Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 76–150

973 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
MCQeasy

Which of the following is a key principle of the zero trust security model?

A.Trust all internal traffic
B.Verify once, trust forever
C.Trust but verify
D.Never trust, always verify
AnswerD

The zero trust model enforces authentication and authorisation at every access request, regardless of network location, by requiring continuous verification of identity, device health, and session context before granting resource access. This satisfies the stem’s requirement for a foundational principle, as it directly opposes the traditional perimeter-based trust model. In Microsoft Entra ID, conditional access policies implement this by evaluating real-time signals for each request.

Why this answer

Zero trust is built on the principle 'never trust, always verify' — no user, device, or network segment is implicitly trusted based on location. Every access request must be authenticated, authorized, and continuously validated regardless of whether it originates inside or outside the traditional perimeter. This is the foundational tenet articulated in NIST SP 800-207.

Exam trap

CAS-005 often tests the confusion between 'trust but verify' (a legacy phrase implying baseline trust) and 'never trust, always verify' (the actual zero trust mantra), since both sound security-conscious but only one reflects the model.

How to eliminate wrong answers

Option A is wrong because trusting all internal traffic is the exact opposite of zero trust — it reflects the legacy castle-and-moat perimeter model that zero trust was designed to replace. Option B is wrong because 'verify once, trust forever' describes a one-time authentication model; zero trust requires continuous verification of session context, device posture, and behavior. Option C is wrong because 'trust but verify' is a Cold War-era phrase implying implicit trust with spot checks, whereas zero trust starts from a position of no trust and requires explicit verification for every request.

77
MCQmedium

A financial institution is adopting a new vendor-managed SaaS platform for customer data processing. The CISO wants to ensure the vendor's security controls meet regulatory requirements before data is transferred. Which of the following should be completed FIRST?

A.Execute a penetration test on the SaaS platform.
B.Implement data loss prevention controls.
C.Conduct a vulnerability assessment of the vendor's network.
D.Perform a third-party risk assessment.
AnswerD

A third-party risk assessment evaluates the vendor's security controls, compliance posture and data handling against regulatory requirements before any data is transferred. It identifies gaps and informs contractual safeguards, making it the necessary first step prior to onboarding the SaaS platform.

Why this answer

Before transferring sensitive customer data to a new vendor-managed SaaS platform, the CISO must first perform a third-party risk assessment to evaluate the vendor's security posture against regulatory requirements (e.g., GDPR, PCI DSS). This assessment reviews the vendor's SOC 2 reports, ISO 27001 certification, and contractual security controls, ensuring compliance before any technical testing or data transfer occurs. Without this initial risk evaluation, subsequent technical controls like penetration tests or DLP may be premature or misaligned with regulatory obligations.

Exam trap

The trap here is that candidates often jump to technical testing (penetration test or vulnerability assessment) as the first step, overlooking that governance and compliance require a contractual and risk-based evaluation before any hands-on technical engagement is permitted.

How to eliminate wrong answers

Option A is wrong because executing a penetration test on the SaaS platform assumes the vendor has granted explicit authorization and a signed testing agreement, which cannot occur before a formal risk assessment establishes the legal and compliance framework. Option B is wrong because implementing data loss prevention controls on the institution's network is a reactive measure that does not address whether the vendor's own security controls meet regulatory requirements; DLP cannot compensate for a vendor's non-compliance. Option C is wrong because conducting a vulnerability assessment of the vendor's network requires prior contractual permission and scope definition, which are outcomes of a third-party risk assessment; without that, the assessment may violate the vendor's terms of service or data protection laws.

78
Multi-Selecthard

A security analyst is reviewing a malware sample in a sandbox environment. The analyst notes that the malware attempts to check for the presence of a debugger and modifies its behavior if one is detected. Additionally, the malware uses encrypted strings and resolves API calls dynamically. Which THREE analysis techniques would be most effective for understanding this malware's capabilities? (Select THREE.)

Select 3 answers
A.Static analysis using a disassembler like IDA Pro to examine the code for anti-debugging and obfuscation techniques
B.Network analysis using Wireshark to capture packets from the sandbox
C.Hash analysis by submitting the malware to VirusTotal
D.Dynamic analysis in a sandbox to observe the malware's behavior after it detects a debugger
E.Memory analysis using Volatility on the sandbox host to capture the malware's process memory
AnswersA, D, E

Disassembly with IDA Pro reveals anti-debugging checks, encrypted string routines and dynamic API resolution logic in the code itself, without executing the sample. This exposes the obfuscation and evasion mechanisms the malware uses, which behavioural observation alone cannot fully map.

Why this answer

Option A is correct because static analysis with a disassembler such as IDA Pro lets the analyst inspect the binary's code directly, revealing the anti-debugging checks (e.g., IsDebuggerPresent, PEB BeingDebugged flag) and the obfuscation/encrypted-string routines without executing the sample. Option D is correct because dynamic analysis in a sandbox observes the malware's actual runtime behavior, and since the sample alters its behavior when a debugger is detected, running it in an instrumented sandbox (without an attached debugger) exposes the alternate execution path and its true capabilities. Option E is correct because memory analysis with Volatility captures the malware's process memory, allowing recovery of dynamically resolved API addresses, decrypted strings, and unpacked code that never appear on disk.

Option B is not among the correct answers because Wireshark packet capture only shows network traffic and cannot reveal the anti-debugging logic, encrypted strings, or dynamic API resolution central to this sample. Option C is not among the correct answers because VirusTotal hash lookups only provide reputation and prior detection data, not an understanding of the malware's internal capabilities.

Exam trap

CAS-005 often tests the misconception that simple hash or network analysis is sufficient for evasive malware, when in fact obfuscated and anti-debugging malware requires deeper static, dynamic, and memory analysis.

79
MCQmedium

A security analyst receives an alert from the SIEM indicating a possible DNS tunneling attempt. The analyst needs to investigate the incident. Which of the following actions should the analyst take FIRST to validate the alert?

A.Run a vulnerability scan on the suspected host to check for DNS-related exploits.
B.Review DNS logs for unusually long or high-entropy subdomain queries from the same host.
C.Capture full packet data for all DNS queries and analyze the payloads for executable content.
D.Immediately block all outbound DNS traffic from the suspected host.
AnswerB

DNS tunneling often encodes data in subdomains, resulting in long, random-looking strings. Reviewing DNS logs for such patterns from a single host can quickly validate the alert. This is a direct and efficient first step because it uses existing log data without disrupting operations, and it can confirm whether the traffic is anomalous.

Why this answer

The first step should be to review DNS logs for anomalies such as long or high-entropy subdomain queries from the same host. This leverages existing data to validate the alert without disrupting services. Blocking DNS traffic is a containment action, packet capture is more resource-intensive, and vulnerability scanning does not address active tunneling behavior.

Exam trap

The trap here is jumping to containment or advanced analysis before performing a simple log review, which can quickly confirm or dismiss the alert.

80
Multi-Selectmedium

A company is implementing continuous compliance monitoring for PCI DSS. Which TWO activities are most appropriate for this approach? (Select TWO.)

Select 2 answers
A.Manual review of access logs every month
B.Automated daily file integrity monitoring on critical systems
C.Annual on-site audit by a Qualified Security Assessor (QSA)
D.Automated quarterly vulnerability scanning of the cardholder data environment
E.Real-time monitoring of firewall and intrusion detection system logs
AnswersB, E

Automated daily file integrity monitoring directly satisfies PCI DSS continuous monitoring by detecting unauthorised changes to critical system files between point-in-time assessments. Unlike periodic manual reviews, it provides the ongoing, evidence-generating oversight the stem demands, flagging tampering or drift promptly so remediation occurs before the next audit cycle.

Why this answer

Option B is correct because continuous compliance monitoring relies on automated, recurring controls such as daily file integrity monitoring (FIM) on critical systems, which detects unauthorized changes to system files in near real time and supports PCI DSS Requirement 11.5. Option E is correct because real-time monitoring of firewall and IDS logs provides continuous visibility into security events and supports PCI DSS Requirements 10 and 11.4, enabling prompt detection and response rather than point-in-time checks. Option A is not appropriate because monthly manual log review is periodic and labor-intensive, not continuous or automated.

Option C is not appropriate because an annual QSA on-site audit is a point-in-time assessment, not continuous monitoring. Option D is not appropriate because quarterly vulnerability scanning, while required by PCI DSS, is periodic rather than continuous monitoring.

Exam trap

CAS-005 often tests the distinction between continuous and periodic activities. Candidates may select quarterly scanning or annual audits because they are required by PCI DSS, but they are not continuous monitoring.

81
MCQhard

A multinational retailer needs to protect cardholder data across its e-commerce platform, which spans on-premises and multiple cloud providers. The security architect must implement a solution that discovers sensitive data, classifies it consistently, and enforces encryption and access policies wherever the data resides, without relying on a single cloud provider's native tools. Which of the following should the architect implement?

A.A hardware security module (HSM) cluster in the primary data center.
B.A data security posture management (DSPM) solution with centralized policy and encryption key management.
C.A web application firewall (WAF) deployed in front of each e-commerce site.
D.A cloud security posture management (CSPM) tool integrated with each cloud provider.
AnswerB

DSPM discovers and classifies sensitive data across on-premises and multi-cloud environments, then applies consistent protection policies. With centralized key management, it can enforce encryption and access controls regardless of where the data resides, meeting the cross-provider, data-centric requirement without vendor lock-in.

Why this answer

The requirement is data-centric protection across on-premises and multiple clouds with consistent discovery, classification, encryption, and access policy. DSPM with centralized key management delivers cross-provider visibility and enforcement. CSPM addresses configuration, WAF addresses application attacks, and HSM addresses key operations, none of which provide the complete data discovery and policy enforcement needed.

Exam trap

The trap here is confusing CSPM with DSPM, when CSPM evaluates cloud configuration posture and DSPM evaluates and protects the data itself.

82
MCQeasy

Which of the following risk treatment options involves transferring the financial impact of a risk to a third party, such as through insurance?

A.Avoid
B.Accept
C.Transfer
D.Mitigate
AnswerC

Transfer shifts the financial consequences of a risk to a third party, typically an insurer, while the risk itself remains. Insurance is the classic example, matching the stem's requirement to move financial impact rather than avoid, reduce or accept the risk.

Why this answer

Risk transfer shifts the financial consequence of a risk to a third party, most commonly through insurance, contractual indemnification, or outsourcing. The organization retains the risk event's possibility but offloads the monetary impact to another party. This is distinct from avoiding, accepting, or mitigating the risk.

Exam trap

The trap is confusing transfer with mitigation — candidates may pick 'mitigate' because insurance feels like a control, but transfer specifically addresses shifting financial impact to a third party.

How to eliminate wrong answers

Option A is wrong because risk avoidance eliminates the activity or process that creates the risk entirely, rather than shifting its financial impact. Option B is wrong because risk acceptance means the organization acknowledges the risk and absorbs the potential loss itself, with no third-party involvement. Option D is wrong because risk mitigation reduces the likelihood or impact of the risk through controls, not by transferring financial responsibility to another party.

83
MCQmedium

A security architect is designing a web application that handles sensitive user data. To protect against cross-site scripting (XSS) attacks, which of the following should be implemented?

A.Implement Content Security Policy (CSP)
B.Use HTTPS for all communications
C.Implement input validation and output encoding
D.Deploy a Web Application Firewall (WAF)
AnswerC

Why this answer

Input validation and output encoding are the primary defenses against XSS because they prevent malicious scripts from being interpreted by the browser. Input validation rejects or sanitizes dangerous characters (e.g., <, >, &) at the point of entry, while output encoding (e.g., HTML entity encoding) ensures that any user-supplied data rendered in the page is treated as text, not executable code. This directly addresses the root cause of XSS—untrusted data being injected into the DOM.

Exam trap

The CAS-004 exam often tests the distinction between preventive controls (input validation/output encoding) and compensating controls (CSP, WAF, HTTPS), leading candidates to choose CSP or WAF because they are security-specific technologies, even though they do not eliminate the injection vulnerability itself.

Why the other options are wrong

A

CSP is a defense-in-depth measure that can reduce the impact of XSS but does not prevent it entirely; proper input validation and output encoding are the primary controls.

B

HTTPS protects data in transit but does not prevent XSS attacks.

D

WAF can detect and block some XSS attempts but is not a primary prevention; it can be bypassed and should not replace secure coding.

84
MCQeasy

A security team is preparing for a penetration test. Which document defines the scope, rules, and restrictions for the test?

A.Rules of Engagement (RoE)
B.Memorandum of Understanding (MOU)
C.Statement of Work (SoW)
D.Service Level Agreement (SLA)
AnswerA

The Rules of Engagement document is the formal agreement that scopes a penetration test, listing authorised targets, permitted techniques, timing windows and prohibited actions. It satisfies the stem's requirement for a document defining scope, rules and restrictions, protecting both tester and client legally.

Why this answer

The Rules of Engagement (RoE) is a formal document that outlines the scope, permissions, and constraints of a penetration test.

85
Multi-Selectmedium

A security team is deploying deception technology to detect lateral movement within the network. They plan to use honeypots configured to mimic critical servers. Which TWO of the following are essential considerations for the honeypot deployment to be effective? (Choose TWO.)

Select 2 answers
A.Configure the honeypots with the same patch level as production systems
B.Use realistic network services and data to attract attackers
C.Isolate the honeypots from production systems to prevent pivoting
D.Ensure the honeypots are in the same broadcast domain as production servers
E.Disable logging on honeypots to avoid detection by attackers
AnswersB, C

Honeypots only detect lateral movement if attackers believe they are genuine targets. Populating them with realistic services, banners, credentials and data sustains attacker engagement long enough to record techniques and tooling, directly satisfying the stem's requirement that the deployment attract and deceive intruders effectively.

Why this answer

Option B is correct because honeypots only generate useful detection telemetry if they present realistic, believable network services, banners, and data that entice an attacker into interacting with them; a bare or obviously fake service will be ignored and yield no lateral-movement indicators. Option C is correct because a honeypot must be isolated (for example, on a separate VLAN or segment with strict firewall/ACL rules) so that an attacker who compromises it cannot pivot into production systems, which would turn a detection asset into an attack platform. Option A is not required: matching production patch levels is not essential to effectiveness, and honeypots are often deliberately left vulnerable to attract attackers.

Option D is not required and can be risky, since placing honeypots in the same broadcast domain as production servers exposes them to unnecessary traffic and increases pivot risk. Option E is wrong because logging and monitoring are fundamental to a honeypot's purpose; disabling logging would defeat detection.

Exam trap

The trap is thinking honeypots should mirror production exactly (patch level, broadcast domain) — but the correct approach is realistic services plus strict isolation, not production parity.

86
MCQhard

A large enterprise has deployed a security information and event management (SIEM) system that ingests logs from all critical servers, network devices, and endpoints. The SIEM is configured to correlate events and generate alerts for suspicious activities. Recently, the SOC team has been overwhelmed by a high volume of false positive alerts, particularly from the web server farm. The false positives are mainly triggered by legitimate web crawling and scanning activities from partners and internal tools. The SOC manager wants to reduce false positives without missing real threats. As the security architect, you are asked to recommend a solution. Which of the following is the BEST course of action?

A.Increase the event threshold for web server alerts to reduce sensitivity.
B.Disable logging of successful requests on the web servers to reduce log volume.
C.Tune the SIEM to use more aggressive deduplication and aggregation globally.
D.Create allowlists for known legitimate sources (e.g., partner IP ranges, internal scanners) in the SIEM correlation rules.
AnswerD

Allowlisting known partner IP ranges and internal scanners suppresses alerts generated by legitimate crawling and scanning, cutting false positives without disabling detection logic for genuine threats. It targets the specific noise source rather than broadly weakening correlation rules.

Why this answer

Creating allowlists for known legitimate sources (e.g., partner IP ranges, internal scanners) in the SIEM correlation rules directly addresses the root cause: false positives from trusted entities. This approach preserves detection sensitivity for unknown or malicious sources while suppressing alerts from pre-vetted IPs, reducing alert fatigue without compromising security coverage.

Exam trap

The trap here is that candidates confuse reducing log volume (Option B) with reducing false positives, or assume that global tuning (Options A and C) is safer than targeted allowlisting, when in fact allowlisting preserves detection fidelity for unknown threats.

How to eliminate wrong answers

Option A is wrong because increasing the event threshold globally would desensitize the SIEM to all web server alerts, potentially missing low-and-slow attacks or novel threats that fall below the new threshold. Option B is wrong because disabling logging of successful requests eliminates valuable forensic data needed for incident investigation and compliance, and does not reduce false positives from scanning activities that may generate 404s or other non-success codes. Option C is wrong because aggressive deduplication and aggregation globally could merge distinct malicious events into a single alert, obscuring attack patterns and causing loss of contextual detail across all log sources, not just web servers.

87
MCQhard

A security engineer is configuring IPsec VPN between two sites. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode and protocol should be used?

A.Transport mode with AH
B.Tunnel mode with AH
C.Transport mode with ESP
D.Tunnel mode with ESP
AnswerD

Tunnel mode encapsulates the entire original IP packet, including its header, inside a new IP packet, whereas transport mode protects only the payload. ESP supplies the encryption, so tunnel mode with ESP encrypts the whole packet as the stem requires.

Why this answer

Tunnel mode with ESP encrypts the entire original IP packet and adds a new IP header, which is required for gateway-to-gateway VPNs. ESP provides encryption and optional authentication.

88
MCQmedium

During a penetration test, the tester has obtained a foothold on an internal server. The tester wants to identify other systems on the network and find potential targets for lateral movement. Which type of reconnaissance is MOST appropriate in this scenario?

A.Internal network scanning with Nmap
B.OSINT gathering via Shodan
C.Social engineering attacks on employees
D.Passive sniffing with Wireshark
AnswerA

Nmap scanning from the compromised host enumerates live neighbours, open ports and services across internal subnets, directly satisfying the requirement to find lateral-movement targets. External reconnaissance cannot reach internal-only systems, and passive sniffing reveals only traffic already traversing the segment.

Why this answer

Active reconnaissance on internal networks (e.g., port scanning, OS fingerprinting) is appropriate after gaining a foothold, as it provides detailed information about adjacent systems. Passive reconnaissance (like sniffing) might be stealthier but active scanning is more effective for mapping.

89
Multi-Selecthard

A container orchestration platform uses secrets management. Which two methods are recommended for injecting secrets into containers? (Choose two.)

Select 2 answers
A.Store secrets in environment variables in the container image.
B.Hardcode secrets in the application source code.
C.Use Kubernetes Secrets mounted as files.
D.Pass secrets via command-line arguments in the Dockerfile.
E.Use a volume mount from a secret store like HashiCorp Vault.
AnswersC, E

Mounting Kubernetes Secrets as files injects sensitive data through the container's filesystem, avoiding environment variables that leak into logs, process listings, and crash dumps. This satisfies the recommendation for secure secret delivery without exposing credentials in container metadata.

Why this answer

Option C is correct because Kubernetes Secrets can be mounted into a pod as files via a volume, keeping the secret data out of the image and source code while making it available at a filesystem path the container can read at runtime. Option E is correct because mounting a volume from an external secret store such as HashiCorp Vault (often via a CSI driver or sidecar injector) delivers secrets dynamically at runtime, supports rotation, and avoids baking credentials into the image or repository. Options A and D are not recommended because storing secrets in environment variables in the image or passing them via command-line arguments in the Dockerfile embeds them in image layers and metadata, where they can be extracted by anyone with image access.

Option B is not recommended because hardcoding secrets in application source code exposes them to anyone with repository access and makes rotation and auditing extremely difficult.

Exam trap

A common misconception is that environment variables are safe for injecting secrets into containers, but they are visible in container metadata, logs, and debugging tools, making them insecure compared to file-based mounts or external secret stores.

90
MCQhard

A security engineer is tasked with designing a cryptographic solution to protect data at rest in a multi-tenant cloud storage system. Each tenant's data must be encrypted with a unique key, and the system must support key rotation with minimal performance impact. Which of the following is the BEST approach?

A.Generate a unique key per tenant and encrypt each key with a master key, then store both in the same database column.
B.Implement envelope encryption: generate a unique data encryption key (DEK) per tenant, encrypt each DEK with a key encryption key (KEK) stored in an HSM, and store the wrapped DEK alongside the data.
C.Use a single master key for all tenants and store the key in a hardware security module (HSM) with access controls.
D.Implement a periodic key rotation schedule that rotates all tenant keys every month manually.
AnswerB

Envelope encryption satisfies the per-tenant uniqueness and rotation constraints: each tenant gets a distinct DEK, while only the KEK in the HSM needs rewrapping during rotation, avoiding bulk data re-encryption. Storing the wrapped DEK alongside the ciphertext keeps key retrieval local, so rotation incurs minimal performance overhead.

Why this answer

Envelope encryption with a unique data encryption key (DEK) per tenant allows independent key rotation and minimizes performance impact by only requiring re-wrapping of the DEK with a new key encryption key (KEK) stored in an HSM. Option A is wrong because storing both the tenant key and the master key in the same database column exposes the master key if the database is compromised. Option C is wrong because a single master key for all tenants violates isolation; if compromised, all tenant data is at risk.

Option D is wrong because manual monthly rotation of all keys is not scalable and does not provide per-tenant isolation.

91
MCQeasy

A multinational corporation that processes personal data of EU residents is required to appoint a Data Protection Officer (DPO) and implement data protection impact assessments. Which regulation primarily drives these requirements?

A.PCI DSS
B.SOX
C.GDPR
D.HIPAA
AnswerC

The GDPR mandates appointing a Data Protection Officer for large-scale monitoring or special-category processing, and requires data protection impact assessments for high-risk processing. These obligations are explicit GDPR articles, matching the stem's EU personal-data scenario rather than CCPA, HIPAA or SOX.

Why this answer

The GDPR (General Data Protection Regulation) is the EU regulation that mandates appointing a Data Protection Officer (DPO) in certain cases and requires Data Protection Impact Assessments (DPIAs) for high-risk processing. It applies to any organization processing personal data of EU residents, regardless of the organization's location, making it the primary driver of these requirements.

Exam trap

CAS-005 often tests the overlap between privacy regulations, so candidates who see 'personal data' and 'DPO' may incorrectly pick HIPAA or PCI DSS instead of recognizing the EU-specific GDPR triggers.

How to eliminate wrong answers

Option A is wrong because PCI DSS is a payment card industry standard focused on cardholder data security, not on DPO appointment or DPIAs. Option B is wrong because SOX (Sarbanes-Oxley) governs financial reporting and internal controls for public companies, not personal data protection. Option D is wrong because HIPAA governs protected health information in the US, not EU residents' personal data or DPO/DPIA requirements.

92
MCQmedium

A company is migrating its on-premises ERP system to a public cloud IaaS environment. The ERP system contains sensitive financial data. Which of the following architectural changes best maintains data security during and after migration?

A.Leverage the cloud provider's default security groups and disable encryption
B.Encrypt the data at rest and in transit, and implement IAM policies
C.Migrate the ERP without changes and apply encryption after migration
D.Use a VPN to connect on-premises and cloud while keeping data unencrypted
AnswerB

IaaS leaves the guest OS, application and data under customer control, so the shared responsibility model places encryption of data at rest and in transit plus identity and access management policies firmly with the company. This preserves confidentiality of financial data throughout and after migration.

Why this answer

Encrypting data at rest (using AES-256 or similar) and in transit (using TLS 1.2/1.3 or IPsec) ensures confidentiality during migration and after the ERP is hosted in the cloud. Implementing IAM policies with least-privilege access controls prevents unauthorized access to the sensitive financial data, addressing both data protection and access management requirements for a public cloud IaaS environment.

Exam trap

The trap here is that candidates may assume encryption after migration is sufficient, overlooking the critical need to protect data during the migration phase, or they may underestimate the importance of IAM as a complementary security control to encryption.

How to eliminate wrong answers

Option A is wrong because relying solely on the cloud provider's default security groups does not protect data at rest or in transit, and disabling encryption exposes sensitive financial data to interception and unauthorized access. Option C is wrong because migrating the ERP without changes and applying encryption after migration leaves data unencrypted during the transfer, violating confidentiality requirements and increasing risk of exposure. Option D is wrong because using a VPN to connect on-premises and cloud while keeping data unencrypted only protects the tunnel, but data remains in plaintext at rest and could be exposed if the VPN is misconfigured or compromised.

93
MCQeasy

A company wants to ensure that a third-party vendor allows them to perform an audit of the vendor's security controls. Which clause should be included in the contract?

A.Indemnification clause
B.Right-to-audit clause
C.Non-disclosure agreement (NDA)
D.Service level agreement (SLA)
AnswerB

A right-to-audit clause contractually grants the company permission to examine the vendor's security controls, evidence and records. It directly satisfies the requirement to perform an audit, giving enforceable access rather than relying on the vendor's voluntary cooperation.

Why this answer

A right-to-audit clause explicitly grants the contracting organization the contractual authority to inspect, audit, and verify the vendor's security controls, policies, and practices. Without this clause, the vendor has no legal obligation to permit audits, regardless of what security assurances they claim. This is a foundational third-party risk management control required by frameworks like SOC 2, ISO 27001, and PCI DSS.

Exam trap

The trap here is confusing contractual risk-transfer mechanisms (indemnification, SLA) with contractual risk-visibility mechanisms (right-to-audit); candidates often pick NDA or SLA because they sound security-related but do not grant audit authority.

How to eliminate wrong answers

Option A is wrong because an indemnification clause only addresses financial compensation for losses or damages caused by one party, not the right to inspect security controls. Option C is wrong because an NDA protects the confidentiality of shared information but does not grant audit rights over the vendor's environment. Option D is wrong because an SLA defines performance and availability commitments (uptime, response times) but does not inherently include the right to audit the vendor's security posture.

94
Multi-Selecthard

A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect needs to ensure that inter-service communication is secure, that services can authenticate each other, and that access to services is controlled based on identity. Which TWO of the following should be implemented? (Choose two.)

Select 2 answers
A.A shared secret used by all services for authentication
B.API keys stored in environment variables for each service
C.Network policies that allow all traffic within the cluster namespace
D.Mutual TLS (mTLS) between services using short-lived certificates
E.A service mesh with identity-based authorization policies
AnswersD, E

Mutual TLS with short-lived certificates provides strong authentication and encryption for inter-service communication. Short-lived certificates reduce the risk of key compromise and enable automatic rotation. This ensures that only authenticated services can communicate, and all traffic is encrypted, meeting the requirements for secure service-to-service communication.

Why this answer

Mutual TLS with short-lived certificates ensures encrypted and authenticated communication between services, while a service mesh with identity-based authorization policies provides centralized, fine-grained access control based on service identity. Together, they secure inter-service communication and enforce access control. The other options either lack encryption, use static secrets, or are overly permissive.

Exam trap

The trap here is thinking that network segmentation or static secrets alone can provide authentication and authorization for microservices, when identity-based controls are required.

95
MCQhard

A SOC team uses a SOAR platform to automate incident response. They want to ensure that playbooks run with minimal human intervention but still require approval for actions that could cause service disruption. Which approach should be used?

A.Require analyst sign-off for every playbook action.
B.Use network isolation as a safety net for any action.
C.Implement conditional manual approval for destructive actions.
D.Configure the SOAR to automatically execute all playbook steps.
AnswerC

Conditional manual approval satisfies the minimal-intervention constraint by automating routine playbook steps while pausing only before destructive actions, such as resource deletion or service restarts. This gates high-impact operations behind human authorisation, preventing service disruption without imposing blanket approval that would defeat the automation's efficiency.

Why this answer

Implementing conditional manual approval for destructive actions allows playbooks to run automatically for most steps, but pauses for human approval when an action could cause service disruption. This balances automation with safety.

Exam trap

CAS-005 often tests the trade-off between automation and human oversight, with candidates incorrectly choosing full automation or full manual approval instead of conditional approval for destructive actions.

How to eliminate wrong answers

Option A is wrong because requiring analyst sign-off for every action eliminates the benefit of automation and increases response time. Option B is wrong because network isolation is a containment measure, not an approval mechanism; it does not address the need for human approval for disruptive actions. Option D is wrong because automatically executing all steps without approval risks unintended service disruption.

96
MCQmedium

An organization is evaluating risk treatment options for a critical vulnerability with a CVSS score of 9.8. The cost to remediate is $500,000, and the potential loss if exploited is estimated at $2,000,000. Which risk response is most appropriate?

A.Transfer the risk through cyber insurance
B.Accept the risk
C.Avoid the risk by decommissioning the affected system
D.Remediate the vulnerability
AnswerD

Remediation costs $500,000 against a potential $2,000,000 loss, so the control is economically justified and eliminates the critical 9.8 vulnerability. This satisfies the stem's cost-benefit constraint, unlike acceptance, which retains unacceptable exposure, or transfer, which rarely covers exploited vulnerabilities.

Why this answer

With a CVSS score of 9.8 (critical) and a potential loss of $2,000,000, the cost to remediate ($500,000) is significantly lower than the expected loss. Remediation reduces the risk to an acceptable residual level, making it the most cost-effective response. This aligns with the principle that when the cost of remediation is less than the potential loss, the organization should directly fix the vulnerability.

Exam trap

CompTIA often tests the misconception that a high CVSS score automatically justifies acceptance or transfer, but the key is comparing the cost of remediation against the potential loss to determine the most appropriate risk response.

How to eliminate wrong answers

Option A is wrong because transferring risk via cyber insurance does not reduce the likelihood or impact of exploitation; it only provides financial compensation after a breach, and insurers often exclude critical vulnerabilities or require remediation as a condition. Option B is wrong because accepting a critical vulnerability with a CVSS of 9.8 and a $2,000,000 potential loss is irresponsible when a cheaper remediation option exists; acceptance is only appropriate when the cost of mitigation exceeds the potential loss. Option C is wrong because avoiding the risk by decommissioning the affected system would eliminate the business function entirely, incurring operational and revenue losses that likely exceed the $500,000 remediation cost, making it an extreme and unnecessary response.

97
MCQmedium

An organization is implementing a data classification scheme. Which data type should be given the highest protection and is typically restricted to a very small number of individuals?

A.Restricted
B.Confidential
C.Internal
D.Public
AnswerA

Restricted data demands the highest protection level, typically limited to a very small number of authorised individuals with strict need-to-know. It sits above confidential, internal and public classifications, matching the scenario's requirement for the most tightly controlled category.

Why this answer

Restricted data is the highest classification tier in most data classification schemes, reserved for the most sensitive information whose unauthorized disclosure would cause severe harm. Access is typically limited to a very small number of named individuals with explicit need-to-know and often additional controls like encryption, logging, and physical security. Examples include trade secrets, M&A plans, and certain regulated personal data.

Exam trap

CAS-005 often tests the ordering of classification tiers; candidates confuse Confidential with Restricted, not realizing Restricted is the top tier limited to a very small number of individuals.

How to eliminate wrong answers

Option B is wrong because Confidential is typically the second-highest tier, allowing broader access to employees with a business need, and does not require restriction to a very small number of individuals. Option C is wrong because Internal data is intended for general employee access within the organization and carries lower protection requirements. Option D is wrong because Public data is intentionally shareable with anyone and requires no special protection.

98
MCQhard

A financial services firm is designing a microsegmentation strategy for its VMware-based private cloud. The security team wants to enforce east-west policy based on workload identity rather than IP address, and it must survive IP address changes during automated redeployments. Which approach best satisfies these requirements?

A.Create VLANs per application tier and enforce inter-VLAN access control lists on the core switches.
B.Deploy a next-generation firewall between the data center core and aggregation layers and define zones by subnet.
C.Use 802.1Q trunking to isolate each application into a dedicated broadcast domain and apply private VLANs.
D.Install host-based firewall agents on each virtual machine and manage rules through a central console keyed to workload labels.
AnswerD

Host-based enforcement keyed to workload labels decouples policy from IP addresses and network topology. Because the agent travels with the workload, rules continue to apply correctly after automated redeployments change IP addresses, and policy can be expressed in terms of workload identity such as application tier or environment, satisfying both stated requirements.

Why this answer

Microsegmentation requires policy that follows the workload rather than the network. Host-based enforcement managed by workload labels keeps rules valid across IP changes caused by automated redeployments and allows east-west policy expressed in terms of identity. VLAN, private VLAN, and perimeter firewall approaches all bind policy to topology, which the scenario explicitly rules out.

Exam trap

The trap here is equating microsegmentation with VLAN or subnet zoning, when true microsegmentation enforces policy at the workload level using identity labels that persist across IP changes.

99
MCQhard

A company is conducting a vendor risk assessment and receives a SOC 2 Type II report from a cloud service provider. The report covers a 12-month period and includes an opinion on the effectiveness of controls. Which of the following is the primary benefit of using this report?

A.It guarantees the vendor is compliant with all regulations
B.It offers an independent assessment of control effectiveness over time
C.It eliminates the need for a right-to-audit clause
D.It provides real-time monitoring data from the vendor
AnswerB

A SOC 2 Type II report tests controls across a defined audit period rather than a single point in time, so the auditor's opinion addresses whether controls operated effectively throughout those 12 months. This satisfies the vendor risk assessment's need for evidence of sustained control performance.

Why this answer

A SOC 2 Type II report provides an independent auditor's opinion on the effectiveness of a service organization's controls over a period of time (here, 12 months). This temporal coverage is the key benefit: it demonstrates that controls operated effectively throughout the period, not just on a single date. For vendor risk assessment, this gives assurance about sustained control performance rather than a point-in-time snapshot.

Exam trap

The trap is overstating what SOC 2 provides — candidates pick A (guarantees compliance) or D (real-time monitoring) because they conflate attestation with certification or continuous monitoring, but SOC 2 is a periodic, independent opinion on control effectiveness.

How to eliminate wrong answers

Option A is wrong because SOC 2 does not guarantee regulatory compliance — it attests to the design and operating effectiveness of controls against the Trust Services Criteria, which may or may not map to specific regulations. Option C is wrong because a SOC 2 report does not eliminate the need for a right-to-audit clause; many organizations still require contractual audit rights for their own assurance. Option D is wrong because SOC 2 is a periodic attestation report, not a real-time monitoring feed — it covers a historical period and is issued after the fact.

100
MCQmedium

A software company suffers a breach exposing customer records. Legal counsel determines the incident meets the regulatory threshold for notification. The incident response lead must decide which external parties receive notice and within what timeframe, balancing regulatory duties against contractual obligations. Which action best satisfies the organization's notification obligations?

A.Notify regulators and affected data subjects within the applicable legal timeframes, and notify contractual partners per their agreements
B.Notify law enforcement and defer all other notifications until the criminal case concludes
C.Notify only the affected customers once the forensic investigation is fully complete
D.Publish a general notice on the corporate website in place of direct notification
AnswerA

Regulatory breach-notification regimes impose fixed deadlines measured from awareness, and contracts with partners often impose separate, sometimes tighter deadlines. Notifying regulators, affected individuals, and contractually entitled parties within each applicable window satisfies the full set of obligations. This parallel approach respects that different recipients have different triggers and timelines, which is exactly what the incident lead must coordinate.

Why this answer

Breach notification obligations run in parallel and on different clocks. Regulators and affected individuals must be notified within statutory windows measured from awareness, while contractual partners may have their own deadlines triggered by the same event. Notifying all required parties within their respective timeframes is the only approach that satisfies both legal and contractual duties, whereas waiting for investigation closure or substituting public notices fails those deadlines.

Exam trap

The trap here is believing that notification can wait until the forensic investigation is complete or the criminal case ends, when regulatory and contractual clocks start at awareness regardless of investigation status.

101
MCQmedium

When conducting a vendor risk assessment, which contractual clause is most important for ensuring ongoing visibility into the vendor's security posture?

A.Indemnification clause
B.Right-to-audit clause
C.Non-disclosure agreement (NDA)
D.Service level agreement (SLA)
AnswerB

A right-to-audit clause contractually grants the organisation the ability to inspect the vendor's controls, records and security practises on an ongoing basis. This directly satisfies the requirement for continuing visibility into the vendor's security posture, unlike one-off certifications or SLAs, which only report point-in-time or service-level assurances.

Why this answer

A right-to-audit clause contractually grants the customer the ability to inspect the vendor's security controls, processes, and records — either directly or via third-party reports like SOC 2. This is the mechanism that provides ongoing visibility into the vendor's security posture over the life of the relationship, not just at onboarding. Without it, the customer has no enforceable means to verify that controls remain effective.

Exam trap

CAS-005 often tests the confusion between clauses that compensate after an incident (indemnification, SLA credits) and clauses that provide proactive, ongoing visibility (right-to-audit).

How to eliminate wrong answers

Option A is wrong because an indemnification clause only addresses financial compensation after a loss occurs; it provides no visibility into controls and is reactive rather than preventive. Option C is wrong because an NDA protects confidentiality of shared information but says nothing about the vendor's internal security practices or the customer's ability to inspect them. Option D is wrong because an SLA defines performance and availability commitments (uptime, latency) and remedies for misses — it does not grant inspection rights into security controls or evidence.

102
Multi-Selectmedium

A security architect is designing a secure boot chain for an IoT device. Which THREE components are essential to ensure the integrity of the firmware update process? (Select THREE.)

Select 3 answers
A.Firmware update files signed with a private key
B.A mechanism to prevent firmware rollback to older versions
C.Encryption of firmware at rest on the device
D.Secure over-the-air (OTA) update delivery mechanism (e.g., TLS)
E.A hardware root of trust (e.g., read-only memory) storing the public key
AnswersA, D, E

Signed firmware images let the device verify authenticity and integrity before flashing, using the vendor’s public key to validate the private-key signature. This directly satisfies the stem’s requirement for a trustworthy update process, preventing tampered or malicious firmware from being installed on the IoT device.

Why this answer

Option A is correct because signing firmware update files with a private key lets the device verify authenticity and integrity using the corresponding public key, ensuring only authorized firmware is installed. Option D is correct because a secure OTA delivery mechanism such as TLS protects the update in transit against interception, tampering, and man-in-the-middle modification before it reaches the device. Option E is correct because a hardware root of trust, such as read-only memory storing the public key, provides an immutable anchor that validates the signature and boot chain, preventing attackers from substituting keys or firmware.

Option B is not essential to integrity itself; rollback prevention is an anti-downgrade control that addresses version freshness rather than cryptographic integrity. Option C is also not essential, since encryption of firmware at rest protects confidentiality, not the integrity of the update process.

Exam trap

CAS-005 often tests the difference between integrity and confidentiality controls — candidates select encryption at rest thinking it ensures firmware authenticity, when signing and root of trust are what actually provide integrity.

103
MCQmedium

A company is evaluating a vendor that will process sensitive customer data. The vendor's SOC 2 Type II report shows that controls were in place but had several exceptions noted. Which of the following is the BEST course of action?

A.Perform a risk assessment on the exceptions
B.Request a SOC 2 Type I report instead
C.Accept the vendor because it has a Type II report
D.Reject the vendor immediately due to exceptions
AnswerA

SOC 2 Type II exceptions indicate control failures during the audit period, so their impact on the specific data being processed must be evaluated. A risk assessment determines the severity, likelihood and appropriate mitigation or acceptance before contracting, rather than relying on the report alone.

Why this answer

A SOC 2 Type II report with exceptions indicates that controls were tested over a period and found to have gaps. The best course is to perform a risk assessment on the exceptions to evaluate their severity, impact on confidentiality, integrity, or availability of sensitive data, and determine if compensating controls or remediation plans are acceptable. This aligns with the risk management framework required for vendor due diligence under compliance standards like GDPR or PCI DSS.

Exam trap

CompTIA often tests the misconception that any exception in a SOC 2 report automatically disqualifies a vendor, when in fact the correct approach is to perform a risk assessment to determine the materiality and acceptability of the exceptions.

How to eliminate wrong answers

Option B is wrong because a SOC 2 Type I report only evaluates control design at a single point in time, which provides less assurance than a Type II report and does not address the operational effectiveness gaps indicated by the exceptions. Option C is wrong because accepting a vendor solely because it has a Type II report ignores the significance of the exceptions, which could represent material weaknesses in data protection controls. Option D is wrong because immediate rejection without analyzing the exceptions' risk level is an overreaction; some exceptions may be low-risk or have compensating controls, and a risk-based decision is required.

104
MCQhard

A company wants to protect its intellectual property stored on a file server. The security architect proposes implementing rights management services (RMS) integrated with Active Directory. Which attack is this architecture primarily designed to mitigate?

A.Unauthorized distribution of sensitive documents outside the organization
B.Phishing attacks targeting user credentials
C.Malware infection on the file server
D.Buffer overflow attack on the file server
AnswerA

Rights management encrypts documents and binds access permissions to Active Directory identities, so files remain protected even after leaving the network perimeter. This directly mitigates unauthorised distribution, since recipients outside the organisation cannot decrypt or open the protected intellectual property.

Why this answer

Rights Management Services (RMS) integrated with Active Directory enables persistent protection of documents by encrypting them and enforcing usage policies (e.g., who can open, print, or forward) regardless of where the file resides. This architecture is specifically designed to prevent unauthorized distribution of sensitive documents outside the organization because the protection travels with the file and requires authentication to an RMS server for decryption, even if the file is copied or emailed externally.

Exam trap

The trap here is that candidates may confuse data-at-rest protection (e.g., file server encryption) with data-in-use protection (RMS), leading them to incorrectly select malware or buffer overflow options, which are server-level threats rather than content-level distribution threats.

How to eliminate wrong answers

Option B is wrong because RMS does not protect against phishing attacks targeting user credentials; phishing is a social engineering threat that RMS cannot mitigate, as it focuses on document-level access control, not authentication security. Option C is wrong because RMS does not prevent malware infection on the file server; it protects the content of files after they are created, but the server itself remains vulnerable to malware without additional security controls like antivirus or endpoint detection. Option D is wrong because RMS does not address buffer overflow attacks on the file server; buffer overflows are software vulnerabilities that require patching, input validation, or memory protection, not document-level encryption and policy enforcement.

105
MCQhard

A security engineer is implementing a new endpoint detection and response (EDR) solution. The engineer wants to detect process injection techniques where malware writes to the memory of a remote process and then creates a remote thread to execute its payload. Which of the following Windows API call sequences should the EDR monitor to detect this behavior?

A.RegOpenKeyEx, RegSetValueEx, RegCloseKey
B.OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread
C.WSAStartup, socket, connect, send
D.CreateFile, ReadFile, WriteFile, CloseHandle
AnswerB

This sequence is the classic remote process injection pattern: OpenProcess obtains a handle to the target process, VirtualAllocEx allocates memory in its address space, WriteProcessMemory writes the payload, and CreateRemoteThread starts execution. Monitoring these API calls in sequence is a reliable indicator of remote thread injection, commonly used by malware to execute code in another process.

Why this answer

Remote process injection via CreateRemoteThread requires allocating memory in the target process (VirtualAllocEx), writing the payload (WriteProcessMemory), and then creating a thread to execute it (CreateRemoteThread). The OpenProcess call obtains the necessary handle. Monitoring this API sequence helps EDR solutions detect a common malware technique.

The other options describe file, registry, or network operations that are not related to process injection.

Exam trap

The trap here is confusing process injection with other malicious behaviors like file manipulation or registry persistence, which use entirely different API sets.

106
MCQhard

A security architect is designing a cross-domain solution that must move data between a classified network and an unclassified network. The requirement is to enforce a formally verified, non-bypassable policy that prevents any high-to-low leakage, while still permitting a controlled release of approved structured data. Which design element is MOST appropriate to satisfy this requirement?

A.A content-filtering proxy that performs deep packet inspection and blocks known malicious signatures
B.A stateful packet-filtering firewall with an explicit deny-all rule between the two enclaves
C.A data diode that permits only unidirectional physical-layer transmission from the unclassified to the classified network
D.A high-assurance cross-domain guard with a formally verified security kernel that filters and downgrades approved structured records
AnswerD

A high-assurance guard combines a formally verified security kernel with content filtering and a controlled release process, which is exactly what is needed to enforce a non-bypassable information-flow policy while permitting approved structured data to cross. The formal verification provides the assurance evidence that the policy cannot be bypassed, and the filtering performs the necessary sanitization.

Why this answer

Only a high-assurance cross-domain guard with a formally verified security kernel can enforce a non-bypassable information-flow policy and simultaneously release approved structured records. Firewalls and content-filtering proxies lack formal verification and structured-data transformation, and a data diode addresses flow direction rather than content policy. The guard is purpose-built for this multi-level release requirement.

Exam trap

The trap here is treating a data diode as a complete cross-domain solution, when it only enforces directionality and performs no content inspection or structured-record release.

107
MCQmedium

A security architect is designing a data classification scheme. Which of the following is the highest level of sensitivity that would typically require the most stringent controls?

A.Restricted
B.Public
C.Internal
D.Confidential
AnswerA

Restricted data demands the strictest controls because it covers information whose exposure causes severe harm, such as trade secrets or regulated personal data. It sits above Confidential, Internal and Public in the classification hierarchy, satisfying the stem's requirement for the highest sensitivity tier needing the most stringent protection.

Why this answer

In most data classification schemes, 'Restricted' represents the highest sensitivity level, reserved for data whose unauthorized disclosure would cause severe damage, such as trade secrets, regulated personal data, or national security information. It requires the most stringent controls, including strict access controls, encryption, and auditing. Public, Internal, and Confidential are lower tiers in the typical hierarchy.

Exam trap

CAS-005 often tests the ordering of classification tiers, tempting candidates to choose 'Confidential' as the highest when 'Restricted' is the top tier in schemes that include both.

How to eliminate wrong answers

Option B is wrong because 'Public' is the lowest classification, intended for information that can be freely shared without harm. Option C is wrong because 'Internal' is a mid-low tier for information meant only for employees, requiring basic controls but far less than Restricted. Option D is wrong because 'Confidential' is typically a high tier but usually sits below Restricted in schemes that include both; Restricted denotes the most severe impact from disclosure and thus the strictest controls.

108
MCQeasy

A network administrator needs to establish a secure VPN tunnel between two branch offices using IPsec. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode should be used?

A.AH mode
B.IKEv1
C.Tunnel mode
D.Transport mode
AnswerC

Tunnel mode encapsulates the complete original IP packet inside a new IP packet, encrypting payload and original header together. Transport mode encrypts only the payload and leaves the original header intact, so tunnel mode is required to meet the stated requirement of encrypting the entire packet.

Why this answer

Tunnel mode encrypts the entire IP packet and adds a new IP header, making it suitable for VPNs between networks.

109
Multi-Selecthard

A security architect is evaluating a new SIEM solution for a large enterprise. Which THREE of the following capabilities are CRITICAL for effective threat detection and response? (Choose three.)

Select 3 answers
A.Real-time correlation of events from multiple sources
B.Scheduled vulnerability scanning
C.Automated patch management
D.Integration with threat intelligence feeds
E.User and entity behavior analytics (UEBA)
AnswersA, D, E

Correlation is essential for identifying patterns and threats.

Why this answer

Real-time correlation of events from multiple sources is critical because it enables the SIEM to aggregate and analyze logs from diverse systems (firewalls, endpoints, servers) simultaneously, identifying complex attack patterns like lateral movement or multi-stage exploits that would be invisible in isolated logs. This capability directly supports timely detection and automated response, which is the core function of a SIEM in a large enterprise.

Exam trap

The trap here is that candidates confuse SIEM capabilities with adjacent security tools (vulnerability scanners, patch managers), forgetting that SIEMs are primarily for detection and correlation, not active remediation or scanning.

110
MCQhard

A financial services firm must allow third-party partners to call internal REST APIs. Partners authenticate with their own OAuth 2.0 authorization servers, and the firm must validate tokens without sharing secrets and enforce per-partner rate limits and scopes. Which approach BEST meets these requirements?

A.Terminate partner tokens at the gateway and reissue firm-issued session cookies for subsequent API calls.
B.Configure the API gateway to trust partner-issued JWTs by validating signatures against published JSON Web Key Sets and mapping claims to scopes and rate limits.
C.Require partners to connect through a dedicated VPN and authenticate with client certificates issued by the firm's internal certificate authority.
D.Issue each partner a shared symmetric key and validate HMAC-signed requests at the API gateway.
AnswerB

Validating partner-issued JWTs against their published JSON Web Key Sets lets the gateway verify authenticity using public keys, so no shared secret is exchanged. Claims such as issuer, audience, scope, and subject can then drive authorization decisions and per-partner throttling policies at the gateway.

Why this answer

Trusting externally issued tokens through published JSON Web Key Sets allows signature verification with public keys, eliminating secret sharing. Claim mapping at the gateway then enforces scopes and per-partner throttling, which is exactly the combination the scenario demands. Symmetric keys, VPN client certificates, and session reissuance each fail at least one stated requirement.

Exam trap

The trap here is treating network-level trust such as VPN or client certificates as equivalent to token-based authorization with scopes.

111
MCQhard

A healthcare provider must allow clinicians to access patient records from personal mobile devices while ensuring that data cannot be copied to unauthorized apps or stored locally. The organization wants to enforce this without managing the entire device. Which of the following should the security architect implement?

A.Virtual desktop infrastructure (VDI) with clipboard redirection disabled
B.Mobile threat defense (MTD) with behavioral anomaly detection
C.Mobile device management (MDM) with full device wipe capability
D.Mobile application management (MAM) with app-level encryption and containerization
AnswerD

MAM applies policy to specific apps rather than the whole device, allowing personal use while preventing data leakage. App-level encryption and containerization keep patient data within the managed app and block copy/paste or local storage to unauthorized apps. This matches the requirement to avoid full device management.

Why this answer

MAM with app-level encryption and containerization enforces data protection at the application layer, allowing personal device use while preventing patient data from being copied to unauthorized apps or stored locally. It avoids the privacy concerns of full device management and directly addresses the data leakage requirement.

Exam trap

The trap here is conflating mobile device management with mobile application management; MDM controls the whole device, while MAM controls only the app.

112
MCQeasy

A security analyst is reviewing firewall logs and notices a large number of outbound connections from an internal server to various external IP addresses on port 443. The connections are occurring at regular intervals and transferring small amounts of data. Which of the following is the MOST likely explanation for this activity?

A.The server is performing legitimate software updates from various vendors.
B.The server is using a peer-to-peer file-sharing application for legitimate business purposes.
C.The server is beaconing to a command-and-control (C2) server as part of a malware infection.
D.The server is experiencing a distributed denial-of-service (DDoS) attack from external sources.
AnswerC

Regular outbound connections to multiple external IPs on port 443 with small data transfers are characteristic of C2 beaconing. Malware often uses HTTPS to blend in with normal traffic. The periodic nature and multiple destinations suggest a compromised host attempting to communicate with its controller, possibly using domain generation algorithms (DGAs) or fast-flux.

Why this answer

The pattern of regular outbound connections to multiple external IPs on port 443 with small data transfers is a classic indicator of C2 beaconing. Malware often uses HTTPS to evade detection and communicates periodically to receive commands or exfiltrate small amounts of data. This behavior warrants further investigation, such as checking the server for malware and analyzing the destinations.

Exam trap

The trap here is assuming that any outbound HTTPS traffic is benign, when in fact attackers commonly use port 443 for C2 to blend in with normal web traffic.

113
Multi-Selectmedium

A security operations center (SOC) is implementing a new SIEM and wants to improve detection of credential-based attacks. The team plans to ingest Windows Security event logs and create correlation rules. Which TWO event IDs should the SOC prioritize to detect a brute-force attack against local accounts? (Choose two.)

Select 2 answers
A.4624 (An account was successfully logged on)
B.4672 (Special privileges assigned to new logon)
C.4625 (An account failed to log on)
D.4740 (A user account was locked out)
E.1102 (The audit log was cleared)
AnswersC, D

Event ID 4625 is generated whenever a logon attempt fails, such as due to a bad password or unknown username. A high volume of 4625 events from a single source or against a single account within a short time frame is a classic indicator of a brute-force or password-spraying attack. Monitoring and alerting on this event is essential for early detection of credential attacks against local accounts.

Why this answer

Brute-force attacks against local accounts are characterized by repeated failed logon attempts, which generate Event ID 4625. When the number of failures exceeds the account lockout threshold, Event ID 4740 is logged. Correlating these two events allows the SOC to detect both the ongoing attack and its impact.

Other events like successful logons or privilege assignments are not direct indicators of the attack itself, and log clearing is a post-compromise action.

Exam trap

The trap here is focusing on successful logon events or privilege events, which may indicate a compromise after the fact, rather than the failed logon and lockout events that directly reveal the brute-force attempt.

114
MCQmedium

An organization is implementing IPsec VPNs between sites. The security team wants to ensure data integrity and authentication but is less concerned about confidentiality for this particular link. Which IPsec protocol and mode should they use?

A.ESP in tunnel mode
B.AH in tunnel mode
C.AH in transport mode
D.ESP in transport mode
AnswerB

AH provides data integrity and origin authentication through its ICV, but performs no encryption, matching the stated indifference to confidentiality. Tunnel mode encapsulates the entire original IP packet, protecting traffic between the two site gateways rather than just host-to-host flows.

Why this answer

IPsec AH (Authentication Header) provides data integrity and authentication but not confidentiality (no encryption). Tunnel mode encapsulates the entire IP packet, which is suitable for site-to-site VPNs. Since confidentiality is not a concern, AH in tunnel mode is the correct choice.

ESP would provide confidentiality, which is unnecessary here.

Exam trap

CAS-005 often tests the difference between AH and ESP; candidates may choose ESP for integrity, but ESP without encryption is not standard, and AH is specifically for integrity without confidentiality.

How to eliminate wrong answers

Option A is wrong because ESP in tunnel mode provides confidentiality via encryption, which is not needed and adds overhead. Option C is wrong because AH in transport mode only protects the payload, not the entire packet, and is typically used for host-to-host communications, not site-to-site VPNs. Option D is wrong because ESP in transport mode provides confidentiality and is not suitable for site-to-site VPNs that require integrity without encryption.

115
MCQmedium

A global pharmaceutical company must comply with the EU GDPR for clinical trial data. The Data Protection Officer is reviewing the data protection impact assessment (DPIA) process. Which of the following situations requires a DPIA under GDPR?

A.Collecting employee emergency contact information for HR records.
B.Processing personal data for routine patient billing using a standard software platform.
C.Conducting a clinical trial that involves large-scale processing of genetic data and health data.
D.Using CCTV cameras in a single office lobby for physical security.
AnswerC

GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to data subjects, especially when using new technologies and processing special categories of data on a large scale. Clinical trials involving genetic and health data on a large scale clearly meet this threshold. Genetic data and health data are special categories under Article 9, and large-scale processing triggers the DPIA requirement.

Why this answer

A DPIA is mandatory under GDPR when processing is likely to result in a high risk to data subjects, particularly when it involves large-scale processing of special categories of data such as genetic and health data. Clinical trials often involve such data and are conducted on a large scale, making a DPIA a legal requirement. Other scenarios described are routine and low risk, so they do not trigger the mandatory DPIA.

Exam trap

The trap here is assuming that any processing of personal data requires a DPIA, when in fact it is only required for high-risk processing involving special categories at scale or systematic monitoring.

116
MCQmedium

A security analyst notices repeated failed login attempts from a single IP address across multiple user accounts. Which of the following is the BEST immediate action to mitigate this attack?

A.Disable the affected user accounts until the source IP is blocked.
B.Reset the passwords for all affected accounts.
C.Enable multi-factor authentication for all accounts.
D.Implement a rate-limiting rule on the network firewall for the source IP.
AnswerD

Rate-limiting the offending source IP on the network firewall throttles or blocks the repeated authentication attempts immediately, disrupting the brute-force pattern while legitimate traffic from other sources continues unaffected, and requires no account or application changes.

Why this answer

Rate-limiting the source IP at the network firewall immediately throttles the number of authentication attempts from that address, mitigating the brute-force attack without disrupting legitimate user access. This is the best immediate action as it directly blocks the attack vector at the network layer, preventing further failed logins while preserving user productivity.

Exam trap

The trap here is that candidates often confuse a long-term security control (like MFA or password resets) with an immediate mitigation technique, failing to recognize that rate-limiting the source IP is the fastest way to stop the ongoing brute-force attack at the network perimeter.

How to eliminate wrong answers

Option A is wrong because disabling affected user accounts would deny service to legitimate users and does not address the root cause—the attacking IP can still target other accounts. Option B is wrong because resetting passwords for all affected accounts is a reactive, time-consuming measure that does not stop the ongoing attack from the same IP; the attacker can simply continue with new attempts. Option C is wrong because enabling multi-factor authentication (MFA) is a strong security improvement but is not an immediate action—it requires user enrollment and configuration, and it does not stop the current burst of failed login attempts from the single IP.

117
MCQhard

A security engineer is analyzing a serverless application that uses AWS Lambda. Which of the following is the most critical security concern when the function processes external input?

A.The function may be vulnerable to injection attacks if input is not sanitized
B.The function has a timeout of 5 minutes
C.The function uses environment variables for configuration
D.The function does not use a custom runtime
AnswerA

Lambda functions that process external input pass untrusted data into downstream queries or commands, so unsanitised input enables injection attacks; this is the most critical concern because it can compromise data and execution context directly.

Why this answer

Injection attacks (e.g., SQL injection, command injection) are the most critical security concern for serverless functions processing external input because Lambda functions often interact with databases or execute commands. If input is not sanitized, attackers can execute arbitrary code or access data. This is a top OWASP risk and directly applies to any application handling untrusted input.

Exam trap

CAS-005 often tests the misconception that serverless functions are inherently secure because they are managed, leading candidates to overlook injection risks and pick configuration-related options.

How to eliminate wrong answers

Option B is wrong because a 5-minute timeout is a configuration limit, not a security vulnerability; it may affect performance but not security. Option C is wrong because using environment variables for configuration is a common best practice, though secrets should be encrypted; it is not the most critical concern. Option D is wrong because not using a custom runtime is not inherently insecure; AWS-provided runtimes are patched and secure.

118
MCQmedium

A security engineer is configuring a Linux server to enforce encrypted remote administration. The requirement is that after the initial key exchange, session keys must be rotated periodically to limit the impact of a compromised session key. Which OpenSSH configuration directive should the engineer use to achieve this?

A.Set Ciphers to aes256-ctr in the sshd_config file.
B.Set MACs to hmac-sha2-512 in the sshd_config file.
C.Set RekeyLimit to 1G 1h in the sshd_config file.
D.Set KexAlgorithms to diffie-hellman-group-exchange-sha256 in the sshd_config file.
AnswerC

RekeyLimit specifies the maximum amount of data and/or time before the session key is renegotiated. Setting it to 1G 1h forces a new key exchange after 1 gigabyte of data or one hour, whichever comes first, thereby rotating session keys and limiting exposure if a key is compromised. This directly satisfies the requirement.

Why this answer

The RekeyLimit directive in OpenSSH allows administrators to enforce periodic rekeying based on data volume, time, or both. By setting it to 1G 1h, the session key is refreshed after 1 gigabyte of data or one hour, whichever occurs first. This limits the amount of data encrypted under a single key, reducing the impact of a key compromise.

Other directives control cipher selection, key exchange algorithms, or integrity algorithms but do not manage key rotation.

Exam trap

The trap here is confusing cipher selection with key rotation, assuming that choosing a strong cipher automatically provides forward secrecy or periodic rekeying.

119
MCQeasy

A security engineer must select a cryptographic algorithm to ensure non-repudiation for digitally signed documents. Which algorithm is most appropriate?

A.RSA with SHA-256
B.HMAC-SHA256
C.AES-256 in GCM mode
D.Elliptic Curve Diffie-Hellman (ECDH)
AnswerA

RSA signatures with SHA-256 provide non-repudiation because only the holder of the private key can produce a signature that the corresponding public key verifies. This asymmetric property binds the signer to the document, unlike symmetric MACs where both parties share the secret.

Why this answer

RSA with SHA-256 (Option A) is the most appropriate choice because digital signatures rely on asymmetric cryptography. RSA provides the private key for signing and the public key for verification, ensuring that only the signer could have created the signature. SHA-256 provides a secure hash.

Together, they provide non-repudiation. In contrast, HMAC-SHA256 (Option B) uses a symmetric key, which does not provide non-repudiation because both parties share the key. AES-256 in GCM mode (Option C) is a symmetric encryption algorithm, not a signature algorithm.

Elliptic Curve Diffie-Hellman (ECDH) (Option D) is a key exchange protocol, not suitable for digital signatures.

120
MCQeasy

A security administrator is reviewing the configuration of a wireless network. The network uses WPA3-Enterprise with 802.1X authentication. The administrator wants to ensure that the authentication server validates the identity of the supplicant before granting network access. Which protocol should be used to encapsulate the authentication credentials?

A.EAP-MD5
B.EAP-TTLS
C.EAP-TLS
D.PEAP
AnswerC

EAP-TLS uses mutual certificate-based authentication, where both the supplicant and the authentication server present certificates. This ensures the server validates the supplicant's identity and vice versa, meeting the requirement. It is widely supported in WPA3-Enterprise and provides strong security without passwords, making it ideal for environments requiring robust mutual authentication.

Why this answer

EAP-TLS requires certificates on both the supplicant and the authentication server, enabling mutual authentication. This ensures the server validates the supplicant's identity before granting access. PEAP and EAP-TTLS typically authenticate only the server with a certificate, while EAP-MD5 lacks mutual authentication entirely.

Thus, EAP-TLS is the correct choice for strong mutual identity validation.

Exam trap

The trap here is confusing tunneled EAP methods like PEAP with true mutual certificate-based authentication.

121
MCQhard

A security architect is evaluating a hardware security module (HSM) deployment for a certificate authority. The requirement is that private keys must never leave the HSM in plaintext, and that key operations must be auditable. During a review, the architect learns that the HSM supports key wrapping for backup. Which of the following is the MOST important control to verify?

A.That the private keys are backed up to an encrypted network share using the HSM's built-in FTP client for offsite storage.
B.That the key wrapping key is stored in a separate, tamper-resistant HSM under a different administrator's control, and that wrapping operations are logged.
C.That the key wrapping key is stored in the same HSM and is itself exportable for disaster recovery.
D.That the HSM uses AES-128 in ECB mode for key wrapping to maximize performance during backup operations.
AnswerB

Separating the wrapping key into a distinct HSM under dual control enforces separation of duties and prevents a single compromised HSM from exposing backed-up keys. Logging wrapping operations provides the required auditability. This design ensures that even if the primary HSM is compromised, the attacker cannot unwrap exported blobs without also compromising the second HSM.

Why this answer

The strongest control is to separate the key wrapping key into an independent, tamper-resistant HSM under different administrative control and to log all wrapping operations. This enforces separation of duties and ensures that compromise of one HSM does not expose all backed-up private keys. Exportable wrapping keys, weak ciphers like ECB, or insecure transport channels all undermine the security of the backup process.

Exam trap

The trap here is focusing on encryption of the backup channel while overlooking that the wrapping key itself must be protected and separated from the keys it wraps.

122
MCQmedium

A security administrator is configuring a new VPN concentrator to support remote workers. The organization requires that all remote access use strong authentication and that the VPN concentrator validate the health of connecting devices before granting access. Which technology should the administrator implement?

A.VPN with IKEv2 and certificate-based authentication
B.802.1X with EAP-TLS
C.Network Access Control (NAC) with posture assessment
D.RADIUS with PAP
AnswerC

NAC with posture assessment checks the health of devices, such as ensuring antivirus is up-to-date and patches are installed, before allowing network access. When integrated with VPN, it can enforce health policies for remote workers. This directly meets the requirement for strong authentication and device health validation.

Why this answer

The requirement is for strong authentication and device health validation for remote VPN access. NAC with posture assessment provides exactly that by evaluating endpoint compliance before granting access. While IKEv2 with certificates offers strong authentication, it lacks health checks.

RADIUS with PAP is weak, and 802.1X is not typically used for VPN health validation.

Exam trap

The trap here is assuming that IKEv2 with certificate-based authentication alone satisfies the health validation requirement, when it only provides strong authentication.

123
Multi-Selecthard

During a business continuity planning meeting, the team identifies several critical systems. Which THREE of the following are key components of a Business Impact Analysis (BIA)? (Select THREE.)

Select 3 answers
A.Mission-essential functions
B.Inventory of all hardware assets
C.Threat modeling of likely attack vectors
D.Recovery Time Objective (RTO)
E.Recovery Point Objective (RPO)
AnswersA, D, E

BIA identifies which functions are critical to the mission.

Why this answer

A is correct because mission-essential functions are a core component of a Business Impact Analysis (BIA). The BIA identifies and prioritizes critical business processes and the resources required to support them, directly linking to mission-essential functions to determine the impact of their disruption. This ensures continuity planning focuses on the most vital operations first.

Exam trap

CompTIA CASP+ often tests the distinction between BIA components (which focus on impact and recovery targets) and risk assessment activities (like threat modeling or asset inventory), leading candidates to confuse the two domains.

124
MCQmedium

An organization is migrating sensitive customer data to a public cloud. Which of the following actions best demonstrates due diligence for compliance with GDPR?

A.Conducting a data protection impact assessment (DPIA).
B.Enabling server-side encryption on the cloud storage.
C.Obtaining explicit consent from all data subjects.
D.Signing a data processing agreement (DPA) with the cloud provider.
AnswerA

A DPIA directly satisfies GDPR Article 35, which mandates assessing high-risk processing before migrating sensitive customer data. It systematically identifies privacy risks, documents lawful basis and mitigation, and evidences accountability to supervisory authorities. This proactive, documented evaluation demonstrates due diligence more concretely than reactive or purely contractual measures.

Why this answer

A Data Protection Impact Assessment (DPIA) is a mandatory requirement under GDPR Article 35 for processing activities that are likely to result in high risk to individuals' rights and freedoms, such as migrating sensitive customer data to a public cloud. Conducting a DPIA demonstrates due diligence by systematically identifying, assessing, and mitigating privacy risks before the migration begins, ensuring compliance with GDPR's accountability principle.

Exam trap

CompTIA often tests the distinction between operational security controls (like encryption) or contractual safeguards (like DPAs) and the procedural due diligence required by GDPR, leading candidates to pick a technically valid but compliance-incomplete answer.

How to eliminate wrong answers

Option B is wrong because enabling server-side encryption on cloud storage addresses data security (confidentiality) but does not fulfill the GDPR requirement to assess and mitigate privacy risks specific to the processing activity; encryption is a technical safeguard, not a due diligence process for compliance. Option C is wrong because obtaining explicit consent from all data subjects is a lawful basis for processing under GDPR Article 7, but it does not replace the need for a DPIA when processing involves high-risk activities like cloud migration of sensitive data; consent alone does not demonstrate the systematic risk assessment required by Article 35. Option D is wrong because signing a Data Processing Agreement (DPA) with the cloud provider is a contractual obligation under GDPR Article 28 to ensure the processor's compliance, but it is a downstream step that assumes the processing is lawful; a DPA does not evaluate the inherent privacy risks of the migration itself, which is the core of due diligence.

125
MCQmedium

A security analyst needs to write a script that detects changes to critical files across a fleet of Linux servers. Which approach is most efficient and secure?

A.Use a cron job on each server running a Python script that checks file hashes.
B.Enable Linux auditd on each server and forward logs to a SIEM for analysis.
C.Deploy a centralized log server and parse syslog for file modifications.
D.Use an agentless tool like OSSEC with a central manager to report file integrity changes.
AnswerD

OSSEC provides centralized, efficient monitoring.

Why this answer

OSSEC is a host-based intrusion detection system (HIDS) specifically designed for file integrity monitoring (FIM). Its agentless mode uses SSH to connect to remote servers, retrieve file hashes, and compare them against a known baseline stored on a central manager. This approach is both efficient (centralized reporting, no per-server cron jobs) and secure (encrypted communication, tamper-proof baseline storage).

Exam trap

CompTIA CASP+ often tests the distinction between event logging (auditd/syslog) and cryptographic integrity verification (FIM tools like OSSEC), leading candidates to choose a logging-based solution that cannot detect subtle content changes like a rootkit replacing a binary with the same size and timestamp.

How to eliminate wrong answers

Option A is wrong because running a Python script via cron on each server is inefficient (no centralized management, each server must be individually configured and maintained) and insecure (the script and its hash database are locally stored and could be tampered with if the server is compromised). Option B is wrong because Linux auditd is designed for system call auditing (e.g., tracking who accessed a file), not for efficient file integrity monitoring; it generates high-volume logs that require heavy SIEM parsing and lacks built-in baseline comparison or alerting for hash changes. Option C is wrong because parsing syslog for file modifications is unreliable (syslog is a text-based, non-tamper-proof protocol, often sent over UDP) and does not provide cryptographic hash verification; it would only detect open/write events, not actual content changes, and is easily evaded.

126
MCQmedium

An organization uses a hardware security module (HSM) to protect cryptographic keys. Which aspect of key management does an HSM primarily address?

A.Key rotation
B.Key escrow
C.Secure key storage and cryptographic operations
D.Digital certificate issuance
AnswerC

An HSM is tamper-resistant hardware that generates, stores and uses cryptographic keys internally, so keys never exist in plaintext outside the module. This directly addresses secure key storage and cryptographic operations, unlike software keystores where keys reside in memory or on disk.

Why this answer

An HSM (Hardware Security Module) is a tamper-resistant physical device whose primary purpose is to securely generate, store, and use cryptographic keys without ever exposing them in plaintext outside the device boundary. It performs cryptographic operations (signing, encryption, key derivation) internally, so keys never leave the protected hardware. This directly addresses secure key storage and cryptographic operations.

Exam trap

The trap is conflating HSM capabilities with broader key-management lifecycle functions (rotation, escrow, issuance) — candidates must recognize that the HSM's core value is protecting keys and performing crypto, not managing policy.

How to eliminate wrong answers

Option A is wrong because key rotation is a policy/process activity that can be performed by a KMS or key management application; the HSM only stores and protects the keys, it does not decide when to rotate them. Option B is wrong because key escrow is a governance practice of storing key copies with a trusted third party for recovery — an HSM can hold escrowed keys but escrow itself is not what an HSM primarily addresses. Option D is wrong because digital certificate issuance is a PKI/CA function; an HSM may sign certificates, but issuing certificates is not its primary key-management role.

127
MCQmedium

During a risk assessment, the analyst identifies that a legacy system containing sensitive data cannot be patched due to vendor end-of-life. The system is critical to operations. Which risk treatment strategy is MOST appropriate?

A.Transfer by purchasing cyber insurance
B.Avoidance by decommissioning the system
C.Acceptance by documenting the risk
D.Mitigation by implementing compensating controls
AnswerD

Compensating controls reduce risk without patching, satisfying the end-of-life constraint. Because the vendor no longer supplies fixes, mitigation through network segmentation, strict access control or virtual patching limits exploitability while the critical system continues operating.

Why this answer

When a legacy system cannot be patched due to vendor end-of-life, the most appropriate risk treatment is to implement compensating controls (e.g., network segmentation, strict access controls, host-based intrusion detection) to reduce the likelihood or impact of exploitation. This allows the organization to continue critical operations while managing the residual risk, as avoidance or transfer would be impractical or insufficient.

Exam trap

CompTIA often tests the misconception that 'acceptance' is the default for legacy systems, but the trap here is that acceptance without compensating controls is only appropriate when the risk is formally accepted by management and the system does not contain sensitive data; for sensitive data, compensating controls are required to reduce risk to an acceptable level.

How to eliminate wrong answers

Option A is wrong because purchasing cyber insurance transfers financial risk but does not reduce the technical vulnerability or prevent a breach; the system remains exploitable. Option B is wrong because decommissioning the system (avoidance) would halt critical operations, which is not acceptable when the system is essential to business continuity. Option C is wrong because acceptance without any compensating controls would leave the sensitive data exposed to exploitation, which is typically not acceptable for systems containing sensitive data unless the risk is explicitly deemed low and documented with formal approval.

128
Multi-Selectmedium

A security governance team is drafting a new data handling standard for a research subsidiary that processes both regulated personal data and proprietary intellectual property. The team must select controls that directly support data classification and labeling objectives. Which two of the following controls best fulfill this requirement? (Choose two.)

Select 2 answers
A.Automated sensitive-data discovery that tags files with the appropriate classification label at creation
B.Role-based access control applied to the subsidiary's file shares
C.Mandatory classification labels embedded in document templates and enforced by data loss prevention policies
D.A quarterly review of firewall rule sets against the approved network baseline
E.Annual security awareness training that mentions the existence of the data classification policy
AnswersA, C

Automated discovery that assigns classification labels at the point of creation enforces the labeling objective at the earliest possible moment and removes reliance on users to remember the scheme. It directly operationalizes the classification standard by ensuring every artifact carries its sensitivity marking, which downstream controls such as encryption and access rules can then act upon consistently.

Why this answer

Controls that directly support classification and labeling must either identify and mark data according to its sensitivity or enforce handling based on those markings. Automated discovery that tags data at creation and template-embedded labels enforced through data loss prevention both do this. Firewall reviews, awareness training, and role-based access control address network hygiene, human behavior, and authorization respectively, but none of them classify or label information assets.

Exam trap

The trap here is selecting training or access control because they feel foundational to data protection, when the question specifically asks for controls that perform classification and labeling rather than consume or support them indirectly.

129
MCQmedium

A security engineer must ensure that log data collected from production servers cannot be altered or deleted by an attacker who gains administrative access to those servers. The logs must remain verifiable for audit purposes. Which of the following designs BEST achieves this?

A.Configure log rotation with a short retention window and compress older files to save space.
B.Encrypt log files at rest on each server using a key stored in the server's local keystore.
C.Forward logs in real time to a centralized server that uses append-only storage and cryptographic hash chaining.
D.Store logs locally on each server with strict file permissions and enable file integrity monitoring.
AnswerC

Real-time forwarding removes logs from the source host before an attacker can tamper with them, and append-only storage with hash chaining makes any later modification detectable because each entry's hash depends on the previous one. An attacker with server administrative rights cannot rewrite records already transmitted to the hardened collector. This directly provides tamper evidence and verifiability.

Why this answer

Sending logs off-host in real time and storing them on a separate system with append-only writes and hash chaining ensures that a compromised server cannot retroactively change the audit record. The chained hashes let auditors detect any insertion, deletion, or modification, so the logs remain trustworthy even if the source host is fully compromised.

Exam trap

The trap here is relying on local file permissions or encryption on the source host, when an attacker with administrative rights on that host controls the keys and the files.

130
MCQmedium

A security analyst is reviewing metrics for the security program. Which metric best measures the effectiveness of incident response processes?

A.Mean time to detect (MTTD)
B.Patch compliance percentage
C.Mean time to respond (MTTR)
D.Number of vulnerabilities by severity
AnswerC

MTTR directly quantifies how quickly the team contains and resolves incidents, making it the clearest indicator of response-process effectiveness. It captures elapsed time from detection to resolution, exposing bottlenecks in triage, escalation and containment that other metrics, such as incident counts, cannot reveal.

Why this answer

Mean time to respond (MTTR) measures the average time taken to respond to and resolve incidents, directly reflecting the efficiency of incident response processes. A lower MTTR indicates a more effective and timely response, making it the best metric to assess incident response effectiveness.

Exam trap

CAS-005 often tests the difference between detection and response metrics; candidates may confuse MTTD with MTTR, but MTTD is about detection, while MTTR is about response and resolution.

How to eliminate wrong answers

Option A is wrong because MTTD measures how quickly incidents are detected, not how effectively they are responded to. Option B is wrong because patch compliance percentage measures vulnerability management, not incident response. Option D is wrong because the number of vulnerabilities by severity measures the volume of vulnerabilities, not the response process.

131
MCQmedium

A security architect is designing a network segmentation strategy for a multi-tenant cloud environment. Which of the following is the MOST effective technique to isolate tenant workloads while maintaining manageability?

A.Host-based iptables
B.Stateful firewall rules
C.Virtual private clouds (VPCs) with separate subnets
D.VLAN tagging
AnswerC

VPCs provide network-level isolation between tenants, while separate subnets within each VPC segment workloads by tier or function. Security groups and network ACLs then enforce traffic rules, delivering strong tenant separation without the operational overhead of per-tenant accounts or dedicated hardware.

Why this answer

Virtual private clouds (VPCs) with separate subnets provide native, tenant-level isolation in a multi-tenant cloud environment by creating logically isolated network segments with their own IP address space, routing tables, and security policies. This approach is the most effective because it scales easily, integrates with cloud-native security controls (e.g., security groups, network ACLs), and maintains manageability through centralized orchestration without requiring per-tenant hardware or complex overlay configurations.

Exam trap

The trap here is that candidates confuse VLAN tagging (a legacy on-premises technique) with cloud-native VPCs, failing to recognize that VLANs cannot provide the scale, automation, or multi-region isolation required in a modern multi-tenant cloud environment.

How to eliminate wrong answers

Option A is wrong because host-based iptables operate at the individual VM/container level, requiring per-instance rule management that does not scale for multi-tenant isolation and lacks centralized control. Option B is wrong because stateful firewall rules, while useful for traffic inspection, are a security control applied at a network boundary and do not inherently create separate tenant network segments; they cannot prevent layer-2 or layer-3 visibility between tenants without underlying segmentation. Option D is wrong because VLAN tagging (IEEE 802.1Q) provides layer-2 segmentation but is limited to a single broadcast domain, does not extend across cloud regions or availability zones, and introduces management overhead (STP, VLAN trunking) that conflicts with cloud elasticity and multi-tenant scalability.

132
MCQmedium

A company uses a CI/CD pipeline with Jenkins to build and deploy containerized applications. Security scanning of container images is currently done manually after deployment, causing delays. Which of the following would be the most effective automation to improve security and efficiency?

A.Add a stage to the Jenkins pipeline that runs container image scanning using Trivy before pushing to the registry.
B.Schedule a weekly cron job to scan the container registry and generate reports.
C.Use Terraform to enforce that only images from a trusted registry are deployed.
D.Require developers to scan images locally using a Dockerfile HEALTHCHECK instruction.
AnswerA

Trivy scanning as a pre-push Jenkins stage shifts detection left, failing the build before vulnerable images reach the registry. This satisfies the stem's automation and delay constraints, replacing manual post-deployment scanning with a gate that blocks flawed artefacts early.

Why this answer

Integrating container image scanning into the CI/CD pipeline ensures vulnerabilities are detected before deployment, reducing delays and improving security. Option A is correct because adding a stage in Jenkins to run Trivy scans before pushing images to the registry catches issues early. Option B is incorrect because weekly scans after deployment do not prevent vulnerable images from being deployed.

Option C is incorrect because Terraform can enforce registry trust but does not scan for vulnerabilities within the image. Option D is incorrect because relying on developers for local scans is inconsistent and not automated.

133
MCQeasy

A security engineer needs to implement a solution that provides both confidentiality and integrity for data at rest. Which cryptographic method BEST meets these requirements?

A.AES-256-GCM
B.SHA-256
C.Diffie-Hellman
D.RSA-2048
AnswerA

AES-256-GCM provides confidentiality through symmetric encryption and integrity via its built-in GHASH authentication tag, detecting tampering without a separate MAC. This single-pass AEAD construction satisfies the stem's dual requirement for data at rest, unlike plain AES-CBC, which encrypts but leaves integrity unverified.

Why this answer

AES-256-GCM is correct because it provides both confidentiality (via AES encryption) and integrity (via Galois/Counter Mode authentication tag). GCM is an authenticated encryption mode that ensures data at rest remains both secret and tamper-proof, meeting the dual requirement directly.

Exam trap

Candidates often confuse integrity-only tools like SHA-256 or key exchange protocols like Diffie-Hellman with solutions that provide both confidentiality and integrity, overlooking that GCM is an authenticated encryption mode specifically designed for this dual purpose.

How to eliminate wrong answers

Option B (SHA-256) is wrong because it is a cryptographic hash function that provides only integrity verification (via message digest), not confidentiality; it cannot encrypt data. Option C (Diffie-Hellman) is wrong because it is a key exchange protocol used for establishing shared secrets over an insecure channel, not for encrypting data at rest. Option D (RSA-2048) is wrong because it is an asymmetric encryption algorithm primarily used for key exchange or digital signatures, not for bulk data encryption at rest; it lacks built-in integrity verification and is computationally inefficient for large data.

134
MCQeasy

A company is evaluating its disaster recovery plan. Which metric indicates the maximum acceptable downtime?

A.Mean Time to Repair (MTTR)
B.Recovery Point Objective (RPO)
C.Recovery Time Objective (RTO)
D.Mean Time Between Failures (MTBF)
AnswerC

Recovery Time Objective (RTO) defines the maximum tolerable duration of service interruption after a disruption, directly answering the downtime constraint in the stem. Unlike Recovery Point Objective, which measures acceptable data loss in time, RTO targets restoration speed, making it the metric that specifies how long an outage may last before unacceptable impact occurs.

Why this answer

Recovery Time Objective (RTO) defines the maximum acceptable downtime after a disruption — the target time within which systems must be restored to avoid unacceptable business impact. It is the metric that directly answers 'how long can we be down?' and drives DR architecture decisions like warm standby versus hot standby. RTO is paired with RPO, which defines acceptable data loss.

Exam trap

CAS-005 often tests the RTO/RPO distinction, and candidates confuse RPO (data loss tolerance) with RTO (downtime tolerance) — the trap is reading 'downtime' and picking RPO because both are recovery metrics.

How to eliminate wrong answers

Option A is wrong because Mean Time to Repair (MTTR) is a reliability metric measuring the average time to fix a failed component — it is a historical average, not a business-defined maximum acceptable downtime target. Option B is wrong because Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time (e.g., 'we can lose up to 15 minutes of transactions'), not downtime duration. Option D is wrong because Mean Time Between Failures (MTBF) measures average time between component failures — it is a reliability/availability metric, not a recovery target.

135
MCQeasy

A company is deploying a wireless network for guests. Which security measure is most important to prevent unauthorized users from accessing internal resources?

A.Use WPA2-Enterprise with 802.1X
B.Disable SSID broadcast
C.Implement MAC address filtering
D.Place the guest network on a separate VLAN with no access to internal subnets
AnswerD

A separate VLAN isolates guest traffic at layer 2, so guest devices cannot route to internal subnets without an explicit gateway or ACL permitting it. This directly satisfies the requirement to prevent unauthorised users reaching internal resources, unlike encryption or captive portals, which authenticate guests but do not segment them.

Why this answer

Placing the guest network on a separate VLAN with no access to internal subnets provides network segmentation, which is the most effective security measure to prevent unauthorized users from reaching internal resources. This approach uses VLAN tagging (802.1Q) and access control lists (ACLs) to enforce Layer 2 and Layer 3 isolation, ensuring that guest traffic cannot traverse to internal networks even if other wireless security measures are bypassed.

Exam trap

The trap here is that candidates often focus on wireless authentication or obscurity measures (like WPA2-Enterprise or disabling SSID broadcast) instead of recognizing that network segmentation is the fundamental control for isolating guest traffic from internal resources.

How to eliminate wrong answers

Option A is wrong because WPA2-Enterprise with 802.1X is an authentication mechanism that controls who can connect to the wireless network, but it does not inherently prevent authenticated guests from accessing internal resources; it only secures the wireless link. Option B is wrong because disabling SSID broadcast is a weak security-by-obscurity measure that can be easily defeated by passive scanning tools (e.g., airodump-ng), and it does not restrict access to internal subnets once a client connects. Option C is wrong because MAC address filtering is easily spoofed using tools like macchanger, and it provides no protection against an attacker who captures a valid MAC address from the airwaves, nor does it segment traffic from internal resources.

136
MCQeasy

A company's risk assessment identifies that employees often use weak passwords. Which control directly addresses this risk?

A.Conduct security awareness training
B.Deploy single sign-on
C.Implement multi-factor authentication
D.Enforce a strong password policy
AnswerD

Weak passwords stem from user behaviour, so a preventive administrative control is needed. Enforcing a strong password policy sets complexity, length and expiry requirements at authentication, directly removing the weak-credential risk rather than detecting it afterwards.

Why this answer

Enforcing a strong password policy directly addresses the risk of weak passwords by mandating complexity, length, and expiration requirements (e.g., minimum 12 characters, mixed case, numbers, symbols). This control reduces the likelihood of successful brute-force or dictionary attacks by increasing the entropy of user credentials. Unlike other options, it specifically targets the root cause—weak password creation—rather than adding compensating controls.

Exam trap

The trap here is that candidates confuse 'addressing the risk' with 'mitigating the impact'—MFA (Option C) reduces the impact of a weak password but does not prevent the weak password itself, which is the root cause identified in the risk assessment.

How to eliminate wrong answers

Option A is wrong because security awareness training educates users but does not technically enforce password strength; users may still choose weak passwords despite training. Option B is wrong because single sign-on (SSO) centralizes authentication but does not prevent users from creating weak passwords for the SSO identity provider or downstream systems. Option C is wrong because multi-factor authentication (MFA) adds a second factor (e.g., TOTP, SMS) but does not address the weakness of the first factor (password); a weak password can still be guessed or cracked offline, bypassing MFA in some attack scenarios (e.g., pass-the-cookie).

137
MCQmedium

A global retailer is deploying a microsegmentation strategy in its data center to limit lateral movement after a breach. The security architect must enforce policy based on workload identity and allow only required east-west flows, even when workloads are migrated between hosts. Which of the following should be implemented?

A.VLAN segmentation with ACLs applied on the core switches.
B.A next-generation firewall (NGFW) deployed at the data center perimeter.
C.802.1X port-based network access control on all switch ports.
D.Host-based firewalls with workload identity labels and a central policy controller.
AnswerD

Host-based firewalls with identity labels enforce policy at the workload level regardless of host or IP changes, and a central controller distributes consistent rules. This allows only required east-west flows and follows workloads across migrations, directly satisfying the microsegmentation requirement in a dynamic data center.

Why this answer

Host-based firewalls with identity labels and a central policy controller enforce microsegmentation based on workload identity rather than IP addresses. This design allows only necessary east-west flows and automatically follows workloads during migration, which is essential in a dynamic data center where lateral movement must be contained.

Exam trap

The trap here is assuming that network-layer segmentation such as VLANs or perimeter firewalls provides microsegmentation, when only identity-based host enforcement can follow workloads and control east-west flows.

138
MCQhard

A security engineer is configuring a wireless network for a hospital. The network must support legacy medical devices that only support WPA2-Personal with pre-shared keys (PSK) and cannot be upgraded. The hospital also wants to prevent unauthorized devices from connecting and to detect rogue access points. Which of the following should the engineer implement to BEST meet these requirements?

A.WPA2-Enterprise with 802.1X authentication and a RADIUS server.
B.Open network with a captive portal and MAC address filtering.
C.WPA3-Enterprise with 192-bit mode and a RADIUS server.
D.WPA2-Personal with a strong, unique PSK and a wireless intrusion prevention system (WIPS).
AnswerD

WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.

Why this answer

WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.

Exam trap

The trap here is assuming that the most secure option (WPA3-Enterprise) is always best, but compatibility with legacy devices is a hard constraint that must be respected.

139
MCQeasy

A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?

A.Incorporating privacy controls during the initial system architecture
B.Encrypting data at rest only
C.Performing an annual privacy audit
D.Providing privacy training to employees
AnswerA

Embedding privacy controls at the initial system architecture stage satisfies privacy by design, which requires data protection to be built into systems from the outset rather than bolted on after deployment. Retrofitting later cannot match this preventative, architecture-level alignment.

Why this answer

Privacy by design, codified in GDPR Article 25 and the ISO/IEC 27550 framework, requires that privacy protections be embedded into systems and processes from the outset rather than bolted on afterward. Incorporating privacy controls during initial system architecture — data minimization, purpose limitation, access controls, retention policies — is the textbook embodiment of this principle. The other options are reactive or partial measures that do not satisfy the 'by design' requirement.

Exam trap

CAS-005 often tests the misconception that any privacy-related control (encryption, audits, training) satisfies 'privacy by design', when the principle specifically requires proactive architectural integration before the system is built.

How to eliminate wrong answers

Option B is wrong because encrypting data at rest is a single technical control, not a design philosophy — it addresses confidentiality but ignores minimization, purpose limitation, and lifecycle governance. Option C is wrong because an annual privacy audit is a detective, after-the-fact control, whereas privacy by design is preventive and proactive. Option D is wrong because employee training addresses human behavior and awareness, not the architectural embedding of privacy controls into systems and data flows.

140
MCQmedium

A security operations center (SOC) has deployed a SOAR platform to automate phishing response. An analyst wants to ensure that when a phishing email is reported, the platform automatically extracts all URLs from the email body and headers, submits them to a threat intelligence service, and then quarantines the email if any URL is malicious. Which SOAR component should the analyst configure to define this sequence of actions?

A.Playbook
B.Case management system
C.Orchestration engine
D.Runbook
AnswerA

A playbook is a predefined, automated workflow that executes a series of actions based on triggers and conditions. Here, the trigger is a reported phishing email, and the actions include URL extraction, threat intelligence lookup, and conditional quarantine. This directly matches the requirement to define a sequence of automated actions.

Why this answer

The requirement is to define an automated sequence of actions triggered by a phishing report. A playbook in SOAR is exactly this: a workflow that can include conditional logic, integrations with threat intelligence, and actions like quarantine. The other components either support execution, document procedures, or track cases but do not define the automation logic.

Exam trap

The trap here is confusing the orchestration engine (which executes workflows) with the playbook (which defines the workflow logic).

141
MCQeasy

A security analyst observes anomalous outbound network traffic from a server that normally only performs internal functions. According to the incident response plan, what should the analyst do first?

A.Follow the incident response plan
B.Contain the server by disconnecting it from the network
C.Immediately shut down the server
D.Ignore the traffic as it might be a false positive
AnswerA

The incident response plan defines the agreed sequence of actions for exactly this anomaly, so following it first ensures containment, evidence handling and escalation occur consistently. Deviating risks destroying forensic data or breaching organisational procedure before the plan's steps are applied.

Why this answer

The incident response plan defines the authorized sequence of actions for handling a suspected incident, including triage, escalation, and containment criteria. Following the plan first ensures the analyst acts within policy and preserves evidence rather than making unilateral decisions. Containment, shutdown, or dismissal are all steps that the plan itself dictates when and how to perform.

Exam trap

CAS-005 often tests the instinct to 'act fast' by containing or shutting down a system, but the exam expects candidates to recognize that the documented incident response plan governs the sequence of actions — jumping to containment is a classic wrong answer.

How to eliminate wrong answers

Option B is wrong because containment is a later phase that should only be executed when the plan or an incident commander authorizes it; prematurely disconnecting the server can destroy volatile evidence and disrupt business services. Option C is wrong because shutting down the server wipes memory-resident artifacts (running processes, network connections, encryption keys) and is a destructive action that violates evidence preservation. Option D is wrong because ignoring anomalous traffic without investigation defeats the purpose of monitoring and could allow an active compromise to persist.

142
MCQeasy

A security administrator is configuring a firewall to allow only encrypted remote administration traffic to a server. The administrator wants to use a protocol that provides confidentiality and integrity for the management session. Which of the following should be used?

A.HTTP over port 8080
B.SSH
C.Telnet
D.SNMPv3 without privacy
AnswerB

SSH provides strong encryption, integrity, and authentication for remote administration. It protects the session against eavesdropping and tampering. It is the standard protocol for secure command-line management. Using SSH meets the requirement for confidentiality and integrity of the management session.

Why this answer

SSH is designed for secure remote administration, providing encryption and integrity. Telnet and HTTP are plaintext, and SNMPv3 without privacy lacks encryption. Only SSH meets the requirement for encrypted management traffic.

Exam trap

The trap here is thinking that changing the port number (e.g., HTTP on 8080) provides security; it does not add encryption.

143
MCQeasy

A security analyst is reviewing threat intelligence feeds and notices indicators from a known APT group. Which threat intelligence sharing standard is most commonly used to structure and share such cyber threat information in a machine-readable format?

A.CybOX
B.MITRE ATT&CK
C.STIX/TAXII
D.OpenIOC
AnswerC

STIX provides a structured, machine-readable schema for describing indicators, threat actors and relationships, while TAXII defines the transport protocol for exchanging that content between servers and clients. Together they satisfy the stem's requirement for a standardised, automated format for sharing APT indicators, unlike document-centric or proprietary feed formats.

Why this answer

STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Intelligence Information) are the standard protocols for sharing cyber threat intelligence in a structured, machine-readable format. STIX defines the data model, and TAXII defines the transport mechanism.

144
Multi-Selectmedium

A security architect is evaluating cryptographic agility for a system that must be resistant to quantum computing attacks. Which TWO algorithms are part of the NIST PQC standards? (Select TWO.)

Select 2 answers
A.RSA-4096
B.CRYSTALS-Dilithium
C.AES-256
D.SHA-256
E.CRYSTALS-Kyber
AnswersB, E

CRYSTALS-Dilithium is a lattice-based digital signature scheme selected by NIST for post-quantum cryptography standardisation, providing quantum-resistant authentication. It satisfies the stem's requirement for cryptographic agility against quantum attacks, unlike RSA or ECDSA, whose security collapses under Shor's algorithm. Its selection as a NIST PQC standard confirms its suitability.

Why this answer

CRYSTALS-Dilithium (option B) is correct because NIST selected it in July 2022 as a post-quantum digital signature algorithm, standardized in FIPS 204 (ML-DSA), designed to resist quantum attacks via lattice-based cryptography. CRYSTALS-Kyber (option E) is also correct because NIST selected it as the post-quantum key-encapsulation mechanism (KEM), standardized in FIPS 203 (ML-KEM), also based on module-lattice hardness. RSA-4096 (option A) is not a PQC algorithm; its security relies on integer factorization, which Shor's algorithm on a quantum computer can break.

AES-256 (option C) is a symmetric cipher, not a NIST PQC standard, though it retains quantum resistance via Grover only reducing effective strength to 128 bits. SHA-256 (option D) is a hash function, not a PQC algorithm, and is likewise not part of the NIST PQC standardization selections.

Exam trap

CAS-005 often tests whether candidates can distinguish between NIST PQC asymmetric algorithms and classical symmetric/hash algorithms; a common mistake is selecting AES or SHA as PQC standards because they are quantum-resistant.

145
MCQmedium

A cloud security engineer is designing an architecture where workloads in a virtual private cloud must reach an on-premises database over a site-to-site VPN. The requirement is that only the database subnet can be reached, no other on-premises networks, and traffic must be encrypted in transit. Which design BEST satisfies this?

A.Deploy a transit gateway and attach every on-premises VPC to it with full route propagation
B.Use VPC peering between the workload VPC and the on-premises database VPC
C.Create an internet gateway and allow the workload subnet to reach the database's public IP over TLS
D.Configure a customer gateway and virtual private gateway with a static route limited to the database subnet CIDR
AnswerD

A site-to-site VPN with a customer gateway on-premises and a virtual private gateway in the cloud encrypts traffic via IPsec, and advertising only the database subnet CIDR in the static route confines reachable destinations to that network. This meets both the encryption requirement and the least-privilege routing constraint without exposing other on-premises ranges.

Why this answer

A site-to-site IPsec VPN between a customer gateway and a virtual private gateway encrypts traffic, and constraining the static route to the database subnet CIDR enforces least-privilege reachability. Transit gateway full propagation, VPC peering, and public-IP exposure either broaden access or fail to provide an encrypted private path to the on-premises database.

Exam trap

The trap here is treating any encrypted connection, such as TLS to a public endpoint, as equivalent to a scoped private VPN path.

146
MCQeasy

Which of the following is the PRIMARY purpose of a business continuity plan (BCP)?

A.Assign roles for incident response.
B.Restore IT systems after a disaster.
C.Ensure critical business functions continue during a disruption.
D.Establish procedures for data backup.
AnswerC

A BCP focuses on maintaining the delivery of critical business functions at acceptable levels during and after a disruption. It prioritises operational resilience of essential processes, distinguishing it from disaster recovery, which restores IT infrastructure, and from incident response, which contains the immediate threat.

Why this answer

The primary purpose of a Business Continuity Plan (BCP) is to ensure that critical business functions can continue during and after a disruption, such as a natural disaster, cyberattack, or infrastructure failure. Unlike a Disaster Recovery Plan (DRP), which focuses on restoring IT systems and data, the BCP takes a broader organizational view, covering people, processes, facilities, and third-party dependencies to maintain minimum acceptable service levels. This aligns with the governance and compliance domain, where the BCP is a strategic document that addresses operational resilience rather than just technical recovery.

Exam trap

A common trap is confusing the BCP (broader organizational continuity) with the DRP (IT system restoration), leading candidates to incorrectly select the DRP-related option.

How to eliminate wrong answers

Option A is wrong because assigning roles for incident response is a function of the Incident Response Plan (IRP), not the BCP; the BCP focuses on continuity of operations, not the specific tactical steps of handling a security incident. Option B is wrong because restoring IT systems after a disaster is the primary purpose of a Disaster Recovery Plan (DRP), which is a subset of the BCP; the BCP itself addresses broader business processes, including manual workarounds and alternate facilities, not just IT restoration. Option D is wrong because establishing procedures for data backup is a specific technical control that supports both the BCP and DRP, but it is not the primary purpose of the BCP; the BCP's goal is to ensure continuity of critical functions, which may involve data backups but also includes many other non-IT elements.

147
MCQhard

A company deploys a microservices architecture using container orchestration. The security team wants to enforce mutual TLS between services. Which technology should be used?

A.Service mesh
B.SSH tunneling
C.API gateway
D.VPN
AnswerA

A service mesh injects sidecar proxies that terminate and originate mTLS on behalf of each workload, issuing and rotating certificates automatically. This enforces mutual TLS between services without modifying application code, which container orchestration alone does not provide.

Why this answer

A service mesh (e.g., Istio, Linkerd) is the correct technology because it provides a dedicated infrastructure layer for handling service-to-service communication, including automatic mutual TLS (mTLS) enforcement between microservices. It injects sidecar proxies that intercept all traffic and negotiate mTLS using X.509 certificates, ensuring both encryption and authentication without modifying application code.

Exam trap

The trap here is that candidates often confuse an API gateway's ability to terminate TLS for external traffic with the need for mTLS between internal services, leading them to incorrectly select API gateway instead of service mesh.

How to eliminate wrong answers

Option B (SSH tunneling) is wrong because SSH tunnels are designed for point-to-point encrypted connections between hosts, not for dynamic, policy-driven mTLS between many microservices in a container orchestration environment; they lack certificate-based identity and automatic rotation. Option C (API gateway) is wrong because an API gateway handles north-south traffic (external clients to services) and can terminate TLS, but it does not enforce mTLS for east-west traffic between internal microservices. Option D (VPN) is wrong because a VPN creates an encrypted network tunnel between networks or hosts, but it does not provide per-service identity or mutual authentication at the application layer; it secures the network path, not the service-to-service communication.

148
Multi-Selectmedium

Which THREE of the following are common challenges when implementing a vendor risk management program? (Select THREE)

Select 3 answers
A.Lack of visibility into vendor security practices
B.Over-automation of risk scoring
C.Resource constraints for conducting assessments
D.Inconsistent assessment criteria across vendors
E.Excessive cooperation from vendors
AnswersA, C, D

Common challenge

Why this answer

A is correct because organizations often lack visibility into vendor security practices, meaning they cannot verify whether vendors comply with security policies or contractual obligations. This challenge arises when vendors do not provide access to their security controls, audit reports, or real-time monitoring data, leaving gaps in the risk assessment process.

Exam trap

The CAS-004 exam often tests the distinction between common operational challenges (like lack of visibility, resource constraints, and inconsistent criteria) versus hypothetical or reversed issues (like over-automation or excessive cooperation) that are not typical in vendor risk management programs.

149
MCQeasy

A security architect is designing a web application that handles sensitive customer data. The application must ensure that if one server is compromised, the attacker cannot access the private keys used for TLS termination. Which of the following approaches best meets this requirement?

A.Store the private keys in an encrypted database on a separate database server.
B.Use a software-based key vault that runs on the same operating system as the web server.
C.Use a hardware security module (HSM) to generate and store the private keys, performing TLS termination on the HSM.
D.Store the private keys in a local file with restricted permissions on the application server.
AnswerC

HSM provides tamper-resistant storage and performs cryptographic operations without exposing keys.

Why this answer

A Hardware Security Module (HSM) provides a dedicated, tamper-resistant cryptographic processor that generates, stores, and manages private keys in hardware, never exposing them to the application server's memory or filesystem. By performing TLS termination directly on the HSM, the private keys remain isolated even if the web server is compromised, meeting the requirement for key confidentiality.

Exam trap

The trap here is that candidates often assume encrypting keys at rest (Option A) or using OS-level permissions (Option D) is sufficient, but the CAS-004 exam emphasizes that any software-based storage, even if encrypted, still exposes the key during runtime operations like TLS termination.

How to eliminate wrong answers

Option A is wrong because storing private keys in an encrypted database on a separate server still exposes the keys to the application server during decryption (the keys must be loaded into memory to terminate TLS), and a compromised server could extract them from memory or intercept the decryption process. Option B is wrong because a software-based key vault running on the same OS as the web server shares the same attack surface; if the OS is compromised, the vault's memory and files can be accessed, allowing key extraction. Option D is wrong because storing private keys in a local file with restricted permissions relies solely on OS-level access controls, which are bypassed if the attacker gains root or equivalent privileges on the compromised server.

150
MCQhard

Which automation security concept coordinates the deployment, scaling, and management of containers?

A.Immutable infrastructure
B.Infrastructure as Code
C.Secret management
D.Container orchestration
AnswerD

Container orchestration platforms schedule containers across hosts, scale replicas up or down, and manage lifecycle and networking automatically. This coordination of deployment, scaling and management is precisely the automation security concept the question describes, distinguishing it from image scanning or secrets management.

Why this answer

Container orchestration is the automation security concept that specifically handles the deployment, scaling, and management of containers. Tools like Kubernetes, Docker Swarm, and Amazon ECS coordinate container lifecycles, including scheduling, health monitoring, and scaling. While other options are related to automation and security, only container orchestration directly addresses the operational coordination of containers at scale.

Exam trap

The trap here is confusing related automation concepts: candidates might select Infrastructure as Code because it also involves automation and deployment, but IaC is about provisioning infrastructure, not coordinating containers. Similarly, immutable infrastructure is a principle, not a coordination tool.

Why the other options are wrong

A

Matched to correct description

B

Matched to correct description

C

Matched to correct description

Page 1

Page 2 of 13

Page 3