Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 151–225

973 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
Multi-Selectmedium

A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)

Select 2 answers
A.Remote attestation to verify boot measurements
B.Platform Configuration Registers (PCRs) for storing measurements
C.UEFI secure boot enforcement
D.Sealed storage to protect encryption keys
E.Generation of RSA keys for code signing
AnswersA, B

Remote attestation lets the TPM sign a quote over selected PCR values, allowing a remote verifier to confirm the boot chain matched expected measurements. This satisfies the integrity-verification requirement by detecting tampering with firmware or boot components before trust is granted.

Why this answer

Option A (Remote attestation to verify boot measurements) is correct because TPM 2.0 can produce a signed quote of PCR values that a remote verifier uses to attest that the boot chain matches expected measurements, directly ensuring boot-process integrity. Option B (Platform Configuration Registers (PCRs) for storing measurements) is correct because TPM 2.0 PCRs hold the cumulative hashes of boot components (firmware, bootloader, OS) that form the basis of measured boot and are the values attested in option A. Option C is not a TPM capability; UEFI Secure Boot enforcement is performed by UEFI firmware using signature databases (db, dbx, KEK, PK), though the TPM may record its state.

Option D, sealed storage, protects encryption keys by binding them to PCR values, but it is a data-protection feature rather than a direct boot-integrity capability. Option E, RSA key generation for code signing, is a general cryptographic function and not specifically tied to ensuring boot-process integrity.

152
MCQmedium

A financial services firm runs its customer portal on a Kubernetes cluster in AWS. During a penetration test, an attacker who compromised a front-end pod moved laterally to a database pod by directly connecting to its IP address, even though no NetworkPolicy existed. The security architect must implement a control that enforces least-privilege communication between pods and blocks all unauthorized east-west traffic by default. Which of the following should the architect implement?

A.Enable AWS Security Groups for the worker nodes and restrict inbound rules to the node CIDR block.
B.Deploy a service mesh sidecar proxy and enforce mutual TLS between all services.
C.Apply egress-only internet gateway rules to prevent pods from reaching external networks.
D.Configure a Kubernetes NetworkPolicy with a default-deny ingress rule and explicit allow rules for required pod-to-pod flows.
AnswerD

NetworkPolicy is the native Kubernetes mechanism to enforce pod-level segmentation. A default-deny ingress policy blocks all traffic not explicitly allowed, satisfying least privilege and stopping lateral movement. Explicit allow rules then permit only the required database access from the front end. This directly addresses the scenario's requirement to block unauthorized east-west traffic without adding external components.

Why this answer

The requirement is to enforce least-privilege pod-to-pod communication and block unauthorized east-west traffic by default. Kubernetes NetworkPolicy is the native control that operates at the pod level and can implement a default-deny posture with explicit allow rules. Node-level Security Groups and egress gateways do not provide pod-level segmentation, and mTLS without authorization policy does not deny connections.

Exam trap

The trap here is assuming that encrypting service traffic with mutual TLS automatically prevents lateral movement, when authorization policy is what actually denies unauthorized connections.

153
MCQhard

A security operations team has deployed a deception platform consisting of several Windows and Linux honeypots on a dedicated VLAN. After two weeks, the team notices the honeypots generate a high volume of connection attempts originating from internal vulnerability scanners, asset discovery tools, and backup agents, drowning out any genuine adversary activity. Which of the following is the BEST course of action to preserve the fidelity of the deception environment?

A.Place the honeypots behind a firewall rule that permits only traffic from external IP address ranges.
B.Decommission the honeypots and replace them with host-based intrusion detection agents installed on production servers.
C.Move the honeypots to the same VLAN as production servers so that legitimate administrative traffic blends in with adversary activity.
D.Tune the deception platform to suppress alerts for known scanner, discovery, and backup agent signatures and source addresses, while forwarding all other honeypot interactions to the SIEM.
AnswerD

Deception fidelity depends on distinguishing authorized tooling from adversary behavior. By fingerprinting the deterministic traffic patterns and source addresses of sanctioned scanners and backup agents and suppressing only those events, the team removes expected noise without blinding the environment to novel or anomalous connections. All other honeypot interactions remain high-signal indicators worth forwarding to the SIEM for correlation and triage.

Why this answer

Deception environments lose value when benign, authorized traffic overwhelms the alerts they produce. The practical fix is to baseline and suppress the deterministic signatures and source addresses of sanctioned tools such as vulnerability scanners, asset discovery engines, and backup agents, while continuing to forward every other honeypot interaction to the SIEM. This preserves the honeypot's high-fidelity detection role without discarding it or exposing production networks.

Exam trap

The trap here is treating honeypot noise as a reason to abandon or isolate the deception layer, rather than tuning suppression for known benign sources while keeping the environment live.

154
MCQmedium

During an incident response, the team identifies that an attacker gained initial access via a phishing email containing a malicious macro. The macro downloaded a payload from a remote server. Which phase of the incident response lifecycle is currently being executed when the team identifies the phishing email as the attack vector?

A.Containment, eradication, and recovery
B.Preparation
C.Lessons learned
D.Detection and analysis
AnswerD

Identifying the phishing email as the initial access vector is analysis of collected evidence to determine how the intrusion occurred, which falls within detection and analysis. This phase scopes the incident and informs later containment and eradication decisions.

Why this answer

Detection and analysis is the phase where the IR team identifies and validates the incident, determines its scope, and identifies the attack vector (e.g., phishing email with malicious macro). Identifying the phishing email as the initial access vector is a classic detection-and-analysis activity, occurring before containment or eradication.

Exam trap

The trap is assuming that identifying the attack vector is part of containment or eradication — but vector identification is squarely in Detection and Analysis, before any containment actions begin.

How to eliminate wrong answers

Option A is wrong because containment, eradication, and recovery happen after the incident is detected and analyzed — the team is still identifying the vector, not yet containing it. Option B is wrong because preparation is the pre-incident phase (building playbooks, tools, training), not the phase where an active incident's vector is identified. Option C is wrong because lessons learned occurs after recovery, when the team documents what happened and improves processes.

155
MCQeasy

An organization wants to implement a hardware security module (HSM) to protect cryptographic keys. Which of the following is a primary benefit of using an HSM?

A.Faster key generation than software
B.Reduced network latency for encryption
C.Automatic cloud backup of keys
D.Tamper-resistant key storage
AnswerD

An HSM physically protects keys within a tamper-resistant boundary that zeroises them if intrusion is detected, so keys never exist in plaintext on the host. This directly satisfies the requirement to protect cryptographic keys, unlike software keystores that rely solely on file permissions.

Why this answer

An HSM provides tamper-resistant key storage by using physical and logical safeguards, such as tamper switches, epoxy potting, and zeroization circuits, that destroy cryptographic keys if an attacker attempts to access the hardware. This ensures that private keys remain secure even if the device is compromised, which is a primary requirement for compliance with standards like FIPS 140-2 Level 3 or 4. Software-based storage cannot offer the same level of physical protection against extraction attacks.

Exam trap

The trap here is that candidates confuse the security benefit of tamper-resistant storage with performance improvements like faster key generation or reduced latency, which are not primary HSM advantages and are often worse than software alternatives.

How to eliminate wrong answers

Option A is wrong because HSMs typically have slower key generation than optimized software implementations due to hardware constraints and the overhead of tamper-proofing mechanisms; software can leverage CPU cryptographic instructions (e.g., AES-NI) for faster generation. Option B is wrong because an HSM does not reduce network latency for encryption; it may actually increase latency due to the need for network communication to the HSM (e.g., via PKCS#11 or KMIP) compared to local software encryption. Option C is wrong because automatic cloud backup of keys is not a built-in HSM feature; cloud backup would require additional configuration and introduces security risks that HSMs are designed to mitigate, and many compliance frameworks prohibit exporting keys from an HSM.

156
MCQhard

A financial services firm is designing a hybrid identity architecture. Employees authenticate on-premises to Active Directory Domain Services, while applications are hosted in multiple SaaS and IaaS providers. The security architect must ensure that a compromised on-premises domain controller cannot be used to forge tokens that grant access to cloud applications, and that cloud access decisions reflect real-time on-premises risk signals. Which of the following BEST achieves these goals?

A.Implement a cloud-based identity provider with conditional access that ingests on-premises risk telemetry through a secure API and uses short-lived tokens.
B.Use password hash synchronization with seamless single sign-on and enforce smart card authentication for all on-premises users.
C.Extend Active Directory Domain Services to the cloud using domain controllers deployed in IaaS virtual networks and replicate credentials.
D.Federate on-premises Active Directory Federation Services with each cloud provider using SAML or OIDC, and require MFA at the federation layer.
AnswerA

A cloud identity provider with conditional access evaluates real-time signals such as device compliance and on-premises risk before issuing short-lived tokens. Because token issuance happens in the cloud and does not trust on-premises domain controllers to sign tokens, a compromised domain controller cannot forge cloud access, satisfying both requirements.

Why this answer

A cloud identity provider that uses conditional access and consumes on-premises risk telemetry issues short-lived tokens based on real-time evaluation, so cloud trust does not depend on on-premises token-signing keys. This prevents a compromised domain controller from forging cloud tokens while allowing risk signals to influence access decisions across SaaS and IaaS applications.

Exam trap

The trap here is equating identity federation or directory extension with protection from token forgery, when only moving token issuance to a cloud identity provider that evaluates real-time risk removes trust in on-premises signing keys.

157
Multi-Selecteasy

Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)

Select 2 answers
A.Reduces the attack surface by hiding network resources
B.Automates patch management
C.Eliminates the need for encryption
D.Provides identity-based access control
E.Simplifies network architecture by removing firewalls
AnswersA, D

SDP uses a deny-by-default model with single-packet authorisation, keeping resources invisible to unauthenticated users. Attackers cannot scan or target what they cannot see, so the exploitable attack surface shrinks — the specific benefit the zero trust scenario requires.

Why this answer

Option A is correct because SDP uses a "black cloud" or dark network approach where resources are cloaked and do not respond to unauthenticated probes, so attackers cannot see or scan them, directly shrinking the attack surface. Option D is correct because SDP enforces access decisions based on verified user and device identity (often via mutual TLS, SAML, or OIDC with a controller and gateway), which is the core identity-centric principle of zero trust. Option B is wrong because patch management is a vulnerability/patch lifecycle function, not a benefit of SDP.

Option C is wrong because SDP actually depends on strong encryption such as mTLS and IPsec/TLS tunnels rather than eliminating it. Option E is wrong because SDP complements rather than removes firewalls, and it typically adds controller/gateway components instead of simplifying the architecture by deleting firewalls.

Exam trap

The trap is selecting 'eliminates the need for encryption' or 'removes firewalls' because SDP sounds like a replacement for traditional perimeter security — in reality SDP depends on encryption and coexists with firewalls.

158
MCQmedium

A multinational corporation is migrating its data centers to a hybrid cloud model. The security team must ensure that data sovereignty laws are respected. The company operates in the EU, US, and Asia. Which of the following is the BEST approach?

A.Require all employees to sign a data processing agreement.
B.Encrypt all data at rest and in transit using a single global encryption key.
C.Implement a virtual private network between all data centers and cloud providers.
D.Use cloud regions in each geographic area where data is stored and processed.
AnswerD

Regional cloud deployments keep data stored and processed inside each jurisdiction, so EU, US and Asian data remain subject to their own sovereignty laws. This satisfies the legal constraint without relying on contractual or encryption-based transfers.

Why this answer

Using cloud regions in each geographic area ensures data remains within the jurisdiction where it was collected, directly complying with data sovereignty laws such as the EU's GDPR, US state laws, and Asia-Pacific regulations. This approach leverages the cloud provider's regional boundaries to enforce legal data residency without relying on technical controls that can be circumvented or misconfigured.

Exam trap

The trap here is that candidates often confuse data sovereignty with data security, assuming encryption or VPNs (Options B and C) satisfy legal residency requirements, when in fact they only protect data in transit or at rest without controlling where the data physically resides.

How to eliminate wrong answers

Option A is wrong because a data processing agreement (DPA) is a contractual document that defines roles and responsibilities under regulations like GDPR, but it does not enforce technical data residency or prevent data from being stored or processed in unauthorized jurisdictions. Option B is wrong because using a single global encryption key for all data at rest and in transit violates data sovereignty by failing to segregate encryption management per region; it also introduces a single point of compromise and does not address where the data is physically stored. Option C is wrong because a VPN between data centers and cloud providers secures the communication channel but does not control or restrict the geographic location of the cloud resources or data storage, so data can still be processed in a non-compliant region.

159
MCQeasy

A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $50,000 and an exposure factor (EF) of 0.2. The annualized rate of occurrence (ARO) is estimated at 4. What is the ALE?

A.$10,000
B.$40,000
C.$50,000
D.$200,000
AnswerB

Multiplying asset value by exposure factor gives the single-loss expectancy: $50,000 × 0.2 = $10,000. Annualising by the ARO of 4 yields $40,000, satisfying the stem's requirement to compute ALE from AV, EF and ARO. The $40,000 figure therefore matches the correct calculation.

Why this answer

The ALE is calculated as SLE × ARO, where SLE (Single Loss Expectancy) = Asset Value × Exposure Factor. Here, SLE = $50,000 × 0.2 = $10,000, and ARO = 4, so ALE = $10,000 × 4 = $40,000. This represents the expected annual monetary loss from the risk.

Exam trap

CAS-005 often tests the confusion between SLE and ALE; candidates stop at AV × EF and forget to multiply by ARO, or they skip the EF and multiply AV × ARO instead.

How to eliminate wrong answers

Option A is wrong because $10,000 is the SLE (single loss expectancy), not the annualized figure; it omits multiplication by the ARO. Option C is wrong because $50,000 is the raw asset value and does not account for the exposure factor or occurrence rate. Option D is wrong because $200,000 would result from multiplying asset value by ARO without applying the exposure factor, which overstates the loss.

160
MCQeasy

An organization wants to ensure that its employees understand their responsibilities regarding data protection. Which of the following is the MOST effective way to achieve this?

A.Include a clause in the employment contract
B.Post posters in common areas
C.Distribute a data protection policy annually via email
D.Conduct regular security awareness training with assessments
AnswerD

Regular security awareness training with assessments repeatedly educates employees on data protection duties and verifies comprehension through testing, directly building the understanding the organisation requires. One-off communications or policy documents alone cannot confirm that responsibilities are understood.

Why this answer

The most effective because it combines regular, recurring training with assessments that verify comprehension, ensuring employees actively engage with data protection responsibilities rather than passively receiving information. This aligns with the continuous improvement cycle required by frameworks like NIST SP 800-50 and GDPR Article 39, which mandate ongoing awareness programs and demonstrable understanding. Assessments provide measurable evidence of employee competence, which is critical for compliance audits and reducing human-error-related breaches.

Exam trap

CompTIA often tests the distinction between passive information dissemination (posters, emails, contract clauses) and active, verifiable training programs, trapping candidates who think any form of communication is sufficient for ensuring employee understanding.

How to eliminate wrong answers

Option A is wrong because an employment contract clause is a one-time legal agreement that does not ensure ongoing understanding or retention of data protection responsibilities; employees may never read or recall it after signing. Option B is wrong because posters in common areas are passive, static communications that lack interactivity, assessment, and reinforcement, making them ineffective for changing behavior or verifying comprehension. Option C is wrong because distributing a policy annually via email is a one-way, infrequent communication that does not require active engagement or confirmation of understanding, and employees often ignore or delete such emails without reading them.

161
Multi-Selectmedium

A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?

Select 2 answers
A.Service mesh with mutual TLS
B.Intrusion detection system (IDS) on the gateway
C.Micro-segmentation of virtual networks
D.Web application firewall (WAF)
E.Network access control lists (ACLs) at the perimeter
AnswersA, C

Mutual TLS in a service mesh authenticates and encrypts every service-to-service call, giving cryptographic workload identity rather than relying on network location. This directly protects east-west traffic inside the cluster, where perimeter controls cannot inspect lateral microservice communication.

Why this answer

Option A (Service mesh with mutual TLS) is correct because a service mesh provides identity-based, encrypted, and authenticated communication between microservices, and mutual TLS ensures both sides of an east-west connection verify each other's certificates, preventing spoofing and eavesdropping inside the cluster. Option C (Micro-segmentation of virtual networks) is correct because it enforces least-privilege reachability between workloads by applying granular policies at the virtual network or workload level, which directly limits lateral movement if a microservice is compromised. Option B is not the best fit because an IDS on the gateway monitors north-south traffic entering the environment rather than internal service-to-service flows, and it is detective rather than preventive.

Option D is not appropriate because a WAF protects HTTP/HTTPS applications from external web attacks at the edge, not east-west microservice traffic. Option E is not appropriate because perimeter ACLs filter traffic at the network boundary and do not provide the identity-aware, workload-level controls needed for internal microservice communication.

Exam trap

CAS-005 often tests the distinction between north-south and east-west controls; candidates frequently select perimeter tools like WAF or gateway IDS, which do not address internal microservice traffic.

162
MCQeasy

A security analyst is investigating a malware sample found on a workstation. The analyst wants to determine the malware's capabilities without executing it. Which type of malware analysis involves examining the binary's strings, headers, and structure?

A.Static analysis
B.Dynamic analysis
C.Reverse engineering
D.Memory forensics
AnswerA

Static analysis examines the binary's strings, headers and structure without running it, directly satisfying the stem's constraint of determining capabilities without execution. Dynamic or behavioural analysis would require detonating the sample in a sandbox, which the analyst explicitly wants to avoid.

Why this answer

Static analysis involves examining the malware binary without executing it, focusing on its structure, strings, headers, and other static properties. This allows the analyst to extract indicators like embedded URLs, IP addresses, and function calls without risking infection or triggering malicious behavior.

Exam trap

The trap here is confusing static analysis with reverse engineering; while reverse engineering is a subset of static analysis, the question specifically asks about examining strings and headers, which is classic static analysis.

How to eliminate wrong answers

Option B is wrong because dynamic analysis requires executing the malware in a controlled environment to observe its behavior, which contradicts the requirement to avoid execution. Option C is wrong because reverse engineering involves disassembling or decompiling the binary to understand its logic, which is a deeper form of static analysis but not the primary term for examining strings and headers. Option D is wrong because memory forensics analyzes volatile memory (RAM) from a running system, not a static binary file.

163
Multi-Selectmedium

A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)

Select 2 answers
A.Penetration testing results
B.Employee background checks
C.List of all open-source components and their versions
D.Network flow logs
E.Dependency analysis to identify known vulnerabilities
AnswersC, E

An SBOM must enumerate every open-source library and its exact version, because version data is what lets you map components to advisories and licences. Without this inventory, the supply chain constraint of knowing what ships inside your software cannot be met.

Why this answer

Option C is correct because an SBOM's core purpose is to enumerate every software component — including open-source libraries and their exact versions — so that downstream consumers can identify what is inside a product and trace provenance. Option E is correct because SBOMs enable dependency analysis, allowing organizations to correlate listed components and versions against vulnerability databases (e.g., NVD/CVE feeds) to detect known vulnerabilities in the supply chain. Together, these two form the essential SBOM strategy: knowing what components exist and analyzing their dependencies for risk.

Option A (penetration testing results) is a point-in-time security assessment, not a component inventory, so it is not an SBOM element. Option B (employee background checks) is a personnel security control unrelated to software composition. Option D (network flow logs) captures runtime traffic metadata, not the software components or dependencies that an SBOM documents.

Exam trap

CAS-005 often tests the distinction between SBOM as a component inventory plus dependency/vulnerability analysis versus generic security activities (pentesting, background checks, flow logs) that sound security-related but have nothing to do with software composition.

164
MCQmedium

A multinational financial services firm must comply with the General Data Protection Regulation (GDPR). The Chief Information Security Officer (CISO) asks the security team to implement a mechanism that allows data subjects to request and receive a copy of their personal data in a structured, commonly used, and machine-readable format. Which of the following technical controls BEST addresses this requirement?

A.Implement an API endpoint that allows authenticated data subjects to download their personal data in JSON or CSV format.
B.Establish a records retention policy that automatically deletes personal data after a defined period.
C.Deploy a data loss prevention (DLP) solution to monitor and block unauthorized exfiltration of personal data.
D.Configure database encryption at rest using Transparent Data Encryption (TDE) to protect personal data.
AnswerA

The GDPR right to data portability requires that data subjects can receive their personal data in a structured, commonly used, and machine-readable format. An API endpoint that returns data in JSON or CSV satisfies this requirement and provides a scalable, automated way to fulfill data subject requests. This is the most direct technical control for the requirement.

Why this answer

The GDPR grants data subjects the right to data portability, which requires organizations to provide personal data in a structured, commonly used, and machine-readable format. An API endpoint that allows authenticated users to download their data in JSON or CSV directly satisfies this requirement. Other controls like DLP, encryption, or retention policies address different GDPR obligations and do not enable data subject access requests.

Exam trap

The trap here is confusing data protection controls, such as encryption or DLP, with data subject rights fulfillment mechanisms like portability APIs.

165
Multi-Selectmedium

Which TWO of the following are key components of a risk assessment methodology?

Select 2 answers
A.Disaster recovery.
B.Threat identification.
C.Risk appetite.
D.Incident response.
E.Asset inventory.
AnswersB, E

Threat identification enumerates the threat sources and events capable of exploiting vulnerabilities, forming the basis for estimating likelihood. It satisfies the methodology's requirement to establish what could cause harm before assessing impact and risk levels.

Why this answer

Threat identification (B) is a core component of risk assessment because risk is derived from threats acting on vulnerabilities, so the methodology must enumerate and characterize relevant threat sources (e.g., natural, human, environmental) before likelihood and impact can be estimated. Asset inventory (E) is equally essential, since risk assessment requires knowing which assets (hardware, software, data, personnel, facilities) have value and therefore what could be harmed, enabling proper scoping and impact analysis. Together, asset inventory and threat identification feed the standard risk calculation (Risk = Threat × Vulnerability × Impact) used in frameworks such as NIST SP 800-30 and ISO/IEC 27005.

Disaster recovery (A) is a reactive continuity capability, not a risk assessment input, and it is addressed after risks are evaluated. Risk appetite (C) is a governance decision about acceptable risk levels that guides treatment, not a component of the assessment itself. Incident response (D) is an operational capability for detecting and handling security events, which likewise falls outside the assessment methodology.

Exam trap

CompTIA CASP+ often tests the distinction between proactive risk assessment components (threat identification, asset inventory) and reactive operational processes (disaster recovery, incident response), expecting candidates to recognize that risk appetite is a governance policy input, not a step in the methodology.

166
MCQhard

A security architect is designing a network segmentation strategy for a critical industrial control system (ICS) environment. The architect must ensure that unauthorized devices cannot communicate with the ICS network even if they gain physical access to a network port. The architect decides to implement IEEE 802.1X with MAC Authentication Bypass (MAB) as a fallback. Which of the following is the MOST significant security weakness introduced by enabling MAB?

A.MAB transmits credentials in clear text, allowing an attacker to capture them and authenticate to the network.
B.MAB disables the use of RADIUS, forcing authentication to occur locally on the switch and reducing centralized control.
C.MAB allows any device to authenticate by spoofing a known MAC address, bypassing 802.1X authentication controls.
D.MAB requires the use of digital certificates on all endpoints, increasing administrative overhead and complexity.
AnswerC

MAB authenticates devices based on their MAC address, which is easily spoofable. An attacker with physical port access can configure a device with a permitted MAC address and gain network access without valid 802.1X credentials. This directly undermines the requirement that unauthorized devices cannot communicate, making MAB a significant weakness in this scenario.

Why this answer

MAB authenticates devices by their MAC address, which is not a secret and can be easily spoofed. In an ICS environment where physical port access might be possible, an attacker could clone a permitted MAC address and bypass 802.1X controls. This defeats the goal of preventing unauthorized devices from communicating.

Certificate-based methods or strict port security would be more robust, but MAB as a fallback introduces this spoofing vulnerability.

Exam trap

The trap here is focusing on encryption of credentials, when MAB's real weakness is that the MAC address itself is a trustable but easily forged identifier.

167
Multi-Selectmedium

Which THREE of the following are common vulnerabilities found in web applications according to the OWASP Top 10 2021? (Select THREE.)

Select 3 answers
A.Cryptographic Failures
B.Broken Access Control
C.Server-Side Request Forgery (SSRF)
D.SQL Injection
E.Remote Code Execution (RCE) via buffer overflow
AnswersA, B, C

Cryptographic Failures ranks second in the OWASP Top 10 2021, covering exposure of sensitive data through weak encryption, poor key management or plaintext transmission. It satisfies the stem's requirement for a genuine 2021 category, having replaced the earlier Sensitive Data Exposure entry.

Why this answer

The OWASP Top 10 2021 explicitly lists A. Cryptographic Failures (A02:2021) as a top web application risk, covering failures related to protecting data in transit and at rest, such as missing TLS, weak ciphers, or improper key management. B.

Broken Access Control is ranked A01:2021, the most critical category, encompassing flaws like missing authorization checks, IDOR, and privilege escalation that let users act outside their intended permissions. C. Server-Side Request Forgery (SSRF) is A10:2021, a newly added category in the 2021 list, where an attacker induces the server to make requests to unintended internal or external resources.

D. SQL Injection is not a standalone OWASP Top 10 2021 category; it falls under A03:2021 Injection, so it is not one of the three named items. E.

Remote Code Execution via buffer overflow is a memory-safety issue more typical of native software and CWE listings, not a distinct OWASP Top 10 2021 web application category.

Exam trap

A common trap is assuming SQL Injection remains a separate category in the OWASP Top 10 2021; however, it was merged into the broader Injection category (A03). Additionally, SSRF was added as a new category (A10), so it is a correct answer despite being a less familiar vulnerability.

168
Multi-Selecthard

An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)

Select 3 answers
A.Selecting the correct AWS region for data storage
B.Using only on-premises storage for all data
C.Storing encryption keys in the same region as the data
D.Implementing data classification policies
E.Using a global AWS account without region constraints
AnswersA, C, D

Data residency requires that stored data physically remains within a permitted jurisdiction. Choosing the correct AWS region determines the physical location of the data at rest, directly satisfying the legal constraint that data must not leave the approved territory.

Why this answer

Option A is correct because data residency is fundamentally about geography: choosing the correct AWS Region (e.g., eu-west-1 for EU data) ensures data at rest and in transit stays within the legally required jurisdiction, since AWS Regions are isolated geographic areas. Option C is correct because encryption keys are themselves regulated data; keeping KMS keys in the same Region as the encrypted data (or using a customer-managed KMS key in that Region) prevents cross-border key movement and satisfies residency controls such as those in GDPR or data-sovereignty mandates. Option D is correct because you cannot enforce residency without first knowing what data you hold; data classification policies identify regulated/sensitive data so it can be tagged, mapped, and placed only in approved Regions and on-premises locations.

Option B is not required because hybrid architectures can store data in compliant AWS Regions, so mandating all-on-premises storage is overly restrictive and defeats the hybrid design. Option E is wrong because a global AWS account without Region constraints allows resources and data to be created in any Region, directly violating data residency requirements.

Exam trap

CAS-005 often tests the nuances of data residency in hybrid cloud, and candidates may overlook the importance of encryption key location or think that on-premises storage is required, missing the essential considerations.

169
MCQmedium

A multinational retailer must comply with the EU General Data Protection Regulation for its European customers and with several U.S. state privacy laws for its American customers. The privacy team wants a single internal control framework that satisfies the strictest common denominator across all jurisdictions. Which approach should the privacy team take?

A.Implement each jurisdiction's requirements as a separate, fully independent control set managed by a regional compliance officer.
B.Apply the least restrictive state privacy law as the baseline because it imposes the fewest operational changes.
C.Adopt the requirements of the EU General Data Protection Regulation as the baseline control set and map additional state-law obligations onto it.
D.Defer framework selection until each regulator publishes an approved cross-mapping, then adopt that mapping verbatim.
AnswerC

GDPR is generally the most stringent regime the retailer faces, so using it as the baseline and layering stricter state-specific duties (for example, opt-out of sale or targeted advertising) onto that control set produces one harmonized framework that satisfies every jurisdiction without duplicating effort.

Why this answer

Harmonizing around the most stringent applicable regime gives the retailer one control set that satisfies every jurisdiction, since stricter requirements generally encompass weaker ones. Layering jurisdiction-specific obligations onto that baseline closes residual gaps, such as opt-out rights unique to certain state laws, while avoiding the cost and inconsistency of parallel compliance programs.

Exam trap

The trap here is assuming that a single framework must be chosen from one law verbatim, when harmonization around the strictest regime with mapped add-ons is the accepted approach.

170
MCQeasy

An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?

A.IaaS
B.FaaS
C.SaaS
D.PaaS
AnswerA

IaaS leaves the customer responsible for the guest OS, runtime, middleware, applications and data, whereas PaaS and SaaS shift those layers to the provider. This maximal customer ownership of the stack is precisely what satisfies the stem's requirement for the model placing the most security responsibility on the customer.

Why this answer

IaaS (Infrastructure as a Service) places the most security responsibility on the customer because the provider only manages the physical hardware, hypervisor, and network fabric. The customer is responsible for the guest OS, middleware, runtime, applications, and data — including patching, hardening, IAM, and encryption. Under SOC 2, this means the customer must implement and evidence most of the Trust Services Criteria controls themselves.

Exam trap

CAS-005 often tests the shared responsibility model by asking which model places the MOST responsibility on the customer — candidates incorrectly pick SaaS or PaaS because they confuse 'cloud-first' with 'provider-managed.'

How to eliminate wrong answers

Option B is wrong because FaaS (Function as a Service) abstracts the runtime and OS, so the provider handles more of the stack — the customer only secures function code, IAM, and data. Option C is wrong because SaaS places the least responsibility on the customer; the provider manages nearly everything except user access and data classification. Option D is wrong because PaaS sits between IaaS and SaaS — the provider manages the OS and runtime, leaving the customer responsible mainly for applications and data, which is less than IaaS.

171
MCQmedium

A software company wants to strengthen the integrity of its build pipeline. Developers currently commit code directly to the main branch, and build servers pull dependencies from public repositories without verification. The security architect must ensure that only reviewed code is built and that dependencies have not been tampered with. Which combination of controls best addresses these requirements?

A.Store build artifacts in an encrypted repository and enable versioning on the storage bucket.
B.Enforce signed commits with mandatory peer review and verify dependency signatures against a trusted allowlist.
C.Run static application security testing on every build and block releases with high-severity findings.
D.Require developers to use multi-factor authentication when pushing to the repository.
AnswerB

Signed commits prove the author's identity and, combined with mandatory peer review and branch protection, ensure only reviewed code reaches the build. Verifying dependency signatures against a trusted allowlist detects tampered or substituted packages before they enter the artifact. Together these controls directly address both code provenance and dependency integrity in the pipeline.

Why this answer

Signed commits with mandatory peer review and branch protection ensure only reviewed, attributable code is built, while verifying dependency signatures against a trusted allowlist confirms that third-party components match their publishers' originals. These preventive controls address both halves of the requirement. Authentication, static analysis, and artifact storage protections each cover different concerns and leave the provenance and dependency integrity gaps open.

Exam trap

The trap here is equating strong developer authentication or code scanning with supply chain integrity, when provenance requires cryptographic verification of both commits and dependencies.

172
MCQmedium

A company is deploying IoT sensors in a remote area with limited connectivity. The sensors must be able to securely transmit data using minimal bandwidth. Which protocol should the engineer choose?

A.SNMPv3
B.HTTPS
C.MQTT with TLS
D.SSH
AnswerC

MQTT with TLS suits constrained IoT links: its publish/subscribe design uses a compact fixed header and persistent sessions, so sensors transmit small payloads over intermittent connections without HTTP's per-request overhead. TLS provides encryption and server authentication, satisfying the stem's secure-transmission and minimal-bandwidth constraints simultaneously.

Why this answer

MQTT with TLS is the correct choice because MQTT is a lightweight publish-subscribe protocol designed for constrained devices and low-bandwidth, high-latency networks. It minimizes overhead with a small header (2 bytes minimum) and supports persistent connections, making it ideal for IoT sensors in remote areas. TLS ensures encrypted, authenticated communication without adding significant bandwidth overhead when using modern cipher suites.

Exam trap

The trap here is that candidates confuse 'secure' with 'lightweight' and choose HTTPS or SSH because they are familiar, overlooking that MQTT is specifically engineered for low-bandwidth IoT scenarios and can be secured with TLS without sacrificing efficiency.

How to eliminate wrong answers

Option A is wrong because SNMPv3, while secure, is designed for network management polling and has higher overhead due to its request-response model and larger message structures, making it unsuitable for minimal-bandwidth IoT sensor data transmission. Option B is wrong because HTTPS relies on TCP and TLS handshakes that add significant latency and bandwidth consumption per request, and its request-response model is inefficient for frequent small sensor updates. Option D is wrong because SSH is a secure remote access protocol for interactive sessions and file transfers, not designed for lightweight machine-to-machine data publishing; it requires maintaining a persistent TCP connection with higher overhead than MQTT.

173
MCQhard

An organization implements a CI/CD pipeline that automatically builds and deploys containerized microservices. Which of the following is the most effective method to ensure that only signed, trusted container images are deployed to production?

A.Implement a private container registry with access controls
B.Enable content trust and require signatures on all images
C.Run vulnerability scanning on all images before deployment
D.Use an admission controller that checks image labels
AnswerB

Content trust enforces cryptographic signing, so the container runtime verifies each image's signature against trusted publishers before deployment. Unsigned or tampered images are rejected at pull time, directly satisfying the pipeline's requirement that only signed, trusted images reach production.

Why this answer

Enabling content trust (e.g., Docker Content Trust or Notary) cryptographically signs container images, ensuring that only images signed by a trusted publisher can be deployed. This directly enforces integrity and authenticity in the CI/CD pipeline, preventing unauthorized or tampered images from reaching production.

Exam trap

The trap here is that candidates confuse access control (registry permissions) or vulnerability scanning with cryptographic trust, failing to recognize that only content trust provides non-repudiation and tamper-evidence for container images.

Why the other options are wrong

A

Access controls prevent unauthorized pushes but do not verify the integrity or authenticity of images.

C

Scanning identifies vulnerabilities but does not verify the publisher's identity or prevent tampering.

D

Labels are metadata and can be easily spoofed; they do not provide cryptographic proof of origin.

174
MCQhard

A multinational manufacturing firm is expanding into the European Union and must demonstrate accountability for personal data processing under GDPR. The Chief Privacy Officer asks the security team to implement a mechanism that proves the organization's compliance posture to supervisory authorities without requiring prior authorization from them. Which of the following should the team implement?

A.Consent from data subjects
B.Standard Contractual Clauses (SCCs)
C.Privacy Shield certification
D.Binding Corporate Rules (BCRs)
AnswerD

BCRs are approved by the competent supervisory authority and serve as a documented, enforceable framework for intra-group transfers and accountability. They demonstrate GDPR compliance without needing case-by-case authorization for each transfer, making them suitable for a multinational expanding into the EU. They are specifically designed for corporate groups with multiple entities, providing a transparent and legally binding mechanism.

Why this answer

Binding Corporate Rules are a GDPR-approved mechanism for multinational corporations to establish a comprehensive, legally binding framework for intra-group data transfers and accountability. They are approved by supervisory authorities and eliminate the need for separate authorizations, directly addressing the need to demonstrate compliance posture. SCCs are transfer-specific, Privacy Shield is invalid, and consent is a processing basis, not an accountability mechanism.

Exam trap

The trap here is assuming that Standard Contractual Clauses provide the same group-wide accountability as Binding Corporate Rules, when SCCs are transfer-specific and do not cover intra-group processing comprehensively.

175
MCQhard

An organization deploys a new web application that stores sensitive data in a backend database. During a penetration test, the tester discovers that the application is vulnerable to SQL injection via a search field. Which of the following design changes would best mitigate this vulnerability without significantly impacting functionality?

A.Deploy a web application firewall (WAF) to filter malicious payloads.
B.Rewrite the database query to use parameterized prepared statements.
C.Move all database queries to stored procedures.
D.Implement client-side input validation to block special characters.
AnswerB

Parameterised prepared statements separate SQL code from user-supplied data, so the search field's input is bound as a value rather than parsed as executable SQL. This neutralises injection at the query layer while preserving the search functionality, satisfying the requirement to mitigate without significantly impacting functionality.

Why this answer

Parameterized prepared statements separate SQL logic from user input, ensuring that any input supplied via the search field is treated strictly as data, not executable code. This directly prevents SQL injection by eliminating the possibility of an attacker altering the query structure, regardless of the input content.

Exam trap

CompTIA often tests the misconception that stored procedures are inherently safe against SQL injection, but the trap is that they only prevent injection if they use parameterized queries internally—otherwise, they are just as vulnerable as inline SQL.

How to eliminate wrong answers

Option A is wrong because a WAF is a reactive, signature-based or heuristic filter that can be bypassed with carefully crafted payloads (e.g., encoding, obfuscation) and does not address the root cause of the vulnerability. Option C is wrong because stored procedures alone do not prevent SQL injection if they still concatenate user input into dynamic SQL strings; the protection comes from using parameterized queries within the stored procedure, not from the stored procedure itself. Option D is wrong because client-side validation can be easily bypassed by disabling JavaScript or using tools like cURL or Burp Suite to send raw HTTP requests, and it provides no server-side defense against injection.

176
Multi-Selecthard

A multinational corporation is subject to GDPR and the California Consumer Privacy Act (CCPA). A security architect is designing a data governance solution to meet both regulations. Which TWO controls are most appropriate?

Select 2 answers
A.Implement data mapping to track personal data across systems and jurisdictions.
B.Establish data classification policies to categorize information based on sensitivity.
C.Deploy data loss prevention (DLP) technology to monitor data exfiltration.
D.Define a data retention schedule that automatically deletes data after a set period.
E.Integrate a security information and event management (SIEM) system for log analysis.
AnswersA, B

Data mapping records where personal data flows across systems and jurisdictions, establishing the visibility GDPR and CCPA both demand for subject access, deletion and transfer requests. Without this inventory, the architect cannot demonstrate lawful processing or respond to cross-border data obligations.

Why this answer

Option A is correct because data mapping (also called data inventory or record of processing activities) is foundational to both GDPR and CCPA compliance: GDPR Article 30 requires maintaining records of processing activities, and CCPA requires businesses to know what personal information they collect, where it flows, and to whom it is disclosed, which is impossible without mapping data across systems and jurisdictions. Option B is correct because data classification policies let the organization categorize personal data by sensitivity and regulatory category (e.g., GDPR special categories vs. CCPA personal information), which drives the appropriate handling, access, and protection controls mandated by both laws.

Option C is not the best fit because DLP monitors exfiltration but does not by itself establish the governance framework of knowing and categorizing regulated data that GDPR and CCPA demand. Option D is not the best fit because retention schedules address storage limitation (GDPR Art. 5(1)(e)) but are a downstream control that depends on the mapping and classification provided by A and B. Option E is not the best fit because SIEM log analysis supports detection and incident response, not the core data governance obligations of data inventory and classification required by these privacy regulations.

Exam trap

CAS-005 often tests the distinction between foundational governance controls (mapping, classification) and technical enforcement controls (DLP, SIEM), causing candidates to select DLP when the question asks for the most appropriate governance controls for privacy regulations.

177
MCQhard

During a malware analysis, an analyst runs a suspicious binary in a sandbox and observes that it attempts to communicate with a known malicious IP address, modifies registry keys, and creates a service. The analyst then extracts strings from the binary and finds references to a specific C2 server. Which analysis phase does the extraction of strings represent?

A.Dynamic analysis
B.Reverse engineering
C.Static analysis
D.Memory analysis
AnswerC

Extracting strings examines the binary's raw bytes without executing it, revealing embedded artefacts such as the C2 server address. That places it firmly in static analysis, which inspects code and metadata at rest, distinct from the dynamic sandbox observation already performed.

Why this answer

Extracting strings from a binary is a static analysis technique because it examines the file's contents without executing it. The strings command or similar tools reveal embedded text such as URLs, IP addresses, and error messages, which can provide immediate indicators of compromise like the C2 server address.

Exam trap

The trap is mixing up static and dynamic analysis phases; candidates might think that because the malware was run in a sandbox, all subsequent analysis is dynamic, but string extraction is purely static.

How to eliminate wrong answers

Option A is wrong because dynamic analysis involves observing the malware's behavior during execution, such as network traffic and registry changes, not extracting strings from the binary file. Option B is wrong because reverse engineering involves disassembling or decompiling the code to understand its logic, which is more complex than simply extracting strings. Option D is wrong because memory analysis examines volatile memory (RAM) to find artifacts of running processes, not the static binary file.

178
MCQmedium

An organization is unable to patch a critical vulnerability in a legacy application due to vendor limitations. The risk assessment indicates a high likelihood of exploitation. Which compensating control should the organization implement to reduce the risk?

A.Deploy an additional firewall in front of the application
B.Disable the application until a patch is available
C.Increase the frequency of vulnerability scanning
D.Implement network segmentation to isolate the application
AnswerD

Network segmentation places the unpatched legacy application in an isolated segment with restricted inbound and outbound traffic, limiting lateral movement and reducing exploitability. This compensates for the vendor-imposed inability to patch while addressing the high likelihood of exploitation.

Why this answer

Network segmentation isolates the legacy application from critical systems, limiting the blast radius if the vulnerability is exploited. This compensating control reduces risk by preventing lateral movement and restricting access to the vulnerable application, even though the vulnerability remains unpatched.

Exam trap

The trap is selecting a control that only detects or monitors (like scanning) rather than one that actually reduces risk; candidates must distinguish between detection and prevention controls.

How to eliminate wrong answers

Option A is wrong because deploying an additional firewall in front of the application may not address the specific vulnerability and could be bypassed if the attack vector is not network-based; it also adds complexity without guaranteeing isolation. Option B is wrong because disabling the application until a patch is available is a disruptive measure that may not be feasible for business operations and is not a compensating control but rather a full mitigation. Option C is wrong because increasing the frequency of vulnerability scanning only improves detection, not protection; it does not reduce the likelihood or impact of exploitation.

179
MCQeasy

A security administrator needs to secure remote access for employees using personal devices. The company requires that company data be encrypted and that the device be wiped if lost. Which solution best meets these requirements?

A.Use network access control (NAC) to allow only compliant devices onto the network.
B.Deploy a mobile device management (MDM) solution that enforces device encryption and supports remote wipe.
C.Require employees to connect via a corporate VPN and use two-factor authentication.
D.Implement remote desktop protocol (RDP) gateways for all remote access.
AnswerB

MDM enforces encryption at the device level and provides remote wipe, satisfying both stated requirements for personal devices. Unlike app-level controls, it manages the whole device, ensuring company data is encrypted and can be erased if lost. This directly meets the encryption and wipe constraints in the scenario.

Why this answer

Mobile device management (MDM) solutions are specifically designed to enforce security policies on personal devices, including mandatory device encryption (e.g., AES-256 for data at rest) and the ability to perform a remote wipe (factory reset) to destroy company data if the device is lost or stolen. This directly addresses the requirement to protect company data on unmanaged, employee-owned devices.

Exam trap

The trap here is that candidates often confuse network-level controls (NAC, VPN) or access methods (RDP) with device-level data protection, failing to recognize that only MDM provides the required encryption enforcement and remote wipe capabilities on the endpoint itself.

How to eliminate wrong answers

Option A is wrong because network access control (NAC) checks device compliance before granting network access but does not provide device-level encryption enforcement or remote wipe capabilities; it controls admission, not data protection on the device. Option C is wrong because requiring a corporate VPN and two-factor authentication secures the communication channel and verifies identity but does not enforce encryption of data stored on the device or allow remote wiping of the device. Option D is wrong because RDP gateways provide remote access to internal desktops or applications but do not enforce encryption of local device storage or support remote wipe of the personal device.

180
Multi-Selectmedium

A healthcare organization is architecting a microsegmentation strategy for its hybrid data center. The security architect must limit lateral movement between workloads, enforce policy based on workload identity rather than IP addresses, and maintain visibility into inter-workload flows. Which TWO of the following controls BEST support these requirements? (Choose two.)

Select 2 answers
A.Enable dynamic ARP inspection and DHCP snooping on all access-layer switches.
B.Deploy a software-defined perimeter (SDP) controller that authenticates endpoints before granting access to protected workload segments.
C.Use a service mesh with mutual TLS and identity-based authorization policies between microservices.
D.Place all workloads behind a next-generation firewall and create zone-based policies for north-south traffic.
E.Implement host-based firewalls with rules based on IP address ranges that mirror the existing VLAN segmentation.
AnswersB, C

A software-defined perimeter authenticates and authorizes endpoints before any network access is granted, creating identity-based, need-to-know connectivity between workloads. This directly limits lateral movement because unauthenticated workloads cannot reach protected segments, and it supports policy based on workload identity rather than static IP addresses.

Why this answer

A software-defined perimeter and a service mesh with mutual TLS both base access decisions on authenticated workload identity rather than IP addresses, which limits lateral movement and supports visibility into inter-workload flows. The other controls either rely on static IP or zone constructs, or address layer 2 threats without providing identity-based segmentation.

Exam trap

The trap here is treating host firewalls or zone-based firewalls as sufficient for microsegmentation, when they still rely on IP or zone constructs and do not enforce policy by cryptographic workload identity.

181
MCQeasy

Based on the exhibit, which vulnerability is being exploited?

A.Cross-site request forgery (CSRF)
B.SQL injection
C.Directory traversal
D.Cross-site scripting (XSS)
AnswerC

Directory traversal exploits insufficient path validation, letting an attacker supply sequences like ../ to escape the intended web root and read arbitrary files. The exhibit shows a manipulated file-path parameter returning files outside the web directory, confirming traversal rather than injection or misconfiguration.

Why this answer

The GET request in the exhibit uses '../' sequences to traverse directories and access the /etc/passwd file, which is characteristic of a directory traversal attack. Option A (CSRF) is wrong because CSRF attacks rely on exploiting a user's authenticated session to perform unintended actions, not directory path manipulation. Option B (SQL injection) is wrong because there is no SQL syntax or database query involved.

Option D (XSS) is wrong because no scripts or client-side code execution is present.

182
MCQhard

A company is migrating from a legacy three-tier architecture to a microservices architecture on Kubernetes. The security team wants to ensure that service-to-service communication is encrypted and mutually authenticated. Which approach best meets these requirements with minimal operational overhead?

A.Implement a service mesh with mutual TLS (mTLS) and automatic certificate management.
B.Deploy IPsec tunnels between each pair of services using pre-shared keys.
C.Establish a site-to-site VPN between the Kubernetes cluster and the legacy network, and route all service traffic through the VPN.
D.Configure each service to use TLS with self-signed certificates, and distribute the CA certificate to all services.
AnswerA

A service mesh with mTLS encrypts all service-to-service traffic and authenticates both endpoints via certificates, satisfying the mutual authentication requirement. Its control plane automates certificate issuance and rotation across Kubernetes pods, delivering this with minimal operational overhead compared with manually managing certificates per service.

Why this answer

A service mesh with mutual TLS (mTLS) and automatic certificate management is the correct approach because it provides encrypted, mutually authenticated service-to-service communication with minimal operational overhead. The service mesh (e.g., Istio, Linkerd) transparently intercepts traffic via sidecar proxies, handles mTLS handshakes, and automates certificate issuance and rotation, eliminating the need for manual key distribution or application-level changes.

Exam trap

The trap here is that candidates may choose IPsec or VPN solutions because they are familiar with network-layer encryption, but they fail to recognize that these approaches do not scale to the dynamic, ephemeral nature of microservices and introduce prohibitive operational overhead compared to a service mesh's automated mTLS.

How to eliminate wrong answers

Option B is wrong because IPsec tunnels between each pair of services introduce significant operational overhead for key management and do not scale well in a dynamic microservices environment where service instances are ephemeral. Option C is wrong because a site-to-site VPN between the Kubernetes cluster and the legacy network secures only cross-network traffic, not internal service-to-service communication within the cluster, and routing all service traffic through the VPN adds unnecessary latency and complexity. Option D is wrong because distributing a CA certificate to all services for self-signed TLS still requires manual management of certificate distribution and does not automate certificate rotation, leading to high operational overhead and potential security gaps if certificates expire or are compromised.

183
MCQmedium

A security architect is designing a new system that processes sensitive customer data. The organization must comply with multiple regulations, including GDPR and PCI DSS. The architect needs to ensure that data protection controls are integrated from the outset. Which approach best aligns with the principle of privacy by design?

A.Obtain consent from all customers for data processing.
B.Rely on the cloud provider's default security settings.
C.Conduct a data protection impact assessment (DPIA) before development begins.
D.Implement encryption for data at rest after the system is deployed.
AnswerC

A DPIA is a GDPR requirement for processing that likely results in high risk to data subjects. It identifies and mitigates privacy risks early in the design phase, directly implementing privacy by design. By conducting it before development, the architect ensures controls are built in, not bolted on, and addresses multiple regulatory requirements proactively.

Why this answer

Conducting a data protection impact assessment before development begins is a core privacy by design practice. It proactively identifies privacy risks and ensures controls are integrated into the system architecture from the start. Encryption after deployment, default settings, and consent are either reactive or insufficient to meet the principle of privacy by design.

Exam trap

The trap here is equating consent or encryption with privacy by design, when the principle fundamentally requires proactive risk assessment and integration of privacy controls throughout the development lifecycle.

184
Multi-Selectmedium

A security architect is designing a secure software development pipeline. The organization wants to ensure that code is thoroughly analyzed before deployment. Which TWO of the following should be integrated into the pipeline to identify vulnerabilities early? (Select TWO.)

Select 2 answers
A.Static application security testing (SAST)
B.Software composition analysis (SCA)
C.Fuzz testing
D.Dynamic application security testing (DAST)
E.Penetration testing
AnswersA, B

SAST analyzes source code without executing it, identifying vulnerabilities early.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binary code without executing it, scanning for vulnerabilities like SQL injection, buffer overflows, and insecure cryptographic functions. Integrating SAST early in the pipeline (shift-left) allows developers to fix issues before compilation, reducing remediation cost and risk. SCA (Software Composition Analysis) identifies known vulnerabilities in third-party libraries and open-source components by comparing dependency versions against databases like the National Vulnerability Database (NVD).

Both tools are non-intrusive and can be automated in CI/CD pipelines to catch flaws before deployment.

Exam trap

The CAS-004 exam often tests the distinction between static and dynamic analysis by presenting SAST and DAST as equally valid early-stage options, but the trap is that DAST requires a running application and cannot be integrated before deployment, making SAST and SCA the only correct choices for early vulnerability identification.

185
MCQeasy

Under the GDPR, which of the following is a data subject right?

A.Right to transfer data across borders without restriction
B.Right to unlimited processing
C.Right to erasure (right to be forgotten)
D.Right to sell data
AnswerC

The right to erasure, also called the right to be forgotten, lets a data subject require an organisation to delete personal data without undue delay. It is one of the GDPR's enumerated data subject rights, satisfying the stem's question.

Why this answer

The right to erasure (right to be forgotten) is explicitly listed in Article 17 of the GDPR. It allows data subjects to request deletion of their personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected. This is one of the core data subject rights alongside access, rectification, and portability.

Exam trap

CAS-005 often tests the specific rights granted by GDPR, and candidates may confuse the right to erasure with other rights like data portability or mistakenly believe there is a right to unrestricted processing.

How to eliminate wrong answers

Option A is wrong because the GDPR does not grant an unrestricted right to transfer data across borders; cross-border transfers are subject to strict conditions (adequacy decisions, standard contractual clauses, etc.). Option B is wrong because the GDPR grants the right to restrict processing, not unlimited processing — unlimited processing would violate the purpose limitation and data minimization principles. Option D is wrong because the GDPR does not grant a right to sell data; in fact, it emphasizes control over personal data and requires a legal basis for any processing, including sale.

186
MCQmedium

A financial services company is designing a hybrid cloud environment. The security architect must ensure that data in transit between the on-premises data center and the cloud provider is protected against interception and that the cloud provider cannot read the data. The company also needs to meet strict compliance requirements for key management. Which of the following should the architect implement to BEST meet these requirements?

A.Implement a dedicated AWS Direct Connect connection with MACsec encryption.
B.Use TLS 1.3 with mutual authentication for all data transfers and store private keys in a cloud-based key management service.
C.Configure a site-to-site VPN using IPsec with pre-shared keys managed by the cloud provider.
D.Deploy a customer-managed VPN gateway with hardware security modules (HSMs) for key storage and use IPsec with customer-managed certificates.
AnswerD

This approach uses a customer-managed VPN gateway and HSMs to store keys, ensuring that the cloud provider does not have access to the encryption keys. IPsec with customer-managed certificates provides strong encryption and authentication. This meets the requirements for data confidentiality against the provider and compliance with strict key management controls.

Why this answer

The requirement is to protect data in transit from interception and ensure the cloud provider cannot read it, while meeting strict key management compliance. A customer-managed VPN gateway with HSMs and customer-managed certificates ensures that encryption keys are controlled by the company, not the provider. IPsec provides strong encryption, and HSMs offer secure key storage, satisfying both security and compliance.

Exam trap

The trap here is assuming that any encryption in transit is sufficient, without considering who controls the encryption keys.

187
MCQhard

A security manager is reviewing the organization's risk register and notes that a critical vulnerability in a legacy application has been accepted for two years. The business owner argues that the cost of remediation exceeds the potential loss. The security manager must present an alternative that aligns with the organization's risk appetite while addressing the residual risk. Which of the following is the BEST recommendation?

A.Transfer the risk by purchasing cyber insurance that covers losses from exploitation of the legacy application.
B.Avoid the risk by decommissioning the legacy application immediately, regardless of business impact.
C.Implement compensating controls such as network segmentation and enhanced monitoring to reduce the likelihood and impact of exploitation.
D.Accept the risk permanently and document the business owner's decision in the risk register without further action.
AnswerC

When remediation is not feasible, applying compensating controls can reduce residual risk to an acceptable level. Network segmentation limits lateral movement, and enhanced monitoring improves detection. This approach aligns with the organization's risk appetite by addressing the risk without incurring the full cost of replacing the legacy application, and it demonstrates due diligence in managing accepted risks.

Why this answer

Compensating controls reduce residual risk when remediation is not feasible, aligning with the organization's risk appetite by lowering likelihood and impact without the full cost of replacing the legacy system. Risk transfer, acceptance without action, and avoidance all fail to address the residual risk appropriately in this context.

Exam trap

The trap here is equating risk acceptance with doing nothing, when in fact accepted risks still require periodic review and may need compensating controls to remain within tolerance.

188
MCQhard

An organization is migrating to an immutable infrastructure model for its containerized applications. Which practice is essential to ensure the integrity of the immutable infrastructure?

A.Regular patching of running containers
B.Image scanning and signing in the CI/CD pipeline
C.Runtime security monitoring with seccomp
D.Use of configuration management tools like Ansible
AnswerB

Scanning detects vulnerabilities and embedded secrets, while signing produces a cryptographic attestation of image provenance. Enforcing signature verification at deploy time ensures only unaltered, approved images run, directly preserving the integrity guarantee that immutable infrastructure depends on.

Why this answer

In an immutable infrastructure model, containers are never modified after deployment — instead, new images replace old ones. Therefore, integrity must be enforced at build time: scanning images for vulnerabilities and cryptographically signing them in the CI/CD pipeline ensures only trusted, verified artifacts are deployed. This shifts security left and guarantees that what runs in production is exactly what was tested and approved.

Exam trap

CAS-005 often tests the misconception that 'patching' or 'runtime monitoring' secures immutable infrastructure, when the exam expects you to recognize that integrity is guaranteed at build/deploy time via scanning and signing.

How to eliminate wrong answers

Option A is wrong because patching running containers violates immutability — you would mutate a live container instead of replacing it with a newly built image. Option C is wrong because runtime security monitoring with seccomp is a detective/preventive control at runtime, not a mechanism for ensuring the integrity of the immutable artifact itself. Option D is wrong because configuration management tools like Ansible are designed for mutable, state-enforced configuration of long-lived hosts, which is the opposite of the immutable infrastructure philosophy.

189
Multi-Selecteasy

A company is implementing MFA for remote access. Which TWO factors are considered possession factors?

Select 2 answers
A.A fingerprint scan
B.A hardware OTP token
C.A PIN
D.A push notification to a registered smartphone
E.A password
AnswersB, D

A hardware OTP token is a possession factor because authentication requires something the user physically holds, satisfying the MFA requirement for a possession-based credential. The device generates time-synchronised one-time codes, so access depends on possessing the hardware itself rather than knowledge or biometrics.

Why this answer

Option B (a hardware OTP token) is a possession factor because authentication depends on something the user physically has — the token device that generates or stores the one-time passcode. Option D (a push notification to a registered smartphone) is also a possession factor because the approval prompt is delivered to a specific device the user possesses, and possession of that enrolled phone is what enables the authentication. Option A (a fingerprint scan) is an inherence factor, since it relies on a biometric characteristic of the user.

Option C (a PIN) and Option E (a password) are both knowledge factors, because they rely on something the user knows rather than something the user has.

190
MCQeasy

An organization is deploying a new application that processes sensitive user data. The security team recommends using a dedicated cryptographic module. Which standard should the module comply with to ensure it is validated for security?

A.ISO 27001
B.PCI DSS
C.NIST SP 800-53
D.FIPS 140-2
AnswerD

FIPS 140-2 is the NIST validation standard for cryptographic modules, specifying security requirements across eleven areas including key management and physical tampering. Compliance certifies the module has been independently tested, satisfying the demand for a validated cryptographic module.

Why this answer

FIPS 140-2 (Federal Information Processing Standard Publication 140-2) is the U.S. government standard for validating cryptographic modules. It specifies security requirements for hardware and software modules that perform cryptographic functions, ensuring they have been tested and validated by an accredited laboratory. For an application processing sensitive user data, deploying a FIPS 140-2 validated module guarantees that the cryptographic implementation meets rigorous security standards.

Exam trap

Candidates often mistake broad security frameworks like ISO 27001 or NIST SP 800-53 for the specific cryptographic module validation standard. For the CASP+ exam, remember that FIPS 140-2 is the dedicated standard for validated cryptographic modules used in government and sensitive data environments.

How to eliminate wrong answers

Option A is wrong because ISO 27001 is an information security management system (ISMS) standard that defines requirements for establishing, implementing, and improving an organization's security management processes; it does not validate cryptographic modules. Option B is wrong because PCI DSS (Payment Card Industry Data Security Standard) is a set of security controls for protecting cardholder data, not a cryptographic module validation standard; it may reference FIPS 140-2 but is not itself a validation standard. Option C is wrong because NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and organizations, not a standard for validating cryptographic modules.

191
Multi-Selectmedium

A security engineer is implementing container security controls. Which TWO practices are most effective in preventing privilege escalation within a container? (Choose two.)

Select 2 answers
A.Dropping all capabilities (CAP_DROP=ALL)
B.Enabling SELinux
C.Using host networking
D.Mounting /var/run/docker.sock
E.Setting USER to non-root in the Dockerfile
AnswersA, E

Removing capabilities eliminates potential escalation via Linux capabilities.

Why this answer

Dropping all capabilities with `CAP_DROP=ALL` removes all Linux capabilities from the container, effectively preventing any process inside from performing privileged operations such as changing user IDs, mounting filesystems, or accessing kernel features that could lead to privilege escalation. This is a fundamental container security best practice, as capabilities are the primary mechanism for granting fine-grained privileges to container processes.

Exam trap

The CAS-004 exam often tests the misconception that SELinux or AppArmor alone can prevent privilege escalation, but these tools enforce access control policies rather than removing the underlying capability to escalate; the trap is that candidates confuse mandatory access control with capability dropping, which directly removes the ability to perform privileged actions.

192
MCQeasy

Which cryptographic best practice ensures that a private key remains protected even if the server it is stored on is compromised?

A.Storing keys in a hardware security module (HSM)
B.Encrypting keys with AES-256
C.Using short key rotation intervals
D.Using strong key derivation functions
AnswerA

An HSM performs cryptographic operations internally, so the private key never leaves the tamper-resistant hardware. Compromising the host server yields no usable key material, satisfying the requirement that the key stay protected despite server compromise.

Why this answer

A hardware security module (HSM) is a dedicated physical device that securely generates, stores, and manages cryptographic keys, ensuring the private key never leaves the tamper-resistant hardware. Even if the server is compromised, the attacker cannot extract the key from the HSM. This provides the strongest protection for private keys.

Exam trap

CAS-005 often tests the misconception that encrypting a key at rest (e.g., with AES) is sufficient; candidates overlook that the encryption key must also be protected, and only an HSM ensures the private key never exists in an extractable form.

How to eliminate wrong answers

Option B is wrong because encrypting keys with AES-256 still requires storing the encryption key somewhere on the server, which could be compromised along with the encrypted key. Option C is wrong because short key rotation intervals reduce the window of exposure but do not protect the key if the server is actively compromised during its lifetime. Option D is wrong because strong key derivation functions protect weak passwords or passphrases, not the private key itself once it is in use on a compromised server.

193
MCQmedium

A financial services company is deploying a new internal web application that must meet PCI DSS requirements for encrypting cardholder data in transit. The security engineer must configure TLS to ensure that only ephemeral key exchanges are used and that compromised long-term keys cannot decrypt past sessions. Which of the following should the engineer implement?

A.Deploy TLS 1.2 with AES-256-GCM and ensure the server certificate uses SHA-1 for signing.
B.Enable TLS 1.3 with cipher suites that use ephemeral Diffie-Hellman (DHE or ECDHE) key exchange.
C.Implement TLS 1.2 with static Diffie-Hellman parameters and a 4096-bit RSA certificate.
D.Configure the server to use TLS 1.2 with RSA key exchange and 2048-bit RSA certificates.
AnswerB

TLS 1.3 mandates forward secrecy by design, using ephemeral Diffie-Hellman key exchange for all cipher suites. Each session generates a unique ephemeral key pair that is discarded after the handshake, so compromise of the server's long-term private key cannot decrypt recorded past sessions. This directly satisfies the requirement and aligns with PCI DSS guidance for strong cryptography.

Why this answer

TLS 1.3 enforces forward secrecy by requiring ephemeral key exchange, so even if the server's long-term private key is compromised, past session keys remain secure. The other options either use static key exchanges that lack forward secrecy or include deprecated algorithms like SHA-1. For PCI DSS compliance, ephemeral Diffie-Hellman with TLS 1.3 is the most robust choice.

Exam trap

The trap here is assuming that simply using TLS 1.2 with a large RSA key or AES-256 provides forward secrecy, when the critical factor is the key exchange method, not the symmetric cipher or certificate size.

194
MCQmedium

A company's incident response team is conducting a post-incident review. They identify that the intrusion was not detected for 72 hours due to insufficient logging on critical servers. Which phase of the incident response lifecycle should be improved to address this gap?

A.Lessons learned
B.Containment
C.Detection
D.Preparation
AnswerD

Preparation covers establishing logging, monitoring and detection capabilities before incidents occur. Insufficient logging on critical servers is a preparation gap, so strengthening log collection and alerting in this phase directly addresses the 72-hour detection failure identified in the review.

Why this answer

The gap is insufficient logging on critical servers, which is a preparation issue because logging must be configured and enabled before an incident occurs. Detection relies on logs, but if logs are not properly set up during the preparation phase, detection will fail. Therefore, improving preparation by ensuring adequate logging is the correct phase to address.

Exam trap

The trap is selecting 'Detection' because the failure occurred during detection, but the question asks which phase should be improved to address the gap, and the gap is in preparation (logging setup).

How to eliminate wrong answers

Option A is wrong because lessons learned is a post-incident activity where improvements are identified, but the actual implementation of logging improvements falls under preparation. Option B is wrong because containment involves limiting the spread of an incident, not addressing logging deficiencies. Option C is wrong because detection is the phase where the lack of logging manifested, but the root cause is inadequate preparation; improving detection would require better logging, which is a preparation task.

195
Multi-Selectmedium

A DevOps team is automating the deployment of a containerized application to production. Which THREE practices are essential for maintaining security and reliability? (Select THREE.)

Select 3 answers
A.Use Helm charts to package and deploy Kubernetes applications.
B.Use Docker Compose files for production deployments.
C.Use infrastructure as code tools like Terraform to provision and manage container hosts.
D.Manually configure each environment to handle unique settings.
E.Implement continuous deployment pipelines with automated security testing.
AnswersA, C, E

Helm provides reusable, versioned deployment packages with rollback capabilities.

Why this answer

Helm charts are essential for packaging and deploying Kubernetes applications because they provide a standardized, version-controlled way to manage complex Kubernetes manifests. Helm simplifies deployment, rollback, and dependency management, which is critical for maintaining security and reliability in production environments.

Exam trap

CompTIA CASP+ often tests the distinction between development tools (like Docker Compose) and production-grade orchestration tools (like Kubernetes with Helm), so candidates mistakenly assume Docker Compose is suitable for production deployments.

196
MCQmedium

An organization is deploying hardware security modules (HSMs) to protect cryptographic keys used for digital signatures. Which attack vector is most effectively mitigated by using an HSM compared to storing keys in software?

A.Side-channel attacks on the host CPU
B.Key extraction from memory dumps
C.Man-in-the-middle attacks on cryptographic operations
D.Brute-force attacks on key strength
AnswerB

HSMs keep private keys inside tamper-resistant hardware and perform signing operations internally, so keys never exist in host RAM. This directly defeats memory-dump extraction, the stated attack vector, unlike software keystores where keys are loaded into process memory and can be captured by a privileged attacker.

Why this answer

HSMs are designed to store cryptographic keys in tamper-resistant hardware, preventing attackers from extracting keys via memory dumps. Unlike software-based storage, where keys reside in volatile or non-volatile memory and can be read through process memory inspection or cold boot attacks, HSMs ensure keys never leave the secure boundary in plaintext form.

Exam trap

The trap here is that candidates confuse the HSM's protection of key material at rest with protection against active attacks like side-channel or MITM, when in fact HSMs primarily defend against key extraction from memory or physical theft, not against all cryptographic attack vectors.

How to eliminate wrong answers

Option A is wrong because side-channel attacks on the host CPU (e.g., timing, power analysis, or cache attacks) can still be performed against the host system even when an HSM is used, as the HSM does not eliminate side-channel leakage from the host's cryptographic operations. Option C is wrong because man-in-the-middle attacks on cryptographic operations target the communication channel between the client and the HSM or between systems, and while HSMs can help with secure key storage, they do not inherently prevent MITM attacks on the protocol layer (e.g., TLS interception). Option D is wrong because brute-force attacks on key strength depend on the key length and algorithm (e.g., AES-256, RSA-2048), not on whether the key is stored in an HSM or software; an HSM does not increase the computational difficulty of brute-forcing the key itself.

197
MCQmedium

A software development team is adopting a DevSecOps approach. Which of the following practices best integrates security into the continuous integration pipeline?

A.Running static application security testing (SAST) on every code commit
B.Conducting annual security training for developers
C.Using a vulnerability scanner on production servers
D.Performing penetration testing after each release
AnswerA

Running SAST on every commit embeds automated security checks directly into the CI pipeline, satisfying the DevSecOps requirement for continuous, shift-left testing. Unlike periodic manual reviews or pre-deployment gates, this scans source code at the earliest stage, catching vulnerabilities before they merge and giving developers immediate feedback.

Why this answer

Running static application security testing (SAST) on every code commit integrates security directly into the continuous integration (CI) pipeline by automatically analyzing source code for vulnerabilities (e.g., SQL injection, buffer overflows) before the build is compiled. This shift-left approach ensures that security checks are performed as early as possible, aligning with DevSecOps principles of continuous security validation without manual intervention.

Exam trap

In CompTIA CASP+, a common trap is confusing security activities that are integrated into the CI/CD pipeline (like SAST) with those performed outside the pipeline (like annual training or post-release pen testing). Candidates may also mistake runtime vulnerability scanning for static analysis or think any security activity qualifies as DevSecOps integration.

How to eliminate wrong answers

Option B is wrong because annual security training is a people-focused, periodic activity that does not provide automated, continuous feedback within the CI pipeline; it addresses awareness but not real-time code-level security. Option C is wrong because using a vulnerability scanner on production servers is a runtime, post-deployment check that occurs too late in the lifecycle to prevent vulnerabilities from entering the build pipeline. Option D is wrong because performing penetration testing after each release is a manual, point-in-time assessment that does not scale to every commit and introduces delays, contradicting the continuous integration model.

198
MCQmedium

A security team needs to implement a CI/CD pipeline that automatically scans container images for vulnerabilities before deployment. Which tool can be integrated into the pipeline for this purpose?

A.SonarQube
B.Prometheus
C.Trivy
D.Grafana
AnswerC

Trivy scans container images for known vulnerabilities.

Why this answer

Trivy is a comprehensive open-source vulnerability scanner specifically designed for container images, filesystems, and Git repositories. It can be integrated directly into a CI/CD pipeline to automatically scan container images for known CVEs before deployment, making it the correct choice for this use case.

Exam trap

The CAS-004 exam often tests the distinction between tools used for static code analysis (SonarQube) versus container vulnerability scanning (Trivy), leading candidates to confuse SAST tools with container security scanners.

How to eliminate wrong answers

Option A is wrong because SonarQube is a static application security testing (SAST) tool focused on source code quality and security, not container image vulnerability scanning. Option B is wrong because Prometheus is a monitoring and alerting toolkit for metrics collection, not a vulnerability scanner for container images. Option D is wrong because Grafana is a visualization and analytics platform for dashboards, not a tool for scanning container images for vulnerabilities.

199
MCQmedium

A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?

A.AWS CloudTrail
B.AWS WAF
C.AWS Config
D.AWS Shield
AnswerC

AWS Config continuously records resource configurations and evaluates them against rules, flagging non-compliant changes across the account. This satisfies the SOC 2 monitoring and enforcement constraint by providing auditable configuration history and automated remediation triggers.

Why this answer

AWS Config is the service purpose-built for continuously assessing, auditing, and evaluating AWS resource configurations against desired baselines. It records configuration changes, evaluates them against Config Rules (including SOC 2-aligned conformance packs), and flags noncompliant resources. This directly maps to SOC 2's change management, monitoring, and configuration control criteria.

CloudTrail, WAF, and Shield serve different purposes — API activity logging, web attack filtering, and DDoS mitigation respectively — none of which provide configuration compliance assessment.

Exam trap

CAS-005 often tests the confusion between CloudTrail (who did what — API activity) and AWS Config (what is the configuration state — compliance), since both are 'monitoring' services and candidates frequently swap them under time pressure.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and who did what, but does not evaluate whether resource configurations meet a compliance baseline — it is an audit log, not a configuration compliance engine. Option B is wrong because AWS WAF filters HTTP/S traffic against web exploits like SQLi and XSS at the application layer; it has no visibility into resource configuration state. Option D is wrong because AWS Shield provides DDoS protection at Layers 3/4 (and Shield Advanced at Layer 7), which is unrelated to configuration monitoring or SOC 2 configuration controls.

200
MCQeasy

A security engineer is deploying a new wireless network for a corporate campus and must ensure that all client traffic is protected with strong encryption and that the network does not rely on a pre-shared key. Which configuration should the engineer implement?

A.WPA2-Personal with a rotated pre-shared key every 30 days
B.WEP with 128-bit keys and MAC address filtering
C.WPA3-Enterprise with 802.1X authentication against a RADIUS server
D.Open authentication with a captive portal for guest access
AnswerC

WPA3-Enterprise uses 802.1X with EAP to authenticate each user or device against a RADIUS server, eliminating the shared-secret weakness of pre-shared keys. It also mandates stronger cryptographic protections, including protected management frames and, in WPA3-Enterprise 192-bit mode, GCMP-256 and SHA-384. This directly satisfies the requirement for strong encryption without a pre-shared key.

Why this answer

WPA3-Enterprise with 802.1X and RADIUS authentication meets both requirements: it provides strong, current cryptographic protections and authenticates each client individually, so no pre-shared key is used. WPA2-Personal retains a shared key, open authentication provides no encryption, and WEP is broken. The enterprise mode with 802.1X is the standard choice for corporate wireless deployments.

Exam trap

The trap here is assuming that rotating a pre-shared key converts WPA2-Personal into an enterprise-grade solution, when the fundamental shared-secret exposure remains.

201
MCQhard

A multinational corporation is implementing a privacy program that must comply with both GDPR and CCPA. Which approach to privacy impact assessments (PIAs) is most appropriate?

A.Perform separate PIAs for GDPR and CCPA requirements
B.Skip PIAs for existing processing activities
C.Conduct a single PIA that covers both regulations' requirements
D.Only perform PIAs when processing high-risk data
AnswerC

A single consolidated PIA mapping overlapping GDPR and CCPA requirements avoids duplicated assessments, since both regimes share core principles around data processing, individual rights and risk. One assessment covering the stricter obligation of each area satisfies both regulators efficiently.

Why this answer

A single, unified PIA that addresses the requirements of both GDPR and CCPA is the most efficient and consistent approach, as many of the core elements (data mapping, risk assessment, mitigation) overlap. It avoids duplication and ensures that the organization has a holistic view of privacy risks across jurisdictions. This approach is recommended by privacy professionals when regulations share common principles.

Exam trap

CAS-005 often tests the misconception that each privacy regulation requires a completely separate assessment, when in fact a unified PIA can satisfy multiple frameworks and is considered best practice.

How to eliminate wrong answers

Option A is wrong because performing separate PIAs for each regulation duplicates effort and can lead to inconsistent risk assessments, especially when the same processing activity is subject to both laws. Option B is wrong because skipping PIAs for existing processing activities violates GDPR Article 35 (which requires DPIAs for high-risk processing) and CCPA's risk assessment expectations. Option D is wrong because PIAs are not only for high-risk data; GDPR requires DPIAs for specific high-risk processing, but CCPA and best practices encourage broader assessments, and limiting to high-risk data may miss compliance obligations.

202
MCQmedium

A company is implementing a Privileged Access Management (PAM) solution to manage admin credentials. Which feature allows administrators to request temporary elevated access for a specific task?

A.Session recording
B.Just-in-time access
C.Password vaulting
D.Break-glass accounts
AnswerB

Just-in-time access grants elevated privileges only when requested and approved for a defined window, then automatically revokes them. This matches the stem's requirement for temporary elevated access for a specific task, rather than standing permanent admin rights.

Why this answer

Just-in-time (JIT) access is a core PAM capability that grants elevated privileges only when needed, for a limited time, and often with approval workflows. It directly addresses the requirement for temporary elevated access for a specific task, reducing standing privileges and the attack surface. JIT typically integrates with identity governance to enforce least privilege and just-enough administration.

Exam trap

The trap here is confusing session recording (auditing) with access granting, or assuming break-glass accounts are for temporary elevation; CAS-005 often tests the distinction between monitoring, credential storage, emergency access, and just-in-time elevation.

How to eliminate wrong answers

Option A is wrong because session recording is a monitoring and auditing feature that captures privileged sessions for compliance and forensics, but it does not grant or manage temporary elevated access. Option C is wrong because password vaulting securely stores and manages privileged credentials, but it does not provide time-bound, request-based elevation; it is about credential checkout and rotation. Option D is wrong because break-glass accounts are emergency access accounts designed for use when normal access mechanisms fail, not for routine temporary elevation for specific tasks; they are typically highly privileged and heavily audited, but not intended for just-in-time requests.

203
Multi-Selecthard

A security analyst is reviewing an incident where an attacker used a compromised service account to perform lateral movement within an Active Directory environment. The analyst wants to identify other systems that the attacker may have accessed using this account. Which two data sources would be most effective for this investigation? (Choose two.)

Select 2 answers
A.Domain controller security logs for Kerberos service ticket requests (Event ID 4769) involving the service account.
B.Windows Security event logs for logon events (e.g., Event ID 4624) filtered by the service account.
C.SIEM alerts for unusual process execution on the service account's original workstation.
D.Antivirus logs on the domain controller.
E.Firewall logs showing outbound connections from the service account's workstation.
AnswersA, B

Event ID 4769 logs Kerberos service ticket requests, showing which services the account accessed. Since service accounts often use Kerberos, this can reveal lateral movement to servers. Correlating with logon events provides a comprehensive view of accessed systems.

Why this answer

To track lateral movement of a service account, the analyst needs authentication records across the domain. Windows Security event logs (4624) show successful logons per system, and domain controller Kerberos service ticket requests (4769) show which services the account requested tickets for. Together, these reveal the systems the attacker accessed.

Other sources lack account-specific authentication details.

Exam trap

The trap here is focusing on network or endpoint logs that do not tie activity to the specific service account, missing the domain-wide authentication trail.

204
MCQhard

A security architect is designing a network segmentation scheme for a containerized workload running on a Kubernetes cluster. The requirement is to enforce least-privilege communication between microservices at Layer 3 and Layer 4, and to ensure that only explicitly allowed traffic can flow between pods, even within the same namespace. Which of the following should the architect implement?

A.Pod Security Admission with the restricted profile applied to all namespaces.
B.A web application firewall (WAF) placed in front of the ingress controller.
C.Istio service mesh with mutual TLS (mTLS) enabled between all sidecars.
D.Kubernetes Network Policies with a default-deny ingress and egress policy.
AnswerD

Kubernetes Network Policies are the native mechanism to control pod-to-pod traffic at Layer 3 and Layer 4. By applying a default-deny policy for both ingress and egress in a namespace, all traffic is blocked unless explicitly allowed by a subsequent policy. This enforces least privilege and prevents lateral movement between microservices. It works with a CNI plugin that supports network policies, such as Calico or Cilium, and is the standard way to achieve microsegmentation in Kubernetes.

Why this answer

To enforce least-privilege communication between microservices at Layer 3 and Layer 4, the architect needs a mechanism that controls pod-to-pod traffic based on labels and ports. Kubernetes Network Policies with a default-deny stance provide exactly that: a whitelist model where only explicitly permitted flows are allowed. This prevents unauthorized lateral movement even within the same namespace and is the native, CNI-supported solution for microsegmentation in Kubernetes.

Exam trap

The trap here is confusing service mesh mTLS, which provides encryption and identity, with network segmentation, which controls reachability; mTLS alone does not restrict which services can connect.

205
MCQeasy

A small business wants to achieve compliance with PCI DSS. Which approach should they take to minimize the scope of the assessment?

A.Segment the cardholder data environment from the corporate network
B.Implement a tokenization service
C.Encrypt all cardholder data at rest
D.Train employees on security awareness
AnswerA

Segmentation reduces the systems that process, store, or transmit card data.

Why this answer

Segmenting the cardholder data environment (CDE) from the corporate network using firewalls or VLANs physically or logically isolates systems that store, process, or transmit cardholder data. This reduces the number of systems and network segments that fall under PCI DSS assessment scope, because only devices within the CDE segment must comply with the full set of requirements. By minimizing the attack surface and the number of controls to validate, segmentation directly lowers the cost and complexity of the assessment.

Exam trap

A common misconception is that encryption or tokenization alone reduces PCI DSS scope, but only network segmentation (or outsourcing to a validated third party) can remove systems from the assessed environment.

How to eliminate wrong answers

Option B is wrong because tokenization replaces cardholder data with a non-sensitive token, but the tokenization service itself still processes and stores the original PAN, so the service and its network remain in scope unless the tokenization is performed by a third-party provider that is PCI DSS compliant and the tokens are not reversible within the merchant environment. Option C is wrong because encrypting cardholder data at rest is a security control required by PCI DSS Requirement 3, but it does not reduce the number of systems or network segments that must be assessed; all systems that store, process, or transmit cardholder data remain in scope regardless of encryption. Option D is wrong because security awareness training is a PCI DSS Requirement 12.6 control that helps prevent data breaches, but it does not change the network architecture or reduce the number of systems subject to the assessment scope.

206
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an attacker used DNS tunneling to exfiltrate data. Which THREE network traffic indicators would support this hypothesis? (Select THREE.)

Select 3 answers
A.A sudden increase in failed login attempts
B.Large DNS response packets (greater than 512 bytes)
C.Unencrypted HTTP traffic to external IPs
D.DNS queries for domains with long subdomains and random characters
E.An unusually high number of DNS queries from a single host
AnswersB, D, E

DNS tunnelling encodes exfiltrated data into DNS records, inflating responses well beyond the 512-byte UDP limit and often forcing TCP fallback. Large response packets therefore satisfy the stem's requirement for network indicators supporting the DNS tunnelling hypothesis.

Why this answer

Option B is correct because DNS tunneling typically requires encoding data in DNS responses, which pushes packet sizes beyond the standard 512-byte UDP DNS limit and often forces TCP fallback or EDNS0 usage, making large DNS response packets a strong indicator. Option D is correct because tunneling tools encode exfiltrated data into subdomain labels, producing long, high-entropy, randomly generated subdomains that are atypical of legitimate DNS traffic. Option E is correct because DNS tunneling generates a high volume of queries from a single host as data is chunked and sent in many small DNS requests, so an unusual spike in query count from one internal host supports the hypothesis.

Option A does not belong because failed login attempts indicate authentication attacks such as brute forcing, not DNS-based exfiltration. Option C does not belong because unencrypted HTTP to external IPs is a general web traffic observation and is not specific to DNS tunneling, which operates over port 53.

Exam trap

CAS-005 often tests the ability to distinguish DNS tunneling indicators from other attack indicators, causing candidates to select generic exfiltration signs like HTTP traffic or failed logins instead of DNS-specific anomalies.

207
MCQmedium

A company is implementing measured boot using TPM 2.0. What is the primary purpose of storing boot measurements in Platform Configuration Registers (PCRs)?

A.To speed up the boot process.
B.To provide a root of trust for storage (sealed storage).
C.To encrypt the bootloader.
D.To enable remote attestation of the system's boot state.
AnswerD

PCRs hold cumulative hashes of boot components, and their values can be signed by the TPM's attestation key. A remote verifier compares these quotes against known-good values, confirming the system booted untampered — the core mechanism enabling remote attestation of boot state.

Why this answer

PCRs store hashes of boot components; these measurements are used for remote attestation to verify the integrity of the boot process.

208
Multi-Selectmedium

A security team is deploying a hardware security module (HSM) to protect the root of trust for a code-signing pipeline. The team must ensure that signing keys cannot be extracted and that all signing operations are attributable to an authorized operator. Which TWO controls BEST meet these requirements? (Choose two.)

Select 2 answers
A.Store an encrypted backup of the HSM's key material on a network share protected by share-level permissions
B.Enable FIPS 140-3 validated mode on the HSM and publish the validation certificate internally
C.Configure the HSM to mark signing keys as non-extractable and perform all cryptographic operations inside the module
D.Enable per-operator authentication to the HSM and log each signing operation with the operator identity and key reference
E.Configure the HSM to allow a shared service account to perform signing so that automation is not interrupted
AnswersC, D

Non-extractable keys that never leave the HSM boundary ensure the private key cannot be copied or exfiltrated, satisfying the key-protection requirement. Because signing happens inside the module, the plaintext key is never exposed to the host OS or application memory, which is exactly the property needed for a code-signing root of trust.

Why this answer

Marking keys non-extractable and performing operations inside the module protects the signing key from extraction, while per-operator authentication with operation logging provides attribution. Backup exports and shared service accounts undermine both goals, and FIPS validation is a module-level compliance attribute rather than an operational control.

Exam trap

The trap here is accepting FIPS validation as if it automatically guarantees non-extractable keys and operator attribution, when those depend on configuration and identity management.

209
MCQeasy

In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?

A.Software-defined perimeter
B.Defense-in-depth layering
C.Identity-centric access
D.Micro-segmentation
AnswerD

Micro-segmentation applies granular, workload-level security controls and policies between individual segments, so a compromised host cannot reach neighbouring workloads. This directly satisfies the zero trust requirement that no implicit trust exists between network segments, blocking lateral movement even after one segment falls.

Why this answer

Micro-segmentation divides a network into granular, isolated segments — often down to individual workloads or identities — and enforces policy between each segment so that compromise of one segment does not grant lateral movement to others. In zero trust, micro-segmentation is the enforcement mechanism that operationalizes 'never trust, always verify' at the network layer, typically using software-defined policies rather than physical firewalls.

Exam trap

CAS-005 often tests the confusion between micro-segmentation (the lateral-movement prevention mechanism) and SDP or defense-in-depth (broader principles), so candidates pick the more familiar-sounding architectural term.

How to eliminate wrong answers

Option A is wrong because a Software-Defined Perimeter (SDP) creates a logical boundary around resources and hides them from unauthorized users, but it does not itself prevent east-west lateral movement between internal segments the way micro-segmentation does. Option B is wrong because defense-in-depth is a layered security strategy (multiple overlapping controls) — it is a principle, not the specific mechanism that isolates segments. Option C is wrong because identity-centric access controls who can authenticate to what, but without network segmentation an attacker with valid credentials can still move laterally across a flat network.

210
MCQeasy

Which of the following best describes the purpose of the STIX and TAXII standards in threat intelligence sharing?

A.They are tools for analyzing malware behavior in a sandbox environment
B.They are used to automatically patch vulnerabilities based on threat feeds
C.They provide a framework for conducting incident response exercises
D.They standardize the format and exchange of cyber threat intelligence
AnswerD

STIX defines a structured language for describing threat indicators, actors and campaigns, while TAXII specifies the transport protocol for exchanging that content between systems. Together they give vendors and sharing communities a common format and delivery mechanism for cyber threat intelligence.

Why this answer

STIX (Structured Threat Information Expression) is a language for describing threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is a protocol for exchanging that intelligence. Together they enable automated sharing of threat data.

211
Multi-Selecthard

A security analyst is prioritizing remediation of vulnerabilities. Which three of the following factors should be considered when determining the risk level of a vulnerability? (Choose three.)

Select 3 answers
A.Availability of a public exploit
B.Vendor patch availability
C.Asset value or criticality
D.CVSS base score
E.Number of days since the vulnerability was discovered
AnswersA, C, D

A publicly available exploit raises the likelihood of active attacks, since attackers can readily obtain working code. This directly increases the vulnerability's risk level when prioritising remediation, alongside impact factors such as asset criticality and exposure.

Why this answer

Option A (Availability of a public exploit) is correct because a publicly available exploit, especially one weaponized in frameworks like Metasploit or CISA's KEV catalog, dramatically increases the likelihood of active exploitation and thus raises the risk level. Option C (Asset value or criticality) is correct because the same vulnerability poses far greater risk on a high-value asset such as a domain controller or PII database than on an isolated test machine, directly affecting impact. Option D (CVSS base score) is correct because it provides a standardized, vendor-agnostic metric of intrinsic severity based on exploitability and impact, forming a foundational input to risk prioritization.

Option B (Vendor patch availability) is not one of the three because a patch being available reduces exposure but does not itself define the inherent risk level of the vulnerability. Option E (Number of days since discovery) is not selected because age alone is a weak indicator; a long-unpatched critical flaw may be high risk, but time since discovery is not a standard risk-scoring factor like exploit availability, asset criticality, or CVSS.

Exam trap

CAS-005 often tests the difference between intrinsic vulnerability severity (CVSS) and contextual risk factors (asset criticality, exploit availability), so candidates must not treat patch availability or age as core risk determinants.

212
MCQhard

A security engineer is reviewing a CI/CD pipeline that builds a Docker image. The engineer notices that the Dockerfile uses a base image from a public registry, installs packages via apt-get without version pinning, and copies a private SSH key into the image. Which of the following vulnerabilities is MOST directly introduced by this practice?

A.Use of untrusted base image
B.Privilege escalation via SUID binaries
C.Exposure of sensitive credentials in the image layers
D.Dependency confusion from unpinned packages
AnswerC

Why this answer

Copying a private SSH key into a Docker image embeds the credential in one of the image's layers. Even if the key is deleted in a later layer, it remains accessible via `docker history` or by pulling the intermediate layers, directly exposing sensitive credentials to anyone who can access the image.

Exam trap

The CAS-004 exam often tests the misconception that deleting a file in a later Docker layer removes it from the image, when in fact the underlying layer still contains the sensitive data.

Why the other options are wrong

A

While a risk, it's not as directly exploitable as an exposed private key.

B

No indication of SUID; the main issue is secret leakage.

D

Unpinned packages are a supply chain risk but not as immediate as credential exposure.

213
MCQeasy

An organization wants to implement a zero-trust architecture for remote access. Which of the following is the MOST important component?

A.RAID 5
B.Syslog server
C.VPN concentrator
D.Micro-segmentation
AnswerD

Micro-segmentation enforces zero trust by dividing the network into isolated zones with granular, workload-level policies, so lateral movement after compromise is contained. For remote access, it satisfies the requirement that no user or device is implicitly trusted once inside the perimeter.

Why this answer

Micro-segmentation is the most important component for zero-trust remote access because it enforces granular, identity-based access controls that limit lateral movement within the network. Unlike perimeter-based models, zero-trust assumes no implicit trust, and micro-segmentation ensures that even after authentication, each remote session is isolated to only the specific resources required, reducing the attack surface.

Exam trap

The trap here is that candidates often mistake a VPN concentrator as the core of zero-trust remote access because it provides encryption and authentication, but zero-trust requires micro-segmentation to enforce least-privilege access and prevent lateral movement, which a traditional VPN alone cannot achieve.

How to eliminate wrong answers

Option A (RAID 5) is wrong because it is a disk redundancy technology used for fault tolerance and data protection, not for access control or network segmentation, and has no role in zero-trust architecture. Option B (Syslog server) is wrong because it is a centralized logging tool for event collection and analysis, which supports monitoring but does not enforce access policies or segmentation required for zero-trust. Option C (VPN concentrator) is wrong because while it provides encrypted tunnels for remote access, it typically operates on a perimeter-based model and does not inherently enforce micro-segmentation or continuous verification, making it insufficient for a zero-trust architecture.

214
MCQmedium

A security engineer is configuring a SIEM and wants to reduce false positives while ensuring that real attacks are detected. Which of the following approaches would best achieve this balance?

A.Aggregate all logs from all sources and create a single correlation rule for each attack type.
B.Use the default correlation rules provided by the SIEM vendor without modification.
C.Block all traffic from external IP addresses that are not on the organization's whitelist.
D.Tune correlation rules based on the organization's asset inventory, network architecture, and threat intelligence.
AnswerD

Correlation rules tuned against asset inventory, network architecture and threat intelligence align detection logic with what is genuinely anomalous for this environment. This satisfies the balance constraint by suppressing benign activity specific to the organisation while preserving detection of real attacks.

Why this answer

Tuning correlation rules to the organization's specific asset inventory, network architecture, and threat intelligence directly reduces false positives by filtering out irrelevant events while ensuring that real attacks against known assets are detected. This approach leverages contextual knowledge to adjust thresholds, exclude noise, and prioritize alerts that match the actual attack surface, achieving the desired balance between sensitivity and specificity.

Exam trap

The trap here is that candidates often confuse network security controls (like blocking IPs) with SIEM tuning techniques, or assume that default rules or aggregation alone can achieve optimal detection without contextual customization.

How to eliminate wrong answers

Option A is wrong because aggregating all logs from all sources into a single correlation rule for each attack type ignores the need for context-specific tuning, leading to excessive noise and false positives from irrelevant or duplicate events. Option B is wrong because using default correlation rules without modification fails to account for the organization's unique environment, resulting in either missed attacks (if rules are too narrow) or overwhelming false positives (if rules are too broad). Option C is wrong because blocking all traffic from external IPs not on a whitelist is a network access control measure, not a SIEM tuning technique, and it would disrupt legitimate business traffic while not addressing false positives in detection logic.

215
Multi-Selectmedium

Which TWO of the following are essential elements of an effective data governance framework?

Select 2 answers
A.Data classification policies and procedures
B.Mandatory data localization requirements
C.Assignment of data stewardship roles
D.Automated breach notification system
E.Implementation of full-disk encryption on all endpoints
AnswersA, C

Data classification policies and procedures satisfy the framework's need to categorise information by sensitivity, enabling controls such as encryption, access restrictions and retention to be applied proportionately. Without classification, Microsoft Entra ID access policies and DLP rules cannot distinguish confidential data from public, so governance decisions lack the risk context they require.

Why this answer

Data classification policies and procedures (A) are essential because they define how data is categorized by sensitivity and value, which drives the controls, handling rules, and access decisions that the rest of the governance framework depends on. Assignment of data stewardship roles (C) is equally essential because governance requires clearly designated owners and stewards who are accountable for data quality, protection, and lifecycle management across business and IT domains. Together, classification and stewardship form the core of an effective framework by establishing both what must be protected and who is responsible for it.

The other options do not belong: mandatory data localization (B) is a jurisdiction-specific regulatory constraint rather than a universal governance element, an automated breach notification system (D) is an incident-response control, and full-disk encryption on all endpoints (E) is a technical safeguard rather than a governance essential.

Exam trap

CAS-005 often tests the confusion between governance elements (classification, stewardship, policy) and technical controls (encryption, breach notification) — candidates must distinguish accountability structures from implementation controls.

216
MCQmedium

You are the compliance officer for a financial institution that must adhere to the Payment Card Industry Data Security Standard (PCI DSS). During a quarterly vulnerability scan, you discover that several critical vulnerabilities in the cardholder data environment (CDE) were not remediated within the required 30-day window. Additionally, the most recent penetration test report shows that a segmentation control between the CDE and the corporate network is not functioning as intended. The next PCI DSS assessment is in two months. Which of the following remediation actions should be prioritized FIRST to maintain compliance?

A.Implement a compensating control for the segmentation failure and document it
B.Immediately patch all critical vulnerabilities in the CDE
C.Request an extension from the acquirer for the next assessment
D.Re-establish correct segmentation between CDE and corporate network
AnswerD

The failed segmentation control means the corporate network can reach the cardholder data environment, so cardholder data is exposed to systems outside PCI DSS scope. Restoring that boundary first re-establishes the scope-defining control the assessor will test, whereas patching overdue vulnerabilities leaves the CDE still reachable.

Why this answer

The segmentation control failure is the most critical issue because it directly undermines the scope of the PCI DSS assessment. If the CDE is not properly isolated from the corporate network, the entire corporate network could be considered in-scope for PCI DSS, drastically increasing compliance requirements. Re-establishing correct segmentation first restores the intended security boundary and reduces the risk of a non-compliant assessment in two months.

Exam trap

Candidates often prioritize patching critical vulnerabilities (Option B) because it seems urgent, but they overlook that a segmentation failure is a scope-breaking issue that must be resolved first to keep the CDE boundary intact. This question tests understanding of PCI DSS scope and the priority of remediating segmentation failures over individual vulnerabilities.

How to eliminate wrong answers

Option A is wrong because implementing a compensating control for segmentation failure is a secondary step that should only be considered after the primary control is restored; PCI DSS requires compensating controls to be robust and approved, but they do not replace the need to fix the underlying segmentation issue. Option B is wrong because while patching critical vulnerabilities is important, the segmentation failure is a more fundamental control that, if left broken, could invalidate the entire CDE scope and make the vulnerability scan results irrelevant. Option C is wrong because requesting an extension does not address the technical non-compliance; it merely postpones the assessment without fixing the root cause, and acquirers rarely grant extensions for known control failures.

217
MCQhard

A security analyst is investigating a security incident where an attacker gained unauthorized access to a server. The analyst reviews the server logs and finds the following entries: 'Accepted password for root from 192.168.1.100 port 22 ssh2' followed by 'session opened for user root by (uid=0)'. The analyst suspects the attacker used stolen credentials. Which of the following log sources would provide the MOST direct evidence of the attacker's activities after the initial access?

A.System call auditing logs (e.g., auditd).
B.Network flow data (NetFlow) from the server's switch.
C.Bash history file for the root user.
D.Authentication logs from the SSH service.
AnswerA

System call auditing logs, such as those generated by auditd on Linux, record detailed information about system calls, including process execution, file access, and network activity. They provide a comprehensive and tamper-resistant record of the attacker's actions after initial access. This is the most direct evidence for forensic analysis.

Why this answer

System call auditing logs, such as those from auditd, capture detailed system-level activities including process execution, file access, and network connections. They are tamper-resistant and provide a comprehensive record of the attacker's actions after initial access. Authentication logs only show login events, bash history can be altered, and NetFlow lacks host-based detail.

Exam trap

The trap here is assuming that bash history or authentication logs provide sufficient detail about post-exploitation activities, when in fact system call auditing offers more comprehensive and reliable evidence.

218
MCQmedium

A SOC team is implementing a SOAR platform to automate responses to phishing emails. The team wants to create a playbook that, upon detection of a phishing email, automatically quarantines the email from all mailboxes and blocks the sender's domain. Which type of playbook action is being described?

A.Advisory action
B.Manual action
C.Semi-automated action
D.Automated action
AnswerD

Automated actions execute without analyst intervention, which satisfies the stem's requirement that quarantine and domain blocking occur automatically upon detection. Unlike manual or semi-automated playbooks, this removes human approval from the response path, enabling immediate containment. Microsoft Entra ID and email security controls are invoked programmatically by the SOAR platform.

Why this answer

Automated response actions are executed by the SOAR platform without human intervention, such as quarantining and blocking.

219
MCQeasy

A security administrator needs to automate the process of revoking access for terminated employees across multiple cloud services. Which scripting approach would best minimize the risk of errors and ensure consistent execution?

A.Create a shell script that relies on environment variables containing API keys.
B.Use a configuration management tool like Ansible with a playbook that calls cloud provider modules using encrypted vault files for credentials.
C.Write a Python script using separate API calls for each service with hardcoded credentials.
D.Manually execute commands each time an employee is terminated.
AnswerB

Ansible playbooks execute idempotently across cloud modules, so revocations run consistently regardless of prior state, while encrypted vault files keep credentials out of plaintext. This minimises manual error and satisfies the consistent, secure execution requirement.

Why this answer

Ansible playbooks with encrypted vault files provide idempotent, repeatable automation across multiple cloud services without exposing credentials in plaintext. The use of dedicated cloud provider modules (e.g., aws_iam, gcp_iam) abstracts API complexities and ensures consistent revocation logic, minimizing human error compared to ad-hoc scripting.

Exam trap

The exam often tests the misconception that any scripting approach (e.g., Python or shell) is sufficient for automation, but the trap is that they ignore the critical need for secure credential management and idempotent execution, which configuration management tools like Ansible are specifically designed to provide.

How to eliminate wrong answers

Option A is wrong because relying on environment variables for API keys introduces a security risk (e.g., accidental exposure in logs or process listings) and lacks the centralized, encrypted credential management that vault files offer. Option C is wrong because hardcoded credentials in a Python script violate security best practices and make the script brittle; any credential rotation requires code changes, increasing error risk. Option D is wrong because manual execution is not automated, introduces human error, and cannot ensure consistent, timely revocation across multiple cloud services.

220
MCQmedium

A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?

A.Creating a single perimeter around the entire network
B.Isolating workloads at the virtual network interface level with granular security policies
C.Using VLANs to separate departments
D.Implementing a VPN for remote access
AnswerB

Micro-segmentation creates granular, workload-level security policies enforced at each virtual network interface, so lateral movement between workloads is blocked regardless of subnet boundaries. This satisfies zero trust's requirement to isolate individual workloads rather than trusting the network perimeter.

Why this answer

Micro-segmentation in a zero trust architecture isolates individual workloads at the virtual network interface level and enforces granular, per-workload security policies. This limits lateral movement because each workload becomes its own security zone, and traffic between workloads is explicitly allowed or denied based on identity and policy rather than network location. It is a foundational zero trust control that assumes no implicit trust based on being 'inside' the network.

Exam trap

The trap here is confusing traditional network segmentation (VLANs, subnets, perimeter firewalls) with micro-segmentation, which operates at the workload/vNIC level with granular per-workload policies.

How to eliminate wrong answers

Option A is wrong because a single perimeter around the entire network is the traditional castle-and-moat model that zero trust explicitly rejects — it assumes everything inside is trusted. Option C is wrong because VLANs provide coarse-grained Layer 2 segmentation by department, not the fine-grained, workload-level isolation and policy enforcement that micro-segmentation requires. Option D is wrong because a VPN for remote access only secures the transport path for remote users; it does not segment internal workloads or enforce east-west zero trust policies.

221
Multi-Selectmedium

A security engineer is deploying a wireless network for a corporate campus that must authenticate users with 802.1X and protect credentials from eavesdropping. The engineer configures a RADIUS server and WPA3-Enterprise. Which TWO additional configuration elements are required to establish a mutually authenticated, encrypted EAP tunnel before the supplicant's identity is exposed? (Choose two.)

Select 2 answers
A.An EAP method that establishes a TLS tunnel before transmitting the inner identity, such as EAP-TTLS or PEAP.
B.A preshared key distributed to all campus clients through group policy.
C.A server certificate issued by an internal CA and trusted by the supplicants.
D.WPA3-SAE on the access point to derive the pairwise master key from the passphrase.
E.A captive portal that redirects unauthenticated clients to a credential entry page.
AnswersA, C

EAP-TTLS and PEAP create an encrypted TLS tunnel using the server certificate, and the actual user identity and credentials are exchanged inside that tunnel. This protects the supplicant identity from passive eavesdroppers and prevents credential theft. A method that sends identity in the clear before the tunnel, such as EAP-MD5, does not meet the requirement.

Why this answer

A protected EAP deployment needs the supplicant to validate the authentication server via a trusted certificate, then negotiate a TLS tunnel in which the real identity and credentials travel. PEAP and EAP-TTLS both do this, whereas methods that expose identity before tunneling do not. Together the trusted server certificate and the tunneling EAP method deliver mutual authentication and credential protection.

Exam trap

The trap here is confusing WPA3-SAE, a personal-mode passphrase method, with WPA3-Enterprise 802.1X, which relies on certificates and a tunneling EAP method.

222
MCQmedium

An organization wants to implement passwordless authentication for its employees using FIDO2/WebAuthn. What is a primary security advantage of this approach over traditional password-based MFA?

A.It is resistant to phishing attacks because credentials are bound to the origin.
B.It eliminates the need for a second factor.
C.It allows users to reuse the same credential across multiple websites.
D.It does not require any client-side hardware.
AnswerA

FIDO2/WebAuthn credentials are cryptographically bound to the relying party's origin, so a credential registered for the genuine sign-in endpoint cannot be replayed against a look-alike phishing domain. This origin binding satisfies the stem's passwordless requirement while eliminating credential theft via reverse-proxy phishing kits such as Evilginx, which defeat OTP-based MFA.

Why this answer

FIDO2 uses public key cryptography; the private key never leaves the user's device, so phishing attacks cannot steal credentials. This provides strong resistance to phishing.

223
MCQhard

A security architect is designing a system that must provide confidentiality and integrity for data at rest and in transit. The organization wants to minimize the risk of key compromise and ensure that a single compromised key does not expose all data. Which key management strategy best meets these requirements?

A.Derive all encryption keys from a single password using PBKDF2
B.Use a single master key to encrypt all data, stored in a hardware security module (HSM)
C.Store all encryption keys in a centralized key vault without additional wrapping
D.Implement a hierarchical key management system with data encryption keys wrapped by key encryption keys
AnswerD

A hierarchical key management system uses unique data encryption keys (DEKs) for each data object or session, and wraps them with key encryption keys (KEKs). Compromise of one DEK exposes only the data it protects, not the entire dataset. This minimizes risk and meets the requirement that a single compromised key does not expose all data.

Why this answer

A hierarchical key management system with unique data encryption keys wrapped by key encryption keys ensures that compromise of one data key only affects the data it protects. This limits the blast radius and meets the requirement that a single compromised key does not expose all data. Other strategies create single points of failure.

Exam trap

The trap here is assuming that storing a single master key in an HSM or a centralized vault is sufficient, when in fact it creates a single point of failure that violates the requirement for key isolation.

224
MCQmedium

A security engineer is hardening a container image. Which practice is MOST effective in reducing the attack surface?

A.Running containers as root
B.Using a minimal base image
C.Adding antivirus software
D.Using the latest version of all packages
AnswerB

A minimal base image ships fewer packages, libraries and services, so fewer vulnerabilities and binaries are present for an attacker to exploit. This directly shrinks the attack surface, satisfying the hardening constraint more effectively than scanning or runtime monitoring alone.

Why this answer

Using a minimal base image (e.g., Alpine, Distroless) removes unnecessary packages and binaries, significantly reducing the attack surface. Running as root increases risk. Antivirus is not typical in containers.

Latest packages are good but do not reduce surface.

225
MCQmedium

A security team is hardening a Kubernetes cluster. Which resource should be used to define fine-grained rules for which pods can communicate with each other?

A.Admission Controller
B.PodSecurityPolicy
C.RBAC
D.NetworkPolicy
AnswerD

NetworkPolicy objects select pods via label selectors and enforce ingress and egress rules at layer 3/4, restricting traffic to explicitly permitted pod, namespace, or CIDR combinations. This satisfies the stem's requirement for fine-grained pod-to-pod communication control, which Kubernetes denies by default until a policy selects the pod.

Why this answer

NetworkPolicy is the Kubernetes resource used to define fine-grained rules for pod-to-pod communication. It acts as a firewall for pods, allowing or denying traffic based on labels, namespaces, and ports. This is essential for microsegmentation and hardening cluster security.

Exam trap

CAS-005 often tests the distinction between NetworkPolicy and other Kubernetes security resources like RBAC or PodSecurityPolicy, leading candidates to choose RBAC for network segmentation.

How to eliminate wrong answers

Option A is wrong because Admission Controllers are used to enforce policies during resource creation, not for runtime network communication. Option B is wrong because PodSecurityPolicy (deprecated in Kubernetes 1.21) defines security contexts for pods, not network rules. Option C is wrong because RBAC controls access to the Kubernetes API, not pod-to-pod traffic.

Page 2

Page 3 of 13

Page 4