevents an attacker with storage access from forging new checkpoints. Encrypting with keys unavailable to the provider keeps contents confidential, satisfying all stated requirements simultaneously.

Why this answer

Tamper-evident archival requires cryptographic binding of entries plus signatures produced with a key the attacker cannot reach, combined with encryption whose keys the storage provider does not hold. Hash chains detect alteration, offline hardware security module signing prevents forgery of new checkpoints, and provider-inaccessible keys preserve confidentiality across the retention period.

Exam trap

The trap here is assuming immutability features such as object locks or versioning provide tamper evidence, when they only restrict deletion and overwrite.

47
Multi-Selectmedium

A security engineer is hardening a Linux bastion host that provides administrative access to production servers. The organization requires that all administrative sessions be cryptographically bound to a hardware-backed credential and that session recordings be tamper-evident. Which TWO controls BEST satisfy these requirements? (Choose two.)

Select 2 answers
A.Enable PasswordAuthentication and enforce a 20-character complexity policy with quarterly rotation.
B.Configure sshd to permit only keyboard-interactive authentication with one-time passwords delivered by SMS.
C.Deploy a session recording solution that writes audit logs to a remote syslog server protected by TLS and stores a hash chain of each session.
D.Configure sshd with PubkeyAuthentication and require FIDO2-backed SSH keys using sk-ssh-ed25519 public keys.
E.Store session recordings locally on the bastion host in a directory writable only by root, and rely on file permissions for integrity.
AnswersC, D

Recording administrative sessions and protecting the log stream with TLS plus a hash chain makes the recordings tamper-evident: any modification breaks the chain and is detectable. Remote storage prevents a local attacker from altering or deleting recordings on the bastion host. This directly satisfies the tamper-evident session recording requirement while complementing hardware-backed authentication.

Why this answer

Hardware-backed authentication and tamper-evident recording are distinct requirements that need complementary controls. FIDO2-backed sk-ssh-ed25519 keys bind administrative sessions to a physical authenticator, while remote TLS-protected logging with a hash chain ensures session recordings cannot be altered undetectably. Together they satisfy both the credential-binding and recording-integrity objectives without relying on weaker password or SMS mechanisms.

Exam trap

The trap here is treating strong password policy or SMS one-time passwords as equivalent to hardware-backed authentication, and treating root-only file permissions as equivalent to cryptographic tamper evidence.

48
MCQeasy

A company is designing a new multi-tier web application. The security team recommends placing a web application firewall (WAF) in front of the web servers and a network firewall between the web and application tiers. Which security architecture principle does this represent?

A.Defense in depth
B.Separation of duties
C.Least privilege
D.Single point of failure
AnswerA

Layering a WAF at the application edge and a network firewall between tiers applies multiple independent controls, so compromising one layer does not expose the next. This layered approach is the definition of defence in depth.

Why this answer

Defense in depth. This architecture implements multiple, overlapping layers of security controls: a WAF at the application layer (Layer 7) to inspect and filter HTTP/HTTPS traffic for web-specific attacks (e.g., SQL injection, XSS), and a network firewall between the web and application tiers to enforce stateful packet inspection and access control at Layers 3/4. This layered approach ensures that if one control fails or is bypassed, another control still provides protection, embodying the core principle of defense in depth.

Exam trap

The trap here is that candidates often confuse 'defense in depth' with 'separation of duties' because both involve multiple layers, but separation of duties is about human roles and access control, not about stacking network security devices.

How to eliminate wrong answers

Option B (Separation of duties) is wrong because it refers to dividing administrative responsibilities among different individuals to prevent fraud or error, not to placing multiple security controls in a network path. Option C (Least privilege) is wrong because it focuses on granting users or processes only the minimum permissions needed to perform their functions, not on layering security devices. Option D (Single point of failure) is wrong because it describes a lack of redundancy that can cause system downtime, whereas the scenario explicitly adds multiple security layers to avoid a single point of failure, not to create one.

49
MCQmedium

A security analyst is using the MITRE ATT&CK framework to categorize adversary behavior observed in recent incidents. The analyst notes that the adversary used spearphishing with a malicious attachment to gain initial access, then executed a PowerShell script to download additional tools. Which ATT&CK tactic is the PowerShell execution associated with?

A.Defense Evasion
B.Execution
C.Initial Access
D.Command and Control
AnswerB

PowerShell running a script to download tools is adversary-controlled code running on the victim host, which maps to the Execution tactic. Initial access was already achieved via spearphishing; the script's purpose is to execute further payloads, satisfying the stem's requirement to categorise this behaviour.

Why this answer

In MITRE ATT&CK, Execution (TA0002) covers techniques that result in adversary-controlled code running on a local or remote system, including T1059 Command and Scripting Interpreter. PowerShell is explicitly documented under T1059.001, so running a PowerShell script to download tools is classified as Execution. Initial Access describes how the adversary got in (the spearphishing), not what they ran afterward.

Exam trap

The trap is conflating the *initial access vector* (spearphishing) with the *post-compromise action* (PowerShell execution) — candidates see 'spearphishing' in the scenario and reflexively choose Initial Access.

How to eliminate wrong answers

Option A is wrong because Defense Evasion (TA0005) covers hiding artifacts, obfuscation, and disabling security tools — merely running PowerShell is not inherently evasive unless paired with techniques like T1027 or T1562. Option C is wrong because Initial Access (TA0001) refers to the entry vector (spearphishing attachment, T1566.001), which already occurred before the PowerShell step. Option D is wrong because Command and Control (TA0011) describes adversary communication with compromised systems (e.g., C2 channels), not local script execution.

50
MCQmedium

A security engineer is deploying a wireless network for a high-security facility. Which protocol should be used to provide the strongest authentication and encryption for client devices?

A.WEP with 128-bit key
B.WPA2-PSK with AES
C.WPA3-Enterprise with 802.1X
D.WPA3-Personal with SAE
AnswerC

WPA3-Enterprise uses individual credentials and stronger encryption than WPA2.

Why this answer

WPA3-Enterprise with 802.1X is the correct choice because it provides the strongest authentication and encryption for a high-security facility. It uses Simultaneous Authentication of Equals (SAE) for secure key exchange, mandates GCMP-256 encryption, and integrates with 802.1X/EAP for per-user, certificate-based authentication, eliminating shared passphrase vulnerabilities.

Exam trap

A common misconception is that WPA3-Personal with SAE is sufficient for enterprise security, but the trap is that it still uses a shared passphrase and lacks the per-user authentication and centralized control provided by 802.1X, which is critical for high-security environments.

How to eliminate wrong answers

Option A is wrong because WEP with a 128-bit key uses the insecure RC4 stream cipher and static keys, which can be cracked in minutes using tools like aircrack-ng. Option B is wrong because WPA2-PSK with AES relies on a pre-shared key (PSK) that is vulnerable to offline dictionary attacks and lacks per-user authentication, making it unsuitable for a high-security facility. Option D is wrong because WPA3-Personal with SAE, while stronger than WPA2-PSK, still uses a shared passphrase for authentication and does not support 802.1X/EAP for individual user identity and centralized access control.

51
MCQeasy

An organization wants to implement passwordless authentication using FIDO2/WebAuthn. Which of the following best describes the primary security advantage of this approach over traditional password-based authentication?

A.It eliminates the need for multi-factor authentication
B.It prevents phishing by using cryptographic keys bound to the origin
C.It allows users to reuse the same password across services
D.It requires a hardware token for every login
AnswerB

FIDO2/WebAuthn credentials are bound to the relying party's origin, and the authenticator signs a challenge with a private key that never leaves the device. A phishing site on a different origin cannot obtain a valid assertion, eliminating credential replay regardless of password reuse.

Why this answer

FIDO2/WebAuthn uses public-key cryptography where the private key never leaves the authenticator, and the credential is cryptographically bound to the origin (relying party ID) during registration. This origin binding means a phishing site on a different domain cannot trigger the authenticator to produce a valid assertion, because the browser enforces the RP ID match. Even if a user is tricked into visiting a lookalike site, the signature will not validate against the legitimate server's expected origin.

Exam trap

The trap here is conflating 'passwordless' with 'no second factor' — candidates assume removing the password means removing MFA, when FIDO2 actually strengthens authentication by binding cryptographic credentials to the origin, which is the specific anti-phishing property the exam wants you to identify.

How to eliminate wrong answers

Option A is wrong because FIDO2/WebAuthn is itself a form of possession-based authentication and is often combined with a PIN or biometric (which acts as a second factor), so it does not eliminate MFA — it can actually implement it. Option C is wrong because FIDO2 does not involve passwords at all; there is no password to reuse, and reusing credentials across services is precisely the anti-pattern FIDO2 eliminates. Option D is wrong because FIDO2 supports platform authenticators (Windows Hello, Touch ID, Android biometrics) as well as roaming hardware keys, so a dedicated hardware token is not required for every login.

52
MCQmedium

An organization is evaluating a third-party vendor that will have access to its customer database. The vendor provides a SOC 2 Type II report dated six months ago. Which of the following is the BEST next step?

A.Conduct a vendor risk assessment using a security questionnaire
B.Accept the SOC 2 report as sufficient evidence
C.Perform an on-site audit of the vendor
D.Request a new penetration test report from the vendor
AnswerA

A SOC 2 Type II report covers controls over a period, but it is six months old and may not address your specific data flows. A risk assessment using a security questionnaire gathers current, scenario-specific evidence about how the vendor protects your customer database.

Why this answer

Even with a recent SOC 2 Type II report, the organization should still perform its own vendor risk assessment using a security questionnaire to evaluate controls specific to the engagement, scope, and data sensitivity. A SOC 2 report covers the vendor's controls but does not address the organization's specific risk tolerance, contractual requirements, or gaps not in the report's scope. This is the best next step because it validates and contextualizes the report.

Exam trap

CAS-005 often tests the misconception that a SOC 2 report alone satisfies vendor due diligence, when in fact it is an input to—not a replacement for—a risk-based assessment.

How to eliminate wrong answers

Option B is wrong because accepting the SOC 2 report as sufficient evidence ignores the need to map the report's scope and exceptions to the organization's specific requirements and risk appetite. Option C is wrong because an on-site audit is disproportionate and typically reserved for high-risk vendors after a risk assessment identifies gaps; it is not the immediate next step. Option D is wrong because requesting a new penetration test report is not the standard next step and does not replace a risk assessment; pen tests are point-in-time and may not cover the relevant scope.

53
MCQmedium

A security architect is designing a cryptographic system for a government agency that must protect classified data for the next 30 years. The agency is concerned about the threat from quantum computers. Which NIST post-quantum cryptography algorithm is recommended for key encapsulation?

A.ECDH with NIST P-384
B.CRYSTALS-Kyber
C.CRYSTALS-Dilithium
D.RSA-4096
AnswerB

CRYSTALS-Kyber is a lattice-based key encapsulation mechanism selected by NIST for post-quantum standardisation, resisting attacks from both classical and quantum computers. Its Module-LWE hardness underpins the 30-year confidentiality requirement, unlike RSA or ECC, which Shor's algorithm breaks.

Why this answer

CRYSTALS-Kyber is the NIST-selected post-quantum algorithm for key encapsulation (KEM), standardized as FIPS 203 (ML-KEM). It is designed to resist attacks from both classical and quantum computers, making it appropriate for long-lived classified data. CRYSTALS-Dilithium is for digital signatures, not key encapsulation, and the classical algorithms (ECDH, RSA) are vulnerable to Shor's algorithm on a sufficiently powerful quantum computer.

Exam trap

The trap is mixing up the two CRYSTALS algorithms — candidates see 'CRYSTALS' and pick Dilithium, forgetting that Kyber is the KEM and Dilithium is the signature scheme.

How to eliminate wrong answers

Option A is wrong because ECDH with P-384 is a classical elliptic-curve key agreement scheme and is broken by Shor's algorithm on a quantum computer — it offers no post-quantum protection. Option C is wrong because CRYSTALS-Dilithium is NIST's selected post-quantum digital signature algorithm (FIPS 204, ML-DSA), not a key encapsulation mechanism. Option D is wrong because RSA-4096 is a classical public-key algorithm also vulnerable to Shor's algorithm; increasing key size does not defend against quantum attacks.

54
MCQeasy

A security administrator must ensure that log data collected from servers across multiple sites cannot be altered or deleted by an attacker who compromises a single server. Which of the following BEST achieves this?

A.Configure each server to write logs to a local encrypted volume and enable file integrity monitoring on the log directory
B.Increase local log retention to one year and rotate log files daily with compression enabled
C.Enable verbose logging on all servers and store the logs in a database that uses transparent data encryption
D.Forward logs in real time to a centralized logging platform with append-only storage and restricted administrative access
AnswerD

Shipping logs off-host in real time means a compromised server no longer holds the only copy, and append-only storage with tightly restricted administration prevents alteration or deletion. This directly satisfies the requirement that a single compromised server cannot tamper with the collected log data.

Why this answer

Centralizing logs with real-time forwarding removes the single point of failure and append-only storage with restricted access prevents tampering or deletion even if one server is fully compromised. Local encryption, retention changes, and database encryption all leave authoritative copies within reach of the compromised host.

Exam trap

The trap here is assuming that encrypting or retaining logs locally provides tamper resistance, when the attacker on that host controls both the logs and the keys.

55
Multi-Selectmedium

A company is implementing a vendor risk management program. Which THREE of the following should be included in the initial vendor assessment?

Select 3 answers
A.Employee training records
B.Financial stability
C.Security incident history
D.Marketing collateral
E.Business continuity plan
AnswersB, C, E

Essential to assess viability.

Why this answer

Financial stability (B) is a critical initial vendor assessment factor because it evaluates the vendor's ability to remain solvent and support long-term contractual obligations. A financially unstable vendor poses a direct risk to service continuity and may be unable to invest in necessary security controls, leading to potential data breaches or service disruptions.

Exam trap

In CompTIA CASP+, the initial vendor assessment focuses on high-level strategic and financial risks rather than granular operational details. Candidates often mistakenly include items like employee training records or marketing collateral, which are more relevant to ongoing due diligence or contract negotiation phases.

56
Multi-Selectmedium

A security architect is evaluating web application firewall (WAF) features to protect against common attacks. Which TWO of the following attacks can a WAF most effectively prevent?

Select 2 answers
A.Session hijacking
B.Cross-site scripting (XSS)
C.SQL injection
D.Distributed denial-of-service (DDoS)
E.Cross-site request forgery (CSRF)
AnswersB, C

A WAF inspects HTTP request and response payloads, so it can detect and block cross-site scripting by filtering malicious scripts before they reach the application. XSS travels in web traffic, which is exactly the layer a WAF parses and controls.

Why this answer

A WAF is designed to inspect HTTP/HTTPS request and response payloads and apply rule sets (e.g., OWASP ModSecurity Core Rule Set) to block injection-style attacks, so option B (cross-site scripting, XSS) is correct because a WAF can detect and block malicious script payloads such as <script> tags or event handlers in parameters, headers, and bodies. Option C (SQL injection) is also correct because a WAF can match SQL meta-characters and known injection patterns like ' OR 1=1-- or UNION SELECT to stop malicious queries before they reach the database. Option A (session hijacking) is not primarily a WAF function, since it depends on stealing or predicting session tokens and is better mitigated by TLS, HttpOnly/Secure cookies, and token rotation.

Option D (DDoS) is not effectively handled by a WAF alone; volumetric and network-layer floods require scrubbing centers, CDNs, or dedicated DDoS protection. Option E (CSRF) is not reliably prevented by a WAF because it exploits a victim's authenticated browser session, and the proper defenses are anti-CSRF tokens, SameSite cookies, and origin/referer validation.

Exam trap

CAS-005 often tests the scope of WAF protection, and candidates frequently overestimate its ability to stop session hijacking, CSRF, or DDoS, which require different controls.

57
Multi-Selectmedium

A security analyst is conducting a penetration test for a client. The rules of engagement specify that no social engineering is allowed. Which TWO of the following reconnaissance techniques are permitted under these rules?

Select 2 answers
A.Calling the help desk to obtain credentials
B.Scanning the client's external network for open ports
C.Performing DNS enumeration using public records
D.Sending phishing emails to employees
E.Tailgating into the building
AnswersB, C

Scanning external networks for open ports is a technical reconnaissance activity that does not involve deceiving or manipulating people, so it satisfies the rules of engagement prohibiting social engineering. It maps the attack surface through direct network probing rather than human interaction, making it permissible alongside other non-social techniques.

Why this answer

Option B is correct because scanning the client's external network for open ports is a purely technical reconnaissance activity that does not involve deceiving or manipulating people, so it falls outside the prohibition on social engineering. Option C is correct because DNS enumeration using public records relies on openly available registration and name-resolution data (e.g., WHOIS, zone data, public DNS queries) rather than human interaction or deception. Option A is not permitted because calling the help desk to obtain credentials is a pretexting/social-engineering attack that manipulates a person into disclosing sensitive information.

Option D is not permitted because phishing emails are a classic social-engineering technique that deceives employees into revealing data or executing actions. Option E is not permitted because tailgating is a physical social-engineering method that exploits human trust to gain unauthorized building access.

Exam trap

The trap here is conflating 'reconnaissance' with 'social engineering' — candidates may think any information-gathering technique is off-limits, but the RoE only prohibits social engineering, so technical scanning and public DNS enumeration remain permitted.

58
MCQeasy

An analyst needs to automate the extraction of indicators of compromise (IOCs) from log files generated by various systems. Which scripting language is most commonly used for cross-platform log parsing and automation due to its extensive library support?

A.PowerShell
B.Bash
C.JavaScript
D.Python
AnswerD

Python's extensive standard and third-party libraries — such as re, pandas and log parsers — handle heterogeneous log formats across platforms, satisfying the cross-platform parsing and automation requirement. Its broad ecosystem makes it the common choice for IOC extraction scripts without bespoke parsing code.

Why this answer

Python is the correct answer because it is a cross-platform scripting language with extensive standard libraries (e.g., `re` for regex, `json`, `csv`, `logging`) and third-party packages (e.g., `pandas`, `yara-python`, `stix2`) that simplify parsing diverse log formats and automating IOC extraction. Its portability across Windows, Linux, and macOS makes it ideal for environments with heterogeneous systems, unlike platform-specific alternatives.

Exam trap

The trap here is that candidates often choose PowerShell (Option A) because they associate it with Windows log parsing (e.g., Event Logs), forgetting the question explicitly requires cross-platform support and extensive library availability for diverse log formats.

How to eliminate wrong answers

Option A is wrong because PowerShell is tightly integrated with the Windows ecosystem and .NET framework, making it less portable for cross-platform log parsing without additional modules like PowerShell Core, and its syntax is less concise for complex text processing compared to Python. Option B is wrong because Bash is a Unix/Linux shell scripting language that lacks native support for Windows environments without emulation layers like WSL, and its text-processing utilities (e.g., `grep`, `awk`, `sed`) are less robust for structured log parsing than Python's libraries. Option C is wrong because JavaScript is primarily designed for web browser client-side scripting and Node.js server-side applications; it lacks built-in libraries for system-level log file parsing and automation, and its asynchronous model complicates sequential log processing tasks.

59
MCQeasy

An organization needs to ensure that evidence collected during a forensic investigation remains intact and admissible in court. Which process is most critical for maintaining the integrity of digital evidence?

A.Storing evidence in a secure locker
B.Maintaining an unbroken chain of custody
C.Using write-blockers when imaging drives
D.Hashing the evidence with SHA-256
AnswerB

Digital evidence is only admissible if its provenance is provable. An unbroken chain of custody documents every transfer, handler and storage condition from seizure to court, so any tampering or contamination can be ruled out. Hashing proves integrity, but the chain of custody is what satisfies the court's admissibility constraint.

Why this answer

Chain of custody documents every person who handled the evidence, from collection to presentation in court, ensuring that evidence has not been tampered with. This is essential for admissibility.

60
MCQmedium

A company is deploying a web application in a containerized environment. The security team wants to ensure that the application runs with the least privilege necessary. Which of the following is the BEST approach to achieve this?

A.Run the container as root and use a restrictive seccomp profile
B.Run the container with a non-root user and drop all capabilities
C.Run the container as root but use a read-only filesystem
D.Run the container with the --privileged flag and a custom AppArmor profile
AnswerB

Why this answer

Running a container with a non-root user and dropping all capabilities enforces the principle of least privilege. By default, containers run with a limited set of capabilities, but explicitly dropping all capabilities and using a non-root user ensures that even if the application is compromised, an attacker cannot escalate privileges or perform privileged operations. This aligns with container security best practices, such as those outlined in the Docker security documentation and the CIS Docker Benchmark.

Exam trap

The CAS-004 exam often tests the misconception that root in a container is safe because of namespace isolation, but the trap here is that root inside a container still has dangerous capabilities that can be exploited if the container is compromised, so the best approach is to avoid root entirely and drop all capabilities.

Why the other options are wrong

A

Running as root still gives elevated privileges; seccomp alone does not enforce user-level least privilege.

C

Read-only filesystem does not prevent root-level process attacks; the container still runs as root.

D

--privileged gives the container nearly all host capabilities, violating least privilege.

61
MCQmedium

During a digital forensics investigation of a compromised Linux server, the investigator needs to preserve the evidence in a forensically sound manner. The server is still running. Which of the following should the investigator do first?

A.Pull the power cord to preserve the disk state
B.Create a forensic image of the hard drive using dd over a network connection
C.Run the 'history' command to see recent user commands
D.Capture the contents of RAM using a tool like LiME or fmem
AnswerD

RAM contents are volatile and lost on shutdown, so capturing memory with LiME or fmem first preserves evidence that would otherwise vanish. Order of volatility demands memory acquisition before disk imaging on a live system.

Why this answer

On a live system, volatile data — RAM contents, running processes, network connections, and encryption keys — is lost the moment power is cut or the system is rebooted. Order of volatility (RFC 3227) dictates capturing RAM first using tools like LiME or fmem before touching the disk. This preserves evidence that may never exist on disk, such as in-memory malware or active sessions.

Exam trap

The trap is thinking 'preserve the disk first' — but on a live system, order of volatility means RAM must be captured before anything else, and pulling the plug is the worst possible action.

How to eliminate wrong answers

Option A is wrong because pulling the power cord destroys volatile evidence (RAM, caches, running processes) and can corrupt the filesystem, violating order of volatility. Option B is wrong because imaging the disk over the network before capturing RAM loses volatile data and also alters the system state by running dd. Option C is wrong because running 'history' modifies the shell environment and only shows the current user's shell history — it's not a first-step evidence-preservation action and can overwrite or miss data.

62
MCQmedium

A security engineer is configuring a wireless network for a corporate office. The network must support 802.1X authentication with EAP-TLS, and the engineer wants to ensure that only devices with valid certificates issued by the corporate CA can connect. Which of the following should the engineer configure on the RADIUS server to enforce this requirement?

A.Configure EAP-TLS and validate client certificates against the corporate CA.
B.Enable PEAP with MSCHAPv2 and require domain credentials.
C.Deploy EAP-FAST with PACs and require machine authentication.
D.Implement EAP-TTLS with a tunneled authentication protocol and check user group membership.
AnswerA

EAP-TLS requires both the server and client to present certificates. By configuring the RADIUS server to trust only the corporate CA and to require client certificates, the engineer ensures that only devices with valid certificates issued by that CA can authenticate. This meets the requirement exactly and is considered the most secure EAP method.

Why this answer

EAP-TLS is the only method that mandates client-side certificates, allowing the RADIUS server to validate them against the corporate CA. This ensures that only devices with certificates from that CA can connect. The other methods either rely on user credentials, tunneled legacy authentication, or PACs, none of which enforce device certificate validation.

Exam trap

The trap here is assuming that any 802.1X method with strong encryption, like PEAP or EAP-TTLS, can enforce device certificate authentication, when only EAP-TLS requires client certificates.

63
Multi-Selectmedium

Which two of the following are effective mitigations against XML External Entity (XXE) injection attacks? (Select the two best options.)

Select 2 answers
A.Disable Document Type Definition (DTD) processing in the XML parser
B.Use a blacklist to filter out dangerous XML tags
C.Validate all XML input against a schema
D.Use a JSON or other less complex data format instead of XML
AnswersA, D

Why this answer

XXE attacks exploit the XML parser's ability to process external entities defined in a DTD. By disabling DTD processing entirely, the parser cannot resolve or fetch external resources, which neutralizes the primary vector for XXE injection. This is a standard security hardening step for XML parsers like libxml2, Xerces, or .NET's XmlReader, often achieved by setting properties such as `LIBXML_NOENT` to false or `XmlReaderSettings.DtdProcessing` to `Prohibit`.

Exam trap

CompTIA often tests the misconception that input validation or schema validation alone can prevent injection attacks, but the trap here is that XXE exploits parser-level features (DTD processing) that occur before any schema validation or content filtering takes place.

Why the other options are wrong

B

Blacklists are easily bypassed; disabling DTD is more robust.

C

Schema validation does not prevent XXE if DTDs are still enabled.

64
MCQmedium

An organization is required to retain logs for seven years per regulatory requirement. Which of the following should be considered to ensure the integrity of these logs?

A.Write-once, read-many (WORM) storage
B.Hashing each log entry
C.Encryption of the logs
D.Compression to reduce storage space
AnswerA

WORM storage prevents modification or deletion of objects for a defined retention period, so logs cannot be altered or tampered with during the seven-year regulatory window. This directly satisfies the stem's integrity requirement, which standard mutable blob or file storage cannot guarantee.

Why this answer

Write-once, read-many (WORM) storage ensures that once log data is written, it cannot be altered, overwritten, or deleted for the retention period. This immutability directly satisfies the regulatory requirement for log integrity over seven years, as it prevents both accidental modification and malicious tampering. WORM can be implemented via optical media, magnetic tape with WORM firmware, or object storage with retention policies.

Exam trap

A common pitfall is confusing integrity (preventing unauthorized modification) with confidentiality (preventing unauthorized access), leading candidates to mistakenly choose encryption when the question specifically asks about integrity.

How to eliminate wrong answers

Option B is wrong because hashing each log entry provides integrity verification (detecting changes) but does not prevent modification or deletion of the logs themselves; an attacker could alter a log entry and recompute its hash, rendering the hash useless without a secure chain. Option C is wrong because encryption protects confidentiality (prevents unauthorized reading) but does not prevent modification or deletion of logs; encrypted data can still be altered or truncated. Option D is wrong because compression reduces storage space but has no effect on integrity; compressed logs can still be modified, and compression may even introduce corruption risks if not handled properly.

65
Matchingmedium

Match each authentication protocol or method to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses tickets and symmetric key cryptography

XML-based federated identity protocol

Authorization framework for delegated access

AAA protocol for network access

Directory access protocol for authentication

Why these pairings

Correct matches: Kerberos uses tickets and symmetric keys for authentication; SAML uses XML assertions for single sign-on; OAuth provides delegated authorization via tokens. Common confusions include mixing cryptographic methods and confusing authorization with authentication.

66
Multi-Selectmedium

A security team is implementing a threat intelligence program and wants to consume intelligence from various sources. Which TWO of the following are commonly used threat intelligence feeds or sharing mechanisms? (Select TWO.)

Select 2 answers
A.DNS
B.SMTP
C.HTTP
D.ISACs
E.STIX/TAXII
AnswersD, E

ISACs are sector-specific non-profit bodies through which member organisations share threat indicators, incidents and mitigation guidance. Consuming their feeds satisfies the stem's requirement for a commonly used threat intelligence sharing mechanism, alongside ISAO and CERT channels.

Why this answer

ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that collect, analyze, and share threat intelligence among their members, making them a standard threat intelligence sharing mechanism. STIX/TAXII is also correct: STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is the application-layer protocol used to exchange that STIX data over HTTPS. By contrast, DNS, SMTP, and HTTP are general-purpose network protocols used for name resolution, email transport, and web communication respectively; while threat intelligence may traverse them, they are not themselves threat intelligence feeds or sharing mechanisms.

Exam trap

The trap is picking generic protocols (DNS, HTTP, SMTP) because they're used to transport threat intel — but the question asks for sharing mechanisms/feeds, which are ISACs and STIX/TAXII.

67
MCQmedium

A security analyst is reviewing threat intelligence feeds and notices that a known Advanced Persistent Threat (APT) group has been using a specific technique to move laterally within networks. The analyst wants to map this technique to the MITRE ATT&CK framework. Which resource would the analyst use to find the corresponding ATT&CK technique ID?

A.MITRE ATT&CK Navigator or website
B.NIST SP 800-61
C.STIX/TAXII feeds
D.CVE database
AnswerA

The MITRE ATT&CK Navigator and website host the full technique matrix with IDs, letting the analyst map the observed lateral movement technique to its corresponding identifier. It is the authoritative source for ATT&CK technique IDs, satisfying the stem's mapping requirement.

Why this answer

The MITRE ATT&CK Navigator and the official ATT&CK website are the authoritative resources for mapping adversary techniques to ATT&CK technique IDs (e.g., T1021 for Remote Services). The analyst would search the technique name or tactic (Lateral Movement) to find the corresponding ID and details.

Exam trap

The trap is confusing ATT&CK (adversary TTPs) with CVE (vulnerabilities) or NIST SP 800-61 (IR process) — candidates must recognize that technique IDs come only from the ATT&CK framework.

How to eliminate wrong answers

Option B is wrong because NIST SP 800-61 is the incident handling guide — it defines IR lifecycle phases, not ATT&CK technique mappings. Option C is wrong because STIX/TAXII is a transport/format for threat intel, not a mapping database for ATT&CK technique IDs. Option D is wrong because the CVE database catalogs software vulnerabilities, not adversary tactics, techniques, and procedures (TTPs).

68
MCQmedium

A security analyst is investigating a phishing campaign targeting the organization. The threat intelligence team has provided indicators such as email subject lines, sender domains, and attachment hashes. However, the analyst notices that these IOCs change rapidly and are only effective for a short period. Which type of threat intelligence would provide more durable and actionable information for defending against this campaign?

A.STIX/TAXII feeds
B.IoC-based threat intelligence
C.TTP-based threat intelligence
D.Strategic threat intelligence
AnswerC

TTP-based intelligence describes adversary behaviours and tradecraft, which change far more slowly than email subjects, sender domains or attachment hashes. This satisfies the stem's constraint that rapidly shifting IOCs give only short-lived value, providing durable detection for the phishing campaign.

Why this answer

TTP-based threat intelligence focuses on the adversary's tactics, techniques, and procedures — the behavioral patterns behind an attack — rather than volatile artifacts like subject lines or hashes. Because TTPs describe how attackers operate (e.g., MITRE ATT&CK techniques such as spearphishing attachment T1566.001), they remain relevant even when IOCs rotate. This makes them far more durable and actionable for building detections and defenses against an ongoing campaign.

Exam trap

CAS-005 often tests the distinction between volatile indicators (hashes, domains, subject lines) and durable behavioral intelligence (TTPs), so candidates who equate 'threat intelligence' with 'IOC feeds' pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because STIX/TAXII are merely standards and transport protocols for sharing threat intelligence (STIX for structured representation, TAXII for exchange) — they are not a category of intelligence and do not inherently provide durable behavioral insight. Option B is wrong because IoC-based intelligence is exactly what the analyst already has, and by definition it is short-lived and easily evaded by attackers who rotate domains, hashes, and subject lines. Option D is wrong because strategic threat intelligence addresses long-term, high-level trends and risk posture for executives, not the operational detection detail needed to defend against a specific active phishing campaign.

69
MCQhard

A financial services company is designing a secure multi-tenant SaaS application hosted on AWS. The security architect must ensure that each tenant's data is isolated and that encryption keys are unique per tenant, while allowing the company to manage keys centrally. Which AWS service should the architect use to meet these requirements?

A.AWS Certificate Manager (ACM) with a wildcard certificate per tenant.
B.AWS CloudHSM with a single cluster shared across all tenants.
C.AWS Key Management Service (KMS) with customer managed keys (CMKs) and encryption context per tenant.
D.AWS Secrets Manager with automatic rotation for each tenant's database credentials.
AnswerC

AWS KMS customer managed keys allow the company to create and manage unique keys per tenant, and encryption context can enforce tenant-specific authorization. This provides centralized key management with per-tenant cryptographic isolation, meeting the requirement for unique encryption keys and central control.

Why this answer

AWS KMS with customer managed keys allows the architect to create a unique key for each tenant and use encryption context to enforce that only the intended tenant can decrypt its data. This centralizes key management while providing cryptographic isolation, satisfying both the per-tenant key requirement and the need for central administration.

Exam trap

The trap here is confusing data-in-transit certificate management or secret storage with encryption key management for data at rest, which requires a dedicated key management service such as KMS.

70
MCQeasy

A vulnerability scanner reports a critical vulnerability on a critical server with a CVSS v3.1 base score of 9.8. The server cannot be patched immediately due to vendor constraints. Which of the following should the security team implement as a compensating control?

A.Disable the server until a patch is available
B.Increase monitoring of the server
C.Isolate the server on a separate network segment with strict firewall rules
D.Apply a workaround provided by the vendor
AnswerC

Network isolation with strict firewall rules is a compensating control: it blocks the exploit paths a CVSS 9.8 vulnerability would use, reducing exposure without patching. This satisfies the vendor constraint preventing immediate remediation while the server keeps operating.

Why this answer

When a patch cannot be applied, compensating controls such as network segmentation, firewall rules, or WAF can reduce risk. Network isolation is a common compensating control.

71
MCQmedium

A security architect is designing a public key infrastructure (PKI). Which component is responsible for issuing and revoking certificates?

A.Validation Authority
B.Certificate Repository
C.Registration Authority
D.Certificate Authority
AnswerD

The Certificate Authority is the trusted entity that signs, issues and publishes revocation status for certificates within the PKI hierarchy. It satisfies the stem's requirement by performing both lifecycle functions, using CRLs or OCSP to distribute revocation data to relying parties.

Why this answer

The Certificate Authority (CA) is the trusted entity that issues digital certificates and maintains Certificate Revocation Lists (CRLs) or supports OCSP for revocation.

72
MCQeasy

A company is implementing a new cloud-based SaaS application and needs to ensure compliance with GDPR. The security team is tasked with updating the data protection impact assessment (DPIA). Which of the following should the team prioritize?

A.Assessing the types of personal data processed and the risks to data subjects
B.Defining data retention schedules for all data types
C.Conducting a vulnerability scan of the SaaS application
D.Reviewing the cloud provider's SLA for uptime guarantees
AnswerA

Assessing personal data categories and risks to data subjects directly satisfies GDPR's DPIA requirement under Article 35, which mandates identifying processing purposes, necessity, and risks to rights and freedoms. This precedes technical controls, ensuring the SaaS deployment's lawful basis and mitigation measures align with regulatory obligations before implementation.

Why this answer

Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing personal data that is likely to result in high risk to individuals. The core requirement is to systematically assess the types of personal data being processed, the necessity and proportionality of the processing, and the risks to data subjects' rights and freedoms. This directly aligns with option A, as the DPIA must identify and mitigate privacy risks before the SaaS application goes live.

Exam trap

The trap here is that candidates confuse a DPIA with a security assessment (like a vulnerability scan or SLA review), but the DPIA is specifically a privacy risk assessment mandated by GDPR Article 35, not a general security or operational review.

How to eliminate wrong answers

Option B is wrong because defining data retention schedules is a separate GDPR compliance activity (Article 5(1)(e)) that occurs after the DPIA, not a priority for the DPIA itself; the DPIA focuses on risk assessment, not retention policies. Option C is wrong because conducting a vulnerability scan addresses technical security controls (Article 32), but a DPIA is a broader privacy risk assessment that evaluates the necessity, proportionality, and impact on data subjects, not just security vulnerabilities. Option D is wrong because reviewing the cloud provider's SLA for uptime guarantees relates to business continuity and availability, not to the GDPR-mandated assessment of risks to data subjects' privacy rights.

73
MCQeasy

Which of the following is a secure method for storing secrets (e.g., API keys, passwords) in a cloud-native application?

A.Encode secrets in base64 in configuration files
B.Store secrets in environment variables
C.Use a secrets management service
D.Hardcode secrets in the source code
AnswerC

A dedicated secrets management service stores credentials encrypted, controls access through fine-grained policies and audit logging, and issues short-lived dynamic secrets. Embedding keys in code, environment variables or config files exposes them to leaks, so centralised vaulting satisfies the secure-storage constraint.

Why this answer

A dedicated secrets management service (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) provides encryption at rest and in transit, automatic rotation, fine-grained access control via IAM policies, and audit logging. This prevents secrets from being exposed in configuration files, environment dumps, or version control, which is essential for cloud-native applications that must adhere to the principle of least privilege and compliance standards like SOC 2 or PCI DSS.

Exam trap

CompTIA often tests the misconception that base64 encoding or environment variables are 'secure enough' because they hide the secret from casual view, but the trap is that neither provides encryption, access control, or rotation, which are required for secure secret storage in cloud-native applications.

Why the other options are wrong

A

Base64 is not encryption; it is easily reversible and does not protect secrets.

B

Environment variables can be exposed via process listings, logs, or debug interfaces; they are not encrypted.

D

Hardcoding secrets is insecure as they can be read from version control or decompiled code.

74
MCQeasy

An organization wants to implement a solution that ensures data cannot be read if a storage device is physically stolen. Which encryption approach BEST meets this requirement?

A.Transport Layer Security (TLS) for network traffic
B.File-level encryption on sensitive documents
C.Database column-level encryption for stored data
D.Full disk encryption (FDE) on the storage device
AnswerD

Encrypts all data on the device, protecting against physical theft.

Why this answer

Full disk encryption (FDE) encrypts the entire storage device at the block level, including the operating system, applications, and all data. If the device is physically stolen, the data remains unreadable without the decryption key or passphrase, as the encryption is transparent and covers all sectors of the drive. This directly addresses the requirement of protecting data at rest on a stolen storage device.

Exam trap

The CAS-004 exam often tests the distinction between encryption of data in transit (TLS) and encryption of data at rest (FDE), leading candidates to mistakenly choose a network encryption solution when the question explicitly involves a stolen storage device.

How to eliminate wrong answers

Option A is wrong because Transport Layer Security (TLS) encrypts data in transit over a network, not data at rest on a storage device; it does not protect against physical theft of the device. Option B is wrong because file-level encryption only encrypts individual files or folders, leaving metadata, temporary files, and the operating system unencrypted, which can expose sensitive data if the device is stolen. Option C is wrong because database column-level encryption protects specific columns within a database, but it does not encrypt the underlying storage device, leaving other data (e.g., logs, swap files, or the database engine itself) exposed upon physical theft.

75
MCQmedium

A company uses an API gateway to manage their microservices. Which security control should the gateway enforce to prevent abuse from excessive API calls?

A.JWT verification
B.Input validation
C.Rate limiting
D.OAuth 2.0
AnswerC

Rate limiting caps the number of requests a client may make within a defined window, throttling or blocking once the threshold is exceeded. This directly prevents abuse from excessive API calls, the specific threat named in the stem, while preserving availability for legitimate consumers.

Why this answer

Rate limiting is the API gateway control that caps the number of requests a client can make within a defined time window (e.g., 100 requests/minute), directly preventing abuse from excessive API calls, brute-force attempts, and denial-of-service. It is enforced at the gateway before requests reach backend microservices.

Exam trap

The trap is conflating authentication/authorization with abuse prevention — candidates pick JWT or OAuth because they sound security-related, but only rate limiting addresses request volume.

How to eliminate wrong answers

Option A is wrong because JWT verification authenticates the caller's identity and integrity of the token, but a valid token can still be used to flood the API — authentication does not equal throttling. Option B is wrong because input validation checks the shape and content of request payloads to prevent injection attacks, not the volume of requests. Option D is wrong because OAuth 2.0 is an authorization framework that grants scoped access tokens; it controls what a client can do, not how often they can do it.

Page 1 of 13

Page 2