Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 751–825

973 questions total · 13pages · All types, answers revealed

Page 10

Page 11 of 13

Page 12
751
Multi-Selecthard

During a penetration test, an assessor successfully exploits a timing side-channel attack to extract an ECDSA private key from a secure enclave. Which TWO mitigations should the development team implement to prevent such attacks? (Select TWO.)

Select 2 answers
A.Implement constant-time cryptographic operations
B.Add random delays to cryptographic operations
C.Disable debug interfaces on the secure enclave
D.Use blinding techniques for ECDSA signing
E.Replace ECDSA with Ed25519
AnswersA, D

Constant-time cryptographic operations eliminate the data-dependent execution timing that leaks ECDSA nonce and scalar information, directly satisfying the stem's timing side-channel constraint. By ensuring every operation takes identical duration regardless of secret values, the attacker gains no exploitable timing variance to correlate against the private key.

Why this answer

Option A is correct because constant-time cryptographic operations ensure that execution time and memory access patterns do not depend on secret data, which directly eliminates the timing side-channel that leaked the ECDSA private key from the enclave. Option D is correct because ECDSA signing blinding (e.g., randomizing the nonce k and/or the private key d with a random value before the scalar multiplication) decorrelates the timing of the modular exponentiation/scalar multiplication from the actual secret, so an attacker cannot recover the key even if timing varies. Option B is not appropriate because adding random delays only obfuscates timing and is statistically defeatable by averaging many traces; it is not a sound cryptographic countermeasure.

Option C does not belong because disabling debug interfaces addresses physical/JTAG-style access, not a timing side-channel observed through normal cryptographic execution. Option E does not belong because Ed25519 is also vulnerable to timing side-channels if implemented without constant-time code and blinding, so simply swapping algorithms does not fix the root cause.

752
MCQhard

To protect against quantum computing attacks, a security architect is planning to transition to post-quantum cryptography. Which algorithm has been selected by NIST for general encryption (key encapsulation) in the PQC standard?

A.Falcon
B.CRYSTALS-Dilithium
C.CRYSTALS-Kyber
D.SPHINCS+
AnswerC

CRYSTALS-Kyber is the NIST-selected key encapsulation mechanism, standardised as ML-KEM (FIPS 203), designed for general encryption against quantum attacks. It satisfies the stem's requirement for a post-quantum key encapsulation algorithm, unlike CRYSTALS-Dilithium or Falcon, which NIST selected for digital signatures rather than encryption.

Why this answer

NIST selected CRYSTALS-Kyber as the primary standard for general encryption and key encapsulation (FIPS 203) in its post-quantum cryptography program. Kyber is a lattice-based KEM designed for efficient key establishment, making it the correct choice for general encryption.

Exam trap

The trap is confusing NIST's PQC selections — candidates must remember Kyber is the KEM for encryption, while Dilithium, Falcon, and SPHINCS+ are signature algorithms.

How to eliminate wrong answers

Option A is wrong because Falcon is a lattice-based digital signature algorithm selected by NIST for signatures (FIPS 206 draft), not for key encapsulation. Option B is wrong because CRYSTALS-Dilithium is a lattice-based digital signature algorithm (FIPS 204), not a KEM. Option D is wrong because SPHINCS+ is a stateless hash-based digital signature scheme (FIPS 205), also for signatures, not encryption.

753
MCQhard

During a security assessment, a tester finds that a web application accepts user input and directly uses it in an LDAP query without sanitization. Which of the following attacks is most likely to be successful?

A.Cross-site scripting
B.SQL injection
C.Remote file inclusion
D.LDAP injection
AnswerD

Unsanitised input concatenated into an LDAP filter lets the tester alter query logic, so LDAP injection succeeds. The stem's constraint is direct use of user input in an LDAP query without sanitisation, which this attack specifically exploits.

Why this answer

The scenario explicitly describes unsanitized user input being used directly in an LDAP query. LDAP injection occurs when an attacker manipulates LDAP statements by injecting special characters (e.g., *, (, ), &, |, !) to alter the query logic, potentially bypassing authentication or extracting unauthorized directory information. This is a direct injection attack against the LDAP protocol (RFC 4511), not against a database or web client.

Exam trap

The trap here is that candidates see 'user input' and 'query' and immediately think SQL injection, failing to recognize that the specific technology mentioned (LDAP) requires its own injection class, and that each injection type is tied to a distinct backend protocol.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) targets the client-side execution of scripts in a user's browser, not the server-side LDAP query processing; the vulnerability here is server-side injection, not output encoding to the browser. Option B is wrong because SQL injection targets relational databases using SQL syntax (e.g., SELECT, UNION), whereas LDAP uses a different query language (LDAP filters based on RFC 4515) with distinct special characters and structure. Option C is wrong because remote file inclusion (RFI) involves including a remote file into a server-side script (e.g., PHP include()), which is unrelated to manipulating directory service queries.

754
MCQhard

A financial institution is adopting a risk management framework based on NIST SP 800-37. The CISO wants to ensure that risk responses are integrated into the enterprise architecture. Which of the following activities best supports this integration during the Risk Response step?

A.Developing a risk register that lists identified risks and their owners.
B.Performing a business impact analysis (BIA) to identify critical business processes.
C.Mapping selected security controls to specific architectural components and documenting the relationships.
D.Conducting a tabletop exercise to validate the effectiveness of the risk response plan.
AnswerC

During Risk Response, NIST SP 800-37 emphasizes selecting, tailoring, and implementing controls. Mapping those controls to architectural components ensures that risk responses are not abstract but are embedded in the system's design. This documentation also facilitates continuous monitoring and change management. It directly supports integration into enterprise architecture by showing where each control resides.

Why this answer

Mapping selected security controls to architectural components is the key activity that integrates risk responses into enterprise architecture. NIST SP 800-37's Risk Response step involves selecting controls, allocating them to systems, and documenting how they are implemented. By explicitly linking controls to architecture, the organization ensures that risk mitigation is designed into systems rather than bolted on later.

This supports traceability and continuous monitoring.

Exam trap

The trap here is confusing documentation or testing activities with the actual architectural integration of controls, which requires explicit mapping to system components.

755
Multi-Selectmedium

A DevOps engineer is automating the deployment of a web application using containers. Which of the following security practices should be implemented to reduce the attack surface of the containers? (Select TWO.)

Select 2 answers
A.Run containers as a non-root user
B.Build images with embedded database credentials
C.Use minimal base images like Alpine or distroless
D.Expose port 22 for SSH debugging
E.Grant all Linux capabilities to the container
AnswersA, C

Why this answer

Running containers as a non-root user (option A) is a fundamental security best practice because it limits the privileges available to processes inside the container. If an attacker compromises the application, they will not have root access to the host or the container runtime, reducing the potential for privilege escalation or host-level damage. This aligns with the principle of least privilege, which is critical for container security.

Exam trap

CompTIA often tests the misconception that containers are inherently secure because they are isolated, but the trap here is that default root execution and bloated base images are common misconfigurations that dramatically increase the attack surface, and candidates may overlook the need to explicitly drop privileges and minimize image content.

Why the other options are wrong

B

Embedding secrets in images is insecure; they should be injected at runtime.

D

Exposing SSH adds an attack vector and is unnecessary in production.

E

Granting all capabilities weakens isolation; should drop all unnecessary capabilities.

756
MCQeasy

A small business wants to achieve compliance with the Payment Card Industry Data Security Standard (PCI DSS). Which of the following is an essential requirement they must implement?

A.Implement logging and monitoring of all access to cardholder data
B.Encrypt all cardholder data at rest
C.Conduct vulnerability scans on a monthly basis
D.Perform continuous penetration testing
AnswerA

PCI DSS Requirement 10 requires logging and monitoring.

Why this answer

PCI DSS Requirement 10 mandates logging and monitoring of access to cardholder data. Option B is wrong because encryption in transit is required, not at rest by all merchants. Option C is wrong because quarterly scans are required, not monthly.

Option D is wrong because penetration testing is required annually, not continuously.

757
MCQmedium

A healthcare organization is designing a new system to store patient records. The security architect must ensure that data at rest is encrypted and that cryptographic keys are rotated regularly without re-encrypting the entire database. Which of the following techniques should be used?

A.Transparent data encryption (TDE) with a single certificate used to encrypt the database.
B.Envelope encryption using a data encryption key (DEK) per record and a key encryption key (KEK) managed by a key management service (KMS).
C.Full database encryption with a single master key stored in a hardware security module (HSM).
D.Column-level encryption using a static symmetric key stored in a configuration file.
AnswerB

Envelope encryption uses a DEK to encrypt each record and a KEK to encrypt the DEK. To rotate keys, only the KEK needs to be rotated, and the DEKs are re-encrypted with the new KEK, not the data itself. This allows regular key rotation without re-encrypting the entire database. It also limits the scope of a compromised DEK to a single record.

Why this answer

Envelope encryption separates data encryption keys from key encryption keys. Each record is encrypted with a unique DEK, and the DEK is encrypted with a KEK. Rotating the KEK only requires re-encrypting the DEKs, not the data, enabling regular key rotation without massive re-encryption.

This is efficient, scalable, and limits the blast radius of a compromised key, making it ideal for healthcare data with strict compliance.

Exam trap

The trap here is assuming that any encryption at rest supports easy key rotation, when in fact full-database encryption often requires re-encryption.

758
MCQhard

A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and modern containerized workloads. The organization wants to enforce least-privilege network access between workloads without relying on IP addresses or VLANs, and it requires the ability to define policy based on workload identity and tags that follow the workload across environments. Which technology best meets these requirements?

A.Traditional stateful firewalls with static IP-based rules
B.Host-based microsegmentation using identity and tag-based policies
C.Software-defined networking (SDN) with VLAN segmentation
D.Network access control (NAC) with 802.1X port-based authentication
AnswerB

Host-based microsegmentation enforces security policy at the workload level using identity and tags rather than IP addresses. This allows policies to follow workloads across environments, including containers and legacy systems, and supports least-privilege access between individual workloads. It meets the requirement to decouple policy from network topology.

Why this answer

Host-based microsegmentation is the only option that enforces policy based on workload identity and tags, decoupling security from IP addresses and VLANs. This allows consistent least-privilege enforcement across legacy and containerized workloads and supports policy portability across environments.

Exam trap

The trap here is equating VLAN segmentation or NAC with microsegmentation, when true microsegmentation requires identity-based policy that follows the workload rather than the network location.

759
Multi-Selecthard

A security analyst is investigating a suspected data exfiltration incident. The analyst has captured network traffic and wants to identify evidence of data being transferred over a covert channel. Which TWO of the following techniques would BEST help detect covert channels in the network traffic? (Choose two.)

Select 2 answers
A.Analyze DNS query patterns for unusually long or high-entropy subdomains.
B.Inspect ICMP packets for unusual payload sizes or patterns.
C.Scan internal hosts for open ports that could be used for data transfer.
D.Examine NetFlow records for spikes in outbound traffic volume during off-hours.
E.Monitor for large file transfers over HTTP/HTTPS to known cloud storage services.
AnswersA, B

DNS tunneling often encodes data in subdomains, resulting in long, high-entropy labels. Analyzing DNS query patterns for these anomalies can reveal covert channels that bypass traditional perimeter controls. This technique is effective because DNS is frequently allowed outbound, and attackers abuse it to exfiltrate data or maintain C2. Monitoring for statistical anomalies in DNS queries is a key detection method.

Why this answer

Covert channels often hide data within protocols that are typically allowed through firewalls, such as DNS and ICMP. Analyzing DNS for long, high-entropy subdomains can reveal DNS tunneling, while inspecting ICMP payloads for anomalies can detect ICMP tunneling. Both techniques focus on the content and patterns within these protocols, which is essential for identifying stealthy exfiltration.

Exam trap

The trap here is focusing on volume-based anomalies or open ports, which may indicate exfiltration but fail to detect covert channels that hide within allowed protocols using encoding or tunneling.

760
MCQmedium

A company has implemented a hardware security module (HSM) to manage cryptographic keys for a payment processing system. Which of the following best describes an advantage of using an HSM over software-based key storage?

A.Easier key rotation
B.Tamper-resistant key storage
C.Faster cryptographic operations
D.Lower implementation cost
AnswerB

An HSM stores keys inside tamper-resistant hardware that detects and responds to physical intrusion, zeroising keys rather than exposing them. Software-based storage keeps keys in memory or on disk, where compromise of the host yields the key material directly.

Why this answer

An HSM is a dedicated hardware device designed to securely generate, store, and manage cryptographic keys, with physical and logical protections that make it tamper-resistant. Unlike software-based key storage, where keys reside in memory or on disk and can be extracted by malware or an attacker with system access, an HSM's keys never leave the device in plaintext and the device zeroizes keys if tampering is detected. This makes tamper-resistant key storage the primary advantage for high-assurance environments like payment processing.

Exam trap

CAS-005 often tests whether candidates confuse the security benefits of HSMs (tamper resistance, secure key storage) with performance or cost benefits, leading them to incorrectly select 'faster cryptographic operations' or 'lower implementation cost' as advantages.

How to eliminate wrong answers

Option A is wrong because key rotation is a procedural and policy-driven activity that can be equally easy or difficult with HSMs or software stores; HSMs do not inherently make rotation easier and may add complexity. Option C is wrong because HSMs are not necessarily faster — they often have lower throughput than software crypto for bulk operations, though they may accelerate specific algorithms; speed is not the defining advantage. Option D is wrong because HSMs are significantly more expensive to implement than software-based key storage, both in hardware cost and operational overhead, so lower cost is the opposite of reality.

761
Multi-Selectmedium

A security architect is designing a risk mitigation strategy for a critical application. Which TWO of the following are examples of risk acceptance? (Select TWO.)

Select 2 answers
A.Outsourcing the application hosting to a third party.
B.Obtaining senior management sign-off to accept the risk without additional controls.
C.Purchasing cyber insurance to cover potential losses.
D.Formally acknowledging the residual risk after controls are implemented.
E.Implementing an intrusion prevention system to reduce the likelihood of attacks.
AnswersB, D

Management sign-off is a documented acceptance.

Why this answer

Risk acceptance is a formal decision by management to acknowledge and accept a specific risk without implementing additional controls. This is typically documented in a risk register and signed off by senior leadership, indicating that the cost of mitigation outweighs the potential impact. Option D is correct because formally acknowledging residual risk after controls are implemented is also a form of risk acceptance, as the organization accepts the remaining risk that cannot be fully mitigated.

Exam trap

CompTIA CASP+ often tests the distinction between risk acceptance and risk transference, where candidates mistakenly classify outsourcing or insurance as acceptance rather than transference.

762
Multi-Selectmedium

A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)

Select 2 answers
A.Continuous compliance monitoring against frameworks like CIS
B.Vulnerability scanning of container images
C.Configuration drift detection
D.Real-time web application firewall
E.Data loss prevention for cloud storage
AnswersA, C

Continuous compliance monitoring against benchmarks such as CIS satisfies the multi-cloud requirement by evaluating configurations across AWS, Azure and Google Cloud against a common control baseline, detecting drift as it occurs. This provides the ongoing assurance the architect needs, rather than a one-off point-in-time assessment.

Why this answer

Option A (Continuous compliance monitoring against frameworks like CIS) is essential because a CSPM's core purpose is to continuously assess cloud configurations against recognized benchmarks and standards such as CIS, PCI DSS, and NIST, providing ongoing assurance across the multi-cloud estate. Option C (Configuration drift detection) is also essential since CSPM must detect when resources deviate from approved secure baselines, whether through manual changes, automation, or IaC mismatches, and alert or remediate accordingly. Option B (Vulnerability scanning of container images) belongs to container/image scanning tools (e.g., Trivy, Clair) rather than CSPM, which focuses on cloud resource configuration posture.

Option D (Real-time web application firewall) is a runtime application protection control typically delivered by a WAF, not a posture management function. Option E (Data loss prevention for cloud storage) is a separate data-security capability (DLP) and, while complementary, is not a defining CSPM requirement.

Exam trap

CAS-005 often tests the boundary between CSPM (configuration/posture) and adjacent tools like CWPP, WAF, and DLP — candidates pick 'vulnerability scanning' or 'WAF' because they sound security-relevant, but CSPM is strictly about configuration posture and compliance.

763
Multi-Selectmedium

A company is implementing privileged access management (PAM) for its critical servers. Which THREE practices should be included to enhance security? (Select THREE.)

Select 3 answers
A.Record and monitor all privileged sessions
B.Implement just-in-time (JIT) access provisioning
C.Use break-glass accounts for emergency access
D.Enforce multi-factor authentication for all users
E.Require periodic password rotation for all service accounts
AnswersA, B, C

Session recording and monitoring create an auditable trail of every privileged action on critical servers, satisfying the PAM requirement for accountability and detecting misuse or insider threats in real time. This directly supports the scenario's goal of enhancing security for privileged access to critical infrastructure.

Why this answer

Option A is correct because recording and monitoring all privileged sessions provides an audit trail and enables real-time detection of malicious or anomalous activity by administrators, which is a core PAM control. Option B is correct because just-in-time (JIT) access provisioning grants elevated privileges only when needed and for a limited time, reducing the standing attack surface and the window for credential misuse. Option C is correct because break-glass accounts provide controlled emergency access when normal PAM workflows fail, and when properly vaulted, monitored, and alerted on, they preserve availability without creating unmanaged privileged access.

Option D is not the best fit because MFA for all users is a general identity control, not a PAM-specific practice for critical server privileged access. Option E is not correct because periodic password rotation for service accounts is a legacy practice that can weaken security and is not a core PAM enhancement compared to session monitoring, JIT access, and break-glass procedures.

Exam trap

CAS-005 often tests whether candidates can distinguish PAM-specific controls from general IAM hygiene — MFA and password rotation are commonly selected but are not the PAM practices the question targets.

764
MCQeasy

Which of the following is a core principle of the Zero Trust security model?

A.Perimeter-based trust
B.Never trust, always verify
C.Trust based on network location
D.Trust but verify
AnswerB

Zero Trust removes implicit trust based on network location, requiring every access request to be authenticated and authorised explicitly before granting resources. "Never trust, always verify" captures that continuous verification principle, which is the model's foundational tenet.

Why this answer

The core principle of Zero Trust is 'never trust, always verify,' which means that no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. Every access request must be authenticated, authorized, and encrypted before access is granted. This principle eliminates implicit trust based on network location.

Exam trap

The trap is selecting 'trust but verify' because it sounds similar to 'never trust, always verify,' but 'trust but verify' still implies initial trust, which contradicts Zero Trust's core tenet.

How to eliminate wrong answers

Option A is wrong because perimeter-based trust is the opposite of Zero Trust; it assumes that everything inside the network is trusted, which Zero Trust explicitly rejects. Option C is wrong because trusting based on network location is a traditional security model that Zero Trust replaces; Zero Trust does not grant trust based on being on the corporate network. Option D is wrong because 'trust but verify' is a Russian proverb often used in security, but it still implies an initial trust; Zero Trust starts with no trust and verifies every request.

765
MCQeasy

A security architect is reviewing the authentication design for a new customer portal that will be accessed by partners from multiple external organizations. The business wants partners to use their existing corporate identities, avoid creating new passwords for the portal, and allow the home organization to remain the authoritative source for disabling accounts. Which of the following should the architect recommend?

A.A shared partner account with per-user activity logging
B.Local account provisioning with mandatory password complexity and rotation
C.Certificate-based authentication with manually distributed client certificates
D.Federated identity using SAML or OpenID Connect with the partner identity providers
AnswerD

Federation trusts the partner's identity provider to authenticate users and assert identity claims to the portal. Partners keep their existing corporate credentials, and when the home organization disables an account, the next authentication attempt fails because the portal never holds the credential. This directly satisfies single sign-on, no new passwords, and home-organization authority over access.

Why this answer

Federated identity lets the portal rely on each partner organization's identity provider for authentication and account lifecycle. Partners use existing credentials, and disabling an account at the home organization immediately prevents new sessions because the portal consumes assertions rather than storing passwords. This is the standard pattern for business-to-business access with external identity sources.

Exam trap

The trap here is focusing on password strength for new accounts when the requirement is to avoid creating portal-managed credentials altogether.

766
MCQhard

A global e-commerce company processes payment card data and is required to comply with PCI DSS. During a quarterly vulnerability scan, the security team discovers that a web application firewall (WAF) rule is blocking legitimate traffic, causing transaction failures. The WAF is a critical compensating control for a known vulnerability in the application that cannot be patched for 90 days. The compliance officer is concerned about maintaining PCI DSS compliance while ensuring business continuity. The security team proposes temporarily disabling the WAF to restore service while they fine-tune the rules. Which of the following is the BEST action?

A.Segment the affected application from the rest of the network and remove the WAF from the data path.
B.Disable the WAF immediately to restore service and document the decision as a risk acceptance.
C.Accept the risk of transaction failures and keep the WAF in place until the rules are fully tested.
D.Temporarily modify the WAF rule set to allow legitimate traffic while maintaining security, and schedule a permanent fix within 24 hours.
AnswerD

Adjusting the WAF rule set preserves the compensating control PCI DSS requires for the unpatched vulnerability, restoring transaction flow without disabling protection entirely. A 24-hour remediation window keeps the exception tightly bounded, satisfying the standard's demand that compensating controls remain effective and documented throughout the 90-day patch deferral.

Why this answer

Option D is correct because it balances the need for business continuity with the requirement to maintain the WAF as a compensating control for the unpatched vulnerability. By temporarily modifying the WAF rule set to allow legitimate traffic while still blocking malicious traffic, the team preserves the security control and avoids a compliance violation. Scheduling a permanent fix within 24 hours ensures the change is temporary and documented, aligning with PCI DSS change control and risk management requirements.

This approach avoids the extremes of disabling the WAF entirely or allowing transaction failures.

Exam trap

The trap here is the false dichotomy between security and availability, leading candidates to choose extreme options like disabling the WAF or accepting failures, rather than seeking a balanced, temporary mitigation that preserves both.

How to eliminate wrong answers

Option A is wrong because removing the WAF from the data path eliminates the compensating control entirely, leaving the known vulnerability exposed and violating PCI DSS requirement 6.6 for web-facing applications. Option B is wrong because disabling the WAF immediately removes a critical security control, directly violating PCI DSS and creating an unacceptable risk of data compromise, even if documented as risk acceptance. Option C is wrong because accepting transaction failures harms business continuity and does not address the root cause; it also fails to meet the PCI DSS requirement to maintain a functional WAF, as the WAF is not effectively protecting the application if it blocks legitimate traffic.

767
MCQhard

An organization is implementing a zero trust architecture (ZTA). The security architect proposes using a software-defined perimeter (SDP) to replace the traditional VPN for remote access. Which of the following best describes the primary security benefit of SDP over VPN in a zero trust model?

A.It provides deep packet inspection to detect malicious traffic.
B.It enforces multi-factor authentication for every session.
C.It reduces latency by establishing direct peer-to-peer connections.
D.It prevents unauthorized users from discovering the application infrastructure.
AnswerD

SDP enforces a "black cloud" model: users authenticate and are authorised before any application infrastructure is revealed, so unauthorised parties cannot even discover or scan the protected resources. A traditional VPN exposes its gateway and internal network topology once connected, failing the zero trust requirement for concealment.

Why this answer

In a zero trust architecture, the primary security benefit of a software-defined perimeter (SDP) over a traditional VPN is that it hides the application infrastructure from unauthorized users. SDP uses a controller-based model where devices must authenticate and be authorized before they can even see the application servers, effectively creating a 'black cloud' that prevents discovery and reduces the attack surface. This aligns with the zero trust principle of 'never trust, always verify' and eliminates the network-level visibility that VPNs inherently provide to any connected client.

Exam trap

The trap here is that candidates confuse the 'direct' connection behavior of some SDP implementations with a security benefit, when in fact the core advantage is hiding infrastructure from unauthorized users, not reducing latency or enabling peer-to-peer connections.

How to eliminate wrong answers

Option A is wrong because deep packet inspection is a feature of next-generation firewalls or intrusion prevention systems, not a core or defining benefit of SDP; SDP focuses on access control and visibility hiding, not traffic inspection. Option B is wrong because multi-factor authentication is a common requirement in both SDP and modern VPN solutions; it is not unique to SDP and does not represent the primary security benefit over VPN. Option C is wrong because SDP typically uses a controller to broker connections and often routes traffic through a gateway or proxy, not direct peer-to-peer connections; reducing latency is not a primary security benefit, and direct connections can actually introduce security risks in a zero trust model.

768
Multi-Selecthard

Which TWO of the following are effective defenses against Server-Side Request Forgery (SSRF) attacks? (Select TWO.)

Select 2 answers
A.Whitelist allowed outbound IP addresses and domains
B.Use a web application firewall (WAF) to block SSRF signatures
C.Enforce strict referrer headers on requests
D.Disable unused URL schemes (e.g., file://, dict://)
E.Implement input validation on all user-supplied URLs
AnswersA, D

Whitelisting permitted outbound IP addresses and domains constrains where the server can send requests, so an SSRF payload cannot reach internal metadata services or arbitrary external hosts. This directly limits the destinations an attacker can abuse.

Why this answer

Option A is correct because an allowlist (whitelist) of permitted outbound IP addresses and domains restricts the destinations a server can reach, so even if an attacker injects an internal URL like http://169.254.169.254/ or http://localhost, the request is denied before it leaves the application. Option D is correct because disabling unused URL schemes such as file://, dict://, gopher://, and ftp:// removes dangerous protocol handlers that SSRF payloads abuse to read local files or pivot to other services, leaving only the required http/https schemes. Option B is not a reliable defense because WAF signature matching is easily bypassed with encoding, DNS rebinding, or novel payloads and cannot understand application-level intent.

Option C is ineffective because the Referer header is client-controlled and trivially spoofed or omitted, and it has no bearing on server-initiated requests. Option E is insufficient on its own because URL validation is notoriously hard to implement correctly (bypasses via redirects, alternate IP encodings, and DNS rebinding), so it is not one of the two strongest defenses compared with allowlisting and scheme restriction.

Exam trap

Many test-takers mistakenly believe that input validation alone is sufficient to prevent SSRF, but attackers can bypass validation via encoding, redirects, or protocol smuggling. Whitelisting outbound destinations and disabling unused URL schemes are the primary effective controls.

769
MCQeasy

A security administrator is implementing a new policy that requires all employees to use multi-factor authentication (MFA) for accessing cloud applications. The administrator wants to choose an MFA method that is resistant to phishing attacks. Which of the following MFA methods should the administrator select?

A.FIDO2 security keys
B.Push notifications with number matching
C.Time-based one-time passwords (TOTP) generated by an authenticator app
D.SMS-based one-time codes
AnswerA

FIDO2 security keys use public-key cryptography and are bound to the origin, making them highly resistant to phishing. The authentication is scoped to the legitimate website, so even if a user is tricked into visiting a phishing site, the key will not release credentials. This is the strongest phishing-resistant MFA method among the options.

Why this answer

FIDO2 security keys are phishing-resistant because they use public-key cryptography and the authentication is bound to the specific origin. Even if a user is directed to a phishing site, the key will not authenticate to the fraudulent domain. Other methods like SMS, push notifications, and TOTP are vulnerable to real-time phishing or interception, so FIDO2 is the most secure choice for this requirement.

Exam trap

The trap here is assuming that any MFA method is phishing-resistant, but only those based on FIDO2/WebAuthn provide origin-bound credentials that cannot be replayed on a phishing site.

770
MCQhard

An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?

A.Software as a Service (SaaS)
B.Infrastructure as a Service (IaaS)
C.Platform as a Service (PaaS)
D.Function as a Service (FaaS)
AnswerB

IaaS lets the organisation manage its own operating systems, middleware and applications, giving maximum control over security configuration, while the provider's FedRAMP authorisation covers the underlying infrastructure. PaaS and SaaS shift more configuration responsibility to the provider, reducing customer control.

Why this answer

IaaS gives the customer control over the operating system, middleware, runtime, and applications while the provider manages the physical infrastructure, hypervisor, and network fabric. Under FedRAMP, the provider's authorization covers the underlying infrastructure, but the customer retains responsibility for configuring and securing everything above the hypervisor — offering the most security configuration control among the listed models while still leveraging the provider's FedRAMP package.

Exam trap

CAS-005 often tests the inverse relationship between abstraction level and customer control — candidates may assume PaaS or SaaS offers more control because it 'does more,' when in fact IaaS gives the customer the most configuration responsibility.

How to eliminate wrong answers

Option A is wrong because SaaS abstracts nearly all layers — the customer only controls data and user access, giving the least security configuration control. Option C is wrong because PaaS manages the OS, runtime, and middleware, leaving the customer with only application and data-layer control, which is less than IaaS. Option D is wrong because FaaS (serverless) abstracts even more than PaaS, with the customer controlling only function code and configuration, offering the least control of the compute models.

771
MCQmedium

A healthcare organization is architecting a secure data exchange with a partner hospital. The partners need to share patient records in near real time, but they do not want to expose their internal databases directly. The security architect must ensure that only specific, authorized fields are exchanged, that the data is validated against a predefined schema, and that the exchange is auditable and resistant to tampering. Which approach best satisfies these requirements?

A.A shared message queue using AMQP with no message signing
B.A mutually authenticated API gateway with schema validation and signed messages
C.SFTP file drops of full database exports on a scheduled basis
D.Direct database replication between the two organizations over a VPN
AnswerB

A mutually authenticated API gateway allows the partners to expose only specific endpoints and fields, enforce schema validation, and log all exchanges for auditability. Digital signatures on messages provide tamper resistance and non-repudiation. This approach avoids direct database exposure and meets the real-time, least-privilege, and audit requirements.

Why this answer

A mutually authenticated API gateway with schema validation and signed messages enables selective field exchange, real-time communication, strict schema enforcement, and tamper-resistant auditing. It avoids exposing internal databases and provides the necessary security controls for partner data sharing.

Exam trap

The trap here is underestimating the need for schema validation and message signing, and assuming that any encrypted transport such as a VPN or SFTP is sufficient for secure data exchange.

772
MCQmedium

An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?

A.RSA-4096
B.CRYSTALS-Kyber
C.ECDHE
D.CRYSTALS-Dilithium
AnswerB

CRYSTALS-Kyber is a lattice-based key encapsulation mechanism (KEM), standardised by NIST as ML-KEM, which secures symmetric keys through public-key encryption. It directly satisfies the stem's requirement for a post-quantum algorithm designed for key encapsulation, unlike CRYSTALS-Dilithium or SPHINCS+, which are digital signature schemes.

Why this answer

CRYSTALS-Kyber is a NIST-approved post-quantum cryptographic algorithm designed for key encapsulation (KEM), selected in the NIST PQC standardization process. It is based on module learning with errors (MLWE) and provides secure key exchange resistant to quantum attacks. RSA-4096 and ECDHE are classical algorithms vulnerable to quantum computers, and CRYSTALS-Dilithium is designed for digital signatures, not key encapsulation.

Exam trap

The trap is confusing key encapsulation with digital signatures; candidates may pick CRYSTALS-Dilithium because it is also a NIST PQC algorithm, but it is for signatures, not KEM.

How to eliminate wrong answers

Option A is wrong because RSA-4096 is a classical public-key algorithm based on integer factorization, which is vulnerable to Shor's algorithm on a quantum computer. Option C is wrong because ECDHE is a classical key exchange based on elliptic-curve discrete logarithms, also vulnerable to quantum attacks. Option D is wrong because CRYSTALS-Dilithium is a NIST-approved post-quantum algorithm for digital signatures, not key encapsulation.

773
Multi-Selecteasy

An organization is implementing a public key infrastructure (PKI). Which THREE of the following are essential components?

Select 3 answers
A.Key escrow agent
B.Certificate authority (CA)
C.Certificate database and CRL
D.Registration authority (RA)
E.Time-stamping authority (TSA)
AnswersB, C, D

The CA is the trust anchor that issues, signs and revokes all X.509 certificates, binding public keys to verified identities. Without it, no entity can validate another's certificate, so the PKI's core assurance function cannot operate.

Why this answer

Option B (Certificate authority (CA)) is essential because the CA is the trusted entity that issues, signs, and revokes digital certificates, forming the core of any PKI. Option C (Certificate database and CRL) is essential because the PKI must store issued certificates and publish a Certificate Revocation List so relying parties can validate certificate status. Option D (Registration authority (RA)) is essential because the RA handles identity proofing and certificate enrollment requests on behalf of the CA, binding a subject's identity to its public key.

Option A (Key escrow agent) is not essential; key escrow is an optional recovery mechanism used in some deployments, not a required PKI component. Option E (Time-stamping authority (TSA)) is not essential; a TSA provides trusted time proofs for non-repudiation in specific use cases but is not required for basic PKI operation.

Exam trap

CompTIA CASP+ often tests the distinction between essential PKI components (CA, RA, certificate database/CRL) and optional services (key escrow, TSA), trapping candidates who assume all listed items are mandatory for a basic PKI implementation.

774
MCQmedium

During a security incident, a SOC analyst identifies a process with a suspicious hash on several endpoints. The analyst wants to determine if this hash is known to be malicious by querying internal and external threat intelligence sources. Which standard should the analyst use to structure the threat intelligence data for automated sharing?

A.TAXII
B.STIX
C.OpenIOC
D.CybOX
AnswerB

STIX provides a structured, machine-readable schema for expressing indicators, malware and relationships, enabling automated exchange between platforms via TAXII. It satisfies the requirement to structure threat intelligence for automated sharing, unlike prose formats or vulnerability scoring systems.

Why this answer

STIX (Structured Threat Information eXpression) is the OASIS standard that defines the structured language and data model for representing cyber threat intelligence — indicators, malware, attack patterns, and their relationships — in a machine-readable JSON format. When an analyst needs to structure threat intelligence data (such as a suspicious file hash) for automated sharing, STIX is the correct standard because it defines the content schema itself. TAXII is the transport protocol that carries STIX, not the structuring standard.

Exam trap

The trap is the classic STIX-vs-TAXII confusion: candidates see 'automated sharing' and pick TAXII, but the question asks which standard structures the data — that is STIX; TAXII only transports it.

How to eliminate wrong answers

Option A is wrong because TAXII (Trusted Automated eXchange of Indicator Information) is the transport/exchange protocol for moving threat intelligence between systems, not the data structuring standard — it defines how to send data, not how to format it. Option C is wrong because OpenIOC is a legacy Mandiant (FireEye) indicator format that predates STIX and is largely deprecated; it is not the current standard for automated sharing. Option D is wrong because CybOX (Cyber Observable eXpression) was a separate OASIS standard for representing cyber observables, but its functionality was merged into STIX 2.x, so CybOX is no longer the standalone standard to use for structuring threat intelligence.

775
Multi-Selecthard

A security team is automating incident response using playbooks. Which two of the following are critical considerations when designing automated response actions? (Select two.)

Select 2 answers
A.Execute all actions immediately to minimize damage.
B.Include a manual approval step for high-impact actions.
C.Ensure automated actions are reversible.
D.Use the same playbook for all incident types.
AnswersB, C

Why this answer

High-impact automated actions, such as blocking a critical server or deleting user accounts, can cause significant collateral damage if triggered by a false positive. Including a manual approval step ensures a human verifies the alert before irreversible or disruptive actions are taken, aligning with the principle of least privilege and incident response best practices.

Exam trap

CompTIA often tests the misconception that speed is always the priority in automation, tempting candidates to select 'execute all actions immediately' without considering the need for validation and reversibility in high-stakes environments.

Why the other options are wrong

A

Immediate execution without validation can cause collateral damage.

D

Different incidents require tailored responses; one-size-fits-all is ineffective.

776
MCQeasy

A network architect is designing a DMZ for a web application. Which of the following is the MOST appropriate placement for a reverse proxy?

A.In the management network
B.In the DMZ
C.In the database tier
D.Inside the internal network
AnswerB

A reverse proxy terminates client connections and forwards requests to backend web servers, so placing it in the DMZ exposes only the proxy to untrusted networks while shielding internal servers, matching the requirement to design a DMZ for the web application.

Why this answer

A reverse proxy is placed in the DMZ to act as an intermediary for client requests to the web application. It terminates external connections, inspects traffic, and forwards legitimate requests to internal web servers, thereby hiding the internal server architecture and providing an additional layer of security. This placement aligns with the principle of least exposure, as the DMZ is a semi-trusted network segment designed to host publicly accessible services.

Exam trap

Many candidates mistakenly think a reverse proxy belongs inside the internal network for better performance or easier management, but the correct placement is in the DMZ to enforce security boundaries and protect internal resources.

How to eliminate wrong answers

Option A is wrong because the management network is isolated for administrative access and should not host a reverse proxy, which must be reachable by external clients. Option C is wrong because the database tier is a highly sensitive internal network segment that should never be directly exposed to external traffic; placing a reverse proxy there would violate network segmentation and security best practices. Option D is wrong because placing a reverse proxy inside the internal network would expose internal IP addresses and architecture to external clients, defeating the purpose of traffic inspection and hiding backend servers.

777
MCQmedium

A financial services company is implementing a risk management framework. The security team has identified that the current encryption algorithm for customer data in transit is deprecated. According to NIST SP 800-53, which of the following is the MOST appropriate step to address this finding?

A.Implement compensating controls such as network segmentation
B.Update the encryption algorithm to a FIPS 140-2 validated one
C.Accept the risk because the algorithm is still functional
D.Transfer the risk by purchasing cyber insurance
AnswerB

Updating aligns with NIST SP 800-53 cryptographic controls.

Why this answer

NIST SP 800-53 requires that cryptographic algorithms used to protect data in transit must be FIPS 140-2 validated. A deprecated algorithm (e.g., DES, RC4, or 3DES) is no longer considered secure and must be replaced with a current, approved algorithm such as AES-256 or ChaCha20. Updating the encryption algorithm directly remediates the security finding and aligns with the risk management framework's requirement to maintain adequate security controls.

Exam trap

The trap here is that candidates may choose compensating controls (Option A) thinking they can avoid updating the encryption algorithm, but NIST SP 800-53 explicitly requires the use of FIPS 140-2 validated cryptography for data in transit, and compensating controls are not a substitute for a deprecated algorithm.

How to eliminate wrong answers

Option A is wrong because implementing compensating controls like network segmentation does not address the root cause of a deprecated encryption algorithm; segmentation can reduce the attack surface but does not fix the cryptographic weakness in the data-in-transit channel. Option C is wrong because accepting the risk of a deprecated algorithm violates NIST SP 800-53's requirement for FIPS 140-2 validated cryptography, and the algorithm being 'still functional' does not mean it provides adequate security against modern attacks (e.g., RC4 is broken). Option D is wrong because transferring risk via cyber insurance does not remediate the technical vulnerability; insurance covers financial loss but does not satisfy the compliance requirement to use approved encryption.

778
Drag & Dropmedium

Drag and drop the steps to perform a secure code review for a web application into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Secure code review: understand code, automated scan, manual review, document, and communicate findings.

779
MCQhard

An organization's risk register shows a critical risk with a very high annualized loss expectancy. Executive leadership decides the potential loss is unacceptable but concludes that no cost-effective control exists and that the activity generating the risk is essential to revenue. They formally document the decision, obtain board sign-off, and set a review date. Which risk treatment has leadership applied?

A.Risk avoidance
B.Risk transference
C.Risk acceptance
D.Risk mitigation
AnswerC

Acceptance is the deliberate decision to retain a risk after evaluating treatment options, usually with formal documentation and senior sign-off. Leadership judged the loss unacceptable but found no cost-effective control, kept the essential activity running, recorded the rationale, obtained board approval, and set a review date. Those actions are the defining characteristics of a formally accepted risk rather than avoidance, transference, or mitigation.

Why this answer

Risk acceptance is the conscious decision to retain an identified risk when treatment is not cost-effective or feasible, and it is legitimized through documented rationale, executive or board approval, and scheduled re-evaluation. Leadership continued the essential activity, applied no control, transferred nothing, and formally signed off with a review date. That combination distinguishes acceptance from avoidance, transference, and mitigation.

Exam trap

The trap here is confusing documented acknowledgment of an unremediated risk with mitigation, when the absence of any applied control and the decision to continue the activity indicate formal acceptance.

780
MCQmedium

You are a security consultant for a law firm that handles highly confidential client data. The firm wants to implement a data loss prevention (DLP) solution to prevent sensitive data from leaving the network via email. The firm's email system is Microsoft 365. The DLP policy must comply with the firm's data classification policy, which identifies 'Legal Strategy' as top secret and 'Client Contact Info' as confidential. The firm also wants to allow attorneys to send confidential information to clients with a business justification. Which of the following DLP rule configurations best meets these requirements?

A.Encrypt all emails containing any sensitive data and allow delivery
B.Block both top secret and confidential content with no override
C.Block top secret content and allow confidential content with an audit log
D.Block top secret content and allow confidential content with an override requiring a business justification
AnswerD

Blocking top secret content outright satisfies the Legal Strategy classification, while permitting confidential content with a justification override lets attorneys email Client Contact Info to clients as required. Microsoft Purview DLP policy tips enforce the override, capturing the business justification before release rather than silently blocking legitimate client communication.

Why this answer

It aligns with the firm's data classification policy by blocking top-secret 'Legal Strategy' content outright, while allowing 'Client Contact Info' (confidential) to be sent with a business justification override. This balances security with operational needs, as Microsoft 365 DLP supports policy tips and override options with justification for lower-sensitivity data, ensuring compliance without disrupting attorney-client communication.

Exam trap

The trap here is that candidates often confuse 'allow with audit log' (passive monitoring) with 'allow with override requiring justification' (active enforcement), overlooking the specific business requirement for a justification workflow.

How to eliminate wrong answers

Option A is wrong because encrypting all emails containing sensitive data does not prevent data leakage; it only protects data in transit, and the firm requires blocking top-secret content, not just encrypting it. Option B is wrong because blocking both top-secret and confidential content with no override is too restrictive; it would prevent attorneys from sending confidential client contact info even with a legitimate business need, violating the requirement to allow such communication with justification. Option C is wrong because allowing confidential content with only an audit log provides no enforcement mechanism; the firm explicitly requires a business justification override for confidential data, not just passive logging.

781
MCQmedium

A security architect is evaluating a SASE solution. Which capability is expected to be part of a SASE platform?

A.Intrusion prevention system (IPS) at the data center
B.Network segmentation via VLANs
C.Secure web gateway (SWG)
D.Virtual private network (VPN) concentrator
AnswerC

Secure web gateway is a core SASE capability, filtering web traffic and enforcing acceptable-use and threat policies at the cloud edge. SASE converges SWG with CASB, ZTNA and FWaaS, so SWG satisfies the expected-capability constraint rather than endpoint or on-premises controls.

Why this answer

Secure Web Gateway (SWG) is one of the core converged capabilities of a SASE platform, alongside CASB, ZTNA, FWaaS, and SD-WAN. SASE merges network and security functions into a cloud-delivered service, and SWG provides web filtering, malware inspection, and policy enforcement for user web traffic. It is explicitly expected in a SASE architecture.

Exam trap

CAS-005 often tests whether candidates can distinguish legacy on-premises controls (IPS appliances, VPN concentrators, VLANs) from the cloud-delivered converged services that define SASE — SWG is the canonical correct answer.

How to eliminate wrong answers

Option A is wrong because an IPS deployed at the data center is a traditional perimeter security control, not a cloud-delivered SASE component; SASE expects FWaaS/IPS capabilities delivered from the cloud edge, not a data-center appliance. Option B is wrong because VLAN-based network segmentation is a legacy LAN construct and is not a SASE capability — SASE uses identity- and policy-based microsegmentation delivered from the cloud. Option D is wrong because a VPN concentrator is a traditional remote-access appliance; SASE replaces this with ZTNA and cloud-delivered secure access rather than a centralized concentrator.

782
MCQmedium

A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for known attack patterns. The administrator wants to ensure that the NIDS can detect a specific SQL injection attempt that uses a particular string. Which Snort rule action and option combination will BEST accomplish this?

A.alert udp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
B.alert tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
C.drop tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
D.alert tcp any any -> any 443 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
AnswerB

This rule triggers an alert when the string '1=1' is found in TCP traffic destined for port 80. The content option performs a simple pattern match, which is effective for detecting known SQL injection strings. The alert action logs the event, allowing the administrator to be notified of potential attacks.

Why this answer

The goal is to detect a SQL injection attempt containing a specific string. Snort rules with the alert action and a content match on TCP port 80 are appropriate for unencrypted HTTP traffic. Using drop would block traffic, which is not required.

UDP or port 443 would not match typical SQL injection traffic. Thus, the rule with alert, TCP, port 80, and content match is correct.

Exam trap

The trap here is confusing detection with prevention, or assuming that HTTPS traffic can be inspected without decryption.

783
MCQmedium

A company is designing a secure web application that processes credit card payments. The architect needs to ensure that the application is resilient against SQL injection attacks. Which of the following is the most effective defense?

A.Use stored procedures exclusively for database access.
B.Deploy a web application firewall (WAF) with SQL injection rules.
C.Use parameterized queries or prepared statements for all database interactions.
D.Implement client-side input validation and sanitize all user input.
AnswerC

Parameterised queries separate SQL code from user-supplied data, so injected input is treated as a literal value rather than executable SQL. This structurally prevents injection, unlike input sanitisation or escaping, which rely on filtering and can be bypassed.

Why this answer

Parameterized queries (prepared statements) are the most effective defense against SQL injection because they separate SQL logic from user-supplied data at the database driver level. This ensures that user input is always treated as a literal value, never as executable SQL code, regardless of any malicious content. This approach directly prevents the attacker from altering the query structure, which is the root cause of SQL injection.

Exam trap

The trap here is that candidates often choose stored procedures (Option A) thinking they are inherently safe, but Cisco tests the nuance that stored procedures are only safe if they use parameterized queries internally, not if they concatenate input into dynamic SQL.

How to eliminate wrong answers

Option A is wrong because stored procedures alone do not prevent SQL injection if they are called with dynamically concatenated SQL strings or if the stored procedure itself uses dynamic SQL without parameterization. Option B is wrong because a WAF is a reactive, signature-based defense that can be bypassed with encoding variations or novel attack patterns; it does not fix the underlying vulnerability in the application code. Option D is wrong because client-side validation is easily bypassed (e.g., by disabling JavaScript or using tools like Burp Suite), and server-side sanitization is error-prone and often insufficient against all injection vectors.

784
Multi-Selectmedium

A security engineer is reviewing the configuration of a web application firewall (WAF) that protects a critical e-commerce site. Which TWO settings should be enabled to defend against SQL injection attacks? (Select TWO.)

Select 2 answers
A.Enable SQL injection signature rules.
B.Enable input validation for all query parameters.
C.Enable rate limiting on login endpoints.
D.Enable IP reputation blocking.
E.Enable SSL/TLS inspection for all traffic.
AnswersA, B

SQL injection signature rules inspect request payloads for known injection patterns, such as tautologies and UNION constructs, and block matching traffic. This provides direct detection and blocking of SQL injection attempts against the e-commerce site.

Why this answer

Option A is correct because enabling SQL injection signature rules lets the WAF match known SQLi patterns (e.g., UNION SELECT, OR 1=1, comment sequences) in request parameters, headers, and bodies, blocking or alerting on malicious payloads before they reach the application. Option B is correct because input validation for all query parameters enforces expected data types, lengths, and character sets, rejecting or sanitizing malformed input that could otherwise be interpreted as SQL syntax, providing a complementary defense beyond signature matching. Option C is not correct because rate limiting on login endpoints mitigates brute-force and credential-stuffing attacks, not SQL injection.

Option D is not correct because IP reputation blocking addresses known malicious sources but does not detect SQLi payloads from otherwise trusted or new IPs. Option E is not correct because SSL/TLS inspection decrypts traffic for analysis but does not itself identify or block SQL injection attempts.

Exam trap

The trap here is that candidates often confuse rate limiting or IP reputation as general security measures that would stop SQL injection, but these controls address different attack vectors (DoS and network-layer filtering) and do not inspect the content of requests for malicious SQL syntax.

785
MCQmedium

A financial services firm is designing a new online banking platform. The security architect must ensure that if the session token issued to a customer is stolen via a cross-site scripting attack, the attacker cannot use it from a different device or network. Which of the following should be implemented to meet this requirement?

A.Shortening the session token lifetime to five minutes and requiring re-authentication.
B.Token binding that cryptographically ties the session token to the client's TLS connection.
C.Encrypting the session token with AES-256 before writing it to the client's local storage.
D.Storing the session token in an HttpOnly cookie with the Secure and SameSite attributes.
AnswerB

Token binding uses the TLS layer to cryptographically associate the token with the client's key pair, so a stolen token cannot be replayed from a different TLS connection or device. This directly blocks the cross-device reuse scenario described, even if the token value is exfiltrated through XSS.

Why this answer

Token binding is the only mechanism that cryptographically links the session token to the client's TLS connection, so a token stolen via XSS cannot be replayed from a different device or network. Lifetime reduction, cookie flags, and local storage encryption mitigate other risks but do not satisfy the explicit cross-device reuse requirement.

Exam trap

The trap here is assuming that cookie security flags or shorter lifetimes prevent token replay across devices, when only cryptographic binding to the client's TLS session actually stops cross-device reuse.

786
Multi-Selecteasy

An organization is creating a data classification policy. Which THREE of the following are common classification levels used in government and defense? (Select THREE.)

Select 3 answers
A.Top Secret
B.Private
C.Secret
D.Confidential
E.Public
AnswersA, C, D

Top Secret is a standard classification.

Why this answer

Top Secret is a standard classification level in government and defense, indicating information that would cause exceptionally grave damage to national security if disclosed without authorization. It is the highest level in the U.S. classification system, defined under Executive Order 13526, and requires the most stringent access controls and handling procedures.

Exam trap

CompTIA CASP+ often tests the distinction between government/defense classification levels (Top Secret, Secret, Confidential) and commercial/private-sector labels (e.g., Private, Public, Internal), expecting candidates to recognize that 'Private' and 'Public' are not part of the official government classification hierarchy.

787
MCQmedium

A security operations center (SOC) analyst is investigating a potential security incident. The analyst needs to determine the order of events on a compromised Windows host. The analyst has access to the following artifacts: a memory dump, the Windows Event Log, and the file system metadata. Which of the following provides the most reliable timeline of user and system activity?

A.A combination of all three artifacts correlated together.
B.The memory dump, because it contains running processes and network connections at the time of capture.
C.The Windows Event Log, because it records all system and application events with timestamps.
D.The file system metadata, because it includes timestamps for file creation, modification, and access.
AnswerA

Correlating multiple artifacts provides the most reliable timeline. The Windows Event Log gives system and security events, file system metadata shows file operations, and memory dump reveals running processes and network state. Together, they compensate for individual limitations and provide a more complete picture. This approach is standard in digital forensics to establish an accurate sequence of events.

Why this answer

The most reliable timeline is obtained by correlating the Windows Event Log, file system metadata, and memory dump. Each source has unique data and limitations; combining them allows the analyst to cross-validate timestamps and activities. For example, a process execution in the event log can be linked to a file creation in metadata and a network connection in memory.

This multi-source correlation is essential for accurate incident reconstruction.

Exam trap

The trap here is assuming any single artifact provides a complete and tamper-proof timeline, when in fact each has gaps and can be manipulated.

788
MCQeasy

A security analyst is reviewing a SIEM alert that indicates a user's credentials were used to log in from two different countries within a span of 10 minutes. This is likely an indicator of what type of attack?

A.Brute-force attack
B.Man-in-the-middle attack
C.Credential theft and reuse
D.Pass-the-hash attack
AnswerC

Impossible travel detects the same credentials authenticating from geographically distant locations within a timeframe too short for physical transit. The 10-minute, two-country constraint makes concurrent credential theft and reuse the mechanism, since one user cannot be in both places.

Why this answer

A single user account authenticating from two geographically distant countries within 10 minutes is physically impossible for one person to do via normal travel, which strongly indicates the credentials have been stolen and are being reused by an attacker from a different location. This is the classic 'impossible travel' indicator of credential theft and reuse. The legitimate user and the attacker are using the same credentials from different locations, producing the anomalous login pattern.

Exam trap

The trap is focusing on the authentication mechanism (pass-the-hash, brute-force) rather than the behavioral signal (impossible travel); candidates who overthink the technical attack vector miss that two successful logins from distant countries in minutes is the textbook credential-theft-and-reuse indicator.

How to eliminate wrong answers

Option A is wrong because a brute-force attack involves many failed authentication attempts against an account, not two successful logins from different countries; the alert shows successful credential use, not repeated failures. Option B is wrong because a man-in-the-middle attack intercepts or alters traffic between two parties, which would not by itself produce two successful logins from different geographic locations. Option D is wrong because a pass-the-hash attack uses a captured NTLM hash to authenticate without the plaintext password, typically within the same network or domain, and does not inherently produce geographically dispersed logins — the question's key signal is location and timing, not the authentication mechanism.

789
MCQmedium

A DevOps team uses Ansible to automate server configuration. They need to ensure that sensitive variables like passwords are not exposed in playbook logs or version control. What is the recommended approach?

A.Use Ansible Vault to encrypt sensitive variables
B.Use environment variables only
C.Store secrets in plain text within the playbook
D.Encrypt the entire playbook file
AnswerA

Ansible Vault encrypts specific variables or files, protecting secrets.

Why this answer

Ansible Vault is the built-in mechanism for encrypting sensitive data such as passwords, API keys, and certificates within Ansible projects. It encrypts variables or files at rest using AES-256, and the vault password is provided at runtime (e.g., via --ask-vault-pass or a vault password file), ensuring secrets are never stored in plaintext in playbook logs or version control. This approach integrates seamlessly with Ansible's workflow without requiring external tools or compromising automation.

Exam trap

The CAS-004 exam often tests the distinction between encrypting the entire playbook versus selectively encrypting sensitive variables, tempting candidates to choose 'encrypt the whole file' as a stronger security measure, but the recommended approach is to use Ansible Vault for targeted encryption to maintain readability and operational flexibility.

How to eliminate wrong answers

Option B is wrong because environment variables can still be exposed in logs, process listings, or version control if not carefully managed, and they lack the native encryption and access control that Ansible Vault provides. Option C is wrong because storing secrets in plain text within the playbook directly violates security best practices and would expose sensitive data in logs, version control history, and any system with access to the playbook files. Option D is wrong because encrypting the entire playbook file is overly restrictive, prevents easy review of non-sensitive logic, and complicates collaboration; Ansible Vault allows selective encryption of only sensitive variables while keeping the rest of the playbook readable.

790
MCQhard

A healthcare provider must ensure that electronic protected health information (ePHI) stored in a public cloud object storage bucket is unreadable to the cloud provider and remains confidential even if the provider's infrastructure is compromised. The security architect wants to use a customer-managed key that never leaves the organization's on-premises hardware security module (HSM). Which approach should the architect implement?

A.Configure default encryption on the bucket using a provider-managed key and enable versioning
B.Enable provider-side encryption with a customer-provided key (SSE-C) and upload the key with each object request
C.Implement bucket policies that restrict access to a specific VPC endpoint and enable access logging
D.Use client-side encryption with a key stored in an on-premises HSM, encrypting data before it is uploaded to the bucket
AnswerD

Client-side encryption performed before upload ensures that the cloud provider only receives ciphertext and never has access to the plaintext or the encryption key. Keeping the key in an on-premises HSM prevents the provider from decrypting data even if its infrastructure is compromised, fully meeting the confidentiality requirement.

Why this answer

Client-side encryption with keys held in an on-premises HSM ensures that data is encrypted before it reaches the cloud, so the provider only stores ciphertext and never possesses the key. This architecture preserves confidentiality even if the provider's infrastructure is breached, which is essential for ePHI under strict regulatory requirements.

Exam trap

The trap here is confusing provider-side encryption options, such as SSE-C, with true customer-controlled encryption where the key never leaves the customer's premises.

791
MCQmedium

A security team is measuring the effectiveness of its incident response process. Which of the following metrics would best indicate how quickly the team can contain an incident after it is detected?

A.Mean time to respond (MTTR)
B.Vulnerabilities by severity
C.Patch compliance percentage
D.Mean time to detect (MTTD)
AnswerA

MTTR measures the elapsed time from incident detection to containment, directly quantifying response speed. Other metrics such as MTTD address detection latency, so MTTR is the precise indicator of how quickly the team contains a detected incident.

Why this answer

Mean time to respond (MTTR) measures the average time between incident detection and containment/resolution, directly reflecting how quickly the team can act once an incident is identified. It is the standard metric for response and containment speed in incident response frameworks such as NIST SP 800-61. The other options measure detection speed, vulnerability posture, or patch hygiene, not containment speed.

Exam trap

CAS-005 often tests the confusion between MTTD and MTTR — candidates must read whether the question asks about detecting an incident (MTTD) or responding to/containing it after detection (MTTR).

How to eliminate wrong answers

Option B is wrong because 'vulnerabilities by severity' is a risk-posture metric that counts open vulnerabilities by CVSS severity — it says nothing about how fast the team contains an active incident. Option C is wrong because 'patch compliance percentage' measures how many systems are up to date with patches, which is a preventive control metric, not a response-time metric. Option D is wrong because mean time to detect (MTTD) measures the time from incident occurrence to detection, which is the phase before response — the question specifically asks about containment after detection.

792
MCQeasy

What is the primary benefit of using infrastructure as code (IaC) tools like Terraform for cloud resource provisioning?

A.It reduces cloud costs by optimizing resource usage.
B.It eliminates the need for manual configuration management.
C.It provides a declarative language to define resources, enabling version control and repeatability.
D.It automatically applies security patches to resources.
AnswerC

Terraform's declarative HCL describes desired end state rather than imperative steps, so configurations live in version control and produce identical, repeatable provisioning. This satisfies the auditability and consistency requirement that manual console provisioning cannot deliver.

Why this answer

Infrastructure as Code (IaC) tools like Terraform use a declarative language (HCL) to define cloud resources in configuration files. This approach enables version control (e.g., Git), repeatable deployments, and consistent environments, which are the primary benefits of IaC over manual provisioning.

Exam trap

Common pitfall: Candidates often select a secondary benefit (like cost reduction or automated patching) instead of the primary benefit of IaC, which is declarative, version-controlled repeatability.

How to eliminate wrong answers

Option A is wrong because IaC does not directly reduce cloud costs; cost optimization requires separate practices like right-sizing, reserved instances, or auto-scaling policies. Option B is wrong because IaC does not eliminate manual configuration management entirely—it automates provisioning, but ongoing configuration management (e.g., using Ansible or Chef) may still be needed for OS-level settings. Option D is wrong because IaC does not automatically apply security patches; patch management is a separate operational process, though IaC can help ensure consistent baseline images.

793
MCQeasy

Refer to the exhibit. A security review is being conducted on the Python application configuration. Which of the following security issues is present?

A.The DB_CONNECTION environment variable is missing a default value
B.The default database connection is SQLite, which is insecure for production
C.The code does not handle the case where API_KEY is not set, potentially causing an error
D.The API key is stored in an environment variable, which is insecure
AnswerC

Reading API_KEY via os.environ without a fallback raises KeyError when the variable is absent, so the application crashes on startup or first use. The stem's configuration review asks for the security issue present, and unhandled missing secrets is that flaw.

Why this answer

The code attempts to retrieve the API_KEY environment variable using `os.environ['API_KEY']`, which raises a `KeyError` if the variable is not set. This lack of a fallback or error handling can cause the application to crash at startup, making it a security issue as it could lead to denial of service or expose stack traces in production logs.

Exam trap

CompTIA often tests the distinction between `os.environ[]` (raises error on missing key) and `os.getenv()` (returns default), leading candidates to overlook the missing default for API_KEY while focusing on the less critical DB_CONNECTION default or the storage method of the API key.

How to eliminate wrong answers

Option A is wrong because the DB_CONNECTION environment variable is accessed with `os.getenv('DB_CONNECTION', 'sqlite:///default.db')`, which provides a default value, so no issue exists. Option B is wrong because SQLite is not inherently insecure for production; the question focuses on configuration handling, not the database type, and SQLite can be secure with proper file permissions and encryption. Option D is wrong because storing an API key in an environment variable is a standard and recommended practice (e.g., 12-factor app methodology) compared to hardcoding it in source code; the insecurity here is the lack of a default or error handling, not the storage method itself.

794
MCQmedium

A company deploys a web application behind a WAF. The security team discovers that the WAF allows traffic from a known malicious IP. After investigating, they find the WAF is configured to allow all traffic from a specific country for business reasons. Which of the following is the BEST course of action?

A.Deploy an additional IPS device to block the IP.
B.Remove the country-based allow rule immediately.
C.Add a specific deny rule for the malicious IP within the country allow rule, using an exception list.
D.Change the WAF from detection mode to blocking mode.
AnswerC

A deny rule for the malicious IP placed above or within the country allow rule creates an exception, so legitimate country traffic still passes while that address is blocked. This satisfies the business constraint of retaining the country allow list without permitting a known threat.

Why this answer

The country-based allow rule exists for legitimate business reasons, so removing it outright would break required traffic. The correct approach is to preserve the business-justified allow rule while layering a more specific deny exception for the known malicious IP, since WAF rule precedence evaluates more specific rules before broader ones. This achieves both security and business continuity without disrupting legitimate users from that country.

Exam trap

The trap here is the instinct to 'remove the risky rule' or 'add another device,' when the exam expects the least-disruptive, most precise fix — a specific deny exception that preserves the business-justified allow rule.

How to eliminate wrong answers

Option A is wrong because adding an IPS device does not fix the WAF misconfiguration and introduces unnecessary complexity and cost; the malicious traffic is already being explicitly allowed by the WAF, so an IPS downstream may not see or block it consistently. Option B is wrong because removing the country allow rule immediately would break legitimate business traffic that the rule was created to permit, causing an availability incident. Option D is wrong because the WAF is already in blocking mode (it is allowing based on a rule, not merely detecting); switching modes does not address the specific allow rule that is permitting the malicious IP.

795
MCQmedium

A threat hunter hypothesizes that a sophisticated attacker is using DNS tunneling for command and control. Which data source would most likely confirm this activity?

A.Network flow data (NetFlow)
B.DNS query logs from authoritative/internal DNS servers
C.Endpoint antivirus alerts
D.Web proxy logs
AnswerB

DNS query logs capture the full request-and-response traffic tunnelling relies on, including the long, high-entropy subdomains and unusual record types (TXT, NULL) that encode exfiltrated data and C2 instructions. This directly satisfies the stem's requirement to confirm DNS tunnelling, since endpoint or flow data alone cannot reveal the encoded payload contents.

Why this answer

DNS tunneling encodes command-and-control data inside DNS queries and responses, so the authoritative or internal DNS server logs are the only data source that captures the full query strings, TXT/NULL record payloads, and response sizes needed to confirm the activity. These logs reveal anomalies such as unusually long subdomain labels, high-entropy hostnames, and excessive query volume to a single domain.

Exam trap

The trap is assuming network flow data is sufficient because it shows DNS traffic volume, when only DNS query logs contain the encoded payload needed to confirm tunneling.

How to eliminate wrong answers

Option A is wrong because NetFlow only records metadata (source/destination IP, port, byte counts) and cannot show the encoded payload inside DNS queries, so it can suggest volume anomalies but cannot confirm tunneling content. Option C is wrong because endpoint antivirus alerts focus on file-based or behavioral malware detections and typically do not inspect DNS query contents, so a tunneling implant may generate no AV alert at all. Option D is wrong because web proxy logs capture HTTP/HTTPS traffic, and DNS tunneling bypasses the proxy entirely by using port 53 to a DNS resolver.

796
MCQhard

A security team needs to automate the enforcement of cloud security policies across multiple accounts in AWS. They want a solution that uses code to define policies and automatically remediate violations. Which approach best meets these requirements?

A.Write Python boto3 scripts that run on a schedule to check and update security groups.
B.Use AWS Config with managed rules and custom Lambda functions for auto-remediation.
C.Enable AWS GuardDuty and rely on its threat detection alerts.
D.Deploy a third-party cloud security posture management (CSPM) tool like Prisma Cloud.
AnswerB

AWS Config continuously evaluates resource configurations against managed or custom rules, and its remediation actions trigger Lambda functions to correct non-compliant resources automatically. This satisfies the stem's dual requirement: defining policy as code and remediating violations without manual intervention, across the multiple AWS accounts in scope.

Why this answer

AWS Config with managed rules and custom Lambda functions enables automated enforcement of security policies across multiple AWS accounts. This approach uses code to define policies and automatically remediate violations via Lambda, meeting the requirement for automation and code-defined policies. Option A (boto3 scripts) is manual and not fully automated; Option C (GuardDuty) is reactive and focuses on threats, not policy enforcement; Option D (CSPM) is a third-party tool, not a code-defined approach within AWS.

797
MCQhard

A defense contractor must demonstrate compliance with NIST SP 800-171 for controlled unclassified information stored in a contractor-owned system. The compliance lead is preparing evidence for an upcoming assessment and wants to avoid the most common cause of failed assessments. Which activity best prevents assessment failure?

A.Producing a plan of action and milestones that lists every unimplemented requirement with target dates, even if no compensating controls exist.
B.Relying on the cloud service provider's FedRAMP authorization to inherit all 110 security requirements for the contractor system.
C.Maintaining artifacts that show each security requirement is implemented and periodically reviewed, tied to the specific system boundary being assessed.
D.Scheduling the assessment immediately after a penetration test so the most recent findings can serve as proof of implementation.
AnswerC

Assessment failures most often stem from missing or stale evidence rather than absent controls, so maintaining current artifacts that demonstrate each requirement operates within the defined system boundary directly addresses the root cause and lets assessors verify implementation without relying on interviews alone.

Why this answer

Assessments of controlled unclassified information environments fail most often because organizations cannot produce current, boundary-specific evidence for implemented requirements. Sustaining reviewed artifacts tied to the assessed system lets assessors verify each objective directly. Plans of action, provider inheritance, and penetration tests each address only part of the picture and cannot substitute for complete implementation evidence.

Exam trap

The trap here is treating a documented plan of action or inherited provider authorization as equivalent to implemented, evidenced controls within the assessed boundary.

798
MCQmedium

A multinational financial services firm is subject to GDPR and must transfer personal data from its EU offices to a data analytics vendor in the United States. The vendor is not certified under the EU-U.S. Data Privacy Framework. Which mechanism should the firm use to lawfully transfer the data while meeting GDPR Chapter V requirements?

A.Obtaining explicit consent from every data subject for each transfer
B.Standard Contractual Clauses (SCCs) with a transfer impact assessment
C.Relying on the vendor's ISO/IEC 27001 certification as an adequacy mechanism
D.Binding Corporate Rules (BCRs) approved by the lead supervisory authority
AnswerB

SCCs are pre-approved contractual terms adopted by the European Commission that provide appropriate safeguards for international data transfers when the destination country lacks an adequacy decision. Pairing them with a transfer impact assessment satisfies the Schrems II requirement to evaluate local surveillance laws. Because the vendor lacks Data Privacy Framework certification, SCCs are the correct lawful transfer mechanism here.

Why this answer

Because the U.S. vendor lacks Data Privacy Framework certification, the firm must rely on an Article 46 safeguard. Standard Contractual Clauses are the European Commission's pre-approved contractual terms for such transfers, and after Schrems II they must be supplemented by a transfer impact assessment evaluating the destination's surveillance laws. This combination lawfully supports routine transfers to the analytics provider.

Exam trap

The trap here is assuming that any vendor security certification, such as ISO/IEC 27001, automatically satisfies GDPR cross-border transfer requirements.

799
MCQeasy

A company wants to automate the creation of IAM roles and policies in AWS using infrastructure as code. Which tool is specifically designed for provisioning cloud infrastructure across multiple providers?

A.Terraform
B.Jenkins
C.Docker
D.Ansible
AnswerA

Terraform uses declarative HCL and a provider plugin model to provision infrastructure across AWS, Azure and others from one workflow, with state tracking for drift. This satisfies the stem's multi-provider requirement, unlike cloud-native tools such as CloudFormation that target a single vendor.

Why this answer

Terraform is a IaC tool focused on provisioning resources across cloud providers. Docker handles containers, Ansible is configuration management, and Jenkins is CI/CD.

800
MCQmedium

A vulnerability has a CVSS base score of 9.8. The vulnerability is present on a server that is not exposed to the internet but is accessible to internal users with valid credentials. Which CVSS metric should be adjusted to reflect the reduced risk?

A.None, the base score should be used as-is
B.Temporal score
C.Environmental score
D.Base score
AnswerC

The Environmental score adjusts the base metrics to reflect the assessed organisation's actual context, including mitigations and asset exposure. Since the server is internal-only and requires valid credentials, that reduced exploitability is captured here, not in the Temporal score, which covers exploit maturity and remediation level.

Why this answer

The Environmental Score allows customization based on specific organizational context, such as modified access requirements.

801
Multi-Selectmedium

A SOC team is implementing a SOAR playbook to automate the response to phishing emails reported by users. The playbook should perform initial triage and, if the email is determined to be malicious, take containment actions. Which TWO of the following actions should be included in the playbook? (Choose TWO.)

Select 2 answers
A.Send an alert to the user's manager for approval
B.Automatically create a ticket in the service desk system
C.Automatically block the sender's email address in the email gateway
D.Initiate a full antivirus scan on the user's workstation
E.Extract embedded URLs and file hashes for threat intelligence lookup
AnswersC, E

Blocking the sender's address at the gateway contains the campaign, preventing further delivery from that source to any recipient. This satisfies the playbook's containment requirement once triage confirms the email is malicious, limiting spread without manual intervention.

Why this answer

Option E is correct because extracting embedded URLs and file hashes is a core initial triage step in a phishing SOAR playbook — these indicators are submitted to threat intelligence platforms (e.g., VirusTotal, MISP) to determine whether the email is malicious before any containment action is taken. Option C is correct because, once the email is confirmed malicious, blocking the sender's address at the email gateway is a standard, low-risk containment action that prevents further messages from that sender reaching other users. Option A is not appropriate because requiring manager approval introduces a manual delay that defeats the purpose of an automated SOAR playbook and is not a triage or containment action.

Option B is not a triage or containment action; ticketing is a documentation/notification step, not part of the initial decision or containment logic. Option D is not indicated here because a full antivirus scan on the workstation is a host-level remediation action that is not triggered by email triage alone and would typically follow only if the user executed an attachment or payload.

Exam trap

The trap is selecting administrative or heavy remediation actions (ticket creation, manager approval, full AV scan) instead of the core triage and containment actions (IOC extraction and sender blocking); candidates must distinguish between 'nice to have' workflow steps and the essential automated triage/containment actions the question asks for.

802
MCQmedium

A security engineer is configuring a Linux server that hosts a web application. The engineer needs to ensure that the application runs with the least privilege necessary and that any compromise of the application is confined to a limited set of system resources. Which of the following should the engineer implement?

A.Running the web server as a non-root user without additional controls
B.SELinux in enforcing mode with a targeted policy for the web server
C.chroot jail for the web server process
D.AppArmor with a complain-mode profile for the web server
AnswerB

SELinux in enforcing mode applies mandatory access controls that confine the web server process to only the resources defined in its policy. This limits the impact of a compromise by preventing the process from accessing files or network ports outside its defined domain, thus achieving least privilege and confinement.

Why this answer

SELinux in enforcing mode enforces a mandatory access control policy that restricts the web server to only the resources it needs, such as specific files and network ports. This provides strong confinement and least privilege. The other options either do not enforce restrictions, provide only partial isolation, or rely on traditional permissions that are insufficient for limiting a compromised process.

Exam trap

The trap here is confusing logging or permissive modes with actual enforcement, or assuming that a chroot or non-root user provides complete isolation.

803
Multi-Selectmedium

A security analyst is investigating a potential data exfiltration incident. The analyst needs to preserve evidence for legal proceedings. Which two actions must the analyst take to maintain the chain of custody? (Select TWO).

Select 2 answers
A.Encrypt the evidence with a personal key
B.Share the evidence with all team members for analysis
C.Document every person who accesses the evidence and the time of access
D.Run antivirus scans on the evidence to ensure it is safe
E.Create a forensic image of the hard drive using a write-blocker
AnswersC, E

A documented access log records every individual who handles the evidence and when, forming the unbroken accountability trail that chain of custody demands for legal admissibility. Without this audit record, opposing counsel can challenge evidence integrity, so it directly satisfies the stem's legal-preservation constraint.

Why this answer

Option C is correct because chain of custody requires an unbroken, auditable record documenting every individual who handles or accesses the evidence, along with the date and time of each access, which is essential for the evidence to be admissible in legal proceedings. Option E is correct because creating a forensic image of the hard drive using a write-blocker preserves the original evidence in an unaltered state while allowing analysis to be performed on the copy; the write-blocker prevents any modification to the source drive, maintaining its integrity. Option A is incorrect because encrypting evidence with a personal key could render it inaccessible to investigators or the court and does not support an auditable custody record.

Option B is incorrect because indiscriminately sharing evidence with all team members breaks the controlled, documented access that chain of custody demands. Option D is incorrect because running antivirus scans can modify files or metadata on the evidence, potentially altering or destroying forensic artifacts.

Exam trap

CAS-005 often tests the misconception that antivirus scanning or encryption is part of evidence preservation; in reality, these actions can alter or restrict access to evidence, breaking the chain of custody.

804
MCQmedium

An incident responder notices that a compromised host is sending encrypted C2 traffic over TCP port 443. The existing firewall rule allows outbound HTTPS (443) to any destination. Which change to the security architecture would best detect this behavior while minimizing impact on legitimate traffic?

A.Deploy a forward proxy with SSL/TLS inspection
B.Block outbound TCP 443 and require users to use a VPN
C.Enable logging on the firewall for all outbound 443 traffic
D.Install a network-based IDS on the internal side of the firewall
AnswerA

TLS inspection terminates the encrypted session at the proxy, exposing the plaintext C2 payload for signature and behavioural analysis. The existing any-destination 443 rule otherwise renders the traffic opaque, so this satisfies the detection requirement while legitimate HTTPS continues through the same proxy path.

Why this answer

A forward proxy with SSL/TLS inspection decrypts outbound HTTPS traffic, allowing the security team to inspect the payload of connections over TCP 443. This reveals encrypted C2 traffic that would otherwise be hidden within legitimate HTTPS flows, while still permitting authorized business traffic to pass through after inspection.

Exam trap

The trap here is that candidates often assume a network-based IDS can detect malicious traffic in encrypted streams, but without decryption (as in a forward proxy with SSL inspection), the IDS sees only ciphertext and cannot analyze the payload.

How to eliminate wrong answers

Option B is wrong because blocking outbound TCP 443 entirely would disrupt all legitimate HTTPS traffic, causing significant business impact, and C2 traffic could simply shift to another port or use a VPN to bypass the block. Option C is wrong because merely enabling logging on the firewall for outbound 443 traffic only records metadata (source, destination, timestamps) but cannot inspect the encrypted payload, so the C2 traffic remains undetected. Option D is wrong because a network-based IDS placed on the internal side of the firewall sees only encrypted traffic on port 443 and cannot decrypt it, rendering it blind to the C2 content without SSL inspection capabilities.

805
Multi-Selectmedium

A company is adopting a serverless architecture using AWS Lambda. Which of the following are security concerns specific to serverless functions? (Select TWO.)

Select 2 answers
A.Insecure deserialization of function input
B.Event injection via malformed input
C.Container escape vulnerabilities
D.Overly permissive IAM roles assigned to the function
E.SQL injection in the database
AnswersB, D

Why this answer

Event injection via malformed input (B) is a specific serverless security concern because AWS Lambda functions are triggered by events from sources like API Gateway, S3, or DynamoDB Streams. An attacker can craft malicious input that exploits the function's event-handling logic, leading to unintended execution paths or data corruption. This differs from traditional injection attacks because the event structure itself can be manipulated to bypass validation.

Exam trap

CompTIA often tests the misconception that serverless functions are immune to injection attacks because they are 'stateless' or 'event-driven,' but the trap here is that event injection is a distinct attack vector where the event structure itself is the injection surface, not just the data within it.

Why the other options are wrong

A

A general web vulnerability, not specific to serverless.

C

Serverless functions run in isolated containers, but escape is more relevant to traditional containers.

E

A general web vulnerability, not specific to serverless.

806
MCQeasy

An organization wants to reduce the attack surface of its web servers by ensuring only necessary modules are enabled. Which practice directly supports this goal?

A.Patch management
B.Application whitelisting and module disablement
C.Regular backups
D.Multi-factor authentication
AnswerB

Disabling unused modules directly shrinks the web server's exploitable surface, satisfying the stem's requirement that only necessary modules stay enabled. Application whitelisting complements this by blocking unapproved executables, preventing attackers from loading rogue modules or code onto the hardened host.

Why this answer

Application whitelisting and module disablement. This practice directly reduces the attack surface by ensuring only authorized applications and necessary modules are enabled, eliminating unnecessary services that could be exploited. Option A (Patch management) addresses vulnerabilities in existing software but does not remove unused modules.

Option C (Regular backups) focuses on data recovery, not attack surface reduction. Option D (Multi-factor authentication) strengthens access control but does not limit enabled modules or applications.

807
MCQhard

A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?

A.Trusted Platform Module (TPM)
B.Hardware Security Module (HSM)
C.Software-based keystore
D.Key Management Service (KMS) in the cloud
AnswerB

An HSM stores private keys in tamper-resistant hardware and performs cryptographic operations internally, so keys are never exposed in software memory. This satisfies both stem constraints: secure private key storage and execution within a tamper-resistant environment.

Why this answer

An HSM is a dedicated, tamper-resistant hardware appliance that generates, stores, and uses cryptographic keys without ever exposing them to the host OS or application memory. It provides FIPS 140-2/3 validated key protection and performs crypto operations (signing, encryption, key wrapping) inside the secure boundary. For a PKI requiring secure private key storage and tamper-resistant cryptographic operations at scale, an HSM (or cloud HSM service) is the correct answer.

Exam trap

CAS-005 often tests the distinction between KMS (managed, software-centric key service) and HSM (dedicated tamper-resistant hardware); candidates pick KMS because it 'manages keys' but miss the tamper-resistant hardware requirement.

How to eliminate wrong answers

Option A is wrong because a TPM is a single-chip, host-bound module designed to protect keys for one machine (e.g., BitLocker, measured boot); it is not a scalable, network-accessible PKI key store and does not provide the throughput or multi-tenant key management an enterprise PKI requires. Option C is wrong because a software-based keystore stores keys in files or memory protected only by OS permissions — keys can be extracted via memory dumps or privilege escalation, and there is no tamper-resistant hardware boundary. Option D is wrong because a general cloud KMS provides managed key storage and rotation, but it is typically a multi-tenant software service (unless backed by Cloud HSM); it does not by itself guarantee a dedicated tamper-resistant hardware boundary for all cryptographic operations the way an HSM does.

808
MCQeasy

A security administrator is configuring a RADIUS server for a wireless network. The administrator wants to ensure that the shared secret between the access point and the RADIUS server is protected against eavesdropping. Which protocol should be used to encapsulate RADIUS traffic?

A.RADIUS with MS-CHAPv2
B.RADIUS over TLS (RadSec)
C.RADIUS over UDP with IPsec transport mode
D.RADIUS with EAP-TTLS
AnswerB

RadSec encapsulates RADIUS in TLS, providing encryption and integrity for the shared secret and all authentication traffic. Standard RADIUS uses a shared secret to obfuscate passwords but does not encrypt the entire packet, leaving it vulnerable to eavesdropping. RadSec protects against this by securing the entire communication channel.

Why this answer

RadSec (RADIUS over TLS) is the standard protocol for securely encapsulating RADIUS traffic. It uses TLS to encrypt the entire RADIUS conversation, including the shared secret, protecting against eavesdropping. Other options either do not encrypt the RADIUS packet fully or are authentication methods that do not address the shared secret protection.

Exam trap

The trap here is confusing authentication protocols like EAP-TTLS with transport protection mechanisms for RADIUS itself, or assuming that IPsec is the only way to secure RADIUS.

809
MCQhard

During a penetration test, a tester finds that an application uses server-side sessions with predictable session IDs. Which attack is this vulnerability most likely to facilitate?

A.Session fixation
B.Clickjacking
C.Session hijacking
D.CSRF
AnswerC

Predictable server-side session identifiers let an attacker guess or enumerate a valid ID and present it in a cookie, impersonating the authenticated user without credentials. That predictability directly enables session hijacking, the attack this weakness most readily facilitates.

Why this answer

Predictable session IDs allow an attacker to guess or calculate a valid session identifier for an authenticated user. By obtaining or predicting the session ID, the attacker can impersonate that user and gain unauthorized access to the application, which is the essence of session hijacking. This attack directly exploits weak session ID generation or insufficient entropy in the server-side session management.

Exam trap

The trap here is that candidates often confuse session hijacking with session fixation, but session fixation requires the attacker to force a specific session ID onto the victim, whereas predictable session IDs enable the attacker to simply guess or calculate the victim's current session ID without any prior interaction.

How to eliminate wrong answers

Option A is wrong because session fixation requires the attacker to set a known session ID on the victim's browser (e.g., via a URL parameter or cookie injection) before the victim logs in, not simply predicting server-generated IDs. Option B is wrong because clickjacking relies on transparent overlays and UI redressing to trick users into clicking unintended elements, not on session ID predictability. Option D is wrong because CSRF (Cross-Site Request Forgery) forces an authenticated user to execute unwanted actions via crafted requests, but it does not require or exploit predictable session IDs; it typically leverages the user's existing session cookie.

810
MCQhard

A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect must ensure that inter-service communication is encrypted, mutually authenticated, and that services can be authorized based on their identity. Which of the following should the architect implement to meet these requirements?

A.Use Kubernetes Secrets to store TLS certificates and manually configure each service to use them.
B.Implement an API gateway that terminates TLS and performs authentication for all inbound traffic.
C.Deploy a service mesh with mutual TLS (mTLS) and identity-based authorization policies.
D.Configure Kubernetes Network Policies to allow only specific pod-to-pod traffic.
AnswerC

A service mesh such as Istio or Linkerd provides transparent mTLS for all inter-service communication, encrypting traffic and authenticating both ends using service identities (e.g., SPIFFE IDs). It also enables fine-grained authorization policies based on those identities. This directly satisfies the requirements for encryption, mutual authentication, and identity-based authorization.

Why this answer

A service mesh with mTLS provides transparent encryption and mutual authentication for all service-to-service communication, using verifiable identities. Its authorization policies can enforce access based on those identities, which is essential for zero-trust microservices. The other options either lack encryption, mutual authentication, or are limited to external traffic, failing to secure east-west communication.

Exam trap

The trap here is confusing network segmentation or API gateways with service mesh capabilities; only a service mesh provides built-in mTLS and identity-based authorization for inter-service traffic.

811
MCQhard

An organization is adopting a SASE architecture to provide secure access to cloud applications. Which component is essential for enforcing security policies based on user identity and device posture?

A.Zero Trust Network Access (ZTNA)
B.Firewall as a Service (FWaaS)
C.Secure Web Gateway (SWG)
D.Cloud Access Security Broker (CASB)
AnswerA

ZTNA brokers each session, verifying user identity and device posture before granting least-privilege access to specific applications rather than the whole network. This identity- and posture-based policy enforcement satisfies the SASE requirement, unlike IP-centric VPNs or proxy-only controls.

Why this answer

Zero Trust Network Access (ZTNA) is essential for enforcing security policies based on user identity and device posture in a SASE architecture. ZTNA provides secure, identity-based access to applications, ensuring that only authenticated and authorized users with compliant devices can connect, regardless of location.

Exam trap

CAS-005 often tests the confusion between SASE components. Candidates may select CASB or SWG because they are also part of SASE, but only ZTNA enforces policies based on user identity and device posture.

How to eliminate wrong answers

Option B is wrong because Firewall as a Service (FWaaS) provides network-level security but does not enforce policies based on user identity and device posture; it focuses on traffic filtering. Option C is wrong because Secure Web Gateway (SWG) primarily filters web traffic and enforces acceptable use policies, but it does not provide identity-based access to applications. Option D is wrong because Cloud Access Security Broker (CASB) provides visibility and control over cloud services, but it does not enforce access based on device posture; it focuses on data security and compliance.

812
MCQhard

After containing a confirmed security incident, the incident response team must plan for eradication. What must be done before eradication begins?

A.Conduct a full forensic analysis of all systems
B.Determine the root cause of the incident
C.Begin eradication immediately to minimize dwell time
D.Notify law enforcement agencies
AnswerB

Eradication removes the adversary's foothold, so the team must first establish root cause to identify every compromised account, persistence mechanism and entry point. Without it, removal is guesswork and the attacker can re-enter through the same vector.

Why this answer

Before eradication, the incident response team must determine the root cause of the incident. This is essential to ensure that all components of the threat are identified and removed, and to prevent reoccurrence. Eradication involves removing the threat, but without understanding the root cause, the team might miss additional backdoors or persistence mechanisms.

Exam trap

CAS-005 often tests the order of incident response phases; candidates may confuse eradication with containment or recovery, or assume that eradication can begin immediately without root cause analysis.

How to eliminate wrong answers

Option A is wrong because a full forensic analysis is not always required before eradication; it may be conducted in parallel or after, depending on the incident. Option C is wrong because beginning eradication immediately without understanding the root cause can lead to incomplete removal and reinfection. Option D is wrong because notifying law enforcement is not a prerequisite for eradication and is only done in specific cases.

813
MCQmedium

A software company is pursuing ISO/IEC 27001 certification. The ISMS scope covers its cloud-hosted product and corporate IT. An auditor requests evidence that management reviews the ISMS at planned intervals. Which artifact should the security manager provide?

A.The latest internal audit report and nonconformity log
B.Business continuity and disaster recovery test results
C.The Statement of Applicability listing implemented controls
D.Management review meeting minutes with inputs, decisions, and actions
AnswerD

ISO/IEC 27001 clause 9.3 requires top management to review the ISMS at planned intervals, and documented minutes showing inputs, decisions, and actions are the expected evidence. These records demonstrate that leadership evaluated performance, risks, and opportunities and directed changes. Providing them directly satisfies the auditor's request for management review evidence.

Why this answer

Clause 9.3 of ISO/IEC 27001 mandates that top management review the ISMS at planned intervals, considering status of actions, changes, performance feedback, and risk assessment results. Documented minutes capturing inputs, decisions, and resulting actions are the direct evidence auditors seek. Other artifacts such as internal audit reports or the Statement of Applicability may feed the review but do not demonstrate that it took place.

Exam trap

The trap here is treating any governance-related document, such as the Statement of Applicability, as proof of management review without matching it to clause 9.3.

814
MCQhard

A security architect is designing a system that requires secure key exchange over an untrusted network. The system must provide perfect forward secrecy (PFS) and must be resistant to quantum computer attacks. Which key exchange algorithm BEST meets these requirements?

A.RSA key exchange with 4096-bit keys
B.Diffie-Hellman Ephemeral (DHE) with 2048-bit parameters
C.Post-quantum key exchange using lattice-based cryptography (e.g., Kyber)
D.Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) with Curve25519
AnswerC

Lattice-based key exchange mechanisms like Kyber are designed to be resistant to quantum attacks while also supporting ephemeral key generation to provide perfect forward secrecy. Kyber is a NIST-standardized post-quantum algorithm, making it the best choice for this scenario that demands both PFS and quantum resistance.

Why this answer

The requirements are perfect forward secrecy and resistance to quantum attacks. Traditional key exchanges like RSA, DHE, and ECDHE provide PFS but are vulnerable to quantum computers. Lattice-based post-quantum algorithms such as Kyber are designed to withstand quantum attacks and can be used in ephemeral modes to achieve PFS, making them the only suitable option.

Exam trap

The trap here is assuming that any ephemeral Diffie-Hellman variant provides quantum resistance, when in fact all classical DH and ECC are quantum-vulnerable.

815
Multi-Selecteasy

A security engineer is hardening a Linux server. Which TWO of the following are best practices for preventing privilege escalation attacks?

Select 2 answers
A.Disable all user accounts except root
B.Apply kernel hardening with sysctl
C.Enable SELinux in enforcing mode
D.Remove the SUID bit from all binaries
E.Restrict cron jobs to root only
AnswersB, C

sysctl tunes kernel parameters at runtime, such as disabling IP forwarding or restricting dmesg and kptr access. These settings shrink the kernel attack surface that local users could exploit to gain elevated privileges, directly satisfying the hardening requirement.

Why this answer

Option B is correct because applying kernel hardening with sysctl (e.g., setting kernel.kptr_restrict, kernel.dmesg_restrict, kernel.yama.ptrace_scope, and disabling unprivileged user namespaces) reduces the kernel attack surface and blocks common privilege-escalation vectors such as kernel pointer leaks and ptrace-based injection. Option C is correct because running SELinux in enforcing mode confines processes with mandatory access control (type enforcement, domain transitions), so even if an attacker exploits a service, the policy limits what the compromised domain can do and prevents escalation to unconfined root. Option A is wrong because disabling all non-root accounts is not a hardening practice; it breaks accountability and least privilege, and root-only access increases risk rather than preventing escalation.

Option D is wrong because removing the SUID bit from all binaries indiscriminately breaks legitimate tools like sudo, passwd, and ping; SUID should be audited and minimized, not globally stripped. Option E is wrong because restricting cron to root alone does not prevent privilege escalation and can conflict with legitimate per-user or system maintenance jobs; cron should instead be permission-controlled and monitored.

Exam trap

CAS-005 often tests the misconception that 'removing SUID from all binaries' or 'disabling non-root accounts' is a hardening best practice, when in fact these break functionality and violate least-privilege principles.

816
Multi-Selectmedium

An IoT device uses a Trusted Platform Module (TPM) 2.0 for secure boot and attestation. Which THREE of the following functions does the TPM provide to support these security features?

Select 3 answers
A.Accelerated symmetric encryption
B.Platform Configuration Registers (PCRs) for storing measurements
C.Hardware random number generation
D.Sealed storage that decrypts data only if PCR values match expected measurements
E.Remote attestation using TPM_Quote to sign PCR values
AnswersB, D, E

PCRs are shielded registers that hold cumulative hashes of firmware and software measurements taken during boot. Secure boot compares these values against expected ones, and attestation reports them, so PCRs provide the measurement storage underpinning both features.

Why this answer

Option B is correct because TPM 2.0 provides Platform Configuration Registers (PCRs), which are shielded registers used to store cryptographic measurements (hashes) of firmware, boot loaders, and OS components during secure boot, forming the basis for integrity verification. Option D is correct because sealed storage binds a decryption key to specific PCR values, so the protected data can only be unsealed when the platform's measurements match the expected known-good state, enforcing secure boot integrity. Option E is correct because remote attestation relies on the TPM_Quote command, which signs the current PCR values with an Attestation Identity Key (AIK) so a remote verifier can confirm the device's boot state.

Option A is not correct because TPM 2.0 is not designed for accelerated bulk symmetric encryption; it only offers limited cryptographic operations and is far too slow for that purpose. Option C is not correct because, although TPM 2.0 includes a hardware random number generator, it is not one of the functions specifically supporting secure boot and attestation as described in this scenario.

817
MCQeasy

Which of the following best describes the security benefit of using an API gateway in a microservices architecture?

A.It eliminates the need for input validation in individual microservices
B.It encrypts all data between the client and server using mTLS
C.It enforces security policies such as authentication and rate limiting centrally
D.It automatically load balances traffic to ensure high availability
AnswerC

An API gateway sits in front of microservices and applies authentication, authorisation, throttling and rate limiting at that single ingress point. This centralises enforcement, so individual services need not each implement these controls, satisfying the requirement for consistent, centrally managed security policy.

Why this answer

An API gateway sits in front of microservices and acts as a single entry point for all client requests, making it the ideal enforcement point for cross-cutting security controls. Centralizing authentication (e.g., OAuth2/JWT validation), authorization, rate limiting, and threat protection at the gateway means individual microservices don't each need to reimplement these policies. This reduces attack surface and ensures consistent policy enforcement across the entire API estate.

Exam trap

The trap here is conflating availability features (load balancing) with security features, or assuming the gateway replaces rather than centralizes security controls — candidates often pick the 'eliminates validation' answer because it sounds efficient.

How to eliminate wrong answers

Option A is wrong because input validation must still occur within each microservice — the gateway can perform schema validation but cannot replace service-level business logic validation, and relying solely on the gateway violates defense-in-depth. Option B is wrong because while API gateways can terminate TLS and support mTLS, they do not inherently 'encrypt all data' — encryption depends on configuration, and mTLS is a mutual authentication mechanism, not a blanket encryption guarantee. Option D is wrong because load balancing is an availability/scalability function, not a security benefit, and it does not describe the security value the question asks about.

818
MCQmedium

A security architect is evaluating a SASE solution. Which component of SASE is primarily responsible for inspecting encrypted traffic for threats?

A.Zero Trust Network Access (ZTNA)
B.Next-generation firewall (NGFW)
C.Secure web gateway (SWG)
D.SD-WAN edge
AnswerC

The secure web gateway performs full TLS inspection, decrypting outbound sessions, applying URL filtering, malware scanning and data-loss rules, then re-encrypting traffic. That decryption capability is what lets SASE inspect encrypted traffic for threats, unlike components such as SD-WAN or zero-trust network access.

Why this answer

The Secure Web Gateway (SWG) is the SASE component that proxies outbound user web traffic and performs full TLS inspection, URL filtering, malware scanning, and DLP on decrypted content. Because it terminates and re-originates TLS sessions, it can inspect encrypted traffic for threats. This is its core function within the SASE stack.

Exam trap

CAS-005 often tests the SASE component mapping; candidates confuse ZTNA (access to private apps) with SWG (inspection of outbound web traffic), or assume NGFW handles all inspection in a SASE model.

How to eliminate wrong answers

Option A is wrong because ZTNA provides identity- and context-based access to internal applications (replacing VPN), not inspection of outbound web traffic for threats; it enforces access, it does not decrypt and scan content. Option B is wrong because an NGFW enforces network-layer policy (L3-L7) at the perimeter or between segments, but in SASE architectures the SWG — not the NGFW — is the component designed for full web traffic TLS inspection and content threat scanning. Option D is wrong because the SD-WAN edge handles WAN transport optimization, path selection, and connectivity, not content inspection or TLS decryption.

819
MCQmedium

In a CI/CD pipeline, a security gate fails because a high-severity vulnerability is found in the base image of a container. The pipeline is configured to block deployment on such findings. What is the appropriate remediation step?

A.Update the base image to a patched version
B.Override the security gate and proceed with deployment
C.Rebuild the image using the same base image
D.Add the vulnerability to an exception list
AnswerA

The vulnerability originates in the base image layer, so rebuilding the image on a patched base removes the vulnerable package while preserving application layers. This satisfies the blocking gate by eliminating the high-severity finding at its source, rather than suppressing the scan or excluding the image.

Why this answer

Updating the base image to a patched version ensures the vulnerability is fixed. Overriding the gate or adding exceptions bypasses security, and rebuilding with the same base retains the issue.

820
MCQhard

The engineer needs to prevent brute-force attacks while allowing legitimate access. Which security control is MOST effective?

A.Disable root login
B.Change SSH port to 2222
C.Implement fail2ban with a threshold of 5 attempts per minute
D.Implement IP whitelist for 10.0.0.0/8
AnswerC

Fail2ban dynamically bans source IPs after repeated authentication failures, directly throttling brute-force attempts while legitimate users continue unaffected. The five-per-minute threshold satisfies the stem's dual constraint: blocking automated guessing without locking out genuine access, unlike static lockout policies that deny valid users.

Why this answer

Fail2ban is a security tool that monitors log files for suspicious patterns, such as repeated failed login attempts, and dynamically updates firewall rules to block the offending IP addresses. Implementing fail2ban with a threshold of 5 attempts per minute effectively mitigates brute-force attacks by temporarily or permanently banning IPs that exceed the threshold, while allowing legitimate users to access the system. This is more effective than the other options because it actively responds to brute-force behavior.

Exam trap

The trap is choosing a simple hardening measure like changing the SSH port or disabling root login, which are good practices but do not actively prevent brute-force attacks, whereas fail2ban provides active blocking based on behavior.

How to eliminate wrong answers

Option A is wrong because disabling root login only prevents direct root access but does not stop brute-force attacks on other accounts. Option B is wrong because changing the SSH port to 2222 is security through obscurity and does not prevent brute-force attacks; attackers can scan for the new port. Option D is wrong because an IP whitelist for 10.0.0.0/8 would block all other IPs, including legitimate remote users, and is not practical for allowing broad access.

821
MCQmedium

A company is migrating its workloads to a public cloud and wants to ensure it understands the division of security responsibilities. Which model defines the demarcation of security controls between the cloud provider and the customer?

A.Cloud Security Posture Management (CSPM)
B.Zero trust architecture
C.Cloud Access Security Broker (CASB)
D.Shared responsibility model
AnswerD

The shared responsibility model divides security controls along the cloud service model's boundary: the provider secures the physical hosts, network and hypervisor up to the layer it operates, while the customer secures what they configure, such as data, identities and access policies. This directly answers the stem's need to understand the demarcation of controls between provider and customer.

Why this answer

The shared responsibility model clearly delineates which security tasks are handled by the cloud provider and which by the customer, varying by service type (IaaS, PaaS, SaaS).

822
Multi-Selecthard

A security architect is designing a data loss prevention (DLP) program for a company that uses Microsoft 365 and a SaaS CRM. The architect must reduce false positives while still detecting sensitive data leaving the environment. Which TWO capabilities should be prioritized? (Choose two.)

Select 2 answers
A.Blocking all outbound email attachments larger than 10 MB
B.Keyword lists built from common industry terms such as 'confidential' and 'internal use'
C.Trainable classifiers that learn from labeled examples of the organization's confidential documents
D.Exact data matching (EDM) against a hashed fingerprint of the organization's customer records
E.Regular expressions that match any nine-digit number as a potential account identifier
AnswersC, D

Trainable classifiers use machine learning on labeled samples to recognize categories such as contracts or source code, which pattern matching cannot. Combining them with EDM lets the program detect both known records and semantic categories, improving coverage without flooding analysts with false positives from generic regex rules.

Why this answer

High-fidelity DLP combines exact data matching, which fingerprints the organization's own sensitive records, with trainable classifiers that recognize document categories from labeled examples. Together they detect both known data and semantically sensitive content while avoiding the noise of generic regex or keyword rules. Size limits and broad patterns do not target sensitive content and increase false positives.

Exam trap

The trap here is assuming broader detection rules always improve DLP, when in fact overly broad patterns and keywords drive false positives and analyst fatigue.

823
Multi-Selecthard

During a penetration test, the tester has gained initial access to a web server and wants to perform lateral movement to reach a database server. The tester enumerates the network and finds that the web server has two network interfaces: one connected to a DMZ and one to an internal network. The database server is on the internal network. Which TWO techniques could the tester use to pivot from the web server to the database server? (Choose TWO.)

Select 2 answers
A.Use SSH tunneling to create a local forward to the database server's port
B.Perform a SQL injection attack against the database server
C.Deploy a reverse shell from the web server to the tester's machine
D.Install a keylogger on the web server to capture database credentials
E.Use Metasploit's route add command to add a route to the internal subnet through the web server
AnswersA, E

SSH local port forwarding binds a listener on the tester's host that relays traffic through the compromised dual-homed web server to the database server's internal port, exploiting the web server's DMZ and internal interfaces to cross the network boundary.

Why this answer

Option A is correct because SSH local port forwarding (ssh -L) lets the tester tunnel traffic from their machine through the compromised web server to reach the database server's port on the internal network, effectively pivoting across the dual-homed host. Option E is correct because Metasploit's 'route add' command (e.g., route add <internal_subnet> <session_id>) configures the framework to route traffic for the internal subnet through the existing Meterpreter session on the web server, enabling pivoting to the database server. Option B is incorrect because SQL injection targets a database through a vulnerable web application and does not provide network-level pivoting from the web server to the internal database server.

Option C is incorrect because a reverse shell only establishes command-and-control back to the tester's machine; it does not route traffic into the internal network. Option D is incorrect because a keylogger passively captures credentials on the web server and does not create a pivot path to the database server.

824
MCQmedium

A security architect is designing a new authentication system for a cloud-based application that requires strong multi-factor authentication. The solution must be resistant to phishing attacks and not rely on shared secrets. Which of the following is the BEST choice?

A.HOTP with a hardware token
B.FIDO2/WebAuthn
C.TOTP via a mobile authenticator app
D.SMS one-time passcodes
AnswerB

FIDO2/WebAuthn satisfies both constraints by using public-key cryptography: the authenticator holds a private key, while the server stores only the public key, so no shared secret crosses the wire. Origin binding ties each credential to the legitimate domain, defeating phishing proxies that replay credentials against lookalike sites.

Why this answer

FIDO2/WebAuthn is a passwordless authentication protocol that uses public key cryptography and is resistant to phishing because the private key never leaves the user's device.

825
MCQhard

An OpenVPN configuration file is shown. A security auditor recommends replacing the cipher and auth directives. Which of the following is the BEST replacement pair from a security engineering perspective?

A.cipher AES-256-GCM and auth SHA256
B.cipher AES-128-GCM and auth SHA384
C.cipher 3DES-168 and auth MD5
D.cipher Blowfish-128 and auth SHA1
AnswerA

AES-256-GCM is an AEAD cipher that includes authentication, so the auth directive becomes unnecessary; however, OpenVPN allows both. This is a secure modern combination.

Why this answer

Cipher AES-256-GCM and auth SHA256, is the best replacement pair. AES-256-GCM is an AEAD cipher that provides both confidentiality and integrity, making the auth directive redundant but still compatible with SHA256. AES-256-GCM is considered strong and current.

Option B uses AES-128-GCM with SHA384; while still secure, AES-256 is generally preferred for higher security margins. Option C uses 3DES-168 and MD5, both of which are weak and deprecated. Option D uses Blowfish-128 and SHA1, where Blowfish is outdated and SHA1 is considered weak.

Page 10

Page 11 of 13

Page 12