Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 376–450

973 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
Multi-Selecthard

A security engineer is hardening an SSH server. The policy requires disabling all legacy algorithms and using only modern, secure cryptography. Which THREE of the following configurations should the engineer apply?

Select 3 answers
A.Set HMAC algorithms to use only SHA-2 or stronger.
B.Allow only SSH protocol version 1 for compatibility.
C.Enable root login with password for administrative convenience.
D.Disable password authentication and allow only key-based authentication.
E.Restrict key exchange algorithms to curve25519-sha256.
AnswersA, D, E

Restricting HMAC to SHA-2 or stronger removes MD5 and SHA-1 message authentication codes, which are collision-prone and deprecated. This directly satisfies the policy's requirement to disable legacy algorithms, since SSH MAC negotiation would otherwise still permit these weak integrity checks.

Why this answer

Option A is correct because configuring the MAC (HMAC) list to SHA-2 or stronger (e.g., hmac-sha2-256, hmac-sha2-512) removes weak legacy integrity algorithms such as hmac-md5 and hmac-sha1, which are vulnerable to collision and downgrade attacks. Option D is correct because disabling password authentication and permitting only public-key authentication eliminates brute-force and credential-replay risks, since SSH keys provide stronger, non-reusable cryptographic proof of identity. Option E is correct because restricting KEX algorithms to curve25519-sha256 uses modern elliptic-curve Diffie-Hellman with strong forward secrecy, excluding outdated groups like diffie-hellman-group1-sha1.

Option B is wrong because SSH protocol version 1 is deprecated and insecure (vulnerable to MITM and CRC-32 attacks); only SSH-2 should be allowed. Option C is wrong because enabling direct root login with a password violates least-privilege and hardening best practices, exposing the most privileged account to brute-force attacks.

Exam trap

CAS-005 often tests the temptation to allow legacy protocols or root password login 'for compatibility' — candidates must recognise that these options directly violate the hardening requirement and are never correct in a secure configuration context.

377
MCQmedium

A security engineer is reviewing the configuration of an AWS S3 bucket that stores customer data. Which of the following settings is most likely to cause a data breach?

A.Versioning enabled on the bucket
B.Bucket policy that allows public read access
C.Server-side encryption with AWS KMS
D.MFA delete enabled on the bucket
AnswerB

A bucket policy granting public read access exposes every object to anonymous retrieval, so anyone with the URL can download customer data. This is the setting most likely to cause a breach, unlike encryption or versioning misconfigurations.

Why this answer

A bucket policy allowing public read access exposes data to anyone. Option A (versioning) is a feature, not a risk. Option C (encryption) is secure.

Option D (MFA delete) is a security control.

378
MCQeasy

Which key exchange algorithm provides perfect forward secrecy (PFS) and is recommended for use in TLS 1.3?

A.ECDHE
B.RSA key exchange
C.Pre-shared key (PSK)
D.Diffie-Hellman (DH)
AnswerA

ECDHE generates an ephemeral key pair per session, then discards the private key, so compromising the long-term certificate key cannot decrypt past sessions — satisfying TLS 1.3's PFS requirement. TLS 1.3 mandates ephemeral Diffie-Hellman, and ECDHE is its recommended elliptic-curve instantiation, unlike static RSA key transport.

Why this answer

ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) provides PFS as session keys are ephemeral.

379
MCQmedium

An organization's risk appetite is defined as 'low' for data privacy. Which of the following risk treatments is most aligned with this appetite?

A.Transfer the risk through cyber insurance
B.Mitigate the risk by encrypting personal data
C.Avoid the risk by not collecting unnecessary personal data
D.Accept the risk and self-insure
AnswerC

Eliminates risk directly

Why this answer

With a 'low' risk appetite for data privacy, the organization must minimize exposure to privacy breaches. Avoiding the risk by not collecting unnecessary personal data is the most aligned treatment because it eliminates the privacy risk entirely rather than reducing or transferring it. This approach ensures no personal data exists to be compromised, directly supporting a low-risk appetite.

Exam trap

The CAS-004 exam often tests the distinction between risk mitigation and risk avoidance, where candidates mistakenly choose encryption (mitigation) as the best option for a low-risk appetite, overlooking that avoidance eliminates the risk entirely.

How to eliminate wrong answers

Option A is wrong because transferring risk through cyber insurance does not reduce the likelihood or impact of a privacy breach; it only provides financial compensation, which is insufficient for a low-risk appetite that demands minimal exposure. Option B is wrong because mitigating the risk by encrypting personal data reduces but does not eliminate the risk; encrypted data can still be exfiltrated and decrypted, leaving residual privacy risk unacceptable for a low appetite. Option D is wrong because accepting the risk and self-insuring implies tolerance of potential privacy breaches, which contradicts a low-risk appetite that seeks to avoid such events entirely.

380
MCQmedium

A security architect is designing a hybrid identity solution for a company that wants to enforce device-based conditional access for Microsoft 365. Employees use personal Android and iOS devices, and the company wants to ensure that only compliant devices can access email and SharePoint. The architect must minimize on-premises infrastructure and avoid a full VPN. Which solution should the architect recommend?

A.Configure a full-tunnel VPN that routes all mobile traffic through the corporate network and enforce network access control (NAC) at the edge.
B.Implement Active Directory Federation Services (AD FS) with a Web Application Proxy and require certificate-based authentication for all devices.
C.Use Microsoft Entra ID with Security Defaults enabled and require multi-factor authentication (MFA) for all users.
D.Deploy Microsoft Entra ID with Conditional Access policies that require device compliance, and enroll devices in Microsoft Intune.
AnswerD

Entra ID Conditional Access can require that a device be marked compliant by Intune before granting access to Microsoft 365. Intune enforces device configuration and compliance on Android and iOS without requiring on-premises infrastructure or VPN, directly meeting the requirement to restrict access to compliant devices.

Why this answer

Microsoft Entra ID Conditional Access combined with Intune device compliance is the correct approach because it enforces device-based access decisions for cloud applications without requiring on-premises infrastructure or a full VPN. Conditional Access evaluates signals such as device compliance state and can block or grant access to Microsoft 365 accordingly, while Intune manages device configuration and compliance for both Android and iOS.

Exam trap

The trap here is assuming that multi-factor authentication alone satisfies a device-based conditional access requirement, when in fact device compliance must be evaluated and enforced through a management channel such as Intune.

381
MCQeasy

Based on the auth.log exhibit, what is the MOST appropriate immediate action to mitigate this attack?

A.Disable root login and remove the admin account.
B.Block the entire 192.168.1.0/24 subnet at the firewall.
C.Configure fail2ban to block the IP address after a threshold of failed attempts.
D.Change the SSH port to a non-standard port.
AnswerC

Fail2ban parses auth.log and dynamically inserts firewall rules to drop the source IP once failed authentication attempts cross a threshold, immediately throttling the brute-force source while legitimate users retain access, and it is reversible once the attack subsides.

Why this answer

Configuring fail2ban to block the IP address after a threshold of failed attempts is the most appropriate immediate action because it dynamically mitigates brute-force attacks by temporarily banning offending IPs. This approach is targeted and automated, reducing the attack surface without disrupting legitimate users. It directly addresses the observed repeated failed login attempts in the auth.log.

Exam trap

The trap is choosing a broad or permanent solution (like blocking a subnet or changing ports) instead of a targeted, automated response that directly mitigates the attack.

How to eliminate wrong answers

Option A is wrong because disabling root login and removing the admin account may be part of a hardening strategy but does not immediately stop an ongoing attack from a specific IP, and removing the admin account could cause operational issues. Option B is wrong because blocking an entire subnet is overly broad and may block legitimate users, and it does not address attacks from other sources. Option D is wrong because changing the SSH port is security through obscurity and does not prevent brute-force attacks; it only reduces automated scanning.

382
MCQeasy

Which key performance indicator (KPI) is most useful for measuring the effectiveness of an incident response process?

A.Patch compliance percentage
B.Vulnerabilities by severity
C.Number of security awareness training sessions
D.Mean time to respond (MTTR)
AnswerD

MTTR measures elapsed time from incident detection to containment or resolution, directly reflecting how quickly the response process actually works. It satisfies the stem's requirement for a KPI gauging incident response effectiveness, unlike volume or cost metrics.

Why this answer

Mean time to respond (MTTR) measures the average time taken to respond to and contain a security incident from detection. It directly reflects the efficiency and effectiveness of the incident response process, as lower MTTR indicates faster containment and reduced impact. Other metrics like patch compliance or vulnerabilities by severity are related to vulnerability management, not incident response effectiveness.

Exam trap

CAS-005 often tests the confusion between preventive metrics (like patch compliance) and response metrics (like MTTR), leading candidates to choose a vulnerability management metric.

How to eliminate wrong answers

Option A is wrong because patch compliance percentage measures how well systems are patched, which is a preventive control, not an incident response metric. Option B is wrong because vulnerabilities by severity is a risk assessment metric, not a measure of incident response effectiveness. Option C is wrong because the number of security awareness training sessions is a training metric, not an incident response KPI.

383
MCQmedium

An organization wants to adopt a cybersecurity framework that provides a structured approach to managing cyber risks. Which framework is BEST suited?

A.COBIT
B.NIST Cybersecurity Framework
C.ISO 27001
D.ITIL
AnswerB

The NIST Cybersecurity Framework supplies a structured, voluntary approach organised around Identify, Protect, Detect, Respond and Recover, giving organisations a repeatable way to manage cyber risk. Its risk-based core functions directly match the stem's requirement for structured cyber risk management.

Why this answer

The NIST Cybersecurity Framework (CSF) is specifically designed to provide a structured, risk-based approach to managing cybersecurity risks, offering core functions (Identify, Protect, Detect, Respond, Recover) and implementation tiers that align with an organization's risk appetite. It is the best fit because it directly addresses cyber risk management through a flexible, outcome-driven framework, unlike other frameworks that focus on IT governance, information security management systems, or service management.

Exam trap

CompTIA often tests the distinction between governance/IT management frameworks (COBIT, ITIL) and cybersecurity-specific risk frameworks, trapping candidates who confuse ISO 27001's ISMS certification with a structured cyber risk management approach.

How to eliminate wrong answers

Option A (COBIT) is wrong because it is an IT governance and management framework focused on aligning IT processes with business objectives and control objectives, not a dedicated cybersecurity risk management framework. Option C (ISO 27001) is wrong because it is an information security management standard that specifies requirements for an ISMS (Information Security Management System) and is certification-oriented, not a structured cyber risk management framework like the NIST CSF. Option D (ITIL) is wrong because it is a set of best practices for IT service management (ITSM), focusing on service lifecycle and delivery, with no direct emphasis on cybersecurity risk management.

384
MCQeasy

A security analyst is investigating a compromised Linux web server. The analyst needs to preserve volatile evidence before shutting the system down for forensic imaging. Which action should the analyst perform FIRST?

A.Create a forensic image of the server's disk drives.
B.Review the application and system logs for signs of intrusion.
C.Capture the contents of physical memory and the current network connections.
D.Shut down the server gracefully to prevent further attacker activity.
AnswerC

Order of volatility dictates that the most perishable evidence, such as RAM contents and active network connections, must be collected before anything else because it is lost on shutdown or even over time. Capturing memory and live connections first preserves artifacts that no disk image can recover.

Why this answer

Forensic handling follows the order of volatility, so the most transient data is collected first. RAM and network connections vanish on power loss or reboot, while disk contents persist. Capturing memory and live connections before imaging or analysis preserves evidence that would otherwise be unrecoverable.

Exam trap

The trap here is equating thoroughness with starting at the disk image, when the perishable memory and network state must be captured before any shutdown or lengthy disk operation.

385
Multi-Selectmedium

A company is evaluating multi-factor authentication methods. Which TWO are considered phishing-resistant? (Select TWO.)

Select 2 answers
A.FIDO2/WebAuthn
B.Biometric authentication on a smartphone
C.TOTP via mobile app
D.SMS one-time codes
E.Hardware security tokens (e.g., YubiKey)
AnswersA, E

FIDO2/WebAuthn binds credentials to the origin's domain via public-key cryptography, so a phishing site on a different domain cannot trigger or replay the authentication. This origin-binding satisfies the phishing-resistance requirement, unlike OTP or push methods vulnerable to real-time relay.

Why this answer

FIDO2/WebAuthn (A) is phishing-resistant because it uses public-key cryptography bound to the origin (relying party ID), so credentials created for one site cannot be replayed on a look-alike phishing domain. Hardware security tokens such as a YubiKey (E) are phishing-resistant for the same reason: they implement FIDO2/U2F and sign a challenge with a private key tied to the legitimate origin, and the private key never leaves the device. In contrast, biometric authentication on a smartphone (B) is only a local verification factor and, by itself, is not bound to the web origin, so it can be captured or relayed in a phishing flow.

TOTP via a mobile app (C) is a shared-secret code that a phishing site can proxy in real time, so it is not phishing-resistant. SMS one-time codes (D) are similarly replayable and additionally vulnerable to SIM-swapping and interception, making them the weakest option here.

386
MCQmedium

An organization is using the FAIR model to quantify risk. Which of the following is a primary component of the FAIR taxonomy?

A.Inherent risk and residual risk
B.Annualized loss expectancy and single loss expectancy
C.Loss event frequency and loss magnitude
D.Threat event frequency and vulnerability
AnswerC

Loss event frequency and loss magnitude form FAIR's two top-level factors, splitting risk into how often a threat event occurs and how much it costs. This taxonomy directly satisfies the stem's quantification requirement, letting analysts model frequency and magnitude separately rather than relying on qualitative ratings.

Why this answer

The FAIR (Factor Analysis of Information Risk) taxonomy decomposes risk into two primary factors: Loss Event Frequency (LEF) — how often a loss event is expected to occur — and Loss Magnitude (LM) — how much loss each event would cause. These two top-level factors are then further decomposed (e.g., LEF into threat event frequency and vulnerability; LM into primary and secondary loss). LEF and LM are the canonical first-level components of the FAIR ontology.

Exam trap

CAS-005 often tests whether candidates can distinguish FAIR's structural taxonomy components (LEF, LM) from derived quantitative outputs (ALE, SLE) or generic risk terms (inherent vs. residual risk).

How to eliminate wrong answers

Option A is wrong because inherent risk and residual risk are general risk-management concepts (risk before and after controls), not primary components of the FAIR taxonomy — FAIR models them through control strength affecting LEF. Option B is wrong because ALE and SLE are quantitative outputs derived from FAIR analysis (SLE × ARO = ALE), not taxonomy components; they are results, not structural elements. Option D is wrong because threat event frequency and vulnerability are sub-components that feed into Loss Event Frequency, not the top-level primary components of the FAIR taxonomy.

387
Multi-Selecteasy

A company is implementing a software-defined perimeter (SDP) architecture. Which TWO of the following are key characteristics of SDP? (Select TWO.)

Select 2 answers
A.Network segmentation is implemented via VLANs
B.The infrastructure is invisible to unauthorized users
C.Peering between SDP components is done via BGP
D.All communications are encrypted using public key cryptography
E.Device authentication is required before granting network access
AnswersB, E

SDP uses a black cloud model, hiding assets until authentication.

Why this answer

A core principle of Software-Defined Perimeter (SDP) is to make the infrastructure invisible to unauthorized users. This is achieved by deploying SDP controllers and gateways that hide network components (e.g., servers, IP addresses) from unauthenticated clients, effectively creating a 'black cloud' that only reveals resources after successful authentication and authorization.

Exam trap

The trap here is that candidates often confuse SDP's encryption requirement with 'public key cryptography only,' forgetting that SDP uses a hybrid approach (public key for key exchange, symmetric for bulk encryption) and that the defining characteristic is invisibility and device authentication, not the specific encryption algorithm.

388
MCQeasy

A company is migrating its applications to a SaaS model. Which of the following should be included in the contract to ensure secure data handling?

A.Right to audit
B.Indemnification clause
C.SLA for uptime
D.Data encryption at rest and in transit
AnswerD

Mandating encryption at rest and in transit in the SaaS contract ensures the provider applies cryptographic controls to stored data and network traffic, directly satisfying the secure data handling requirement that the migration imposes on the outsourced service.

Why this answer

Data encryption at rest and in transit is a fundamental security requirement for protecting sensitive data in a SaaS environment. Encryption at rest (e.g., AES-256) ensures data stored on the provider's servers is unreadable if physically compromised, while encryption in transit (e.g., TLS 1.2/1.3) protects data as it moves between the client and the SaaS platform. This directly addresses secure data handling, which is the core concern of the question.

Exam trap

The trap here is that candidates often confuse legal or operational clauses (audit, indemnification, SLA) with technical security controls, mistakenly believing that contractual terms alone can enforce secure data handling without specifying cryptographic protections.

How to eliminate wrong answers

Option A is wrong because a right to audit clause allows the customer to verify the provider's security controls, but it does not itself ensure secure data handling; it is a verification mechanism, not a technical safeguard. Option B is wrong because an indemnification clause is a legal remedy that transfers liability for breaches or damages, but it does not prevent data mishandling or enforce encryption; it is a post-incident financial protection, not a proactive security control. Option C is wrong because an SLA for uptime (e.g., 99.9% availability) addresses service reliability and availability, not data confidentiality or integrity; it is unrelated to secure data handling.

389
MCQmedium

A security architect is evaluating a hardware security module (HSM) for key management. Which of the following is a PRIMARY benefit of using an HSM over software-based key storage?

A.Easier key rotation
B.Integration with cloud APIs
C.Tamper-resistant physical protection of keys
D.Lower cost
AnswerC

Tamper-resistant physical protection directly satisfies the stem's hardware-versus-software constraint: keys reside inside a validated cryptographic boundary that zeroises on intrusion, so extraction attempts destroy the material. Software-based storage exposes keys to memory scraping and host compromise, whereas an HSM's physical shielding enforces confidentiality independently of the operating system.

Why this answer

An HSM provides tamper-resistant physical protection for cryptographic keys, ensuring that even if an attacker gains physical access to the device, the keys cannot be extracted or modified. This is a primary benefit over software-based key storage, which stores keys in memory or disk and is vulnerable to OS-level attacks, memory dumps, or file system breaches. The HSM's hardware root of trust and physical security mechanisms (e.g., tamper switches, zeroization) make it the gold standard for key protection in compliance-heavy environments like FIPS 140-2 Level 3 or PCI DSS.

Exam trap

The trap here is that candidates confuse 'ease of use' or 'cost savings' with security benefits, overlooking that the HSM's core value is its physical tamper resistance and hardware-enforced key isolation, not operational convenience or lower price.

How to eliminate wrong answers

Option A is wrong because key rotation is not inherently easier with an HSM; in fact, software-based solutions often provide more flexible scripting and automation for rotation, while HSM rotation may require specific API calls or manual intervention depending on the model. Option B is wrong because integration with cloud APIs is a feature of cloud HSM offerings (e.g., AWS CloudHSM, Azure Key Vault), not a primary benefit of HSM technology itself; on-premises HSMs often lack native cloud API integration and require additional middleware. Option D is wrong because HSMs are significantly more expensive than software-based key storage due to dedicated hardware, certification costs, and maintenance, making lower cost a disadvantage, not a benefit.

390
MCQmedium

A security engineer is implementing a network access control (NAC) solution that must authenticate users and devices before granting access to the corporate network. The organization wants to use a protocol that supports both authentication and authorization and can carry attributes such as VLAN assignment and ACLs. The engineer decides to use RADIUS. Which of the following statements about RADIUS is correct?

A.RADIUS encrypts the entire authentication packet, including attributes, using a shared secret.
B.RADIUS supports the EAP framework natively without any additional encapsulation.
C.RADIUS uses UDP ports 1812 for authentication and 1813 for accounting.
D.RADIUS operates at the application layer and uses TCP for reliable delivery.
AnswerC

RADIUS traditionally uses UDP ports 1812 (authentication) and 1813 (accounting). These are the official IANA-assigned ports. While some legacy implementations use 1645 and 1646, the standard ports are 1812 and 1813. This is a correct statement about RADIUS.

Why this answer

RADIUS uses UDP ports 1812 for authentication and 1813 for accounting as assigned by IANA. It encrypts only the password field, not the whole packet, and it requires EAP encapsulation to support EAP methods. Understanding these details is essential for proper NAC implementation.

Exam trap

The trap here is assuming RADIUS encrypts all attributes or uses TCP, when it actually only encrypts the password and uses UDP, with EAP requiring encapsulation.

391
MCQeasy

A security analyst discovers that a containerized application is running with root privileges. Which of the following is the best practice to reduce the attack surface?

A.Use a minimal base image
B.Disable network access for the container
C.Run the container as a non-root user
D.Use a read-only root filesystem
AnswerC

Running the container as a non-root user removes the ability to perform privileged operations inside the container. If the application is compromised, the attacker gains only the limited permissions of that unprivileged account, reducing the attack surface.

Why this answer

Running a container as a non-root user directly reduces the attack surface by limiting the privileges available to an attacker if the container is compromised. Option A (minimal base image) reduces potential vulnerabilities but does not address the root privilege issue. Option B (disable network access) could break application functionality and does not affect privilege level.

Option D (read-only root filesystem) prevents writing to the filesystem but still allows root-level access.

392
MCQhard

A security engineer is hardening a Kubernetes cluster. They want to reduce the risk of container escape attacks. Which combination of settings is most effective at the pod security context level?

A.Set runAsNonRoot: true, readOnlyRootFilesystem: true, and drop: ['ALL'].
B.Set runAsNonRoot: false and readOnlyRootFilesystem: true.
C.Set runAsUser: 1000 and capabilities.add: ['NET_ADMIN'].
D.Set privileged: true and readOnlyRootFilesystem: false.
AnswerA

Drops all capabilities, enforces non-root, and read-only filesystem – defense in depth against escapes.

Why this answer

Setting `runAsNonRoot: true` prevents the container from running as the root user, `readOnlyRootFilesystem: true` prevents writes to the container's root filesystem, and dropping all Linux capabilities with `drop: ['ALL']` removes all kernel privileges. Together, these three settings at the pod security context level drastically reduce the attack surface for container escape attacks by eliminating common privilege escalation vectors.

Exam trap

The CAS-004 exam often tests the misconception that setting a specific `runAsUser` (like 1000) is equivalent to enforcing non-root execution, when in fact `runAsNonRoot: true` is the explicit directive that prevents root UID (0) from being used, regardless of the numeric UID set.

How to eliminate wrong answers

Option B is wrong because `runAsNonRoot: false` allows the container to run as root, which is a primary vector for container escape; even with a read-only root filesystem, a root process can still use capabilities or syscalls to break out. Option C is wrong because setting `runAsUser: 1000` does not prevent running as root (it only sets a specific UID but does not enforce non-root), and adding `NET_ADMIN` capability grants network administration privileges that can be abused for escape, increasing risk rather than reducing it. Option D is wrong because `privileged: true` disables all security isolation, effectively giving the container host-level access, and `readOnlyRootFilesystem: false` allows writes to the root filesystem, making container escape trivial.

393
MCQhard

A security architect must protect a REST API that issues short-lived, signed access tokens. The design goal is to prevent a compromised authorization server from minting tokens that other resource servers will accept after the compromise is detected, without requiring resource servers to poll a central service on every request. Which design BEST meets this goal?

A.Publish a signed token status list that resource servers fetch and cache, allowing revoked or suspect token identifiers to be rejected until the list's next refresh.
B.Shorten the token lifetime to five minutes and require resource servers to validate the signature with the authorization server's public key.
C.Issue tokens bound to the client's TLS session so that a token is only usable from the connection on which it was issued.
D.Require mutual TLS between the authorization server and each resource server and pin the authorization server's certificate.
AnswerA

A signed, cacheable status list lets resource servers reject tokens that the authorization server (or a recovery process) marks as invalid without a per-request call to the issuer. Because the list is signed and versioned, resource servers can refresh it on a schedule and honor the most recent revocation state, bounding the acceptance window after a compromise while keeping request-path latency low.

Why this answer

The goal is to bound how long a fraudulent token remains acceptable without adding a synchronous dependency on the issuer. A signed, cacheable token status list gives resource servers an offline-checkable revocation signal that they can refresh periodically, so tokens minted after detection can be rejected within the refresh interval while normal request processing stays fast and resilient.

Exam trap

The trap here is treating signature validation or channel security as proof that the issuer was uncompromised, when neither addresses tokens minted during an issuer breach.

394
Multi-Selecthard

A security architect is designing a data loss prevention (DLP) program for a multinational retailer that processes payment card data and personally identifiable information. The program must discover sensitive data at rest across on-premises file shares and cloud storage, and it must prevent sensitive data from leaving the organization through email and web uploads. Which two capabilities are essential for this program? (Choose two.)

Select 2 answers
A.Security information and event management (SIEM) correlation of DLP alerts with threat intelligence feeds.
B.Content inspection using pattern matching and data classifiers to identify regulated data types.
C.Enforcement policies applied at egress points such as email gateways and secure web gateways.
D.Full-disk encryption on all endpoint devices and servers that store regulated data.
E.Network segmentation of the cardholder data environment using internal firewalls.
AnswersB, C

Content inspection with pattern matching and classifiers is the foundation of any DLP program because it identifies regulated data such as card numbers and PII within files, messages, and uploads. Without accurate classification, neither discovery at rest nor prevention in motion can distinguish sensitive content from ordinary business data, so this capability is essential to meet both stated requirements.

Why this answer

A functioning DLP program needs both accurate identification of regulated content and an enforcement point where policy can act. Content inspection with classifiers supplies the identification, while egress enforcement at email and web gateways supplies the prevention. Encryption, SIEM correlation, and segmentation are valuable controls but do not deliver either of the two required DLP capabilities.

Exam trap

The trap here is selecting adjacent data-protection controls such as encryption or segmentation that secure data but do not inspect content or enforce egress policy, which are the actual DLP functions.

395
MCQeasy

A financial institution must comply with the Sarbanes-Oxley Act (SOX). Which of the following is a primary focus of SOX compliance?

A.Security of credit card transactions
B.Privacy of health information
C.Protection of personally identifiable information (PII)
D.Accuracy and reliability of financial reporting
AnswerD

SOX mandates accurate, reliable financial reporting and internal controls over financial disclosure, directly satisfying the stem's regulatory constraint for a financial institution. Unlike frameworks centred on data privacy or payment card handling, SOX specifically governs the integrity of financial statements and the controls assuring their accuracy.

Why this answer

SOX is a U.S. federal law enacted in 2002 to protect investors by improving the accuracy and reliability of corporate financial disclosures. Its primary focus is ensuring that financial reporting is accurate, reliable, and subject to internal controls and independent audits. This directly aligns with option D.

Exam trap

CAS-005 often tests the confusion between compliance frameworks — candidates may associate SOX with financial data but incorrectly pick PII or PCI, forgetting that SOX is specifically about financial reporting accuracy and internal controls.

How to eliminate wrong answers

Option A is wrong because credit card transaction security is governed by PCI DSS, not SOX. Option B is wrong because health information privacy is the domain of HIPAA. Option C is wrong because PII protection is a broad privacy concern covered by laws like GDPR or CCPA, not the primary focus of SOX.

396
MCQmedium

A security operations center (SOC) analyst is reviewing a Windows event log after a suspected credential dumping incident. The analyst observes Event ID 4688 (process creation) for a process named 'rundll32.exe' with command-line arguments containing 'comsvcs.dll MiniDump'. Which of the following best describes the attacker's technique?

A.Credential dumping via LSASS memory using a signed Windows binary
B.Pass-the-hash using NTLM authentication against remote systems
C.Kerberoasting by requesting service tickets for SPNs
D.DCSync attack to replicate directory services data
AnswerA

This is correct because comsvcs.dll MiniDump is a known LOLBin technique to dump LSASS memory using rundll32.exe, a signed Microsoft binary. It avoids dropping custom tools and can bypass some application whitelisting. The command-line arguments are a strong indicator of credential dumping, aligning with MITRE ATT&CK T1003.001.

Why this answer

The attacker used rundll32.exe to call the MiniDump export of comsvcs.dll, a built-in Windows DLL, to dump LSASS process memory. This is a living-off-the-land technique for credential dumping (T1003.001) that evades detection by using a signed binary. The other options describe different credential access methods that do not match the observed command line.

Exam trap

The trap here is assuming that credential dumping always requires custom tools like Mimikatz, overlooking built-in Windows utilities that can achieve the same goal.

397
MCQmedium

A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?

A.Store the key in an encrypted file on a secure server
B.Generate the key on a dedicated virtual machine
C.Use a Hardware Security Module (HSM) for key management
D.Keep the key on a smart card stored in a safe
AnswerC

An HSM is tamper-resistant hardware that generates and stores the root CA private key internally, performing signing operations without exposing the key to software or memory. This provides the physical protection and non-exportability that high-assurance root key custody demands.

Why this answer

A Hardware Security Module (HSM) is a tamper-resistant physical device that generates, stores, and uses cryptographic keys within its protected boundary, never exposing the private key in plaintext. For a root CA — the trust anchor of the entire PKI — an HSM provides FIPS 140-2 Level 3 (or higher) assurance, key backup/recovery controls, and audit logging that no software-based or portable storage method can match. This is the industry-standard approach for high-assurance root CA key protection.

Exam trap

CAS-005 often tests whether candidates equate 'encrypted storage' or 'dedicated VM' with high-assurance key protection, when only an HSM provides tamper-resistant, non-exportable key custody for a root CA.

How to eliminate wrong answers

Option A is wrong because storing a root CA key in an encrypted file on a server exposes it to memory scraping, disk theft, and OS compromise; encryption at rest does not protect the key when decrypted for use. Option B is wrong because a dedicated VM still runs a general-purpose OS with hypervisor and memory attack surface, and the key exists in RAM during signing operations. Option D is wrong because a smart card in a safe is offline and lacks the tamper-resistant, high-throughput signing, and audited key lifecycle management that an HSM provides for a root CA.

398
MCQeasy

Which component of the MITRE ATT&CK framework categorizes the 'why' of an adversary's action, such as initial access or credential access?

A.Tactics
B.Mitigations
C.Procedures
D.Techniques
AnswerA

Tactics represent the adversary's tactical goal — the 'why' behind an action — with entries such as Initial Access, Execution and Credential Access. Techniques, by contrast, describe the 'how'. The stem asks which component categorises the 'why', so Tactics is the matching category.

Why this answer

In MITRE ATT&CK, tactics represent the adversary's tactical goal — the 'why' behind an action — such as Initial Access, Execution, Persistence, or Credential Access. Techniques describe the 'how' (specific methods), and procedures describe the specific implementation. The question explicitly asks for the 'why,' which maps to tactics.

Exam trap

CAS-005 often tests the distinction between tactics (the why/goal) and techniques (the how/method), since both terms appear frequently and candidates conflate them under the TTP umbrella.

How to eliminate wrong answers

Option B is wrong because Mitigations are defensive countermeasures mapped to techniques, not adversary goals. Option C is wrong because Procedures (the 'P' in TTP) describe the specific, detailed implementation an adversary uses, not the high-level goal. Option D is wrong because Techniques describe how a tactic is accomplished (e.g., phishing is a technique under Initial Access), not the why.

399
MCQhard

An incident responder is analyzing a malware sample obtained from an infected host. The responder wants to perform dynamic analysis to observe the malware's behavior in a safe environment. Which of the following is the best approach?

A.Check the PE header for imported functions
B.Disassemble the malware using IDA Pro
C.Run strings on the malware binary
D.Execute the malware in a virtual machine with network monitoring tools
AnswerD

Running the sample inside an isolated virtual machine with network monitoring captures real behavioural indicators — process creation, registry writes, file drops and command-and-control traffic — without risking the production host. This satisfies the stem's safe-environment constraint, since the VM can be snapshotted and reverted after execution.

Why this answer

Dynamic analysis requires observing malware behavior during execution, not examining its static properties. Running the sample in an isolated VM with network monitoring (e.g., Wireshark, INetSim, FakeNet-NG) allows the responder to capture real-time process creation, file system changes, registry modifications, and C2 callbacks. This is the only option that actually executes the malware and observes runtime behavior, which is the definition of dynamic analysis.

Exam trap

CAS-005 often tests the distinction between static analysis (PE headers, strings, disassembly) and dynamic analysis (execution in a sandbox/VM), so candidates who equate 'analyzing malware' with 'inspecting the binary' pick A, B, or C instead of the only option that actually executes the sample.

How to eliminate wrong answers

Option A is wrong because inspecting the PE header for imported functions is static analysis — it reveals potential capabilities (e.g., CreateRemoteThread, InternetOpen) but never confirms actual runtime behavior and can be defeated by packing or dynamic API resolution. Option B is wrong because disassembling with IDA Pro is also static analysis; it produces assembly code for human review but does not execute the sample, so it cannot observe live behavior and is heavily hindered by obfuscation, packing, or anti-disassembly tricks. Option C is wrong because running strings extracts printable ASCII/Unicode sequences from the binary — a purely static, low-fidelity technique that may reveal URLs or error messages but provides no behavioral insight and is trivially obfuscated.

400
MCQmedium

A security analyst is reviewing alerts from a SIEM and notices multiple failed login attempts from a single IP address to different user accounts over a 5-minute window. What should the analyst do FIRST?

A.Block the IP address at the firewall.
B.Isolate all endpoints that received the login attempts.
C.Check the source IP and correlate with other logs to confirm suspicious activity.
D.Reset all user accounts that were targeted.
AnswerC

Correlating the source IP against authentication, firewall and endpoint logs distinguishes a genuine password-spraying or brute-force attempt from a misconfigured service account or scanner, establishing scope and intent before escalation or blocking. Verification precedes containment actions such as blocking the address.

Why this answer

The analyst should first validate the alert by checking the source IP and correlating with other logs to confirm whether the activity is truly malicious. This step ensures that the response is based on accurate information and avoids unnecessary actions. Correlating logs can reveal patterns, such as whether the attempts are part of a broader attack or a false positive.

Only after confirmation should the analyst proceed with containment or remediation.

Exam trap

CAS-005 often tests the order of incident response steps, and candidates may jump to containment actions like blocking or isolating without first validating the alert, which is a common mistake.

How to eliminate wrong answers

Option A is wrong because blocking the IP immediately without validation could disrupt legitimate traffic and is a containment step that should follow confirmation. Option B is wrong because isolating endpoints is a drastic containment measure that should only be taken after confirming a compromise, not for mere failed login attempts. Option D is wrong because resetting accounts is a remediation action that could cause unnecessary disruption and should only be done if accounts are confirmed compromised.

401
MCQmedium

A company is required to comply with PCI DSS. What is the primary purpose of conducting quarterly network vulnerability scans?

A.To ensure firewall rules are correctly configured
B.To verify encryption strength
C.To detect and remediate vulnerabilities in a timely manner
D.To monitor user access logs
AnswerC

Quarterly scanning satisfies PCI DSS Requirement 11.3.2 by identifying exploitable weaknesses in external and internal networks before attackers do, enabling remediation within the mandated timeframe. Continuous detection keeps the cardholder data environment compliant between annual penetration tests, directly addressing the standard's timely-remediation constraint.

Why this answer

The primary purpose of quarterly network vulnerability scans under PCI DSS is to detect and remediate vulnerabilities in a timely manner. PCI DSS Requirement 11.2 mandates quarterly internal and external vulnerability scans to identify security weaknesses and address them before they can be exploited. This proactive approach helps maintain a secure network environment.

Exam trap

CAS-005 often tests the confusion between vulnerability scanning and other security assessments like firewall audits or encryption validation, leading candidates to select a secondary benefit.

How to eliminate wrong answers

Option A is wrong because while firewall rule configuration is important, vulnerability scans are not primarily for verifying firewall rules; that is typically done through configuration reviews or penetration testing. Option B is wrong because verifying encryption strength is not the main goal of vulnerability scans; encryption is assessed through other means like cryptographic audits. Option D is wrong because monitoring user access logs is a detective control, not the purpose of vulnerability scans.

402
MCQhard

During a red team exercise, the team gains access to a workstation and needs to maintain persistence. They modify a registry run key to execute a payload. However, the organization uses EDR that monitors registry changes. Which technique could the red team use to avoid detection?

A.Delete the registry key after execution
B.Change the registry key to a less suspicious name
C.Encrypt the registry key value
D.Use a LOLBin to execute the payload via a scheduled task
AnswerD

A LOLBin such as schtasks.exe creates the scheduled task using a signed Microsoft binary, so the registry run key is never touched. This satisfies evading the EDR's registry-change monitoring while still achieving persistence through Task Scheduler.

Why this answer

Using a LOLBin (Living Off the Land Binary) such as schtasks.exe, regsvr32.exe, or mshta.exe to trigger the payload via a scheduled task avoids writing to the classic Run/RunOnce registry keys that EDR products heavily monitor. Scheduled tasks are a native Windows persistence mechanism, and when invoked through signed Microsoft binaries, the activity blends into legitimate administrative behavior. This reduces the registry-change telemetry that would otherwise flag the Run key modification.

Exam trap

CAS-005 often tests the misconception that hiding or obfuscating a monitored artifact (renaming, encrypting, deleting) defeats EDR, when the correct answer is usually to switch to a different, less-monitored persistence mechanism such as a scheduled task or WMI subscription.

How to eliminate wrong answers

Option A is wrong because deleting the Run key after execution removes the persistence mechanism entirely — the payload would not survive a reboot, defeating the purpose of persistence. Option B is wrong because renaming a Run key to something 'less suspicious' does not evade EDR; modern EDR monitors the Run/RunOnce hives by path and value content, not by name reputation, so any write to those keys still generates telemetry. Option C is wrong because encrypting the registry value does not prevent the registry write event from being logged — EDR detects the modification itself, and the encrypted blob would also fail to execute as a valid command.

403
Multi-Selectmedium

A risk manager is applying the FAIR model to quantify a risk. Which TWO of the following are primary components used in FAIR analysis? (Select TWO.)

Select 2 answers
A.Loss Magnitude (LM)
B.Single Loss Expectancy (SLE)
C.Annual Loss Expectancy (ALE)
D.Loss Event Frequency (LEF)
E.Annualized Rate of Occurrence (ARO)
AnswersA, D

Loss Magnitude quantifies the financial impact of a single loss event across primary and secondary forms. It is a primary FAIR factor, paired with Loss Event Frequency to derive annualised risk exposure in the model.

Why this answer

FAIR model decomposes risk into Loss Event Frequency (LEF) and Loss Magnitude (LM). Single Loss Expectancy (SLE) and Annualized Rate of Occurrence (ARO) are used in quantitative risk analysis (e.g., ALE), but not primary FAIR components. Exposure Factor (EF) is part of SLE calculation.

Annual Loss Expectancy (ALE) is a result, not a component.

404
Multi-Selecthard

An organization is implementing a vendor risk management program and is reviewing a contract that includes a right-to-audit clause. Which THREE of the following are common elements that should be verified during such an audit? (Select THREE.)

Select 3 answers
A.Employee satisfaction surveys
B.Vendor's financial stability
C.Access control mechanisms
D.Incident response procedures
E.Data encryption practices
AnswersC, D, E

Access control mechanisms are a core control area verified under right-to-audit clauses, confirming that only authorised identities reach vendor systems and data. Auditors examine authentication, authorisation and privileged access management to validate the vendor's safeguards against unauthorised entry.

Why this answer

Option C (Access control mechanisms) is correct because a right-to-audit review must verify that the vendor enforces least privilege, authentication, and authorization controls to protect the organization's data from unauthorized access. Option D (Incident response procedures) is correct because the audit should confirm the vendor has documented detection, containment, eradication, and notification processes, including breach notification timelines, to meet contractual and regulatory obligations. Option E (Data encryption practices) is correct because auditors must verify encryption in transit and at rest, key management, and algorithm standards to ensure data confidentiality and integrity.

Option A (Employee satisfaction surveys) is not a security or compliance control relevant to vendor risk, and Option B (Vendor's financial stability) is a business viability concern typically assessed during due diligence rather than a right-to-audit control review.

Exam trap

CAS-005 often tests the distinction between security-focused audit elements and broader business or HR factors, tempting candidates to select financial stability or employee satisfaction as part of a right-to-audit, which are typically outside the scope of information security audits.

405
MCQmedium

A security analyst is reviewing a packet capture of suspicious traffic that uses a custom protocol over TCP. The analyst needs to determine the application-layer payload and session flow to identify potential data exfiltration. Which tool is MOST appropriate for this task?

A.Nmap
B.tcpdump
C.Wireshark
D.NetFlow
AnswerC

Wireshark provides deep packet inspection with protocol dissectors, allowing the analyst to view application-layer payloads, reassemble TCP streams, and analyze session flow. It supports custom protocol analysis through user-defined dissectors and is the most appropriate tool for this scenario.

Why this answer

Wireshark is the correct choice because it enables deep packet inspection, protocol dissection, and TCP stream reassembly, which are essential for analyzing custom protocols and identifying data exfiltration. The other tools lack the granular payload analysis and session reconstruction capabilities required for this task.

Exam trap

The trap here is assuming that any packet capture tool can perform deep application-layer analysis, when only Wireshark provides the necessary dissectors and stream reassembly.

406
MCQhard

A security analyst calculates the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

A.$50,200
B.$2,500
C.$10,000
D.$250,000
AnswerC

ALE is calculated by multiplying single loss expectancy by annualised rate of occurrence: $50,000 × 0.2 = $10,000. This quantifies the expected annual loss from the risk, matching the stem's supplied SLE and ARO values.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, SLE = $50,000 and ARO = 0.2, so ALE = $50,000 * 0.2 = $10,000. This represents the expected monetary loss per year from the risk.

Exam trap

CAS-005 often tests the confusion between the ALE formula and other combinations like SLE + ARO or SLE / ARO, leading candidates to pick a mathematically incorrect option.

How to eliminate wrong answers

Option A is wrong because $50,200 is the sum of SLE and ARO, not the product; ALE is not calculated by addition. Option B is wrong because $2,500 is SLE divided by 20 (or ARO multiplied by 0.05), which is not the correct formula. Option D is wrong because $250,000 is SLE multiplied by 5 (or SLE divided by 0.2), which incorrectly uses the reciprocal of ARO.

407
MCQeasy

An organization uses Kubernetes to orchestrate containers. Which practice enhances the security of pod-to-pod communication?

A.Implement network policies that restrict ingress and egress traffic based on labels.
B.Expose all pods via NodePort services.
C.Use ClusterIP services for all internal traffic.
D.Rely on the default Kubernetes network configuration.
AnswerA

Kubernetes network policies act as pod-level firewalls, selecting pods by label and permitting only declared ingress and egress flows. This segments pod-to-pod traffic, blocking lateral movement between compromised containers that would otherwise communicate freely on the flat cluster network.

Why this answer

Network policies in Kubernetes act as a firewall for pods, allowing you to define ingress and egress rules based on labels, namespaces, or IP blocks. By default, all pod-to-pod traffic is allowed; implementing network policies restricts this traffic to only what is explicitly permitted, thereby enhancing security by enforcing the principle of least privilege.

Exam trap

A common misconception is that ClusterIP services inherently secure pod-to-pod communication, but ClusterIP only provides service discovery and load balancing, not traffic filtering or segmentation.

How to eliminate wrong answers

Option B is wrong because exposing all pods via NodePort services opens them to external network access on every node's IP, which increases the attack surface and bypasses pod-level segmentation. Option C is wrong because ClusterIP services only provide a stable internal IP for load balancing traffic to pods; they do not restrict or filter traffic between pods themselves. Option D is wrong because the default Kubernetes network configuration allows all pod-to-pod traffic with no restrictions, which is insecure and does not enforce any segmentation or access control.

408
MCQmedium

A security engineer is configuring a Linux bastion host that must expose SFTP to external partners while preventing interactive shell access for those same partner accounts. Partner keys are already deployed in each account's authorized_keys file. Which sshd_config directive combination BEST satisfies this requirement?

A.Set Subsystem sftp /usr/lib/openssh/sftp-server and PermitTunnel no in the global sshd_config.
B.Set PasswordAuthentication no and PubkeyAuthentication yes for the partner group in sshd_config.
C.Set PermitRootLogin no and AllowUsers partner1 partner2 in the global sshd_config.
D.Set ForceCommand internal-sftp and ChrootDirectory /sftp/%u for the partner group in sshd_config.
AnswerD

ForceCommand internal-sftp makes the server run the built-in SFTP subsystem for every matched session regardless of what the client requests, so no shell is ever spawned, and ChrootDirectory confines each partner to their own directory tree with the path token expanded per account. This pairing delivers file transfer without interactive shell access.

Why this answer

Forcing the internal SFTP subsystem for matched sessions guarantees the connection can only perform file transfer, because the daemon never invokes the user's login shell. Combining that with a chroot directory confines each partner to a dedicated subtree and satisfies both the access and isolation goals with a single Match block. Authentication hardening alone does not change what a successfully authenticated session is allowed to do.

Exam trap

The trap here is assuming that strong authentication directives such as disabling passwords or restricting allowed users also restrict what the authenticated session can execute.

409
MCQmedium

An organization wants to implement infrastructure as code (IaC) with immutable infrastructure. Which security benefit does immutable infrastructure provide?

A.Better performance through caching
B.Reduced attack surface due to consistent configurations
C.Simpler network segmentation
D.Easier patch management
AnswerB

Immutable infrastructure replaces rather than patches instances, so every deployment derives from one hardened image. Drift and configuration creep disappear, and no lingering services or stale packages accumulate, which is precisely the consistent-configuration reduction of attack surface the stem asks for.

Why this answer

Immutable infrastructure means servers and components are never modified after deployment — instead, changes require replacing the entire instance with a newly built, tested image. This eliminates configuration drift, ensures every instance matches a known-good baseline, and removes the accumulated patches, leftover packages, and ad-hoc changes that attackers exploit, thereby reducing the attack surface. The other options describe operational or performance benefits, not the core security advantage.

Exam trap

CAS-005 often tests whether candidates confuse immutable infrastructure's security benefit (consistent, drift-free configurations reducing attack surface) with operational benefits like easier patching or performance gains.

How to eliminate wrong answers

Option A is wrong because caching is a performance optimization unrelated to immutability; immutable infrastructure may actually reduce caching opportunities since instances are frequently replaced. Option C is wrong because network segmentation is a separate architectural control (VPCs, subnets, security groups) and is not inherently simplified by immutable infrastructure. Option D is wrong because patch management is not necessarily easier — immutability shifts patching from in-place updates to rebuilding images, which can be more complex, though it does improve consistency.

410
MCQhard

A security analyst is reviewing logs from a SIEM and notices that a user account has been successfully authenticated from two different geographic locations within a short time span, which is impossible. The SIEM uses user behavior analytics (UBA). What type of anomaly is this most likely to detect?

A.A credential theft and reuse incident
B.A misconfigured VPN that routes traffic through multiple gateways
C.A brute-force attack on the user account
D.A man-in-the-middle attack intercepting the authentication
AnswerA

Impossible travel is the classic UBA signal: the same credentials authenticating from two distant locations faster than physical travel allows. This pattern indicates the account's credentials have been compromised and reused by an attacker, directly matching the impossible-login constraint described in the stem.

Why this answer

The scenario describes a successful authentication from two geographically distant locations within a time span that makes physical travel impossible. This is a classic indicator of credential theft and reuse, where an attacker has obtained valid credentials and is using them from a different location while the legitimate user is also active. UBA detects this as an anomaly because it deviates from the normal access pattern for that user, such as typical login locations and times.

Exam trap

CAS-005 often tests the distinction between anomaly types, and candidates may confuse brute-force attacks (which involve multiple failed logins) with credential theft (successful logins from impossible locations), or they may overlook that the scenario specifies successful authentication, leading them to choose brute-force or MITM.

How to eliminate wrong answers

Option B is wrong because a misconfigured VPN might cause multiple IP addresses or locations to appear, but it would not result in two simultaneous successful authentications from different geographies; VPN misconfigurations typically cause connectivity issues or inconsistent geolocation, not impossible travel. Option C is wrong because a brute-force attack involves repeated failed authentication attempts, not successful logins from two locations; the scenario specifies successful authentication. Option D is wrong because a man-in-the-middle attack intercepts authentication traffic but does not typically result in successful logins from two different locations; it would more likely cause session hijacking or credential interception, but the anomaly of impossible travel points to credential reuse.

411
Multi-Selecthard

A security architect is designing a microsegmentation strategy for a data center that hosts both legacy virtual machines and modern containerized workloads. The architect must ensure that security policies follow the workload regardless of its location and that lateral movement is restricted even if a host is compromised. (Choose two.)

Select 2 answers
A.Implement a host-based firewall on each virtual machine that enforces allow-list rules based on workload tags
B.Use a software-defined networking (SDN) overlay that applies security groups based on workload identity rather than IP address
C.Enable port security on all physical switch ports to limit MAC addresses
D.Deploy a centralized next-generation firewall (NGFW) at the data center perimeter to inspect all north-south traffic
E.Segment the network into VLANs based on physical rack location and apply ACLs between VLANs
AnswersA, B

Host-based firewalls with tag-based rules enforce policy at the workload level, so protections move with the VM even if it is migrated. This restricts lateral movement because only explicitly allowed traffic can reach the workload, regardless of network topology or host compromise.

Why this answer

Host-based firewalls with tag-based rules and an SDN overlay using identity-based security groups both enforce policy at the workload level, ensuring that protections follow the workload regardless of location. These controls restrict lateral movement even if a host is compromised, unlike perimeter or physical segmentation approaches.

Exam trap

The trap here is equating network segmentation with microsegmentation; traditional VLANs and perimeter firewalls do not provide identity-based, workload-following policy enforcement.

412
MCQmedium

A multinational financial services firm is aligning its enterprise risk management program with the NIST Risk Management Framework (RMF). The Chief Risk Officer wants to ensure that risk response decisions are formally authorized before changes are made to production systems. Which RMF step is responsible for providing that authorization?

A.Assess security controls
B.Categorize the system
C.Monitor security controls
D.Authorize the system
AnswerD

The Authorize step is where a senior official reviews the security assessment results, the plan of action and milestones, and the continuous monitoring strategy, then formally accepts the residual risk and grants an authorization to operate. This directly satisfies the Chief Risk Officer's requirement that risk decisions be authorized before production changes are made, because the authorization decision is documented and tied to explicit risk acceptance.

Why this answer

Authorization is the RMF step where an authorizing official formally accepts residual risk and permits the system to operate. It follows categorization, control selection, implementation, and assessment, and it is the point at which risk decisions become official. Continuous monitoring then sustains that authorization over time.

Because the CRO requires formal risk acceptance before production changes, the Authorize step is the correct fit.

Exam trap

The trap here is confusing the assessment of controls with the formal acceptance of residual risk, which occurs only at the authorization decision.

413
MCQmedium

A hospital is preparing for a compliance audit and must demonstrate that it has implemented administrative safeguards required by the HIPAA Security Rule. Which activity best provides this evidence?

A.Publishing a notice of privacy practices on the hospital website
B.Installing biometric access readers at the data center entrance
C.Maintaining a current inventory of all electronic protected health information systems and the results of periodic risk analyses
D.Enabling full-disk encryption on all clinical workstations
AnswerC

The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. Documented system inventories and periodic risk analysis results are core administrative safeguards and provide direct audit evidence. This activity demonstrates that the hospital has identified where ePHI resides and has evaluated risks, which is exactly what an auditor expects to see.

Why this answer

Administrative safeguards under the HIPAA Security Rule include risk analysis, risk management, workforce security, and access management. A documented inventory of ePHI systems and periodic risk analysis results directly demonstrate that the hospital has assessed risks and identified where ePHI is stored and processed. The other choices are physical, technical, or Privacy Rule activities that do not provide the specific administrative evidence the auditor seeks.

Exam trap

The trap here is selecting any security control as evidence of administrative safeguards, when the auditor specifically requires documentation of risk analysis and governance activities.

414
Multi-Selectmedium

A SOC wants to improve detection of advanced persistent threats (APTs) that evade traditional signature-based tools. Which TWO approaches are most effective? (Select exactly 2.)

Select 2 answers
A.Reduce the false positive rate of the SIEM
B.Increase log retention period to 12 months
C.Hire additional security analysts
D.Deploy honeypots and deception technology
E.Integrate external threat intelligence feeds into the SIEM
AnswersD, E

Honeypots and deception technology present fake assets with no legitimate traffic, so any interaction is inherently suspicious. This exposes APT reconnaissance and lateral movement that signature-based tools miss, satisfying the stem's requirement to detect evasive threats.

Why this answer

Option D is correct because honeypots and deception technology create decoy assets and fake credentials that have no legitimate production purpose, so any interaction with them is high-fidelity evidence of adversary reconnaissance or lateral movement, which is exactly the kind of stealthy, low-signature behavior APTs exhibit. Option E is correct because integrating external threat intelligence feeds (e.g., STIX/TAXII indicators such as malicious IPs, domains, and file hashes) into the SIEM enriches correlation rules and enables detection of known APT infrastructure and TTPs that signature-based tools miss. Option A is not the best fit because lowering SIEM false positives improves analyst efficiency and alert quality but does not by itself add new detection capability against evasive APTs.

Option B is not the best fit because extending log retention to 12 months supports retroactive hunting and forensic timelines but does not directly improve detection of threats that evade signatures. Option C is not the best fit because hiring more analysts adds human capacity for triage and hunting but is not a technical detection approach and scales poorly against advanced threats without supporting tooling.

Exam trap

The trap is selecting options that improve general security posture (more analysts, longer retention, fewer false positives) instead of the two approaches specifically designed to detect evasive APTs: deception and threat intelligence integration.

415
MCQeasy

A company wants to protect sensitive data stored in a public cloud bucket. Which of the following is the MOST effective control to prevent accidental public exposure?

A.Enable bucket logging
B.Implement lifecycle policies
C.Use server-side encryption
D.Apply resource-based policies with explicit deny for public access
AnswerD

Resource-based policies with an explicit deny for public access override any bucket or object ACL that would otherwise grant anonymous read, directly preventing accidental exposure. This control enforces the restriction at the resource itself, satisfying the requirement to block public access reliably.

Why this answer

Resource-based policies with an explicit deny for public access are the most effective control because they override any allow statements that might inadvertently grant public access. In cloud providers like AWS, an explicit deny in a bucket policy takes precedence over all other permissions, ensuring that even if other settings (like ACLs) allow public access, the deny blocks it. This directly prevents accidental exposure by enforcing a strict boundary on who can access the bucket.

Exam trap

The trap here is that candidates often confuse encryption (Option C) with access control, mistakenly thinking encrypting data prevents unauthorized reading, but encryption only protects the data's confidentiality if the key is managed separately—it does not block public read requests to the bucket.

How to eliminate wrong answers

Option A is wrong because bucket logging records access requests but does not prevent public exposure; it only provides audit trails after the fact. Option B is wrong because lifecycle policies manage object transitions or deletions based on age, not access permissions, so they have no effect on public exposure. Option C is wrong because server-side encryption protects data at rest from unauthorized decryption but does not control who can read the bucket or its objects; a publicly accessible bucket with encryption is still publicly readable.

416
MCQhard

A security architect is designing a secure connectivity solution between an on-premises data center and a public cloud provider. The solution must provide low latency, high bandwidth, and avoid traversing the public internet. Which approach BEST meets these requirements?

A.SSL VPN
B.SD-WAN over internet
C.Direct Connect
D.Site-to-site VPN over internet
AnswerC

Direct Connect provisions a dedicated private circuit between the on-premises data centre and the cloud provider, bypassing the public internet entirely. This satisfies all three stated constraints simultaneously: low latency, high bandwidth, and no internet traversal, which VPN or internet-based alternatives cannot guarantee.

Why this answer

AWS Direct Connect (and equivalent dedicated cloud interconnects) provides a private, dedicated network connection from on-premises to the cloud provider, bypassing the public internet entirely. This delivers consistent low latency, high bandwidth (up to 100 Gbps per port with link aggregation), and predictable performance that internet-based options cannot guarantee.

Exam trap

The trap here is assuming that any encrypted tunnel (VPN) satisfies 'private connectivity' — CAS-005 often tests the distinction between encryption over the public internet versus a physically dedicated private circuit.

How to eliminate wrong answers

Option A is wrong because an SSL VPN still tunnels traffic over the public internet, so it cannot guarantee low latency or high bandwidth and is subject to internet congestion. Option B is wrong because SD-WAN over internet optimizes and prioritizes traffic but still traverses public internet paths, so it fails the 'avoid public internet' requirement. Option D is wrong because a site-to-site VPN over internet is encrypted but still rides the public internet, offering no bandwidth or latency guarantees.

417
MCQmedium

An organization is implementing a threat hunting program. The team decides to use a hypothesis-driven approach. Which of the following best describes this methodology?

A.Developing a theory about potential adversary behavior and actively looking for signs
B.Searching for known indicators of compromise from threat feeds
C.Automated scanning of all systems for vulnerabilities
D.Analyzing historical alerts for patterns
AnswerA

Hypothesis-driven hunting starts from an informed theory about attacker tactics, techniques or targets, then queries telemetry for evidence confirming or refuting it. This differs from indicator-led hunting, which searches for known IoCs rather than testing a reasoned proposition about adversary behaviour.

Why this answer

Hypothesis-driven threat hunting starts with an analyst forming a testable theory about how an adversary might operate in the environment — for example, 'attackers may be using PowerShell for lateral movement' — and then proactively searching telemetry for evidence that confirms or refutes that theory. This differs from reactive or feed-driven approaches because the hunt is guided by the analyst's hypothesis rather than by pre-existing alerts or indicators. The goal is to discover threats that have evaded automated detection, not to validate known badness.

Exam trap

CAS-005 often tests the distinction between proactive hypothesis-driven hunting and reactive indicator-based or alert-driven approaches, so candidates must recognize that 'searching for known IOCs' and 'analyzing historical alerts' are not true threat hunting even though they sound security-related.

How to eliminate wrong answers

Option B is wrong because searching for known indicators of compromise from threat feeds is indicator-based hunting, which is reactive and limited to threats already catalogued by third parties; it does not involve forming an original hypothesis about adversary behavior. Option C is wrong because automated vulnerability scanning is a preventive control that identifies misconfigurations and missing patches, not a threat hunting methodology — it does not seek evidence of active adversary activity. Option D is wrong because analyzing historical alerts for patterns is retrospective alert triage or retrospective analysis, which relies on data already flagged by detection tools rather than proactively testing a novel hypothesis about attacker tradecraft.

418
MCQhard

An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?

A.Data residency compliance
B.Cost optimization of cloud resources
C.Security controls of the cloud service provider
D.Performance SLA
AnswerC

FedRAMP authorisation directly evaluates the cloud service provider's implementation of NIST SP 800-53 security controls, satisfying the stem's compliance constraint. Assessment covers the provider's control environment, not customer-side configurations or data classification. This makes the CSP's security controls the object of FedRAMP review under Microsoft Entra ID-governed environments.

Why this answer

FedRAMP most directly assesses the security controls of the cloud service provider (CSP). The entire FedRAMP process is designed to evaluate, authorise, and continuously monitor the security posture of a CSP's offering against NIST SP 800-53 controls. While data residency, cost, and performance may be considerations, they are not the primary focus of FedRAMP assessment.

Exam trap

CAS-005 often tests the confusion between FedRAMP's focus on security controls and other cloud concerns like data residency or cost — candidates must remember that FedRAMP is fundamentally a security assessment framework for CSPs.

How to eliminate wrong answers

Option A is wrong because data residency compliance is a separate legal/regulatory concern (e.g., GDPR, data sovereignty laws) and is not the core of FedRAMP; FedRAMP focuses on security controls, not where data is stored. Option B is wrong because cost optimisation is a business concern, not a security compliance requirement; FedRAMP does not assess cost efficiency. Option D is wrong because performance SLAs are operational metrics, not security controls; FedRAMP assesses security, not performance guarantees.

419
MCQhard

A security architect is designing a system that requires hardware-enforced isolation for sensitive computations. Which technology provides the strongest isolation by running code in a protected environment within the CPU?

A.HSM
B.TPM 2.0
C.Intel SGX
D.ARM TrustZone
AnswerC

Intel SGX creates hardware-isolated enclaves within the CPU, encrypting code and data in memory so even the operating system or hypervisor cannot read them. This directly satisfies the stem's requirement for hardware-enforced isolation of sensitive computations, providing stronger protection than virtualisation or process-level sandboxing alone.

Why this answer

Intel SGX provides enclaves that isolate code and data even from the operating system, offering strong hardware isolation.

420
MCQmedium

A security architect is designing a zero trust architecture for a financial services company. Which component is MOST critical to enforce identity-centric access control in a zero trust model?

A.Network firewall
B.Intrusion prevention system
C.Software-defined perimeter
D.VPN concentrator
AnswerC

A software-defined perimeter creates identity-based, need-to-know network segments, so access to resources is granted per user and device rather than by network location. This enforces identity-centric control, satisfying zero trust's requirement that trust be continuously verified before any connection is established.

Why this answer

A software-defined perimeter (SDP) is the most critical component for enforcing identity-centric access control in zero trust because it creates a 'black cloud' where resources are invisible until users and devices are authenticated and authorized. SDP uses a controller that brokers connections based on identity, device posture, and policy, rather than network location. This directly implements the zero trust principle of 'never trust, always verify' at the access layer.

Exam trap

The trap is confusing network security appliances (firewalls, IPS, VPNs) with identity-centric access control mechanisms; candidates must recognize that zero trust requires an identity-aware proxy or SDP, not just perimeter defenses.

How to eliminate wrong answers

Option A is wrong because a network firewall enforces perimeter-based, IP/port-centric rules and does not natively perform identity-centric access control or hide resources from unauthenticated users. Option B is wrong because an intrusion prevention system (IPS) detects and blocks malicious traffic patterns but does not authenticate users or enforce identity-based access decisions. Option D is wrong because a VPN concentrator grants broad network-level access after authentication, which contradicts zero trust micro-segmentation and least-privilege principles.

421
MCQhard

An organization wants to implement a zero-trust architecture for remote access. Which component is most critical for enforcing least-privilege access to internal applications?

A.Virtual private network (VPN) concentrator
B.Software-defined perimeter (SDP)
C.Next-generation firewall (NGFW)
D.Intrusion detection system (IDS)
AnswerB

A software-defined perimeter hides internal applications behind an identity-based, need-to-know broker, granting per-session access only after device and user verification. This directly enforces least-privilege access to internal apps, unlike network-centric controls that expose services broadly.

Why this answer

A Software-Defined Perimeter (SDP) is the most critical component for enforcing least-privilege access in a zero-trust architecture because it implements a 'need-to-know' model where resources are hidden (black cloud) until the user and device are authenticated and authorized. SDP uses a controller to broker connections, dynamically creating single-packet authorization (SPA) and mutual TLS tunnels, ensuring that only authorized users can even see the internal applications. This directly supports zero-trust principles of never trust, always verify, and least-privilege access.

Exam trap

The trap here is confusing network-centric security controls (VPN, NGFW) with identity-centric zero-trust enforcement, leading candidates to pick a traditional perimeter device instead of the SDP that embodies zero-trust least-privilege access.

How to eliminate wrong answers

Option A is wrong because a VPN concentrator typically grants broad network-level access once authenticated, violating least-privilege and zero-trust principles. Option C is wrong because an NGFW operates at the network perimeter and cannot enforce per-application, per-user least-privilege access for remote users. Option D is wrong because an IDS is a passive monitoring tool that detects threats but does not enforce access control.

422
MCQmedium

A security administrator is hardening SSH access to a jump host. The requirement is to allow only key-based authentication and restrict the use of weak cryptographic algorithms. Which of the following configurations accomplishes this?

A.Set PermitRootLogin prohibit-password and PasswordAuthentication yes
B.Set PubkeyAuthentication yes, PasswordAuthentication no, and configure Ciphers and MACs to strong algorithms only
C.Set PasswordAuthentication yes and use a strong password policy
D.Set AuthenticationMethods publickey,keyboard-interactive
AnswerB

Disabling PasswordAuthentication enforces key-only access, satisfying the key-based constraint, while explicitly restricting Ciphers and MACs to strong algorithms removes weak cryptographic suites. Together these directives harden the SSH daemon against both password brute force and downgrade attacks on the jump host.

Why this answer

Option B is correct because it explicitly enables public key authentication (PubkeyAuthentication yes), disables password-based authentication (PasswordAuthentication no), and restricts cryptographic algorithms by configuring the Ciphers and MACs directives to only strong algorithms. This directly satisfies both requirements: key-only authentication and elimination of weak crypto. The other options either leave password authentication enabled or do not address weak algorithms.

Exam trap

CAS-005 often tests the misconception that enabling a strong password policy or using keyboard-interactive with publickey satisfies key-only authentication, when in fact any form of password authentication must be explicitly disabled.

How to eliminate wrong answers

Option A is wrong because it sets PasswordAuthentication yes, which allows password-based logins, violating the key-only requirement. Option C is wrong because it enables PasswordAuthentication yes and relies on a strong password policy, which still permits password authentication and does not restrict weak cryptographic algorithms. Option D is wrong because AuthenticationMethods publickey,keyboard-interactive requires both public key and keyboard-interactive (which often includes passwords), so it does not enforce key-only authentication and does not address weak algorithms.

423
MCQeasy

A security administrator is configuring a new web server and wants to ensure that it is protected against cross-site scripting (XSS) attacks. Which of the following controls should the administrator implement to BEST mitigate XSS?

A.Content Security Policy (CSP)
B.Web application firewall (WAF) in blocking mode
C.Input validation and output encoding
D.HTTPS with HSTS
AnswerC

Input validation ensures that user-supplied data conforms to expected formats, while output encoding (e.g., HTML entity encoding) ensures that any data rendered in the browser is treated as data, not executable code. Together, they prevent XSS by stopping malicious scripts from being injected and executed. This is a fundamental and effective mitigation for XSS.

Why this answer

Cross-site scripting occurs when untrusted data is included in web output without proper handling. Input validation ensures data is safe, and output encoding ensures it is rendered as text, not code. These controls directly address the vulnerability.

A WAF, HTTPS, and CSP are supplementary but do not fix the underlying issue. Thus, input validation and output encoding are the best mitigations.

Exam trap

The trap here is assuming that a WAF or CSP alone can fully prevent XSS, when they are only additional layers and not the root fix.

424
MCQmedium

An organization wants to implement a hardware root of trust for measuring system integrity at boot. Which technology should be used to store measurements in Platform Configuration Registers (PCRs) and support remote attestation?

A.HSM
B.Secure Enclave
C.TPM 2.0
D.UEFI Secure Boot
AnswerC

TPM 2.0 provides the hardware root of trust: it stores boot measurements in Platform Configuration Registers and holds the attestation key used for remote attestation. PCRs reside in shielded TPM memory, so software cannot rewrite them, satisfying the tamper-resistant integrity measurement constraint.

Why this answer

TPM 2.0 provides PCRs for measured boot and supports attestation, making it suitable for hardware root of trust.

425
Multi-Selectmedium

A security analyst is reviewing a CVSS score for a vulnerability that affects a critical server. The base score is 7.5, but the analyst needs to adjust for the environment. Which TWO of the following are valid CVSS environmental metrics that can modify the score? (Choose two.)

Select 2 answers
A.Exploit Code Maturity (ECM)
B.Privileges Required (PR)
C.Modified Attack Vector (MAV)
D.Attack Vector (AV)
E.Modified Privileges Required (MPR)
AnswersC, E

Modified Attack Vector (MAV) is a valid CVSS environmental metric that adjusts the base Attack Vector to reflect how the vulnerability is actually exploitable in the organisation's environment, directly satisfying the stem's requirement to tailor the 7.5 base score.

Why this answer

Modified Attack Vector (MAV) is a valid CVSS environmental metric because the Environmental metric group includes Modified versions of the Base exploitability metrics (MAV, MAC, MPR, MUI, MS), allowing the analyst to re-score the Attack Vector based on how the vulnerable server is actually reachable in their environment. Modified Privileges Required (MPR) is likewise a valid environmental metric, since it lets the analyst adjust the privilege level an attacker needs in their specific deployment rather than using the Base PR value. Both MAV and MPR are explicitly part of the CVSS Environmental metric group and therefore can modify the overall score.

By contrast, Exploit Code Maturity (ECM) belongs to the Temporal metric group, not the Environmental group, so it is not an environmental metric. Attack Vector (AV) and Privileges Required (PR) are Base metrics, which describe the intrinsic vulnerability and cannot themselves be used to adjust for the environment.

426
Multi-Selectmedium

A security architect is designing a zero trust network architecture and needs to implement micro-segmentation. Which TWO of the following techniques are commonly used to achieve micro-segmentation? (Select TWO).

Select 2 answers
A.Network Access Control (NAC)
B.Software-defined networking (SDN) policies
C.IPsec VPN tunnels between subnets
D.Host-based firewalls
E.VLAN segmentation
AnswersB, D

Software-defined networking policies centralise control and enforce per-workload rules through a programmable controller, segmenting traffic independently of physical topology. This satisfies micro-segmentation's requirement for granular, identity- and workload-based east-west controls, unlike VLANs or subnet ACLs, which segment only at coarser network boundaries and cannot isolate individual workloads dynamically.

Why this answer

Option B (Software-defined networking (SDN) policies) is correct because SDN centralizes control-plane policy and lets you program fine-grained, workload-level segmentation rules (e.g., via flow tables and distributed policy enforcement) rather than relying only on coarse network boundaries. Option D (Host-based firewalls) is correct because enforcing allow/deny rules directly on each workload's OS (e.g., Windows Defender Firewall, iptables/nftables, or a host agent) provides identity- and workload-centric micro-segmentation that follows the host even across network changes. Option A (NAC) is not the intended answer here because NAC primarily controls device admission and compliance at the network edge, not granular east-west workload-to-workload policy.

Option C (IPsec VPN tunnels between subnets) is not correct because it provides encrypted connectivity between subnets, not the fine-grained segmentation policy itself. Option E (VLAN segmentation) is not correct because VLANs are coarse Layer 2 broadcast-domain partitions, not the granular, often identity-based micro-segmentation required in zero trust.

Exam trap

CAS-005 often tests the confusion between traditional network segmentation (VLANs, VPNs, NAC) and true micro-segmentation (SDN policies, host-based firewalls), causing candidates to select coarse-grained network controls instead of workload-level enforcement.

427
MCQeasy

An engineer reviews the TLS configuration for a web server, which includes the following line: ssl_verify_client optional; Which of the following is a security concern present in this configuration?

A.The cipher suite does not include perfect forward secrecy (PFS).
B.The configuration supports outdated TLS 1.2 protocols.
C.The private key is stored in an accessible location.
D.The server does not require client certificates for authentication.
AnswerD

With ssl_verify_client optional, nginx requests a certificate but accepts connections lacking one, so the client certificate is never enforced as an authentication factor. Any client can complete the handshake without proving identity, satisfying the stem's concern that certificates are not required.

Why this answer

The directive ssl_verify_client optional; means the server will request a client certificate but will not require it; if the client does not present one, the connection still proceeds. This weakens mutual TLS authentication because clients are not forced to authenticate with certificates, allowing unauthenticated access.

Exam trap

CAS-005 often tests the security implication of 'optional' vs 'on' for client certificate verification — candidates may overlook that 'optional' does not enforce authentication.

How to eliminate wrong answers

Option A is wrong because the directive does not address cipher suites or PFS; that would be controlled by ssl_ciphers. Option B is wrong because the directive does not specify TLS versions; TLS 1.2 is not inherently outdated, and the line does not indicate protocol support. Option C is wrong because the directive does not concern private key storage location; that is a separate configuration/file permission issue.

428
MCQhard

An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?

A.Risk acceptance
B.Risk mitigation
C.Risk transfer
D.Risk avoidance
AnswerA

Accepting the risk means the risk owner acknowledges the legacy application's exposure and proceeds without encryption, absorbing potential loss. This matches risk acceptance rather than mitigation, transfer or avoidance, satisfying the stem's decision to tolerate the identified risk.

Why this answer

Risk acceptance is the correct answer because the risk owner has decided to acknowledge the risk and continue operating without implementing additional controls. The legacy application cannot support encryption without a major rewrite, so the organization chooses to accept the risk rather than mitigate, transfer, or avoid it. This aligns with the definition of risk acceptance as a risk treatment strategy where no action is taken to reduce the risk, and the organization retains the potential consequences.

Exam trap

The trap here is confusing risk acceptance with risk mitigation when a compensating control is mentioned, or assuming that any decision to not encrypt automatically means acceptance, while ignoring that the risk owner's formal acceptance is the key differentiator.

How to eliminate wrong answers

Option B is wrong because risk mitigation involves implementing controls to reduce the risk, such as encryption, which is not possible here without a rewrite. Option C is wrong because risk transfer shifts the risk to a third party, typically through insurance or outsourcing, which is not mentioned. Option D is wrong because risk avoidance would mean discontinuing the activity or application entirely to eliminate the risk, which is not the case here.

429
Multi-Selecthard

During a compliance audit for PCI DSS, the auditor identifies that cardholder data is stored beyond the required retention period. The organization wants to implement proper data lifecycle management. Which THREE of the following should the organization include in its data retention policy? (Select THREE.)

Select 3 answers
A.Encryption requirements for data in transit
B.Retention schedules for each data classification level
C.Process for legal hold to suspend deletion
D.Data classification scheme definitions
E.Secure disposal methods for data at end of life
AnswersB, C, E

Retention schedules per classification level directly satisfy PCI DSS's requirement to define and enforce how long cardholder data is kept. Mapping each classification to a defined retention period ensures data is disposed of once its purpose expires, preventing the indefinite storage the audit identified.

Why this answer

Option B is correct because a data retention policy must define explicit retention schedules for each data classification level, ensuring cardholder data is not stored beyond the PCI DSS-required period and is deleted when no longer needed. Option C is correct because a legal hold process is essential to suspend scheduled deletion when data is subject to litigation, regulatory investigation, or e-discovery obligations, preventing spoliation while still enforcing lifecycle management. Option E is correct because secure disposal methods (such as NIST SP 800-88 media sanitization, cryptographic erasure, or physical destruction) must be specified for data at end of life to ensure cardholder data cannot be recovered after retention expires.

Option A does not belong because encryption for data in transit is a transmission-security control, not a retention lifecycle element. Option D does not belong because the data classification scheme itself is a prerequisite input to the policy, not a retention-specific requirement being asked for here.

Exam trap

CAS-005 often tests whether candidates can distinguish retention policy content (schedules, legal hold, disposal) from adjacent policies like encryption and classification definitions, which are inputs rather than retention-policy components.

430
MCQmedium

A security team is evaluating the effectiveness of their patching program. Which metric would best indicate how quickly the organization applies critical patches?

A.Number of unpatched systems
B.Patch compliance percentage
C.Mean time to patch
D.Vulnerabilities by severity
AnswerC

Mean time to patch measures the average elapsed duration between patch release and deployment across systems, directly quantifying remediation speed. It isolates the time dimension of the patching programme, unlike coverage or count metrics, which describe breadth rather than how quickly critical patches are applied.

Why this answer

Mean time to patch measures the average time taken from the release of a patch to its application on systems. It directly indicates how quickly the organization applies critical patches, as a lower mean time to patch signifies a faster patching process. Other metrics like patch compliance percentage show the proportion of systems patched but not the speed.

Exam trap

CAS-005 often tests the confusion between metrics that measure patching coverage (like patch compliance percentage) and those that measure patching speed (like mean time to patch).

How to eliminate wrong answers

Option A is wrong because the number of unpatched systems indicates the current state but not the speed of patching. Option B is wrong because patch compliance percentage measures the extent of patching, not the time taken. Option D is wrong because vulnerabilities by severity is a risk metric, not a measure of patching speed.

431
MCQmedium

An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?

A.ZTNA
B.SD-WAN
C.Secure Web Gateway
D.CASB
AnswerC

The secure web gateway is the SASE component that inspects and filters web traffic, enforcing acceptable-use and malware policies. Converging it into SASE delivers SWG filtering from the cloud edge, satisfying the requirement to combine network and security functions in one architecture.

Why this answer

Secure Web Gateway (SWG) is itself the SASE component that provides SWG capabilities — it filters web traffic, enforces URL categorization, blocks malicious content, and applies acceptable-use policies. In SASE architectures, SWG is one of the core security pillars delivered from the cloud edge, alongside CASB, ZTNA, and FWaaS. ZTNA, SD-WAN, and CASB serve different functions and do not deliver SWG's web filtering and threat inspection.

Exam trap

CAS-005 often tests whether candidates can map each SASE capability to its correct component, so they must not confuse SWG (web filtering) with CASB (cloud app governance) or ZTNA (private app access).

How to eliminate wrong answers

Option A is wrong because ZTNA (Zero Trust Network Access) provides identity- and context-based access to private applications, replacing VPN, not web content filtering. Option B is wrong because SD-WAN is the networking pillar of SASE that optimizes WAN connectivity and routing; it does not inspect or filter web traffic. Option D is wrong because CASB governs cloud application usage and data (shadow IT, DLP), not general web browsing traffic that SWG handles.

432
MCQmedium

A financial institution is evaluating a cloud service provider for hosting customer data. During the due diligence process, which report would best help the institution assess the provider's control environment and compliance with SOC 2?

A.SOC 2 Type II report
B.ISO 27001 certificate
C.Penetration test report
D.Vulnerability scan results
AnswerA

A SOC 2 Type II report covers the design and operating effectiveness of controls over a review period, giving evidence that the provider's control environment actually functioned. Type I only assesses design at a point in time, so it cannot demonstrate sustained SOC 2 compliance during due diligence.

Why this answer

A SOC 2 Type II report is the correct choice because it provides an independent auditor's opinion on the design AND operating effectiveness of a service provider's controls over a period of time (typically 3-12 months). This directly addresses the financial institution's need to assess the provider's control environment and SOC 2 compliance. Type II is specifically designed for vendor due diligence where evidence of sustained control operation is required.

Exam trap

CAS-005 often tests the distinction between SOC 2 Type I (design at a point in time) and Type II (operating effectiveness over time), and candidates frequently pick ISO 27001 or a pentest report as equivalent evidence when the question specifically asks about SOC 2 compliance.

How to eliminate wrong answers

Option B is wrong because an ISO 27001 certificate attests to an ISMS framework and certification, not to SOC 2 Trust Services Criteria, and it does not provide the detailed control testing evidence a SOC 2 Type II report contains. Option C is wrong because a penetration test report is a point-in-time technical assessment of exploitable vulnerabilities, not an attestation of the control environment or SOC 2 compliance. Option D is wrong because vulnerability scan results are raw technical findings from automated scanners and provide no auditor opinion on control design or operating effectiveness.

433
MCQeasy

A security architect is designing a secure remote access solution for employees using personal devices (BYOD). The company requires that corporate data is separated from personal data and can be wiped remotely without affecting personal data. Which solution best meets these requirements?

A.Deploy a virtual desktop infrastructure (VDI) solution
B.Provide a full VPN client and remote wipe capability
C.Implement mobile device management (MDM) with containerization
D.Require employees to use company-owned devices only
AnswerC

MDM with containerisation creates an encrypted work container separating corporate apps and data from personal content. IT can selectively wipe only that container remotely, leaving the employee's personal data and applications untouched on the BYOD device.

Why this answer

Mobile Device Management (MDM) with containerization creates a separate, encrypted workspace on the BYOD device that isolates corporate data from personal data. The MDM policy can remotely wipe only the corporate container (selective wipe) without affecting the user's personal apps, photos, or settings, meeting both separation and remote wipe requirements.

Exam trap

The trap here is that candidates confuse full-device remote wipe (common in early MDM) with selective wipe, or assume VDI inherently provides client-side data separation, when in fact containerization is the precise mechanism for BYOD data isolation and selective wipe.

How to eliminate wrong answers

Option A is wrong because VDI streams a full desktop session to the device but does not inherently separate or wipe corporate data stored locally on the BYOD device; it relies on server-side isolation, not client-side containerization. Option B is wrong because a full VPN client only encrypts network traffic and does not enforce data separation on the device; remote wipe capability in this context typically wipes the entire device, not just corporate data. Option D is wrong because requiring company-owned devices violates the BYOD premise and does not address the requirement of allowing personal devices.

434
Multi-Selecthard

A security engineer is designing a secure enclave for processing sensitive personally identifiable information (PII). The enclave must protect data at rest and in use, and must support attestation to verify its integrity. Which THREE technologies should the engineer incorporate? (Choose three.)

Select 3 answers
A.Trusted Platform Module (TPM)
B.AMD Secure Encrypted Virtualization (SEV)
C.ARM TrustZone
D.Intel Software Guard Extensions (SGX)
E.Hardware Security Module (HSM)
AnswersB, C, D

Encrypts memory for VMs, supports attestation.

Why this answer

AMD Secure Encrypted Virtualization (SEV) (B) is correct because it encrypts each VM's memory with a per-VM AES key managed by the AMD Secure Processor, protecting data in use and supporting remote attestation of the VM's launch integrity. ARM TrustZone (C) is correct because it partitions the SoC into a secure world and normal world, isolating sensitive PII processing and enabling attestation of trusted applications within the secure enclave. Intel Software Guard Extensions (SGX) (D) is correct because it creates hardware-isolated enclaves (secure enclaves) whose memory is encrypted and inaccessible to the OS/hypervisor, and it provides remote attestation via quoting enclaves to verify enclave integrity.

TPM (A) is not the right fit because it primarily provides sealed storage, measured boot, and platform attestation for data at rest, but it does not create an execution enclave that protects data in use. HSM (E) is not the right fit because it safeguards cryptographic keys and performs crypto operations, but it does not provide a general-purpose trusted execution environment for processing PII in use.

Exam trap

CompTIA often tests the distinction between hardware roots of trust (TPM, HSM) and actual secure enclave technologies (SGX, SEV, TrustZone), so candidates mistakenly choose TPM or HSM because they associate them with 'trust' and 'security' without understanding that enclaves require isolated memory regions for processing data in use.

435
MCQmedium

An organization is reviewing its third-party risk management process. Which of the following clauses should be included in contracts with critical vendors to ensure ongoing visibility into their security posture?

A.Non-disclosure agreement (NDA)
B.Service-level agreement (SLA) for uptime
C.Right-to-audit clause
D.Data processing agreement (DPA)
AnswerC

A right-to-audit clause contractually grants the organisation the ability to inspect a critical vendor's security controls and evidence on demand, satisfying the requirement for ongoing visibility into their security posture rather than relying on one-off assurances.

Why this answer

A right-to-audit clause contractually grants the organization the ability to inspect, assess, and verify a vendor's security controls, policies, and practices — either directly or via a qualified third party. This is the mechanism that provides ongoing visibility into the vendor's security posture beyond initial due diligence. Without it, the organization has no legal standing to demand evidence of security compliance during the contract term.

Exam trap

The trap is conflating legal/privacy documents (NDA, DPA) or performance documents (SLA) with the specific contractual mechanism that grants inspection and verification rights — the right-to-audit clause.

How to eliminate wrong answers

Option A is wrong because an NDA only protects confidentiality of shared information; it does not grant any right to inspect or audit the vendor's security environment. Option B is wrong because an SLA for uptime addresses availability commitments and remedies, not security posture visibility or control verification. Option D is wrong because a DPA governs how personal data is processed and protected under privacy law (e.g., GDPR), but it does not by itself grant audit rights or ongoing security assessment access.

436
MCQmedium

A security engineer is configuring a Linux bastion host that must use only the strongest key-exchange method available in OpenSSH, avoiding any Diffie-Hellman group that relies on finite-field modular exponentiation. Which sshd_config directive setting should the engineer apply?

A.KexAlgorithms diffie-hellman-group14-sha256
B.KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
C.HostKeyAlgorithms ssh-ed25519
D.Ciphers chacha20-poly1305@openssh.com
AnswerB

Curve25519-sha256 and its libssh.org alias implement X25519, an elliptic-curve Diffie-Hellman exchange that does not use finite-field modular exponentiation and provides strong forward secrecy. Restricting KexAlgorithms to these two entries removes all classic DH group1/group14-sha1 and ECDH NIST-curve options, satisfying the requirement to avoid finite-field DH based key exchange.

Why this answer

Restricting KexAlgorithms to the X25519-based curve25519-sha256 variants forces the server and client to use elliptic-curve Diffie-Hellman, eliminating all finite-field modular-exponentiation groups. The other directives govern ciphers or host-key signatures and leave the default key-exchange list, which still permits classic DH groups, intact. Only the KexAlgorithms restriction directly enforces the stated cryptographic constraint.

Exam trap

The trap here is confusing the directives that select ciphers or host-key signatures with the one that actually controls which key-exchange groups can be negotiated.

437
Multi-Selecthard

A security analyst is performing dynamic malware analysis in a sandbox. The analyst observes that the malware sample attempts to connect to a command-and-control (C2) server but fails. The analyst wants to modify the sandbox environment to allow the malware to communicate with the C2 server to observe its behavior. Which TWO of the following changes should the analyst make? (Choose two.)

Select 2 answers
A.Configure the sandbox to use a simulated internet service (INetSim) to respond to network requests.
B.Set up a fake DNS server to resolve the C2 domain to a local listener.
C.Use a VPN to route all sandbox traffic through a different country.
D.Increase the sandbox's CPU and memory resources to prevent timeouts.
E.Disable the sandbox's firewall to allow all outbound traffic to the internet.
AnswersA, B

INetSim simulates common internet services, allowing malware to receive responses as if it were communicating with real servers. This can trick the malware into revealing its C2 behavior, such as HTTP requests or DNS queries. It is a safe way to observe network activity without allowing actual external connections, which is essential in a sandbox environment.

Why this answer

To allow the malware to communicate with its C2 server in a safe manner, the analyst should simulate network services. INetSim provides fake responses to common protocols, and a fake DNS server redirects C2 domains to a local listener. Both techniques enable observation of the malware's network behavior without risking actual external communication.

Disabling the firewall or using a VPN could expose the real C2 and is unsafe. Resource adjustments do not solve the network issue.

Exam trap

The trap here is thinking that simply allowing all outbound traffic or using a VPN will solve the problem, when in fact controlled simulation is the safe and effective approach.

438
Multi-Selecthard

An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)

Select 3 answers
A.Implicit trust based on network location
B.Least privilege access with just-in-time privileges
C.Continuous verification of identity and device health
D.Multi-factor authentication (MFA) for all users
E.Single static firewall perimeter
AnswersB, C, D

Standing admin rights violate zero trust's assume-breach stance. Just-in-time privilege elevation grants access only when needed, then revokes it, shrinking the blast radius of compromised accounts. This directly satisfies the identity-centric requirement that entitlements are scoped and time-bound rather than permanent.

Why this answer

Option B is correct because identity-centric zero trust enforces least privilege access, granting users only the minimum permissions needed and elevating privileges just-in-time rather than permanently, which limits the blast radius of compromised accounts. Option C is correct because zero trust requires continuous verification of identity and device health on every access request, rather than trusting a session once authenticated, using signals such as device compliance and risk scores. Option D is correct because MFA for all users strengthens identity assurance by requiring multiple factors, directly supporting the identity-centric principle that no user is trusted by default.

Option A is incorrect because implicit trust based on network location is the opposite of zero trust, which assumes no implicit trust regardless of where the request originates. Option E is incorrect because a single static firewall perimeter reflects the traditional castle-and-moat model, whereas zero trust replaces perimeter-based trust with identity- and policy-based controls.

Exam trap

CAS-005 often tests the confusion between zero trust and traditional perimeter security — candidates pick 'implicit trust based on network location' or 'static firewall perimeter' because those are familiar concepts, missing that zero trust explicitly rejects both.

439
MCQhard

A company is deploying a just-in-time (JIT) privileged access management solution. Which of the following BEST describes a key security benefit of JIT access?

A.It eliminates the need for multi-factor authentication
B.It replaces the need for a break-glass account
C.It reduces the risk of lateral movement by limiting the duration of elevated privileges
D.It provides continuous monitoring of all user actions
AnswerC

Just-in-time access issues credentials only for a bounded period, so stolen or misused sessions expire quickly. This shrinks the window attackers have to pivot between systems, directly delivering the reduced lateral-movement risk the stem asks for.

Why this answer

JIT access grants temporary privileges only when needed, reducing the attack surface and the risk of standing privileges being misused.

440
Multi-Selectmedium

A company's incident response team is developing a playbook for ransomware incidents. The playbook should cover the preparation phase. Which THREE of the following are appropriate preparation activities? (Choose THREE.)

Select 3 answers
A.Train employees on how to recognize and report phishing attempts
B.Conduct regular backup testing and ensure offline backups are available
C.Isolate infected systems from the network immediately after detection
D.Develop communication procedures, including legal and PR contacts
E.Perform threat hunting in the network to identify potential threats
AnswersA, B, D

Phishing remains the primary initial access vector for ransomware, so training employees to recognise and report suspicious messages directly reduces the likelihood of successful compromise. This satisfies the preparation phase's requirement to build preventive human controls before an incident occurs, complementing technical safeguards such as email filtering and endpoint detection.

Why this answer

Option A is correct because user awareness training on recognizing and reporting phishing is a foundational preparation activity, since phishing is a leading initial access vector for ransomware and trained employees enable earlier detection and response. Option B is correct because regular backup testing and maintaining offline, immutable backups are essential preparation steps that ensure data can be restored without paying a ransom and that backups are not encrypted or deleted by the malware. Option D is correct because establishing communication procedures with legal, PR, and other stakeholders before an incident occurs is a preparation-phase task that supports coordinated, compliant crisis communication during an actual ransomware event.

Option C is not a preparation activity but a containment action performed during the detection/response phase after an infection is identified. Option E is not a preparation activity in this context; threat hunting is an ongoing detection operation conducted during normal security monitoring rather than a preparatory step in a ransomware playbook.

Exam trap

CAS-005 often tests the distinction between preparation and other incident response phases, and candidates may incorrectly classify containment or detection activities as preparation.

441
MCQhard

A multinational retailer operates an on-premises data center and two public cloud regions. Regulations require that customer payment data never leave the home country, but the company wants centralized security analytics. The architect needs a design that keeps raw payment records local while enabling global threat detection. Which design best meets these constraints?

A.Keep raw payment records in the home country and forward only normalized security telemetry to a central SIEM.
B.Replicate the full payment database to a central cloud data lake for analytics.
C.Deploy independent SIEM instances per region with no cross-region data sharing.
D.Encrypt payment records with a customer-managed key and store them in the nearest cloud region.
AnswerA

Keeping raw payment records local satisfies data residency, while forwarding normalized telemetry such as authentication events, network flows, and alerts gives the central SIEM the visibility needed for global threat detection. The telemetry is stripped of payment data, so no regulated records cross borders, and correlation across regions remains possible for detecting coordinated attacks.

Why this answer

Local retention of raw payment records meets the residency regulation, while exporting only normalized security telemetry to a central SIEM preserves the global correlation needed for threat detection. This separates regulated data from operational telemetry. Full replication, per-region silos, and encrypted offsite storage each either move regulated records across borders or prevent the centralized analytics the company requires.

Exam trap

The trap here is believing that encryption or tokenization automatically resolves data residency, when regulations govern where the records are stored and processed regardless of their encryption state.

442
Multi-Selecteasy

A healthcare organization is implementing HIPAA Security Rule safeguards. Which TWO of the following are required administrative safeguards? (Choose TWO.)

Select 2 answers
A.Security management process.
B.Encryption of ePHI at rest.
C.Unique user identification.
D.Assigned security responsibility.
E.Facility access controls.
AnswersA, D

The HIPAA Security Rule names the security management process as a required administrative safeguard. It obliges covered entities to conduct risk analysis, risk management, sanction policy and information system activity review, forming the governance foundation the rule mandates.

Why this answer

Option A, Security management process, is correct because 45 CFR 164.308(a)(1) requires it as an administrative safeguard: covered entities must conduct a risk analysis, implement risk management, have a sanction policy, and review information system activity. Option D, Assigned security responsibility, is correct because 45 CFR 164.308(a)(2) requires the covered entity to designate a security official responsible for developing and implementing the security policies and procedures. Option B, Encryption of ePHI at rest, is not a required administrative safeguard; under 45 CFR 164.312(a)(2)(iv) and 164.312(e)(2)(ii) encryption is an addressable implementation specification under Technical Safeguards.

Option C, Unique user identification, is a Technical Safeguard under 45 CFR 164.312(a)(2)(i), not an administrative safeguard. Option E, Facility access controls, is a Physical Safeguard under 45 CFR 164.310(a)(1), not an administrative safeguard.

Exam trap

On the CASP+ exam, the trap is correctly distinguishing between administrative, physical, and technical safeguards under HIPAA. Candidates often mistake technical controls like encryption (ePHI at rest) or unique user identification for administrative safeguards, or think facility access controls are administrative instead of physical. The required administrative safeguards listed are security management process and assigned security responsibility.

443
MCQmedium

A security architect is designing a microservices application that uses JWTs for authentication. Which of the following is the most critical security concern regarding JWT handling?

A.Token expiration not being enforced
B.The JWT being transmitted over HTTP instead of HTTPS
C.The server not validating the JWT's 'alg' header properly
D.The JWT containing personally identifiable information (PII)
AnswerC

Failing to validate the 'alg' header lets attackers forge tokens by switching to 'none' or downgrading RS256 to HS256, signing with the public key as an HMAC secret. This directly satisfies the stem's authentication-integrity constraint, since unverified algorithm choice undermines every downstream authorisation decision in the microservices chain.

Why this answer

A failure to validate the JWT's 'alg' header can allow an attacker to change the algorithm to 'none' or from an asymmetric algorithm (e.g., RS256) to a symmetric one (e.g., HS256), potentially bypassing signature verification. This vulnerability, known as a JWT algorithm confusion attack, is a critical security concern because it directly undermines the integrity and authenticity of the token, which is the core security mechanism for authentication in microservices.

Exam trap

The trap here is that candidates often focus on obvious issues like HTTP vs. HTTPS or token expiration, but CompTIA tests the deeper understanding that a JWT's security hinges on proper validation of the 'alg' header, as a single misconfiguration can completely bypass all other security controls.

Why the other options are wrong

A

Though important, expiration can be mitigated with refresh tokens; algorithm confusion is more fundamental.

B

Transmission security is important but is a network-layer concern, not JWT-specific.

D

PII in JWT is a data privacy concern, but not the most critical security vulnerability.

444
MCQmedium

An IoT device manufacturer wants to ensure secure firmware updates. Which approach best protects against malicious firmware being installed on devices?

A.Digitally sign the firmware with a private key
B.Compress the firmware to reduce size
C.Use a hash of the firmware for integrity verification
D.Encrypt the firmware with a symmetric key
AnswerA

Digitally signing firmware with a private key lets devices verify the signature using the corresponding public key before installation, so any tampered or forged image fails validation. This cryptographically ensures only vendor-authorised firmware is accepted.

Why this answer

Code signing with a trusted key ensures only authorized firmware can be installed.

445
MCQhard

An organization uses a SIEM to collect logs from multiple sources. The security team wants to identify users who are accessing resources outside of normal business hours and exhibiting unusual data transfer patterns. Which advanced SIEM capability would be most effective?

A.Threat intelligence feed integration
B.User and Entity Behavior Analytics (UEBA)
C.Log normalization and aggregation
D.Correlation rules with threshold-based alerts
AnswerB

UEBA baselines each user's and entity's normal activity, then flags statistical deviations such as logons outside business hours and anomalous data volumes. Unlike static correlation rules, it detects subtle, gradual changes in behaviour, directly satisfying the requirement to identify off-hours access and unusual transfer patterns.

Why this answer

UEBA (User and Entity Behavior Analytics) is designed to baseline normal behavior for users and entities, then detect statistical deviations such as off-hours access and anomalous data transfer volumes. Unlike static rules, UEBA uses machine learning to model each user's typical login times, peer group activity, and data movement patterns, flagging outliers that would otherwise go unnoticed. This makes it the most effective capability for identifying subtle insider-threat or compromised-account behavior described in the scenario.

Exam trap

CAS-005 often tests the distinction between static, rule-based detection (correlation rules, thresholds) and adaptive, behavior-based analytics (UEBA), so candidates must recognize that 'unusual patterns' and 'outside normal business hours' signal a need for baselining rather than predefined thresholds.

How to eliminate wrong answers

Option A is wrong because threat intelligence feeds provide known indicators of compromise (IPs, domains, hashes) and do not baseline individual user behavior or detect off-hours access patterns. Option C is wrong because log normalization and aggregation only parse and store logs in a common format; they enable analysis but do not themselves identify behavioral anomalies. Option D is wrong because threshold-based correlation rules are static and require predefined limits, so they cannot adapt to each user's normal schedule or detect subtle deviations like unusual data transfer patterns without generating excessive false positives.

446
MCQeasy

Which of the following is a primary advantage of using ChaCha20-Poly1305 over AES-256-GCM in certain environments?

A.Better hardware acceleration support
B.Higher security margin
C.Smaller ciphertext size
D.Faster performance on devices without AES-NI
AnswerD

ChaCha20-Poly1305 relies solely on ARX operations, which execute efficiently in software on CPUs lacking AES-NI hardware acceleration. AES-256-GCM depends on dedicated AES instructions for competitive throughput, so on such constrained devices ChaCha20-Poly1305 delivers markedly faster encryption, directly satisfying the stem's "certain environments" constraint.

Why this answer

ChaCha20-Poly1305 is designed to be faster in software that lacks AES hardware acceleration, making it suitable for mobile devices.

447
Multi-Selectmedium

A security operations center (SOC) is implementing User Behavior Analytics (UBA) to detect insider threats. Which TWO of the following data sources are most critical for establishing a baseline of normal user behavior?

Select 2 answers
A.Authentication logs from Active Directory
B.Threat intelligence feeds
C.Network traffic logs from firewalls and proxies
D.HR records of employee performance reviews
E.Email content and subject lines
AnswersA, C

Authentication logs from Microsoft Entra ID or Active Directory record who logged on, when, from where and whether attempts failed. These identity events form the core behavioural baseline UBA needs to flag anomalous insider sign-in patterns, such as impossible travel or off-hours access, satisfying the stem's requirement for normal user behaviour data.

Why this answer

Authentication logs from Active Directory (A) are critical because they capture logon events, logon types, source workstations, and failure patterns (e.g., Event IDs 4624/4625), which directly define each user's normal access times, locations, and habits for UBA baselining. Network traffic logs from firewalls and proxies (C) are equally critical because they reveal each user's typical destinations, protocols, ports, data volumes, and timing, enabling detection of deviations such as large uploads or access to unusual external services. Together, identity/authentication data and network activity data form the core behavioral baseline for insider-threat detection.

Threat intelligence feeds (B) describe external adversaries and indicators of compromise, not a given user's normal behavior, so they support threat matching rather than baselining. HR performance reviews (D) are subjective personnel records unrelated to technical behavior patterns. Email content and subject lines (E) are content-level data that raise privacy and legal concerns and are not required to establish behavioral baselines, which rely on metadata and activity patterns.

Exam trap

The trap is selecting data sources that seem security-related but are not behavioral, such as threat intelligence feeds or email content. Candidates might also overlook network traffic logs as a key source for behavioral baselining.

448
Multi-Selecthard

Which THREE of the following are required components of a Business Continuity Plan (BCP) per ISO 22301?

Select 3 answers
A.Detailed technical recovery procedures for IT systems
B.Scope and policy for business continuity
C.Vulnerability scanner configuration
D.Communication and notification plan
E.Business Impact Analysis (BIA)
AnswersB, D, E

ISO 22301 requires documented scope and policy as the foundation of the BCMS, defining which parts of the organisation, locations and services the plan covers and the top-management commitment governing it. This satisfies the stem's requirement for a mandatory BCP component under the standard.

Why this answer

Option B is correct because ISO 22301 requires the BCMS to define its scope and establish a business continuity policy that sets the organization's objectives, commitments, and top-management direction for continuity. Option E is correct because the Business Impact Analysis (BIA) is a mandatory core element of ISO 22301; it identifies critical business functions, dependencies, and the maximum tolerable period of disruption (MTPD) that drive recovery priorities and objectives. Option D is correct because ISO 22301 requires documented communication and notification arrangements, including internal and external stakeholder warning, escalation, and crisis communication procedures during and after a disruption.

Option A is not a required BCP component per ISO 22301 because detailed technical IT recovery procedures belong to IT disaster recovery planning (e.g., ISO/IEC 27031), which supports but is distinct from the business continuity management system. Option C is not required because vulnerability scanner configuration is a technical security control from vulnerability management, not a BCP element under ISO 22301.

Exam trap

CompTIA often tests the distinction between a BCP (organizational continuity) and a DRP (technical recovery), leading candidates to mistakenly select detailed IT recovery procedures as a BCP component.

449
MCQmedium

A security architect is designing a hybrid cloud environment. The organization requires low-latency, private connectivity between on-premises and a public cloud provider, bypassing the public internet. Which solution best meets this requirement?

A.Site-to-site VPN over the internet
B.Private link (e.g., AWS PrivateLink)
C.Direct Connect / ExpressRoute
D.SD-WAN with internet breakout
AnswerC

Direct Connect and ExpressRoute provide dedicated private circuits from on-premises into the cloud provider's network, so traffic never traverses the public internet. This satisfies the low-latency, private connectivity constraint, unlike site-to-site VPNs, which still ride the internet.

Why this answer

Direct Connect (AWS) and ExpressRoute (Azure) provide dedicated private circuits from on-premises to the cloud provider, bypassing the public internet entirely. This delivers predictable low latency, higher bandwidth, and stronger security than internet-based options. It directly satisfies the 'private connectivity, bypassing the public internet' requirement.

Exam trap

CAS-005 often tests the distinction between 'private connectivity to cloud services' (PrivateLink) and 'dedicated private circuit to on-premises' (Direct Connect/ExpressRoute) — candidates conflate the two because both use the word 'private.'

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN traverses the public internet, introducing variable latency and exposure that the question explicitly wants to avoid. Option B is wrong because AWS PrivateLink provides private connectivity to services within or across VPCs/accounts, not a dedicated on-premises-to-cloud circuit. Option D is wrong because SD-WAN with internet breakout still uses public internet paths, failing the bypass requirement.

450
MCQmedium

A security architect is designing a hybrid environment in which on-premises applications must consume APIs hosted in a public cloud. The architect wants to ensure that if the primary cloud region fails, API consumers continue to receive responses without changing client configuration. Which design element BEST satisfies this requirement?

A.Deploy a global server load balancing tier that performs health-checked DNS failover across regional API endpoints.
B.Configure a forward proxy on the on-premises network that caches API responses for the duration of the outage.
C.Place the API behind a reverse proxy that terminates TLS and inspects request payloads for malicious content.
D.Implement API versioning so consumers can switch to an alternate endpoint when the primary region becomes unavailable.
AnswerA

Health-checked global server load balancing continuously probes each regional API endpoint and withdraws a failed region from DNS answers, so existing clients resolve to a healthy region on their next lookup without any client-side change. This directly addresses regional failover for API consumers while preserving a single stable hostname.

Why this answer

Continuity across regions for API consumers is achieved by abstracting endpoints behind a health-aware global load balancing layer that removes failed regions from resolution and returns healthy ones. Caching, versioning, and single-region reverse proxies all leave the consumer dependent on the failed region or require client changes, so they do not meet the requirement.

Exam trap

The trap here is assuming that caching or API versioning provides availability, when neither redirects traffic to a surviving region.

Page 5

Page 6 of 13

Page 7