Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 676–750

973 questions total · 13pages · All types, answers revealed

Page 9

Page 10 of 13

Page 11
676
MCQhard

During a third-party risk assessment, an organization discovers that a cloud service provider (CSP) stores data in a jurisdiction with conflicting privacy laws. The organization's legal team advises that this could expose the organization to regulatory penalties. Which of the following contractual clauses would best address this compliance risk?

A.Insert a right-to-audit clause allowing the organization to inspect the CSP's facilities.
B.Include a Data Processing Agreement (DPA) that requires data to be stored only in approved jurisdictions.
C.Negotiate a service-level agreement (SLA) guaranteeing 99.99% uptime.
D.Require the CSP to sign a business associate agreement (BAA) under HIPAA.
AnswerB

A DPA with data residency clauses legally restricts where data can be stored, addressing the compliance risk.

Why this answer

A Data Processing Agreement (DPA) is the correct contractual mechanism to enforce data residency restrictions. By requiring the CSP to store data only in approved jurisdictions, the DPA directly addresses the compliance risk of conflicting privacy laws and potential regulatory penalties, as it legally binds the provider to specific geographic data handling requirements.

Exam trap

The CAS-004 exam often tests the distinction between operational controls (audit clauses, SLAs) and legal/compliance controls (DPAs), trapping candidates who confuse visibility with enforcement or apply US-specific agreements (like BAAs) to global privacy issues.

How to eliminate wrong answers

Option A is wrong because a right-to-audit clause allows the organization to inspect the CSP's facilities and processes, but it does not proactively restrict where data is stored; it only provides visibility after the fact, not a preventive control. Option C is wrong because an SLA guaranteeing 99.99% uptime addresses availability and performance, not data residency or privacy law compliance; it is irrelevant to the jurisdictional conflict. Option D is wrong because a Business Associate Agreement (BAA) under HIPAA is specific to protected health information (PHI) in the United States and does not apply to general privacy law conflicts in other jurisdictions; it also does not restrict data storage locations.

677
MCQmedium

An organization uses a TPM 2.0 for measured boot and attestation. Which TPM feature ensures that the boot process has not been tampered with by measuring each component before it executes?

A.Platform Configuration Registers (PCRs)
B.Endorsement Key (EK)
C.Secure boot
D.Sealed storage
AnswerA

PCRs hold cumulative hash measurements of each boot component, extending values sequentially so any tampering alters the final register state. This satisfies the measured boot requirement, letting attestation compare PCR values against known-good baselines to detect modification before execution.

Why this answer

Platform Configuration Registers (PCRs) store hash measurements of boot components. Any change in the boot sequence will result in different PCR values, alerting to tampering.

678
Multi-Selectmedium

A security architect is implementing network segmentation in a hybrid cloud environment. Which TWO controls are most effective for reducing east-west traffic risks?

Select 2 answers
A.Micro-segmentation
B.VPN concentrator
C.NAT gateway
D.East-west traffic inspection
E.Perimeter firewall
AnswersA, D

Micro-segmentation enforces granular firewall rules at the workload or pod level, using distributed virtual firewalls or network security groups to restrict lateral movement between application tiers. This directly reduces east-west traffic risks in a hybrid cloud by limiting the blast radius of a compromised host, satisfying the constraint of controlling internal, cross-subnet communication rather than perimeter ingress.

Why this answer

Micro-segmentation (A) is correct because it applies granular, workload-level security policies—typically via host-based agents or SDN constructs—that restrict lateral (east-west) movement between workloads even inside the same subnet or VPC, directly reducing east-west risk. East-west traffic inspection (D) is correct because it examines internal traffic flows (e.g., via next-generation firewalls, IDS/IPS, or virtual taps) to detect and block lateral movement, malicious scanning, and exfiltration that perimeter controls would miss. VPN concentrator (B) is not correct because it secures remote-access or site-to-site north-south connectivity, not internal lateral traffic.

NAT gateway (C) is not correct because it provides outbound internet address translation and does not inspect or segment internal east-west flows. Perimeter firewall (E) is not correct because it primarily enforces north-south boundary controls and does not address lateral movement within the segmented environment.

Exam trap

The trap is mixing north-south and east-west controls — candidates select perimeter firewalls or VPN concentrators, which protect the boundary or remote access, instead of controls that specifically govern lateral internal traffic.

679
Multi-Selectmedium

Which two of the following are best practices for securing container orchestration platforms (e.g., Kubernetes)? (Select two.)

Select 2 answers
A.Apply network policies to isolate workloads.
B.Use privileged containers for system services.
C.Disable all security contexts to avoid restrictions.
D.Enable Role-Based Access Control (RBAC).
AnswersA, D

Why this answer

Network policies in Kubernetes act as a firewall for pods, controlling ingress and egress traffic at the IP address or port level (OSI layer 3 or 4). By default, all pods can communicate with each other; applying network policies enforces least-privilege segmentation, which is a core security best practice for container orchestration platforms.

Exam trap

The CAS-004 exam often tests the misconception that privileged containers are necessary for system services, when in fact they should be avoided and replaced with specific capability grants (e.g., CAP_NET_ADMIN) or security context constraints.

Why the other options are wrong

B

Privileged containers should be avoided as they have nearly unrestricted access to the host.

C

Security contexts enforce necessary restrictions; disabling them weakens security.

680
MCQhard

A healthcare provider must allow clinicians to access a SaaS electronic health record from unmanaged personal devices without installing agents. The security architect needs to enforce contextual access decisions based on device posture, user identity, and location, while keeping the EHR session isolated from the local browser. Which of the following should the architect implement?

A.A next-generation firewall (NGFW) with TLS inspection and application control.
B.A cloud access security broker (CASB) in API mode with data loss prevention policies.
C.A virtual desktop infrastructure (VDI) environment hosted in the provider's data center.
D.A Secure Access Service Edge (SASE) platform with a remote browser isolation (RBI) component and identity-based policies.
AnswerD

SASE converges network and security functions with identity-aware policy. Remote browser isolation renders the EHR session in a disposable cloud container, so no data touches the unmanaged device, and access decisions can incorporate user identity, device posture signals, and geolocation. This satisfies agentless access and contextual enforcement while isolating the session.

Why this answer

The need is agentless access from unmanaged devices with contextual decisions and session isolation. A SASE platform with remote browser isolation and identity-based policies enforces access based on user, device posture, and location while keeping the EHR session in a cloud container. VDI, API-mode CASB, and NGFW each address parts of the problem but fail to deliver the combined agentless, contextual, isolated access.

Exam trap

The trap here is treating CASB as sufficient for unmanaged device access, when API-mode CASB governs data at rest and does not isolate or control the live browser session.

681
MCQeasy

Which of the following is the primary purpose of implementing a public key infrastructure (PKI)?

A.To store and verify password hashes for user authentication.
B.To sign software and files to verify integrity and origin.
C.To bind public keys to identities through certificates for authentication and encryption.
D.To provide a secure method for remote access via VPN.
AnswerC

A certificate authority signs certificates that cryptographically bind a public key to a verified identity. This binding lets relying parties authenticate the key holder and establish encrypted sessions, which is PKI's core function rather than key generation or storage alone.

Why this answer

The primary purpose of a Public Key Infrastructure (PKI) is to bind public keys to identities through digital certificates, enabling authentication, non-repudiation, and encryption. PKI uses Certificate Authorities (CAs) to issue and manage X.509 certificates, which associate a public key with a specific entity (e.g., a user or server) and are validated via certificate chains. This binding is essential for secure communications, such as TLS/SSL, where certificates authenticate the server and establish encrypted sessions.

Exam trap

The trap here is that candidates confuse the primary purpose of PKI (binding identities to keys) with its common applications (e.g., code signing, VPN), leading them to select a specific use case rather than the foundational function.

How to eliminate wrong answers

Option A is wrong because storing and verifying password hashes is the function of a directory service (e.g., LDAP) or authentication protocol (e.g., NTLM, Kerberos), not PKI; PKI does not manage passwords. Option B is wrong because while PKI can be used to sign software and files (e.g., via code signing certificates), this is a specific application of PKI, not its primary purpose; the core purpose is binding identities to keys for broader authentication and encryption. Option D is wrong because providing secure remote access via VPN is a use case that may leverage PKI (e.g., IPsec with certificates), but it is not the primary purpose of PKI itself; VPNs can also use pre-shared keys or other methods.

682
MCQeasy

An enterprise is deploying a multi-factor authentication (MFA) solution. The security team requires a factor that is resistant to phishing and does not rely on shared secrets. Which of the following MFA types BEST meets this requirement?

A.Biometric fingerprint scanner
B.SMS one-time passcodes
C.FIDO2/WebAuthn security keys
D.TOTP via authenticator app
AnswerC

FIDO2/WebAuthn security keys satisfy both constraints: cryptographic challenge–response using per-origin public/private key pairs, so no shared secret traverses the wire, and origin binding prevents credential replay on lookalike phishing domains. Microsoft Entra ID supports these keys as phishing-resistant authentication, unlike OTP or push methods.

Why this answer

FIDO2/WebAuthn uses public-key cryptography, with the private key stored on the device, and the protocol is designed to be phishing-resistant by binding credentials to the origin. TOTP/HOTP rely on shared secrets and are vulnerable to phishing. Hardware tokens like YubiKey can implement FIDO2.

Biometrics are a factor but not inherently phishing-resistant alone.

683
MCQeasy

A small business wants to protect endpoints from malware without incurring per-device licensing costs. Which approach is MOST cost-effective?

A.Implement network-based IPS
B.Use open-source host firewall
C.Use built-in Windows Defender and periodically scan with free tools
D.Purchase enterprise EDR suite
AnswerC

Windows Defender ships with the operating system, so endpoint malware protection costs nothing per device; free scanning tools supplement it without subscriptions. This satisfies the no-per-device-licensing constraint, unlike paid endpoint protection platforms that charge per seat.

Why this answer

The most cost-effective because Windows Defender (now Microsoft Defender Antivirus) is built into modern Windows operating systems at no additional cost, providing real-time protection against malware. Supplementing it with free on-demand scanners like Microsoft Safety Scanner or Malwarebytes Free provides periodic secondary checks without per-device licensing fees, meeting the small business's requirement for endpoint protection without recurring costs.

Exam trap

A common misconception is that network-based IPS or host firewall alone can replace endpoint antivirus, when in fact these tools address different layers of defense and cannot detect or remove malware that has already executed on the endpoint.

How to eliminate wrong answers

Option A is wrong because a network-based IPS (e.g., Snort or Cisco Firepower) inspects traffic at the network perimeter and cannot protect endpoints from malware that arrives via encrypted channels, removable media, or offline vectors; it also requires ongoing signature updates and hardware/software maintenance costs. Option B is wrong because a host firewall (e.g., Windows Defender Firewall or open-source iptables) controls inbound/outbound traffic based on rules but does not detect or remediate malware already on the system; it lacks signature-based or behavioral malware scanning. Option D is wrong because an enterprise EDR suite (e.g., CrowdStrike Falcon or SentinelOne) typically charges per-device licensing fees, which directly contradicts the requirement to avoid such costs and is overkill for a small business with basic needs.

684
Multi-Selecthard

An organization is planning to deploy a new internal CA hierarchy. Which THREE considerations are critical for ensuring the security and manageability of the PKI?

Select 3 answers
A.Keep the root CA offline and only bring it online for cross-certification or disaster recovery.
B.Use a 4096-bit RSA key for the root CA and at least 2048-bit for issuing CAs.
C.Use SHA-1 for certificate signing to ensure compatibility with legacy systems.
D.Use a single-tier CA to simplify management.
E.Ensure all certificates include CRL distribution points and OCSP responder URLs.
AnswersA, B, E

Keeping the root CA offline means its private key is never exposed on a network-connected host, so compromise of subordinate systems cannot forge the trust anchor. It is brought online only for cross-certification or disaster recovery, preserving hierarchy integrity and manageability.

Why this answer

Option A is correct because keeping the root CA offline (air-gapped) protects the trust anchor's private key from compromise, bringing it online only for cross-certification or disaster recovery, which is a foundational PKI best practice. Option B is correct because using a 4096-bit RSA key for the long-lived root CA and at least 2048-bit keys for issuing CAs provides adequate cryptographic strength for the hierarchy's lifetime and resists brute-force attacks. Option E is correct because embedding CRL distribution points and OCSP responder URLs in certificates enables timely revocation checking, which is essential for security and manageability of the PKI.

Option C is incorrect because SHA-1 is deprecated and vulnerable to collision attacks; SHA-256 or stronger should be used. Option D is incorrect because a single-tier CA exposes the root to online issuance risks and reduces flexibility, whereas a multi-tier hierarchy with an offline root is more secure and manageable.

685
Matchingmedium

Match each command-line tool to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

DNS query and lookup

Display network connections and listening ports

Capture and analyze network traffic

Perform SSL/TLS cryptographic operations

Network discovery and port scanning

Why these pairings

These tools are commonly used for network troubleshooting and security assessments.

686
MCQmedium

A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?

A.Using a software-defined perimeter to hide network resources
B.Implementing identity-centric access controls across all resources
C.Applying defense-in-depth layering by adding multiple security controls
D.Deploying micro-segmentation to isolate workloads and enforce granular policies
AnswerD

Micro-segmentation enforces least-privilege east-west controls between individual workloads, so a compromised host cannot reach unrelated systems. This directly satisfies the stem's constraint of preventing lateral movement inside the data centre, unlike perimeter or identity-only controls that leave internal traffic largely trusted.

Why this answer

Micro-segmentation isolates workloads and enforces granular, identity- and label-based policies on east-west traffic, which directly prevents lateral movement inside the data center. In a zero trust model, micro-segmentation operationalizes the 'never trust, always verify' principle at the workload level, so a compromised host cannot freely reach other workloads. This is the most direct and effective control for the stated objective of stopping lateral movement.

Exam trap

The trap is selecting a broad zero trust principle (identity-centric controls, defense-in-depth) instead of the specific technical control — micro-segmentation — that directly addresses lateral movement in the data center.

How to eliminate wrong answers

Option A is wrong because a software-defined perimeter (SDP) hides resources from unauthorized users and is primarily used for secure application access (north-south), not for containing lateral movement between internal workloads. Option B is wrong because identity-centric access controls are foundational to zero trust but address authentication and authorization at access points; they do not by themselves segment workload-to-workload traffic inside the data center. Option C is wrong because defense-in-depth layering adds controls but is a general strategy, not a specific mechanism that prevents lateral movement the way micro-segmentation does.

687
MCQeasy

A security architect is designing a network for a small business that wants to allow employees to use their personal smartphones and tablets to access corporate email and files. The company wants to enforce screen lock, encryption, and remote wipe on these devices without managing the entire device. Which of the following should the architect implement?

A.Mobile device management (MDM) with full device enrollment for all personal devices.
B.Network access control (NAC) that checks personal devices for compliance before granting access to the corporate network.
C.Virtual desktop infrastructure (VDI) accessed from personal devices through a web browser.
D.Mobile application management (MAM) with containerization of corporate applications.
AnswerD

MAM with containerization allows the company to enforce policies such as screen lock, encryption, and remote wipe on the corporate applications and data only, without managing the entire personal device. This preserves employee privacy and is the appropriate solution for a BYOD scenario where the company wants to control corporate data but not the whole device. It directly meets the stated requirements.

Why this answer

Mobile application management (MAM) with containerization enforces policies on corporate applications and data without managing the entire personal device. It supports screen lock, encryption, and remote wipe for corporate data, preserving employee privacy. Full MDM enrollment controls the whole device, VDI does not enforce device-level policies, and NAC only checks compliance at network access time, so MAM is the correct choice.

Exam trap

The trap here is conflating mobile device management with mobile application management, when the scenario explicitly requires controlling corporate data without managing the entire personal device.

688
Multi-Selecthard

A security analyst is investigating a potential compromise of a Windows server. The analyst suspects that an attacker used a technique to dump credentials from memory. Which TWO of the following artifacts or events would MOST likely indicate that a credential dumping tool such as Mimikatz was executed? (Choose two.)

Select 2 answers
A.Event ID 4624 with logon type 3 (network) for a service account
B.Event ID 10 from Sysmon showing lsass.exe accessed by an unsigned process
C.Event ID 4688 with process creation for lsass.exe
D.Event ID 7045 with a new service named 'MimikatzSvc'
E.Event ID 4656 with handle to lsass.exe requesting PROCESS_VM_READ
AnswersB, E

Sysmon Event ID 10 logs process access, including when a process opens a handle to another process. If an unsigned process accesses lsass.exe, it is highly suspicious because legitimate processes accessing lsass are typically signed by Microsoft. This event is a strong indicator of credential dumping attempts, as tools like Mimikatz often run as unsigned binaries or injected code.

Why this answer

The correct indicators are a handle request to lsass.exe with PROCESS_VM_READ (Event ID 4656) and Sysmon Event ID 10 showing lsass.exe accessed by an unsigned process. Both directly relate to unauthorized memory reading of the Local Security Authority Subsystem Service, which stores credentials. The other events are either normal system activities or too generic to specifically indicate credential dumping.

Exam trap

The trap here is assuming that any process creation or service installation involving lsass or Mimikatz is a clear indicator, when in fact credential dumping is best detected by monitoring access to lsass memory.

689
MCQhard

During a security incident, a forensic analyst needs to acquire a memory dump from a Linux server without altering the system state. Which tool is most appropriate for this task?

A.Volatility framework
B.LiME (Linux Memory Extractor)
C.dd if=/dev/mem of=mem.dump
D.memdump utility
AnswerB

LiME is a loadable kernel module that captures physical memory to a file or over the network, operating from within the kernel to minimise changes to user-space processes. This satisfies the requirement to acquire a memory dump while preserving system state for later forensic analysis.

Why this answer

LiME (Linux Memory Extractor) is the most appropriate tool because it is specifically designed to acquire volatile memory from Linux systems while minimizing the footprint on the target system. It loads as a kernel module and directly accesses physical memory, ensuring that the acquisition process does not alter the system state, which is critical for forensic integrity.

Exam trap

The trap here is that candidates often confuse memory acquisition tools with analysis tools, picking Volatility (A) because it is well-known, or incorrectly assume that 'dd' can reliably access full physical memory on modern Linux systems.

How to eliminate wrong answers

Option A is wrong because the Volatility framework is a memory analysis tool, not an acquisition tool; it requires an already captured memory dump to analyze, and cannot acquire memory directly. Option C is wrong because 'dd if=/dev/mem of=mem.dump' is unreliable on modern Linux kernels; /dev/mem is restricted to the first 1 MB of physical memory (due to CONFIG_STRICT_DEVMEM) and may cause system instability or incomplete acquisition. Option D is wrong because 'memdump' is not a standard Linux utility; it is a generic term that could refer to various tools, but no standard 'memdump' command exists for Linux memory acquisition, and using an unverified tool risks altering system state.

690
MCQhard

A large enterprise is implementing a SOAR platform to automate incident response. The security team wants to create a playbook for handling phishing emails reported by users. The playbook should: 1) validate the reported email by checking headers and attachments, 2) automatically block the sender's domain at the email gateway if malicious, 3) create a ticket, and 4) send an automated response to the user. Which of the following describes the best approach to design this playbook?

A.Create a ticket and route it to a junior analyst for manual investigation, then close after user acknowledgement.
B.Immediately sandbox the attachment and block the sender's domain if the sandbox reports malicious behavior.
C.Use an automated triage step that extracts indicators, then present the verdict to an analyst in a manual approval step before executing blocks.
D.Automatically delete the email from all users' inboxes and send a warning to the organization.
AnswerC

Automated triage extracts headers, URLs and attachment hashes, but a human approval gate precedes the gateway block. This preserves containment speed while preventing a false positive from blocking a legitimate sender's entire domain, satisfying the requirement to validate before executing the block.

Why this answer

The best approach is to use automated triage to extract indicators and then present the verdict to an analyst for manual approval before executing blocks. This balances automation with human oversight, reducing false positives and ensuring that blocking actions are justified. It also aligns with SOAR best practices of automating repetitive tasks while keeping critical decisions under human control.

Exam trap

CAS-005 often tests the balance between automation and human oversight, and candidates may choose fully automated blocking without considering the risk of false positives.

How to eliminate wrong answers

Option A is wrong because it relies entirely on manual investigation by a junior analyst, which is not automated and does not leverage SOAR capabilities; it also lacks automated validation and response. Option B is wrong because it immediately blocks the sender's domain based solely on sandbox results without human approval, which could lead to blocking legitimate domains if the sandbox has false positives. Option D is wrong because automatically deleting the email from all users' inboxes and sending a warning is a drastic action that could cause disruption if the email is not malicious, and it does not include validation or ticketing.

691
MCQeasy

A network administrator is configuring a firewall to allow only necessary traffic to a web server. The server should be accessible from the internet on port 443 and from a management subnet on port 22. Which firewall rule ensures least privilege?

A.Allow traffic from management subnet to port 443 and any to port 22
B.Allow traffic from any source to ports 443 and 22
C.Allow all traffic to the server, then block specific ports
D.Allow traffic from any to port 443, and from management subnet to port 22; deny all else
AnswerD

This rule permits only the two required flows — HTTPS from anywhere and SSH restricted to the management subnet — then denies everything else. Scoping port 22 to the management subnet enforces least privilege, satisfying the constraint that the server be reachable only as specified.

Why this answer

It explicitly allows only the required traffic (HTTPS on port 443 from any source, SSH on port 22 from the management subnet) and then denies all other traffic by default. This follows the principle of least privilege by ensuring no unintended services or sources are permitted, which is the core goal of firewall rule design.

Exam trap

The trap here is that candidates often choose an option that allows all traffic to the server (like Option C) thinking they can later block unwanted ports, but this violates the default-deny principle and is not considered least privilege in firewall design.

How to eliminate wrong answers

Option A is wrong because it allows traffic from the management subnet to port 443 (unnecessary) and allows any source to port 22 (overly permissive, exposing SSH to the internet). Option B is wrong because it allows any source to both ports 443 and 22, which violates least privilege by exposing SSH to the entire internet. Option C is wrong because it uses an allow-all-then-block approach, which is inherently insecure and violates the default-deny principle; it also fails to specify which ports to block, leaving the server exposed until explicit deny rules are added.

692
MCQhard

Using the FAIR model, which of the following best describes the factor that represents the probable frequency of a threat acting on a vulnerability?

A.Threat event frequency (TEF)
B.Vulnerability
C.Loss event frequency (LEF)
D.Control effectiveness
AnswerA

Threat event frequency (TEF) quantifies how often a threat agent is likely to act against an asset within a given period, directly answering the stem's requirement for probable frequency of action on a vulnerability. It sits alongside vulnerability and loss magnitude as a core FAIR factor, distinct from contact frequency or probability of action.

Why this answer

Threat event frequency (TEF) is the FAIR factor that quantifies how often a threat agent is expected to act against an asset within a given timeframe. It directly measures the probable frequency of a threat acting on a vulnerability, independent of whether the action succeeds. TEF is a primary input to calculating loss event frequency (LEF).

Exam trap

The trap here is confusing threat event frequency (TEF) with loss event frequency (LEF); candidates often pick LEF because it sounds like the frequency of threat actions, but LEF incorporates vulnerability and represents actual loss events, not just threat actions.

How to eliminate wrong answers

Option B is wrong because vulnerability in FAIR is the probability that a threat event becomes a loss event, not the frequency of the threat action itself. Option C is wrong because loss event frequency (LEF) is the probable frequency of loss events, derived from TEF and vulnerability, not the raw threat action frequency. Option D is wrong because control effectiveness is not a core FAIR factor; it is a modifier that influences vulnerability and TEF, but does not represent the frequency of threat actions.

693
MCQmedium

A security operations center (SOC) analyst is reviewing logs from a Linux web server and notices a high volume of requests containing encoded characters such as %2e%2e%2f and %00 in the URI. The analyst suspects an attempt to exploit a path traversal vulnerability. Which of the following log sources would BEST confirm whether the attack was successful?

A.Firewall logs showing allowed outbound connections from the web server to a database server.
B.Intrusion detection system (IDS) alerts indicating a path traversal signature match.
C.Web server access logs showing HTTP 200 responses for requests containing encoded traversal sequences.
D.Authentication logs showing multiple failed login attempts from the same IP address.
AnswerC

HTTP 200 responses to traversal attempts indicate the server processed the requests successfully, which may mean files outside the web root were accessed. This directly confirms potential success, unlike error codes. Correlating with file access logs can further validate, but the access logs are the primary source for web-based attacks.

Why this answer

To confirm a path traversal attack's success, the analyst needs evidence that the server actually processed the malicious requests and potentially returned sensitive files. Web server access logs with HTTP 200 responses to traversal attempts provide that evidence. Other log sources may indicate attempts or unrelated activity but do not directly confirm file access.

Exam trap

The trap here is assuming that an IDS alert or firewall log confirms a successful attack, when they only show attempts or unrelated traffic.

694
MCQmedium

A security analyst is reviewing a suspicious process that has been identified on an endpoint. The analyst wants to determine if the process has any network connections and what data it might be sending. Which tool is most appropriate for analyzing the memory of the affected system to identify network connections and potential data exfiltration?

A.Wireshark
B.Volatility
C.Autopsy
D.Nmap
AnswerB

Volatility performs memory forensics, parsing a captured RAM image to enumerate running processes, their network sockets and injected artefacts. That directly satisfies the requirement to analyse memory for network connections and potential exfiltration, which disk-based or live-response tools cannot reconstruct from volatile state.

Why this answer

Volatility is a memory forensics framework that analyzes RAM dumps to extract running processes, network connections, and injected code. It is the most appropriate tool for examining memory to identify network connections and potential data exfiltration from a suspicious process.

Exam trap

CAS-005 often tests the confusion between network forensics tools (Wireshark, Nmap) and memory forensics tools (Volatility), causing candidates to select a network analysis tool when the question explicitly asks for memory analysis.

How to eliminate wrong answers

Option A (Wireshark) is wrong because Wireshark captures and analyzes live network traffic, not memory — it cannot inspect process memory or identify which process initiated a connection. Option C (Autopsy) is wrong because Autopsy is a disk forensics tool for file system analysis, not memory analysis. Option D (Nmap) is wrong because Nmap is a network scanning tool for host and port discovery, not memory forensics.

695
Multi-Selecthard

Which THREE of the following are required for PCI DSS compliance regarding cardholder data?

Select 3 answers
A.Maintain a vulnerability management program.
B.Store cardholder data after authorization.
C.Restrict access to cardholder data by business need-to-know.
D.Encrypt transmitted cardholder data over open networks.
E.Implement multifactor authentication for all physical access to data centers.
AnswersA, C, D

Requirements 6 and 11 require a vulnerability management program to identify and remediate vulnerabilities.

Why this answer

PCI DSS Requirement 5 mandates that entities must maintain a vulnerability management program that includes deploying anti-malware software on all systems commonly affected by malicious software, as well as performing regular vulnerability scans and applying security patches. This requirement ensures that cardholder data environments are protected against known vulnerabilities that could be exploited by attackers.

Exam trap

The most common pitfall in this question is confusing PCI DSS requirements for access control. Option E (multifactor authentication for all physical access) seems plausible, but PCI DSS only mandates MFA for remote network access to the cardholder data environment (CDE), not for physical access to data centers. Physical access controls are covered by other requirements such as visitor management and facility entry logs.

Similarly, option B (storing cardholder data after authorization) violates PCI DSS Requirement 3, which prohibits storing sensitive authentication data after authorization (e.g., full track data, CVV, PIN) except for specific business justifications with truncation. Candidates often select these incorrect options because they overgeneralize security best practices.

696
Multi-Selecthard

A security analyst is reviewing a potentially malicious PowerShell script that was executed on a workstation. The script contains obfuscated code and makes network connections. The analyst wants to perform dynamic analysis to understand its behavior. Which TWO of the following methods would BEST allow the analyst to observe the script's runtime actions in a controlled environment? (Choose two.)

Select 2 answers
A.Use PowerShell's Constrained Language Mode to restrict script execution
B.Set up a debugger and step through the script line by line
C.Execute the script in an isolated sandbox with network simulation and monitor API calls
D.Perform static analysis by extracting strings and examining the abstract syntax tree
E.Run the script on a production workstation with logging enabled
AnswersB, C

Using a debugger to step through the script line by line allows the analyst to observe variable values, function calls, and execution flow in real time. This is a powerful dynamic analysis method for understanding obfuscated scripts. It can reveal decryption routines and network calls as they happen, without needing to fully deobfuscate statically.

Why this answer

Dynamic analysis involves executing the script in a controlled environment to observe its behavior. An isolated sandbox with network simulation allows safe execution and monitoring of API calls, network traffic, and system changes. Stepping through the script with a debugger provides line-by-line visibility into its execution, revealing obfuscated logic and runtime actions.

Both methods are essential for understanding malicious scripts without risking production systems.

Exam trap

The trap here is confusing static analysis or restrictive controls with dynamic analysis, which requires executing the code in a safe environment to observe behavior.

697
Multi-Selectmedium

A security engineer is implementing a zero trust architecture for a corporate network. The engineer must ensure that all access requests are continuously verified and that least privilege is enforced. Which TWO components are essential to achieve these goals? (Choose two.)

Select 2 answers
A.A VPN concentrator that provides encrypted tunnels for all remote access.
B.A next-generation firewall (NGFW) that inspects all traffic at the network perimeter.
C.A policy administrator that establishes and maintains the trust relationship between the subject and the resource.
D.A security information and event management (SIEM) system that aggregates logs for analysis.
E.A policy engine that evaluates access requests based on identity, device posture, and context.
AnswersC, E

The policy administrator is responsible for executing the decisions made by the policy engine. It configures the data plane to allow or deny connections, often by instructing gateways or agents. It is essential for enforcing least privilege because it dynamically provisions access based on the policy engine's verdict. Together with the policy engine, it forms the control plane.

Why this answer

Zero trust architecture relies on a policy engine to make dynamic access decisions based on context, and a policy administrator to enforce those decisions by configuring the data plane. These two components form the control plane and are essential for continuous verification and least privilege. Other options like VPN, NGFW, and SIEM are supporting technologies but not core to the zero trust access decision process.

Exam trap

The trap here is confusing network security devices like VPNs and firewalls with the core zero trust control plane components that actually enforce dynamic access decisions.

698
MCQhard

A mid-sized e-commerce company has recently experienced a data breach where customer payment card information was exfiltrated. The security team has identified that the breach originated from a compromised web server that was part of a PCI DSS compliant environment. The server was running outdated software and had several known vulnerabilities. Post-incident analysis reveals that the attacker exploited a SQL injection vulnerability in the order-tracking feature. The incident response team followed NIST SP 800-61 guidelines: they contained the threat, eradicated the malicious code, and restored the server from a known clean backup. However, two weeks after the restoration, the same server is again showing signs of similar malicious activity. The server is still in production and handling credit card transactions. Which of the following is the MOST effective course of action to prevent this recurring compromise?

A.Conduct a thorough code review of the order-tracking feature, implement parameterized queries, and then redeploy the application after passing a static code analysis scan.
B.Replace the web server with a new server running the latest OS and web server version, then redeploy the same web application code.
C.Implement network segmentation to isolate the web server and restrict outbound traffic to only essential services.
D.Increase logging and deploy a WAF in front of the server with rules to block common SQLi patterns.
AnswerA

Parameterised queries eliminate the SQL injection vector by separating code from data, so attacker-supplied input can no longer alter query structure. This directly addresses the root cause the stem identifies — the order-tracking feature's injection flaw — rather than merely restoring a vulnerable server, which is why the compromise recurred after remediation.

Why this answer

The root cause of the breach is a SQL injection vulnerability in the order-tracking feature. Simply patching the server or redeploying the same code (Option B), implementing network segmentation (Option C), or adding a WAF (Option D) are all band-aid solutions that do not address the underlying flawed code. To prevent recurrence, the application code must be reviewed and the SQL injection flaw remediated by using parameterized queries.

After fixing the code, redeploying after passing a static code analysis scan ensures the vulnerability is resolved. Therefore, option A is the most effective course of action.

699
MCQmedium

A financial institution needs to ensure that transaction logs are tamper-proof after creation. Which solution should be implemented?

A.Cryptographic hashing with chain hashing
B.Access control lists
C.Encryption with AES
D.Digital signatures on each log entry
AnswerA

Chain hashing links each log entry's cryptographic hash to the previous entry, so altering any record invalidates all subsequent hashes. This satisfies the stem's tamper-proof requirement, since retrospective modification becomes detectable without needing to trust the storage layer itself.

Why this answer

Chain hashing (also known as hash chaining or blockchain-style linking) ensures tamper-proof logs by including the cryptographic hash of the previous log entry in the current entry. This creates an immutable chain: any modification to a prior entry changes its hash, breaking the chain for all subsequent entries, making tampering immediately detectable. Unlike simple hashing of individual entries, chain hashing ties the entire log sequence together, providing integrity and non-repudiation of the log's chronological order.

Exam trap

CompTIA CASP+ often tests the distinction between integrity (hash chaining) and non-repudiation (digital signatures), leading candidates to choose digital signatures because they associate them with 'proof'—but signatures alone do not enforce sequential ordering or detect reordering/deletion, which is the core requirement for tamper-proof logs.

How to eliminate wrong answers

Option B (Access control lists) is wrong because ACLs only control who can read or write logs, but they do not provide cryptographic proof of tampering after the fact—an attacker with elevated privileges could modify logs undetected. Option C (Encryption with AES) is wrong because encryption protects confidentiality (secrecy) of log data, not integrity; an attacker could still alter encrypted logs (though garbled) or replace entire encrypted blocks without detection unless an integrity check like HMAC is used. Option D (Digital signatures on each log entry) is wrong because while a digital signature proves the origin and integrity of a single entry, it does not enforce ordering or detect deletion/reordering of entries—an attacker could remove or reorder signed entries without breaking individual signatures, whereas chain hashing links entries sequentially.

700
MCQeasy

A company is implementing a passwordless authentication solution using FIDO2/WebAuthn. What is the primary security advantage of this approach over traditional password-based authentication?

A.It allows users to share passwords securely.
B.It reduces server storage requirements.
C.It eliminates the need for multi-factor authentication.
D.It prevents phishing attacks by using cryptographic keys.
AnswerD

FIDO2/WebAuthn binds the credential's private key to the relying party's origin, so a phishing site on a different domain cannot invoke it. This origin-scoped cryptographic assertion removes the shared-secret replay weakness inherent in password-based authentication.

Why this answer

FIDO2/WebAuthn uses public-key cryptography where the private key never leaves the authenticator (e.g., a security key or platform authenticator), and the origin is cryptographically bound to the credential. This origin binding means a phishing site with a different domain cannot trigger the authenticator to sign the challenge, effectively preventing credential phishing. Traditional passwords, by contrast, can be captured and replayed by phishing proxies.

Exam trap

The trap is selecting 'eliminates the need for multi-factor authentication' because candidates conflate passwordless with single-factor; in reality, FIDO2 can be one factor and the core advantage tested is phishing resistance via cryptographic origin binding.

How to eliminate wrong answers

Option A is wrong because FIDO2/WebAuthn is designed to eliminate shared secrets entirely — there are no passwords to share, and the private key is non-exportable. Option B is wrong because while the server stores a public key instead of a password hash, the primary security advantage is phishing resistance, not storage reduction; server storage is a secondary benefit at best. Option C is wrong because FIDO2/WebAuthn can serve as one factor (possession) and may still be combined with a PIN or biometric for multi-factor authentication; it does not inherently eliminate the need for MFA in all contexts, and claiming so misrepresents the standard.

701
MCQeasy

An organization is implementing a third-party risk management program. Which of the following is the FIRST step in the vendor risk assessment process?

A.Identify the vendor and the type of data it will handle
B.Conduct an on-site audit of the vendor's facilities
C.Review the vendor's contractual security clauses
D.Determine risk treatment options
AnswerA

Vendor risk assessment must begin by identifying the vendor and classifying the data it will handle, since data sensitivity determines the depth of due diligence, contractual controls and ongoing monitoring required. Without this scoping step, subsequent assessment activities cannot be appropriately tailored.

Why this answer

The first step in a vendor risk assessment is to identify the vendor and the type of data it will handle. This foundational step determines the scope and criticality of the assessment, as the data classification (e.g., PII, PHI, PCI-DSS) directly dictates the required security controls and regulatory compliance obligations. Without this identification, subsequent steps like audits or contract reviews lack context and may miss key risk areas.

Exam trap

The trap here is that candidates often jump to contractual or audit steps (options B or C) because they seem like concrete actions, but the exam tests the logical sequence of risk management, where identification of the asset (vendor and data) must precede any control evaluation.

How to eliminate wrong answers

Option B is wrong because conducting an on-site audit occurs later in the process, after the vendor and data type are identified and a risk assessment plan is developed; auditing prematurely wastes resources without understanding what to audit. Option C is wrong because reviewing contractual security clauses assumes a contract exists, but the initial step is to identify the vendor and data before any contractual relationship is established or reviewed. Option D is wrong because determining risk treatment options (e.g., accept, mitigate, transfer) is a downstream decision made after risks are identified and assessed, not the first step.

702
MCQmedium

A security analyst is investigating a potential insider threat. The analyst needs to correlate user activity across multiple systems, including file access, email, and web browsing, to build a timeline of events. Which data source is MOST critical for this correlation?

A.Endpoint detection and response (EDR) telemetry
B.Active Directory authentication logs
C.NetFlow records
D.Firewall logs
AnswerA

EDR telemetry captures detailed endpoint activity, including process execution, file operations, network connections, and user context. This rich data enables correlation of user actions across systems, making it the most critical source for building a comprehensive timeline of insider activity.

Why this answer

EDR telemetry is the most critical data source because it provides detailed, user-attributed activity across endpoints, including file, process, and network events. This allows the analyst to correlate actions across multiple systems and construct a timeline, whereas other sources offer only partial or network-level visibility.

Exam trap

The trap here is assuming that network-centric logs like NetFlow or firewall logs can provide user-level activity correlation, when they lack identity and application context.

703
MCQhard

After a risk assessment, a company identifies that the residual risk for a critical application is higher than the risk appetite. The risk owner proposes implementing additional controls to reduce the risk further. Which risk treatment option does this represent?

A.Risk transfer
B.Risk mitigation
C.Risk acceptance
D.Risk avoidance
AnswerB

Adding controls to lower residual risk below the risk appetite is risk mitigation: the organisation reduces likelihood or impact rather than avoiding, transferring or accepting the risk. The risk owner's proposal modifies the risk itself, matching mitigation.

Why this answer

Risk mitigation involves implementing additional controls to reduce the likelihood or impact of a risk. Since the residual risk exceeds the risk appetite, the risk owner proposes further controls to lower it, which is the definition of risk mitigation. This aligns with the goal of bringing risk within acceptable limits.

Exam trap

The trap here is confusing risk mitigation with risk acceptance or avoidance, especially when the scenario mentions residual risk exceeding appetite; candidates might think acceptance is implied, but the proposal of additional controls clearly indicates mitigation.

How to eliminate wrong answers

Option A is wrong because risk transfer shifts the risk to a third party (e.g., insurance), not reducing it through controls. Option C is wrong because risk acceptance means acknowledging the risk without taking action, which is inappropriate when residual risk exceeds appetite. Option D is wrong because risk avoidance involves eliminating the activity or process that generates the risk, not adding controls to reduce it.

704
MCQmedium

A penetration tester is performing a test against a web application. The rules of engagement prohibit any denial of service (DoS) attacks. Which of the following actions is most likely prohibited by this restriction?

A.Performing a SQL injection that deletes a table
B.Exploiting a file upload vulnerability to upload a web shell
C.Using a tool to send thousands of requests to overwhelm the server
D.Running a directory brute-force tool
AnswerC

Flooding the server with thousands of requests is a volumetric denial-of-service technique, consuming resources until legitimate users are denied service. The rules of engagement explicitly prohibit DoS, so this action falls squarely within the restriction, unlike enumeration or injection testing which do not deny availability.

Why this answer

Using a tool to send thousands of requests to overwhelm the server is a denial-of-service (DoS) attack, which is explicitly prohibited by the rules of engagement. This action aims to exhaust server resources, causing service unavailability.

Exam trap

CAS-005 often tests the interpretation of rules of engagement, and candidates may confuse other malicious actions (like SQL injection) with DoS, failing to recognize that DoS specifically targets availability.

How to eliminate wrong answers

Option A is wrong because SQL injection that deletes a table is a data integrity attack, not a DoS, though it may cause disruption, it is not primarily about overwhelming the server. Option B is wrong because uploading a web shell is a remote code execution attack, not a DoS. Option D is wrong because directory brute-forcing is a reconnaissance or access attempt, not a DoS, though it generates traffic, it does not aim to overwhelm the server.

705
MCQeasy

A security architect is reviewing the company's incident response plan and wants to ensure that the team can detect and respond to threats in real time across endpoints, networks, and cloud workloads. The architect needs a solution that correlates events from multiple sources and provides automated response actions. Which technology should the architect recommend?

A.Security information and event management (SIEM) with security orchestration, automation, and response (SOAR) capabilities.
B.Endpoint detection and response (EDR) deployed only on servers.
C.Network detection and response (NDR) with full packet capture at the perimeter.
D.A vulnerability scanner with scheduled scans of all assets.
AnswerA

SIEM aggregates and correlates logs from multiple sources, while SOAR provides automated response actions and orchestration. Together they enable real-time detection and automated response across endpoints, networks, and cloud workloads, meeting the requirement for correlated events and automation.

Why this answer

A SIEM with SOAR capabilities is the correct choice because it centralizes log collection and correlation from diverse sources and enables automated response workflows. This combination provides the real-time detection and orchestrated response across endpoints, networks, and cloud workloads that the incident response plan requires.

Exam trap

The trap here is thinking that a single-domain tool such as EDR or NDR can cover all environments, when the requirement specifically calls for cross-domain correlation and automation.

706
MCQhard

A security team is auditing a Kubernetes cluster. They find a pod running with `securityContext`: `privileged: true` and `runAsUser: 0`. Which of the following is the most critical risk?

A.The pod cannot communicate with other pods.
B.The pod cannot mount volumes.
C.The pod can access all node resources and potentially escape to the host.
D.The pod will be killed by Kubernetes if it consumes too much memory.
AnswerC

Privileged mode disables container isolation, granting the pod full access to host devices, kernel capabilities and node resources. Combined with runAsUser 0, a compromise can mount the host filesystem and escape the container to control the node.

Why this answer

Setting `privileged: true` and `runAsUser: 0` (root) in a pod's securityContext grants the container unrestricted access to the host's kernel capabilities. This effectively disables all container isolation, allowing the container to perform privileged operations such as loading kernel modules, accessing raw block devices, and using `nsenter` or `chroot` to escape the container and gain root-level access to the underlying node. This is the most critical risk because it directly compromises the host and potentially the entire cluster.

Exam trap

A common misconception is that privileged mode only affects resource limits or network policies, when in fact it removes all kernel-level isolation, enabling container escape to the host.

How to eliminate wrong answers

Option A is wrong because privileged containers can communicate with other pods normally via the cluster's CNI network plugin; privilege escalation does not affect network isolation. Option B is wrong because privileged containers can mount volumes, and in fact they have greater ability to mount host paths and devices. Option D is wrong because Kubernetes does not automatically kill pods for high memory consumption; it uses resource limits and the OOM killer, but this is a resource management issue, not a security risk.

707
MCQeasy

A security analyst is performing incident response and needs to collect evidence from a live system. Which of the following should be collected first to preserve volatile data?

A.Memory (RAM)
B.Network connections
C.Hard drive contents
D.System logs
AnswerA

RAM is the most volatile evidence, lost on power-down or reboot, so it must be captured before disk, logs or network state. Collecting memory first preserves running processes, injected code and encryption keys that would otherwise be irretrievable, satisfying the order-of-volatility constraint.

Why this answer

Memory (RAM) is the most volatile evidence on a live system — it contains running processes, encryption keys, network connections, and uncommitted data that vanish the moment the system is powered off or rebooted. Collecting RAM first preserves this ephemeral state before it is lost. This follows the order of volatility principle in digital forensics.

Exam trap

CAS-005 often tests the order of volatility — candidates pick network connections or logs thinking they are 'more volatile' because they change frequently, but RAM is the most volatile and must be collected first.

How to eliminate wrong answers

Option B is wrong because network connections, while volatile, are partially captured in memory and can be re-collected via netstat or similar tools — they are less volatile than RAM contents. Option C is wrong because hard drive contents are non-volatile and persist across reboots, so they can be collected later without loss. Option D is wrong because system logs are typically written to disk (non-volatile) and may also exist in memory, but they are less volatile than raw RAM and can be collected after memory.

708
MCQhard

A security architect is evaluating a new cloud SaaS application that will handle sensitive customer data. The SaaS provider offers a shared responsibility model where the customer is responsible for data classification, access management, and encryption of data at rest using customer-managed keys. The architect must ensure that the organization retains the ability to revoke access to the data if the provider is compromised. Which key management strategy best meets this requirement?

A.Escrow the encryption key with a third-party and rely on legal agreements for revocation
B.Use the provider's default encryption with a customer-managed key stored in the provider's KMS
C.Use a cloud hardware security module (HSM) to generate and store keys
D.Implement bring-your-own-key (BYOK) with keys stored in a customer-controlled external KMS
AnswerD

BYOK with external KMS gives the customer full control to revoke access immediately.

Why this answer

BYOK with keys stored in a customer-controlled external KMS ensures the organization retains full control over encryption keys, enabling immediate revocation of access to data at rest if the SaaS provider is compromised. This aligns with the shared responsibility model where the customer manages keys, and external KMS decouples key management from the provider's infrastructure, preventing the provider from accessing data after key revocation.

Exam trap

The CAS-004 exam often tests the misconception that using a provider's KMS or HSM (even with customer-managed keys) provides sufficient separation, but the trap is that any key stored within the provider's boundary can be accessed by the provider if their security is breached, whereas BYOK with an external KMS ensures true customer-only control.

How to eliminate wrong answers

Option A is wrong because escrowing keys with a third-party and relying on legal agreements introduces latency and lacks technical immediacy for revocation; legal processes cannot guarantee instant access removal during a breach. Option B is wrong because storing a customer-managed key in the provider's KMS still places the key under the provider's control, as the provider's KMS is part of their trusted environment, allowing potential access if the provider is compromised. Option C is wrong because using a cloud HSM within the provider's ecosystem still ties key management to the provider's infrastructure; while HSMs offer hardware security, the provider retains administrative access to the HSM service, undermining customer-only revocation capability.

709
Multi-Selectmedium

A security architect is designing a network segmentation strategy for a data center to reduce the attack surface. Which TWO of the following are best practices for implementing effective network segmentation?

Select 2 answers
A.Deploy network access control (NAC) to authenticate devices before granting network access.
B.Place all external-facing services in a single shared DMZ segment.
C.Allow any-to-any communication within each security zone to avoid performance bottlenecks.
D.Use VLANs to logically isolate traffic between different security zones.
E.Implement microsegmentation using host-based firewalls or virtual networking to restrict east-west traffic.
AnswersD, E

VLANs provide Layer 2 isolation, which is a fundamental segmentation technique.

Why this answer

VLANs (IEEE 802.1Q) provide Layer 2 isolation between security zones by segmenting broadcast domains, preventing traffic from crossing zone boundaries without a Layer 3 device (router/firewall). This reduces the attack surface by containing lateral movement within a single VLAN and enforcing access control at the gateway.

Exam trap

A common misconception is that NAC alone is a segmentation technique, when in fact it is an authentication and authorization mechanism that complements but does not replace Layer 2/3 isolation methods like VLANs or microsegmentation.

710
MCQmedium

A security architect is designing a data-at-rest protection scheme for a multi-tenant SaaS platform. The requirement is that each tenant's data be encrypted with a unique key, and that compromise of one tenant's key never exposes another tenant's data. The platform must support cryptographic erasure of a single tenant without re-encrypting the entire database. Which design BEST satisfies these requirements?

A.Encrypt all tenant data with a single database master key and rely on row-level access controls to isolate tenants.
B.Use a per-tenant data encryption key wrapped by a key encryption key, and destroy the wrapped data key to erase that tenant.
C.Encrypt each tenant's data with a key derived from the tenant identifier using PBKDF2, and rotate the derivation salt to erase the tenant.
D.Store each tenant's data in a separate database encrypted with a shared HSM-backed key, and delete rows to erase a tenant.
AnswerB

Envelope encryption with a unique data encryption key per tenant ensures that compromising one tenant's key reveals only that tenant's data. The key encryption key wraps each data key, so destroying a single wrapped data key renders that tenant's ciphertext permanently unrecoverable, achieving cryptographic erasure without touching other tenants or re-encrypting the database. This satisfies isolation, erasure, and operational efficiency requirements.

Why this answer

Envelope encryption with a unique wrapped data key per tenant provides both cryptographic isolation and efficient cryptographic erasure. Destroying a single wrapped data key makes that tenant's ciphertext unrecoverable while leaving the key encryption key and all other tenants untouched. This avoids full-database re-encryption and ensures that one key compromise cannot cascade across tenants.

Exam trap

The trap here is confusing logical access controls or physical database separation with cryptographic isolation, when only per-tenant keys wrapped under a higher-level key deliver both isolation and crypto-erasure.

711
MCQeasy

A company is implementing a microservices architecture and needs to ensure secure service-to-service communication. Which of the following BEST describes the recommended approach?

A.Basic HTTP authentication
B.Mutual TLS (mTLS) with certificate authentication
C.IP whitelisting
D.Shared API keys
AnswerB

Mutual TLS authenticates both client and server via X.509 certificates, giving each microservice a cryptographic identity independent of network location. This satisfies the zero-trust requirement for service-to-service communication, where workloads are ephemeral and IP-based trust fails. Certificates can be rotated and scoped per service, enabling least-privilege access without shared secrets.

Why this answer

Mutual TLS (mTLS) with certificate authentication is the recommended approach for secure service-to-service communication in a microservices architecture because it provides both encryption and bidirectional authentication. Each service presents a unique X.509 certificate to verify its identity, preventing unauthorized access and man-in-the-middle attacks. This aligns with the principle of zero-trust networking, where no implicit trust is granted based on network location.

Exam trap

CompTIA often tests the misconception that IP whitelisting or shared API keys are sufficient for service-to-service security, but the trap here is that candidates overlook the need for both encryption and mutual authentication in a zero-trust microservices environment, where network perimeters are obsolete and dynamic identity verification is critical.

How to eliminate wrong answers

Option A is wrong because Basic HTTP authentication transmits credentials (username and password) in cleartext (Base64-encoded, not encrypted) and offers no protection against replay attacks or eavesdropping, making it unsuitable for service-to-service communication. Option C is wrong because IP whitelisting relies on network-layer addresses, which can be spoofed, and does not provide encryption or mutual authentication; it also breaks down in dynamic environments like Kubernetes where pod IPs change frequently. Option D is wrong because shared API keys are static secrets that must be transmitted with each request, lack built-in encryption, and are vulnerable to leakage, rotation complexity, and replay attacks; they also do not provide mutual authentication.

712
MCQmedium

A financial services firm is undergoing a SOC 2 Type II examination. The auditor asks the CISO to demonstrate that the organization continuously monitors whether the controls described in the system description operated effectively throughout the review period. Which activity should the CISO present as the primary evidence supporting this requirement?

A.Collecting and retaining timestamped system-generated logs and control execution records across the entire audit period
B.Delivering the organization's information security policy manual and a list of planned future controls
C.Scheduling a one-time penetration test two weeks before the auditor's fieldwork begins
D.Providing a completed security questionnaire signed by the CISO on the last day of the audit period
AnswerA

A SOC 2 Type II opinion covers control operating effectiveness over a defined period, so the auditor needs evidence gathered continuously, not at a single point. Timestamped logs, ticket histories, change records, and monitoring artifacts spanning the full window demonstrate that controls such as access review, change approval, and incident handling actually ran as described throughout the period.

Why this answer

SOC 2 Type II differs from Type I because it reports on control operating effectiveness over a period rather than design at a point in time. The strongest evidence is contemporaneous, system-generated, and timestamped, covering the full window. Signed questionnaires, single penetration tests, and policy manuals only show intent or a snapshot, so they cannot demonstrate that the described controls ran effectively on an ongoing basis.

Exam trap

The trap here is assuming a signed management attestation or policy document can substitute for period-wide evidence, when Type II demands proof that controls actually operated throughout the audited window.

713
MCQeasy

A security engineer is configuring a VPN between two sites and needs to ensure data confidentiality and integrity. Which IPsec mode and protocol combination should be used to encrypt the entire IP packet including the header?

A.Transport mode with ESP
B.Transport mode with AH
C.Tunnel mode with AH
D.Tunnel mode with ESP
AnswerD

Tunnel mode encapsulates the complete original IP packet, header included, inside a new IP packet, so the original addresses are hidden. ESP provides confidentiality and integrity for that payload. Transport mode would leave the original header exposed, failing the stated requirement.

Why this answer

IPsec tunnel mode with ESP encrypts and authenticates the entire IP packet, providing confidentiality and integrity. Transport mode only encrypts the payload, and AH provides integrity without encryption.

714
MCQeasy

An organization wants to implement continuous compliance monitoring for PCI DSS. Which of the following tools would be MOST effective for this purpose?

A.Encryption solution
B.Network firewall
C.Vulnerability scanner
D.SIEM system
AnswerD

A SIEM system continuously ingests and correlates log data from cardholder-data environment systems, generating real-time alerts against PCI DSS controls such as access monitoring, file integrity and log review. This satisfies the stem's continuous compliance monitoring requirement, unlike point-in-time assessment tools that only snapshot posture periodically.

Why this answer

A SIEM (Security Information and Event Management) system is the most effective tool for continuous compliance monitoring because it aggregates and correlates log data from across the environment in real time, providing ongoing visibility into security events and control effectiveness. For PCI DSS, this directly supports requirements like 10.x (logging and monitoring), 11.5 (change detection), and 12.10 (incident response), enabling automated alerts and evidence collection. Unlike point-in-time tools, a SIEM continuously ingests data, making it ideal for demonstrating sustained compliance rather than periodic snapshots.

Exam trap

CAS-005 often tests the distinction between tools that provide point-in-time assessments (like vulnerability scanners) and those that enable continuous monitoring (like SIEM), so candidates may incorrectly choose a scanner because it sounds security-focused.

How to eliminate wrong answers

Option A is wrong because an encryption solution protects data confidentiality but does not monitor compliance status or generate continuous evidence across PCI DSS controls. Option B is wrong because a network firewall enforces perimeter access rules but provides only limited, static logging and cannot correlate events across systems for continuous compliance. Option C is wrong because a vulnerability scanner performs periodic assessments (e.g., quarterly external scans per PCI DSS 11.2.2) and does not offer real-time, continuous monitoring of the overall control environment.

715
MCQeasy

Which of the following is the BEST practice for securely storing secrets (e.g., database passwords) in a cloud-native application?

A.Embed the secrets in the application's source code
B.Store them in environment variables
C.Use a secrets management service with encryption and access policies
D.Store them in a configuration file with restricted file permissions
AnswerC

Why this answer

Cloud-native applications should rely on a dedicated secrets management service (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) that encrypts secrets at rest and in transit, enforces fine-grained access policies via IAM, and supports automatic rotation. This approach decouples secrets from code and infrastructure, eliminating the risks of exposure through version control, logs, or misconfigured permissions.

Exam trap

The CAS-004 exam often tests the misconception that environment variables are a secure storage method because they are not in source code, but the trap is that they are still plaintext and accessible via runtime introspection, logging, or orchestration APIs, lacking the encryption and access control of a dedicated secrets manager.

Why the other options are wrong

A

Hardcoding secrets exposes them in version control and to anyone with code access.

B

Environment variables can be leaked through debugging interfaces or process listings; they are not encrypted.

D

File permissions can be bypassed; configuration files are often not encrypted.

716
MCQhard

A security analyst observes that SSH connections to the server are failing, but HTTP and HTTPS traffic works. Based on the exhibit, what is the most likely cause?

A.The HTTPS rule is overriding the SSH rule.
B.The SSH service is being blocked by a firewall rule that drops TCP port 22 traffic.
C.The SSH service is only allowed from the 10.0.0.0/8 subnet.
D.The SSH service is misconfigured and not listening on the correct interface.
AnswerB

SSH uses TCP port 22, whereas HTTP and HTTPS use ports 80 and 443. A firewall rule dropping TCP 22 blocks only SSH while leaving web traffic unaffected, matching the stem's symptom of failing SSH with working HTTP and HTTPS.

Why this answer

The exhibit shows a firewall rule that explicitly drops TCP port 22 traffic, which is the default port for SSH. Since HTTP (port 80) and HTTPS (port 443) are unaffected, the issue is isolated to SSH. This rule is the most direct cause of the connection failures, as it blocks all SSH traffic regardless of source or destination.

Exam trap

The trap here is that candidates may assume SSH is failing due to a service misconfiguration (Option D) or an overly restrictive allow rule (Option C), but the exhibit clearly shows a specific drop rule for port 22, which is the definitive cause.

How to eliminate wrong answers

Option A is wrong because HTTPS (port 443) and SSH (port 22) are different protocols and ports; firewall rules are evaluated in order, and unless the HTTPS rule explicitly matches SSH traffic (which it does not), it cannot override the SSH rule. Option C is wrong because the exhibit does not show any source subnet restriction for SSH; the rule simply drops all TCP port 22 traffic without any allow condition for 10.0.0.0/8. Option D is wrong because if the SSH service were misconfigured to listen on the wrong interface, the failure would be at the application layer, but the firewall rule explicitly drops the traffic before it reaches the SSH daemon, making a misconfiguration irrelevant to the observed symptom.

717
MCQmedium

A security architect is designing a zero-trust network architecture. Which of the following is a fundamental principle of zero trust?

A.Place all resources on the internal network and rely on perimeter firewalls.
B.Authenticate and authorize every device and user for every resource access, and encrypt all communication.
C.Implement VLANs to separate traffic based on user roles.
D.Use a VPN to secure all remote access to the corporate network.
AnswerB

Authenticating and authorising every device and user per resource access satisfies zero trust's verify-explicitly principle, replacing implicit trust from network location. Continuous per-request evaluation, combined with encryption of all communication, enforces least-privilege access and assumes breach, directly meeting the scenario's requirement for a fundamental zero-trust principle.

Why this answer

Zero trust is built on the principle of 'never trust, always verify.' This means every device and user must be authenticated and authorized for each resource access, regardless of network location, and all communication should be encrypted to protect data in transit. This eliminates implicit trust based on network perimeter and enforces least-privilege access.

Exam trap

Candidates often mistakenly believe that network segmentation (VLANs) or VPNs achieve zero trust, but zero trust requires per-session authentication, authorization, and encryption for every access regardless of network location.

How to eliminate wrong answers

Option A is wrong because placing all resources on the internal network and relying on perimeter firewalls assumes a trusted internal network, which violates the zero-trust principle of eliminating implicit trust. Option C is wrong because implementing VLANs to separate traffic based on user roles provides network segmentation but does not enforce per-request authentication, authorization, or encryption, which are core to zero trust. Option D is wrong because using a VPN secures remote access but still creates a trusted tunnel into the network, contradicting the zero-trust requirement to authenticate and authorize every access attempt regardless of source.

718
MCQmedium

A security architect is designing a secure connection between an on-premises data center and a cloud provider's virtual network. The connection must be private, low-latency, and not traverse the public internet. Which solution should they recommend?

A.Software-Defined WAN (SD-WAN)
B.Cloud Access Security Broker (CASB)
C.Site-to-site VPN over the internet
D.Direct Connect / ExpressRoute
AnswerD

Direct Connect and ExpressRoute provide dedicated private circuits between on-premises infrastructure and the cloud provider's network, bypassing the public internet entirely. This satisfies the private, low-latency, non-internet-traversing constraints that site-to-site VPN over the internet cannot guarantee.

Why this answer

Direct Connect (AWS) and ExpressRoute (Azure) are dedicated private circuits from the on-premises data center to the cloud provider's network, providing low-latency, high-bandwidth connectivity that never traverses the public internet. This matches all three stated requirements: private, low-latency, and no public internet traversal.

Exam trap

The trap is assuming 'VPN = private' — candidates select site-to-site VPN because it is encrypted, but encryption does not change the fact that IPsec VPN traffic still traverses the public internet, which the question explicitly forbids.

How to eliminate wrong answers

Option A is wrong because SD-WAN optimizes and manages WAN traffic across multiple transports (often including the internet) but does not inherently provide a private, non-internet path to a specific cloud VNet. Option B is wrong because a CASB is a policy/visibility control for cloud service usage, not a network transport mechanism. Option C is wrong because a site-to-site VPN over the internet is encrypted but still traverses the public internet, violating the 'not traverse the public internet' requirement and typically adding latency variability.

719
MCQeasy

A company's development team uses a CI/CD pipeline hosted in a public cloud. The pipeline builds container images, pushes them to a private registry, and deploys them to a Kubernetes cluster. A security engineer must ensure that only signed and vulnerability-scanned images are deployed. The engineer has configured the registry to require signatures and the CI/CD pipeline to scan images. However, deployments are still failing because unsigned images are being pulled. The engineer discovers that developers can push images directly to the registry bypassing the CI/CD pipeline and that Kubernetes nodes can pull images without signature verification. Which of the following should the engineer implement to enforce image signing and scanning?

A.Implement a manual approval step in the pipeline for each deployment.
B.Use network policies to block all outbound traffic from developer workstations to the container registry.
C.Restrict registry write access to the CI/CD service account and enable image signature verification via admission controller in Kubernetes.
D.Configure the CI/CD pipeline to perform vulnerability scanning after every build.
AnswerC

Restricting registry write access to the CI/CD service account prevents developers bypassing the pipeline, while a Kubernetes admission controller rejects unsigned images at deploy time. Together these enforce signing and scanning, closing both gaps the stem describes.

Why this answer

It addresses both root causes: restricting registry write access to only the CI/CD service account prevents developers from bypassing the pipeline, and enabling image signature verification via an admission controller (e.g., using Kubernetes ImagePolicyWebhook or a tool like Cosign with OCI signatures) ensures that only signed and scanned images are allowed to run in the cluster. This combination enforces the security policy at both the registry and the cluster level, closing the gaps identified in the scenario.

Exam trap

The trap here is that candidates often focus only on the CI/CD pipeline (e.g., scanning or approvals) and overlook the need to restrict direct registry access and enforce signature verification at the cluster level, which are the two distinct vulnerabilities described in the scenario.

How to eliminate wrong answers

Option A is wrong because a manual approval step in the pipeline does not prevent developers from pushing unsigned images directly to the registry, nor does it enforce signature verification at the Kubernetes level; it only adds a human gate in the CI/CD process. Option B is wrong because network policies blocking outbound traffic from developer workstations to the registry would not stop developers from pushing images via other means (e.g., through a jump host or VPN), and it does not address the lack of signature verification on Kubernetes nodes. Option D is wrong because configuring the pipeline to perform vulnerability scanning after every build does not prevent unsigned images from being deployed; scanning alone does not enforce signature verification, and it does not restrict direct pushes to the registry or enforce admission control.

720
Multi-Selecteasy

An IoT device manufacturer wants to ensure the security of over-the-air (OTA) firmware updates. Which TWO measures are essential to protect the update process?

Select 2 answers
A.Sign the firmware with a trusted code signing certificate
B.Use a simple checksum for integrity verification
C.Implement a secure boot chain that verifies the signature before applying the update
D.Encrypt the firmware using a hardcoded key
E.Allow firmware downgrades to previous versions
AnswersA, C

Code signing binds the firmware to a trusted publisher's private key, so devices can verify authenticity and integrity before flashing. This directly satisfies the OTA constraint: preventing attackers from pushing tampered or malicious firmware images to fielded devices.

Why this answer

Option A is correct because signing the firmware with a trusted code signing certificate lets the device verify authenticity and integrity via the vendor's public key, ensuring the OTA image genuinely originates from the manufacturer and has not been tampered with. Option C is correct because a secure boot chain validates that signature against a hardware-rooted trust anchor before the update is applied, preventing malicious or corrupted firmware from ever executing. Together, signing plus signature verification in a secure boot chain form the essential cryptographic trust path for OTA updates.

Option B is not sufficient because a simple checksum detects only accidental corruption, not deliberate tampering, since it is not cryptographically bound to a secret or key. Option D is wrong because a hardcoded key can be extracted from the device and reused by attackers, and encryption alone does not prove authenticity. Option E is wrong because permitting downgrades enables rollback attacks that reintroduce known vulnerabilities.

721
MCQhard

A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?

A.AWS Direct Connect
B.Site-to-site VPN over the internet
C.AWS Client VPN
D.AWS Transit Gateway with internet gateway
AnswerA

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet entirely. This satisfies both constraints in the stem: low latency, since traffic avoids internet routing variability, and security, since data never traverses public infrastructure. Site-to-Site VPN would encrypt traffic but still traverse the internet, failing the no-internet requirement.

Why this answer

AWS Direct Connect provides dedicated private network connectivity from on-premises to AWS, offering low latency and security without internet exposure.

722
MCQhard

A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?

A.Ensuring that data subjects can exercise their rights upon request
B.Appointing a Data Protection Officer to oversee all privacy matters
C.Embedding privacy controls into the design and architecture of systems and processes
D.Conducting a privacy impact assessment after a data breach
AnswerC

Privacy by design means data protection controls are built into system architecture and business processes from the outset, not bolted on afterwards. Embedding them at design time satisfies GDPR's requirement that protection be integral to processing, covering minimisation, purpose limitation and default settings.

Why this answer

Privacy by design is a foundational GDPR principle (Article 25) that requires data protection measures to be integrated into the design and architecture of systems and business processes from the outset, rather than added as an afterthought. This means embedding privacy controls such as data minimization, pseudonymization, and access controls into the very structure of applications and workflows. Option C accurately captures this proactive, architecture-level approach.

Exam trap

The trap is confusing privacy by design with other GDPR principles like data subject rights or DPO appointment; candidates may pick A because it sounds like a privacy control, but privacy by design is specifically about proactive embedding into system architecture.

How to eliminate wrong answers

Option A is wrong because ensuring data subjects can exercise their rights (access, erasure, etc.) is a separate GDPR requirement about data subject rights, not the definition of privacy by design. Option B is wrong because appointing a Data Protection Officer is an organizational governance requirement under GDPR for certain organizations, but it is not the concept of privacy by design. Option D is wrong because conducting a privacy impact assessment after a data breach is reactive and contrary to the proactive nature of privacy by design; GDPR requires DPIAs before processing in high-risk cases, not after a breach.

723
MCQmedium

During a merger, two companies need to integrate their networks securely. Company A uses RFC 1918 addresses (10.0.0.0/8) and Company B also uses 10.0.0.0/8. Which architectural solution prevents routing conflicts and maintains security?

A.Configure a site-to-site VPN with no address translation
B.Enable direct BGP peering between the two networks
C.Implement a firewall between the networks and allow all traffic
D.Deploy network address translation (NAT) on the border routers to translate one company's addresses to a unique range
AnswerD

Overlapping RFC 1918 ranges cannot coexist in a routed topology, so NAT on the border routers rewrites one company's 10.0.0.0/8 addresses into a unique range. This removes the routing ambiguity while preserving address hiding and security at the boundary.

Why this answer

Both companies use the same RFC 1918 address space (10.0.0.0/8), which would cause routing conflicts if directly connected. Deploying NAT on the border routers translates one company's overlapping addresses to a unique range (e.g., 172.16.0.0/12 or a public IP block), eliminating IP collisions while maintaining security through stateful inspection or ACLs. This allows the merged networks to communicate without renumbering either company's internal infrastructure.

Exam trap

The trap here is that candidates assume a site-to-site VPN (Option A) inherently resolves overlapping IPs, but VPNs only encrypt traffic—they do not translate addresses, so routing conflicts persist without NAT or renumbering.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN with no address translation would directly expose the overlapping 10.0.0.0/8 addresses, causing routing conflicts and packet misdelivery. Option B is wrong because enabling direct BGP peering between the two networks would advertise the same 10.0.0.0/8 prefixes, leading to route flapping, black holes, and potential loops. Option C is wrong because implementing a firewall between the networks and allowing all traffic does not resolve the underlying IP overlap; traffic would still be dropped or misrouted due to duplicate addresses, and it violates the principle of least privilege.

724
MCQhard

A security engineer is writing a Python script to automate the revocation of compromised certificates using the ACME protocol. The script uses the `acme` library and requires secure credential storage. Which method is MOST appropriate for storing the ACME account private key used for authentication?

A.Store the key in the operating system's keychain (e.g., macOS Keychain, Windows Credential Manager) or a HSM
B.Store the key in a configuration file with 600 permissions
C.Embed the key directly in the script as a string variable
D.Store the key in an environment variable
AnswerA

Why this answer

The ACME account private key is a highly sensitive cryptographic credential used to authenticate against the ACME server (RFC 8555). Storing it in the OS keychain or a Hardware Security Module (HSM) provides encryption at rest, access control via OS-level permissions, and protection against accidental exposure. This aligns with the principle of least privilege and secure key management required for automation scripts handling certificate revocation.

Exam trap

The CAS-004 exam often tests the misconception that file permissions (e.g., 600) or environment variables are sufficient for secure credential storage, when in fact they lack encryption at rest and are vulnerable to broader system-level access.

Why the other options are wrong

B

The key remains in plaintext on disk; even with restricted permissions, it can be read by any process running as the same user or through privilege escalation.

C

The key is exposed in source code, version control, and accessible to anyone who can read the script.

D

Environment variables are often written to logs, process dumps, and are not encrypted at rest; they are not designed for long-term cryptographic key storage.

725
Multi-Selecteasy

A risk assessment report is being prepared for senior management. Which TWO of the following should be included to effectively communicate risk?

Select 2 answers
A.Remediation deadlines
B.Risk register with scores
C.Executive summary
D.Names of employees responsible
E.Detailed control configurations
AnswersB, C

A risk register with scores presents each identified risk alongside its likelihood and impact rating, giving senior management a prioritised, comparable view. This satisfies the requirement to communicate risk effectively, supporting informed decisions on acceptance, mitigation and resource allocation.

Why this answer

Option B (Risk register with scores) is correct because a risk register provides senior management with a structured, prioritized view of identified risks, their likelihood and impact scores, and current status, which is essential for informed decision-making at an executive level. Option C (Executive summary) is correct because senior management needs a concise, high-level overview of the most significant risks, key findings, and recommended actions, enabling them to grasp the risk posture quickly without wading through technical detail. Option A (Remediation deadlines) is not appropriate as a primary communication element for senior management, since deadlines are operational details better suited to tactical plans or project schedules rather than strategic risk communication.

Option D (Names of employees responsible) is not included because attributing risk ownership to specific individuals is a management/accountability detail that does not effectively convey the nature or severity of risk to executives. Option E (Detailed control configurations) is not included because granular technical settings are far too low-level for senior management and belong in technical documentation or audit workpapers, not executive risk reporting.

Exam trap

In risk assessment reports for senior management, it is important to include summary-level strategic information such as the risk register with scores and an executive summary, rather than overly detailed operational items like remediation deadlines or employee names.

726
MCQhard

A cloud security architect is designing a multi-region active-active application. The application must maintain high availability even if an entire AWS region fails. Which architecture BEST meets this requirement?

A.Active-active in one region with auto scaling
B.Deploy identical stacks in two regions with Route 53 weighted routing and DynamoDB global tables
C.Single region with multiple AZs and RDS Multi-AZ
D.Two regions with active-passive failover using Route 53 health checks
AnswerB

Identical stacks in two regions with Route 53 weighted routing distribute traffic across regions, while DynamoDB global tables replicate data multi-directionally, so either region can serve writes if the other fails. This satisfies the requirement to survive a complete regional outage.

Why this answer

Deploying identical application stacks in two AWS regions with Route 53 weighted routing distributes traffic evenly across both regions, and DynamoDB global tables provide multi-region, multi-master replication with eventual consistency, ensuring the application remains fully active and available even if an entire AWS region fails. This architecture meets the active-active and region-failure requirement without relying on failover or single-region dependencies.

Exam trap

The primary trap in this question is that candidates may confuse multi-AZ or single-region high availability with true multi-region active-active resilience, or assume that Route 53 health checks alone make an architecture active-active when they are often used for failover (active-passive).

How to eliminate wrong answers

Option A is wrong because active-active in a single region with auto scaling cannot survive the failure of an entire AWS region; it only handles scaling within that region. Option C is wrong because a single region with multiple AZs and RDS Multi-AZ protects against Availability Zone failures but not against a complete region outage. Option D is wrong because active-passive failover using Route 53 health checks is not active-active; it introduces a passive standby that does not serve traffic until failover, violating the requirement for continuous active-active operation.

727
MCQmedium

A company is adopting a DevOps model and wants to integrate security into CI/CD pipelines. Which of the following is the MOST effective approach?

A.Annual vulnerability scans
B.Post-deployment security testing
C.Manual security reviews before each release
D.Automated security scanning in the pipeline with fail-fast
AnswerD

Automation with fail-fast provides immediate feedback and prevents vulnerable code from progressing.

Why this answer

Automated security scanning in the pipeline with fail-fast is the most effective approach because it integrates security checks (e.g., SAST, DAST, dependency scanning) directly into the CI/CD workflow, enabling immediate detection and blocking of vulnerabilities before they reach production. This aligns with DevSecOps principles by shifting security left, reducing remediation costs, and ensuring that insecure code fails the build automatically, preventing deployment of vulnerable artifacts.

Exam trap

The CAS-004 exam often tests the misconception that post-deployment testing (Option B) is sufficient for security, but the trap here is that candidates overlook the fundamental DevSecOps principle of shifting security left, where automated fail-fast scanning in the pipeline is the only approach that prevents vulnerable code from ever reaching production.

How to eliminate wrong answers

Option A is wrong because annual vulnerability scans are far too infrequent for a DevOps model with frequent releases, leaving critical vulnerabilities undetected for months and failing to provide real-time feedback to developers. Option B is wrong because post-deployment security testing detects vulnerabilities only after code is already in production, increasing risk and remediation cost, and violates the shift-left security principle. Option C is wrong because manual security reviews before each release introduce human error, are not scalable for rapid CI/CD pipelines, and cannot keep pace with the speed of automated builds and deployments.

728
MCQhard

Refer to the exhibit. A cloud security engineer is reviewing an AWS S3 bucket policy. What security issue does the policy contain?

A.No server-side encryption is specified
B.Public read access is allowed
C.No version ID is specified in the resource
D.No logging is enabled for the bucket
AnswerB

The bucket policy grants read permission to the Everyone or AllUsers principal, meaning any unauthenticated internet user can list and download objects. That wildcard principal is the specific flaw, exposing stored data publicly regardless of other conditions.

Why this answer

The S3 bucket policy grants read access to all principals, typically via a Principal of "*" combined with an s3:GetObject action, which exposes every object in the bucket to anonymous or any AWS account. This is the classic public-read misconfiguration that has caused numerous high-profile data breaches, so the identified security issue is public read access.

Exam trap

CAS-005 often tests whether candidates can distinguish security issues that belong in a bucket policy (public access, overly broad principals) from those configured elsewhere (encryption, logging, versioning), tricking them into selecting non-policy settings.

How to eliminate wrong answers

Option A is wrong because server-side encryption is configured on the bucket or object level (default encryption, SSE-S3/SSE-KMS), not in a bucket policy — its absence from the policy does not indicate a policy flaw. Option C is wrong because version IDs are only required in a resource ARN when referencing a specific object version; omitting them is normal and not a security issue. Option D is wrong because access logging is enabled via bucket properties or a separate logging configuration, not through the bucket policy, so its absence from the policy is not a policy defect.

729
MCQmedium

A security architect is designing a defense-in-depth strategy for a web application. Which combination of controls provides overlapping protection against SQL injection attacks?

A.Encryption and hashing
B.Input validation and parameterized queries
C.Intrusion detection system (IDS) and antivirus
D.Web application firewall (WAF) and network segmentation
AnswerB

Input validation rejects malformed or suspicious input at the boundary, while parameterised queries ensure user-supplied values are treated as data, never executable SQL. Together they provide overlapping defence: if validation is bypassed, parameterisation still prevents injected statements from altering query structure.

Why this answer

Input validation and parameterized queries provide overlapping, defense-in-depth protection against SQL injection: input validation rejects malformed or malicious input at the application boundary, while parameterized queries ensure user input is treated as data, not executable SQL, even if validation is bypassed. Together they address the root cause of SQLi at multiple layers.

Exam trap

CAS-005 often tests defense-in-depth by presenting perimeter controls (WAF, IDS) as tempting answers — candidates must recognize that overlapping protection against a specific application flaw requires controls at the application layer, not just the network layer.

How to eliminate wrong answers

Option A is wrong because encryption and hashing protect data confidentiality and integrity at rest or in transit, but they do not prevent SQL injection — an attacker can still inject SQL into an encrypted database connection. Option C is wrong because IDS and antivirus are detective/preventive controls for network and endpoint threats, not application-layer injection flaws; IDS may alert after the fact but does not stop SQLi. Option D is wrong because a WAF and network segmentation are perimeter controls — a WAF can block known SQLi patterns but is bypassable with obfuscation, and network segmentation does not address the application's query construction flaw, so they do not provide the overlapping application-layer protection the question requires.

730
MCQhard

A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?

A.TTP-driven hunting by analyzing adversary behaviors mapped to the ATT&CK framework
B.Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
C.Automated hunting using SIEM correlation rules that trigger on known malicious file hashes
D.IoC-driven hunting using known indicators of compromise from open-source feeds
AnswerB

Hypothesis-driven hunting tests the specific process injection technique by examining memory and process activity for injected code, hollowed processes or anomalous API calls. This targeted approach suits an APT that evades signature-based defences, since it searches for behavioural evidence rather than known indicators.

Why this answer

Hypothesis-driven hunting is the most appropriate because the analyst has a specific, testable hypothesis: the attacker is using process injection, a known ATT&CK technique (T1055). This methodology involves proactively searching for evidence of that technique—such as anomalous memory allocations, thread execution, or API calls—rather than waiting for alerts. It directly addresses the scenario where signature-based defenses have failed, as it focuses on behavioral artifacts rather than static indicators.

Exam trap

CAS-005 often tests the distinction between reactive IoC/signature-based hunting and proactive hypothesis-driven hunting, tricking candidates into choosing familiar but ineffective methods like SIEM rules or IoC feeds when the scenario explicitly states evasion of traditional defenses.

How to eliminate wrong answers

Option A is wrong because TTP-driven hunting is broader and focuses on mapping adversary behaviors to multiple techniques, not a single hypothesized technique; it lacks the specificity of a hypothesis-driven approach. Option C is wrong because automated hunting with SIEM rules based on known malicious file hashes is essentially signature-based detection, which the scenario states has already been evaded. Option D is wrong because IoC-driven hunting relies on known indicators (e.g., IPs, domains, hashes) from feeds, which are reactive and easily bypassed by APTs, contrary to the proactive, technique-focused hunt needed here.

731
Multi-Selectmedium

A financial institution is implementing a secure software development lifecycle (SSDLC) for a new web application that will handle sensitive transactions. The security architect must ensure that application security testing is integrated into the development process. Which THREE testing techniques should be used to identify vulnerabilities early and throughout the lifecycle? (Choose THREE.)

Select 3 answers
A.Static Application Security Testing (SAST)
B.Runtime Application Self-Protection (RASP)
C.Interactive Application Security Testing (IAST)
D.Dynamic Application Security Testing (DAST)
E.Threat modeling
AnswersA, C, D

SAST analyses source code without executing it, flagging injection flaws, insecure patterns and coding errors during development. This satisfies the SSDLC requirement to identify vulnerabilities early, before code reaches testing or production, reducing remediation cost for the sensitive-transaction application.

Why this answer

SAST (A) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find flaws such as injection patterns, insecure coding, and hardcoded secrets early in the SSDLC, even in CI pipelines. IAST (C) is correct because it instruments the running application and combines static and dynamic analysis to detect vulnerabilities during functional testing with high accuracy and code-level context, fitting continuous integration. DAST (D) is correct because it tests the deployed application from the outside by sending crafted requests to find runtime and configuration issues such as SQL injection, XSS, and authentication flaws in the running web app.

RASP (B) is not a testing technique but a runtime protection mechanism that detects and blocks attacks in production, so it does not identify vulnerabilities early in development. Threat modeling (E) is a design-phase risk analysis activity, not an application security testing technique, so it does not satisfy the requirement for testing throughout the lifecycle.

Exam trap

The trap is treating RASP as a testing tool because it shares the 'application security' label — candidates must distinguish runtime protection (RASP) from vulnerability discovery techniques (SAST/DAST/IAST).

732
MCQmedium

A company uses a multi-cloud strategy with workloads in AWS and Azure. They need a centralized solution to enforce consistent security policies across both cloud environments. Which type of tool should they deploy?

A.Cloud Access Security Broker (CASB)
B.Cloud Security Posture Management (CSPM)
C.Cloud Workload Protection Platform (CWPP)
D.Security Information and Event Management (SIEM)
AnswerB

CSPM continuously assesses configurations across AWS and Azure against a unified policy baseline, detecting misconfigurations and compliance drift in both environments. This directly satisfies the stem's requirement for centralised, consistent policy enforcement spanning multiple clouds, since CSPM ingests native APIs from each provider rather than relying on a single-vendor security stack.

Why this answer

CSPM continuously monitors cloud configurations against security benchmarks and compliance frameworks across multiple providers, providing a centralized view and policy enforcement for misconfigurations, drift, and compliance violations in AWS and Azure. This directly addresses the need for consistent security policy enforcement across both clouds.

Exam trap

The trap is conflating CSPM with CWPP — candidates pick CWPP because it also 'secures the cloud,' but the question is about configuration posture and policy consistency, not workload runtime protection.

How to eliminate wrong answers

Option A is wrong because a CASB focuses on governing SaaS and cloud service usage (shadow IT, DLP, access control) rather than assessing IaaS/PaaS configuration posture across providers. Option C is wrong because CWPP protects workloads (VMs, containers, serverless) at runtime — vulnerability scanning, EDR, and workload firewalling — not the configuration posture of the cloud control plane. Option D is wrong because a SIEM aggregates and correlates logs for detection and response; it does not enforce configuration policies or assess posture across clouds.

733
MCQmedium

A company's security policy requires all sensitive data to be encrypted at rest. However, a business unit requests an exception to store certain data unencrypted due to performance constraints. Which document should govern the exception process?

A.Security policy
B.Risk treatment plan
C.Acceptable use policy
D.Data classification standard
AnswerA

A security policy defines mandatory controls and the formal exception process, so it governs deviations from the encryption-at-rest requirement. It specifies who may approve exceptions, the compensating controls and review periods needed, satisfying the stem's constraint that an exception be authorised rather than informally granted by the business unit.

Why this answer

The security policy is the overarching document that defines the organization's security requirements and typically includes provisions for exceptions, including the process for requesting, reviewing, and approving exceptions to policy. Since the requirement to encrypt sensitive data at rest originates from the security policy, any exception to that requirement must be governed by the same policy's exception process. The security policy should specify who can approve exceptions, under what conditions, and for how long.

Exam trap

The trap is selecting a more specific document like the risk treatment plan or data classification standard, but the question asks which document governs the exception process — that is the security policy itself, as it defines the rules and the mechanism for exceptions.

How to eliminate wrong answers

Option B is wrong because a risk treatment plan documents how identified risks will be managed (mitigated, transferred, accepted, etc.), but it does not govern the exception process itself; it may reference exceptions but is not the governing document. Option C is wrong because an acceptable use policy defines how users may use organizational assets and resources, not how to handle exceptions to encryption requirements. Option D is wrong because a data classification standard defines categories of data and handling requirements, but it does not prescribe the exception process for policy deviations.

734
MCQmedium

A security architect is designing a network for a financial services firm. The firm requires that all data in transit between its internal microservices be encrypted and mutually authenticated, but the services run in a containerized environment where static IP addresses are not available. Which of the following is the MOST appropriate solution to meet these requirements?

A.Deploy a service mesh with mutual TLS (mTLS) between sidecar proxies.
B.Implement IPsec tunnels between each container host.
C.Configure a VPN concentrator that all microservices connect to for encrypted communication.
D.Use TLS with server-side certificates only for each microservice.
AnswerA

A service mesh with mTLS provides encryption and mutual authentication for service-to-service communication. It uses sidecar proxies to manage certificates and identity without relying on static IPs, which suits containerized environments. This directly meets the requirements for encrypted, mutually authenticated traffic in a dynamic infrastructure.

Why this answer

A service mesh with mutual TLS (mTLS) provides encryption and mutual authentication for service-to-service communication. It uses sidecar proxies to manage certificates and identity without relying on static IPs, which suits containerized environments. This directly meets the requirements for encrypted, mutually authenticated traffic in a dynamic infrastructure.

Exam trap

The trap here is assuming that any encryption method (like IPsec or server-side TLS) is sufficient, but the requirement for mutual authentication and dynamic environments points specifically to mTLS in a service mesh.

735
MCQhard

A security analyst is using a SOAR platform to automate response to phishing emails reported by users. The playbook should perform the following actions in order: (1) extract indicators from the email, (2) query threat intelligence feeds for reputation, (3) if malicious, block the sender's domain at the email gateway and delete the email from all user inboxes. Which type of playbook step is most appropriate for step 3?

A.Playbook trigger
B.Output step
C.Action step
D.Conditional step
AnswerC

Blocking the sender's domain at the gateway and deleting the email from all inboxes are automated response actions executed against infrastructure. An action step performs these containment tasks, satisfying the playbook requirement that step 3 remediate confirmed-malicious email rather than merely enrich or decide.

Why this answer

Step 3 involves performing concrete actions: blocking the sender's domain and deleting the email. In SOAR playbooks, these are action steps that execute response activities.

Exam trap

The trap is confusing conditional step with action step because step 3 is preceded by a condition ('if malicious'), but the step itself is the action taken, not the evaluation.

How to eliminate wrong answers

Option A (playbook trigger) is wrong because a trigger initiates the playbook, not an intermediate response action. Option B (output step) is wrong because output steps present results or notifications, not perform blocking or deletion. Option D (conditional step) is wrong because a conditional step evaluates logic (e.g., if malicious), but step 3 is the execution after the condition is met.

736
MCQmedium

A security architect at a healthcare provider must ensure that electronic protected health information (ePHI) stored in an on-premises Microsoft SQL Server database is unreadable if the physical media is stolen. The organization has strict performance requirements and cannot tolerate application changes or key management outside its own hardware security modules (HSMs). Which SQL Server feature BEST meets these requirements?

A.Dynamic Data Masking (DDM)
B.Always Encrypted with secure enclaves
C.Transparent Data Encryption (TDE)
D.Row-Level Security (RLS)
AnswerC

TDE performs real-time I/O encryption and decryption of the data and log files at the page level, protecting data at rest without application changes. It uses a database encryption key protected by a certificate stored in the master database, and the certificate can be backed by an HSM via Extensible Key Management, satisfying the key custody requirement while maintaining performance.

Why this answer

Transparent Data Encryption (TDE) encrypts the database files at rest without requiring application changes and supports key protection through an HSM via Extensible Key Management. The other options either require application modifications or do not encrypt data at rest, leaving the stolen media scenario unresolved.

Exam trap

The trap here is assuming that any SQL Server security feature that mentions encryption, such as Always Encrypted, will satisfy a data-at-rest requirement without considering application changes or key custody constraints.

737
MCQhard

A security analyst is reviewing a third-party assessment report and notes that the vendor's encryption algorithms are outdated. The contract requires the vendor to follow industry best practices. Which of the following is the BEST response?

A.Conduct a penetration test on the vendor's system.
B.Request the vendor to upgrade encryption algorithms to current standards.
C.Terminate the contract immediately.
D.Accept the risk because the vendor is technically compliant with the contract.
AnswerB

Requesting an upgrade directly addresses the outdated algorithms, satisfying the contract's industry best-practices requirement. Unlike compensating controls or risk acceptance, remediation eliminates the weak cryptography at source. This is the proportionate response when a vendor's assessed posture breaches a contractual security obligation, restoring compliance without severing the relationship.

Why this answer

The contract requires the vendor to follow industry best practices, and outdated encryption algorithms (e.g., DES, RC4, or 3DES) are no longer considered secure or compliant with standards like NIST SP 800-131A or PCI DSS. The best response is to formally request the vendor to upgrade to current, approved algorithms such as AES-256 or ChaCha20, as this directly addresses the non-compliance with the contractual requirement. This action aligns with the governance and risk management process of enforcing contractual security obligations.

Exam trap

The trap here is that candidates may confuse 'technically compliant' with 'secure' and choose to accept the risk (Option D), failing to recognize that outdated encryption algorithms violate the contractual requirement to follow industry best practices, which is a governance and compliance issue, not just a technical one.

How to eliminate wrong answers

Option A is wrong because conducting a penetration test on the vendor's system would test for exploitable vulnerabilities but does not directly enforce the contractual requirement to use current encryption standards; it is a detective control, not a corrective action. Option C is wrong because terminating the contract immediately is a disproportionate response without first attempting to remediate the issue through a formal request, and it could cause unnecessary business disruption. Option D is wrong because accepting the risk is inappropriate when the vendor is not technically compliant with the contract's requirement to follow industry best practices; outdated encryption algorithms are a known security risk and violate the agreement.

738
Multi-Selectmedium

A small business is implementing a privacy impact assessment (PIA) for a new application that processes personal data of EU citizens. Which TWO of the following are required under GDPR?

Select 2 answers
A.Obtain approval from a data protection authority before processing
B.Appoint a data protection officer (DPO)
C.Publish the PIA on the company website
D.Describe the processing operations and purposes
E.Assess the necessity and proportionality of the processing
AnswersD, E

Article 35(7)(a) of GDPR requires the data protection impact assessment to contain a systematic description of the processing operations and the purposes of the processing. This is a mandatory DPIA content element, so describing operations and purposes satisfies that requirement.

Why this answer

Under GDPR Article 35, a Data Protection Impact Assessment (DPIA) must contain a systematic description of the envisaged processing operations and the purposes of the processing, which is exactly what option D requires, so D is correct. Article 35(7)(b) also mandates an assessment of the necessity and proportionality of the processing operations in relation to their purposes, making option E correct. Option A is wrong because GDPR does not generally require prior DPA approval before processing; prior consultation under Article 36 is only needed when a DPIA indicates high residual risk that cannot be mitigated.

Option B is wrong because a DPO is mandatory only under Article 37 conditions (large-scale regular monitoring, large-scale special-category data, or public authority), not for every PIA. Option C is wrong because GDPR does not require publishing the DPIA on a website; the DPIA is documented and made available to the supervisory authority on request.

Exam trap

CAS-005 often tests whether candidates conflate DPIA requirements with DPO appointment or DPA consultation, so picking 'appoint a DPO' or 'obtain DPA approval' reflects a misunderstanding of when those obligations actually trigger.

739
MCQhard

A security team is analyzing a suspicious binary using static analysis. They run the strings command and observe references to 'CreateRemoteThread' and 'WriteProcessMemory'. Which technique is the binary likely employing?

A.DLL sideloading
B.Reflective DLL loading
C.Process injection
D.API hooking
AnswerC

CreateRemoteThread and WriteProcessMemory are the canonical Windows API pair for injecting code into another process's address space. Their presence in the import table indicates the binary writes a payload into a remote process and starts it via a new thread, which is process injection.

Why this answer

The presence of 'CreateRemoteThread' and 'WriteProcessMemory' in the strings output strongly indicates process injection. These Windows API functions are commonly used together to inject code into another process: WriteProcessMemory writes the malicious code into the target process's memory, and CreateRemoteThread executes it.

Exam trap

CAS-005 often tests the identification of techniques based on API calls, and candidates may confuse process injection with DLL sideloading or reflective loading, especially if they are not familiar with the specific API combinations.

How to eliminate wrong answers

Option A is wrong because DLL sideloading involves placing a malicious DLL alongside a legitimate executable to be loaded, and it typically does not require CreateRemoteThread or WriteProcessMemory. Option B is wrong because reflective DLL loading is a technique where a DLL loads itself into memory without using the Windows loader, often using functions like VirtualAlloc and LoadLibrary, but not necessarily CreateRemoteThread and WriteProcessMemory. Option D is wrong because API hooking involves intercepting calls to functions, often using techniques like IAT hooking or inline hooking, and does not typically use CreateRemoteThread and WriteProcessMemory for the hooking itself.

740
MCQeasy

A security architect is designing a VPN that requires both authentication and encryption. Which IPsec protocol provides both services in a single protocol?

A.AH in transport mode
B.IKEv2
C.ESP in tunnel mode
D.AH in tunnel mode
AnswerC

ESP encrypts the payload and authenticates its origin and integrity, delivering confidentiality plus authentication in one protocol. Tunnel mode encapsulates the entire original packet, so the site-to-site VPN's demand for both services is met without adding AH alongside.

Why this answer

ESP provides both encryption and optional authentication, while AH only provides authentication without encryption.

741
MCQhard

A security operations center (SOC) analyst is investigating an alert indicating potential credential dumping on a Windows server. The analyst reviews the process execution logs and sees that a process named 'lsass.exe' was accessed by an unsigned binary. Which of the following techniques is the attacker MOST likely using?

A.LSASS memory dumping
B.Pass-the-hash
C.Kerberoasting
D.DCSync
AnswerA

LSASS (Local Security Authority Subsystem Service) stores credential material in memory, including password hashes and Kerberos tickets. Attackers often target lsass.exe to dump these credentials using tools like Mimikatz, ProcDump, or Task Manager. The scenario describes an unsigned binary accessing lsass.exe, which is a common indicator of credential dumping. This technique allows the attacker to obtain credentials for lateral movement and privilege escalation.

Why this answer

The scenario describes an unsigned binary accessing lsass.exe, which is a strong indicator of credential dumping. LSASS stores credentials in memory, and attackers use tools like Mimikatz to extract them. This allows the attacker to obtain password hashes or plaintext passwords for lateral movement.

The other techniques do not involve direct access to lsass.exe.

Exam trap

The trap here is assuming that any credential-related attack involves lsass.exe, but techniques like Kerberoasting and DCSync do not access lsass.exe directly.

742
MCQhard

A company is migrating to a zero trust architecture. Which of the following is a key principle of zero trust?

A.Allow all traffic within the corporate network
B.Assume breach and verify every request
C.Trust devices based on their IP address
D.Trust but verify for all internal traffic
AnswerB

Zero trust removes implicit trust based on network location, so every access request must be authenticated and authorised regardless of origin. Assuming breach means designing as though attackers are already inside, which drives continuous verification of identity, device health and context before granting access to resources.

Why this answer

Zero trust architecture is built on the principle of 'never trust, always verify,' which explicitly requires that every access request—regardless of origin—be authenticated, authorized, and continuously validated. Option B ('Assume breach and verify every request') captures this core tenet, as it mandates that no implicit trust is granted based on network location or device status, and every request must be treated as potentially malicious until proven otherwise.

Exam trap

The trap here is that candidates often confuse 'trust but verify' (Option D) with zero trust, but zero trust explicitly eliminates the initial trust assumption, requiring verification before any access is granted, not after.

How to eliminate wrong answers

Option A is wrong because zero trust explicitly rejects the model of allowing all traffic within the corporate network; instead, it enforces micro-segmentation and least-privilege access, blocking all traffic by default and only permitting what is explicitly allowed. Option C is wrong because zero trust does not trust devices based on their IP address—IP addresses are easily spoofed and change frequently; trust is instead established through device identity, health posture, and continuous authentication (e.g., using certificates or device attestation). Option D is wrong because 'trust but verify' is the opposite of zero trust; zero trust assumes no trust at any point, requiring verification for every request, including internal traffic, rather than granting initial trust and then verifying.

743
MCQhard

A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?

A.FAIR is the only framework recognized by NIST
B.FAIR is easier to communicate to non-technical stakeholders
C.FAIR requires less data and expertise to implement
D.FAIR provides a monetary value for risk, enabling ROI calculations
AnswerD

FAIR quantifies risk in monetary terms by modelling loss event frequency and loss magnitude, producing annualised loss exposure. This contrasts with qualitative heat maps that rank risks ordinally, and enables cost-benefit and ROI comparisons of proposed security controls.

Why this answer

FAIR (Factor Analysis of Information Risk) is a quantitative risk framework that expresses risk in monetary terms — typically annualized loss expectancy (ALE) derived from loss event frequency and loss magnitude. This monetary output enables direct ROI calculations for security investments and lets leadership compare cyber risk against other business risks in financial terms.

Exam trap

CAS-005 often tests the qualitative-vs-quantitative tradeoff, so candidates who assume FAIR is 'easier' or 'more communicable' pick the wrong advantage — the real advantage is monetary output for ROI.

How to eliminate wrong answers

Option A is wrong because NIST does not endorse FAIR as the only recognized framework — NIST SP 800-30 and the NIST RMF are separate, and FAIR is an Open Group standard, not a NIST-mandated one. Option B is wrong because FAIR's quantitative outputs (dollar ranges, Monte Carlo simulations) are often harder to communicate to non-technical stakeholders than a simple red/yellow/green heat map. Option C is wrong because FAIR typically requires more data, modeling expertise, and time than a qualitative heat map, which relies on subjective ratings.

744
MCQeasy

During a secure SDLC, a development team wants to identify vulnerabilities in running code. Which type of testing should be performed?

A.IAST
B.SAST
C.DAST
D.RASP
AnswerC

DAST tests a running application from the outside, exercising it as an attacker would and observing responses. This detects vulnerabilities in executing code, including runtime and configuration flaws that static analysis of source cannot reveal, matching the team's requirement.

Why this answer

DAST (Dynamic Application Security Testing) tests running applications from the outside by simulating attacks against a live deployment, which is exactly what is needed to identify vulnerabilities in running code. It analyzes the application in its deployed state, including runtime configuration and environment-specific issues.

Exam trap

CAS-005 often tests the SAST vs. DAST vs. IAST distinction — candidates may pick SAST because it is 'code testing,' but the key phrase 'running code' signals DAST, which tests the live application.

How to eliminate wrong answers

Option A is wrong because IAST (Interactive Application Security Testing) instruments the application from within during runtime, often combined with DAST or unit tests, but the question asks for testing running code from a black-box perspective — IAST requires agent instrumentation and is not the primary answer for identifying vulnerabilities in running code. Option B is wrong because SAST analyzes source code or binaries statically without executing the application, so it cannot find runtime or deployment-specific vulnerabilities. Option D is wrong because RASP (Runtime Application Self-Protection) is a protection mechanism that detects and blocks attacks at runtime, not a testing methodology for identifying vulnerabilities during SDLC.

745
MCQhard

An organization is implementing a hybrid cloud architecture and must ensure secure connectivity between its on-premises network and a public cloud VPC. The traffic includes sensitive data that must not traverse the internet. The solution must provide high bandwidth and low latency. Which connectivity option should the architect choose?

A.AWS Direct Connect
B.Site-to-Site VPN over the internet
C.AWS Client VPN
D.Internet gateway with encryption
AnswerA

AWS Direct Connect establishes a dedicated private network link from on-premises infrastructure to the VPC, keeping sensitive traffic off the internet. It delivers the required high bandwidth and low latency, satisfying the stem's explicit prohibition on internet traversal.

Why this answer

AWS Direct Connect provides a dedicated private network connection between on-premises and AWS that does not traverse the internet, delivering high bandwidth and consistent low latency. It is the only option that satisfies both the 'must not traverse the internet' and 'high bandwidth, low latency' requirements.

Exam trap

The trap is that candidates may choose a VPN because it encrypts traffic, but the question's hard constraint is that traffic must not traverse the internet — only Direct Connect satisfies that, and encryption can be layered on top separately.

How to eliminate wrong answers

Option B is wrong because a Site-to-Site VPN runs over the public internet, so sensitive traffic traverses the internet and latency is variable, violating the requirement. Option C is wrong because AWS Client VPN is a managed remote-access VPN for individual users, not a high-bandwidth site-to-site link between an on-premises network and a VPC. Option D is wrong because an internet gateway routes traffic over the public internet; adding encryption does not change the fact that traffic traverses the internet, and it does not provide dedicated bandwidth or low latency.

746
Multi-Selecthard

Which THREE of the following are required for a valid Business Associate Agreement (BAA) under HIPAA? (Select THREE)

Select 3 answers
A.Indemnification clause for breaches
B.Permitted and required uses of PHI
C.Requirement to store data in the United States
D.Safeguards to protect PHI
E.Procedures for breach notification
AnswersB, D, E

Must be specified

Why this answer

A Business Associate Agreement (BAA) must specify the permitted and required uses of Protected Health Information (PHI) by the business associate. This is a core requirement under HIPAA §164.504(e)(2)(i) to ensure the business associate does not use or disclose PHI beyond what is authorized by the covered entity or required by law.

Exam trap

The CAS-004 exam often tests the distinction between mandatory BAA elements (permitted uses, safeguards, breach notification) and optional contractual terms (indemnification, data storage location) to see if candidates confuse common business contract clauses with HIPAA regulatory requirements.

747
MCQhard

A defense contractor must comply with DFARS clause 252.204-7012 and achieve a passing score in its NIST SP 800-171 self-assessment before a contract award. The security lead discovers that several controls in the CUI environment are only partially implemented. Which action should the security lead take to meet the assessment requirement?

A.Document a plan of action with milestones to remediate the partially implemented controls and complete a System Security Plan describing the current state.
B.Request a variance from the contracting officer to exclude the unimplemented controls from the assessment scope.
C.Submit the self-assessment with a perfect score and remediate the gaps after contract award within the first performance period.
D.Implement a compensating control for each partial control and claim full credit in the score to reach the required total.
AnswerA

NIST SP 800-171 assessments permit a score below 110 only when the contractor documents the deficiencies in a System Security Plan and a Plan of Action with defined milestones, resources, and completion dates. This is the accepted path to demonstrate compliance intent and qualify for award while remediation proceeds, so documenting both artifacts is the required action.

Why this answer

When controls are not fully implemented, the accepted method is to document the current state in a System Security Plan and describe remediation in a Plan of Action with milestones. This preserves an honest score while showing the contracting officer a credible path to full implementation.

Exam trap

The trap here is believing that partially implemented controls earn partial points or that a contractor can claim credit for compensating controls to reach a passing score.

748
MCQmedium

A security operations center (SOC) analyst receives an alert from the endpoint detection and response (EDR) platform indicating that a process on a finance workstation has made an outbound connection to a known command-and-control (C2) domain. The analyst wants to quickly determine the full scope of the incident, including other hosts that may have communicated with the same domain. Which of the following actions should the analyst take FIRST?

A.Run a full antivirus scan on the finance workstation to remove any malware.
B.Immediately isolate the finance workstation from the network using the EDR console.
C.Block the C2 domain at the perimeter firewall to prevent further communication.
D.Query the SIEM for all events matching the C2 domain and create a timeline of affected hosts.
AnswerD

Querying the SIEM for the C2 domain leverages centralized log aggregation to identify all hosts that communicated with the malicious domain, providing immediate scope. This is a core incident response step: containment and eradication depend on understanding the blast radius. The SIEM retains historical network and endpoint logs, enabling rapid correlation across the environment without disrupting systems.

Why this answer

In incident response, scoping the incident is critical before containment or remediation. Querying the SIEM for the C2 domain rapidly identifies all hosts that communicated with the malicious infrastructure, revealing the full extent of the compromise. This allows the analyst to prioritize containment efforts and avoid missing additional compromised systems.

Other actions like isolation or blocking are containment steps that should follow scoping.

Exam trap

The trap here is assuming that immediate containment (isolation or blocking) is always the first step, when in fact scoping the incident to understand its breadth must precede containment to avoid incomplete response.

749
MCQhard

A defense contractor is required to comply with NIST SP 800-171 for protecting controlled unclassified information (CUI). The security team is implementing the required security requirements. Which of the following best describes the purpose of the System Security Plan (SSP) in this context?

A.It provides a detailed inventory of all CUI data elements and their locations.
B.It documents how the organization implements each security requirement and describes any planned remediation.
C.It contains the results of penetration testing and vulnerability scans for the CUI environment.
D.It serves as a legal contract between the contractor and the Department of Defense.
AnswerB

NIST SP 800-171 defines the SSP as the document that describes how the organization meets each of the 110 security requirements. It includes descriptions of implemented controls, identifies any requirements not yet met, and outlines remediation plans. The SSP is a key deliverable for compliance and is often required for contracts involving CUI. It provides a clear picture of the security posture.

Why this answer

The System Security Plan (SSP) documents how the organization implements each of the NIST SP 800-171 security requirements and identifies any gaps with remediation plans. It is the primary artifact used to demonstrate compliance with DFARS 252.204-7012. It is not a data inventory, contract, or test report, although it may reference those.

The SSP provides a structured narrative of the security posture for the CUI environment.

Exam trap

The trap here is equating the SSP with a data inventory or test report, when its core purpose is to explain how each security requirement is satisfied.

750
MCQeasy

A security architect is implementing defense-in-depth for a critical application. Which of the following is an example of a detective control?

A.Data encryption
B.Access control list
C.Firewall
D.Intrusion detection system
AnswerD

An intrusion detection system monitors network or host activity and raises alerts on malicious patterns, which is detection after the fact rather than prevention. That matches the detective control requirement, unlike firewalls or access controls, which block activity and are preventive.

Why this answer

An intrusion detection system (IDS) is a detective control because it monitors network or host activity and generates alerts when it identifies suspicious or malicious behavior, allowing security teams to respond. Detective controls are designed to identify and log incidents after or during their occurrence, rather than preventing them outright. Encryption, ACLs, and firewalls are preventive controls that stop unauthorized access or protect data before an incident occurs.

Exam trap

The trap here is confusing preventive controls (encryption, ACLs, firewalls) with detective controls (IDS), as candidates often assume any security tool that 'protects' is detective, when in fact only monitoring/alerting tools qualify.

How to eliminate wrong answers

Option A is wrong because data encryption is a preventive control that protects confidentiality by making data unreadable to unauthorized parties, not a detective control. Option B is wrong because an access control list is a preventive control that enforces authorization decisions, blocking unauthorized access rather than detecting it. Option C is wrong because a firewall is a preventive control that filters traffic based on rules to block unwanted connections, not a monitoring or detection mechanism.

Page 9

Page 10 of 13

Page 11