Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 226–300

973 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
Multi-Selectmedium

An organization is deploying a cloud workload protection platform (CWPP). Which TWO capabilities are essential for protecting workloads in a hybrid cloud?

Select 2 answers
A.Security information and event management
B.Identity and access management
C.Data loss prevention
D.Runtime protection
E.Vulnerability management
AnswersD, E

Runtime protection continuously monitors executing workloads for malicious behaviour such as process injection or fileless attacks, then blocks or alerts in real time. This satisfies the hybrid cloud constraint because on-premises and cloud workloads share the same runtime threat surface, which static scanning alone cannot address.

Why this answer

Runtime protection (D) is essential because a CWPP must continuously monitor executing processes, detect malicious behavior such as fileless attacks or cryptomining, and block threats in real time across VMs, containers, and serverless workloads in hybrid environments. Vulnerability management (E) is equally essential since CWPPs must scan workloads for missing patches, misconfigurations, and known CVEs (e.g., via agents or agentless snapshots) to prioritize remediation before exploitation. Options A, B, and C, while valuable security disciplines, are typically delivered by SIEM, IAM, and DLP platforms respectively, and are not the defining workload-protection capabilities of a CWPP.

Exam trap

CAS-005 often tests whether candidates can distinguish CWPP's workload-centric capabilities (runtime protection, vulnerability management) from adjacent enterprise security domains (SIEM, IAM, DLP) that are frequently bundled in vendor marketing but are not core CWPP functions.

227
MCQhard

An organization wants to implement a privileged access management (PAM) solution to manage administrative credentials. They require that administrators request temporary access to privileged accounts and that these credentials are automatically rotated after each use. Which PAM approach best meets these requirements?

A.Password vaulting with checkout
B.Just-in-time access provisioning with credential rotation
C.Privileged account session management
D.Break-glass account procedures
AnswerB

Just-in-time access provisioning grants privileged accounts only for an approved, time-bound window, and credential rotation replaces the password after each session. Together these satisfy both stated requirements: temporary access on request and automatic rotation following use.

Why this answer

Option B is correct because just-in-time (JIT) access provisioning grants privileged credentials only for the duration of a task and automatically rotates or revokes them afterward, directly matching the requirement for temporary access with post-use rotation. This approach minimizes standing privileges and the attack surface. Password vaulting with checkout (A) provides temporary access but does not inherently rotate credentials after each use unless combined with rotation workflows.

Exam trap

CAS-005 often tests the confusion between password vaulting (which stores and checks out credentials) and JIT provisioning with rotation (which issues and automatically rotates credentials), causing candidates to pick vaulting when rotation after each use is explicitly required.

How to eliminate wrong answers

Option A is wrong because password vaulting with checkout typically checks out a credential for a period but does not guarantee automatic rotation after each use; the credential may remain valid until manually rotated. Option C is wrong because privileged account session management focuses on recording and monitoring sessions, not on issuing temporary credentials with automatic rotation. Option D is wrong because break-glass accounts are emergency, standing privileged accounts meant for disaster recovery, not for routine temporary access with rotation.

228
MCQmedium

The security engineer notices that SSH login attempts to 192.168.1.1 from the untrust zone are being blocked. Which policy misconfiguration is MOST likely causing this?

A.The application is incorrect
B.The source zone is not permitted
C.The log setting prevents connections
D.The destination address is incorrect
AnswerB

Security policy evaluates traffic by source and destination zone pair. If the untrust zone is absent from the permitted source zones on the rule matching 192.168.1.1, SSH traffic is dropped before any service or application check occurs.

Why this answer

The security engineer observes SSH login attempts from the untrust zone to 192.168.1.1 being blocked. In a typical firewall policy, the source zone must be explicitly permitted for traffic to be allowed. If the source zone 'untrust' is not included in the policy's source zone list, the firewall will drop the traffic regardless of other correct parameters.

This is the most likely misconfiguration because SSH traffic from the untrust zone is reaching the destination but being denied at the policy level.

Exam trap

A common misconception is that a correct destination address or application is sufficient for traffic to pass, when in fact the source zone must be explicitly permitted in the firewall policy.

How to eliminate wrong answers

Option A is wrong because the application (SSH, TCP port 22) is correctly identified in the logs, indicating the firewall recognizes the traffic; an incorrect application would cause a different behavior, such as misclassification but not outright blocking. Option C is wrong because log settings only control whether events are recorded, not whether connections are permitted or denied; blocking occurs due to policy rules, not logging configuration. Option D is wrong because the destination address 192.168.1.1 is reachable and the logs show attempts reaching it; an incorrect destination address would result in traffic being routed elsewhere or dropped at a different stage, not specifically blocked by policy.

229
MCQmedium

An organization discovers that a third-party vendor has a subcontractor that processes its data. The organization did not have a contract with the subcontractor. This is an example of which type of risk?

A.Residual risk
B.Third-party risk
C.Fourth-party risk
D.Supply chain risk
AnswerC

Fourth-party risk arises when a subcontractor, contracted by your direct vendor, handles your data without privity of contract with you. The stem's defining constraint — no contract exists between the organisation and the subcontractor — matches this exactly, since the exposure flows through the third party rather than directly.

Why this answer

Fourth-party risk refers to the risk introduced by a vendor's subcontractors or sub-processors — parties with whom the organization has no direct contractual relationship. Since the organization has no contract with the subcontractor, this is a classic fourth-party risk scenario.

Exam trap

CAS-005 often tests the distinction between third-party and fourth-party risk — candidates pick third-party risk because a vendor is involved, missing that the absence of a direct contract with the subcontractor is the defining factor for fourth-party risk.

How to eliminate wrong answers

Option A is wrong because residual risk is the risk that remains after controls have been applied, not a risk arising from a subcontractor relationship. Option B is wrong because third-party risk refers to risks from direct vendors/partners with whom the organization has a contract — here the organization has no contract with the subcontractor, so it is one level removed. Option D is wrong because supply chain risk is a broader umbrella term that encompasses third- and fourth-party risks; the question asks for the specific type exemplified by a subcontractor without a direct contract, which is fourth-party risk.

230
Multi-Selecteasy

Which TWO of the following are best practices for securing a database server?

Select 2 answers
A.Install sample databases for testing
B.Enable remote access from any IP
C.Disable default accounts
D.Use encrypted connections
E.Use simple passwords for ease of administration
AnswersC, D

Default and sample accounts often ship with well-known credentials or excessive privileges, giving attackers an easy entry point. Disabling or removing them eliminates that unnecessary attack surface before any other database hardening measure is applied.

Why this answer

Option C is correct because default accounts (such as Oracle's SCOTT/TIGER, MySQL's anonymous users, or SQL Server's sa) are widely known to attackers and should be disabled, renamed, or have their passwords changed to eliminate an easy entry point. Option D is correct because using encrypted connections (e.g., TLS/SSL for MySQL, PostgreSQL, and SQL Server, or Oracle Native Network Encryption) protects credentials and data in transit from eavesdropping and man-in-the-middle attacks. Option A is not a best practice because sample databases often contain known schemas, default credentials, and unnecessary attack surface that should be removed from production servers.

Option B is wrong because enabling remote access from any IP (0.0.0.0/0) exposes the database to the entire internet; access should be restricted to specific trusted hosts or subnets via firewall rules and bind-address settings. Option E is incorrect because simple passwords are trivially brute-forced or guessed; strong password policies, account lockout, and multi-factor authentication are the recommended controls.

Exam trap

CompTIA CASP+ often tests the misconception that sample databases are harmless for testing, but in a production security context, any unnecessary software or data increases risk and should be removed.

231
MCQhard

An organization has implemented a zero-trust architecture for its mobile workforce. Employees use company-managed smartphones to access internal applications through a reverse proxy. Recently, users report that they are frequently prompted to re-authenticate, causing workflow interruptions. The security team wants to maintain zero-trust principles while improving the user experience. Analysis shows that session tokens are being revoked after a short idle timeout. Which adjustment should the security team implement to balance security and usability?

A.Extend the session token expiration time to reduce the frequency of re-authentication
B.Replace token-based authentication with certificate-based authentication and revoke certificates based on device posture
C.Reduce the number of authentication factors required for re-authentication
D.Implement short-lived access tokens with refresh tokens that are automatically rotated
AnswerD

Short-lived access tokens with rotated refresh tokens preserve zero-trust verification without forcing repeated interactive sign-ins. The refresh token silently renews access after idle periods, so the short idle timeout no longer triggers full re-authentication. This satisfies the stem's constraint of maintaining zero-trust principles while reducing workflow interruptions for the mobile workforce.

Why this answer

Implementing short-lived access tokens with refresh tokens that are automatically rotated aligns with zero-trust principles by minimizing token exposure time while allowing seamless re-authentication without user intervention. The refresh token is used to obtain new access tokens transparently, reducing workflow interruptions. Option A is incorrect because extending token lifetime increases the risk of token theft and misuse.

Option B is incorrect because certificate-based authentication does not inherently reduce re-authentication frequency and adds management complexity. Option C is incorrect because reducing authentication factors weakens security and violates zero-trust principles. Option D is correct as it balances security and usability by providing continuous authentication through automatic token rotation.

232
Multi-Selecthard

A security governance team is defining the scope of its enterprise risk management (ERM) program. Which TWO of the following activities are core components of ERM as described in frameworks such as ISO 31000 and COSO ERM? (Choose two.)

Select 2 answers
A.Performing technical vulnerability scans on all production servers weekly
B.Maintaining an inventory of all hardware assets with purchase dates
C.Integrating risk considerations into strategic planning and objective setting
D.Establishing risk appetite and tolerance statements approved by leadership
E.Encrypting all databases containing personally identifiable information
AnswersC, D

COSO ERM emphasizes that risk management must be integrated with strategy-setting and performance, not treated as a separate compliance exercise. Embedding risk into strategic planning ensures objectives are pursued within the organization's risk appetite. This integration is a defining core component of ERM.

Why this answer

ERM frameworks such as ISO 31000 and COSO ERM center on governance, strategy integration, and risk appetite. Defining risk appetite and tolerance gives leadership a benchmark for decisions, while integrating risk into strategic planning ensures objectives are set with awareness of uncertainty. Technical controls and asset inventories support risk management but are not core ERM components themselves.

Exam trap

The trap here is equating ERM with operational security activities like vulnerability scanning or encryption, which are controls rather than enterprise risk governance components.

233
MCQhard

A company's security team is reviewing its risk register. A risk related to an outdated internal application has been assigned an owner, but the owner has taken no action for two quarters. The Chief Information Security Officer wants to ensure the risk is tracked and escalated appropriately. Which action should the security team take first?

A.Immediately accept the risk on behalf of the business owner to close the item
B.Remove the risk from the register because the owner has implicitly accepted it by doing nothing
C.Escalate the overdue risk to the risk owner's management and the risk committee with the current status
D.Transfer the risk to an insurance carrier and mark the register item as resolved
AnswerC

When a risk owner fails to act, the security team's role is to escalate through governance channels so that accountable leadership can make a decision. Providing the risk committee with the current status, potential impact, and lack of progress ensures the risk remains visible and that a timely treatment decision is made. This preserves accountability and aligns with risk management practices that require escalation when treatment deadlines are missed.

Why this answer

The security team should escalate the overdue risk to the owner's management and the risk committee with current status. Escalation preserves accountability, keeps the risk visible, and forces a timely treatment decision by those with authority. Accepting, deleting, or unilaterally transferring the risk would bypass governance and hide the exposure rather than manage it, which is why escalation is the correct first action.

Exam trap

The trap here is treating an owner's silence as implicit risk acceptance, when governance requires an explicit, documented decision by the accountable party.

234
Multi-Selecthard

A security operations center (SOC) is evaluating a new EDR solution. Which three capabilities are essential for effective endpoint detection and response? (Select THREE).

Select 3 answers
A.Network firewall management
B.Behavioral analysis to detect anomalies
C.Automated containment of malicious processes
D.Real-time monitoring of endpoint activities
E.Vulnerability scanning of endpoints
AnswersB, C, D

Behavioural analysis continuously baselines normal endpoint activity and flags deviations, catching fileless malware and living-off-the-land techniques that signature matching misses. This satisfies the SOC's need for detection beyond known indicators, enabling EDR to surface novel threats in real time rather than waiting for updated signatures.

Why this answer

Option B is correct because behavioral analysis is the core of EDR: it baselines normal process, file, registry, and network activity and flags deviations (e.g., anomalous parent-child process chains, suspicious PowerShell usage) that signature-based tools miss, enabling detection of unknown or fileless threats. Option C is correct because EDR must not only detect but respond; automated containment capabilities such as isolating the host from the network, terminating or suspending malicious processes, and quarantining files are essential to stop lateral movement and reduce dwell time. Option D is correct because continuous, real-time telemetry collection from endpoints (process creation, command-line arguments, file and registry modifications, network connections) is the foundational data source that feeds both detection analytics and post-incident investigation.

Option A is not correct because network firewall management is a network-perimeter control, not an endpoint detection and response capability, even though EDR may integrate with firewalls for containment. Option E is not correct because vulnerability scanning identifies known weaknesses for patch prioritization and is typically a separate VM tool, not a core EDR detection-and-response function.

Exam trap

The trap is selecting vulnerability scanning or firewall management because they sound security-related, but the exam expects you to distinguish EDR's host-centric detect/respond triad from adjacent network or vulnerability management functions.

235
MCQmedium

A security architect is designing a network for a company that requires high availability and confidentiality for data in transit between two data centers. The company wants to use a protocol that operates at the network layer, supports perfect forward secrecy (PFS), and can be implemented in hardware for high throughput. Which protocol BEST meets these requirements?

A.IPsec with IKEv2
B.Secure Shell (SSH) tunneling
C.Datagram Transport Layer Security (DTLS)
D.Transport Layer Security (TLS) 1.3
AnswerA

IPsec operates at the network layer and can be implemented in hardware for high throughput. IKEv2 supports perfect forward secrecy through Diffie-Hellman key exchange, ensuring that compromise of long-term keys does not compromise past session keys. This combination provides confidentiality and high availability for data in transit between data centers.

Why this answer

IPsec with IKEv2 operates at the network layer, supports perfect forward secrecy through Diffie-Hellman, and is widely implemented in hardware for high throughput. The other protocols either operate at higher layers or are not typically hardware-accelerated for site-to-site network-layer encryption.

Exam trap

The trap here is selecting a transport-layer protocol like TLS 1.3 because it also supports perfect forward secrecy, without considering the network-layer and hardware acceleration requirements.

236
Multi-Selectmedium

A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and new containerized workloads. The architect must reduce lateral movement while minimizing disruption to existing traffic flows. (Choose two.)

Select 2 answers
A.Apply identical static access control lists to every subnet regardless of the workloads hosted there.
B.Replace all existing firewalls with a single perimeter appliance that inspects north-south traffic at the data center edge.
C.Disable all inter-tier communication by default and require application teams to open ports manually after each deployment.
D.Map application dependencies and traffic flows before defining segmentation policy so that legitimate communication paths are preserved.
E.Enforce segmentation policy at the workload level using identity-based rules rather than relying solely on network address ranges.
AnswersD, E

Dependency and flow mapping establishes which systems genuinely need to communicate, which is the prerequisite for writing allow-list policy that does not break production. Without this baseline, microsegmentation rules either block required traffic or remain so permissive that lateral movement is still possible.

Why this answer

Effective microsegmentation starts with understanding real traffic dependencies, then enforces least-privilege rules anchored to workload identity so policy survives address churn in mixed legacy and container environments. Blanket deny-with-manual-opening, perimeter-only appliances, and uniform static lists either disrupt operations or fail to constrain east-west movement.

Exam trap

The trap here is equating perimeter firewalling or uniform ACLs with microsegmentation, when the objective is workload-level east-west control.

237
Multi-Selecthard

A security architect at a financial services firm is designing a microsegmentation strategy for a data center running both virtual machines and containerized workloads. The architect must reduce east-west lateral movement and enforce least-privilege communication between tiers. Which TWO design elements are most appropriate? (Choose two.)

Select 2 answers
A.Enable promiscuous-mode intrusion detection on a SPAN port for all internal traffic.
B.Use a service mesh with mutual TLS and authorization policies for service-to-service communication.
C.Deploy a single perimeter firewall with rules based on source and destination IP ranges.
D.Rely on VLAN segmentation between application tiers to control east-west traffic.
E.Apply host-based firewall policies tied to workload identity rather than IP address.
AnswersB, E

A service mesh with mutual TLS authenticates both ends of every service connection using cryptographic identities and enforces authorization policies for which services may call which endpoints. This directly limits east-west movement between containerized tiers and provides visibility into service dependencies, complementing host-based controls for workloads that sit outside the mesh.

Why this answer

Identity-based host firewall policies and a service mesh with mutual TLS and authorization policies both enforce least-privilege communication at the workload level. Identity-based rules survive IP changes across VMs and containers, while the mesh cryptographically authenticates and authorizes service-to-service calls. Together they reduce east-west lateral movement, whereas perimeter, VLAN, and monitoring-only controls cannot enforce per-workload segmentation.

Exam trap

The trap here is treating VLANs or a perimeter firewall as microsegmentation, when true microsegmentation enforces policy at the individual workload using identity rather than network location.

238
Multi-Selectmedium

A security architect is designing a zero trust network access (ZTNA) solution for a company with remote workers. The architect must ensure that access to internal applications is granted based on user identity and device posture, without exposing applications to the internet. Which TWO design elements are essential for this ZTNA implementation? (Choose two.)

Select 2 answers
A.An outbound-only connection from the application to the trust broker, so the application is never directly exposed to the internet.
B.A public DNS record that maps each internal application to a routable IP address for direct access.
C.A next-generation firewall (NGFW) in the DMZ that performs deep packet inspection on all inbound traffic to internal applications.
D.A site-to-site VPN between each remote worker's home router and the corporate data center.
E.A trust broker that authenticates users and devices and evaluates access policies before granting access to applications.
AnswersA, E

ZTNA typically uses outbound-only connections from the application to the trust broker, which hides the application from the internet and prevents inbound exposure. This design ensures that users connect through the broker and that the application remains protected behind the broker's policy enforcement.

Why this answer

ZTNA requires a trust broker to authenticate users and devices and enforce access policies, and it relies on outbound-only connections from applications to the broker to avoid exposing them to the internet. Together, these elements ensure that access is granted based on identity and device posture rather than network location, which is the core of zero trust.

Exam trap

The trap here is assuming that a traditional VPN or firewall can provide zero trust access, when in fact ZTNA requires a brokered, identity-aware connection that does not expose applications to the internet.

239
Multi-Selecthard

During an incident response, a team is prioritizing containment actions. Which THREE of the following actions should be taken to contain the incident effectively?

Select 3 answers
A.Blocking malicious IP addresses at the firewall
B.Notifying law enforcement
C.Collecting forensic images of affected systems
D.Isolating affected systems from the network
E.Disabling compromised user accounts
AnswersA, D, E

Blocking malicious IP addresses at the firewall satisfies the containment constraint by severing the network path attackers use for command-and-control and lateral movement. Perimeter filtering stops inbound exploitation attempts and outbound callbacks immediately, limiting blast radius while forensic investigation continues. This is a standard, reversible containment action that preserves evidence on affected hosts.

Why this answer

Option A is correct because blocking malicious IP addresses at the firewall is a direct, immediate containment action that severs the attacker's command-and-control or exfiltration channel at the network perimeter, preventing further ingress or egress. Option D is correct because isolating affected systems from the network (e.g., VLAN quarantine, disabling switch ports, or pulling the cable) stops lateral movement and prevents the compromised hosts from infecting other assets while preserving their state for later analysis. Option E is correct because disabling compromised user accounts (e.g., resetting credentials and revoking sessions/tokens in Active Directory or the IdP) contains the incident by cutting off the attacker's authenticated access and halting further abuse of those identities.

Option B does not belong because notifying law enforcement is an external communication/coordination step, not a technical containment action, and it typically occurs after containment or per legal guidance. Option C does not belong because collecting forensic images is evidence preservation and investigation work that, while important, is not itself a containment measure and is often performed after systems are isolated.

Exam trap

CAS-005 often tests the distinction between containment and other incident response phases, and candidates frequently select evidence collection or legal notification as containment actions when they are actually part of investigation or communication.

240
MCQmedium

A security analyst is reviewing a suspicious PowerShell script found on a compromised host. The script contains a long string of base64-encoded text and uses the `-EncodedCommand` parameter. The analyst wants to understand the script's functionality without executing it. Which of the following actions should the analyst take FIRST?

A.Run the script in a sandboxed environment to observe its behavior.
B.Submit the script's hash to VirusTotal for threat intelligence.
C.Use a debugger to step through the script line by line.
D.Decode the base64 string using a tool like CyberChef or PowerShell's FromBase64String method.
AnswerD

Decoding the base64 string reveals the actual PowerShell commands, allowing the analyst to understand the script's intent without execution. This is a safe, static analysis step that can quickly expose malicious actions like downloading payloads or establishing persistence. It is the logical first step before any dynamic analysis or containment.

Why this answer

The most efficient and safe first step is to decode the base64-encoded command to reveal the underlying PowerShell code. This static analysis technique requires no execution and often immediately exposes the script's purpose, such as downloading a payload or creating a scheduled task. It allows the analyst to make informed decisions about further investigation or containment without risking the environment.

Exam trap

The trap here is assuming that dynamic analysis or sandboxing is always the best first step, when static decoding can provide immediate insight without any risk.

241
MCQmedium

A security architect is designing a cloud security strategy for a company that uses multiple cloud providers. The architect needs a solution that provides visibility into cloud application usage, enforces security policies, and protects data. Which technology is most appropriate?

A.Cloud Workload Protection Platform (CWPP)
B.Cloud Access Security Broker (CASB)
C.Cloud Security Posture Management (CSPM)
D.Secure Access Service Edge (SASE)
AnswerB

A CASB sits between users and multiple cloud providers, delivering the required visibility into sanctioned and unsanctioned application usage, policy enforcement, and data protection such as DLP and encryption. This directly satisfies the multi-cloud visibility and policy constraint in the stem.

Why this answer

A Cloud Access Security Broker (CASB) sits between cloud consumers and cloud providers to provide visibility into cloud application usage, enforce security policies (e.g., DLP, access control), and protect data across multiple cloud services. It is specifically designed for multi-cloud visibility and policy enforcement.

Exam trap

CAS-005 often tests the overlap between CASB, CSPM, and CWPP; candidates must distinguish CASB's focus on application usage and data policy from CSPM's focus on configuration compliance.

How to eliminate wrong answers

Option A is wrong because CWPP focuses on protecting workloads (VMs, containers, serverless) at the compute layer, not on providing visibility into cloud application usage or enforcing SaaS policies. Option C is wrong because CSPM focuses on identifying misconfigurations in cloud infrastructure (e.g., open S3 buckets, overly permissive IAM) rather than monitoring application usage or enforcing data policies across SaaS. Option D is wrong because SASE converges networking and security (SD-WAN, SWG, ZTNA, CASB) into a cloud-delivered service, but the question specifically asks for visibility into cloud application usage and policy enforcement, which is the CASB function, not the entire SASE stack.

242
MCQhard

A security architect is designing a data loss prevention (DLP) program for a global enterprise that uses Microsoft 365, endpoint devices, and a custom web application. The requirement is to detect and block sensitive data exfiltration across all three channels while minimizing false positives caused by legitimate business data that resembles regulated data. The architect needs a control that classifies data consistently and applies policy at the point of egress. Which of the following BEST meets this requirement?

A.Require full-disk encryption on all endpoints and enforce TLS for all data in transit to external destinations.
B.Implement database activity monitoring on all repositories and alert on bulk read operations of sensitive tables.
C.Apply sensitivity labels with unified DLP policies that use exact data match and trainable classifiers across Microsoft 365, endpoints, and the custom application.
D.Deploy network DLP appliances at each internet egress point and configure regex patterns for regulated data types.
AnswerC

Sensitivity labels persist with the data and provide consistent classification across Microsoft 365, endpoints, and integrated applications. Unified DLP policies using exact data match and trainable classifiers reduce false positives by matching actual regulated records and learning business context, and they enforce policy at egress points across all three channels.

Why this answer

Sensitivity labels with unified DLP policies classify data persistently and apply consistent enforcement across Microsoft 365, endpoints, and integrated applications. Exact data match and trainable classifiers improve accuracy by matching real regulated records and learning business context, which reduces false positives while blocking exfiltration at egress points across all channels.

Exam trap

The trap here is assuming that network DLP with regex patterns is sufficient for cross-channel protection, when it lacks persistent classification and generates false positives that only exact data match and trainable classifiers can mitigate.

243
MCQeasy

A small business is designing a defense-in-depth strategy for its e-commerce website. The web server is hosted in a cloud provider and handles credit card transactions. Which of the following additional controls best complements the existing firewall and IDS?

A.Set up a security information and event management (SIEM) system
B.Add a load balancer with SSL termination
C.Implement a web application firewall (WAF)
D.Deploy a network-based antivirus on the web server
AnswerC

A web application firewall inspects HTTP/S traffic, filtering SQL injection and cross-site scripting that a network firewall and IDS cannot parse at layer 7. This directly protects the credit card transaction data the e-commerce site handles, satisfying the stem's requirement for a complementary control at the application layer.

Why this answer

A web application firewall (WAF) is the correct complement because it specifically protects against application-layer attacks (e.g., SQL injection, cross-site scripting) that a network firewall and IDS cannot block. Since the e-commerce site handles credit card transactions, a WAF is critical for PCI DSS compliance and to filter malicious HTTP/HTTPS traffic targeting the web application logic.

Exam trap

The trap here is that candidates confuse a SIEM or load balancer with a security control, but the question specifically asks for a control that 'complements' existing firewall and IDS by addressing the missing application-layer protection, which only a WAF provides.

How to eliminate wrong answers

Option A is wrong because a SIEM system aggregates and correlates logs for analysis and alerting, but it does not actively block attacks; it is a detection and monitoring tool, not a preventive control. Option B is wrong because a load balancer with SSL termination distributes traffic and offloads encryption, but it does not inspect application-layer payloads for malicious content; it provides availability and performance, not security against web attacks. Option D is wrong because network-based antivirus scans for malware signatures at the network level, but it cannot inspect or block application-layer attacks like SQL injection or XSS, and it is redundant with host-based antivirus already assumed on the server.

244
Drag & Dropmedium

Drag and drop the steps to implement a DLP policy to prevent credit card data exfiltration via email into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DLP implementation: classify data, create policy, define match condition, set action, then enable and test.

245
MCQhard

A security analyst is investigating a malware sample that uses the Windows API function NtQueryInformationProcess to detect if it is being debugged. The analyst wants to understand how this anti-debugging technique works and how to bypass it. Which of the following statements accurately describes the technique and a potential bypass?

A.The malware checks the ProcessDebugFlags field, which is zero when a debugger is attached. A bypass is to use a kernel-mode debugger to avoid detection.
B.The malware checks the ProcessDebugPort field, which is non-zero when a debugger is attached. A bypass is to patch the return value of the API call.
C.The malware checks the ProcessBasicInformation field, which contains a pointer to the PEB. A bypass is to modify the PEB directly.
D.The malware checks the ProcessDebugObjectHandle field, which is zero when a debugger is attached. A bypass is to set a breakpoint on the API and modify the handle.
AnswerB

NtQueryInformationProcess with ProcessDebugPort (0x07) returns a non-zero port when a debugger is present. Malware uses this to detect debugging. Bypassing can be done by patching the API to always return zero or using a plugin that hides the debug port. This is a known anti-debugging technique, and the described bypass is effective in many cases.

Why this answer

The correct answer describes the ProcessDebugPort technique. When a debugger is attached, the system creates a debug port, and NtQueryInformationProcess with ProcessDebugPort returns a non-zero value. Malware can check this to detect debugging.

A common bypass is to patch the API function to always return zero for that information class, effectively hiding the debug port. This is a standard anti-anti-debugging approach used in malware analysis.

Exam trap

The trap here is confusing the various ProcessInformationClass values and their return conditions, such as when they indicate a debugger is present.

246
Multi-Selectmedium

A security architect is designing a PKI for a large enterprise that issues certificates to thousands of users and devices. The architect wants to implement a mechanism to efficiently check certificate revocation status without requiring clients to download a full CRL. Which TWO technologies should be considered?

Select 2 answers
A.CRL distribution points
B.Certificate transparency logs
C.OCSP stapling
D.Online Certificate Status Protocol (OCSP)
E.Delta CRL
AnswersC, D

OCSP stapling lets the server fetch a signed, timestamped revocation response and present it during the TLS handshake, so clients avoid downloading the full CRL or contacting the OCSP responder directly. This satisfies the stem's constraint of efficient revocation checking without full CRL downloads, while reducing latency and privacy leakage.

Why this answer

Option C (OCSP stapling) is correct because it lets the server obtain a signed, time-stamped OCSP response from the CA and present it during the TLS handshake, so clients get revocation status without contacting the OCSP responder themselves, reducing latency and load. Option D (Online Certificate Status Protocol, OCSP) is correct because it is the standard protocol for querying a responder about a single certificate's revocation status, returning good, revoked, or unknown, which avoids downloading an entire CRL. Option A (CRL distribution points) is not appropriate here because it points clients to full CRLs, which is exactly the bulk-download behavior the architect wants to avoid.

Option B (certificate transparency logs) is unrelated to revocation checking; CT logs provide public auditability of issued certificates, not revocation status. Option E (delta CRL) still relies on CRL downloads (a base CRL plus deltas), so it does not meet the goal of avoiding full CRL retrieval.

247
MCQhard

A security architect is designing segmentation for a manufacturing network where legacy programmable logic controllers cannot be patched or run endpoint agents. The architect wants to prevent a compromised business workstation from initiating connections to the controllers while still allowing the controllers to send telemetry to a historian server. Which of the following design elements best achieves this objective?

A.Network address translation between the business network and the controller subnet with private addressing
B.An intrusion prevention system deployed inline on the business network with industrial protocol signatures
C.A unidirectional gateway enforcing one-way data flow from the controller network out to the historian
D.A stateful firewall rule permitting any internal source to reach the controller subnet on the industrial protocol port
AnswerC

A unidirectional gateway physically or logically enforces one-way traffic, so controllers can emit telemetry toward the historian while no path exists for inbound connections from the business network. This directly satisfies the requirement to block workstation-initiated access to unpatched controllers. It is purpose-built for this exact industrial constraint, where endpoints cannot defend themselves.

Why this answer

A unidirectional gateway enforces that data can flow only from the protected controller network outward, so telemetry reaches the historian while no inbound path exists from the business network. This protects unpatched controllers that cannot run agents or be hardened, precisely matching the constraint that a compromised workstation must never initiate connections to them.

Exam trap

The trap here is relying on inspection-based controls like IPS or permissive firewall rules, which still allow a compromised host to initiate sessions with controllers.

248
MCQmedium

A security engineer is implementing a solution to protect sensitive data stored in a database. The requirement is to ensure that even if the database files are stolen, the data cannot be read without access to a hardware security module (HSM). Which of the following should the engineer implement?

A.Application-level encryption with keys derived from a user password
B.Column-level encryption with keys stored in a configuration file
C.Transparent Data Encryption (TDE) with keys stored in an HSM
D.Disk encryption on the database server with keys stored in the operating system keyring
AnswerC

TDE encrypts the database files at rest, and storing the encryption keys in an HSM ensures that the keys are protected and never exposed in software. Without the HSM, the stolen files cannot be decrypted, meeting the requirement. This approach provides strong protection for data at rest with hardware-based key management.

Why this answer

Transparent Data Encryption with keys stored in an HSM ensures that the encryption keys are protected by hardware and never exposed in software or configuration files. This means that even if the database files are stolen, decryption is impossible without the HSM. The other options either store keys insecurely or do not provide hardware-based key protection.

Exam trap

The trap here is assuming that any encryption at rest is sufficient, without considering where the keys are stored and whether they are hardware-protected.

249
Drag & Dropmedium

Drag and drop the steps to set up a SIEM alert for a failed login threshold into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

SIEM rule creation: identify log source, create rule, set threshold, configure response, then enable and test.

250
MCQeasy

A cloud-based application uses serverless functions to process user uploads. Which of the following is the most effective way to limit the attack surface of the function?

A.Encrypt all data at rest using KMS
B.Enable detailed logging and monitoring
C.Place a web application firewall (WAF) in front of the function
D.Minimize the function's dependencies and reduce its code footprint
AnswerD

Fewer dependencies and less code shrink the vulnerable surface available to attackers, since each library and line is potential exploit material. This directly limits the attack surface of the serverless function, satisfying the stem's constraint without relying on runtime controls.

Why this answer

Minimizing the function's dependencies and reducing its code footprint directly shrinks the attack surface by eliminating unnecessary libraries, packages, and code paths that could contain vulnerabilities. In serverless architectures, the function's runtime environment is ephemeral and stateless, so every added dependency increases the risk of supply-chain attacks or unpatched flaws. This aligns with the principle of least functionality, which is more effective than perimeter controls for serverless compute.

Exam trap

CompTIA often tests the misconception that perimeter defenses like WAFs or encryption are the primary way to secure serverless functions, when in fact the shared responsibility model places code-level attack surface reduction as the most effective control for serverless compute.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest with KMS protects data confidentiality but does not reduce the attack surface of the function itself; it addresses a different threat (data breach) and does not prevent exploitation of code vulnerabilities. Option B is wrong because enabling detailed logging and monitoring improves detection and incident response but does not proactively limit the attack surface; it is a detective control, not a preventive one. Option C is wrong because placing a WAF in front of the function only filters HTTP-level attacks (e.g., SQLi, XSS) and does not reduce the function's code or dependency attack surface; serverless functions often have multiple triggers (e.g., S3 events, queues) that bypass the WAF entirely.

251
MCQmedium

An organization is adopting a DevSecOps approach and wants to integrate security early in the development lifecycle. Which practice involves creating visual representations of threats and identifying potential attack vectors during the design phase?

A.Threat modeling
B.Dynamic application security testing (DAST)
C.Static application security testing (SAST)
D.Runtime application self-protection (RASP)
AnswerA

Threat modelling produces structured diagrams of systems, data flows and trust boundaries, then enumerates potential attack vectors against them. Conducted during design, it shifts security left, satisfying the DevSecOps goal of integrating security early in the development lifecycle.

Why this answer

Threat modeling is a structured process that visually maps system components, data flows, and trust boundaries to identify potential threats and attack vectors during the design phase. It aligns with DevSecOps by shifting security left, enabling teams to address risks before code is written. Frameworks like STRIDE and tools like Microsoft Threat Modeling Tool are commonly used to create these visual representations.

Exam trap

The trap here is confusing design-phase activities with testing or runtime protection; candidates often pick SAST or DAST because they are familiar security practices, but the key phrase 'during the design phase' and 'visual representations' points exclusively to threat modeling.

How to eliminate wrong answers

Option B is wrong because DAST is a black-box testing technique performed on running applications to find vulnerabilities from an external attacker's perspective, not during design. Option C is wrong because SAST analyzes source code or binaries for security flaws without executing the program, typically during coding or build phases, not design. Option D is wrong because RASP instruments an application at runtime to detect and block attacks in real time, which is a runtime protection mechanism, not a design-phase activity.

252
MCQhard

A DevOps team integrates security into the CI/CD pipeline. They want to identify vulnerabilities in open-source libraries used by their application. Which tool or practice is specifically designed for this purpose?

A.Software Bill of Materials (SBOM) and dependency analysis
B.Runtime Application Self-Protection (RASP)
C.Static Application Security Testing (SAST)
D.Dynamic Application Security Testing (DAST)
AnswerA

SBOM generation plus dependency analysis inventories every open-source component and its transitive dependencies, then cross-references them against vulnerability databases to flag known CVEs. This directly satisfies the stem's constraint: identifying vulnerabilities in open-source libraries, which static code scanning or container hardening would not target at the dependency layer.

Why this answer

SBOM and dependency analysis are specifically designed to inventory open-source components and their transitive dependencies, then cross-reference them against vulnerability databases like the NVD or OSV. This directly addresses the need to identify vulnerabilities in third-party libraries, which is a core part of software supply chain security. Unlike code analysis tools that focus on first-party code, SBOM-driven scanning targets the exact problem of open-source component risk.

Exam trap

CAS-005 often tests the confusion between SAST, DAST, RASP, and SBOM, where candidates mistakenly pick SAST for third-party library vulnerabilities because it sounds like 'code analysis' — but SAST only scans first-party source code, not dependencies.

How to eliminate wrong answers

Option B is wrong because RASP operates at runtime inside the application, monitoring execution to block attacks, but it does not inventory or analyze open-source libraries for known vulnerabilities. Option C is wrong because SAST analyzes proprietary source code for coding flaws like SQL injection or buffer overflows, not third-party library vulnerabilities. Option D is wrong because DAST tests a running application from the outside, simulating attacks, but it cannot identify which open-source libraries are used or their specific CVEs.

253
MCQhard

A security architect is designing a key management system for a multinational corporation that must comply with FIPS 140-3 Level 3. The system will store long-term asymmetric private keys used for digital signatures. The architect must ensure that the private keys are protected against physical extraction and that cryptographic operations are performed within a tamper-responsive environment. Which of the following is the MOST appropriate solution?

A.Use a Hardware Security Module (HSM) that is FIPS 140-3 Level 3 validated for key storage and cryptographic operations.
B.Implement a Trusted Platform Module (TPM) 2.0 on each server to store private keys and perform signing operations.
C.Store private keys in a cloud key management service (KMS) that uses FIPS 140-2 Level 2 validated hardware.
D.Store private keys in a software-based keystore encrypted with a passphrase and implement strict access controls.
AnswerA

A FIPS 140-3 Level 3 validated HSM provides tamper-responsive physical security, detects and responds to tampering by zeroizing keys, and performs cryptographic operations internally. It meets the requirements for protecting long-term private keys against extraction and ensures operations occur in a secure environment, making it the most appropriate solution.

Why this answer

FIPS 140-3 Level 3 requires tamper-responsive physical security and identity-based authentication. An HSM validated to this level provides a hardened environment that detects and responds to tampering, such as by zeroizing keys. It also performs cryptographic operations internally, preventing key exposure.

Software keystores, TPMs, and Level 2 cloud KMS solutions do not meet the tamper-responsive and physical extraction resistance requirements for Level 3.

Exam trap

The trap here is assuming that any hardware-based key storage, such as a TPM or a Level 2 HSM, automatically satisfies Level 3 requirements, when in fact Level 3 mandates tamper-responsive mechanisms and validated hardware.

254
MCQmedium

A security engineer is configuring a Linux web server that must accept TLS connections only from clients presenting a valid client certificate issued by the corporate internal CA. The engineer adds `SSLVerifyClient require` to the Apache configuration, restarts the service, and finds that all connections now fail with a handshake error. Which of the following is the MOST likely cause?

A.The server is missing an OCSP responder URL, so revocation checking fails and the handshake is rejected.
B.The client certificates were generated with ECDSA keys while the server is configured to accept only RSA client keys.
C.The `SSLCACertificateFile` directive pointing to the internal CA trust anchor is missing or incorrect.
D.The `SSLProtocol` directive allows only TLSv1.3, which does not support client certificate authentication.
AnswerC

With SSLVerifyClient require, the server must validate the client's chain against a configured trust anchor; without a correct SSLCACertificateFile (or SSLCACertificatePath) the handshake aborts because the presented certificate cannot be chained to a trusted root. Pointing this directive at the internal CA resolves the failure, which makes it the most likely cause here.

Why this answer

Requiring client certificates forces the server to build and validate a chain from each client certificate to a trusted anchor. If the CA file that contains the internal root is absent or wrong, every validation fails and the handshake is torn down. Configuring the correct SSLCACertificateFile restores trust and allows valid clients to complete the handshake.

Exam trap

The trap here is assuming that enabling SSLVerifyClient alone is sufficient, when the server also needs an explicit trust anchor to validate the client chain.

255
MCQeasy

A mid-sized retailer wants to demonstrate to customers that its payment card handling meets industry security requirements. The company does not store, process, or transmit cardholder data; it only uses a validated third-party payment page that handles all card data. Which PCI DSS self-assessment questionnaire is most appropriate?

A.SAQ D for Merchants
B.SAQ A
C.SAQ B-IP
D.SAQ P2PE
AnswerB

SAQ A is designed for merchants that fully outsource all cardholder data functions to PCI DSS validated third parties and do not store, process, or transmit cardholder data electronically. The retailer's use of a validated third-party payment page matches this profile exactly. Completing SAQ A is the correct and least burdensome validation path here.

Why this answer

PCI DSS self-assessment questionnaire eligibility depends on how cardholder data is handled. A merchant that completely outsources card data functions to a validated third party and never stores, processes, or transmits the data qualifies for SAQ A. The other questionnaires apply to environments with direct card data handling, standalone IP terminals, or validated point-to-point encryption solutions.

Exam trap

The trap here is selecting the most comprehensive questionnaire, SAQ D, out of caution when the merchant's fully outsourced model qualifies for the much simpler SAQ A.

256
MCQmedium

A company is migrating critical workloads to AWS and must secure data at rest. They need to maintain control over the encryption keys. Which service should they use to meet this requirement?

A.AWS Secrets Manager
B.AWS Certificate Manager (ACM)
C.AWS CloudHSM
D.AWS Shield
AnswerC

CloudHSM provides dedicated, single-tenant hardware security modules where the organisation retains sole control of key material; AWS cannot access the keys. This satisfies the stem's requirement to maintain control over encryption keys for data at rest, unlike KMS, where AWS manages the underlying key infrastructure.

Why this answer

AWS CloudHSM provides dedicated hardware security modules that give the customer full control over encryption keys, including key generation, storage, and management. It meets the requirement of maintaining control over keys for data at rest because the keys are stored in tamper-resistant hardware and are not accessible to AWS. Other services like Secrets Manager and ACM manage keys but do not offer the same level of customer-controlled key custody.

Exam trap

CAS-005 often tests the difference between key management services, and candidates may confuse CloudHSM with KMS or Secrets Manager, overlooking the need for dedicated hardware control.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is for storing and rotating secrets like database credentials, not for managing encryption keys for data at rest. Option B is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates, not encryption keys for data at rest. Option D is wrong because AWS Shield is a DDoS protection service, unrelated to encryption key management.

257
MCQeasy

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?

A.SQL injection
B.Cross-site scripting (XSS)
C.Pass-the-Hash
D.ARP spoofing
AnswerC

Pass-the-Hash reuses captured NTLM password hashes to authenticate to remote Windows systems without cracking the plaintext password, enabling lateral movement between hosts. This satisfies the scenario's Windows lateral-movement requirement by leveraging credential material already obtained during initial access.

Why this answer

Pass-the-Hash (PtH) is a credential theft technique where an attacker captures NTLM password hashes (e.g., via Mimikatz from LSASS memory) and uses them to authenticate to other Windows systems without cracking the plaintext password. It is one of the most common lateral movement techniques in Windows environments because NTLM authentication accepts the hash directly.

Exam trap

The trap is that SQL injection and XSS are famous attack names, so candidates pick them without checking whether the question asks about lateral movement versus initial access — the key is recognizing that lateral movement in Windows almost always involves credential abuse like Pass-the-Hash.

How to eliminate wrong answers

Option A is wrong because SQL injection is an initial access or data exfiltration technique against web applications, not a lateral movement technique between Windows hosts. Option B is wrong because XSS targets web application users in their browsers and does not facilitate host-to-host movement in a Windows domain. Option D is wrong because ARP spoofing is a man-in-the-middle technique on the local subnet used for traffic interception, not a credential-based lateral movement method across Windows systems.

258
Multi-Selectmedium

A security engineer is configuring a web application firewall (WAF) to protect a public-facing application from common attacks. The engineer wants to ensure the WAF can detect and block SQL injection and cross-site scripting (XSS) attempts. Which TWO of the following WAF capabilities should the engineer enable? (Choose two.)

Select 2 answers
A.IP reputation blocking based on threat intelligence feeds
B.Signature-based detection for known attack patterns
C.SSL/TLS termination for encrypted traffic inspection
D.Rate limiting to prevent brute force attacks
E.Positive security model with whitelisting of allowed parameters
AnswersB, E

Signature-based detection uses predefined patterns to identify known attack payloads for SQL injection and XSS. It is effective for common attacks and is a standard WAF feature. Enabling this helps block well-known malicious requests based on their structure and content.

Why this answer

To detect and block SQL injection and XSS, the WAF should use signature-based detection to recognize known attack patterns and a positive security model to enforce strict input validation. These two capabilities directly address the attack vectors. Rate limiting, SSL termination, and IP reputation are useful but do not specifically target SQL injection or XSS.

Exam trap

The trap here is assuming that SSL/TLS termination alone provides protection against SQL injection and XSS, when it only enables inspection of encrypted traffic.

259
MCQhard

A financial services firm operates a trading platform in which a 15-minute outage causes direct contractual penalties. The CISO must present a recommendation to the board on how to treat the residual risk of a ransomware event that could halt trading. The firm already has immutable offline backups and a tested recovery runbook. Which risk treatment action is MOST appropriate to recommend?

A.Transfer the risk by purchasing a cyber insurance policy that covers business interruption.
B.Mitigate the risk further by engineering automated failover and rehearsing recovery to meet the 15-minute recovery time objective.
C.Avoid the risk by shutting down the trading platform until ransomware can be fully eliminated.
D.Accept the residual risk because immutable backups and a tested runbook already exist.
AnswerB

Because the dominant residual exposure is time-to-recover against a hard 15-minute threshold, additional mitigation through automated failover and validated recovery exercises directly reduces the likelihood and impact of missing that objective. This aligns treatment with the actual risk driver, complements the existing backup controls, and gives the board measurable evidence that the residual risk now sits within appetite.

Why this answer

The scenario isolates recovery speed as the binding constraint, since backups and runbooks already exist. Further mitigation through automated failover and rehearsed recovery directly attacks the 15-minute recovery time objective, whereas insurance only offsets financial loss, acceptance contradicts the evident risk appetite, and avoidance would destroy the business line. Treatment should map to the specific residual risk driver rather than to generic control categories.

Exam trap

The trap here is reflexively choosing risk transfer through insurance whenever a large financial loss is mentioned, even when the scenario's real constraint is recovery time.

260
MCQeasy

A financial institution must ensure that its data classification policy aligns with regulatory requirements for customer financial information. Which of the following actions best demonstrates governance in this context?

A.Implement a formal data classification policy that maps data types to regulatory categories and enforce it via technical controls.
B.Restrict all customer financial data to a single secure server without labeling.
C.Allow data owners to classify data on an ad-hoc basis as needed.
D.Encrypt all customer data at rest and in transit regardless of classification.
AnswerA

Mapping data types to regulatory categories directly satisfies the alignment constraint, while enforcement through technical controls ensures the policy is operational rather than aspirational. Governance therefore spans both definition and enforcement, covering classification, handling and accountability for customer financial information as the stem requires.

Why this answer

It directly implements governance by establishing a formal data classification policy that maps data types to specific regulatory categories (e.g., PCI DSS, GLBA, SOX) and enforces compliance through technical controls such as Data Loss Prevention (DLP) rules, access control lists (ACLs), and encryption policies. This structured approach ensures that customer financial information is consistently protected according to legal requirements, rather than relying on ad-hoc or incomplete measures.

Exam trap

The trap here is that candidates often confuse encryption (a security control) with governance (a policy-driven framework), leading them to select Option D because they assume encryption alone satisfies regulatory compliance, when in fact governance requires classification to define which data must be encrypted and under what conditions.

How to eliminate wrong answers

Option B is wrong because restricting all customer financial data to a single secure server without labeling violates the principle of data classification; without labels or tags, the organization cannot differentiate between data types or apply granular controls (e.g., retention policies, access restrictions) required by regulations like GDPR or PCI DSS. Option C is wrong because allowing data owners to classify data on an ad-hoc basis introduces inconsistency and human error, undermining governance and potentially leading to misclassification that fails to meet regulatory mandates. Option D is wrong because encrypting all customer data at rest and in transit regardless of classification ignores the need for differentiated controls; while encryption is a security control, governance requires classification to apply appropriate policies (e.g., key management, access logging, retention) based on data sensitivity and regulatory obligations.

261
MCQhard

A security analyst is investigating a potential side-channel attack on an IoT device. The device's cryptographic operations show variable execution times based on the key and plaintext. Which mitigation is most effective against timing attacks?

A.Use a faster processor to reduce execution time.
B.Use constant-time cryptographic implementations.
C.Implement random delays in cryptographic operations.
D.Disable caching in the CPU during cryptographic operations.
AnswerB

Constant-time implementations execute identical instruction sequences and memory access patterns regardless of key or plaintext values, eliminating the timing variance the analyst observed. This removes the correlation between execution duration and secret data that enables timing attacks.

Why this answer

Timing attacks exploit variations in execution time. Using constant-time algorithms ensures that operations take the same amount of time regardless of input, preventing information leakage.

262
MCQhard

A security manager is reviewing business continuity plans. Which element is MOST critical to test regularly?

A.Updated contact lists
B.Failover capability of critical systems
C.Alternate site readiness
D.Backup media integrity
AnswerB

Failover is the mechanism that actually restores service when a primary system fails, so it must be exercised regularly to confirm recovery time and data integrity targets hold. Untested failover leaves the continuity plan's core assumption unverified.

Why this answer

The most critical element to test regularly is the failover capability of critical systems, as it directly validates that business-critical operations can continue during a disruption. This testing ensures that the entire failover process works, including system redundancy, network paths, and data synchronization. While updated contact lists (A) are important for communication, they do not test operational continuity.

Alternate site readiness (C) is a component of failover testing, but testing the full failover capability is more comprehensive. Backup media integrity (D) is essential for data recovery but does not validate the entire system recovery process.

263
MCQhard

A regional healthcare provider with 2,000 employees recently acquired a smaller clinic that uses a legacy electronic health record (EHR) system. The provider's security team performed a risk assessment and identified that the legacy system does not support encryption at rest, lacks role-based access controls (RBAC), and stores administrative credentials in plaintext. The system is scheduled to be decommissioned in 18 months, but it must remain operational to support patient care during the transition. The provider is subject to HIPAA and state breach notification laws. The CEO wants to avoid any disruption to patient services but also minimize regulatory risk. Which of the following is the BEST course of action?

A.Accelerate the migration timeline to replace the legacy system within 6 months.
B.Immediately disconnect the legacy system from the network and use manual processes.
C.Accept the residual risk and document it in the risk register.
D.Implement compensating controls such as network segmentation, storage-level encryption, and strict access monitoring.
AnswerD

Compensating controls address the legacy system's missing encryption, RBAC and plaintext credentials without disrupting patient care during the 18-month transition. Network segmentation, storage-level encryption and access monitoring reduce HIPAA and breach-notification exposure while the system remains operational.

Why this answer

The best course of action because it allows the legacy EHR system to remain operational for patient care while reducing regulatory risk. Compensating controls like network segmentation isolate the vulnerable system, storage-level encryption (e.g., BitLocker or LUKS) protects data at rest, and strict access monitoring (e.g., SIEM with real-time alerts) mitigates the lack of RBAC and plaintext credentials. This approach balances the CEO's requirement for no disruption with HIPAA's security rule requirements for reasonable safeguards.

Exam trap

CompTIA often tests the concept that compensating controls are a valid risk treatment option when a vulnerability cannot be immediately remediated, and candidates mistakenly choose risk acceptance (Option C) without realizing that HIPAA requires active safeguards, not just documentation.

How to eliminate wrong answers

Option A is wrong because accelerating migration to 6 months is unrealistic and would likely cause significant disruption to patient services, violating the CEO's directive to avoid disruption. Option B is wrong because immediately disconnecting the legacy system would halt patient care, creating an unacceptable operational impact and potentially violating continuity of care requirements under HIPAA. Option C is wrong because accepting residual risk without implementing any compensating controls would leave the organization exposed to a high likelihood of a breach, violating HIPAA's requirement to implement reasonable and appropriate safeguards and increasing regulatory risk under state breach notification laws.

264
MCQmedium

An organization is deploying a just-in-time (JIT) privileged access management solution. What is a key benefit of JIT access compared to standing privileged accounts?

A.It allows users to permanently elevate privileges.
B.It eliminates the need for multi-factor authentication.
C.It requires no audit logging.
D.It reduces the window of exposure for privileged credentials.
AnswerD

JIT provisioning grants privileged rights only for the approved duration, then revokes them automatically. This directly shrinks the attack surface created by standing accounts, whose credentials remain valid indefinitely. The reduced exposure window satisfies the scenario's core requirement: limiting how long compromised or misused privileged credentials stay exploitable.

Why this answer

JIT access provides temporary privileges that are automatically revoked after use, reducing the attack surface and limiting lateral movement.

265
MCQeasy

Which of the following is a benefit of using an immutable infrastructure approach?

A.Reduced need for configuration management
B.Easier manual patching of running servers
C.Elimination of configuration drift
D.Lower cost due to reusable hardware
AnswerC

Immutable infrastructure replaces servers rather than modifying them in place, so every deployment starts from an identical known image. Because running instances are never patched or hand-edited, configuration drift between environments is eliminated, which is the stated benefit.

Why this answer

Immutable infrastructure means servers are never modified in place — instead, new instances are built from a known-good image and old ones are replaced. This eliminates configuration drift because every instance is identical to its image, and any change requires a new image and redeployment. Manual patching and hardware reuse are not benefits of this model.

Exam trap

CAS-005 often tests the misconception that immutable infrastructure means 'no configuration management' or 'easier manual patching' — the trap is confusing immutability with reduced operational discipline, when it actually shifts discipline to image pipelines.

How to eliminate wrong answers

Option A is wrong because immutable infrastructure does not reduce the need for configuration management — it shifts it to image build time (e.g., Packer, Ansible in the image pipeline), so configuration management is still required, just applied earlier. Option B is wrong because immutable infrastructure explicitly discourages manual patching of running servers; patching is done by rebuilding images and replacing instances, not by logging in and updating live systems. Option D is wrong because immutable infrastructure does not inherently lower cost through reusable hardware — it often increases resource churn (new instances replace old), and cost benefits come from elasticity and right-sizing, not hardware reuse.

266
MCQmedium

A company is adopting a defense-in-depth strategy. Which of the following is an example of a preventive control at the network layer?

A.Intrusion Detection System (IDS)
B.Security Information and Event Management (SIEM)
C.Network segmentation
D.Penetration testing
AnswerC

Network segmentation restricts lateral movement by dividing the network into isolated zones with enforced access rules, blocking traffic before it reaches targets. This preventive, network-layer control satisfies the defense-in-depth requirement by stopping intrusion attempts rather than merely detecting them.

Why this answer

Network segmentation is a preventive control because it proactively restricts lateral movement by dividing the network into isolated segments using firewalls, VLANs, or subnets. This limits an attacker's ability to move freely after compromising a host, thereby preventing the spread of an attack. It operates at the network layer (Layer 3) and enforces access control policies between segments, making it a classic example of a preventive control in a defense-in-depth strategy.

Exam trap

The trap here is confusing detective controls (IDS, SIEM) with preventive controls; candidates often assume that monitoring tools prevent attacks, but they only detect and alert.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) is a detective control—it monitors and alerts on malicious activity but does not prevent it. Option B is wrong because a SIEM is also a detective and logging control that aggregates and correlates events for analysis, not prevention. Option D is wrong because penetration testing is an assessment or testing control that identifies vulnerabilities but does not prevent attacks; it is not a preventive control at the network layer.

267
MCQmedium

Which of the following is the MOST effective way to detect unauthorized changes to critical files?

A.Antivirus software
B.Intrusion detection system
C.Regular backups
D.File integrity monitoring
AnswerD

File integrity monitoring continuously hashes critical files and compares results against a known-good baseline, generating alerts the moment content changes. This directly satisfies the stem's requirement to detect unauthorised modification, unlike access logging, which records who touched a file but not whether its contents were altered.

Why this answer

File integrity monitoring (FIM) is the most effective method for detecting unauthorized changes to critical files because it uses cryptographic hashing (e.g., SHA-256) to create a baseline of file states and then periodically re-computes hashes to identify any alterations. Unlike other security controls, FIM specifically focuses on the integrity of file content, metadata, and permissions, providing immediate alerts when a deviation from the baseline occurs.

Exam trap

The trap here is that candidates confuse detection (FIM) with prevention (antivirus) or recovery (backups), or mistakenly think an IDS can monitor file integrity when it is designed for network-level anomaly detection.

How to eliminate wrong answers

Option A is wrong because antivirus software relies on signature-based or heuristic detection of known malware patterns, not on monitoring file integrity; it cannot detect unauthorized changes to non-malicious files or changes made by authorized users. Option B is wrong because an intrusion detection system (IDS) monitors network traffic or system logs for suspicious activity patterns, not the integrity of individual files on disk; it would miss file changes that do not generate network or log anomalies. Option C is wrong because regular backups are a recovery mechanism, not a detection control; they restore files after a change is discovered but do not alert on or identify unauthorized modifications in real time.

268
MCQhard

A security architect is designing segmentation for an industrial control network that runs Modbus/TCP between engineering workstations and programmable logic controllers. The architect wants to prevent an attacker who compromises a workstation from issuing unauthorized write commands to the controllers, while avoiding disruption of legitimate polling traffic. Which control BEST addresses the specific risk?

A.Apply network address translation so controllers are not directly reachable from the workstation subnet.
B.Enable 802.1X port-based authentication on the switches that connect the controllers.
C.Implement a deep packet inspection device that understands the protocol and blocks write function codes from workstations.
D.Deploy a stateful firewall that permits only the workstation-to-controller TCP port used by the protocol.
AnswerC

A protocol-aware inspection device parses Modbus/TCP function codes and can permit read or polling functions while dropping write functions from engineering workstations. This directly constrains what a compromised workstation can do to the controllers without blocking legitimate polling. Because it operates at the application layer of the industrial protocol, it addresses the specific unauthorized write risk.

Why this answer

The risk is a compromised workstation sending unauthorized write commands over a legitimate protocol. Only a control that inspects the industrial protocol at the application layer can distinguish reads from writes and block the dangerous function codes while allowing polling. Address, port, and device-authentication controls operate below that layer and cannot enforce command-level policy.

Exam trap

The trap here is trusting port-based or identity-based controls to stop malicious commands, when only protocol-aware inspection can distinguish a read from a write.

269
MCQmedium

During a threat modeling exercise for a new web application, the team identifies a risk of API abuse due to lack of rate limiting. Which security control should be implemented at the API gateway to mitigate this risk?

A.Input validation
B.OAuth 2.0 scopes
C.Rate limiting policies
D.JWT token expiration
AnswerC

Rate limiting policies at the API gateway cap the number of requests a client may make within a defined window, throttling or blocking excessive calls. This directly mitigates the identified API abuse risk arising from absent rate limiting.

Why this answer

Rate limiting policies are the direct control to mitigate API abuse by restricting the number of requests a client can make within a time window. Implemented at the API gateway, they prevent denial-of-service, brute-force, and excessive consumption of backend resources. While other controls like input validation or OAuth scopes address different threats, rate limiting specifically targets the risk of API abuse due to lack of throttling.

Exam trap

CAS-005 often tests the confusion between authentication/authorisation controls (OAuth scopes, JWT expiration) and availability/abuse controls (rate limiting) — candidates must match the control to the specific risk of API abuse via excessive requests.

How to eliminate wrong answers

Option A is wrong because input validation protects against injection attacks (e.g., SQLi, XSS) by ensuring data conforms to expected formats, but it does not limit the volume or frequency of API calls, so it cannot mitigate abuse via excessive requests. Option B is wrong because OAuth 2.0 scopes define authorisation boundaries (what resources a token can access), not how often; they do not prevent a legitimate token from being used to flood the API. Option D is wrong because JWT token expiration limits the lifetime of a token, reducing the window for misuse if stolen, but it does not throttle request rates and thus does not address API abuse through high-frequency calls.

270
MCQmedium

A data loss prevention (DLP) solution is being implemented to prevent sensitive data from leaving the corporate network. Which of the following is the most effective approach for detecting structured data like credit card numbers in outbound traffic?

A.Keyword matching
B.Regular expression matching
C.Machine learning classification
D.Exact file hash matching
AnswerB

Regular expressions match the fixed numeric patterns of credit card numbers, such as 16-digit groupings with valid prefixes, in outbound traffic. This pattern-based detection suits structured data, unlike keyword or document-fingerprint methods aimed at unstructured content.

Why this answer

Regular expression matching is the most effective approach for detecting structured data like credit card numbers because it can match the specific pattern (e.g., 16 digits with optional separators) and validate format, such as the Luhn check in some DLP engines. This provides high precision for well-defined formats like PANs, SSNs, and IBANs.

Exam trap

CAS-005 often tests the distinction between detection techniques for structured versus unstructured data — candidates must recognize that regex is the right tool for fixed-format identifiers like credit card numbers, while ML is for unstructured content.

How to eliminate wrong answers

Option A is wrong because keyword matching only looks for literal strings (e.g., 'credit card') and cannot detect the numeric pattern of a card number itself. Option C is wrong because machine learning classification is better suited for unstructured data (e.g., contracts, emails) where patterns are not fixed, and it is less precise for structured numeric formats. Option D is wrong because exact file hash matching only detects known files by their hash and cannot identify a credit card number embedded in a new document or email.

271
MCQhard

An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?

A.Micro-segmentation
B.Transport Layer Security (TLS)
C.Virtual Private Network (VPN)
D.Secure Access Service Edge (SASE)
AnswerA

Micro-segmentation enforces granular, workload-level policies on east-west traffic, isolating application tiers across subnets within a virtual network. Unlike perimeter controls, it inspects inter-VM flows directly, satisfying the requirement to limit lateral movement between tiers at the virtual network level.

Why this answer

Micro-segmentation enforces security policies at the virtual network level, isolating workloads (e.g., VMs in different subnets) and controlling east-west traffic between them. It typically uses distributed firewalls or security groups applied to individual workloads, allowing granular policy enforcement regardless of subnet boundaries. This directly limits lateral movement by ensuring that even if an attacker compromises one VM, they cannot freely communicate with others.

Exam trap

CAS-005 often tests the confusion between connectivity technologies (VPN, TLS) and segmentation technologies (micro-segmentation) — candidates must recognise that only micro-segmentation enforces east-west policies between VMs in different subnets.

How to eliminate wrong answers

Option B is wrong because TLS is a cryptographic protocol for securing data in transit (encryption and authentication), not a segmentation technology; it does not enforce network-level access policies between VMs. Option C is wrong because a VPN extends a private network over a public network (e.g., site-to-site or remote access), but it does not provide micro-segmentation or east-west traffic control within a cloud environment; it is about secure connectivity, not isolation. Option D is wrong because SASE is a cloud-delivered architecture converging networking (SD-WAN) and security (SWG, CASB, ZTNA) for branch and remote users, not a mechanism for enforcing east-west policies between VMs in different subnets within a cloud VPC.

272
MCQmedium

A security engineer is designing a hybrid encryption solution for a messaging application. The requirement is that each message must be encrypted with a unique symmetric key, and that symmetric key must be delivered to the recipient without exposing it to the server. The solution must also support sender authentication. Which combination of cryptographic mechanisms BEST satisfies these requirements?

A.Use Diffie-Hellman key exchange to establish a shared secret, encrypt the message with that secret using AES-256-GCM, and rely on the shared secret itself to authenticate the sender.
B.Encrypt the message with AES-256-CBC using a key derived from the sender's password, and include the password hash in the message header for verification.
C.Encrypt the message with AES-256-GCM using a randomly generated key, encrypt that key with the recipient's RSA public key, and sign the ciphertext with the sender's RSA private key.
D.Encrypt the message directly with the recipient's RSA public key, and have the recipient verify authenticity by comparing a SHA-256 hash sent alongside the ciphertext.
AnswerC

This is the standard hybrid encryption pattern: AES-GCM provides confidentiality and integrity for the message, RSA-OAEP key wrapping delivers the unique symmetric key only to the recipient, and a sender signature provides authentication and non-repudiation. Because the symmetric key is random per message, compromise of one key does not affect other messages, and the server never sees the plaintext key.

Why this answer

Hybrid encryption combines asymmetric and symmetric cryptography to meet confidentiality, integrity, and authentication goals. A random AES-GCM key per message ensures unique symmetric keys, RSA key wrapping delivers that key confidentially to the recipient, and a sender signature binds the message to the sender's identity. The other options either leak key material, use impractical direct asymmetric encryption, or omit sender authentication.

Exam trap

The trap here is assuming that a shared secret from a key exchange inherently authenticates the sender, when it only proves possession of the key and not identity.

273
MCQmedium

A security architect is designing a zero-trust architecture for a multi-cloud environment. Which principle is essential for enforcing identity-centric micro-segmentation?

A.Identity-based access policies
B.VPN concentrators
C.Network address translation
D.Perimeter firewalls
AnswerA

Identity-based access policies evaluate each request against user identity and context rather than network location, which is what enables micro-segmentation to be enforced per identity across multiple clouds. Network-centric controls alone cannot deliver identity-centric segmentation in a multi-cloud estate.

Why this answer

Identity-based access policies are essential for zero-trust micro-segmentation because they authorize every request based on the verified identity of the user, device, or workload — not on network location. In a multi-cloud zero-trust model, policy decisions follow the identity (via IAM, OIDC, SPIFFE, or mTLS) so that workloads are segmented by who they are, not where they sit. This is the core of identity-centric micro-segmentation.

Exam trap

The trap is equating network controls (VPNs, firewalls, NAT) with zero-trust — candidates pick perimeter firewalls because they 'segment the network,' but zero-trust requires identity-based, per-request authorization, not location-based trust.

How to eliminate wrong answers

Option B is wrong because VPN concentrators extend network-level trust — once connected, a user often has broad access, which contradicts zero-trust's 'never trust, always verify' model. Option C is wrong because NAT is an address-translation mechanism for connectivity and IP conservation; it provides no identity-based authorization. Option D is wrong because perimeter firewalls enforce coarse, location-based trust at the network edge, which zero-trust explicitly rejects in favor of per-request, identity-driven decisions.

274
MCQmedium

An organization wants to enforce consistent security policies across multiple cloud providers (AWS, Azure, GCP). Which tool is designed to continuously monitor and remediate misconfigurations in cloud environments?

A.Cloud Access Security Broker (CASB)
B.Security Information and Event Management (SIEM)
C.Cloud Workload Protection Platform (CWPP)
D.Cloud Security Posture Management (CSPM)
AnswerD

CSPM continuously monitors multi-cloud infrastructure for misconfigurations and automatically remediates drift, satisfying the requirement to enforce consistent policy across AWS, Azure and GCP. Unlike native tools that operate within a single provider, CSPM normalises posture assessment across heterogeneous environments, directly addressing the cross-provider constraint in the stem.

Why this answer

CSPM (Cloud Security Posture Management) tools are purpose-built to continuously scan multi-cloud environments (AWS, Azure, GCP) against benchmarks like CIS, NIST, and PCI DSS, detecting misconfigurations such as public S3 buckets, overly permissive IAM roles, or unencrypted storage. They provide automated remediation workflows and drift detection across providers, which is exactly what the organization needs for consistent policy enforcement. CASB, SIEM, and CWPP address different layers (data access, log correlation, workload runtime) and do not natively deliver cross-cloud configuration posture management.

Exam trap

CAS-005 often tests the confusion between CSPM (configuration posture) and CWPP (runtime workload protection) or CASB (data access control), so candidates must map the keyword 'misconfiguration' specifically to CSPM.

How to eliminate wrong answers

Option A is wrong because a CASB governs access to cloud services and enforces data-centric policies (DLP, shadow IT discovery) rather than continuously scanning infrastructure configurations for misconfigurations. Option B is wrong because a SIEM aggregates and correlates log/event data for detection and response; it does not perform configuration assessment or automated remediation of cloud resources. Option C is wrong because a CWPP protects running workloads (VMs, containers, serverless) at runtime via vulnerability scanning and behavioral monitoring, not the cloud control plane's configuration posture.

275
MCQeasy

An organization is implementing a PKI and wants to ensure that clients can quickly check if a certificate has been revoked without downloading a large list. Which protocol should be used?

A.Certificate Revocation List (CRL)
B.Online Certificate Status Protocol (OCSP)
C.Certificate Transparency (CT)
D.Simple Certificate Enrollment Protocol (SCEP)
AnswerB

OCSP returns a signed, per-certificate revocation status from a responder, so clients query one certificate rather than downloading and parsing an entire CRL. This satisfies the requirement for fast revocation checking without transferring a large list.

Why this answer

OCSP (Online Certificate Status Protocol) allows clients to check the revocation status of a single certificate in real time without downloading a full CRL.

276
MCQeasy

In the shared responsibility model for cloud security, which of the following is generally the responsibility of the cloud customer?

A.Configuration of network access controls
B.Hardware maintenance of servers
C.Hypervisor vulnerability patching
D.Physical security of data centers
AnswerA

Under the shared responsibility model, the provider secures the cloud infrastructure, but customers configure their own network access controls, security groups and firewall rules. This makes network access control configuration a customer responsibility, matching the stem's question.

Why this answer

In the cloud shared responsibility model, the customer is always responsible for 'security IN the cloud' — their data, configurations, and access controls. Network access control configuration (security groups, NACLs, firewall rules) is a customer-managed setting in IaaS/PaaS, so option A is correct. The provider handles 'security OF the cloud' — physical, host, and hypervisor layers.

Exam trap

CAS-005 often tests the misconception that the cloud provider secures everything once data is migrated, when in fact the customer retains responsibility for configuration, identity, and data protection layers.

How to eliminate wrong answers

Option B is wrong because hardware maintenance of servers is performed by the cloud provider, who owns and operates the physical infrastructure. Option C is wrong because hypervisor vulnerability patching is a provider responsibility — the hypervisor sits below the customer's visibility boundary in IaaS and is fully managed in PaaS/SaaS. Option D is wrong because physical security of data centers is always the provider's responsibility, as customers have no physical access to cloud facilities.

277
MCQmedium

A security architect is designing a zero trust architecture for a company with a large remote workforce. The requirement is to verify device health and user identity for every session to internal applications, regardless of network location, and to prevent session hijacking after initial authentication. Which of the following BEST meets these requirements?

A.Require all remote users to connect through a cloud access security broker (CASB) that applies data loss prevention policies to cloud applications.
B.Use a reverse proxy with mutual TLS client certificates and enforce certificate revocation checks at each connection.
C.Implement a zero trust network access (ZTNA) service that continuously evaluates identity and device posture and issues per-session, context-bound tokens.
D.Deploy a VPN concentrator with split tunneling and require users to authenticate with a username and password plus a one-time code.
AnswerC

ZTNA brokers access per application based on continuous evaluation of user identity and device posture, and it issues context-bound tokens that are validated for each session. This prevents session hijacking because tokens are tied to the session context and cannot be replayed from a different device or location, meeting both requirements.

Why this answer

ZTNA continuously evaluates identity and device posture and issues per-session tokens bound to context, so every access request is verified regardless of network location. Because tokens are tied to the session and device context, a stolen token cannot be replayed elsewhere, which directly prevents session hijacking after initial authentication.

Exam trap

The trap here is treating strong initial authentication such as VPN with MFA or mutual TLS as sufficient, when zero trust requires continuous per-session verification and context-bound tokens to prevent session hijacking.

278
MCQhard

A healthtech startup is developing a mobile app that collects PHI. They plan to use a third-party cloud provider for data storage. What is the most critical compliance requirement before signing the contract?

A.Verify the provider's data center locations comply with data residency laws
B.Execute a Business Associate Agreement (BAA) with the provider
C.Review the provider's SOC 2 Type II report
D.Ensure all data is encrypted at rest and in transit
AnswerB

HIPAA requires a Business Associate Agreement before a third party creates, receives or stores PHI, contractually binding the cloud provider to safeguards, breach notification and use restrictions. This satisfies the stem's requirement for the most critical compliance step preceding contract signature.

Why this answer

Under HIPAA, a Business Associate Agreement (BAA) is a mandatory contract that ensures the third-party cloud provider (a business associate) will safeguard Protected Health Information (PHI). Without a BAA, the startup would be in direct violation of HIPAA's Privacy and Security Rules, regardless of other security measures. This requirement is non-negotiable before any PHI is shared or stored by the provider.

Exam trap

CompTIA often tests the distinction between contractual compliance (BAA) and technical controls (encryption, SOC reports), leading candidates to prioritize security measures over the mandatory legal agreement required by HIPAA.

How to eliminate wrong answers

Option A is wrong because while data residency laws (e.g., GDPR, local regulations) are important, they are not the most critical compliance requirement under HIPAA; a BAA is the foundational legal agreement. Option C is wrong because reviewing a SOC 2 Type II report provides assurance about the provider's controls but does not satisfy the HIPAA requirement for a contractual BAA; it is a supplementary due diligence step. Option D is wrong because encryption at rest and in transit is a technical safeguard, but it does not replace the legal obligation of a BAA; HIPAA mandates the BAA even if encryption is implemented.

279
Multi-Selecteasy

Which TWO of the following are examples of administrative controls? (Select TWO)

Select 2 answers
A.Firewall rules
B.Encryption of data at rest
C.Security awareness training
D.Access control policy
E.Intrusion detection system
AnswersC, D

Administrative control

Why this answer

Security awareness training (C) is an administrative control because it involves policies, procedures, and human behavior management rather than technical mechanisms. It educates users on security risks and compliance requirements, reducing the likelihood of social engineering or policy violations. This aligns with the administrative domain of the CIA triad's governance framework.

Exam trap

The CAS-004 exam often tests the distinction between administrative, technical, and physical controls, and the trap here is that candidates confuse technical controls like encryption or firewalls with administrative controls because they are both part of a defense-in-depth strategy, but only administrative controls involve human processes and documentation.

280
MCQmedium

During a policy gap analysis, it is discovered that the organization has a policy stating that sensitive data must be encrypted, but there are no procedures for implementing encryption on mobile devices. This is an example of a gap between:

A.Standards and guidelines
B.Policy and standards
C.Policy and guidelines
D.Policy and procedures
AnswerD

The encryption mandate exists as a stated policy, but no implementing procedures exist for mobile devices. The gap therefore lies between policy and procedures, since the documented requirement lacks the operational steps needed to enact it on that platform.

Why this answer

A policy states the mandatory 'what' (sensitive data must be encrypted), while procedures describe the step-by-step 'how' (how to enable encryption on mobile devices, which tools, who does it). The gap described is the absence of implementation procedures supporting an existing policy, so it is a policy-to-procedures gap.

Exam trap

The trap is treating 'standards' and 'procedures' as synonyms; the exam expects you to distinguish the mandatory technical requirement (standard) from the step-by-step implementation (procedure).

How to eliminate wrong answers

Option A is wrong because standards are specific mandatory requirements (for example, AES-256) and guidelines are recommendations; the question describes missing implementation steps, not missing technical standards. Option B is wrong because the policy exists and no specific standard is described as missing; the missing element is the procedural how-to. Option C is wrong because guidelines are advisory best practices, and the question is about the absence of mandatory implementation steps, which are procedures.

281
MCQeasy

A developer needs to securely store user passwords in a database. Which hashing technique is recommended for password storage?

A.SHA-256 with a random salt
B.bcrypt with a per-user salt
C.MD5 with a static salt
D.Base64 encoding
AnswerB

bcrypt applies an adaptive, deliberately slow key-derivation function with a tunable cost factor, and the per-user salt ensures identical passwords yield distinct digests, defeating rainbow-table and precomputation attacks. This directly satisfies the stem's requirement for secure password storage, unlike fast general-purpose hashes such as SHA-256.

Why this answer

Bcrypt is recommended for password storage because it incorporates a per-user salt to prevent rainbow table attacks and uses a configurable cost factor to slow down brute-force attempts, making it resistant to GPU-based cracking. Unlike general-purpose hashes like SHA-256, bcrypt is designed specifically for password hashing with built-in salting and adaptive work factor.

Exam trap

CompTIA CASP+ often tests the misconception that adding a salt to a fast hash like SHA-256 makes it suitable for passwords, but the trap is that without a built-in work factor, the hash remains too fast for attackers to brute-force efficiently.

How to eliminate wrong answers

Option A is wrong because SHA-256 is a fast general-purpose hash that lacks an inherent work factor, making it vulnerable to high-speed brute-force attacks even with a salt; it is not designed for password storage. Option C is wrong because MD5 is cryptographically broken (collision attacks demonstrated) and a static salt means all users with the same password produce the same hash, nullifying salt benefits. Option D is wrong because Base64 is an encoding scheme, not a hashing algorithm; it provides no security whatsoever and can be trivially reversed.

282
Multi-Selecthard

A security governance committee is reviewing the organization's risk register after a merger. The committee wants to apply risk treatment strategies that transfer or share risk with another party rather than reducing it internally. Which two actions represent risk transference? (Choose two.)

Select 2 answers
A.Deploying endpoint detection and response agents across all workstations to catch malicious activity earlier.
B.Diversifying the cloud provider portfolio so no single vendor outage halts all critical services.
C.Outsourcing the payment card processing function to a PCI DSS validated third-party service provider under contract.
D.Accepting the risk of a legacy application because remediation cost exceeds the potential loss.
E.Purchasing a cyber liability insurance policy that covers breach response costs and regulatory fines where insurable.
AnswersC, E

Contracting a validated service provider to handle card processing moves operational responsibility and much of the associated risk to that vendor. This is transference or sharing, since the provider assumes defined obligations and liabilities through the agreement, though the organization retains oversight and compliance accountability.

Why this answer

Risk transference shifts the financial or operational consequence to another party. Cyber insurance and outsourcing card processing to a validated provider both move risk to external entities through contracts or policies, whereas detection controls, acceptance, and diversification change or retain the risk internally.

Exam trap

The trap here is confusing risk reduction controls, such as deploying detection agents, with transference, which requires another party to absorb the consequence.

283
MCQeasy

A web developer is designing an e-commerce application that stores customer payment information. The application runs on a cloud platform and uses a relational database. During a security review, the auditor identifies that the database admin credentials are hardcoded in the application configuration file. The developer must implement a solution that eliminates hardcoded credentials and enables automatic rotation of secrets. Which course of action should the developer take?

A.Replace the database with one that supports certificate-based authentication
B.Encrypt the configuration file using the application's built-in encryption
C.Store the credentials in environment variables and use a scheduled script to change them
D.Use a secrets management service to store and rotate the credentials dynamically
AnswerD

A secrets management service stores credentials outside the application configuration and injects them at runtime, directly eliminating the hardcoded values the auditor flagged. Its built-in rotation engine can automatically cycle database admin passwords on a schedule, satisfying the automatic rotation requirement without code changes or redeployment.

Why this answer

A secrets management service (e.g., Google Secret Manager, AWS Secrets Manager, Azure Key Vault) stores credentials securely and provides automatic rotation, eliminating hardcoded secrets. The application retrieves secrets at runtime via API, and rotation can be scheduled or triggered.

Exam trap

CAS-005 often tests the misconception that encrypting configuration files or using environment variables is sufficient; the key is centralized secrets management with automatic rotation.

How to eliminate wrong answers

Option A is wrong because changing the database to certificate-based authentication does not eliminate the need to manage and rotate certificates, and it may not be feasible. Option B is wrong because encrypting the configuration file still leaves the encryption key to be managed, and it does not enable automatic rotation. Option C is wrong because environment variables are still static and a scheduled script is not a secure, integrated rotation mechanism.

284
MCQmedium

A multinational retailer operates under GDPR for its EU customers and must demonstrate accountability to supervisory authorities. The Chief Privacy Officer wants a mechanism that documents, on an ongoing basis, which processing activities occur, what data categories are involved, and how long each is retained. Which GDPR instrument should the privacy team maintain to satisfy this requirement?

A.Standard Contractual Clauses (SCCs)
B.Binding Corporate Rules (BCRs)
C.Data Protection Impact Assessment (DPIA)
D.Records of Processing Activities (RoPA) under Article 30
AnswerD

The RoPA is the Article 30 accountability artifact that catalogues each processing activity, its purposes, data categories, recipients, retention periods, and security measures. It directly answers the regulator's need for a living register documenting what is processed and for how long. Because the retailer processes data at scale, maintaining this register is mandatory and serves as the documentary backbone for demonstrating GDPR accountability.

Why this answer

The Records of Processing Activities is the Article 30 accountability instrument that captures processing purposes, data categories, recipients, retention, and safeguards in one maintained register. A DPIA analyses a single high-risk activity, while SCCs and BCRs are cross-border transfer mechanisms. Only the RoPA provides the persistent, organization-wide documentation the retailer needs to show supervisory authorities how EU personal data is handled and retained.

Exam trap

The trap here is assuming any accountability document satisfies GDPR Article 30, when only the Records of Processing Activities provides the required ongoing inventory of processing purposes, data categories, and retention periods.

285
MCQmedium

A financial services firm must protect cardholder data in a database and wants a control that renders the data unreadable to database administrators and to anyone who steals a backup, while still allowing the application to run equality lookups on the protected column. Which approach BEST meets these requirements?

A.Store the column encrypted with AES-256-GCM using a key held in an HSM, and let the application decrypt rows after retrieving them by primary key.
B.Store the column in plaintext but restrict table access with database roles and enable transparent data encryption on the tablespace.
C.Store a keyed hash of the column using HMAC-SHA-256 with a key held outside the database, and query by recomputing the hash of the search value.
D.Store the column encrypted with AES-256-CBC using a static initialization vector so identical plaintexts produce identical ciphertext for lookups.
AnswerC

A keyed hash is deterministic for a given input and key, so identical values produce identical digests and the database can index and match them for equality searches. Because the key lives outside the database, administrators and backup thieves see only digests they cannot reverse or verify without the key, meeting both the confidentiality and lookup requirements.

Why this answer

A keyed hash computed with a secret key held outside the database is deterministic, so equality predicates can be evaluated directly against the stored digest while the original values stay hidden from administrators and backup thieves. This preserves index-based lookups and satisfies the confidentiality goal, whereas randomized encryption breaks equality queries and static-IV encryption introduces serious cryptographic weaknesses.

Exam trap

The trap here is assuming that strong encryption such as AES-GCM automatically supports searchable equality lookups, when randomized encryption deliberately prevents them.

286
MCQhard

A security team discovers a misconfiguration that exposes sensitive data. The operations team wants to wait until the next maintenance window. What is the BEST course of action?

A.Document the risk and accept it
B.Notify the data protection authority
C.Immediately fix the misconfiguration
D.Implement a temporary workaround
AnswerC

Reduces risk immediately.

Why this answer

When a misconfiguration exposes sensitive data, the security team must prioritize immediate remediation to prevent data exfiltration or regulatory penalties. Waiting for a maintenance window violates the principle of timely risk mitigation, especially when the exposure is active and exploitable. The best course of action is to fix the misconfiguration immediately, even if it requires a temporary service disruption, as the risk of data breach outweighs operational convenience.

Exam trap

CompTIA often tests the misconception that operational convenience (waiting for a maintenance window) can override immediate security risks, but in CAS-004, the correct answer always prioritizes containment and remediation of active exposures over change management schedules.

How to eliminate wrong answers

Option A is wrong because documenting and accepting the risk without action is only appropriate after a formal risk assessment and approval from management, not when an active exposure of sensitive data is known and can be quickly remediated. Option B is wrong because notifying the data protection authority is a mandatory breach notification step after a confirmed data breach, not a first response to a misconfiguration that has not yet been exploited; premature notification can cause unnecessary regulatory scrutiny. Option D is wrong because implementing a temporary workaround does not address the root cause of the misconfiguration and may leave the sensitive data exposed or introduce new vulnerabilities, whereas a direct fix is more effective and permanent.

287
MCQhard

An organization uses a microservices architecture where services communicate via REST APIs. To ensure defense in depth, they want to authenticate and authorize every API call. Which of the following implementations BEST enforces this at the application layer?

A.Mutual TLS (mTLS) between services
B.API keys in HTTP headers
C.OAuth 2.0 with JWT bearer tokens and scoped permissions
D.IP whitelisting at the network firewall
AnswerC

OAuth 2.0 with JWT bearer tokens authenticates each API call and enforces authorisation through scoped permissions carried in the token. This satisfies the requirement to authenticate and authorise every REST call at the application layer, providing defence in depth beyond network controls.

Why this answer

OAuth 2.0 with JWT bearer tokens and scoped permissions is the best choice because it provides a standardized, token-based authentication and authorization mechanism at the application layer. The JWT contains claims (e.g., issuer, subject, expiration, and scopes) that can be cryptographically verified by each microservice without requiring a centralized session store, enabling fine-grained, per-API authorization. This directly addresses the requirement to authenticate and authorize every API call within a defense-in-depth strategy.

Exam trap

For the CompTIA CASP+ exam, the trap is that candidates confuse transport-layer security (mTLS) with application-layer authorization, assuming that mutual authentication alone satisfies the 'authenticate and authorize' requirement, but mTLS provides no mechanism for scoped permissions or user-level claims.

Why the other options are wrong

A

mTLS provides transport-layer authentication but does not enforce application-level authorization.

B

API keys are static and often lack scoping; they are not as secure or granular as OAuth tokens.

D

IP whitelisting is network-level and does not authenticate users or services at the application layer.

288
MCQhard

During a security audit, it is discovered that a critical server uses SSH with password authentication and supports weak key exchange algorithms. Which of the following is the most effective hardening step to prevent brute-force attacks and ensure forward secrecy?

A.Implement fail2ban to block IPs after failed attempts
B.Disable password authentication and restrict key exchange algorithms to curve25519-sha256
C.Change the SSH port to a non-default high port
D.Use RSA keys with 4096-bit length
AnswerB

Disabling password authentication removes the credential-guessing vector entirely, forcing key-based access that resists brute force. Restricting key exchange to curve25519-sha256 enforces ephemeral elliptic-curve Diffie-Hellman, delivering forward secrecy so compromised long-term keys cannot decrypt past sessions. Together these satisfy both the brute-force and forward-secrecy constraints in the stem.

Why this answer

Disabling password authentication forces the use of key-based authentication, which is resistant to brute-force attacks. Restricting key exchange algorithms to those providing forward secrecy (e.g., Curve25519) ensures that session keys cannot be compromised even if the long-term private key is exposed.

289
MCQeasy

An organization's security team has drafted a new acceptable use policy that defines how employees may handle company devices, email, and internet access. Before the policy is published and enforced, which action is most important to complete?

A.Translate the policy into every language spoken by employees before any review occurs
B.Archive the draft in the document management system with a version number
C.Publish the policy on the intranet and begin disciplinary enforcement immediately
D.Obtain review and formal approval from executive management and the appropriate governance body
AnswerD

Policies gain authority only when senior leadership formally approves them, which signals organizational commitment and provides the mandate for enforcement. Approval by executive management and the relevant governance body also ensures the policy aligns with business objectives and legal obligations, and it establishes accountability if disciplinary action is later required for violations, making this the essential step before publication.

Why this answer

Approval by executive management and the relevant governance body is what gives a policy its authority. Without that endorsement, the acceptable use policy is an unreviewed draft that cannot be enforced consistently, may conflict with legal or contractual obligations, and offers no defensible basis for disciplinary action. Distribution, translation, and version archiving are supporting activities that follow approval.

Exam trap

The trap here is focusing on distribution mechanics such as publishing or translating, when the policy's legitimacy depends on formal leadership approval before anything else.

290
MCQhard

A security engineer needs to design a solution to detect and respond to insider threats involving unauthorized data exfiltration via USB devices. Which of the following is the MOST effective approach?

A.Conduct regular security awareness training on data handling policies.
B.Deploy endpoint detection and response (EDR) agents on all workstations.
C.Disable all USB ports via group policy.
D.Implement a data loss prevention (DLP) solution with device control and content inspection.
AnswerD

DLP with device control blocks or audits USB mass-storage use, while content inspection identifies sensitive data being copied, catching exfiltration attempts regardless of user intent. This combination directly addresses unauthorised USB data movement, which endpoint logging alone cannot prevent.

Why this answer

The most effective because a DLP solution with device control and content inspection can monitor, block, or alert on unauthorized data transfers to USB devices by inspecting the content being written (e.g., file types, keywords, patterns) and enforcing policies at the endpoint or network level. This directly addresses the specific threat of data exfiltration via USB, unlike other options that either lack detection or are too restrictive.

Exam trap

The trap here is that candidates often choose EDR (Option B) because they associate it with endpoint security, but EDR is designed for threat detection (e.g., malware, lateral movement), not for granular data exfiltration control via USB, which requires DLP's content-aware inspection and device control capabilities.

How to eliminate wrong answers

Option A is wrong because security awareness training is a preventive control that relies on user compliance and does not provide real-time detection or automated response to unauthorized USB data transfers. Option B is wrong because EDR agents focus on detecting and responding to malware and suspicious process behavior, not on monitoring or blocking file copy operations to removable media. Option C is wrong because disabling all USB ports via group policy is a brute-force approach that prevents legitimate use (e.g., keyboards, mice) and does not allow for granular control or detection of authorized vs. unauthorized data transfers.

291
MCQmedium

An organization wants to detect attackers who have already breached the network by deploying decoy credentials and data files. Which type of deception technology should they use?

A.Sandbox
B.Honeypot
C.Honeytoken
D.Honeynet
AnswerC

Honeytokens are decoy credentials, files or records that have no legitimate use, so any access or use signals an attacker already inside the network. This matches the requirement to detect breached attackers, unlike honeypots, which are decoy systems rather than planted data artefacts.

Why this answer

Honeytokens are decoy credentials, API keys, or data files placed in systems that legitimate users would never access. When an attacker uses them, an alert fires, revealing the breach. This matches the requirement to detect attackers already inside the network using decoy credentials and files.

Exam trap

CAS-005 often tests the confusion between honeypots (decoy systems) and honeytokens (decoy credentials/files), causing candidates to pick the broader deception category instead of the precise technique.

How to eliminate wrong answers

Option A (Sandbox) is wrong because a sandbox is an isolated environment for detonating and analyzing suspicious files or code, not for planting decoy credentials to detect intruders. Option B (Honeypot) is wrong because a honeypot is a decoy system or service designed to attract attackers, not a planted credential or file. Option D (Honeynet) is wrong because a honeynet is a network of honeypots, which is broader than the specific decoy-credential technique described.

292
Multi-Selecthard

A security engineer is deploying a zero trust architecture for a hybrid cloud environment. The organization wants to enforce least privilege access to internal APIs. The engineer must select TWO mechanisms that provide continuous authentication and authorization for each API request. (Choose two.)

Select 2 answers
A.Mutual TLS (mTLS) with short-lived client certificates issued by an internal CA.
B.OAuth 2.0 access tokens with a one-hour expiry and no refresh tokens.
C.Static API keys stored in a configuration file and rotated every 90 days.
D.A service mesh sidecar proxy that enforces per-request authorization policies based on workload identity.
E.IP allowlisting based on the source subnet of the API caller.
AnswersA, D

mTLS ensures that both the client and server authenticate each other using certificates. Short-lived certificates limit the window of compromise and force frequent re-authentication, aligning with zero trust principles. This mechanism provides strong identity verification for each API request, and when combined with a policy engine, enables continuous authorization decisions based on certificate attributes.

Why this answer

Continuous authentication and authorization in zero trust require identity-based mechanisms that evaluate every request. Mutual TLS with short-lived certificates verifies the client's identity cryptographically, while a service mesh sidecar enforces per-request authorization policies based on workload identity. Together, they ensure that each API call is authenticated and authorized based on dynamic policy, not static network trust.

Exam trap

The trap here is equating network-level controls like IP allowlisting or long-lived tokens with continuous per-request identity verification, which zero trust explicitly rejects.

293
MCQhard

An organization is implementing a privacy program based on privacy by design. Which principle requires that privacy controls be integrated into the system's default settings?

A.Full functionality – positive-sum, not zero-sum
B.Privacy embedded into design
C.Privacy as the default setting
D.Proactive not reactive; preventative not remedial
AnswerC

Privacy as the default setting requires that systems automatically apply the strictest privacy protections without user intervention, so personal data is protected unless the individual opts otherwise. This directly satisfies the requirement that controls be integrated into default settings.

Why this answer

Privacy as the default setting is the privacy-by-design principle requiring that privacy protections be built into the system's default configuration, so users do not have to take action to protect their data. It means the most privacy-protective settings are on by default, and users must opt in to share more. This directly matches the question's wording about default settings.

Exam trap

The trap is mixing up the seven privacy-by-design principles; candidates often pick 'privacy embedded into design' when the question specifically mentions default settings.

How to eliminate wrong answers

Option A is wrong because full functionality (positive-sum) means privacy and functionality should not be traded off against each other; it does not address default settings. Option B is wrong because privacy embedded into design means privacy is considered from the start of system design, not specifically that defaults are privacy-protective. Option D is wrong because proactive not reactive means anticipating and preventing privacy issues before they occur, rather than remediating after; it does not describe default settings.

294
MCQeasy

An organization wants to collect threat intelligence from multiple Information Sharing and Analysis Centers (ISACs) relevant to their industry. Which of the following is a primary benefit of participating in an ISAC?

A.Free penetration testing services
B.Access to proprietary threat intelligence feeds
C.Ability to share sensitive information anonymously
D.Timely and relevant threat data from peers
AnswerD

ISAC membership gives sector-specific sharing between peers facing comparable threats, so members receive timely, relevant threat data — indicators and tactics — far faster than public feeds, directly satisfying the requirement to collect intelligence from multiple industry-relevant centres.

Why this answer

ISACs provide a trusted community for sharing threat intelligence, early warnings, and best practices, helping members defend against sector-specific threats.

295
MCQeasy

A security manager is updating the organization's risk register. A new risk has been identified: a critical vendor may fail to provide timely security patches, potentially leading to a breach. The manager decides to purchase cyber insurance to cover potential financial losses from such a breach. Which risk treatment strategy does this represent?

A.Risk transference
B.Risk mitigation
C.Risk avoidance
D.Risk acceptance
AnswerA

Risk transference shifts the financial impact of a risk to a third party, typically through insurance or contracts. By purchasing cyber insurance, the organization transfers the potential financial losses from a breach to the insurer. This is a classic example of risk transference. The risk itself remains, but the financial burden is shared or shifted. This aligns with the scenario.

Why this answer

Purchasing cyber insurance transfers the financial impact of a potential breach to the insurer. Risk transference is the correct treatment because the organization is not reducing the likelihood or impact through controls, nor is it avoiding the risk or accepting it without action. Insurance is a common method of transferring financial risk associated with vendor failures.

Exam trap

The trap here is confusing risk transference with risk mitigation; insurance does not reduce the chance of a breach, it only transfers the financial consequences.

296
MCQmedium

An organization is implementing SSH hardening for server access. Which configuration change most effectively reduces the attack surface against brute-force and credential theft?

A.Change the default SSH port from 22 to a high-numbered port.
B.Enable public-key authentication and disable password authentication.
C.Set MaxAuthTries to 6 to limit login attempts.
D.Use TCP wrappers to restrict source IP addresses.
AnswerB

Public-key authentication replaces reusable passwords with a private key the client holds, so there is no shared secret to brute-force or steal through phishing. Disabling password authentication removes that credential path entirely, directly shrinking the attack surface.

Why this answer

Public-key authentication replaces the shared secret (password) with an asymmetric key pair, so there is no reusable credential an attacker can brute-force or steal via phishing/keylogging. Disabling password authentication also eliminates the entire class of credential-guessing attacks against SSH. This is the single most impactful hardening step because it removes the attack vector rather than merely slowing it down.

Exam trap

The trap here is confusing 'reducing attack surface' with 'obscuring the service' — candidates often pick port changes or rate-limiting because they sound like hardening, but only eliminating the password credential actually removes the attack vector.

How to eliminate wrong answers

Option A is wrong because changing the SSH port only obscures the service (security through obscurity) and does not stop brute-force tools that scan all ports or target the service directly. Option C is wrong because MaxAuthTries=6 actually permits more attempts than the default of 6 is not a reduction — the default is already 6, and raising or keeping it does not eliminate credential theft; it only throttles guessing. Option D is wrong because TCP wrappers restrict source IPs but do not prevent brute-force from allowed networks or credential theft via compromised hosts inside the permitted range.

297
MCQmedium

An organization uses a multi-cloud strategy with workloads on AWS, Azure, and GCP. They need a single tool to monitor and enforce security configurations across all cloud environments. Which cloud security solution is best suited for this requirement?

A.Secure Access Service Edge (SASE)
B.Cloud Access Security Broker (CASB)
C.Cloud Workload Protection Platform (CWPP)
D.Cloud Security Posture Management (CSPM)
AnswerD

CSPM continuously assesses configurations against benchmarks and compliance frameworks across AWS, Azure and GCP through native APIs, satisfying the single-tool, multi-cloud monitoring and enforcement constraint. It detects misconfigurations such as public storage buckets and overly permissive IAM policies, unlike single-cloud native tooling.

Why this answer

CSPM is correct because it continuously monitors cloud configurations against security benchmarks (CIS, NIST, PCI) and detects misconfigurations across AWS, Azure, and GCP from a single pane of glass. It is purpose-built for multi-cloud posture management — identifying publicly exposed buckets, overly permissive IAM roles, and unencrypted storage. This directly matches the requirement to monitor and enforce security configurations across all three clouds.

Exam trap

CAS-005 often tests the CSPM vs. CWPP vs. CASB distinction — candidates pick CWPP or CASB because they 'secure the cloud,' but only CSPM continuously monitors and enforces configuration posture across multiple clouds.

How to eliminate wrong answers

Option A is wrong because SASE converges networking and security (SD-WAN, SWG, ZTNA, CASB) at the network edge for user traffic — it does not assess cloud resource configurations. Option B is wrong because CASB governs access to and data in cloud services (shadow IT, DLP, API control), not the security posture of cloud infrastructure. Option C is wrong because CWPP protects running workloads (VMs, containers, serverless) at runtime — it addresses workload security, not configuration compliance across cloud accounts.

298
MCQmedium

An organization is implementing a Secure Access Service Edge (SASE) architecture. Which of the following is a key component of SASE?

A.Demilitarized Zone (DMZ)
B.Cloud Access Security Broker (CASB)
C.Intrusion Prevention System (IPS)
D.Virtual Private Network (VPN)
AnswerB

A CASB enforces data-security policy between users and cloud services, delivering the threat protection, data-loss prevention and visibility SASE requires for cloud-bound traffic. It satisfies the stem's SASE component requirement because SASE converges networking with exactly these cloud-security functions, alongside SWG, ZTNA and FWaaS, rather than relying on on-premises appliances.

Why this answer

SASE (Secure Access Service Edge) converges networking (SD-WAN) with a stack of cloud-delivered security services, and CASB is one of its core security pillars alongside SWG, ZTNA, and FWaaS. CASB provides visibility and control over cloud application usage, enforces DLP, and detects shadow IT — functions that SASE delivers from a globally distributed edge. DMZ, IPS, and VPN are traditional on-premises or point-solution constructs that SASE is explicitly designed to replace or absorb, not core defining components.

Exam trap

CAS-005 often tests whether candidates can distinguish SASE's core components (CASB, SWG, ZTNA, FWaaS, SD-WAN) from legacy security appliances like DMZ, IPS, and VPN that SASE replaces.

How to eliminate wrong answers

Option A is wrong because a DMZ is a legacy network segmentation pattern for hosting public-facing services; SASE eliminates the need for backhauling traffic to a DMZ by enforcing policy at the cloud edge. Option C is wrong because an IPS is a network security appliance/function; while FWaaS within SASE may include IPS capabilities, IPS itself is not a named core SASE component. Option D is wrong because a traditional VPN is a remote-access tunneling technology that SASE supersedes with ZTNA's identity-based, per-application access model.

299
Multi-Selectmedium

A security operations team is developing a SOAR playbook to automate response to a detected ransomware outbreak. The team wants to ensure the playbook can contain the threat quickly while minimizing business disruption. Which TWO actions should the playbook include as automated responses? (Select TWO.)

Select 2 answers
A.Run a full antivirus scan on all systems
B.Restore all systems from the latest backup automatically
C.Power off all affected servers immediately
D.Block outbound traffic to known malicious IP addresses and domains
E.Isolate the affected endpoints from the network
AnswersD, E

Blocking outbound traffic to known malicious IPs and domains via firewall or DNS sinkhole rules halts command-and-control communication and data exfiltration, directly satisfying the containment requirement while leaving internal business services untouched. This limits ransomware spread without disrupting legitimate user access, unlike broad network isolation.

Why this answer

Option D is correct because blocking outbound traffic to known malicious IP addresses and domains (e.g., via firewall, proxy, or DNS sinkhole rules) severs command-and-control (C2) and exfiltration channels, which is a fast, low-disruption containment action that prevents the ransomware from receiving instructions or leaking data. Option E is correct because isolating affected endpoints from the network (for example, via EDR network containment or switch port/VLAN quarantine) stops lateral movement and further encryption or spread while leaving the hosts powered on for forensic memory capture and recovery. Option A is not appropriate as an automated containment response because a full antivirus scan is slow, resource-intensive, and does not stop an active outbreak.

Option B is not appropriate because automatically restoring all systems from backup can overwrite forensic evidence, reintroduce malware if the backup is compromised, and cause major business disruption before the threat is contained. Option C is not appropriate because powering off affected servers immediately destroys volatile memory evidence, can corrupt encrypted or in-flight data, and may disrupt critical services more than isolation would.

Exam trap

The trap here is confusing containment with eradication or recovery — candidates pick 'run antivirus' or 'restore backups' because those sound like fixing the problem, but the question asks for immediate containment actions that stop spread without destroying evidence or availability.

300
Multi-Selectmedium

A security manager is implementing a policy exception management process. Which TWO of the following are essential components of an effective exception management process?

Select 2 answers
A.A policy that all exceptions are denied
B.A defined expiration date for each exception
C.A formal request and approval workflow
D.Automatic approval for temporary workarounds
E.Immediate policy revision to eliminate the need for exceptions
AnswersB, C

Expiration dates enforce time-bound risk acceptance, ensuring exceptions are reviewed and renewed rather than persisting indefinitely. This directly satisfies the process requirement for periodic reassessment, preventing stale waivers from silently accumulating. Without expiry, exceptions become permanent policy bypasses, undermining governance and auditability across Microsoft Entra ID and other controlled environments.

Why this answer

An effective exception management process requires a formal request and approval workflow (C) so that each exception is documented, justified, risk-assessed, and authorized by the appropriate authority rather than granted informally. It also requires a defined expiration date for each exception (B), ensuring exceptions are temporary, time-bound, and reviewed or renewed before they become permanent policy gaps. Together, these components provide accountability and limit risk exposure.

Option A is wrong because blanket denial of all exceptions is impractical and prevents legitimate business needs from being addressed. Option D is wrong because automatic approval of temporary workarounds bypasses risk review and oversight. Option E is wrong because immediately revising policy to eliminate every exception is not always feasible and does not constitute an exception management process.

Exam trap

The trap is selecting options that sound efficient (automatic approval, immediate policy revision) but actually undermine the control and accountability that exception management is meant to provide.

Page 3

Page 4 of 13

Page 5