Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 901–973

973 questions total · 13pages · All types, answers revealed

Page 12

Page 13 of 13

901
Multi-Selecthard

Which three measures should be implemented to secure a RESTful API? (Select THREE.)

Select 3 answers
A.Use JSONP for cross-origin requests
B.Implement proper error handling that does not expose stack traces
C.Disable rate limiting to ensure availability
D.Validate all input against a strict schema
E.Use OAuth2 with scopes for authorization
AnswersB, D, E

Generic error messages prevent information leakage.

Why this answer

Proper error handling in a RESTful API must never expose stack traces or internal implementation details to the client. Stack traces can reveal file paths, database schemas, library versions, and logic flows that attackers can exploit to craft targeted attacks. Instead, the API should return generic error messages (e.g., '500 Internal Server Error') while logging full details server-side for debugging.

Exam trap

CASP+ often tests the misconception that disabling rate limiting improves availability, when in fact it destroys availability by removing protection against resource exhaustion attacks.

902
MCQmedium

A company is deploying a SASE architecture. Which component is responsible for securing web traffic and enforcing acceptable use policies at the edge?

A.Zero Trust Network Access (ZTNA)
B.Secure Web Gateway (SWG)
C.Cloud Access Security Broker (CASB)
D.SD-WAN
AnswerB

Secure Web Gateway sits at the edge and inspects outbound web traffic, enforcing acceptable use policies, URL filtering and threat protection. It satisfies the stem's requirement to secure web traffic and apply acceptable use controls within the SASE architecture.

Why this answer

A Secure Web Gateway (SWG) sits at the network edge and inspects outbound web traffic, enforcing URL filtering, malware blocking, and acceptable use policies — exactly the function described. In a SASE architecture, SWG is the component that governs user web access regardless of location, applying policy based on categories, reputation, and content inspection. It is distinct from ZTNA (which controls application access), CASB (which governs cloud service usage), and SD-WAN (which optimizes WAN transport).

Exam trap

CAS-005 often tests the blurry boundary between SWG, CASB, and ZTNA — candidates pick CASB for 'cloud app control' or ZTNA for 'edge security' when the question specifically describes web traffic filtering and acceptable use, which is SWG's domain.

How to eliminate wrong answers

Option A is wrong because ZTNA provides identity- and context-based access to internal applications, not web traffic filtering or acceptable use enforcement. Option C is wrong because CASB focuses on discovery, governance, and policy enforcement for cloud applications (SaaS/IaaS), not general web browsing policy. Option D is wrong because SD-WAN is a networking technology for optimizing and routing WAN traffic; it does not perform security inspection or acceptable use enforcement.

903
MCQhard

A security audit reveals that Docker containers are built with multiple unnecessary layers and utilities. Which practice reduces the attack surface of the container image?

A.Use multi-stage builds
B.Use a base image with only the required packages
C.Combine multiple RUN commands into one
D.Delete the apt cache in the Dockerfile
AnswerB

Minimizing installed packages reduces the attack surface.

Why this answer

Using a base image with only the required packages directly reduces the attack surface by eliminating unnecessary binaries, libraries, and services that could contain vulnerabilities. This practice aligns with the principle of minimalism in container security, where every extra package increases the potential for exploitation. Unlike multi-stage builds or RUN command consolidation, this approach targets the root cause: the contents of the image itself.

Exam trap

The CAS-004 exam often tests the misconception that reducing image size (via multi-stage builds or cache deletion) is equivalent to reducing attack surface, but the real security improvement comes from removing unnecessary software, not just shrinking the image.

How to eliminate wrong answers

Option A is wrong because multi-stage builds primarily reduce image size by separating build-time dependencies from runtime artifacts, but they do not inherently reduce the attack surface if the final stage still contains unnecessary packages. Option C is wrong because combining multiple RUN commands into one reduces the number of layers, which can slightly improve build efficiency and reduce layer count, but it does not remove unnecessary utilities or packages from the image. Option D is wrong because deleting the apt cache reduces image size but does not eliminate the unnecessary packages themselves; the vulnerable binaries and libraries remain installed.

904
MCQeasy

During a threat hunting exercise, a security analyst hypothesizes that adversaries may be using PowerShell to execute commands in memory. Which threat hunting methodology is being employed?

A.Signature-based hunting
B.TTP-driven hunting
C.Hypothesis-driven hunting
D.IoC-driven hunting
AnswerC

Hypothesis-driven hunting begins with a formulated proposition — here, that adversaries execute PowerShell in memory — then tests it against telemetry. It differs from intelligence-driven hunting, which starts from known indicators, and from situational-awareness hunting, which explores anomalies without a stated premise.

Why this answer

Hypothesis-driven hunting starts with a hypothesis about potential adversary behavior, then searches for evidence. IoC-driven uses indicators of compromise, and TTP-driven focuses on tactics, techniques, and procedures.

905
MCQeasy

A security manager is reviewing the company's vendor risk management program. Which of the following should be included as a mandatory step BEFORE entering into a contract with a new cloud service provider?

A.Establishing an incident response plan
B.Performing a penetration test of the vendor's infrastructure
C.Conducting a third-party security assessment
D.Requesting monthly vulnerability reports
AnswerC

A third-party security assessment independently verifies the provider's controls, certifications and data-handling practises before contractual commitment, giving the security manager evidence to judge residual risk. This due diligence must precede signing, since contractual leverage and exit options diminish afterwards.

Why this answer

A third-party security assessment is a mandatory due diligence step before entering into a contract with a new cloud service provider. This assessment evaluates the vendor's security controls, compliance posture, and risk profile against the organization's requirements, ensuring that the vendor meets minimum security standards before any data or systems are entrusted to them. Without this pre-contract assessment, the organization would be accepting unknown risks that could lead to data breaches or compliance violations.

Exam trap

The trap here is that candidates often confuse post-contract operational activities (like incident response planning or vulnerability reporting) with pre-contract due diligence, leading them to select options that are important but not mandatory before signing a contract.

How to eliminate wrong answers

Option A is wrong because establishing an incident response plan is an operational step that should occur after the contract is signed and the service is being integrated, not before entering into the contract; it is not a prerequisite for vendor selection. Option B is wrong because performing a penetration test of the vendor's infrastructure is typically not feasible or allowed before a contract is in place, as it requires legal agreements and access permissions that do not exist pre-contract; such testing is usually conducted post-contract as part of ongoing validation. Option D is wrong because requesting monthly vulnerability reports is a post-contract monitoring activity, not a pre-contract due diligence step; the vendor may not even have such reports available before the business relationship is established.

906
MCQmedium

A multinational corporation is deploying a new application that will be accessed by employees, partners, and customers. The security architecture must support single sign-on (SSO) across different identity providers (IdPs) while maintaining strict access control based on user attributes such as role, location, and device posture. The company uses Active Directory for employees, a cloud IdP for partners, and self-registration for customers. The architect needs to design a centralized policy enforcement point that can evaluate access requests from multiple IdPs and enforce dynamic access policies before granting access to the application. Which of the following is the BEST architectural approach?

A.Deploy a SAML/WS-Federation federation server that authenticates users and then passes the identity to the application for authorization
B.Have each IdP enforce its own access policies and pass the authorization decision via SAML assertions
C.Configure a reverse proxy to authenticate users from any IdP and pass their identity to the application
D.Implement an externalized authorization management system (e.g., OAuth 2.0 with OpenID Connect) using a policy decision point (PDP) and a policy enforcement point (PEP) at the application gateway
AnswerD

This separates authentication from authorization, allows centralized attribute-based policy, and works across IdPs.

Why this answer

It uses an externalized authorization management system with a Policy Decision Point (PDP) and Policy Enforcement Point (PEP) at the application gateway, which decouples authentication from authorization. This architecture allows centralized, attribute-based access control (ABAC) across multiple IdPs (Active Directory, cloud IdP, self-registration) while supporting SSO via OAuth 2.0 and OpenID Connect. The PDP evaluates dynamic policies based on user attributes (role, location, device posture) and the PEP enforces the decision before granting access, meeting the requirement for strict, context-aware access control.

Exam trap

The CAS-004 exam often tests the misconception that a federation server or reverse proxy alone can handle dynamic authorization, when in fact they only handle authentication and identity propagation, not the centralized, attribute-based policy evaluation required for strict access control.

How to eliminate wrong answers

Option A is wrong because a SAML/WS-Federation federation server primarily handles authentication and identity federation, not dynamic authorization; it would pass identity to the application, which would then need to implement its own authorization logic, violating the centralized policy enforcement requirement. Option B is wrong because having each IdP enforce its own access policies fragments policy management and cannot provide a unified, dynamic access control across different IdPs; SAML assertions carry authentication and static attributes, not real-time authorization decisions based on device posture or location. Option C is wrong because a reverse proxy authenticates users and passes identity to the application, but it lacks a dedicated PDP for evaluating dynamic, attribute-based policies; it would still require the application to implement authorization logic, failing to centralize policy enforcement.

907
MCQhard

A company is merging with another company that has a different security posture. The CISO wants to integrate the two security programs quickly. Which of the following is the MOST critical first step?

A.Establish a joint governance committee
B.Align security policies and standards
C.Implement the same security tools across the enterprise
D.Conduct a joint risk assessment
AnswerA

A joint governance committee establishes shared decision-making authority, policy ownership and escalation paths across both organisations. This satisfies the need to integrate programmes quickly by aligning direction first, preventing duplicated or conflicting security controls during the merger.

Why this answer

Establishing a joint governance committee is the most critical first step because it creates the decision-making authority and accountability structure needed to integrate two distinct security programs. Without a unified governance body, efforts to align policies, select tools, or assess risk lack coordination, ownership, and executive sponsorship. This committee ensures that subsequent activities—such as policy harmonization and risk assessment—are prioritized, resourced, and executed consistently across both organizations.

In M&A integration, governance is the foundation that enables all other security integration tasks.

Exam trap

CAS-005 often tests the distinction between strategic and tactical steps in security program integration, and candidates frequently choose 'conduct a joint risk assessment' because it sounds proactive, but governance must come first to authorize and guide that assessment.

How to eliminate wrong answers

Option B is wrong because aligning security policies and standards is a downstream activity that requires governance to resolve conflicts and approve changes; attempting it first leads to inconsistent or stalled efforts. Option C is wrong because implementing the same security tools across the enterprise is a tactical decision that should follow a joint risk assessment and governance approval, not precede them. Option D is wrong because conducting a joint risk assessment, while important, still requires a governance structure to define scope, assign resources, and act on findings; without it, the assessment may be incomplete or ignored.

908
MCQeasy

Based on the exhibit, what type of attack is indicated?

A.Brute-force attack
B.Man-in-the-middle
C.Denial of service
D.Replay attack
AnswerA

Repeated authentication attempts against one account, each using a different credential, indicate a brute-force attack. The exhibit's pattern of many rapid failures from a single source, followed by a success, matches this signature rather than password spraying or credential stuffing.

Why this answer

The exhibit shows a high number of failed authentication attempts (e.g., 500+ in a short window) against a single user account, which is characteristic of a brute-force attack. This attack systematically tries multiple password combinations to gain unauthorized access, often targeting a specific username or service. The log entries indicate repeated login failures without any evidence of intercepted traffic or session manipulation.

Exam trap

CompTIA CASP+ often tests the distinction between brute-force and replay attacks by presenting logs with repeated failed logins, leading candidates to confuse the 'replay' of credentials with the 'replay' of captured packets, but replay attacks require a valid captured session token, not failed authentication attempts.

How to eliminate wrong answers

Option B is wrong because a man-in-the-middle attack involves intercepting and potentially altering communications between two parties, which would show evidence of ARP spoofing, SSL stripping, or unusual packet forwarding, not repeated failed logins. Option C is wrong because a denial of service attack aims to overwhelm a system with traffic or requests to disrupt service, which would manifest as high resource utilization or service unavailability, not a pattern of authentication failures. Option D is wrong because a replay attack captures and retransmits valid authentication tokens or packets, which would show successful logins from the same token rather than repeated failed attempts.

909
MCQeasy

A compliance officer is reviewing logs from a web application and finds multiple failed login attempts from a single IP address. Which type of control should be implemented to reduce the risk of brute-force attacks?

A.Account lockout policy
B.Network firewall
C.Password hashing
D.Encryption of traffic
AnswerA

An account lockout policy disables an account after a set number of failed attempts, throttling automated password guessing from a single source. This directly mitigates the brute-force risk described, unlike detective logging or generic awareness controls.

Why this answer

An account lockout policy is the correct control because it directly mitigates brute-force attacks by temporarily disabling the account after a predefined number of failed login attempts (e.g., 5 failures within 15 minutes). This prevents an attacker from continuously guessing passwords from a single IP address, as the account becomes unavailable for further attempts until the lockout period expires or an administrator intervenes.

Exam trap

CompTIA often tests the misconception that network-level controls like firewalls are sufficient to stop application-layer attacks, but the trap here is that brute-force prevention requires application-layer logic (account lockout or rate limiting), not just network filtering.

How to eliminate wrong answers

Option B is wrong because a network firewall filters traffic based on IP addresses, ports, or protocols, but it cannot distinguish between legitimate and malicious login attempts at the application layer; it would block the IP only if manually configured, which is reactive and not a standard brute-force prevention control. Option C is wrong because password hashing protects stored passwords from exposure if the database is compromised, but it does not prevent an attacker from attempting multiple logins against the live application. Option D is wrong because encryption of traffic (e.g., TLS) secures data in transit against eavesdropping and tampering, but it has no effect on the rate or success of login attempts at the application layer.

910
MCQeasy

A security analyst is reviewing a suspicious file. Which static analysis technique would the analyst use to examine the file without executing it?

A.Submit the file to VirusTotal
B.Execute the file in a debugger
C.Run the file in a sandbox
D.Use strings to extract readable text
AnswerD

Running strings extracts embedded ASCII and Unicode sequences from the binary without loading or executing it, satisfying the requirement for non-execution. Readable artefacts such as URLs, file paths, registry keys and command fragments reveal functionality and indicators, making this a core static analysis technique.

Why this answer

Using the 'strings' utility extracts readable ASCII/Unicode text from a binary without executing it, which is a classic static analysis technique for examining suspicious files. It reveals embedded URLs, file paths, error messages, and other indicators of compromise without any runtime risk.

Exam trap

CAS-005 often tests the static vs. dynamic analysis distinction, and the trap is that VirusTotal and sandboxes feel like 'analysis' but both involve execution or external submission, not static inspection.

How to eliminate wrong answers

Option A is wrong because submitting to VirusTotal is dynamic/cloud-based multi-engine scanning, not local static analysis, and it shares the sample externally. Option B is wrong because executing the file in a debugger is dynamic analysis — the code runs, which defeats the purpose of examining it without execution. Option C is wrong because running the file in a sandbox is dynamic analysis by definition, observing behavior during execution.

911
MCQhard

A security engineer is implementing an integrity-monitoring solution for a fleet of Linux servers that must detect unauthorized changes to critical binaries and configuration files. The solution must provide a cryptographic baseline, resist tampering by an attacker with root privileges, and support automated verification. Which approach BEST meets these requirements?

A.Deploy a file integrity monitoring agent that stores SHA-256 baselines in a remote, append-only repository and alerts on deviations
B.Schedule a nightly script that computes MD5 hashes of files under /etc and /usr/bin and emails the output to the security team
C.Enable the Linux auditd subsystem to log all file writes and review the audit log manually each week
D.Configure SELinux in enforcing mode with a strict policy that prevents writes to system directories
AnswerA

A file integrity monitoring agent using SHA-256 provides a strong cryptographic baseline, and storing it in a remote, append-only repository prevents a local root attacker from silently rewriting the reference data. Automated comparison against that trusted baseline detects unauthorized changes and generates alerts. This combination satisfies the cryptographic, tamper-resistance, and automation requirements.

Why this answer

The strongest approach combines a cryptographic baseline using SHA-256, remote append-only storage of that baseline to resist tampering by a local root attacker, and automated deviation alerting. MD5 is collision-prone, auditd logs lack baseline comparison and automation, and SELinux is preventive rather than detective. Only the agent with remote append-only baseline storage meets all three requirements.

Exam trap

The trap here is equating preventive controls such as SELinux or audit logging with integrity monitoring, when the requirement is cryptographic baseline comparison against tamper-resistant storage.

912
Multi-Selectmedium

An organization is reviewing its supply chain risk management. Which TWO of the following are effective strategies to manage fourth-party risk?

Select 2 answers
A.Use only vendors that are SOC 2 certified
B.Reduce reliance on vendors by bringing services in-house
C.Conduct penetration tests on all fourth parties directly
D.Include a right-to-audit clause that covers subcontractors
E.Require vendors to contractually mandate security controls for their subcontractors
AnswersD, E

Extending the right-to-audit clause to subcontractors gives the organisation contractual visibility and audit reach into fourth parties, satisfying the stem's requirement to manage risk beyond direct suppliers. Without this flow-down, subcontractor controls remain unverified, so fourth-party exposure cannot be assessed or enforced.

Why this answer

To manage fourth-party risk, organizations can require their vendors to flow down security requirements to subcontractors and include right-to-audit clauses that extend to subcontractors.

913
MCQeasy

An organization wants to ensure that its third-party vendors comply with the company's security policies. Which of the following is the MOST effective method?

A.Include security requirements in contracts and conduct periodic audits
B.Require vendors to obtain ISO 27001 certification
C.Send annual self-assessment questionnaires
D.Perform quarterly penetration tests on vendor networks
AnswerA

Legally binding and verifiable

Why this answer

Including security requirements in contracts and conducting periodic audits is the most effective method because it creates a legally binding obligation for vendors to adhere to the organization's security policies, and audits provide direct, verifiable evidence of compliance. Unlike self-assessments or certifications, audits allow the organization to actively inspect controls, configurations, and processes, ensuring ongoing adherence rather than relying on a point-in-time assertion. This approach aligns with the NIST SP 800-53 continuous monitoring framework and is a core principle of third-party risk management (TPRM) in the CAS-004 domain.

Exam trap

The CAS-004 exam often tests the misconception that a one-time certification or a technical test like a penetration test is sufficient to ensure ongoing compliance, when in reality, continuous contractual obligations and independent audits are required to enforce and verify policy adherence over time.

How to eliminate wrong answers

Option B is wrong because requiring ISO 27001 certification only proves that a vendor had a compliant Information Security Management System (ISMS) at the time of certification, but it does not guarantee ongoing compliance with the organization's specific security policies, nor does it provide a mechanism for the organization to verify current controls or address unique contractual requirements. Option C is wrong because annual self-assessment questionnaires rely on the vendor's self-reported data, which is subjective, lacks independent verification, and can easily miss critical security gaps or misconfigurations, making it unreliable for ensuring compliance. Option D is wrong because quarterly penetration tests on vendor networks only assess technical vulnerabilities at a point in time and do not evaluate the vendor's adherence to security policies, processes, or administrative controls, nor do they cover all aspects of compliance such as data handling, access management, or incident response procedures.

914
Matchingmedium

Match each port number to its associated protocol.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

RDP

SSH

HTTPS

LDAP

LDAPS

Why these pairings

These are standard IANA port assignments for common protocols. Correct matches: Port 80=HTTP, Port 443=HTTPS, Port 22=SSH, Port 21=FTP. Common confusions involve swapping port numbers for similar protocols.

915
MCQeasy

Which technology is used to discover and control cloud applications, enforce security policies, and provide visibility into cloud usage?

A.Cloud Workload Protection Platform (CWPP)
B.Cloud Access Security Broker (CASB)
C.Cloud Security Posture Management (CSPM)
D.Secure Access Service Edge (SASE)
AnswerB

A CASB sits between users and cloud services, discovering shadow IT, enforcing policy and logging usage for visibility. It provides the control and monitoring layer the stem describes, unlike SWG or DLP, which address different traffic types.

Why this answer

A Cloud Access Security Broker (CASB) is specifically designed to discover cloud applications in use (shadow IT), enforce security policies, and provide visibility and governance over cloud service usage. It sits between users and cloud providers, applying policy via inline proxies or API integrations. This matches the question's three requirements — discovery, policy enforcement, and visibility — which are CASB's core functions.

Exam trap

CAS-005 often tests the CASB vs. CSPM vs. CWPP distinction — candidates pick CSPM for 'cloud visibility' or CWPP for 'cloud control' when the question specifically mentions application discovery and usage governance, which is CASB's role.

How to eliminate wrong answers

Option A is wrong because CWPP protects workloads (VMs, containers, serverless) at runtime — vulnerability scanning, workload hardening, and runtime protection — not cloud application discovery or usage visibility. Option C is wrong because CSPM focuses on identifying misconfigurations and compliance drift in cloud infrastructure (e.g., open S3 buckets, overly permissive IAM), not on discovering or controlling SaaS applications. Option D is wrong because SASE is a broader architecture that bundles SWG, CASB, ZTNA, and FWaaS; it is not the specific component responsible for cloud app discovery and control.

916
MCQmedium

An organization wants to protect cryptographic keys used for TLS termination. Which hardware solution should be deployed to prevent key extraction?

A.KMS
B.TPM
C.UEFI
D.HSM
AnswerD

A hardware security module performs cryptographic operations internally, so private keys never leave the tamper-resistant boundary — satisfying the requirement to prevent key extraction during TLS termination. Unlike software keystores or TPMs, an HSM is purpose-built for high-volume server-side TLS, keeping keys non-exportable while Microsoft Entra ID governs access.

Why this answer

A Hardware Security Module (HSM) is a dedicated tamper-resistant hardware appliance designed to generate, store, and manage cryptographic keys, with physical and logical protections that prevent key extraction. For TLS termination, HSMs provide FIPS 140-2/3 validated key storage and can perform cryptographic operations without exposing private keys. This directly addresses the requirement to prevent key extraction.

Exam trap

CAS-005 often tests the KMS vs. HSM distinction — candidates pick KMS because it 'manages keys,' missing that the question demands hardware-level prevention of key extraction, which only an HSM provides.

How to eliminate wrong answers

Option A is wrong because KMS (Key Management Service) is a software service for managing keys centrally, but it does not provide the hardware-level tamper resistance and extraction prevention of an HSM; KMS often uses HSMs internally but is not itself the hardware solution. Option B is wrong because a TPM (Trusted Platform Module) is a chip on a motherboard used for platform integrity, secure boot, and disk encryption key storage — it is not designed for high-volume TLS key operations or as a standalone cryptographic appliance. Option C is wrong because UEFI is firmware that initializes hardware and supports secure boot; it has no role in cryptographic key protection for TLS.

917
MCQeasy

In a cloud shared responsibility model, which of the following is typically the customer's responsibility for IaaS?

A.Hypervisor security
B.Guest OS patch management
C.Hardware maintenance
D.Physical security of data centers
AnswerB

Under IaaS, the provider secures the hypervisor, physical hosts and network fabric, while the customer retains control of everything from the guest OS upward. Patching the guest operating system therefore remains the customer's duty, unlike managed PaaS where the provider handles runtime patching.

Why this answer

In the cloud shared responsibility model for IaaS, the customer is responsible for managing the guest operating system, including patch management, security updates, and configuration. The cloud provider is responsible for the hypervisor, hardware, and physical security of data centers. Therefore, guest OS patch management is the customer's responsibility.

Exam trap

The trap is confusing the responsibilities across service models; candidates may think the cloud provider patches the guest OS in IaaS, but the exam expects knowledge that the customer is responsible for guest OS patching in IaaS, while the provider handles the hypervisor and physical security.

How to eliminate wrong answers

Option A is wrong because hypervisor security is the responsibility of the cloud provider, not the customer, in an IaaS model; the provider manages the virtualization layer. Option C is wrong because hardware maintenance is handled by the cloud provider, who owns and operates the physical infrastructure. Option D is wrong because physical security of data centers is always the cloud provider's responsibility, as customers have no access to the physical facilities.

918
Multi-Selectmedium

A company is implementing a defense-in-depth strategy for its web application. Which THREE security controls should be included in the architecture? (Choose three.)

Select 3 answers
A.Web application firewall (WAF)
B.Load balancer with SSL termination
C.Runtime application self-protection (RASP)
D.Single sign-on (SSO)
E.Network segmentation
AnswersA, C, E

A web application firewall inspects inbound HTTP requests, blocking SQL injection, cross-site scripting and similar attacks before they reach the application. Sitting at the network edge, it forms one independent layer in defence in depth, complementing secure coding, RASP and monitoring controls.

Why this answer

A web application firewall (WAF) is correct because it inspects and filters HTTP/HTTPS traffic at Layer 7, blocking common attacks such as SQL injection and cross-site scripting before they reach the application, which is a core element of defense-in-depth for a web app. Runtime application self-protection (RASP) is correct because it instruments the application from within the runtime, detecting and blocking attacks like deserialization or injection in real time based on actual execution context, complementing perimeter controls. Network segmentation is correct because it limits lateral movement by isolating the web tier from databases and internal services using VLANs, subnets, or security groups, so a compromised web server cannot freely reach other assets.

A load balancer with SSL termination is not a security control in this context; it primarily provides availability and offloads TLS processing, and while it may support TLS, it does not itself enforce application-layer threat protection. Single sign-on (SSO) is an authentication convenience and access-management mechanism, not a defense-in-depth control for protecting the web application against attacks.

Exam trap

The trap here is confusing availability/identity controls (load balancer, SSO) with security controls — candidates pick them because they sound 'enterprise-grade' but they do not block or contain attacks.

919
MCQhard

A security engineer is designing a system that must enforce mandatory access control (MAC) based on security labels. The system must ensure that users cannot read data above their clearance level and cannot write data to lower classification levels. Which security model BEST fits these requirements?

A.Bell-LaPadula model
B.Clark-Wilson model
C.Brewer-Nash model
D.Biba model
AnswerA

The Bell-LaPadula model enforces confidentiality through the no-read-up and no-write-down properties. The no-read-up rule prevents subjects from reading objects at a higher classification, and the no-write-down rule prevents writing to lower classifications. This directly matches the requirement to restrict reading above clearance and writing to lower levels.

Why this answer

The requirements describe the classic confidentiality model: prevent reading above clearance (no-read-up) and prevent writing to lower levels (no-write-down). The Bell-LaPadula model explicitly defines these properties. Biba is for integrity, Clark-Wilson for integrity transactions, and Brewer-Nash for conflict of interest.

Thus, Bell-LaPadula is the correct choice.

Exam trap

The trap here is mixing up confidentiality and integrity models, especially Bell-LaPadula and Biba, which have opposite rules.

920
Multi-Selecthard

A global company must comply with data residency regulations that require customer data to stay within specific geographic boundaries. The company uses a multi-cloud architecture. Which THREE strategies should the architect implement to ensure compliance?

Select 3 answers
A.Using cloud provider's region-specific services and data centers
B.Encrypting all data at rest and in transit
C.Implementing strict identity and access management (IAM) policies
D.Configuring data classification tags to identify regulated data
E.Deploying data loss prevention (DLP) policies to block cross-border data transfers
AnswersA, D, E

Selecting region-specific services and data centres keeps storage and processing physically inside the mandated geography, satisfying the residency boundary directly. In a multi-cloud estate, each provider's regional endpoints must be chosen so customer data never replicates outside the permitted jurisdiction.

Why this answer

Option A is correct because using region-specific services and data centers ensures that data is physically stored and processed within the required geographic boundaries, directly satisfying data residency mandates. Option D is correct because data classification tags identify which data is subject to residency regulations, enabling architects to apply location-based controls and policies only to regulated data. Option E is correct because DLP policies can detect and block cross-border transfers of regulated data, preventing accidental or unauthorized movement outside approved regions.

Option B is not correct because encryption at rest and in transit protects confidentiality but does not restrict where data is stored or transferred, so it does not ensure residency. Option C is not correct because IAM policies control who can access data, not where data resides or whether it crosses borders.

Exam trap

CAS-005 often tests the confusion between data security controls (encryption, IAM) and data residency controls, so candidates must focus on geographic restrictions rather than general security measures.

921
MCQmedium

Refer to the exhibit. Which security issue does this cloud storage bucket policy present?

A.The bucket allows anonymous GET operations from any IP
B.The bucket policy is too restrictive
C.The bucket allows anonymous PUT operations from any source
D.The bucket is not encrypted
AnswerC

Anonymous PUT access lets unauthenticated users upload or overwrite objects, directly violating the least-privilege and data-integrity requirements the bucket policy must enforce. Because no identity or authentication check occurs, any source can inject malicious content, ransomware or exfiltration scripts, and existing objects can be replaced or corrupted without audit attribution.

Why this answer

The cloud storage bucket policy shown includes a `Principal: "*"` with `Action: "PutObject"` and no `Condition` block restricting the source IP or requiring authentication. This means any unauthenticated user on the internet can upload objects to the bucket, which is a classic data ingestion vulnerability. Option C correctly identifies this as allowing anonymous PUT operations from any source.

Exam trap

The trap here is that candidates confuse the action (`PutObject` vs `GetObject`) and assume any anonymous principal implies read access, when in fact the policy explicitly allows write operations without any authentication or IP restriction.

How to eliminate wrong answers

Option A is wrong because the policy grants `s3:PutObject` (write), not `s3:GetObject` (read), so anonymous GET operations are not explicitly allowed by this policy. Option B is wrong because the policy is not too restrictive; it is overly permissive by allowing anonymous writes without any conditions. Option D is wrong because the policy does not mention encryption settings at all; the issue is about access control, not encryption, and S3 buckets can be encrypted separately via bucket policies or default encryption settings.

922
Multi-Selecthard

A security team is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The team must identify and evaluate risks related to data breaches, compliance, and availability. Which TWO of the following factors are MOST important to consider when determining the likelihood of a data breach in this cloud environment? (Choose two.)

Select 2 answers
A.The cloud provider's history of security incidents and transparency in reporting.
B.The physical location of the organization's headquarters.
C.The sensitivity and volume of data stored in the CRM system.
D.The cloud provider's compliance certifications, such as SOC 2 or ISO 27001.
E.The number of employees in the organization's security team.
AnswersA, C

A cloud provider's history of security incidents and their willingness to disclose them is a direct indicator of their security posture. If the provider has a pattern of breaches or lacks transparency, the likelihood of a future breach increases. This factor is critical in assessing the probability of a data breach, as it reflects the provider's operational security maturity and incident response effectiveness.

Why this answer

When assessing the likelihood of a data breach in a cloud environment, two critical factors are the cloud provider's security incident history and transparency, and the sensitivity and volume of data stored. A provider with a poor track record or lack of transparency increases the probability of a breach. High-value data attracts attackers, raising the likelihood.

Other factors like internal team size, headquarters location, or certifications are less directly related to breach probability.

Exam trap

The trap here is focusing on compliance certifications or internal team size as primary indicators of breach likelihood, when the provider's incident history and data sensitivity are more directly relevant.

923
MCQmedium

A multinational retailer is expanding into the European Union and must transfer employee payroll data from its EU subsidiary to its US-based HR platform. Legal counsel recommends relying on the EU-US Data Privacy Framework rather than implementing Standard Contractual Clauses. Which action must the retailer take FIRST to rely on this transfer mechanism?

A.Obtain explicit consent from every EU employee before the payroll records are transmitted to the US platform.
B.Verify that the US HR platform is listed as an active participant on the Data Privacy Framework List maintained by the US Department of Commerce.
C.Conduct a Transfer Impact Assessment documenting that US surveillance laws do not undermine the protection of the payroll data.
D.Execute a Binding Corporate Rules application with the lead supervisory authority in the EU member state where the subsidiary is established.
AnswerB

The EU-US Data Privacy Framework requires the receiving organization to self-certify to the US Department of Commerce and appear on the official Data Privacy Framework List. Only then can EU personal data flow to that importer without SCCs or a derogation. Confirming active certification status is the mandatory prerequisite step before the transfer can lawfully occur.

Why this answer

The EU-US Data Privacy Framework permits transfers to US importers that have self-certified and appear on the Department of Commerce's Data Privacy Framework List. Verifying that the HR platform holds active certification is the foundational requirement; without it, the framework cannot be invoked and another transfer tool would be needed.

Exam trap

The trap here is assuming that any US company is automatically covered by the EU-US Data Privacy Framework instead of confirming the importer's active self-certification on the official list.

924
Multi-Selectmedium

A security operations team is implementing deception technology to detect lateral movement. Which TWO of the following are examples of deception technologies? (Select TWO.)

Select 2 answers
A.Honeytoken
B.Intrusion prevention system
C.Endpoint detection and response (EDR)
D.Security information and event management (SIEM)
E.Honeypot
AnswersA, E

Honeytokens are fabricated credentials, files or records seeded across systems; any access or use triggers an alert, since legitimate users have no reason to touch them. This satisfies the stem's lateral-movement detection requirement by catching adversaries probing with stolen credentials, without generating the false positives typical of signature-based monitoring.

Why this answer

Option A (Honeytoken) is correct because a honeytoken is a fake credential, file, or data artifact (such as a dummy AWS key or a planted document) that has no legitimate use; any access or use of it signals unauthorized activity and potential lateral movement, making it a classic deception technology. Option E (Honeypot) is correct because a honeypot is a decoy system or service deliberately exposed to attract attackers, and interactions with it reveal reconnaissance or lateral movement attempts while generating high-fidelity alerts with minimal false positives. Option B (Intrusion prevention system) is not a deception technology; an IPS is a preventive control that inspects traffic inline and blocks malicious activity based on signatures or anomalies.

Option C (Endpoint detection and response, EDR) is not deception either; EDR continuously monitors endpoint telemetry and responds to threats but does not rely on decoys. Option D (Security information and event management, SIEM) is a log aggregation, correlation, and alerting platform, not a deception mechanism, so it does not belong.

Exam trap

CAS-005 often tests the confusion between detection tools (EDR, SIEM, IPS) and deception tools (honeypots, honeytokens) — candidates pick IPS or EDR because they 'detect' attacks, missing that deception requires fake assets.

925
Multi-Selecteasy

A compliance officer is preparing for an audit and needs to collect evidence. Which TWO of the following are considered acceptable forms of audit evidence? (Select TWO.)

Select 2 answers
A.Screenshots of unofficial reports
B.Verbal statements from employees
C.Written security policies
D.Assumptions about system configurations
E.System access logs
AnswersC, E

Written security policies are documented, approved management directives that auditors accept as evidence of intended control design and governance. This satisfies the stem's acceptable-evidence criterion because they demonstrate the organisation's stated requirements, though they show intent rather than proving the controls actually operate.

Why this answer

Written security policies (C) are acceptable audit evidence because they are documented, approved artifacts that demonstrate the organization's formal security requirements and controls, providing verifiable proof of governance intent. System access logs (E) are acceptable because they are system-generated, tamper-evident records that objectively show actual activity such as authentication events, timestamps, and user actions, which auditors can trace and corroborate. In contrast, screenshots of unofficial reports (A) lack authenticity and provenance since they can be altered and are not from controlled sources, verbal statements from employees (B) are testimonial and unverifiable without documentation, and assumptions about system configurations (D) are unsubstantiated beliefs rather than evidence, so none of these qualify as acceptable audit evidence.

Exam trap

The trap is that candidates select 'verbal statements from employees' because interviews are part of audits — but interviews are inquiry, not evidence, and auditors must corroborate inquiry with documentary or system-generated proof.

926
MCQeasy

A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR can detect malicious activities such as process injection and credential dumping. Which of the following capabilities is MOST important for the EDR to have?

A.Full disk encryption
B.Signature-based detection
C.Behavioral monitoring
D.Network segmentation
AnswerC

Behavioral monitoring observes system activities and process behaviors to detect malicious actions like process injection and credential dumping, which may not have known signatures. This capability is essential for identifying advanced threats in real-time, making it the most important for the EDR.

Why this answer

To detect techniques like process injection and credential dumping, the EDR must monitor system behavior rather than rely solely on signatures. Behavioral monitoring allows the EDR to identify suspicious actions such as unexpected process memory modifications or access to LSASS. Other options are security controls but not detection capabilities for these specific threats.

Exam trap

The trap here is equating EDR with signature-based antivirus, when EDR's strength lies in behavioral detection.

927
Multi-Selecthard

A security administrator is reviewing a Python script used to automate compliance checks across cloud resources. The script uses environment variables for API tokens. Which of the following are secure coding practices that should be implemented in this script? (Select TWO.)

Select 2 answers
A.Use try-except blocks to handle exceptions gracefully
B.Use os.system() to run shell commands for resource management
C.Hardcode API tokens as fallback if environment variables are missing
D.Validate that required environment variables exist before proceeding
E.Log the API tokens for troubleshooting purposes
AnswersA, D

Why this answer

Using try-except blocks in Python allows the script to catch and handle exceptions (e.g., missing environment variables, API call failures) gracefully without crashing. This is a fundamental secure coding practice that prevents unhandled errors from exposing sensitive information or causing unpredictable behavior in automated compliance checks.

Exam trap

The CAS-004 exam often tests the misconception that hardcoding fallback values or logging sensitive data is acceptable for troubleshooting, but the trap here is that both practices directly violate secure coding principles by exposing secrets, while os.system() is a known anti-pattern for command execution in Python.

Why the other options are wrong

B

os.system is vulnerable to injection; prefer subprocess with parameterized commands.

C

Hardcoding tokens is insecure and defeats the purpose of using environment variables.

E

Logging credentials exposes them in logs, which is a security risk.

928
MCQmedium

A security engineer is designing a network segmentation strategy for a new data center. The engineer wants to ensure that if a web server in the DMZ is compromised, the attacker cannot directly access the internal database servers. Which of the following controls would BEST achieve this objective?

A.Implement a firewall rule that allows all traffic from the DMZ to the internal network.
B.Place the database servers in the same VLAN as the web servers to simplify management.
C.Deploy an intrusion detection system (IDS) between the DMZ and internal network.
D.Configure a firewall to allow only specific, required traffic from the web servers to the database servers.
AnswerD

Configuring a firewall to allow only specific, required traffic (e.g., database port) from the web servers to the database servers enforces least privilege and segmentation. This prevents an attacker on a compromised web server from initiating arbitrary connections to the database servers. It is the most effective control to limit lateral movement.

Why this answer

To prevent direct access from a compromised web server to internal database servers, the engineer should implement a firewall rule that allows only specific, required traffic. This enforces least privilege and segmentation, blocking unauthorized connections. Allowing all traffic, sharing a VLAN, or relying solely on an IDS would not prevent lateral movement.

Exam trap

The trap here is confusing detection (IDS) with prevention (firewall rules), or assuming that VLAN separation alone provides sufficient security without firewall filtering.

929
Multi-Selecthard

A security architect is designing a microsegmentation strategy for a hybrid cloud environment. The organization wants to enforce least-privilege network access between workloads, prevent lateral movement, and maintain visibility into east-west traffic. Which TWO of the following controls are MOST appropriate to achieve these goals? (Choose two.)

Select 2 answers
A.Network address translation (NAT) at the perimeter
B.Spanning Tree Protocol (STP) tuning on all switches
C.Software-defined networking (SDN) overlay with distributed policy enforcement
D.Host-based firewalls with workload identity tags
E.Virtual private network (VPN) concentrators between all subnets
AnswersC, D

An SDN overlay with distributed policy enforcement allows security policies to be applied consistently across hybrid cloud workloads regardless of underlying network topology. It enables microsegmentation by defining security groups and rules based on workload attributes, and it provides flow-level visibility into east-west traffic. This approach scales across on-premises and cloud environments.

Why this answer

Host-based firewalls with workload identity tags and an SDN overlay with distributed policy enforcement both enable granular, identity-aware microsegmentation across hybrid cloud environments. They enforce least-privilege access, limit lateral movement, and provide east-west visibility. The other options either provide broad connectivity, address non-security concerns, or operate only at the perimeter.

Exam trap

The trap here is confusing network connectivity mechanisms such as VPNs or NAT with segmentation controls that enforce least privilege between individual workloads.

930
MCQeasy

A security architect is evaluating a software-defined wide area network (SD-WAN) solution to connect branch offices to cloud services. The architect wants to ensure that traffic from branches to cloud applications is inspected for threats without backhauling all traffic to the data center. Which capability should the architect prioritize?

A.Dynamic multipoint VPN (DMVPN) with hub-and-spoke topology
B.Quality of service (QoS) policies that prioritize business-critical applications
C.Application-aware routing that selects the best path based on performance metrics
D.Local internet breakout with integrated next-generation firewall (NGFW) and secure web gateway (SWG) at the branch
AnswerD

Local internet breakout allows branch traffic to go directly to the cloud, and integrating NGFW and SWG at the branch ensures that this traffic is still inspected for threats. This avoids backhauling while maintaining security, directly addressing the architect's requirement.

Why this answer

Local internet breakout with integrated NGFW and SWG at the branch enables direct cloud access while still inspecting traffic for threats. This design eliminates the need to backhaul traffic to a central data center for security inspection, balancing performance and security for branch offices.

Exam trap

The trap here is assuming that SD-WAN's performance features, such as application-aware routing, also provide security inspection, when they are separate functions.

931
Multi-Selectmedium

A security analyst is investigating a potential malware infection on a Windows workstation. The analyst wants to perform live response to collect volatile data. Which of the following commands or tools should the analyst use to capture volatile data? (Choose two.)

Select 2 answers
A.Use `netstat -anob` to capture active network connections and associated process IDs.
B.Use `fsutil usn readjournal C:` to read the USN journal for file system changes.
C.Use `wmic process get name,processid,commandline` to list running processes and their command lines.
D.Use `reg export HKLM\Software\Microsoft\Windows\CurrentVersion\Run run.reg` to export autostart entries.
E.Use `dd if=/dev/mem of=memory.dmp` to capture physical memory.
AnswersA, C

`netstat -anob` displays active connections, listening ports, and the executable name and PID for each connection. This is volatile data that can be lost on reboot and is crucial for identifying command-and-control connections. It is a standard live response command for capturing network state on Windows systems.

Why this answer

Volatile data includes information that is lost when the system is powered off, such as active network connections and running processes. The `netstat -anob` command captures network connections with associated process IDs, and `wmic process get name,processid,commandline` captures running processes with command lines. Both are essential for live response on Windows and help identify malicious activity quickly.

The other options involve non-volatile data or are not applicable to Windows.

Exam trap

The trap here is confusing non-volatile registry or file system data with volatile data, or assuming Linux commands work on Windows.

932
MCQeasy

A security analyst is reviewing the organization's incident response plan and notices that it lacks a formal process for communicating with external stakeholders during a breach. Which of the following should the analyst recommend to address this gap?

A.Increase the cyber insurance coverage to include crisis management services.
B.Implement a security information and event management (SIEM) system to automate alerting of external parties.
C.Develop a communication plan that includes predefined templates, contact lists, and approval workflows for external notifications.
D.Conduct a tabletop exercise to test the existing incident response plan without modifying it.
AnswerC

A formal communication plan ensures timely, accurate, and approved messaging to external stakeholders such as customers, regulators, and media. Predefined templates and contact lists speed up response, while approval workflows prevent unauthorized disclosures. This directly fills the gap in the incident response plan and aligns with best practices for breach notification and reputational management.

Why this answer

A formal communication plan with predefined templates, contact lists, and approval workflows ensures that external stakeholders receive timely, accurate, and authorized information during a breach. This directly addresses the identified gap. SIEM, tabletop exercises, and insurance do not provide the structured communication process required.

Exam trap

The trap here is confusing tools that support incident response, such as SIEM or insurance, with the actual process needed for external communications.

933
MCQeasy

Which of the following is a primary purpose of using code signing for application deployment?

A.To encrypt the application code
B.To verify the integrity and authenticity of the code
C.To prevent reverse engineering
D.To speed up application deployment
AnswerB

Why this answer

Code signing uses a digital signature (typically RSA or ECDSA) to bind the publisher's identity to the code. The primary purpose is to verify both the integrity (the code has not been tampered with) and the authenticity (the code comes from a trusted source) before deployment. This is achieved by hashing the code and signing the hash with the publisher's private key; the recipient verifies the signature using the publisher's public certificate.

Exam trap

The CAS-004 exam often tests the misconception that code signing provides encryption or obfuscation, when in fact it only provides integrity and authenticity verification without hiding the code content.

Why the other options are wrong

A

Encryption is for confidentiality; code signing does not encrypt the code.

C

Code signing does not prevent reverse engineering; obfuscation or other techniques are used for that.

D

Code signing adds overhead, not speed.

934
MCQeasy

A security analyst is reviewing the organization's incident response plan. The plan includes a section on communication with external parties. Which of the following best describes the primary purpose of a communication plan during a security incident?

A.To outline the technical steps for containing the incident.
B.To document the chain of custody for forensic evidence.
C.To provide technical details of the incident to the security operations team.
D.To ensure timely and accurate information sharing with stakeholders, regulators, and the public.
AnswerD

A communication plan defines who communicates what, when, and to whom during an incident. Its primary purpose is to manage information flow to internal and external stakeholders, maintain trust, and meet legal obligations. This reduces confusion and helps control the narrative, which is critical for incident response.

Why this answer

The communication plan is a component of incident response that focuses on information sharing with stakeholders, including executives, legal, regulators, and customers. Its primary goal is to ensure timely, accurate, and compliant messaging. Technical containment and evidence handling are separate processes, making the stakeholder communication purpose the correct choice.

Exam trap

The trap here is equating the communication plan with technical response actions, when it actually governs stakeholder messaging.

935
MCQhard

A security architect must protect a hardware security module's firmware against an attacker who has physical access and can measure power consumption and electromagnetic emissions during signature operations. The architect wants a countermeasure that makes the secret key statistically uncorrelated with the observable side-channel leakage. Which approach BEST meets this goal?

A.Implement constant-time modular exponentiation with blinding of the base and exponent
B.Rate-limit signature operations to ten per second and log each attempt
C.Enable secure boot with a signed firmware image verified by an on-die ROM
D.Store the private key in encrypted form using an AES key derived from a PIN
AnswerA

Constant-time execution removes data-dependent branches and memory-access timing, while base blinding randomizes the operand and exponent blinding randomizes the private exponent value used in each operation. Together they decorrelate the power and EM traces from the actual secret key, directly defeating statistical side-channel analysis even when the attacker can physically measure the device.

Why this answer

Base and exponent blinding combined with constant-time arithmetic randomize the intermediate values on which the leakage depends, so power and EM traces no longer correlate with the secret exponent. Secure boot, at-rest encryption, and rate limiting all leave the runtime arithmetic unchanged and therefore do not stop differential power analysis by an attacker with physical measurement access.

Exam trap

The trap here is assuming that protecting the key's storage or the integrity of the firmware also hides the key's runtime leakage from physical measurement.

936
MCQmedium

A company is conducting a third-party risk assessment for a SaaS provider. The provider has provided a SOC 2 Type II report, penetration test results, and a completed security questionnaire. Which of these provides the most independent and comprehensive view of the provider's control environment over time?

A.Penetration test report
B.Security questionnaire
C.Vendor's marketing materials
D.SOC 2 Type II report
AnswerD

A SOC 2 Type II report tests control design and operating effectiveness across a defined audit period, giving an independent, time-spanning view. Penetration tests and questionnaires are point-in-time or self-reported, so only the Type II report meets the stem's requirement for comprehensive evidence over time.

Why this answer

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls over a period of time (typically 3-12 months). This gives a comprehensive, time-tested view of the provider's control environment, unlike point-in-time assessments.

Exam trap

The trap is assuming a penetration test or questionnaire provides equivalent assurance; candidates often overvalue point-in-time or self-attested evidence over independent, time-bound audits.

How to eliminate wrong answers

Option A is wrong because a penetration test report is a point-in-time snapshot of vulnerabilities and does not evaluate the ongoing effectiveness of controls. Option B is wrong because a security questionnaire is self-reported by the vendor and lacks independent verification. Option C is wrong because marketing materials are unverified, biased, and not an independent assessment.

937
MCQhard

A multinational retailer must transfer employee personal data from its European Union subsidiary to a processing center in a country without an adequacy decision. Legal counsel wants a transfer mechanism that imposes enforceable data protection obligations on the importer and includes a documented transfer impact assessment. Which mechanism best matches these requirements?

A.An explicit consent obtained from each employee once at the time of hire for all future transfers
B.A certification under an approved code of conduct registered with the subsidiary's data protection authority
C.Standard Contractual Clauses supplemented by a transfer impact assessment and additional safeguards
D.Binding Corporate Rules approved only by the subsidiary's local supervisory authority without any further analysis
AnswerC

Standard Contractual Clauses are pre-approved contractual terms that create enforceable obligations on the data importer, and after the Schrems II ruling they must be paired with a transfer impact assessment of the destination country's laws plus supplementary technical or organizational measures when needed. This combination directly satisfies the requirement for enforceable importer obligations and a documented assessment.

Why this answer

Cross-border transfers outside an adequacy decision require a valid Chapter V mechanism. Standard Contractual Clauses impose enforceable obligations on the importer, and following Schrems II they must be accompanied by a transfer impact assessment and supplementary measures where destination laws undermine protection. Consent, codes of conduct, and improperly approved Binding Corporate Rules do not meet the combined contractual and assessment requirements described.

Exam trap

The trap here is treating any listed transfer mechanism as automatically sufficient, when the scenario specifically requires enforceable importer obligations plus a documented transfer impact assessment.

938
Multi-Selecteasy

A security architect is designing a secure remote access solution for contractors who need temporary access to a few internal applications. Which THREE of the following are best practices for controlling contractor access? (Select THREE.)

Select 3 answers
A.Allow contractors to use a shared account for simplicity
B.Implement just-in-time (JIT) temporary privilege elevation
C.Create time-limited accounts that expire automatically
D.Provide full network-level VPN access
E.Use a VPN with application-level access control
AnswersB, C, E

JIT provides access only when needed, reducing the risk of unused standing privileges.

Why this answer

Just-in-time (JIT) temporary privilege elevation ensures contractors only receive the minimum necessary permissions for a limited duration, reducing the attack surface and preventing standing privileges. This aligns with the principle of least privilege and zero-trust architectures, often implemented via tools like Azure AD PIM or AWS IAM Access Analyzer with time-bound policies.

Exam trap

The trap here is that candidates often confuse 'full network-level VPN access' (Option D) as secure because it uses encryption, but the exam focuses on the principle of least privilege and the need to restrict access to only the required applications, not the entire network.

939
MCQhard

A multinational organization is adopting a zero trust architecture and needs to align its network segmentation with regulatory requirements. The compliance team has identified that certain data must be isolated to meet PCI DSS scope reduction. Which of the following design approaches BEST supports both zero trust and PCI DSS compliance?

A.Deploying VLANs to separate cardholder data from other traffic
B.Implementing microsegmentation with software-defined networking
C.Using network access control (NAC) to enforce endpoint compliance
D.Placing all systems that process cardholder data in a DMZ
AnswerB

Microsegmentation with software-defined networking enforces per-workload, identity-based policies at Layer 3–7, isolating cardholder data environment segments to shrink PCI DSS scope. This granular east-west control satisfies zero trust's least-privilege assumption and continuous verification requirements, unlike coarse VLAN or perimeter-based segmentation.

Why this answer

Microsegmentation with software-defined networking (SDN) enables granular, identity-aware isolation of workloads at the virtual network layer, which directly supports zero trust's 'never trust, always verify' principle by restricting lateral movement. For PCI DSS scope reduction, microsegmentation allows the organization to create a logical, auditable boundary around cardholder data environment (CDE) assets without relying on physical network topology, thereby reducing the scope of PCI DSS compliance assessments. This approach is superior because it provides dynamic, policy-driven segmentation that can adapt to regulatory changes while maintaining strict least-privilege access.

Exam trap

CompTIA often tests the misconception that VLANs are sufficient for security segmentation, but the trap here is that VLANs lack the identity-aware, dynamic policy enforcement and east-west traffic control required by zero trust, and they do not provide the auditable, scope-reducing isolation that PCI DSS demands.

How to eliminate wrong answers

Option A is wrong because VLANs operate at Layer 2 and provide only coarse, static segmentation that can be bypassed via VLAN hopping attacks (e.g., double tagging per IEEE 802.1Q) and do not enforce identity-based access controls required by zero trust. Option C is wrong because NAC (e.g., 802.1X) focuses on pre-admission endpoint compliance and posture assessment, not on isolating workloads or reducing PCI DSS scope; it does not provide the granular east-west traffic control needed for zero trust segmentation. Option D is wrong because placing all CDE systems in a DMZ violates the principle of least privilege by exposing them to untrusted networks, increases attack surface, and does not achieve scope reduction—PCI DSS requires isolation of CDE from untrusted networks, not exposure.

940
MCQhard

An organization is implementing a secure software development lifecycle. Which of the following practices BEST ensures that security requirements are addressed early in the development process?

A.Security training for developers
B.Code analysis after development
C.Threat modeling during design phase
D.Penetration testing before release
AnswerC

Threat modelling during design identifies threats, attack surfaces and required mitigations before code is written, so security requirements are embedded in the architecture early. Fixing issues at design stage costs far less than remediating them after implementation, satisfying the early-addressal objective.

Why this answer

Threat modeling during the design phase is the best practice for addressing security requirements early because it proactively identifies potential threats, attack vectors, and vulnerabilities in the system architecture before any code is written. By analyzing data flow, trust boundaries, and threat agents (e.g., using STRIDE or PASTA methodologies), security controls can be integrated into the design, reducing costly rework later. This aligns with the 'shift left' principle in secure SDLC, ensuring security is not an afterthought.

Exam trap

CompTIA CASP+ often tests the distinction between proactive security activities (like threat modeling) and reactive or verification activities (like code analysis or penetration testing), trapping candidates who confuse 'early' with 'any security practice' rather than recognizing that only design-phase activities can truly address requirements before development begins.

How to eliminate wrong answers

Option A is wrong because security training for developers, while important for awareness, does not directly ensure that security requirements are addressed early in the development process; it is a general education activity that may influence behavior but lacks the structured, design-phase analysis needed. Option B is wrong because code analysis after development (e.g., static or dynamic analysis) occurs too late to influence design decisions; it can find implementation flaws but cannot fix architectural security gaps that stem from early design choices. Option D is wrong because penetration testing before release is a validation activity that occurs after the system is built; it identifies exploitable vulnerabilities but does not ensure security requirements are incorporated during the design phase, leading to potentially costly fixes.

941
MCQmedium

Refer to the exhibit. A security analyst notices that users from the internet can reach the web server at 10.0.1.100 on port 443, but they cannot reach it on port 8443. What is the most likely cause?

A.The ACL only permits traffic from specific source IPs
B.The firewall rule order is incorrect
C.The web server is not listening on port 8443
D.The firewall is blocking all traffic on port 8443
AnswerC

Port 443 succeeds while 8443 fails, and both traverse the same network path to 10.0.1.100, so filtering cannot explain the asymmetry. The differing element is the listening socket: if no process binds 8443, the host returns TCP RST, making the service unreachable regardless of firewall rules.

Why this answer

If users can reach the web server on port 443 but not on 8443, the firewall is clearly permitting traffic to that host, so the most likely cause is that the web server process is not listening on port 8443. A service that is not bound to a port cannot accept connections regardless of firewall rules, which explains why one port works and the other does not.

Exam trap

CAS-005 often tests the assumption that any unreachable port is a firewall problem, when the actual cause is frequently a service not listening on that port.

How to eliminate wrong answers

Option A is wrong because an ACL restricting source IPs would block both ports equally, not selectively allow 443 while denying 8443. Option B is wrong because incorrect rule order would typically affect all traffic to the host or produce inconsistent results, not a clean split between two ports on the same server. Option D is wrong because a blanket block on port 8443 is possible but less likely than the server simply not listening; the exhibit shows 443 reachable, so the firewall is not blocking all traffic to the host.

942
MCQmedium

A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?

A.TLS termination
B.SQL injection prevention
C.Cross-site scripting (XSS) filtering
D.Rate limiting per API consumer
AnswerD

An API gateway understands individual consumers via keys, OAuth scopes or tokens, so it can apply quotas and throttling per client. A WAF inspects HTTP traffic for attack signatures but lacks this per-consumer identity context, making per-consumer rate limiting the unique capability.

Why this answer

Rate limiting per API consumer is a capability unique to API gateways because the gateway understands API keys, OAuth tokens, and consumer identities, allowing it to enforce quotas and throttling on a per-client basis. A traditional WAF operates at the network/HTTP layer and inspects traffic patterns for attacks but does not natively identify API consumers or apply per-consumer quotas. This makes per-consumer rate limiting the distinguishing capability in this comparison.

Exam trap

CAS-005 often tests the overlap between WAF and API gateway capabilities, tricking candidates into picking a generic web security control (TLS, SQLi, XSS) that both devices can perform instead of the consumer-aware capability unique to the gateway.

How to eliminate wrong answers

Option A is wrong because TLS termination is a generic capability provided by load balancers, reverse proxies, and WAFs alike — it is not unique to API gateways. Option B is wrong because SQL injection prevention is a core WAF signature/rule capability (e.g., OWASP CRS rules) and is not the differentiator. Option C is wrong because XSS filtering is likewise a standard WAF function via signature and anomaly detection rules, not unique to API gateways.

943
MCQmedium

An application uses a relational database and constructs SQL queries by concatenating user input. Which secure coding practice should be implemented to mitigate SQL injection?

A.Use stored procedures exclusively
B.Escape all user input with a database-specific escaping function
C.Implement parameterized queries / prepared statements
D.Use an ORM (Object-Relational Mapping) framework
AnswerC

Why this answer

Parameterized queries (prepared statements) separate SQL logic from user data by using placeholders (e.g., `?` in MySQLi or `:param` in PDO). The database driver automatically escapes the input values, ensuring they are treated as data, not executable code. This directly prevents SQL injection because the query structure is fixed before user input is bound.

Exam trap

The CAS-004 exam often tests the misconception that stored procedures or ORMs are inherently safe, but the trap is that both can still be vulnerable if they allow dynamic SQL construction or raw query execution without parameterization.

Why the other options are wrong

A

Stored procedures can still be vulnerable if dynamic SQL is used within them.

B

Escaping is error-prone and not as reliable as parameterized queries.

D

ORMs can reduce risk but may still generate dynamic SQL if not used carefully.

944
Multi-Selecthard

A software company is preparing to release a new payment feature that processes cardholder data. The security architect must ensure the feature design meets PCI DSS requirements for protecting stored data and for securing transmission over open, public networks. Which two design choices satisfy these requirements? (Choose two.)

Select 2 answers
A.Disable audit logging for the payment feature to reduce storage of sensitive data
B.Enable TLS 1.2 or higher with strong cipher suites for all payment traffic traversing the internet
C.Replace the primary account number with a token in the application database and map it in a separate hardened token vault
D.Store the full primary account number encrypted with a documented key management process
E.Rely on the payment processor's PCI DSS compliance certificate and transmit card data without additional encryption
AnswersB, C

PCI DSS requires strong cryptography and security protocols to safeguard cardholder data during transmission over open, public networks. TLS 1.2 or higher with strong cipher suites and proper certificate validation satisfies that requirement. This directly addresses the scenario's transmission concern and is a standard, auditable control for protecting data in transit between the customer browser, application, and payment processor.

Why this answer

The two correct design choices are tokenization with a hardened token vault and strong TLS for data in transit. Tokenization reduces the value of stored data and can shrink the cardholder data environment, while TLS 1.2 or higher with strong ciphers protects data moving across open, public networks. Together they address both the storage and transmission requirements in the scenario without relying on a third party's compliance to cover the organization's own obligations.

Exam trap

The trap here is assuming that a payment processor's PCI DSS certificate removes the need to encrypt cardholder data that the organization itself transmits.

945
MCQeasy

A company is modernizing its security operations center and wants to correlate logs from firewalls, endpoints, and cloud services in a single platform that supports long-term retention and custom detection rules. Which technology best fits this requirement?

A.A network performance monitoring (NPM) appliance.
B.A vulnerability management scanner.
C.A security information and event management (SIEM) platform.
D.A configuration management database (CMDB).
AnswerC

A SIEM collects and normalizes logs from disparate sources such as firewalls, endpoints, and cloud services, correlates events across them, retains data for long-term analysis, and supports custom detection rules and alerts. This directly matches the requirement for centralized correlation, retention, and customizable detections in a security operations center.

Why this answer

The described need is centralized ingestion, normalization, correlation, retention, and custom detection across many log sources, which is the core purpose of a SIEM. Vulnerability scanners, network performance monitors, and configuration databases each serve different operational functions and none provides the combined correlation and retention capability required.

Exam trap

The trap here is choosing a tool that produces security-relevant data, such as a vulnerability scanner, when the requirement is a platform that ingests and correlates logs from many sources.

946
MCQmedium

During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?

A.Export the Windows event logs related to network activity
B.Execute a network scan from the compromised host to identify active connections
C.Capture a full disk image using FTK Imager
D.Perform a memory capture using a tool like DumpIt or winpmem
AnswerD

RAM holds running processes, open sockets and encryption keys, and is lost on shutdown or reboot. Capturing memory first with DumpIt or winpmem preserves the process-to-connection mapping the team needs, satisfying the requirement to collect the most volatile evidence before disk artefacts.

Why this answer

Memory capture is the correct first step because running processes, active network connections, and encryption keys exist only in volatile memory (RAM) and are lost on shutdown or reboot. Tools like DumpIt or winpmem preserve this state, including the process-to-connection mapping needed to identify which process initiated the encrypted channels. The order of volatility in digital forensics dictates that RAM be collected before disk or logs, since it is the most transient evidence.

Exam trap

CAS-005 often tests the order of volatility, and candidates frequently choose disk imaging or log export because they seem more permanent, forgetting that RAM is the most volatile and must be captured first.

How to eliminate wrong answers

Option A is wrong because Windows event logs are stored on disk and are less volatile than RAM; they may not contain the process-to-connection mapping and can be overwritten or tampered with, so they should be collected after memory. Option B is wrong because executing a network scan alters the system state, generates new network traffic, and does not preserve existing volatile evidence; it is an investigative action, not evidence collection. Option C is wrong because a full disk image captures non-volatile data and misses active processes, open network sockets, and encryption keys in RAM; disk imaging is performed after memory capture in the order of volatility.

947
MCQmedium

During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?

A.DAST
B.SAST
C.IAST
D.RASP
AnswerB

SAST analyses source code statically, before compilation or execution, tracing tainted data flows to flag injection flaws, unsafe functions and hardcoded secrets. That directly matches the requirement to identify vulnerabilities in source code early, whereas DAST and IAST need a running or instrumented build.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binaries without executing the program, making it the correct choice for finding vulnerabilities before compilation. It integrates into the IDE or CI pipeline and can flag issues like hardcoded secrets, injection flaws, and insecure API usage at the code level. Because it works on the code itself, it is the only option that fits the 'before it is compiled' requirement.

Exam trap

CAS-005 often tests the confusion between SAST (static, pre-compilation, white-box) and DAST/IAST/RASP (dynamic, runtime, black-box or instrumented), tricking candidates who focus on 'testing' rather than on when the code is analyzed.

How to eliminate wrong answers

Option A is wrong because DAST (Dynamic Application Security Testing) tests a running application from the outside by sending malicious requests, so it requires a deployed, executing application and cannot inspect source code. Option C is wrong because IAST (Interactive Application Security Testing) instruments a running application during execution, typically combining agent-based runtime analysis with test traffic, so it also requires execution. Option D is wrong because RASP (Runtime Application Self-Protection) runs inside a live application to detect and block attacks in real time, which is a runtime protection mechanism, not a pre-compilation code review technique.

948
MCQmedium

A security architect is designing a system that must process sensitive personal data. The organization wants to ensure that even if the database is compromised, the data remains unreadable to the attacker. The architect also needs to support searching on a specific field without decrypting the entire dataset. Which cryptographic approach best meets these requirements?

A.Transparent data encryption (TDE) on the database
B.Hashing the sensitive data with a salt
C.Application-level encryption with deterministic encryption for the searchable field
D.Tokenization of all sensitive fields with a centralized token vault
AnswerC

Application-level encryption ensures data is encrypted before it reaches the database, so a database compromise yields only ciphertext. Using deterministic encryption for the searchable field allows equality searches because the same plaintext always produces the same ciphertext. This meets both the confidentiality and searchability requirements, making it the correct approach.

Why this answer

Application-level encryption with deterministic encryption for the searchable field ensures that data is encrypted before storage and remains unreadable if the database is compromised. Deterministic encryption allows equality searches on that field without decrypting the entire dataset. Other methods either leave data readable in memory, prevent searching, or introduce a separate high-value target.

Exam trap

The trap here is assuming that transparent data encryption protects against database compromise, when it only protects data at rest and does not prevent access once the database is running.

949
MCQmedium

A security team is implementing a new detection rule in their SIEM to identify brute-force attacks against a web application. The rule should trigger when there are more than 10 failed login attempts from the same source IP within 5 minutes. Which of the following data sources is MOST critical for this detection?

A.Application authentication logs
B.Intrusion detection system (IDS) alerts
C.Firewall logs
D.Web server access logs
AnswerA

Application authentication logs capture login attempts and their outcomes, including failures. They provide the necessary details such as username, source IP, and timestamp to detect brute-force patterns. This is the most critical source for identifying failed logins within a time window.

Why this answer

To detect brute-force attacks based on failed login attempts, the SIEM needs logs that record authentication failures. Application authentication logs provide this information with sufficient detail (source IP, timestamp, outcome). Other sources either lack authentication context or are derived alerts, making them less suitable for building a precise correlation rule.

Exam trap

The trap here is assuming that firewall or web server logs contain authentication results, when they typically do not.

950
MCQmedium

A security engineer is implementing a solution to securely store and manage cryptographic keys for a fleet of IoT devices. The devices have limited processing power and cannot perform asymmetric operations. Which of the following is the BEST approach?

A.Use a cloud-based Hardware Security Module (HSM) to generate and store keys, and provision them to devices during manufacturing.
B.Install a Trusted Platform Module (TPM) in each device to store keys on the device.
C.Use a cloud KMS to generate and wrap keys, then store the wrapped key in the device.
D.Store keys in obfuscated form in the device firmware and use a custom algorithm for encryption.
AnswerA

A cloud HSM provides secure key generation, storage, and lifecycle management; provisioning keys during manufacturing ensures they are not exposed.

Why this answer

IoT devices with limited processing power cannot efficiently perform asymmetric operations, so pre-provisioning keys from a cloud-based HSM during manufacturing ensures secure key generation and storage without burdening the device. The HSM provides tamper-resistant key generation and lifecycle management, and the keys are injected into the device's secure storage (e.g., eFuse or secure element) before deployment, eliminating the need for on-device asymmetric cryptography.

Exam trap

CompTIA often tests the misconception that TPMs are always suitable for low-power devices, but the trap here is that TPMs require the device to perform asymmetric operations (e.g., RSA key generation) which IoT devices with limited processing power cannot handle, making pre-provisioning from an HSM the only viable option.

How to eliminate wrong answers

Option B is wrong because installing a TPM in each device requires the device to perform asymmetric operations (e.g., RSA or ECC key generation and signing) which the IoT devices cannot handle due to limited processing power. Option C is wrong because storing a wrapped key in the device still requires the device to perform unwrapping (decryption) operations, which typically involve asymmetric or symmetric cryptographic operations that exceed the device's capabilities, and the key management complexity is not reduced. Option D is wrong because storing keys in obfuscated form in firmware and using a custom algorithm violates cryptographic best practices (e.g., relying on security through obscurity) and is easily reverse-engineered, providing no real security against determined attackers.

951
MCQhard

During a security review, a developer discovers that a containerized application runs with root privileges. Which of the following is the most secure approach to mitigate this risk while maintaining functionality?

A.Set the container to run as a non-root user and drop all unnecessary capabilities
B.Disable root login inside the container by modifying /etc/passwd
C.Use a read-only root filesystem for the container
D.Enable SELinux or AppArmor on the host
AnswerA

Why this answer

Running a container as a non-root user with dropped capabilities is the most secure approach because it follows the principle of least privilege. By default, containers run as root, which grants unnecessary kernel capabilities that could be exploited for privilege escalation. Setting a non-root user and using `--cap-drop=ALL` with selective `--cap-add` ensures the application retains only required permissions, reducing the attack surface without breaking functionality.

Exam trap

The CAS-004 exam often tests the misconception that disabling root login or using filesystem restrictions (read-only) is sufficient, when the real risk is the container process running as UID 0 with full capabilities, which requires explicit user context and capability dropping to mitigate.

Why the other options are wrong

B

Disabling root login does not prevent the container process from running as root; the process still has root privileges.

C

A read-only filesystem limits writes but does not reduce privileges; the container still runs as root.

D

These are mandatory access control mechanisms that can confine a process, but they do not directly address the root privilege issue; combining with non-root user is better.

952
Multi-Selecthard

An organization is deploying a new cloud-based application that processes personally identifiable information (PII). The security team must ensure data at rest is encrypted. Which THREE of the following controls should be implemented to protect the data? (Select THREE.)

Select 3 answers
A.Use tokenization for all PII fields in the database.
B.Implement a key management system (KMS) with automatic key rotation.
C.Enable transparent data encryption (TDE) on the database.
D.Use AES-256 encryption for all stored data.
E.Configure TLS 1.3 for all data connections.
AnswersB, C, D

Proper key management and rotation are critical to maintaining encryption security.

Why this answer

A key management system (KMS) with automatic key rotation ensures that encryption keys are securely stored, rotated, and managed, which is essential for protecting data at rest. Without proper key management, encryption can be rendered ineffective if keys are compromised or stale. This control directly supports the confidentiality of PII stored in the cloud.

Exam trap

The CAS-004 exam often tests the distinction between encryption for data at rest (e.g., TDE, AES-256, KMS) and encryption for data in transit (e.g., TLS), so candidates mistakenly select TLS as a data-at-rest control.

953
MCQhard

A security engineer is implementing secure boot for an embedded Linux device that uses U-Boot. The requirement is to ensure that only authenticated firmware can execute, and that the root of trust is immutable. Which of the following should the engineer implement?

A.Verified boot using a public key stored in one-time programmable (OTP) fuses to verify the bootloader signature.
B.Measured boot using a TPM to record hashes of each boot stage.
C.Encrypted boot using AES-256 to encrypt the kernel and root filesystem.
D.Secure boot using a symmetric key stored in the bootloader environment.
AnswerA

Storing the public key in OTP fuses creates an immutable root of trust that cannot be altered without physical tampering. The bootloader verifies its own signature or the next stage's signature using this key, establishing a chain of trust. This ensures that only firmware signed with the corresponding private key can execute, meeting the requirements for authentication and immutability. It is a standard approach for secure boot in embedded systems.

Why this answer

To ensure only authenticated firmware executes with an immutable root of trust, the engineer should use verified boot with a public key stored in OTP fuses. The fuses cannot be changed after programming, providing immutability. The bootloader uses the public key to verify signatures on subsequent stages, creating a chain of trust.

Encryption and measured boot do not enforce authentication, and symmetric keys in mutable storage are insecure.

Exam trap

The trap here is confusing measured boot with verified boot; measured boot only records measurements for attestation, while verified boot actually enforces signature checks and halts on failure.

954
MCQmedium

A company is designing a new data center with high availability requirements. The network team proposes using virtualized network functions (VNFs) on commodity hardware to reduce costs. Which security consideration is MOST important when implementing this design?

A.Isolate VNFs to prevent lateral movement if one VNF is compromised
B.Ensure VNFs are deployed across multiple physical hosts for redundancy
C.Encrypt all traffic between VNFs to prevent eavesdropping
D.Implement quality of service (QoS) to guarantee bandwidth for critical VNFs
AnswerA

VNFs share commodity hardware and a common hypervisor, so a compromised VNF could pivot to co-resident functions or the host. Segmenting and isolating each VNF limits lateral movement, satisfying the high-availability design's need to contain a single failure without cascading across the virtualised estate.

Why this answer

Isolating VNFs is the most important security consideration because VNFs share the same hypervisor and commodity hardware, so a compromise in one VNF could allow an attacker to move laterally to other VNFs or the underlying host. Without proper isolation (e.g., using VLANs, VXLANs, or micro-segmentation), the entire multi-tenant environment is at risk, undermining the high-availability design.

Exam trap

The trap here is that candidates confuse operational requirements (redundancy, QoS, encryption) with security controls, overlooking that isolation is the foundational security measure in a shared virtualized environment.

How to eliminate wrong answers

Option B is wrong because deploying VNFs across multiple physical hosts for redundancy is a high-availability design requirement, not a security consideration; it does not address the risk of lateral movement or compromise. Option C is wrong because encrypting traffic between VNFs (e.g., with IPsec or TLS) protects data in transit but does not prevent a compromised VNF from attacking other VNFs on the same host; isolation is a prerequisite for security. Option D is wrong because QoS guarantees bandwidth for critical VNFs, which is a performance and availability concern, not a security control; it does not mitigate the risk of a VNF being compromised and used to pivot within the network.

955
MCQmedium

A security analyst is writing a script to scan container images for known vulnerabilities before deployment. Which of the following best practices should the analyst implement to ensure the script runs securely?

A.Hardcode API keys into the script for simplicity
B.Use parameterized queries or input sanitization for any user-supplied data
C.Run the script with root privileges to ensure it has access to all images
D.Store credentials in a world-readable configuration file
AnswerB

Why this answer

Input sanitization and parameterized queries prevent injection attacks when the script processes user-supplied data, such as image names or tags. In the context of container scanning, unsanitized input could lead to command injection or SQL injection if the script queries a vulnerability database. This aligns with secure coding practices for automation scripts, ensuring that the script does not inadvertently execute malicious commands or expose sensitive data.

Exam trap

The CAS-004 exam often tests the principle of least privilege and secure credential handling in automation contexts, and the trap here is that candidates may choose root privileges (Option C) thinking it ensures full access to all images, overlooking the security risk of excessive permissions.

Why the other options are wrong

A

Hardcoding credentials is a major security risk; they can be exposed in version control.

C

Running with least privilege is a security best practice; root access increases the attack surface.

D

Credentials should be stored securely (e.g., vault, environment variables), not world-readable.

956
MCQhard

During a threat hunting exercise, a hunter uses the MITRE ATT&CK framework to identify a series of behaviors: an attacker used PowerShell to download a payload, then created a scheduled task for persistence, and finally performed credential dumping via LSASS. Which ATT&CK tactic is associated with the credential dumping technique?

A.Defense Evasion
B.Credential Access
C.Execution
D.Persistence
AnswerB

Credential dumping via LSASS maps to the Credential Access tactic in MITRE ATT&CK, which covers techniques for stealing account credentials such as hashes and plaintext passwords. This directly answers the stem's question about the tactic associated with the LSASS dumping behaviour.

Why this answer

Credential dumping via LSASS (e.g., Mimikatz reading lsass.exe memory) is classified under the Credential Access tactic in MITRE ATT&CK, specifically technique T1003 OS Credential Dumping. The tactic describes the adversary's goal of stealing account names and passwords to use for lateral movement and privilege escalation. LSASS holds cached credentials and Kerberos tickets, making it a prime target for this tactic.

Exam trap

CAS-005 often tests the overlap between tactics — candidates see 'PowerShell' or 'scheduled task' in the scenario and pick Execution or Persistence, ignoring that the question specifically asks about the credential dumping step.

How to eliminate wrong answers

Option A is wrong because Defense Evasion covers techniques like obfuscation, disabling security tools, or process injection to avoid detection — credential dumping may incidentally involve evasion, but its primary goal is obtaining credentials, so it maps to Credential Access. Option C is wrong because Execution covers running adversary-controlled code (e.g., PowerShell, scheduled tasks, WMI) — the PowerShell download in the scenario is Execution, not the LSASS dump. Option D is wrong because Persistence covers maintaining foothold (e.g., scheduled tasks, registry run keys) — the scheduled task in the scenario is Persistence, not credential dumping.

957
MCQeasy

A security administrator is troubleshooting a web application that intermittently rejects valid user sessions. Logs show the application server's clock drifted several minutes behind the authentication service, and the tokens carry short validity windows with issued-at and expiry claims. Which action MOST directly resolves the intermittent rejections?

A.Increase the token validity window from five minutes to several hours so clock differences no longer matter.
B.Disable expiry claim validation on the application server so tokens are trusted until the session store marks them invalid.
C.Configure the application server and authentication service to synchronize their clocks with the same trusted NTP time sources.
D.Shorten the token validity window further so that affected tokens expire quickly and users reauthenticate more often.
AnswerC

Token validation compares the issued-at and expiry claims against the validator's own clock, so a multi-minute skew causes tokens that are genuinely valid to appear not-yet-valid or expired. Pointing both systems at the same authenticated NTP hierarchy removes the skew at its source and restores consistent validation without weakening token lifetimes.

Why this answer

Time-based token claims are only meaningful when the issuer and validator share a common time reference. Synchronizing both systems to the same authenticated NTP sources eliminates the skew that causes valid tokens to be judged expired or not yet valid, fixing the rejections without loosening token lifetimes or removing expiry enforcement.

Exam trap

The trap here is reaching for token lifetime or validation changes to stop the errors instead of correcting the clock skew that makes correct validation fail.

958
Multi-Selecthard

A security team is implementing a new endpoint detection and response (EDR) solution. The team wants to ensure the EDR can detect advanced threats that use fileless malware techniques. Which TWO of the following capabilities are MOST important for detecting fileless malware? (Choose two.)

Select 2 answers
A.Disk encryption of the endpoint's hard drive
B.Monitoring of PowerShell and Windows Management Instrumentation (WMI) activity
C.Regular vulnerability scanning of the endpoint
D.Analysis of in-memory process behavior and API calls
E.Signature-based detection of known malware hashes
AnswersB, D

Fileless malware often uses built-in system tools like PowerShell and WMI to execute malicious code in memory without writing to disk. Monitoring these activities can detect suspicious command lines, encoded scripts, and unusual WMI events. This is critical because traditional file-based detection may miss such threats. EDR solutions that log and analyze PowerShell and WMI behavior can identify malicious patterns and block execution.

Why this answer

Fileless malware executes in memory using legitimate system tools, so detecting it requires monitoring of scripting and management interfaces like PowerShell and WMI, as well as analyzing in-memory process behavior and API calls. These capabilities allow EDR to identify malicious activity without relying on file signatures. The other options are either preventive measures or ineffective against fileless threats.

Exam trap

The trap here is assuming that traditional signature-based detection or vulnerability scanning can catch fileless malware, when in fact they are ineffective because fileless malware leaves no files on disk.

959
MCQeasy

A security architect is evaluating a new identity management solution. The requirement is to allow users to authenticate using their existing social media accounts while maintaining corporate control over access policies. Which architecture best meets this requirement?

A.Privileged access management (PAM) solution
B.Single sign-on (SSO) using a corporate LDAP directory
C.Public Key Infrastructure (PKI) with digital signatures
D.Federated identity management using Security Assertion Markup Language (SAML)
AnswerD

Federation allows external IdPs like social media, while the enterprise controls policies.

Why this answer

Federated identity management using SAML enables users to authenticate via external identity providers (e.g., social media platforms) while the corporate system retains control over access policies through the exchange of SAML assertions. This architecture decouples authentication from authorization, allowing the corporate service provider to enforce its own rules based on trusted identity claims.

Exam trap

The CAS-004 exam often tests the distinction between authentication and authorization, and the trap here is that candidates may confuse SSO with LDAP (Option B) as sufficient for external identity federation, failing to recognize that LDAP requires direct directory membership and does not support trust delegation to external IdPs.

How to eliminate wrong answers

Option A is wrong because Privileged Access Management (PAM) is designed to manage and monitor privileged accounts (e.g., admin credentials), not to authenticate users via social media or federate identities. Option B is wrong because Single Sign-On using a corporate LDAP directory requires users to be provisioned in the corporate directory, which does not support authentication via external social media accounts. Option C is wrong because Public Key Infrastructure with digital signatures provides non-repudiation and encryption but does not inherently enable federation or delegation of authentication to third-party identity providers.

960
MCQmedium

A security analyst is reviewing TLS 1.3 configuration for a web server. The analyst wants to ensure that the configuration provides forward secrecy and prevents the reuse of session keys. Which of the following is a characteristic of TLS 1.3 that supports these goals?

A.0-RTT session resumption
B.Support for static RSA key exchange
C.Use of ephemeral Diffie-Hellman key exchange
D.Removal of CBC mode cipher suites
AnswerC

Ephemeral Diffie-Hellman generates a unique key pair per session, then discards it, so compromising the server's long-term private key cannot decrypt past traffic — satisfying the forward secrecy requirement. Because each handshake derives fresh session keys, reuse across sessions is impossible, meeting the stem's second constraint.

Why this answer

TLS 1.3 mandates the use of ephemeral Diffie-Hellman key exchange (DHE or ECDHE) for all handshakes, which provides forward secrecy by generating a unique session key for each session that cannot be derived from the server's long-term private key. This ensures that even if the server's private key is compromised later, past session keys remain secure and cannot be reused.

Exam trap

CAS-005 often tests the misconception that 0-RTT or static RSA provide forward secrecy, when in fact TLS 1.3's ephemeral Diffie-Hellman is the key mechanism for forward secrecy.

How to eliminate wrong answers

Option A is wrong because 0-RTT session resumption allows a client to send data in the first flight using a previously established pre-shared key, which can be vulnerable to replay attacks and does not provide forward secrecy for the resumed session. Option B is wrong because static RSA key exchange does not provide forward secrecy; it was removed in TLS 1.3 precisely for this reason. Option D is wrong because while TLS 1.3 does remove CBC mode cipher suites, that removal is about eliminating weaknesses like padding oracle attacks, not directly about forward secrecy or session key reuse.

961
MCQeasy

An organization needs to ensure consistent configuration across multiple Linux servers. They want to automate this process with a solution that requires minimal agent installation and uses push-based communication. Which approach is most appropriate?

A.Use PowerShell Desired State Configuration (DSC) with Linux extensions.
B.Use Ansible playbooks to define and enforce server configurations.
C.Run a Docker container on each server with a configuration management tool inside.
D.Deploy Puppet with a master server and agents on each system.
AnswerB

Ansible operates agentlessly over SSH, pushing modules to managed Linux nodes on demand, which directly satisfies the minimal-installation and push-based constraints. Playbooks declaratively define and enforce consistent configuration across all servers, unlike pull-based alternatives such as Puppet or Chef that require an installed agent on every node.

Why this answer

Ansible is the most appropriate choice because it is agentless (no agent installation required) and uses push-based communication over SSH to enforce configurations. It uses YAML-based playbooks to define desired states, making it ideal for automating consistent configuration across multiple Linux servers with minimal overhead.

Exam trap

The trap here is that candidates often confuse agent-based tools like Puppet or DSC with agentless ones, or assume that containerization inherently reduces agent footprint, when in fact it introduces its own runtime dependencies.

How to eliminate wrong answers

Option A is wrong because PowerShell DSC requires the Open Management Infrastructure (OMI) agent on Linux, which contradicts the 'minimal agent installation' requirement. Option C is wrong because running a Docker container with a configuration management tool inside still requires Docker installation and management on each server, adding complexity rather than minimizing agent footprint. Option D is wrong because Puppet typically uses a pull-based model (agents poll the master) and requires agent software on each node, which violates both the push-based and minimal agent installation criteria.

962
MCQhard

A company is implementing single sign-on using SAML 2.0. A security architect is reviewing the authentication flow and notices that the identity provider (IdP) does not digitally sign the SAML assertions. Which of the following is the most significant security risk?

A.The assertion could be modified in transit
B.The assertion could be intercepted and read
C.The IdP could be spoofed
D.The assertion could be replayed
AnswerA

Unsigned SAML assertions let any intermediary alter attributes such as NameID or role claims before the service provider consumes them, because the SP has no cryptographic means of verifying origin or integrity. This directly satisfies the stem's constraint: without an IdP signature, tampering in transit is undetectable, enabling privilege escalation or impersonation.

Why this answer

SAML assertions carry the authentication and authorization claims that the service provider (SP) trusts. Without a digital signature, there is no cryptographic integrity protection, so an attacker who can intercept or manipulate the SAML response (e.g., via a man-in-the-middle or by tampering with the POST binding) can alter the assertion contents—such as changing the user identity or elevating privileges—and the SP has no way to detect the modification. This is the most significant risk because it directly undermines the trust model of SSO.

Exam trap

The trap here is confusing integrity with confidentiality: candidates often pick 'intercepted and read' because they think of encryption, but signing addresses tampering, not eavesdropping.

How to eliminate wrong answers

Option B is wrong because interception and reading (confidentiality) is mitigated by TLS encryption, not by signing; signing provides integrity and authenticity, not confidentiality. Option C is wrong because IdP spoofing is primarily prevented by signing the response/assertion with the IdP's private key and validating with the IdP's public certificate; however, the question specifically states the IdP does not sign the assertion, so spoofing is a related but less direct risk than tampering. Option D is wrong because replay attacks are mitigated by conditions such as NotBefore/NotOnOrAfter timestamps and one-time-use assertions, not by signing alone; signing does not prevent replay.

963
Multi-Selecthard

An incident responder is analyzing a compromised server. Which THREE indicators are MOST likely to confirm a successful attack?

Select 3 answers
A.Corrupted system files
B.Unusual outbound network connections
C.Multiple failed login attempts
D.High CPU usage due to legitimate processes
E.New unauthorized administrative accounts
AnswersA, B, E

Corrupted system files indicate an attacker modified or destroyed critical binaries, confirming successful compromise rather than mere attempted access. This satisfies the stem's requirement for an indicator most likely to confirm a successful attack on the server.

Why this answer

Corrupted system files (A) are a strong confirmation of a successful attack because malware or an intruder with root/SYSTEM privileges often modifies, replaces, or deletes binaries and configuration files (e.g., tampering with /etc/passwd, system DLLs, or boot files) to persist or disable defenses, which is evidence of actual system compromise rather than mere attempted access. Unusual outbound network connections (B) confirm success because they indicate command-and-control (C2) beaconing, data exfiltration, or reverse shells over non-standard ports or protocols (e.g., DNS tunneling, HTTPS to unknown IPs), which only occur after an attacker has established a foothold and executed code. New unauthorized administrative accounts (E) confirm success because creating accounts with elevated privileges (e.g., adding a user to the Administrators group or /etc/sudoers) requires the attacker to have already gained sufficient access to modify the security database, demonstrating persistence and privilege escalation.

Multiple failed login attempts (C) are only an indicator of attempted brute-force or password-guessing activity and do not by themselves prove that any login succeeded, so they are not confirmation of a successful attack. High CPU usage due to legitimate processes (D) is explicitly benign activity and therefore cannot serve as an indicator of compromise at all.

Exam trap

The CASP+ exam often tests the distinction between indicators of an ongoing attack (like failed logins) and indicators of a successful compromise (like corrupted files or new accounts), tricking candidates into selecting multiple failed login attempts as a confirmation of success.

964
Multi-Selectmedium

A penetration tester is conducting a test against a web application. The client has defined rules of engagement that prohibit any denial of service attacks. The tester discovers an endpoint that is vulnerable to command injection. Which THREE of the following actions should the tester take to validate the vulnerability while staying within scope? (Choose THREE.)

Select 3 answers
A.Use the echo command to write a file on the server
B.Run a whoami command to confirm the user context
C.Delete a random system file to observe impact
D.Flood the endpoint with multiple requests to test resilience
E.Execute a ping command to a controlled server to verify code execution
AnswersA, B, E

Writing a file with echo proves command injection executed without launching floods, crashes or resource exhaustion. This validates the vulnerability while honouring the rules of engagement prohibiting denial of service, satisfying the stem's in-scope constraint.

Why this answer

Option A is correct because using the echo command to write a benign file on the server safely demonstrates command injection without causing damage or service disruption, which respects the no-DoS rules of engagement. Option B is correct because running whoami is a non-destructive command that confirms code execution and reveals the privilege context of the injected commands, providing clear validation evidence. Option E is correct because pinging a controlled server (e.g., via the ping command to an IP the tester owns) verifies outbound code execution and network reachability without harming the target or violating the no-DoS constraint.

Option C is not appropriate because deleting a system file is destructive and could cause an outage or data loss, violating the rules of engagement. Option D is not appropriate because flooding the endpoint with multiple requests constitutes a denial-of-service style test, which the client explicitly prohibited.

965
MCQmedium

A security architect at a financial services firm must ensure that virtual machine workloads on a private cloud cannot execute unauthorized binaries, even if an attacker gains root access. The solution must enforce policy at the hypervisor layer without relying on agents inside the guest OS. Which of the following should the architect implement?

A.Virtual machine introspection (VMI) with hypervisor-enforced integrity monitoring
B.File integrity monitoring (FIM) of /usr/bin on each virtual machine
C.Security information and event management (SIEM) correlation with guest OS logs
D.Host-based intrusion prevention system (HIPS) installed on each guest OS
AnswerA

VMI allows the hypervisor to inspect guest memory and CPU state from outside the VM, so policy enforcement cannot be bypassed by root-level attackers inside the guest. It monitors integrity and can block execution of unauthorized binaries at the hypervisor layer, satisfying the agentless and root-resistant requirements described in the scenario.

Why this answer

Hypervisor-based introspection enforces policy outside the guest OS, so even root-level malware cannot disable the control. It provides tamper-resistant visibility and can prevent execution of unauthorized binaries, meeting the agentless and root-resistant requirements. Agent-based tools and log correlation are either bypassable or detective only.

Exam trap

The trap here is assuming that any endpoint security tool running inside the guest OS can enforce policy against a root-level attacker.

966
Multi-Selecthard

An incident response team is handling a ransomware incident. The team has successfully contained the threat and is now in the eradication phase. Which THREE actions are appropriate for the eradication phase? (Select THREE.)

Select 3 answers
A.Restore systems from clean backups
B.Apply security patches to the vulnerability that allowed initial access
C.Revoke and reset all compromised user and service accounts
D.Delete all infected files and registry keys associated with the ransomware
E.Conduct a lessons learned meeting
AnswersB, C, D

Patching the exploited vulnerability removes the initial access vector, preventing re-compromise during recovery. Eradication requires eliminating the root cause, so remediation of the flaw that permitted entry is a core action, distinct from containment or recovery tasks.

Why this answer

In the eradication phase, the goal is to remove the threat and close the attack vector, so option B is correct because applying security patches to the vulnerability that allowed initial access eliminates the root cause and prevents reinfection. Option C is correct because revoking and resetting all compromised user and service accounts removes adversary persistence and stops further unauthorized access using stolen credentials. Option D is correct because deleting all infected files and registry keys associated with the ransomware removes malicious artifacts and persistence mechanisms from affected systems.

Option A is not appropriate here because restoring systems from clean backups is a recovery-phase action performed after eradication, and option E is not appropriate because conducting a lessons learned meeting occurs in the post-incident activity phase after recovery is complete.

Exam trap

CAS-005 often tests the confusion between eradication and recovery phases, where candidates incorrectly select recovery actions like restoring from backups as part of eradication.

967
MCQmedium

A security architect is reviewing the network segmentation of a healthcare organization that must comply with HIPAA. The current flat network allows all devices to communicate. Which segmentation approach provides the best balance of security and manageability?

A.Create a physical air gap between all systems
B.Assign each device its own VLAN with no inter-VLAN routing
C.Segment using VLANs and ACLs to limit traffic to necessary flows
D.Place all critical systems in a single DMZ subnet
AnswerC

VLANs with ACLs enforce least-privilege east-west traffic filtering at Layer 3, isolating regulated ePHI systems from general devices while remaining operationally manageable without per-host agents. This satisfies HIPAA's access-control and segmentation expectations, unlike a flat network where any compromised device reaches every system.

Why this answer

VLANs logically segment the flat network into separate broadcast domains, and ACLs applied at the Layer 3 boundary (e.g., on the switch virtual interface or router) enforce least-privilege access by permitting only necessary traffic flows between segments. This approach meets HIPAA's technical safeguard requirements (45 CFR § 164.312(a)(1)) for access control and integrity without the operational overhead of physical separation or the security risk of a single DMZ.

Exam trap

The trap here is that candidates confuse 'segmentation' with 'isolation' and choose Option B (every device its own VLAN) thinking it maximizes security, but they overlook the manageability nightmare and the fact that HIPAA requires authorized access between systems for treatment, payment, and operations (TPO).

How to eliminate wrong answers

Option A is wrong because a physical air gap between all systems would prevent any electronic communication, making clinical workflows (e.g., EHR access, lab results transmission) impossible and violating HIPAA's requirement for timely access to patient data. Option B is wrong because assigning each device its own VLAN with no inter-VLAN routing creates an unmanageable broadcast domain explosion (4094 VLAN limit per 802.1Q) and prevents any necessary communication between devices (e.g., a workstation needing to reach a printer or database server). Option D is wrong because placing all critical systems in a single DMZ subnet collapses the security zones into one, meaning a compromise of any system (e.g., a web server) would expose all other critical systems (e.g., EHR database) to direct attack, violating the principle of defense in depth.

968
MCQhard

A company wants to implement continuous compliance monitoring. Which of the following approaches BEST supports this goal?

A.Manual review of compliance reports quarterly
B.Deploying a Security Information and Event Management (SIEM) system
C.Implementing automated compliance auditing tools
D.Annual external audits
AnswerC

Automated compliance auditing tools continuously evaluate configurations against benchmarks and frameworks, generating evidence and alerts without manual review cycles. This satisfies the requirement for continuous monitoring rather than periodic point-in-time assessment, enabling prompt detection of drift or non-compliance across the estate.

Why this answer

Continuous compliance monitoring requires automated, real-time checks against policies and regulations. Automated auditing tools can continuously assess controls and generate alerts.

969
Multi-Selecthard

A compliance officer is preparing for a GDPR audit. Which THREE of the following are key data subject rights under GDPR that the organization must be able to demonstrate?

Select 3 answers
A.Right to object to processing
B.Right to unlimited data storage
C.Right to erasure (right to be forgotten)
D.Right to data monetization
E.Right to data portability
AnswersA, C, E

The right to object lets individuals halt processing based on legitimate interests or direct marketing, and controllers must honour it unless they demonstrate compelling grounds. Auditors expect documented workflows and records proving this GDPR right can be exercised and enforced.

Why this answer

GDPR grants data subjects several rights, including the right to erasure (right to be forgotten), right to data portability, and right to object to processing. The right to rectification is also a right but is not listed as an option. The right to data monetization and right to unlimited storage are not GDPR rights.

970
MCQmedium

A security analyst is reviewing the configuration of a web application firewall (WAF) protecting an e-commerce site. The analyst notices that the WAF is in detection-only mode. The site has been experiencing SQL injection attacks that are not being blocked. Which of the following actions should the analyst take to BEST protect the site while minimizing false positives?

A.Switch the WAF to blocking mode immediately.
B.Review the WAF logs, create custom rules to address the SQL injection patterns, and then switch to blocking mode.
C.Disable the WAF and rely on input validation in the application code.
D.Configure the WAF to block only requests from known malicious IP addresses.
AnswerB

Reviewing logs allows the analyst to understand the attack patterns and identify false positives. Creating custom rules tailors the WAF to the specific application, reducing false positives. Switching to blocking mode after tuning ensures that legitimate traffic is not disrupted while attacks are blocked.

Why this answer

Reviewing logs allows the analyst to understand the attack patterns and identify false positives. Creating custom rules tailors the WAF to the specific application, reducing false positives. Switching to blocking mode after tuning ensures that legitimate traffic is not disrupted while attacks are blocked.

Exam trap

The trap here is thinking that simply enabling blocking mode will solve the problem, but without tuning, it can cause more harm than good.

971
MCQhard

A security architect is designing a system that must comply with FedRAMP Moderate controls. The system will use a cloud service provider (CSP) that is already FedRAMP Authorized. What is the primary benefit of using this CSP?

A.The agency no longer needs to conduct any risk assessments
B.The CSP guarantees 100% security
C.The system automatically complies with all international regulations
D.The CSP's authorization can be reused, reducing the agency's assessment burden
AnswerD

Leverages existing authorization

Why this answer

The primary benefit of using a FedRAMP Authorized CSP is that the CSP has already undergone a rigorous third-party assessment and continuous monitoring process. This allows the agency to reuse the existing authorization (via the 'JAB' or agency Provisional Authorization), significantly reducing the time, cost, and effort required for the agency's own assessment and authorization (ATO) process. It does not eliminate the agency's responsibility for risk management or compliance with FedRAMP Moderate controls, but it leverages the CSP's proven security posture.

Exam trap

The CAS-004 exam often tests the misconception that FedRAMP authorization absolves the agency of all compliance work, when in fact the agency must still perform a system-specific risk assessment and maintain its own ATO for the overall system.

How to eliminate wrong answers

Option A is wrong because the agency is still required to conduct its own risk assessments, including a system-specific risk assessment for the overall system and the CSP's inherited controls; FedRAMP authorization does not eliminate the agency's risk management responsibilities. Option B is wrong because no CSP or system can guarantee 100% security; FedRAMP authorization indicates a baseline of security controls have been implemented and assessed, but residual risk always remains. Option C is wrong because FedRAMP is a U.S. federal program and does not automatically confer compliance with international regulations such as GDPR, ISO 27001, or the EU Cloud Code of Conduct; separate assessments are needed for international frameworks.

972
Multi-Selecthard

Which THREE of the following are essential components of a secure software development lifecycle (SSDLC)?

Select 3 answers
A.Continuous deployment
B.Static application security testing (SAST)
C.Code signing
D.Threat modeling
E.Penetration testing
AnswersB, D, E

SAST analyzes source code for vulnerabilities during the development phase.

Why this answer

Static application security testing (SAST) is a white-box testing method that analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. It is an essential component of a secure software development lifecycle (SSDLC) because it enables early detection of flaws such as SQL injection, buffer overflows, and cross-site scripting during the coding and build phases, reducing remediation cost and risk.

Exam trap

CompTIA often tests the distinction between security activities that are integrated into the development process (like SAST, threat modeling, and penetration testing) versus operational or post-deployment practices (like continuous deployment and code signing), leading candidates to mistakenly include the latter as SSDLC essentials.

973
MCQhard

A healthcare organization is implementing a new telehealth platform that stores electronic protected health information (ePHI). The security team must ensure compliance with the HIPAA Security Rule. Which of the following is a required implementation specification for access control under the HIPAA Security Rule?

A.Emergency access procedure
B.Automatic logoff
C.Encryption and decryption
D.Unique user identification
AnswerD

Under the HIPAA Security Rule, unique user identification is a required implementation specification for access control (45 CFR §164.312(a)(2)(i)). It mandates that each user accessing ePHI be assigned a unique identifier to track activity and enforce accountability. This is not optional; it must be implemented to comply with the rule, making it the correct choice for this scenario.

Why this answer

The HIPAA Security Rule distinguishes between required and addressable implementation specifications. Unique user identification is explicitly required for access control, ensuring accountability and traceability. Addressable specifications like emergency access, automatic logoff, and encryption require a risk-based decision but are not mandatory in all cases.

Exam trap

The trap here is assuming that all implementation specifications under the HIPAA Security Rule are mandatory, when some are addressable and allow flexibility.

Page 12

Page 13 of 13