Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 301–375

973 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQhard

During an API security review, an assessor finds that the API uses JSON Web Tokens (JWT) with a symmetric key shared among multiple services. Which of the following is the MOST significant security concern?

A.The token is not encrypted
B.Multiple services share the same symmetric key
C.The token does not include audience claim
D.Token expiration is not set
AnswerB

A shared symmetric key means any compromised service can forge valid tokens for every other service, breaking per-service authentication boundaries. Asymmetric signing with per-service keys, or centralised issuance, would contain the blast radius of a single compromised credential.

Why this answer

The most significant security concern is that multiple services share the same symmetric key. With a shared symmetric key, any service can forge tokens that are accepted by other services, leading to a lack of non-repudiation and increased blast radius if one service is compromised. This violates the principle of least privilege and increases the risk of token forgery.

Exam trap

CAS-005 often tests the misconception that encryption is the primary concern for JWTs, but the bigger risk is often key management and sharing, which enables token forgery.

How to eliminate wrong answers

Option A is wrong because while not encrypting the token (using JWS instead of JWE) means the payload is readable, it is not the most significant concern if the token is transmitted over HTTPS and contains no sensitive data; integrity is still protected. Option C is wrong because missing audience claim can lead to token misuse across services, but it is less severe than a shared symmetric key, as the audience claim is a defense-in-depth measure. Option D is wrong because missing expiration increases the window of opportunity for token misuse, but again, it is less critical than a shared key that allows token forgery.

302
MCQhard

A security architect must protect data at rest on a database server while allowing a backup application to read the raw encrypted files without ever holding the plaintext data key. The architect wants a design where a hardware security module (HSM) enforces key usage policy and keys never leave the module in plaintext. Which approach BEST satisfies these requirements?

A.Apply full-disk encryption with a passphrase-protected key and share the passphrase with the backup operators.
B.Encrypt the database with a key stored in a software keystore and grant the backup service read access to that keystore.
C.Store the data key in a TPM sealed to the database server's boot measurements and let the backup service request unsealing remotely.
D.Use envelope encryption where the data key is wrapped by a master key resident in the HSM, and decrypt the data key only inside the HSM for authorized operations.
AnswerD

Envelope encryption keeps bulk data encrypted under a data key, while the HSM holds the master key that wraps it. The backup application can copy ciphertext freely, but unwrapping the data key happens only inside the HSM under its usage policy, so the plaintext key never leaves the module. This satisfies both the at-rest protection and HSM-enforced control requirements.

Why this answer

Envelope encryption separates the bulk data key from a master key held inside the HSM. Backup processes can handle ciphertext without ever seeing the plaintext data key, because unwrapping occurs only within the HSM under its enforced policy. This design satisfies both the confidentiality requirement and the constraint that key material never leaves the hardware module.

Exam trap

The trap here is treating any hardware-rooted key storage as equivalent, when only an HSM enforcing wrap and unwrap policy keeps the plaintext data key from ever leaving the boundary.

303
MCQmedium

An enterprise is adopting a DevOps model and wants to integrate security into the CI/CD pipeline. The security architect recommends adding automated security testing. Which phase of the pipeline should static application security testing (SAST) be introduced to minimize rework?

A.During the build phase after code commit
B.During the production deployment phase
C.After the code is promoted to production
D.During runtime in the staging environment
AnswerA

SAST analyses source code without executing it, so running it during the build phase immediately after commit catches flaws before they propagate into later artefacts. This satisfies the constraint of minimising rework, since defects are cheapest to fix at the earliest pipeline stage.

Why this answer

SAST scans source code or compiled binaries for vulnerabilities without executing the application. Introducing SAST during the build phase, immediately after code commit and before artifacts are packaged, allows developers to catch and fix security flaws early when remediation cost is lowest, aligning with the 'shift left' principle in DevOps.

Exam trap

CompTIA often tests the distinction between SAST (static, pre-execution) and DAST (dynamic, runtime), and the trap here is assuming security testing can be deferred to later stages like staging or production without understanding the cost of rework.

How to eliminate wrong answers

Option B is wrong because production deployment is too late; vulnerabilities found here require emergency patches or rollbacks, increasing rework and risk. Option C is wrong because promoting code to production before security testing defeats the purpose of CI/CD security gates and exposes the live environment to exploits. Option D is wrong because runtime in staging is the domain of DAST (Dynamic Application Security Testing) or IAST, not SAST; SAST does not execute code and cannot analyze runtime behavior.

304
MCQhard

An organization is implementing a privacy program to comply with GDPR. Which of the following BEST describes the concept of 'privacy by design' as it applies to a new customer relationship management (CRM) system?

A.Incorporating data minimization and access controls into the system architecture from the start.
B.Assigning a data protection officer to review system logs quarterly.
C.Adding a privacy notice to the CRM after deployment.
D.Conducting a privacy impact assessment (PIA) after the system is live.
AnswerA

Privacy by design embeds data minimisation and access controls into the CRM architecture from inception, rather than retrofitting them later. This satisfies GDPR's requirement that protection be built into processing systems and default settings before personal data is collected.

Why this answer

Privacy by design is a foundational GDPR principle (Article 25) requiring data protection to be embedded into systems and processes from the outset, not bolted on afterward. Option A captures this by integrating data minimization and access controls into the CRM's architecture during design, which is exactly what 'by design' means. This proactive approach reduces compliance risk and prevents costly retrofits.

Exam trap

CAS-005 often tests the misconception that privacy by design is about post-deployment activities like privacy notices or audits, rather than proactive architectural integration.

How to eliminate wrong answers

Option B is wrong because assigning a DPO to review logs quarterly is an operational oversight activity, not a design-time control embedded in the system architecture. Option C is wrong because adding a privacy notice after deployment is a reactive, cosmetic measure that does not embed privacy into the system's design. Option D is wrong because conducting a PIA after the system is live is too late — GDPR requires DPIAs before processing begins, especially for high-risk processing.

305
MCQmedium

During a threat hunting exercise, a security analyst hypothesizes that an adversary is using PowerShell to execute malicious scripts. Which approach is the analyst employing?

A.TTP-driven hunting
B.Machine learning-driven hunting
C.IoC-driven hunting
D.Hypothesis-driven hunting
AnswerD

The analyst forms a specific proposition about adversary behaviour, PowerShell execution, then hunts for evidence supporting or refuting it. This structured, hypothesis-first method is hypothesis-driven hunting, matching the stem's constraint of starting from a stated theory rather than an indicator or alert.

Why this answer

Hypothesis-driven hunting starts with a specific assumption about adversary behavior, unlike IoC-driven (based on known indicators) or TTP-driven (focused on tactics, techniques, procedures).

306
MCQmedium

A security architect is reviewing the identity architecture for a company that uses a hybrid cloud. Employees authenticate to an on-premises Active Directory Domain Services (AD DS) domain and also need to access SaaS applications. The company wants to avoid storing separate passwords for each SaaS application and wants to enforce on-premises account status and group membership in real time. Which of the following should the architect implement?

A.Deploy a standalone LDAP directory in the cloud and synchronize user passwords from AD DS using a one-way hash, then point each SaaS application to the cloud LDAP service.
B.Configure each SaaS application with a separate local account for every employee, and use a password manager to generate and store unique passwords.
C.Implement RADIUS authentication between the SaaS applications and the on-premises AD DS, and rely on RADIUS attributes to convey group membership.
D.Federate the on-premises AD DS with each SaaS application using SAML 2.0, and configure the SaaS applications to trust the on-premises identity provider.
AnswerD

Federating AD DS with SAML 2.0 allows the on-premises domain to act as the identity provider, so employees use their existing AD credentials and the SaaS application receives assertions about group membership and account status. This avoids separate passwords and enforces on-premises account state in real time because the identity provider evaluates the account at each authentication. It is the standard approach for hybrid identity with SaaS.

Why this answer

Federating on-premises AD DS with SAML 2.0 makes the domain the identity provider for SaaS applications. Users authenticate once with their AD credentials, and the SaaS application receives assertions about group membership and account status at each login. This satisfies the requirements for no separate passwords and real-time enforcement of on-premises account state, unlike cloud LDAP, local accounts, or RADIUS.

Exam trap

The trap here is confusing authentication protocols that sound similar, such as LDAP or RADIUS, with the SAML federation that SaaS applications actually use for browser-based single sign-on.

307
MCQeasy

Which of the following is a primary function of a Cloud Access Security Broker (CASB)?

A.Scan container images for vulnerabilities
B.Provide IAM for cloud infrastructure
C.Enforce security policies between users and cloud applications
D.Monitor network traffic at the packet level
AnswerC

A CASB sits inline or via APIs between users and cloud services, enforcing policy at that boundary. This directly satisfies the stem's requirement for a primary function: it governs access and data flows to sanctioned and unsanctioned cloud applications, providing visibility and control.

Why this answer

A CASB sits between users and cloud applications and enforces security policies such as data loss prevention, access control, encryption, and compliance monitoring. Its core purpose is to provide visibility and control over cloud service usage, which is exactly what Option C describes.

Exam trap

CAS-005 often tests the boundary between CASB and adjacent technologies — candidates confuse CASB with IAM, container security, or network monitoring because all involve 'cloud security'.

How to eliminate wrong answers

Option A is wrong because scanning container images for vulnerabilities is the function of a container security scanner (e.g., Trivy, Aqua, Twistlock), not a CASB. Option B is wrong because IAM for cloud infrastructure is provided by the cloud provider's native IAM service (e.g., AWS IAM, Azure Entra ID) or third-party IAM tools, not a CASB. Option D is wrong because packet-level network monitoring is performed by firewalls, IDS/IPS, or network TAPs — a CASB operates at the application/API layer, not the packet layer.

308
MCQeasy

A systems administrator is hardening a Linux server that stores regulated data. The requirement is that the server's filesystem must detect unauthorized modification of files at rest, including offline tampering with the disk. Which control BEST meets this requirement?

A.Deploy file integrity monitoring that hashes files and compares them against a known-good baseline on a schedule.
B.Enable full-disk encryption with LUKS using a passphrase entered at boot.
C.Set the immutable attribute on critical files using chattr +i and restrict root access.
D.Enable dm-verity on the filesystem so that reads are validated against a signed hash tree.
AnswerD

dm-verity is a device-mapper target that stores a hash tree and verifies each block as it is read, with the root hash protected by a signature. If an attacker alters data offline, the recomputed hash will not match the tree and reads fail. This provides detection of at-rest tampering even when the disk is modified outside the running system, exactly matching the requirement.

Why this answer

dm-verity provides cryptographic verification of filesystem blocks against a signed hash tree, so any offline modification of the disk causes verification to fail when the data is read. Encryption, integrity monitoring, and filesystem attributes each address different threats and none of them reliably detects offline tampering of the protected volume.

Exam trap

The trap here is equating encryption with integrity, when encryption protects confidentiality and provides no reliable detection of offline modification.

309
MCQeasy

An organization is deploying a new IoT device that must securely update its firmware over the air (OTA). The device has limited processing power and memory. Which cryptographic solution would provide the BEST balance of security and performance for verifying firmware updates?

A.RSA-4096 digital signatures
B.Ed25519 digital signatures
C.HMAC-SHA256 with pre-shared key
D.AES-256-GCM for authentication
AnswerB

Ed25519 signatures verify firmware authenticity with minimal computation, satisfying the constrained processor and memory requirement. Its compact 64-byte signatures and 32-byte keys reduce storage and transmission overhead, while verification is far faster than RSA at equivalent security. This makes it ideal for OTA updates on resource-limited IoT devices.

Why this answer

Ed25519 is a fast and secure digital signature algorithm that performs well on constrained devices. RSA 4096 is computationally expensive. HMAC-SHA256 is a symmetric key technique and requires key management overhead.

AES-256-GCM is for encryption, not verification.

310
MCQmedium

Which of the following is a key feature of TLS 1.3 compared to earlier versions?

A.Mandatory use of static RSA key exchange
B.Support for RC4 cipher
C.Backward compatibility with SSL 3.0
D.Reduced handshake latency
AnswerD

TLS 1.3 cuts the handshake to a single round trip by combining key exchange and authentication, and supports zero round-trip resumption for repeat connections. This directly satisfies the question's comparison against earlier versions, which required two round trips, thereby reducing latency.

Why this answer

TLS 1.3 reduces handshake latency by combining the ClientHello and key share into a single round trip (1-RTT) and supporting 0-RTT resumption for repeat connections. It also removes legacy features like static RSA key exchange, RC4, and SSL 3.0 compatibility. The net effect is faster connection establishment without sacrificing security.

Exam trap

CAS-005 often tests the misconception that TLS 1.3 is merely an incremental update — candidates must remember it removed legacy algorithms and backward compatibility rather than adding them.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 removed static RSA key exchange entirely, mandating forward-secret key exchanges like ECDHE. Option B is wrong because RC4 was deprecated and removed from TLS 1.3 due to known cryptographic weaknesses. Option C is wrong because TLS 1.3 explicitly dropped backward compatibility with SSL 3.0 (and even TLS 1.0/1.1) to eliminate downgrade attacks.

311
MCQhard

A security engineer is configuring a Web Application Firewall (WAF) to protect an e-commerce site against SQL injection attacks. The WAF is deployed in reverse proxy mode. The engineer notices that legitimate search queries containing single quotes are being blocked. Which of the following actions should the engineer take to reduce false positives while maintaining protection?

A.Tune the SQL injection rule to allow single quotes in specific parameter contexts, such as search parameters, while still blocking suspicious patterns.
B.Switch the WAF to detection-only mode so that it logs but does not block SQL injection attempts.
C.Disable the SQL injection rule set entirely to prevent blocking of legitimate traffic.
D.Create a whitelist rule that allows requests containing single quotes from known trusted IP addresses.
AnswerA

Tuning the rule to understand the application's expected input, such as allowing single quotes in search parameters but still detecting SQL injection patterns like ' OR '1'='1', reduces false positives while maintaining protection. This contextual approach is a best practice for WAF tuning, balancing security and usability.

Why this answer

Tuning the SQL injection rule to allow single quotes in specific contexts, such as search parameters, while still blocking malicious patterns is the most effective way to reduce false positives without compromising security. This approach requires understanding the application's normal input and crafting rules that distinguish between benign and malicious use of special characters.

Exam trap

The trap here is thinking that any request with a single quote is malicious, when in fact legitimate queries may contain them, and the solution is contextual tuning rather than blanket blocking.

312
MCQhard

A government agency is designing a system that processes highly sensitive data on a need-to-know basis. The security architect must ensure that access decisions consider the user's clearance level, the data's classification label, and the user's current role, and that users cannot change their own labels. Which of the following access control models best fits these requirements?

A.Role-based access control, where permissions are assigned to roles and users are placed into roles by their manager.
B.Discretionary access control, where data owners set permissions on the objects they own.
C.Attribute-based access control, where a policy evaluates any combination of user, resource, and environment attributes.
D.Mandatory access control, where the system compares the subject's clearance and the object's classification label and enforces the result.
AnswerD

Mandatory access control enforces access decisions by comparing the subject's clearance level with the object's classification label, and the labels are managed by the system rather than by users. This directly satisfies the requirement to consider clearance and classification together and prevents users from changing their own labels. It is the standard model for need-to-know enforcement in government and defense environments handling sensitive data.

Why this answer

Mandatory access control is designed for environments where the system, not the user, manages sensitivity labels and clearance levels. It compares the subject's clearance to the object's classification and enforces the result, which directly implements need-to-know. Role-based and discretionary models lack this mandatory label comparison, and attribute-based access control, while flexible, does not inherently guarantee that labels remain outside user control.

Exam trap

The trap here is assuming that any model which can evaluate multiple attributes is equivalent to mandatory access control, when the defining property is that labels are system-managed and not user-modifiable.

313
MCQmedium

A company is required to comply with FedRAMP for its cloud deployment. Which of the following is a key requirement for FedRAMP compliance?

A.Continuous monitoring and incident response
B.Third-party assessment by an accredited organization
C.Implementation of AES-256 encryption for all data
D.Annual penetration testing by internal team
AnswerB

FedRAMP requires an independent assessment by a Third-Party Assessment Organization accredited under the programme, which validates the cloud service's security controls against NIST baselines before an agency can grant authorisation. This external evaluation is the key requirement the stem asks for.

Why this answer

FedRAMP requires that cloud service offerings undergo an independent third-party assessment by a FedRAMP-accredited Third Party Assessment Organization (3PAO) to validate security controls against NIST SP 800-53. This assessment is a cornerstone of the FedRAMP authorization process, ensuring an unbiased evaluation before a Joint Authorization Board (JAB) or agency grants an Authority to Operate (ATO). While continuous monitoring and incident response are also required, the key differentiator is the mandatory third-party assessment.

Exam trap

CAS-005 often tests the misconception that FedRAMP is just about encryption or continuous monitoring — candidates must recognise that the mandatory third-party assessment by an accredited 3PAO is the defining requirement.

How to eliminate wrong answers

Option A is wrong because continuous monitoring and incident response, while required by FedRAMP, are also common to many frameworks (e.g., FISMA, ISO 27001) and are not unique to FedRAMP; the question asks for a key requirement that distinguishes FedRAMP. Option C is wrong because AES-256 encryption is a best practice and often required for data at rest, but FedRAMP does not mandate a specific algorithm; it requires encryption based on NIST guidelines, which may include AES-256 but also allows other FIPS 140-2 validated algorithms. Option D is wrong because annual penetration testing by an internal team is not a FedRAMP requirement; FedRAMP requires annual penetration testing by a 3PAO or qualified independent party, and continuous monitoring includes vulnerability scanning.

314
MCQmedium

A security architect is designing a data-at-rest protection scheme for a database that stores regulated records on a shared storage array. The requirement is to ensure that even if an administrator copies the raw storage volume, the data cannot be read, and that the keys are never accessible to the storage administrator. Which of the following BEST meets these requirements?

A.Transparent data encryption (TDE) enabled on the database instance with the master key stored in the database's internal keystore
B.Filesystem-level encryption on the database server with keys protected only by the operating system's file permissions
C.Application-level encryption of sensitive columns using keys held in a hardware security module (HSM) with strict role separation
D.Full-disk encryption using the storage array's built-in controller-based encryption with keys managed by the array firmware
AnswerC

Encrypting at the application layer with keys resident in an HSM means the ciphertext stored on the shared array is useless without the HSM, and role separation prevents the storage administrator from accessing key material. This directly satisfies both the confidentiality requirement for copied volumes and the key-access restriction.

Why this answer

The strongest control is application-level encryption whose keys live in an HSM with strict role separation, because the ciphertext on shared storage is meaningless without the HSM and the storage administrator cannot reach the keys. Controller, database, and filesystem encryption all leave key material accessible to privileged administrators in the same trust domain.

Exam trap

The trap here is assuming that any encryption at rest satisfies the key-separation requirement, when array, database, and OS-level encryption all expose keys to privileged administrators.

315
Multi-Selecthard

A security architect is designing a data classification scheme aligned with a new privacy regulation. Which THREE of the following are common data classification levels used in enterprise environments? (Select THREE.)

Select 3 answers
A.Public
B.Internal
C.Critical
D.Secret
E.Confidential
AnswersA, B, E

Public denotes information approved for unrestricted disclosure, carrying no confidentiality requirement. It satisfies the stem's requirement for a common classification level, forming the lowest tier of enterprise schemes and letting architects label marketing material, published policies and open datasets without unnecessary controls.

Why this answer

Common classification levels include public (no impact), internal (moderate impact), confidential (high impact), and restricted (very high impact). Secret is typically a government classification, not enterprise. Critical is not a standard classification level.

316
MCQhard

A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The architect plans to use full-disk encryption (FDE) with a TPM 2.0 module. Which of the following BEST describes a limitation of this approach that the architect must address?

A.FDE with TPM does not protect data if the operating system is running and an attacker gains remote access.
B.TPM 2.0 modules are vulnerable to cold boot attacks that can extract the encryption key from RAM.
C.TPM 2.0 requires a PIN to be entered at every boot, which is impractical for servers.
D.FDE with TPM cannot be used with self-encrypting drives (SEDs) or hardware encryption.
AnswerA

Full-disk encryption protects data only when the system is powered off or the volume is locked. Once the OS is running and the volume is decrypted, any process or remote attacker with sufficient privileges can read the data. The TPM unseals the key during boot, so the disk remains transparently accessible. This limitation means additional controls like file-level encryption or access controls are needed for runtime protection.

Why this answer

Full-disk encryption with TPM protects data at rest when the system is off or locked. Once the OS is running, the volume is decrypted and accessible to any process with sufficient privileges, including remote attackers. This runtime exposure is the key limitation.

Other options misstate TPM capabilities or conflate optional features with fundamental constraints.

Exam trap

The trap here is believing that full-disk encryption continues to protect data after the operating system has booted and unlocked the volume.

317
MCQmedium

Based on the exhibit, what is the primary purpose of the condition in this IAM policy?

A.Enable encryption in transit for the S3 bucket
B.Allow all incoming traffic to the S3 bucket
C.Deny access from the specified IP ranges
D.Restrict access to requests originating from the specified IP ranges
AnswerD

The condition compares the request's source IP against defined ranges, permitting access only when the origin falls within them. This satisfies the policy's constraint of scoping permissions geographically or to trusted networks, rejecting requests from any other address.

Why this answer

The condition in the IAM policy uses the `aws:SourceIp` key to restrict access to requests originating from the specified IP ranges. Option A is incorrect because the condition does not address encryption in transit. Option B is incorrect because the policy does not allow all traffic; it allows only requests from the specified IPs.

Option C is incorrect because the policy is an allow with a condition, not a deny statement. The condition effectively limits which IPs can perform the allowed actions, making D the primary purpose.

318
MCQhard

A multinational retailer must demonstrate compliance with the EU General Data Protection Regulation while also honoring local data-residency laws in a country where it operates. Legal counsel advises that a single global retention schedule cannot satisfy both regimes. Which governance artifact should the security manager produce to reconcile these competing obligations?

A.A records retention and residency matrix mapping each data category to jurisdictional requirements
B.An updated acceptable use policy signed by all employees who handle customer data
C.A business continuity plan that documents failover of the retailer's EU data centers
D.A data protection impact assessment covering the retailer's cross-border transfers
AnswerA

A retention and residency matrix ties each data category to the specific retention period and storage location mandated by every applicable jurisdiction, making conflicts explicit and resolvable. This is exactly the governance artifact needed when a single global schedule cannot satisfy GDPR and local residency law, because it allows differentiated handling per jurisdiction while preserving an auditable rationale.

Why this answer

Where global retention rules collide with local residency mandates, the organization needs a structured mapping of each data category to the retention period and permitted location required by every jurisdiction involved. A retention and residency matrix makes the conflicts visible and provides auditable, differentiated handling, whereas privacy assessments, use policies, and continuity plans address risk, behavior, and availability rather than reconciling legal obligations.

Exam trap

The trap here is treating any privacy-focused document, such as a DPIA, as the universal answer for multi-jurisdictional compliance, when the specific need is an artifact that maps obligations per data category and jurisdiction.

319
MCQeasy

A security architect is designing a network segmentation strategy for a multi-tier web application. The web servers must be accessible from the internet, while the application and database servers must only be accessible from the web tier. Which architecture best meets these requirements?

A.Use a single VLAN with access control lists to restrict traffic between servers.
B.Place all servers in the same subnet and use host-based firewalls for isolation.
C.Deploy web servers in a DMZ, application servers in an internal network, and database servers in a separate restricted network with firewall rules allowing only necessary traffic.
D.Use a VPN concentrator for all external access and place all servers in a private subnet.
AnswerC

Placing each tier in its own segment with firewall rules permitting only required flows enforces least-privilege segmentation. Internet-facing web servers sit in the DMZ, while application and database servers remain unreachable from the internet, satisfying the stated access constraints.

Why this answer

It implements a classic three-tier DMZ architecture: web servers in a DMZ (publicly accessible), application servers in an internal network (accessible only from the DMZ), and database servers in a restricted backend network (accessible only from the application tier). This layered segmentation enforces the principle of least privilege and uses firewall rules to control traffic between each tier, ensuring that internet-facing components cannot directly reach sensitive data stores.

Exam trap

The trap here is that candidates often confuse network segmentation with simple access control lists or host-based firewalls, failing to recognize that true segmentation requires separate network zones (DMZ, internal, restricted) with firewall-enforced traffic flows between them.

How to eliminate wrong answers

Option A is wrong because a single VLAN with ACLs does not provide true network segmentation; ACLs on a Layer 3 device can filter traffic but all servers remain in the same broadcast domain, increasing the attack surface and risk of lateral movement. Option B is wrong because placing all servers in the same subnet with host-based firewalls relies solely on endpoint security, which can be bypassed if a host is compromised, and does not provide network-level isolation or defense in depth. Option D is wrong because using a VPN concentrator for all external access and placing all servers in a private subnet would require all users to connect via VPN, which is impractical for a public web application and does not segment internal tiers from each other.

320
Multi-Selectmedium

An organization's security team is reviewing security metrics to present to the board. Which THREE of the following are commonly used Key Performance Indicators (KPIs) for a security program? (Select THREE.)

Select 3 answers
A.Patch compliance percentage
B.Mean time to respond (MTTR)
C.Number of firewalls deployed
D.Vulnerabilities by severity
E.Mean time to detect (MTTD)
AnswersA, B, E

Patch compliance percentage directly measures the proportion of assets carrying current security updates, giving the board a quantifiable view of vulnerability exposure reduction. It is a standard operational KPI because it tracks remediation effectiveness over time against a defined baseline, satisfying the stem's requirement for board-level security programme metrics.

Why this answer

Patch compliance percentage (A) is a valid KPI because it measures the proportion of systems that have current security patches applied within a defined SLA, directly reflecting vulnerability exposure reduction and the effectiveness of patch management. Mean time to respond (B) is a KPI that quantifies the average elapsed time from alert or incident identification to containment/remediation action, showing the operational efficiency of the incident response process. Mean time to detect (E) is a KPI measuring the average time between an actual compromise or event occurring and its detection, which gauges monitoring and detection capability maturity.

Number of firewalls deployed (C) is a raw inventory count, not a performance measure, so it is a metric rather than a KPI. Vulnerabilities by severity (D) is a point-in-time risk/volume metric describing the current state, not a performance indicator of the security program's effectiveness over time.

Exam trap

CAS-005 often tests the distinction between KPIs (outcome-oriented, tied to goals) and raw metrics or vanity counts (e.g., number of firewalls), causing candidates to select inventory counts as KPIs.

321
MCQhard

A financial services firm is designing a new internal API platform. The security architect must ensure that every service-to-service call is authenticated, that a compromised service cannot impersonate another service, and that credentials are short-lived and automatically rotated. The platform runs on Kubernetes and uses an external secrets manager. Which of the following designs best meets these requirements?

A.Rely on network policies that restrict pod-to-pod traffic to approved namespaces and assume that only authorized services can reach each other.
B.Issue a long-lived shared API key to each service and store it in a Kubernetes Secret mounted as an environment variable.
C.Use mutual TLS with certificates issued by a service mesh certificate authority that binds each certificate to the service's Kubernetes service account and rotates it automatically.
D.Require services to present a JSON Web Token signed with a symmetric key that is distributed to all services in the cluster.
AnswerC

Mutual TLS with certificates bound to a Kubernetes service account gives each service a cryptographic identity that cannot be transferred to another service without its private key. A service mesh certificate authority can issue short-lived certificates and rotate them automatically, and the service account binding ensures a compromised pod cannot claim a different service identity. This satisfies authentication, non-impersonation, and automated rotation in one design.

Why this answer

Binding a cryptographic identity to each service's Kubernetes service account through a service mesh certificate authority ensures that a compromised service cannot present another service's identity. Mutual TLS authenticates both ends of every call, and the mesh can issue short-lived certificates and rotate them automatically without manual intervention. The other options either share secrets across services, rely only on network reachability, or use long-lived credentials that are not bound to a specific service identity.

Exam trap

The trap here is treating network segmentation or a shared secret as equivalent to cryptographic service identity, when only a per-service credential bound to an identity prevents impersonation.

322
Multi-Selecthard

A company is implementing a secure SDLC and wants to integrate application security testing early. Which THREE tools are most appropriate for shift-left security? (Select THREE.)

Select 3 answers
A.Runtime Application Self-Protection (RASP)
B.Static Application Security Testing (SAST)
C.Interactive Application Security Testing (IAST)
D.Software Composition Analysis (SCA)
E.Dynamic Application Security Testing (DAST)
AnswersB, C, D

SAST analyses source code without executing it, detecting vulnerabilities during development and satisfying shift-left by finding flaws before deployment. It integrates into CI pipelines and IDEs, unlike DAST, which requires a running application and therefore tests later in the lifecycle.

Why this answer

SAST (B) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find vulnerabilities like injection flaws during coding in the IDE or CI pipeline — the essence of shift-left. IAST (C) is correct because it instruments the running application (often via agents) during functional testing to detect vulnerabilities in real time with code-level detail, fitting early integration into dev/test workflows. SCA (D) is correct because it scans dependencies and third-party libraries for known CVEs and license issues, which is critical for shifting left since most modern code is composed of open-source components.

RASP (A) is not appropriate here because it runs inside the application at runtime in production, protecting against live attacks rather than enabling early pre-deployment testing. DAST (E) is not selected because it tests a deployed running application from the outside (black-box), typically later in the pipeline, making it less aligned with early shift-left integration than SAST, IAST, and SCA.

323
MCQhard

During a security assessment, a penetration tester discovers that a web application uses a custom encryption algorithm to protect session tokens. According to secure engineering principles, what is the primary concern?

A.Performance overhead of the custom algorithm
B.Insufficient key length used in the algorithm
C.Incompatibility with modern browsers
D.Lack of peer review and cryptanalysis
AnswerD

Custom algorithms bypass public scrutiny, so undiscovered weaknesses persist. Without peer review and cryptanalysis, flaws such as biased output, weak key scheduling or predictable IVs remain unproven, making the scheme untrustworthy regardless of its apparent complexity.

Why this answer

The primary concern with a custom encryption algorithm is the lack of peer review and cryptanalysis. Without rigorous public scrutiny by the cryptographic community, hidden vulnerabilities or backdoors may remain undetected, violating the secure engineering principle of using well-vetted, standard cryptographic primitives. This is a foundational principle in security engineering, as custom algorithms often fail to withstand known attack vectors like differential or linear cryptanalysis.

Exam trap

CompTIA emphasizes that security through obscurity (custom algorithms) is fundamentally flawed, and candidates mistakenly focus on implementation details like key length or performance instead of the critical lack of peer review.

How to eliminate wrong answers

Option A is wrong because performance overhead, while a practical consideration, is not the primary security concern; a custom algorithm could be fast but still insecure. Option B is wrong because insufficient key length is a symptom of poor algorithm design, but the root issue is the lack of validation and analysis, not the key length itself—even a long key in a flawed algorithm offers no real security. Option C is wrong because incompatibility with modern browsers is a deployment issue, not a cryptographic security concern; session tokens are typically handled server-side and transmitted via cookies or headers, not directly executed by the browser's encryption engine.

324
MCQeasy

A company wants to implement certificate pinning for its mobile application to prevent man-in-the-middle attacks. Which of the following is the BEST practice when implementing certificate pinning?

A.Disable certificate pinning after the first successful connection
B.Pin the root CA certificate only
C.Pin the public key of the server certificate
D.Pin the entire certificate chain
AnswerC

Pinning the public key rather than the full certificate lets the app continue trusting the server after certificate renewal, provided the key pair is reused. This maintains man-in-the-middle protection while avoiding outages from routine certificate rotation.

Why this answer

Pinning the public key rather than the entire certificate allows for certificate renewal without invalidating the pin.

325
MCQhard

During a forensic investigation, an analyst finds that a compromised system's memory dump shows signs of a kernel-mode rootkit. Which technique is MOST effective to detect the rootkit without relying on the compromised OS?

A.Run antivirus scans on the disk image.
B.Compare registry snapshots before and after infection.
C.Analyze network packet captures for C2 traffic.
D.Perform memory analysis using volatility on an isolated forensic workstation.
AnswerD

Volatility reconstructs kernel structures from the raw memory image on a trusted, isolated workstation, so the rootkit's own hooks and hidden process lists cannot conceal themselves. This satisfies the constraint of detecting kernel-mode compromise without relying on the compromised operating system's APIs.

Why this answer

Memory forensics on a different system enables analysis of the memory dump without relying on the compromised OS, allowing detection of kernel-mode rootkits that hide from OS-level tools. Option A (antivirus on disk image) depends on the compromised OS and may miss rootkits that hide from file system scans. Option B (registry snapshots) is ineffective because kernel rootkits operate below the registry level and can manipulate or avoid registry entries.

Option C (network packet captures) may show C2 traffic but does not directly detect the rootkit itself, and many rootkits use encrypted communication.

326
MCQmedium

A security analyst is reviewing a suspicious PowerShell script that was found on a compromised host. The analyst wants to understand the script's functionality without executing it. Which of the following techniques should the analyst use?

A.Network traffic analysis
B.Debugging with PowerShell ISE
C.Static code analysis
D.Dynamic analysis in a sandbox
AnswerC

Static code analysis examines the script's source code without executing it. The analyst can read the PowerShell commands, identify obfuscation, and understand the script's intent. Tools like PowerShell's AST parser or manual review can be used. This directly fulfills the requirement to analyze without execution, making it the correct choice.

Why this answer

The analyst needs to understand the script's functionality without executing it. Static code analysis involves examining the script's code, deobfuscating if necessary, and identifying malicious commands. This avoids the risks of execution.

Dynamic analysis, debugging, and network traffic analysis all require or assume execution, which is not desired here. Therefore, static code analysis is the correct approach.

Exam trap

The trap here is thinking that debugging or sandboxing is a form of static analysis, when they actually involve execution.

327
Multi-Selectmedium

A security analyst is reviewing a web application's authentication mechanism. Which of the following are best practices to prevent session hijacking? (Select TWO.)

Select 2 answers
A.Regenerate session ID upon successful login
B.Set the session timeout to 5 minutes
C.Use the same session ID before and after authentication
D.Store session tokens in localStorage
E.Use the Secure and HttpOnly flags on session cookies
AnswersA, E

Why this answer

Regenerating the session ID upon successful login (option A) is a critical defense against session fixation attacks, where an attacker forces a known session ID on a user before authentication. By issuing a new, server-generated session ID after login, the application ensures that any pre-authentication session ID controlled by an attacker becomes invalid. This practice is recommended by OWASP and aligns with RFC 6265 session management guidelines.

Exam trap

The CAS-004 exam often tests the misconception that short session timeouts (like 5 minutes) are a primary defense against session hijacking, when in fact they are a secondary mitigation that can harm usability, while the core technical controls are session ID regeneration and cookie security flags.

Why the other options are wrong

B

Short timeouts reduce risk but do not prevent hijacking; they are a mitigation, not a prevention.

C

Using the same session ID allows session fixation attacks.

D

localStorage is accessible by JavaScript and vulnerable to XSS; cookies with HttpOnly flag are more secure.

328
MCQeasy

A security engineer is configuring a TLS 1.3 connection between a web server and client. Which feature is unique to TLS 1.3 and provides reduced latency for returning clients?

A.Cipher suite negotiation
B.0-RTT
C.Forward secrecy
D.Mutual authentication
AnswerB

0-RTT allows a returning client to send application data in the first flight using a previously established pre-shared key, eliminating a round trip. This satisfies the reduced-latency requirement unique to TLS 1.3, though it carries replay risk that deployments must mitigate.

Why this answer

0-RTT (zero round-trip time) resumption is a TLS 1.3 feature that lets a returning client send application data in the first flight using a previously established session ticket, eliminating the round trip needed for a full handshake. This reduces latency for repeat connections. It is unique to TLS 1.3 and not available in TLS 1.2.

Exam trap

CAS-005 often tests whether candidates confuse forward secrecy (a confidentiality property present since TLS 1.2) with 0-RTT (a TLS 1.3-only latency feature), so pick 0-RTT when the question mentions reduced latency for returning clients.

How to eliminate wrong answers

Option A is wrong because cipher suite negotiation exists in TLS 1.2 and earlier, not unique to 1.3. Option C is wrong because forward secrecy (via ECDHE) was introduced in TLS 1.2 and is mandatory in 1.3, but it is not unique to 1.3 nor does it reduce latency for returning clients. Option D is wrong because mutual authentication (client certificates) is supported in TLS 1.2 and earlier and is not a latency-reduction feature.

329
MCQeasy

Which of the following is the primary purpose of input validation in application security?

A.To improve application performance by filtering out large inputs
B.To prevent injection attacks by ensuring data conforms to expected formats
C.To encrypt user input before storing it in the database
D.To log all user input for auditing purposes
AnswerB

Why this answer

Input validation is a security control that ensures user-supplied data matches expected formats, types, lengths, and ranges before processing. By rejecting malformed input, it directly prevents injection attacks (e.g., SQL injection, XSS, command injection) where an attacker embeds malicious code within input fields. This aligns with OWASP's top application security risks and is a foundational defense-in-depth measure.

Exam trap

The CAS-004 exam often tests the misconception that input validation is about performance or logging, but the core purpose is always preventing injection attacks by enforcing data integrity at the application layer.

Why the other options are wrong

A

Performance improvement is a side effect, not the primary security goal.

C

Encryption protects data at rest, but input validation focuses on input integrity.

D

Logging is important but not the primary purpose of input validation.

330
MCQeasy

An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?

A.Zero trust
B.Shared responsibility model
C.Software-defined perimeter
D.Defense in depth
AnswerB

The shared responsibility model defines the security boundary between provider and customer, satisfying the cloud-first scenario's need to clarify who secures what. The provider secures the cloud infrastructure, while the customer secures data, identities, and access in the cloud. This division varies by service model (IaaS, PaaS, SaaS), directly answering the stem's requirement.

Why this answer

The shared responsibility model defines which security tasks are handled by the provider (e.g., physical security) and which by the customer (e.g., data access).

331
MCQhard

An organization is adopting the NIST Risk Management Framework (RMF). During which step would the security team select and implement security controls, and how does this map to the organization's governance structure?

A.Step 4: Assess — controls are evaluated for effectiveness.
B.Step 1: Prepare — the organization establishes risk management roles and responsibilities.
C.Step 5: Authorize — a senior official accepts the risk.
D.Step 2: Select and Step 3: Implement — controls are chosen based on risk assessment and integrated into the system.
AnswerD

Within the NIST RMF, Step 2 (Select) chooses controls from the risk assessment, and Step 3 (Implement) deploys them into the system. This mapping satisfies the stem's requirement to tie control selection and implementation to the organisation's governance structure.

Why this answer

In the NIST RMF, Step 2 (Select) is where controls are chosen based on the risk assessment and organizational risk tolerance, and Step 3 (Implement) is where those controls are deployed and integrated into the system and its environment of operation. Together they represent the control selection and implementation phase, which maps to governance through the policies, roles, and risk decisions established in Step 1 (Prepare).

Exam trap

The trap is conflating the RMF steps: candidates often pick Assess (Step 4) because it sounds like where controls are handled, but Assess only evaluates controls that were already selected and implemented in Steps 2 and 3.

How to eliminate wrong answers

Option A is wrong because Step 4 (Assess) evaluates whether the selected and implemented controls are effective — it does not select or implement them. Option B is wrong because Step 1 (Prepare) establishes the risk management context, roles, responsibilities, and governance structure, but does not choose or deploy controls. Option C is wrong because Step 5 (Authorize) is where a senior official makes a risk-based decision to authorize the system to operate, not where controls are selected or implemented.

332
MCQeasy

A security team wants to implement a certificate pinning strategy for their mobile application to prevent man-in-the-middle attacks. Which of the following should be pinned in the application code?

A.The server's public key
B.The intermediate CA certificate
C.The server's IP address
D.The root CA certificate
AnswerA

Pinning the server's public key, rather than the whole certificate, survives certificate renewal because the key pair persists across reissues. This satisfies the mobile app's requirement to block man-in-the-middle attacks without breaking connectivity each time the certificate rotates.

Why this answer

Certificate pinning involves pinning the public key of the server's certificate or the certificate itself. Pinning the public key allows for certificate renewal without updating the app.

333
Multi-Selecthard

Which THREE of the following are common vulnerabilities in IoT devices? (Select THREE.)

Select 3 answers
A.Large storage capacity
B.Hardcoded credentials
C.Lack of secure boot
D.High compute power
E.Unencrypted communications
AnswersB, C, E

Hardcoded credentials ship identical usernames and passwords across every unit, so attackers who extract them from firmware or documentation gain access to the whole fleet. This satisfies the stem's requirement to identify a common IoT vulnerability.

Why this answer

Hardcoded credentials (B) are a classic IoT vulnerability because manufacturers often ship devices with fixed default usernames and passwords (e.g., admin/admin) that cannot be changed, allowing attackers to authenticate via Telnet/SSH or web interfaces. Lack of secure boot (C) is a vulnerability because without a hardware root of trust verifying firmware signatures at each boot stage, attackers can flash malicious firmware or persistently modify the boot chain. Unencrypted communications (E) expose IoT traffic to eavesdropping and man-in-the-middle attacks, since protocols like plain HTTP, MQTT without TLS, or unencrypted Zigbee/BLE traffic leak credentials and telemetry.

By contrast, large storage capacity (A) and high compute power (D) are merely hardware characteristics that do not by themselves create exploitable weaknesses, so they are not common IoT vulnerabilities.

Exam trap

CompTIA often tests the misconception that hardware features like storage or compute power are vulnerabilities, when in fact the risks stem from insecure design choices (e.g., hardcoded credentials, lack of encryption) rather than raw capability.

334
Multi-Selectmedium

A security engineer is reviewing how a Transport Layer Security session derives its keys and protects data. The engineer wants to identify the mechanisms that provide confidentiality and integrity for application data in TLS 1.3. (Choose two.)

Select 2 answers
A.HKDF-based key schedule using the transcript hash
B.The server certificate's RSA signature over the handshake
C.The ClientHello random value and session ID
D.AEAD ciphers such as AES-GCM and ChaCha20-Poly1305
E.Compression of the record payload before encryption
AnswersA, D

The TLS 1.3 key schedule uses HKDF to derive secrets from the shared ECDHE value and the handshake transcript hash, producing traffic keys for each direction. Those derived keys are what the AEAD ciphers use, so the key schedule underpins confidentiality and integrity by ensuring unique, context-bound keys per session and epoch.

Why this answer

In TLS 1.3, confidentiality and integrity for application data come from AEAD ciphers such as AES-GCM and ChaCha20-Poly1305, whose keys are produced by the HKDF-based key schedule bound to the handshake transcript. The certificate signature authenticates the peer, while randoms, session IDs, and compression do not protect record data.

Exam trap

The trap here is crediting the certificate's signature or handshake randoms with protecting application data, when only the AEAD layer and its derived keys do that.

335
MCQhard

A security engineer is designing a new network architecture for a government agency that requires compliance with NIST SP 800-53. The network must segregate data tiers and enforce least privilege. Which of the following designs BEST meets the requirements?

A.Perimeter-based security with a VPN for remote access.
B.Zero-trust architecture with micro-segmentation and continuous verification.
C.DMZ architecture with a single firewall between the internet and internal network.
D.Flat network with VLANs for each data tier and ACLs controlling traffic.
AnswerB

Micro-segmentation enforces least privilege by permitting only explicitly authorised flows between individual workloads, satisfying NIST SP 800-53 access control and separation-of-duties controls. Continuous verification re-evaluates every request against identity and device posture, so a compromised tier cannot pivot laterally into adjacent data tiers.

Why this answer

Zero-trust architecture with micro-segmentation and continuous verification directly enforces least privilege by requiring authentication and authorization for every connection, regardless of source location. Micro-segmentation isolates data tiers at the workload level, preventing lateral movement, which aligns with NIST SP 800-53 access control and system and communications protection requirements.

Exam trap

Candidates may mistakenly believe that VLANs combined with ACLs provide sufficient isolation for data tiers. However, NIST SP 800-53 requires dynamic access control and continuous verification, which VLANs and ACLs cannot support because they rely on static network segmentation rather than identity-based enforcement at the workload level.

How to eliminate wrong answers

Option A is wrong because perimeter-based security with a VPN assumes trust inside the network, failing to enforce least privilege across data tiers and allowing lateral movement once inside. Option C is wrong because a DMZ with a single firewall only protects the perimeter, not internal segmentation between data tiers, violating the segregation requirement. Option D is wrong because a flat network with VLANs and ACLs still allows east-west traffic within the same VLAN and relies on static rules, which cannot provide continuous verification or granular micro-segmentation.

336
Multi-Selecteasy

A security analyst is reviewing web server logs and notices repeated requests to URLs containing sequences like '/../../../etc/shadow' and '/../../../etc/passwd'. Which TWO actions should the analyst take as part of the immediate incident response process?

Select 2 answers
A.Check for successful exploitation by reviewing file access logs
B.Block the source IP address at the firewall
C.Run a full antivirus scan on the web server
D.Rebuild the web server from a known good backup
E.Disable the web server until a patch is applied
AnswersA, B

Reviewing file access logs confirms whether the directory traversal attempts actually reached /etc/shadow or /etc/passwd, distinguishing reconnaissance from compromise. This satisfies the immediate response requirement to establish exploitation status before containment, since the URL patterns alone only evidence attempted traversal, not successful reads of those credential files.

Why this answer

Option A is correct because the log entries show directory traversal attempts targeting sensitive files like /etc/shadow and /etc/passwd, so the analyst must determine whether any request actually succeeded by correlating web server logs with file access logs (e.g., auditd or file integrity monitoring) to confirm compromise. Option B is correct because blocking the attacking source IP at the firewall is a standard immediate containment step that stops ongoing exploitation attempts while investigation continues. Option C is not appropriate as an immediate response since antivirus scanning targets malware, not directory traversal exploitation of a web application.

Option D is premature because rebuilding from backup is a recovery action that should only follow confirmed compromise and root-cause analysis. Option E is overly disruptive; disabling the web server is not warranted unless exploitation is confirmed and no other containment is feasible.

Exam trap

CAS-005 often tests the balance between validation and containment—candidates pick drastic actions like rebuilding the server or disabling it, but the immediate response requires confirming exploitation and blocking the source, not full remediation.

337
Multi-Selecthard

When evaluating the security architecture of a containerized application, which THREE of the following practices should be implemented to minimize the attack surface? (Select THREE.)

Select 3 answers
A.Encrypt sensitive data at rest within the container
B.Use minimal base images (e.g., Alpine Linux) instead of full OS images
C.Implement multi-factor authentication for container registries
D.Set container file systems to read-only where possible
E.Drop all capabilities except those required for the application
AnswersB, D, E

Smaller images have fewer packages and vulnerabilities.

Why this answer

Using minimal base images like Alpine Linux reduces the number of installed packages, libraries, and utilities, which directly shrinks the attack surface by eliminating unnecessary components that could contain vulnerabilities. This practice aligns with the principle of least functionality, ensuring only essential binaries are present in the container image.

Exam trap

CompTIA CASP+ often tests the distinction between security controls that protect data (encryption, MFA) versus controls that reduce the attack surface (minimal images, read-only filesystems, dropped capabilities), causing candidates to select all seemingly 'secure' options rather than those that specifically minimize exploitable components.

338
MCQhard

A security team is implementing a new detection for a fileless malware attack that uses PowerShell to execute a malicious script directly in memory. The team wants to detect this activity using Windows Event Logs. Which of the following event IDs should they monitor to capture the script block content?

A.Event ID 4688
B.Event ID 5156
C.Event ID 4104
D.Event ID 4624
AnswerC

Event ID 4104 is generated when PowerShell logs a script block, capturing the actual code being executed. This is crucial for detecting fileless malware because the malicious script may never touch disk. Monitoring this event allows the team to see the script content and identify malicious patterns, even if the script is obfuscated or executed in memory.

Why this answer

Event ID 4104 is the correct choice because it logs PowerShell script block content, which is essential for detecting fileless malware that executes in memory. Event ID 4688 only shows process creation and command-line arguments, not the script itself. Event IDs 4624 and 5156 are unrelated to script execution and do not provide the needed visibility.

Exam trap

The trap here is confusing process creation logging (Event ID 4688) with script block logging (Event ID 4104), assuming that command-line arguments capture the full script content.

339
Multi-Selectmedium

A security analyst is analyzing a network capture and sees repeated TCP SYN packets to a host but no SYN-ACK responses. Which TWO conclusions are MOST likely? (Choose two.)

Select 2 answers
A.The host is out of TCP receive window space.
B.The network has a loop causing packet duplication.
C.The host has accepted the connections.
D.A firewall is dropping the SYN packets before they reach the host.
E.An attacker is performing a SYN flood DDoS attack.
AnswersD, E

Unanswered SYNs indicate the handshake never completes because the SYN never reaches the host. A firewall silently dropping those packets before delivery produces exactly this capture pattern, distinguishing it from a host actively refusing connections with RST responses.

Why this answer

Option D is correct because a firewall rule silently dropping inbound SYN packets would prevent the target host from ever receiving them, so no SYN-ACK would be generated and the capture would show repeated SYNs with no replies. Option E is correct because a SYN flood DDoS attack sends many TCP SYN packets, often with spoofed source addresses, and the victim either never responds or exhausts its backlog, producing the same pattern of unanswered SYNs. Option A is not the best conclusion because a full TCP receive window affects established connections and would typically still involve SYN-ACKs or window advertisements, not a total absence of SYN-ACKs.

Option B is not supported because a network loop would duplicate frames, including any SYN-ACKs, rather than selectively eliminate all SYN-ACK responses. Option C is incorrect because accepted connections require the three-way handshake, meaning a SYN-ACK would be observed, which contradicts the capture.

Exam trap

The trap is that candidates assume no SYN-ACK means the host is down or unreachable, when in fact the two most common causes — firewall filtering and SYN flood — both leave the host potentially alive but unable to complete handshakes.

340
MCQmedium

A security architect is designing a microsegmentation strategy for a data center hosting a three-tier application (web, application, database). The organization wants to enforce least-privilege east-west traffic without relying on IP addresses, and must ensure that workloads can move between hypervisors without requiring rule changes. Which technology best meets these requirements?

A.A next-generation firewall deployed at the perimeter with application-aware rules
B.Software-defined networking with distributed firewalls that apply policy based on workload identity tags
C.VLAN segmentation with access control lists applied on the core switch
D.Host-based intrusion prevention systems installed on each virtual machine
AnswerB

Distributed firewalls in an SDN fabric enforce policy at the hypervisor level using workload identity tags rather than IP addresses. This allows rules to follow the workload as it migrates between hosts, maintaining least-privilege east-west controls. It directly satisfies the requirements of identity-based enforcement and mobility without rule changes, making it the correct architectural choice.

Why this answer

Microsegmentation requires granular, identity-based policy enforcement for east-west traffic that remains consistent as workloads move. Distributed firewalls integrated with SDN use workload tags to apply rules regardless of IP changes, providing least-privilege segmentation. Perimeter firewalls, VLAN ACLs, and host IPS lack the combination of identity awareness and mobility support needed here.

Exam trap

The trap here is assuming that traditional VLAN segmentation or perimeter firewalls provide sufficient microsegmentation, when they actually depend on static IP addresses and cannot follow mobile workloads.

341
MCQhard

A healthcare provider is designing a data protection scheme for patient records stored in a cloud object store. Regulatory requirements mandate that encryption keys never leave the organization's on-premises hardware security modules (HSMs), while the cloud provider must still be able to perform server-side encryption on upload. The architect needs a key management approach that satisfies both constraints. Which of the following should the architect implement?

A.Provider-managed customer master keys stored in the cloud KMS
B.Client-side encryption with locally generated data keys
C.External key store backed by on-premises HSMs integrated with the cloud KMS
D.Envelope encryption using a customer-provided key uploaded to the KMS
AnswerC

An external key store lets the cloud KMS delegate cryptographic operations to key material held in the organization's own HSM, so plaintext keys never enter the provider's infrastructure. The provider still performs server-side encryption using the externally held key, satisfying both the residency mandate and the server-side encryption requirement. This is the designed pattern for exactly this regulatory scenario.

Why this answer

An external key store keeps the root key material inside the organization's HSMs while allowing the cloud KMS to call out for encrypt and decrypt operations, so server-side encryption still occurs without the provider holding plaintext keys. This satisfies the dual constraint of regulatory key residency and provider-side encryption. The other approaches either place key custody with the provider or shift encryption to the client, breaking one of the two requirements.

Exam trap

The trap here is treating any customer-controlled key option as equivalent, when importing a key into the cloud KMS still transfers custody to the provider.

342
MCQhard

In a CI/CD pipeline, a container image is built from a Dockerfile that uses a base image from a public registry. To minimize the attack surface, which of the following actions should be automated in the pipeline?

A.Use the 'latest' tag for the base image to get latest patches
B.Run a vulnerability scanner and fail the build on critical findings
C.Store the Dockerfile in a private repository only
D.Install all available packages inside the container
AnswerB

Automating a vulnerability scanner that fails the build on critical findings prevents images containing known exploitable packages from progressing through the pipeline. This directly minimises attack surface by blocking vulnerable base-image layers before deployment, rather than relying on manual review or post-deployment detection.

Why this answer

Integrating a vulnerability scanner into the CI/CD pipeline and failing the build on critical findings directly reduces the attack surface by preventing deployment of images with known exploitable vulnerabilities. This aligns with the principle of secure software supply chain management, where automated security gates are essential for containerized environments.

Exam trap

CompTIA often tests the misconception that using the 'latest' tag is a safe practice for security patching, when in fact it undermines deterministic builds and introduces supply chain risks.

Why the other options are wrong

A

'latest' can introduce breaking changes or untested versions.

C

Storage location does not reduce attack surface.

D

Installing extra packages increases attack surface.

343
MCQmedium

A multinational corporation is designing a hybrid cloud architecture that spans an on-premises data center and two public cloud regions. The security architect needs to ensure that all administrative access to cloud resources is brokered through a central identity provider, that access decisions consider device posture, and that no long-lived credentials are stored in the cloud. Which combination of technologies should the architect implement?

A.SAML federation with the on-premises identity provider and role-based access control (RBAC) in each cloud
B.A cloud identity provider with SAML/OIDC federation, conditional access policies, and short-lived credentials issued via just-in-time elevation
C.OIDC federation combined with a cloud access security broker (CASB) and just-in-time access
D.A hardware security module (HSM) for key storage and a VPN for administrative access
AnswerB

Federation through SAML or OIDC centralizes authentication with the identity provider, while conditional access policies evaluate device posture and other signals. Just-in-time elevation issues short-lived credentials, eliminating long-lived secrets in the cloud. Together, these satisfy all three architectural requirements.

Why this answer

Centralizing administrative access through federation, evaluating device posture with conditional access, and issuing short-lived credentials via just-in-time elevation collectively meet the requirements. This design removes long-lived credentials from the cloud and ensures that access decisions are context-aware, which is essential for a hybrid, multi-region architecture.

Exam trap

The trap here is assuming that federation alone eliminates long-lived credentials, when in fact static service accounts often persist unless just-in-time access is also implemented.

344
MCQeasy

A system administrator is configuring a Linux server to host a web application. Which file permission should be set for the private SSL key?

A.600
B.644
C.444
D.755
AnswerA

Permission 600 grants read and write to the owner only, denying all access to group and others. This satisfies the stem's requirement for a private SSL key, since any broader permission such as 644 would expose the key material to other local users.

Why this answer

The private SSL key must be protected from unauthorized access because it is used to decrypt traffic and establish trust. Setting permissions to 600 (owner read/write only) ensures that only the root or the application user who owns the key can read it, preventing other users or processes from extracting the key material.

Exam trap

The trap here is that candidates confuse file permissions for private keys with those for public certificates or configuration files, often choosing 644 because it is common for non-sensitive files, but private keys must never be readable by anyone except the owner.

How to eliminate wrong answers

Option B (644) is wrong because it grants read access to the group and others, which would allow any user on the system to read the private key, compromising its secrecy. Option C (444) is wrong because while it restricts write access, it still allows all users to read the key, which is a critical security failure. Option D (755) is wrong because it gives read and execute permissions to everyone, and execute is unnecessary for a key file, while also exposing the key to all users.

345
MCQmedium

During a vendor risk assessment, a company receives a SOC 2 Type II report from a cloud service provider. What does this report primarily attest to?

A.The design and operating effectiveness of controls over a period of time
B.The vendor's financial stability
C.The vendor's compliance with privacy laws
D.The vendor's penetration test results
AnswerA

SOC 2 Type II evaluates control design and operating effectiveness across a defined audit period, unlike Type I which reports design at a single point in time. This satisfies the vendor assessment requirement for sustained control performance evidence.

Why this answer

SOC 2 Type II reports on the effectiveness of controls over a period of time.

346
Multi-Selecthard

A security assessor is evaluating an application that uses ChaCha20-Poly1305 for encryption. Which TWO of the following are true about this cryptographic algorithm?

Select 2 answers
A.It is based on the AES algorithm
B.It requires padding to achieve correct block sizes
C.It is a stream cipher
D.It provides authenticated encryption with additional data (AEAD)
E.It is a block cipher
AnswersC, D

ChaCha20 is a stream cipher, generating a keystream from a 256-bit key and nonce that is XORed with plaintext. This distinguishes it from block ciphers such as AES, and explains its efficiency in software without dedicated hardware acceleration.

Why this answer

Option C is correct because ChaCha20 is a stream cipher: it generates a keystream from a 256-bit key and a 96-bit nonce (with a 32-bit counter) and XORs it with the plaintext, so no block structure is involved. Option D is correct because the Poly1305 one-time authenticator is combined with ChaCha20 to form an AEAD construction, producing a 128-bit authentication tag that protects both the ciphertext and any additional authenticated data (AAD) such as headers. Option A is wrong because ChaCha20 is unrelated to AES; it was designed by Daniel J.

Bernstein as a variant of Salsa20 and does not use the Rijndael/AES structure or S-boxes. Option B is wrong because stream ciphers encrypt data byte-by-byte and require no padding to reach a block size. Option E is wrong because ChaCha20 is not a block cipher; it processes data as a continuous keystream rather than fixed-size blocks.

Exam trap

CAS-005 often tests the misconception that all modern ciphers are block ciphers or AES-based — candidates must recognize ChaCha20 as a stream cipher with AEAD properties and no padding requirement.

347
MCQmedium

A company uses a microservices architecture with Docker containers orchestrated by Kubernetes. Developers push code to a Git repository, which triggers a CI/CD pipeline using Jenkins. The pipeline builds Docker images and pushes them to a private registry (Harbor). Recently, a critical vulnerability (CVE-2024-XXXX) was discovered in the base image of several containers. The security team wants to ensure that only images that pass vulnerability scans are deployed to production. The pipeline currently builds and pushes images without any security check. Developers are responsible for updating base images, but this has been inconsistent. Which action should the security team take?

A.Require developers to manually check their images and update base images
B.Implement a webhook in Harbor to automatically scan all images upon push and block vulnerable images from being pulled
C.Configure Jenkins to run Trivy scans on each built image and fail the pipeline if vulnerabilities exceed a defined threshold, and only allow images that pass to be pushed to the production registry
D.Use Kubernetes PodSecurity admission to block containers with high-severity vulnerabilities
AnswerC

Running Trivy scans inside Jenkins and failing the pipeline when vulnerabilities exceed a threshold enforces the constraint that only scanned, compliant images reach production, replacing inconsistent manual base-image updates with automated gatekeeping before the registry push.

Why this answer

It integrates vulnerability scanning directly into the CI/CD pipeline. By running Trivy as a step after the image is built but before it is pushed to the production registry, the pipeline can fail if the vulnerability count or severity exceeds a defined threshold. This ensures that only images that pass the security scan are deployed to production.

Option A (manual updates) is unreliable and does not enforce policy. Option B (Harbor webhook) would block pulls but does not prevent the push of vulnerable images; the image would already be in the registry. Option D (PodSecurity admission) controls what runs in Kubernetes but does not assess vulnerability severity and operates too late; the image would already be built and pushed.

348
MCQeasy

A security architect is selecting a cipher suite for TLS 1.3 to ensure forward secrecy and high performance. Which cipher suite should be recommended?

A.TLS_RSA_WITH_AES_256_CBC_SHA
B.TLS_AES_256_GCM_SHA384
C.TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
D.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
AnswerB

TLS_AES_256_GCM_SHA384 uses ephemeral Diffie-Hellman key exchange, which is mandatory in TLS 1.3, delivering the required forward secrecy. AES-256-GCM provides authenticated encryption with hardware-accelerated performance, while SHA-384 strengthens the handshake. It satisfies both the forward secrecy and high-performance constraints.

Why this answer

TLS_AES_256_GCM_SHA384 is the only option that is a valid TLS 1.3 cipher suite. TLS 1.3 removed RSA key transport and all CBC-mode ciphers, mandating AEAD (Authenticated Encryption with Associated Data) ciphers and ephemeral key exchange for forward secrecy. This suite uses AES-256 in GCM mode for authenticated encryption and SHA-384 for the HKDF-based key schedule, delivering both high performance (AES-NI accelerated) and strong security.

Exam trap

The trap here is that candidates may select a TLS 1.2 cipher suite that includes ECDHE and GCM, thinking it provides forward secrecy and performance, but TLS 1.3 only accepts the simplified TLS_<AEAD>_<HASH> naming format and prohibits CBC and static RSA.

How to eliminate wrong answers

Option A is wrong because TLS_RSA_WITH_AES_256_CBC_SHA uses RSA key transport (no forward secrecy) and CBC mode, both of which were removed in TLS 1.3. Option C is wrong because TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 is a TLS 1.2 cipher suite name; TLS 1.3 renamed suites to the TLS_<AEAD>_<HASH> format and no longer specifies key exchange or authentication in the cipher suite string. Option D is wrong because TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 uses CBC mode and SHA-256 (not SHA-384), and is a TLS 1.2 suite; TLS 1.3 prohibits CBC and requires AEAD.

349
Multi-Selecthard

A security architect is designing a Zero Trust architecture for a multinational corporation. The organization wants to enforce least-privilege access to applications based on device health, user identity, and contextual factors, and it requires continuous verification of trust. Which TWO of the following are core enforcement mechanisms that should be implemented to achieve these goals? (Choose two.)

Select 2 answers
A.Microsegmentation with identity-based policies
B.Static VPN access with split tunneling for all employees
C.A single-factor password authentication for all internal applications
D.Implicit trust for devices on the corporate LAN
E.Policy Decision Point (PDP) and Policy Enforcement Point (PEP) separation
AnswersA, E

Microsegmentation with identity-based policies enforces least-privilege access between workloads and applications by using identity and context rather than IP addresses. It supports continuous verification and limits lateral movement, aligning with Zero Trust. This mechanism is essential for dynamically controlling access based on device health and user identity.

Why this answer

The PDP/PEP separation and microsegmentation with identity-based policies are core Zero Trust enforcement mechanisms. The PDP/PEP model enables dynamic, context-aware access decisions, while identity-based microsegmentation enforces least privilege and limits lateral movement, together supporting continuous verification and device health evaluation.

Exam trap

The trap here is assuming that network location such as the corporate LAN or a VPN implies trust, when Zero Trust explicitly rejects implicit trust and requires continuous, context-aware verification.

350
MCQhard

An organization has a critical vulnerability in a legacy application that cannot be patched due to vendor end-of-life. The application is required for business operations and is accessible only from the internal network. Which compensating control would best reduce the risk of exploitation while maintaining availability?

A.Deploy a host-based intrusion prevention system (HIPS) on the server
B.Apply a vendor-supplied patch
C.Implement network segmentation and strict ACLs to limit access to the application
D.Uninstall the application
AnswerC

Segmentation with strict ACLs restricts reachability to the vulnerable legacy application, shrinking the attack surface while it stays available to authorised internal users. Since patching is impossible, this compensating control limits lateral movement and exploitation attempts, satisfying the availability constraint better than disabling the service.

Why this answer

Network segmentation with strict ACLs limits who can reach the legacy application, reducing the attack surface while keeping it available to authorized internal users. This is a classic compensating control when patching is impossible — it does not fix the vulnerability but constrains exploitability and blast radius.

Exam trap

The trap is that HIPS sounds like a strong security control, so candidates pick it — but the question asks for the BEST compensating control that maintains availability, and network segmentation with ACLs directly limits exposure while HIPS is a weaker, host-level mitigation.

How to eliminate wrong answers

Option A is wrong because a HIPS is detective/preventive at the host level but does not address the unpatched vulnerability itself and can be bypassed by novel exploits; it is a weaker compensating control than restricting network access. Option B is wrong because the question states the vendor is end-of-life, so no patch exists — this is a distractor that ignores the scenario constraint. Option D is wrong because uninstalling the application would break business operations, violating the requirement to maintain availability.

351
MCQhard

During a compliance audit, an organization's security team discovers that sensitive data in a legacy database is stored in plaintext. The database is critical for operations and cannot be taken offline for patching until the next maintenance window in three months. Which of the following is the BEST compensating control to reduce risk immediately?

A.Restrict network access to the database to only authorized applications
B.Use file-level encryption on the database storage volume
C.Implement transparent database encryption (TDE)
D.Apply a digital signature to the database files
AnswerA

Restricting network access to authorised applications only shrinks the attack surface without touching the database, so it can be applied immediately while patching waits three months. It directly mitigates exposure of plaintext data by preventing unauthorised hosts from reaching the database.

Why this answer

Restricting network access to the database to only authorized applications is the best compensating control because it immediately reduces the attack surface without requiring any changes to the database itself. By implementing a host-based firewall or network ACLs that limit inbound connections to only specific application servers (e.g., via IP whitelisting and port restrictions), the organization can prevent unauthorized users or malware from directly querying the plaintext data. This control is operational immediately, does not require downtime, and aligns with the principle of least privilege, making it the most practical short-term risk mitigation while awaiting the maintenance window.

Exam trap

The key trap is that encryption solutions like TDE or file-level encryption require database downtime or reconfiguration, which is not permitted in the scenario. Network access control provides immediate risk reduction without touching the database.

How to eliminate wrong answers

Option B is wrong because file-level encryption on the database storage volume would require the volume to be taken offline or remounted to enable encryption, which contradicts the constraint that the database cannot be taken offline; additionally, it does not protect data in transit or in use, only at rest. Option C is wrong because implementing transparent database encryption (TDE) typically requires a database restart or at least a schema change, which would cause downtime, and it also requires the database to be taken offline for the initial encryption process, violating the operational constraint. Option D is wrong because applying a digital signature to the database files only ensures integrity and authenticity of the files, not confidentiality; it does not prevent unauthorized access to the plaintext data stored within the database.

352
MCQeasy

Under GDPR, which of the following is a data subject right that allows an individual to request that their personal data be erased?

A.Right to portability
B.Right to access
C.Right to erasure
D.Right to rectification
AnswerC

The right to erasure, or right to be forgotten, lets a data subject demand deletion of personal data where no overriding legal ground for retention applies. This directly satisfies the GDPR requirement for an individual to request erasure of their data.

Why this answer

The right to erasure (also known as the 'right to be forgotten') is explicitly defined in GDPR Article 17, allowing data subjects to request deletion of their personal data under certain conditions. This is a core data subject right alongside access, rectification, and portability. Option C directly names this right.

Exam trap

CAS-005 often tests the confusion among GDPR data subject rights, particularly mixing up erasure with portability or rectification, by using similar-sounding descriptions.

How to eliminate wrong answers

Option A is wrong because the right to portability (Article 20) allows data subjects to receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller. Option B is wrong because the right to access (Article 15) allows individuals to obtain confirmation of whether their data is being processed and access to that data. Option D is wrong because the right to rectification (Article 16) allows individuals to correct inaccurate or incomplete personal data.

353
MCQmedium

A SOC team receives an alert from a SOAR platform indicating a potential phishing email. The SOAR playbook automatically quarantines the email, blocks the sender, and opens a ticket. This is an example of which SOAR capability?

A.Response
B.Automation
C.Orchestration
D.Correlation
AnswerB

The playbook executes quarantine, sender blocking and ticket creation without human intervention, which is machine-driven execution of a predefined workflow. That distinguishes automation from orchestration, which coordinates multiple tools, and from case management or threat intelligence enrichment.

Why this answer

Automation in SOAR refers to executing predefined actions without human intervention — here, the playbook automatically quarantines the email, blocks the sender, and opens a ticket. This is the defining characteristic of automation: machine-driven execution of response steps based on a trigger.

Exam trap

The trap is that Orchestration and Automation are often used interchangeably, so candidates pick Orchestration — but the exam distinguishes them: orchestration is coordinating tools, automation is executing actions without human intervention, and the question's 'automatically' keyword points to automation.

How to eliminate wrong answers

Option A is wrong because 'Response' is the broader category of actions taken against a threat, not the specific SOAR capability of executing them automatically; the question asks which capability the automatic execution represents. Option C is wrong because Orchestration refers to coordinating multiple tools and systems (e.g., email gateway, firewall, ticketing system) into a unified workflow — while orchestration is involved, the question emphasizes the automatic execution, which is automation. Option D is wrong because Correlation is the process of linking related alerts or events (e.g., SIEM correlating logs) to identify incidents, not executing response actions.

354
MCQhard

An organization is deploying a containerized application on Kubernetes and must enforce that only approved container images are allowed to run, and that containers cannot escalate privileges. Which combination of controls should the architect implement?

A.Seccomp and AppArmor profiles with RBAC
B.Kubernetes network policies and RBAC
C.Admission controllers with image signing and PodSecurityPolicy
D.Container image scanning and network policies
AnswerC

Admission controllers intercept API requests before pods are created, rejecting unsigned or unapproved images, while PodSecurityPolicy restricts privileged escalation and capability use. Together they enforce image provenance and prevent privilege escalation, matching both stem constraints.

Why this answer

Admission controllers are the Kubernetes mechanism that intercepts API server requests before objects are persisted, so they can reject pods that violate policy. Combined with image signing (e.g., via cosign/Notary or an admission webhook that verifies signatures), they enforce that only approved images run. PodSecurityPolicy (or its successor, Pod Security Admission with restricted/baseline profiles) blocks privilege escalation by restricting privileged containers, hostPath mounts, and capabilities.

Exam trap

CAS-005 often tests the misconception that runtime hardening tools like Seccomp/AppArmor or RBAC alone satisfy 'only approved images' requirements, when admission control plus image signing is the actual enforcement point.

How to eliminate wrong answers

Option A is wrong because Seccomp and AppArmor constrain syscall and file-access behavior at runtime but do not gate which images are admitted or prevent privileged pod specs from being scheduled; RBAC only governs API verbs, not workload content. Option B is wrong because network policies only control pod-to-pod traffic flows and RBAC only controls API authorization — neither validates image provenance nor blocks privileged containers. Option D is wrong because image scanning detects vulnerabilities after the fact but does not enforce admission of only signed images, and network policies do not address privilege escalation.

355
MCQeasy

A small business uses Puppet for configuration management on Linux servers. They are now migrating to containers and want to maintain security. The operations team is unfamiliar with containers. The security team insists on automated vulnerability scanning of container images before deployment. What should be the company's first step?

A.Deploy a Kubernetes cluster and migrate all applications.
B.Discontinue using Puppet and switch entirely to container-based configurations.
C.Train the operations team on Docker and Kubernetes fundamentals.
D.Create a hardened base image standard, and set up a CI pipeline that automatically scans every image for vulnerabilities before it is pushed to the registry.
AnswerD

Automated scanning in CI satisfies the security team's pre-deployment scanning mandate while the hardened base image standard reduces the container knowledge gap for an unfamiliar operations team, establishing a repeatable, secure foundation before any workload reaches the registry.

Why this answer

The first step in securing container images is to establish a hardened base image standard and integrate vulnerability scanning into a CI pipeline. This ensures that every image is automatically checked for known vulnerabilities before being pushed to the registry, addressing the security team's requirement without requiring the operations team to immediately master container orchestration. This approach aligns with the principle of shifting security left, preventing vulnerable images from ever reaching production.

Exam trap

The trap here is that candidates often confuse the immediate security requirement (vulnerability scanning) with broader orchestration or training needs, leading them to choose a later-stage activity (like deploying Kubernetes or training) instead of the foundational step of establishing a secure image pipeline.

How to eliminate wrong answers

Option A is wrong because deploying a Kubernetes cluster and migrating all applications is a premature and risky step; it assumes the operations team understands containers and orchestration, and it does not address the immediate need for automated vulnerability scanning of images. Option B is wrong because discontinuing Puppet entirely is unnecessary; Puppet can still manage host-level configurations (e.g., Docker daemon settings, OS hardening) while containers are introduced, and the question does not require a complete switch. Option C is wrong because training the operations team on Docker and Kubernetes fundamentals is important but is not the first step; the immediate priority is to implement the vulnerability scanning process to satisfy the security team's requirement, and training can occur in parallel.

356
Multi-Selectmedium

A security engineer is implementing a secure boot process for an embedded device. The engineer needs to ensure that only trusted firmware is executed and that the integrity of the boot chain is maintained. Which TWO of the following are essential components of a secure boot implementation? (Choose two.)

Select 2 answers
A.Full disk encryption of the boot partition
B.Trusted Platform Module (TPM) for measured boot
C.Digital signature verification of each boot stage
D.Secure enclave for key storage
E.Root of trust in immutable hardware
AnswersC, E

Each boot stage must be digitally signed by a trusted authority, and the signature must be verified before execution. This ensures that only authorized code runs. Without verification, an attacker could replace a boot stage with malicious code. The verification uses the public key from the root of trust or a chain of trust.

Why this answer

Secure boot requires an immutable root of trust to anchor trust and digital signature verification at each stage to ensure only trusted code executes. Encryption, secure enclaves, and TPMs can complement security but are not essential for the fundamental secure boot process.

Exam trap

The trap here is equating measured boot with secure boot; measured boot records but does not enforce, while secure boot enforces.

357
Multi-Selectmedium

Which of the following are secure scripting practices when automating administrative tasks? (Choose two.)

Select 2 answers
A.Hardcode credentials in the script for convenience
B.Use a secrets management service to retrieve credentials at runtime
C.Run the script with the highest privileges required
D.Implement input validation to prevent injection attacks
AnswersB, D

Why this answer

Using a secrets management service (e.g., HashiCorp Vault, AWS Secrets Manager) retrieves credentials at runtime via secure APIs, avoiding hardcoded secrets in scripts. This practice ensures credentials are encrypted at rest and in transit, and supports rotation without modifying the script. It aligns with the principle of least privilege and reduces the risk of credential exposure in version control or logs.

Exam trap

The CAS-004 exam often tests the misconception that running with elevated privileges is necessary for automation, when in fact least privilege and secrets management are the secure practices, and input validation is a separate but equally important control.

Why the other options are wrong

A

Hardcoding exposes secrets in version control.

C

Should run with least privilege, not highest.

358
MCQeasy

A security administrator is hardening a Linux server that hosts a public web application. The administrator wants to reduce the attack surface by restricting which services are accessible from the internet. Which of the following actions BEST achieves this?

A.Enable SELinux in enforcing mode and set the web server's context to httpd_sys_content_t for all files.
B.Configure the host-based firewall to allow only TCP ports 80 and 443 from any source, and drop all other inbound traffic.
C.Disable password authentication for SSH and require key-based authentication for all users.
D.Install and configure a host-based intrusion detection system (HIDS) to monitor for suspicious activity on all ports.
AnswerB

Allowing only ports 80 and 443 from any source restricts inbound access to the web services, which is exactly what the public web application requires. Dropping all other inbound traffic reduces the attack surface by preventing access to other services. This is a fundamental host-based firewall hardening step that directly addresses the requirement.

Why this answer

The most direct way to reduce the attack surface is to configure the host-based firewall to allow only the necessary ports (80 and 443) and drop all other inbound traffic. This ensures that only the web application is reachable from the internet. SELinux, HIDS, and SSH hardening are valuable but do not restrict network accessibility of services.

Exam trap

The trap here is confusing hardening a specific service with reducing the overall network attack surface, which requires controlling which ports are reachable.

359
MCQmedium

A security administrator is configuring SSH for a jump host used to access critical servers. Which of the following is the most secure configuration option to restrict authentication and reduce the attack surface?

A.Enable root login with a strong password
B.Allow only SSH protocol version 2
C.Change the default port to 2222
D.Allow only key-based authentication
AnswerD

Key-based authentication removes password brute-forcing and credential-replay vectors entirely, since possession of the private key is required. This directly reduces the attack surface on the jump host, satisfying the stem's requirement to restrict authentication to the most secure method.

Why this answer

Disabling password authentication and using only key-based authentication eliminates the risk of password brute force and credential theft. Listening on a non-standard port provides security through obscurity, which is not a strong control.

360
Multi-Selectmedium

A security architect is reviewing supply chain security for a software product. Which TWO artifacts are most important for verifying the integrity and provenance of third-party components?

Select 2 answers
A.Penetration test results
B.Software bill of materials (SBOM)
C.Dependency analysis report
D.Network flow logs
E.Database encryption configuration
AnswersB, C

An SBOM enumerates every component and version in the product, giving the inventory needed to trace third-party dependencies. Combined with provenance attestation, it lets the architect verify what was supplied and detect tampering or unexpected inclusions, satisfying the integrity and provenance requirement.

Why this answer

Option B, the software bill of materials (SBOM), is correct because it enumerates every third-party and open-source component, library, and version in the product, which is the foundation for verifying provenance and detecting tampered or vulnerable dependencies. Option C, the dependency analysis report, is correct because it maps direct and transitive dependencies and flags known vulnerabilities, license conflicts, and unexpected or unvetted components, directly supporting integrity verification of the supply chain. Together, the SBOM provides the authoritative component inventory while the dependency analysis validates those components against known-good and known-bad data.

Option A, penetration test results, is not correct because pen testing assesses exploitable weaknesses in a running system, not the provenance or integrity of third-party components. Option D, network flow logs, is not correct because they record traffic metadata for monitoring and forensics, not component-level supply chain integrity. Option E, database encryption configuration, is not correct because it addresses data-at-rest protection and is unrelated to verifying third-party component provenance.

361
Multi-Selecthard

Which THREE of the following are common techniques to mitigate side-channel attacks?

Select 3 answers
A.Disable CPU caching to prevent cache timing attacks
B.Implement constant-time algorithms for cryptographic operations
C.Add noise to power consumption or electromagnetic emissions
D.Ensure memory access patterns are independent of secret data
E.Use random delays in code execution paths
AnswersB, C, D

Constant-time algorithms execute identical instruction sequences and memory accesses regardless of secret values, removing the timing and cache-usage variations that side-channel attackers measure. This directly satisfies the stem's mitigation requirement by eliminating the data-dependent execution path that leaks key material.

Why this answer

Option B is correct because constant-time algorithms execute the same sequence of operations regardless of secret values, eliminating the data-dependent timing variations that timing side-channel attacks exploit. Option C is correct because adding noise to power consumption or electromagnetic emissions masks the correlation between a device's physical leakage and the secret data being processed, which is the core of power-analysis and EM side-channel attacks. Option D is correct because making memory access patterns independent of secret data (e.g., via oblivious access or cache-line-aligned constant-time lookups) prevents cache-timing attacks that infer secrets from which cache lines are accessed.

Option A is not a common mitigation: disabling CPU caching is impractical, severely degrades performance, and is not a standard countermeasure. Option E is not correct because random delays only add probabilistic noise to timing and are generally considered weak and insufficient against modern statistical timing attacks, unlike true constant-time execution.

Exam trap

CompTIA often tests the misconception that adding random delays (Option E) is a valid side-channel mitigation, but candidates must recognize that statistical averaging defeats such noise, whereas constant-time algorithms (Option B) and noise injection (Option C) are standard, effective techniques.

362
MCQmedium

An organization is implementing a governance framework to ensure that security controls are aligned with business objectives. Which of the following frameworks is specifically designed for this purpose?

A.COBIT 2019
B.NIST SP 800-53
C.ITIL 4
D.ISO/IEC 27001
AnswerA

COBIT 2019 is a governance framework that explicitly separates governance from management and maps IT objectives to enterprise goals, satisfying the stem's requirement to align security controls with business objectives. Other frameworks address control implementation or risk, not enterprise-wide IT governance alignment.

Why this answer

COBIT 2019 is specifically designed to align IT governance and security controls with business objectives by providing a comprehensive framework that links business goals to IT goals and enablers. It focuses on governance of enterprise IT (GEIT), ensuring that security investments and controls directly support strategic business outcomes, unlike other frameworks that are more operational or compliance-focused.

Exam trap

CompTIA often tests the distinction between governance frameworks (COBIT) and operational or compliance frameworks (NIST SP 800-53, ITIL, ISO 27001), trapping candidates who confuse control implementation with strategic alignment.

How to eliminate wrong answers

Option B (NIST SP 800-53) is wrong because it is a catalog of security and privacy controls for federal information systems, not a governance framework designed to align controls with business objectives; it focuses on technical and operational control implementation rather than strategic alignment. Option C (ITIL 4) is wrong because it is a service management framework that focuses on IT service lifecycle and delivery processes, not on governance or linking security controls to business goals. Option D (ISO/IEC 27001) is wrong because it is an information security management standard that specifies requirements for an ISMS, emphasizing risk management and compliance, but it does not inherently provide a governance structure to align controls with business objectives like COBIT does.

363
Multi-Selecthard

An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)

Select 3 answers
A.Relies on IP-based allowlists
B.Applications are invisible to unauthorized users
C.Creates encrypted tunnels per session
D.Uses a single shared firewall for all traffic
E.Requires device authentication before granting network access
AnswersB, C, E

SDP employs a deny-by-default model where the controller authenticates and authorises both endpoints before any connection is brokered, so applications never respond to unauthenticated probes. This satisfies the zero trust requirement that resources remain hidden from unauthorised users, mitigating scanning and reconnaissance.

Why this answer

Option B is correct because a core SDP principle is the "dark cloud" or black cloud model, where protected applications do not respond to unauthenticated probes and remain invisible until a user and device are authenticated and authorized by the controller. Option C is correct because SDP establishes dynamic, per-session encrypted connections (for example, mutual TLS or DTLS tunnels) between the initiating host and the accepting host, rather than granting broad network-level access. Option E is correct because SDP enforces device authentication and posture checks through the controller before any connection to the accepting host is brokered, which is fundamental to zero trust network access.

Option A is not correct because SDP deliberately moves away from static IP-based allowlists and perimeter rules, relying instead on identity- and context-based authorization. Option D is not correct because SDP does not funnel all traffic through a single shared firewall; it uses distributed controllers and gateways to broker individualized, least-privilege connections.

Exam trap

CAS-005 often tests the misconception that SDP is just a next-gen VPN or firewall, when its defining trait is application invisibility and identity-based per-session tunnels.

364
Multi-Selecthard

A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution. The team wants to ensure that the EDR can detect advanced threats that use fileless techniques and living-off-the-land binaries (LOLBins). Which two data sources should the SOC prioritize collecting from the EDR to effectively detect such threats? (Choose two.)

Select 2 answers
A.User login and logout events from the domain controller
B.Windows Event Logs, specifically Sysmon events for process creation and network connections
C.API call tracing and script block logging from PowerShell
D.Full packet capture (PCAP) of all network traffic
E.Antivirus scan logs showing signature-based detection results
AnswersB, C

Sysmon provides detailed process creation events including command-line arguments, parent process, and hashes, which are critical for detecting suspicious LOLBin execution and fileless techniques. Network connection events from Sysmon also help identify command-and-control traffic. This data source is essential for advanced threat detection because it captures rich context that native Windows event logs may lack.

Why this answer

Detecting fileless threats and LOLBins requires visibility into process execution and script activity. Sysmon events provide detailed process creation and network connection data, while PowerShell script block logging and API tracing capture the actual code and function calls used by attackers. These sources together give the SOC the behavioral context needed to identify advanced techniques that evade traditional file-based detection.

Exam trap

The trap here is assuming that traditional antivirus logs or network packet captures are sufficient for detecting fileless threats, when in fact endpoint process and script-level telemetry is required.

365
MCQeasy

A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?

A.Trust based on device compliance
B.Never trust, always verify
C.Trust based on network location
D.Trust but verify
AnswerB

Never trust, always verify requires every access request to be authenticated and authorised explicitly, regardless of network location, replacing implicit trust with continuous verification. This is the foundational tenet from which all other zero trust controls derive.

Why this answer

Zero trust assumes no implicit trust; every access request must be verified regardless of origin.

366
Multi-Selecthard

A security architect is designing a new cloud-based system that must comply with the Payment Card Industry Data Security Standard (PCI DSS). The architect needs to ensure that cardholder data is protected both at rest and in transit. Which TWO of the following controls are required by PCI DSS to protect cardholder data in this scenario? (Choose two.)

Select 2 answers
A.Restrict physical access to cardholder data storage systems.
B.Render primary account numbers (PAN) unreadable anywhere they are stored.
C.Conduct quarterly external and internal vulnerability scans.
D.Implement a web application firewall (WAF) in front of all public-facing web servers.
E.Encrypt transmission of cardholder data across open, public networks.
AnswersB, E

PCI DSS Requirement 3 requires that stored cardholder data be rendered unreadable through encryption, truncation, tokenization, or hashing. This addresses data at rest and is essential for protecting stored PAN. The architect must ensure that any storage of cardholder data complies with this requirement to reduce the risk of compromise.

Why this answer

PCI DSS explicitly requires encrypting cardholder data during transmission over open, public networks (Requirement 4) and rendering stored PAN unreadable (Requirement 3). These two controls directly protect data in transit and at rest. WAF, physical access, and vulnerability scans are important but do not specifically fulfill the data protection requirements for those states.

Exam trap

The trap here is selecting general PCI DSS requirements like WAF or vulnerability scans, which are important but not the specific controls for protecting cardholder data at rest and in transit.

367
MCQmedium

A security analyst discovers that container images in the company's private registry lack signatures. The development team uses a script to build and push images. The analyst wants to ensure image integrity and prevent tampering. Which solution should the analyst recommend?

A.Implement Docker Content Trust with a Notary server to require signatures on all images.
B.Restrict registry access to only the build servers.
C.Use SSH keys to sign the image tarball before pushing.
D.Encrypt the image filesystem layer using AES-256.
AnswerA

Docker Content Trust uses Notary to sign image tags, and the Docker client verifies those signatures before pull or run. Enforcing it in the build-and-push script blocks unsigned or tampered images from the private registry, directly satisfying the integrity requirement.

Why this answer

Docker Content Trust (DCT) integrates with a Notary server to enforce cryptographic signing of container images. When enabled, the Docker client will only pull, push, or run images that have been signed by trusted keys, ensuring image integrity and preventing tampering. This directly addresses the requirement to require signatures on all images in the private registry.

Exam trap

Candidates often confuse access control (authentication/authorization) with integrity verification (signing/hashing) and mistakenly choose restricting access (Option B), thinking it prevents tampering, but it does not protect against insider threats or registry-level attacks.

How to eliminate wrong answers

Option B is wrong because restricting registry access to build servers controls who can push images but does not provide any mechanism to verify image integrity or detect tampering after the image is stored. Option C is wrong because SSH keys are used for authentication and secure transport, not for signing image content; signing an image tarball with SSH keys is not a standard or supported method for container image integrity in Docker/OCI ecosystems. Option D is wrong because encrypting the image filesystem layer protects data at rest but does not provide a signature or hash to verify that the image has not been altered; encryption alone cannot detect tampering.

368
MCQhard

During a penetration test, the tester gains access to a web server and wants to escalate privileges to root. The tester discovers that the web application runs with a service account that has the SeImpersonatePrivilege enabled. Which attack is most likely to succeed for privilege escalation?

A.SQL injection
B.Pass-the-hash attack
C.DLL hijacking
D.JuicyPotato attack
AnswerD

JuicyPotato exploits the SeImpersonatePrivilege token by coercing a privileged service into authenticating, then impersonating its token via COM server abuse. Since the stem confirms the service account holds SeImpersonatePrivilege, this satisfies the exact prerequisite, enabling escalation to SYSTEM or root without needing kernel exploits.

Why this answer

SeImpersonatePrivilege allows a process to impersonate a user token. Tools like JuicyPotato exploit this privilege to impersonate SYSTEM by forcing a higher-privileged process to authenticate and then stealing its token. This is a common technique for local privilege escalation on Windows.

369
MCQhard

An organization uses AWS, Azure, and GCP for different workloads. They want a single tool to manage infrastructure consistently across all providers. Which approach is most appropriate?

A.Use Terraform with provider plugins
B.Use Azure Resource Manager templates
C.Write provider-specific scripts in PowerShell
D.Use AWS CloudFormation
AnswerA

Terraform's provider plugins translate a single declarative configuration into each cloud's native API calls, so one workflow and state file manage AWS, Azure and GCP resources. That satisfies the requirement for consistent multi-provider infrastructure management without separate tooling per cloud.

Why this answer

Terraform is an infrastructure-as-code tool that uses provider plugins to interact with the APIs of AWS, Azure, GCP, and hundreds of other services. This allows a single declarative configuration language (HCL) to manage resources consistently across all three cloud providers, making it the most appropriate choice for multi-cloud infrastructure management.

Exam trap

Candidates often mistakenly choose a single-vendor tool like CloudFormation or ARM templates for multi-cloud management. The correct approach uses a cloud-agnostic tool that abstracts provider APIs.

How to eliminate wrong answers

Option B is wrong because Azure Resource Manager (ARM) templates are Azure-specific JSON templates that cannot manage AWS or GCP resources. Option C is wrong because writing provider-specific scripts in PowerShell would require separate scripts for each cloud provider (e.g., AWS Tools for PowerShell, Azure PowerShell, and GCP PowerShell cmdlets), failing to provide a single consistent tool. Option D is wrong because AWS CloudFormation is a native AWS service that uses JSON or YAML templates and cannot manage Azure or GCP resources.

370
MCQeasy

Which of the following is a primary benefit of using a Web Application Firewall (WAF) in front of a web application?

A.It encrypts all traffic between client and server
B.It prevents all types of attacks against the application
C.It filters malicious HTTP requests and can block common web exploits
D.It performs static code analysis on the application
AnswerC

A WAF inspects inbound HTTP traffic against rule sets such as the OWASP Core Rule Set, blocking SQL injection, cross-site scripting and similar exploits before they reach the application. This filtering at layer 7 satisfies the requirement to stop common web attacks rather than merely logging them.

Why this answer

A Web Application Firewall (WAF) operates at Layer 7 (application layer) of the OSI model and inspects HTTP/HTTPS traffic for malicious payloads. It uses a combination of signature-based detection, behavioral analysis, and rule sets (e.g., OWASP ModSecurity Core Rule Set) to filter out common web exploits such as SQL injection, cross-site scripting (XSS), and path traversal. By intercepting and blocking malicious requests before they reach the web application, a WAF provides a critical layer of defense without requiring changes to the application code.

Exam trap

CompTIA often tests the misconception that a WAF provides comprehensive protection against all attacks, when in fact it is a specialized Layer 7 filter that cannot prevent network-layer attacks, business logic abuse, or vulnerabilities in the application's own code logic.

Why the other options are wrong

A

Encryption is typically handled by TLS, not the WAF.

B

WAFs cannot prevent all attacks, especially logic flaws or zero-days.

D

Static code analysis is a separate process, not a WAF function.

371
MCQmedium

A company wants to reduce the mean time to detect (MTTD) for security incidents. Which technology is most effective for this purpose?

A.Security information and event management (SIEM) with behavior analytics
B.Full disk encryption software
C.Data loss prevention (DLP) system
D.Network-based intrusion detection system (NIDS)
AnswerA

SIEM with behaviour analytics correlates logs across sources and baselines normal activity, surfacing anomalies that indicate compromise faster than signature-only tooling. This directly reduces mean time to detect, the metric the company wants to improve.

Why this answer

A SIEM with User and Entity Behavior Analytics (UEBA) is most effective for reducing MTTD because it baselines normal behavior and detects anomalies in real time, enabling early detection of threats. Full disk encryption (B) protects data at rest but does not aid detection. A DLP system (C) focuses on preventing data exfiltration, not broad detection.

A NIDS (D) relies on signature matching, which can miss novel or subtle attacks and typically has a higher detection latency than behavior analytics.

372
Multi-Selectmedium

A security architect is designing deception technologies to detect and delay attackers. Which TWO of the following are examples of deception technologies that can be deployed? Select TWO.

Select 2 answers
A.Honeytokens
B.Honeypots
C.Security Information and Event Management (SIEM)
D.Vulnerability scanner
E.Intrusion Prevention System (IPS)
AnswersA, B

Honeytokens are decoy credentials, files or records seeded across systems; any access triggers an alert, since legitimate users have no reason to touch them. This satisfies the stem's detection requirement, giving high-fidelity, low-false-positive signals of attacker reconnaissance or lateral movement without delaying normal business activity.

Why this answer

Honeytokens (A) are deception artifacts such as fake credentials, files, or database records that have no legitimate use, so any access or use of them is a high-fidelity indicator of malicious activity and can trigger alerts while wasting attacker time. Honeypots (B) are decoy systems or services deliberately exposed to attract and observe attackers, allowing defenders to detect intrusions, collect TTPs, and delay or divert adversaries from real assets. SIEM (C) is a log aggregation, correlation, and alerting platform, not a deception mechanism, so it does not itself lure or deceive attackers.

A vulnerability scanner (D) is an assessment tool that identifies weaknesses in systems and does not create decoys or false targets. An IPS (E) is a preventive control that detects and blocks malicious traffic inline, but it is not a deception technology because it does not present fake assets or bait to attackers.

373
MCQmedium

A company uses a SIEM with User Behavior Analytics (UBA). The UBA generates an alert when a user accesses sensitive data at unusual hours. Which type of correlation rule is being applied?

A.Threshold-based correlation
B.Signature-based correlation
C.Anomaly-based correlation
D.Trend-based correlation
AnswerC

Anomaly-based correlation baselines normal behaviour and alerts on statistically significant deviations, rather than matching fixed signatures or thresholds. Accessing sensitive data at unusual hours deviates from the established behavioural baseline, which is precisely what this rule type detects.

Why this answer

Anomaly-based correlation establishes a baseline of normal behavior and alerts when activity deviates from that baseline. Accessing sensitive data at unusual hours is a deviation from the user's typical access pattern, which is exactly what UBA anomaly detection flags. This is distinct from threshold, signature, and trend rules, which rely on fixed counts, known patterns, or long-term statistical drift respectively.

Exam trap

CAS-005 often tests the confusion between anomaly-based and threshold-based correlation, since both can involve 'unusual' activity — the key discriminator is whether a learned baseline or a fixed numeric limit drives the alert.

How to eliminate wrong answers

Option A is wrong because threshold-based correlation triggers when a count exceeds a predefined limit (e.g., more than 10 failed logins in 5 minutes), not when behavior deviates from a learned baseline. Option B is wrong because signature-based correlation matches known indicators such as specific hashes, IPs, or regex patterns, and unusual access timing is not a static signature. Option D is wrong because trend-based correlation analyzes changes over a longer period (e.g., increasing data exfiltration volume week over week), whereas the scenario describes a single deviation from a behavioral baseline.

374
MCQhard

A security analyst is reviewing a Windows event log from a domain controller and notices Event ID 4769 with the ticket encryption type 0x17. The analyst suspects a Kerberoasting attack. Which of the following best explains why this event is suspicious?

A.The encryption type 0x17 indicates that the ticket is encrypted with the KRBTGT account hash, which is only used for TGTs and not service tickets.
B.The encryption type 0x17 indicates AES256-CTS-HMAC-SHA1-96, which is the default for modern Windows systems and should not trigger alerts.
C.Event ID 4769 with encryption type 0x17 indicates a TGT request using DES, which is deprecated and signals an attempt to downgrade encryption.
D.The encryption type 0x17 indicates RC4-HMAC, which is weak and often requested by attackers to crack service account passwords offline.
AnswerD

Event ID 4769 logs a Kerberos service ticket request. The encryption type 0x17 corresponds to RC4-HMAC, which is weaker and faster to crack than AES. Attackers performing Kerberoasting often request RC4-encrypted tickets for service accounts with SPNs, then extract and crack them offline. Thus, seeing RC4 where AES is expected is a strong indicator of Kerberoasting.

Why this answer

Kerberoasting involves requesting service tickets for accounts with SPNs and then cracking them offline. Attackers often request RC4 (0x17) encryption because it is weaker and faster to crack. Event ID 4769 with encryption type 0x17 on a domain controller is a key detection point.

The correct answer identifies RC4-HMAC as the suspicious element, which aligns with known attacker tactics.

Exam trap

The trap here is confusing encryption type 0x17 with AES, or misidentifying the event ID as a TGT request instead of a service ticket request.

375
MCQmedium

A network administrator is configuring a firewall rule set. The requirement is to allow inbound HTTPS traffic from the internet to a web server at 10.1.1.10, and to allow the web server to respond. All other inbound traffic should be blocked. Which rule set accomplishes this?

A.Allow inbound TCP 80 to 10.1.1.10; allow outbound TCP from 10.1.1.10; deny all inbound
B.Allow inbound TCP 443 to 10.1.1.10; allow outbound TCP from 10.1.1.10; deny all inbound
C.Deny all inbound; allow inbound TCP 443 to 10.1.1.10; allow outbound TCP from 10.1.1.10
D.Allow inbound TCP 22 to 10.1.1.10; allow outbound TCP from 10.1.1.10; deny all inbound
AnswerB

Stateful inspection matches the outbound TCP reply to the existing inbound session, so permitting outbound TCP from 10.1.1.10 lets the web server respond. The explicit deny all inbound then blocks every other unsolicited inbound connection.

Why this answer

HTTPS uses TCP port 443, and the rule set correctly allows inbound TCP 443 to the web server at 10.1.1.10, permits the server's outbound responses (stateful or explicit), and then denies all other inbound traffic. This matches the requirement to allow only HTTPS traffic from the internet while blocking everything else.

Exam trap

The trap here is that candidates often overlook rule order and choose Option C, thinking a 'deny all' at the top is safe, but it actually blocks the intended traffic before the allow rule is processed.

How to eliminate wrong answers

Option A is wrong because it allows inbound TCP port 80 (HTTP), not HTTPS (TCP 443), so it does not meet the requirement for HTTPS traffic. Option C is wrong because the order of rules matters: placing 'deny all inbound' first would block all inbound traffic, including the intended HTTPS traffic, before the allow rule is evaluated. Option D is wrong because it allows inbound TCP port 22 (SSH), which is not HTTPS and would permit unauthorized administrative access, violating the requirement to block all other inbound traffic.

Page 4

Page 5 of 13

Page 6