Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 451–525

973 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQmedium

A security analyst is calculating the annualized loss expectancy (ALE) for a server that processes credit card data. The server has a $100,000 asset value, and the exposure factor for a security breach is 0.4. Historical data shows that such breaches occur twice per year. What is the ALE?

A.$100,000
B.$40,000
C.$80,000
D.$200,000
AnswerC

SLE equals asset value multiplied by exposure factor: $100,000 × 0.4 = $40,000. ALE equals SLE multiplied by annualised rate of occurrence: $40,000 × 2 = $80,000. This matches the calculated annualised loss expectancy for the credit card server.

Why this answer

ALE is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). SLE = Asset Value × Exposure Factor = $100,000 × 0.4 = $40,000. ARO = 2 occurrences per year.

Therefore ALE = $40,000 × 2 = $80,000.

Exam trap

CAS-005 often tests whether candidates confuse SLE with ALE or forget to multiply by ARO; the trap is stopping at $40,000 or using the full asset value.

How to eliminate wrong answers

Option A is wrong because $100,000 is the asset value, not the ALE; it ignores both the exposure factor and the frequency. Option B is wrong because $40,000 is the SLE (the loss per single incident), not the annualized figure. Option D is wrong because $200,000 would result from multiplying the full asset value by 2 without applying the 0.4 exposure factor, which overstates the loss.

452
MCQeasy

A security administrator is reviewing an architecture diagram for a new web application. The diagram shows the application servers in a private subnet, a database in a separate private subnet, and a public load balancer in a public subnet. The administrator wants to ensure that the application servers can retrieve software updates from the internet without being directly reachable from it. Which of the following should the administrator recommend?

A.Configure the application servers to use a proxy server hosted in the database subnet for all outbound update requests.
B.Place a NAT gateway in a public subnet and route the application subnet's outbound traffic through it.
C.Assign public IP addresses to the application servers and use a security group that permits only outbound port 443.
D.Attach an internet gateway directly to the application server subnet and allow outbound traffic on port 443.
AnswerB

A NAT gateway in a public subnet allows instances in a private subnet to initiate outbound connections to the internet while preventing unsolicited inbound connections. This is exactly the pattern needed for software updates. The application servers remain unreachable from the internet, and the NAT gateway handles address translation and return traffic, preserving the private subnet's isolation while still permitting necessary outbound access.

Why this answer

A NAT gateway located in a public subnet lets private application servers initiate outbound connections for updates while blocking unsolicited inbound connections from the internet. This preserves the private subnet's isolation and keeps the application tier unreachable externally. Direct internet gateway attachment, public IP assignment, and placing egress components in the database tier all either expose the servers or violate the intended tier separation.

Exam trap

The trap here is confusing outbound internet access with public reachability, when a NAT gateway provides the former without granting the latter.

453
MCQhard

A security analyst is investigating a potential breach and needs to determine the timeline of events on a compromised Windows workstation. The analyst has access to the disk image and memory dump. Which artifact should the analyst examine FIRST to establish a timeline of file system activity?

A.Registry hives
B.$MFT (Master File Table)
C.Prefetch files
D.Windows Event Logs
AnswerB

$MFT contains metadata for every file on an NTFS volume, including timestamps for creation, modification, and access. It is a primary source for file system timeline analysis. Other artifacts like prefetch or registry hives provide program execution or configuration data but are not as comprehensive for file system activity timelines.

Why this answer

The $MFT is the central repository for file metadata on NTFS, including timestamps for file creation, modification, and access. It provides a comprehensive record of file system activity, making it the primary artifact for timeline analysis. Other artifacts like Prefetch or Event Logs are useful for specific activities but do not cover the full scope of file system changes.

Exam trap

The trap here is assuming that Prefetch files provide a complete file system timeline, when they only record program execution and limited file references.

454
MCQmedium

An organization requires a cryptographic algorithm that provides both encryption and authentication in a single pass. Which algorithm should be selected?

A.AES-256-GCM
B.AES-256-CBC
C.SHA-256
D.RSA 4096
AnswerA

AES-256-GCM combines AES counter-mode encryption with GHASH authentication, producing ciphertext and a tag in one operation. This satisfies the stem's single-pass requirement, unlike separate encrypt-then-MAC schemes. It also delivers the confidentiality and integrity the organization demands, using a 256-bit key for strong protection.

Why this answer

AES-256-GCM (Galois/Counter Mode) is an authenticated encryption with associated data (AEAD) algorithm that provides both confidentiality (encryption) and integrity/authentication in a single pass. It combines AES counter mode encryption with GHASH for authentication, making it efficient and secure. This meets the requirement for a single algorithm that does both.

Exam trap

The trap is thinking CBC with a separate HMAC counts as 'single pass' or that RSA can do both; the exam expects you to recognize AEAD modes like GCM as the only single-pass encryption+authentication algorithms.

How to eliminate wrong answers

Option B is wrong because AES-256-CBC provides only encryption and requires a separate MAC (e.g., HMAC) for authentication, so it does not provide both in a single pass. Option C is wrong because SHA-256 is a hash function used for integrity, not encryption; it provides no confidentiality. Option D is wrong because RSA 4096 is an asymmetric encryption algorithm that provides encryption or digital signatures, but not both in a single pass, and it is not an AEAD cipher.

455
MCQmedium

A security architect is designing a microservices platform that runs on a shared Kubernetes cluster. Each service must be able to prove its identity to other services, and the design must avoid long-lived shared secrets and support automatic credential rotation when a pod is rescheduled. Which approach BEST meets these requirements?

A.Enable Kubernetes service account token projection with a 24-hour expiration and use the token as a bearer credential for inter-service calls.
B.Store a unique API key for each service in a Kubernetes Secret and require services to present the key in an HTTP header.
C.Issue each service a signed SPIFFE SVID through a SPIRE agent running as a DaemonSet, and use mTLS between services.
D.Configure Kubernetes NetworkPolicies to allow traffic only between approved service namespaces.
AnswerC

SPIFFE/SPIRE issues short-lived, cryptographically verifiable identities (SVIDs) to workloads based on attested node and pod attributes, and automatically rotates them. mTLS using these SVIDs lets each service authenticate peers without embedded static secrets, satisfying the rotation requirement when pods move.

Why this answer

Workload identity frameworks such as SPIFFE/SPIRE bind a cryptographic identity to the actual workload through node and pod attestation, then issue short-lived certificates that rotate automatically. Using mTLS with those identities gives mutual authentication and encryption without shared static secrets, which is exactly what the microservices platform needs.

Exam trap

The trap here is assuming that Kubernetes Secrets or NetworkPolicies provide workload identity, when they only store data or filter traffic and cannot cryptographically prove which service is calling.

456
MCQmedium

A security operations center (SOC) receives a high-severity alert indicating that a domain administrator account was used to authenticate to a workstation at 03:00. The account is normally used only for interactive logons to domain controllers during business hours. The SOC analyst wants to quickly determine whether this is a malicious activity or a false positive. Which of the following is the MOST appropriate next step?

A.Run a vulnerability scan against the workstation to check for missing patches that could have allowed credential theft.
B.Immediately disable the domain administrator account to prevent further unauthorized access.
C.Check the domain controller's security log for Event ID 4768 to see if a Kerberos ticket was issued for the account.
D.Review the Windows Security event log on the workstation for Event ID 4624 and examine the Logon Type and Source Network Address fields.
AnswerD

Event ID 4624 records successful logons and includes the Logon Type and Source Network Address. A Type 3 (network) or Type 10 (RemoteInteractive) logon from an unusual source would confirm suspicious remote access, while a Type 2 (interactive) logon at the console would suggest a different scenario. This directly addresses the anomaly and is the fastest way to validate or dismiss the alert.

Why this answer

The most direct way to investigate an anomalous logon is to examine the successful logon event on the target system. Event ID 4624 includes critical details such as logon type and source address, which can quickly differentiate between a legitimate interactive logon and a suspicious remote or network logon. This evidence-based approach avoids premature containment actions and focuses the investigation on the actual behavior observed.

Exam trap

The trap here is assuming that any out-of-hours domain admin logon is automatically malicious and jumping to disable the account, rather than first verifying the logon type and source to understand the context.

457
MCQeasy

A security administrator is configuring a new wireless network for a small office. The administrator wants to ensure that only authorized devices can connect and that traffic is encrypted. Which of the following should the administrator implement?

A.WPA3-Personal with SAE
B.Open network with a captive portal
C.WPA2-Enterprise with RADIUS
D.WEP with MAC address filtering
AnswerA

WPA3-Personal with Simultaneous Authentication of Equals (SAE) provides strong encryption and resistance to offline dictionary attacks. SAE replaces the pre-shared key handshake in WPA2, offering forward secrecy and protecting against brute-force attempts. This meets the requirements for authorized device access and encrypted traffic, making it the most secure choice for a small office wireless network.

Why this answer

WPA3-Personal with SAE offers robust encryption and authentication without the need for additional infrastructure like a RADIUS server. It is designed for small to medium-sized networks where individual user credentials are not required. SAE prevents offline dictionary attacks, ensuring that only devices with the correct password can connect, and all traffic is encrypted.

Exam trap

The trap here is assuming that WPA2-Enterprise is always better, but for a small office without RADIUS infrastructure, WPA3-Personal with SAE provides superior security with simpler deployment.

458
MCQhard

A security architect at a financial institution is designing a cloud-native application using AWS. The application processes sensitive customer data and must comply with PCI DSS. Which of the following security architecture decisions best supports both compliance and operational efficiency?

A.Place all application resources in a VPC with no internet gateway and use VPC endpoints for AWS services
B.Use a cloud-based web application firewall (WAF) and enable logging for all API calls
C.Deploy the application on a single tenant dedicated instance and rely on the cloud provider's compliance certifications
D.Implement a cloud access security broker (CASB) and use customer-managed encryption keys (CMKs) for data at rest
AnswerD

CASB provides visibility and policy enforcement; CMKs meet PCI DSS encryption requirements.

Why this answer

A CASB provides visibility and control over data in cloud environments, which is critical for PCI DSS compliance, while customer-managed encryption keys (CMKs) give the institution direct control over encryption of data at rest, meeting both compliance requirements and operational flexibility. This combination allows the financial institution to enforce data protection policies and audit access without sacrificing the agility of cloud-native deployment.

Exam trap

The CAS-004 exam often tests the misconception that network isolation (Option A) or a single security tool (Option B) is sufficient for compliance, when in reality PCI DSS requires a layered approach including encryption key management and data access governance, which a CASB and CMKs directly address.

How to eliminate wrong answers

Option A is wrong because placing all resources in a VPC with no internet gateway and using VPC endpoints does not address PCI DSS requirements for encryption key management, access control, or logging; it only restricts network access, which is insufficient for full compliance. Option B is wrong because a WAF and API logging are important for security monitoring but do not cover PCI DSS mandates for encryption of data at rest, key management, or data access controls; they are supplementary, not foundational. Option C is wrong because relying solely on a single tenant dedicated instance and the cloud provider's compliance certifications does not meet PCI DSS requirements for the customer to implement and manage their own encryption keys, access controls, and audit logging; shared responsibility means the customer must still enforce specific controls.

459
Multi-Selecthard

A security engineer is implementing a hardware security module (HSM) to protect cryptographic keys used by a certificate authority (CA). The engineer must ensure that the HSM provides strong protections against key extraction and unauthorized use. Which of the following are security properties that the HSM should provide? (Choose two.)

Select 2 answers
A.Tamper-responsive mechanisms that zeroize keys upon physical intrusion.
B.FIPS 140-2 Level 1 validation for the cryptographic module.
C.Support for exporting private keys in plaintext for backup purposes.
D.Role-based access control with separation of duties for key management operations.
E.The ability to run arbitrary code within the HSM to extend functionality.
AnswersA, D

Tamper-responsive mechanisms detect physical intrusion attempts (e.g., drilling, voltage tampering) and automatically erase sensitive key material. This prevents attackers from extracting keys even if they gain physical access to the HSM. It is a critical security property for HSMs used in CAs, as it ensures that keys cannot be recovered from a compromised device.

Why this answer

Tamper-responsive mechanisms and role-based access control with separation of duties are essential security properties for an HSM protecting CA keys. Tamper responsiveness prevents physical key extraction, while RBAC with separation of duties prevents unauthorized logical access. The other options either provide insufficient protection or weaken security.

Exam trap

The trap here is assuming that any FIPS validation or key export capability is sufficient for an HSM, when higher-level physical protections and strict access controls are required for CA key security.

460
MCQmedium

Which CVSS metric component is used to reflect the impact of a vulnerability based on the specific environment of an organization?

A.Attack vector metric
B.Temporal metric
C.Environmental metric
D.Base metric
AnswerC

The environmental metric group modifies the base score using factors unique to the organisation's deployment, such as modified attack vector, confidentiality, integrity and availability requirements. It therefore reflects impact within a specific environment, exactly the constraint the question specifies.

Why this answer

The Environmental metric in CVSS adjusts the Base score to reflect the specific environment of an organization, including factors like modified attack vector, confidentiality, integrity, and availability requirements. It is the component explicitly designed to capture organization-specific impact.

Exam trap

CAS-005 often tests the confusion between Temporal metrics (time-based changes) and Environmental metrics (organization-specific context), causing candidates to pick Temporal when the question mentions the organization's environment.

How to eliminate wrong answers

Option A is wrong because Attack Vector is a Base metric that describes how the vulnerability is exploited (network, adjacent, local, physical) and is not environment-specific. Option B is wrong because Temporal metrics reflect characteristics that change over time, such as exploit code maturity, remediation level, and report confidence — not the organization's environment. Option D is wrong because Base metrics represent the intrinsic characteristics of the vulnerability that are constant across environments.

461
MCQmedium

A security analyst is investigating a potential security incident and needs to determine the order of events. The analyst has collected logs from various sources, including Windows Event Logs, firewall logs, and IDS alerts. Which of the following should the analyst do FIRST to establish a timeline?

A.Create a visual representation of the incident using a timeline tool
B.Correlate the IDS alerts with firewall logs to identify the attacker's IP address
C.Review Windows Event Logs for failed login attempts
D.Normalize the timestamps from all log sources to a common time zone and format
AnswerD

Logs from different sources may use different time zones, formats, or clock settings. Normalizing timestamps to a common standard (e.g., UTC) is essential to accurately correlate events and establish a timeline. Without this step, the analyst might misinterpret the sequence of events. This is a fundamental step in incident response and forensic analysis to ensure data integrity and consistency across disparate sources.

Why this answer

To establish an accurate timeline, the analyst must first normalize timestamps from all log sources to a common time zone and format. This ensures that events can be correctly ordered and correlated. Without this step, any subsequent analysis or correlation could be flawed due to time discrepancies.

The other actions are important but should be performed after timestamp normalization.

Exam trap

The trap here is jumping directly into log analysis or correlation without first ensuring that timestamps are consistent, which can lead to an incorrect sequence of events.

462
MCQeasy

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer when using an Infrastructure as a Service (IaaS) model?

A.Configuration of the hypervisor
B.Network infrastructure maintenance
C.Physical security of data centers
D.Encryption of data at rest within the environment
AnswerD

Under IaaS, the customer controls everything above the hypervisor, including guest operating systems, applications and data. Encrypting data at rest within that environment therefore falls to the customer, whereas the provider secures the physical hosts, network fabric and underlying storage infrastructure.

Why this answer

In an IaaS model, the cloud provider manages the physical infrastructure, network, and hypervisor, while the customer is responsible for everything from the guest OS upward, including data encryption at rest. Encrypting data at rest within the environment is a customer responsibility because the customer controls the data and the encryption keys. The provider secures the underlying storage but does not automatically encrypt customer data unless the customer configures it.

Exam trap

The trap is assuming the cloud provider encrypts all data by default; candidates often forget that in IaaS, data encryption at rest is a customer responsibility, not the provider's.

How to eliminate wrong answers

Option A is wrong because hypervisor configuration is part of the virtualization layer managed by the cloud provider in IaaS, not the customer. Option B is wrong because network infrastructure maintenance (physical routers, switches, cabling) is the provider's responsibility. Option C is wrong because physical security of data centers is always the provider's responsibility in any cloud model.

463
MCQeasy

A security analyst is investigating an API that uses JSON Web Tokens (JWT) for authentication. Which field in a JWT contains the token expiration time?

A.exp
B.iss
C.iat
D.sub
AnswerA

The exp claim is a registered JWT payload field holding the expiration time as a NumericDate, after which the token must be rejected. Validating exp lets the analyst determine whether the token has lapsed, directly answering which field carries the expiration time.

Why this answer

The 'exp' (expiration time) claim in a JWT is a NumericDate value representing the UTC time after which the token MUST NOT be accepted, as defined in RFC 7519. Validating 'exp' is the standard mechanism for enforcing token lifetime and limiting the window of abuse if a token is stolen.

Exam trap

The trap is confusing the temporal claims — candidates mix up 'iat' (issued at) with 'exp' (expires), or assume 'nbf' means expiration when it actually means 'not before'.

How to eliminate wrong answers

Option B is wrong because 'iss' (issuer) identifies the principal that issued the JWT and is used for trust validation, not expiration. Option C is wrong because 'iat' (issued at) records when the token was created and is used for age checks or as a nonce, but it does not define when the token expires. Option D is wrong because 'sub' (subject) identifies the principal the token is about (typically the user ID), which is an identity claim, not a temporal one.

464
MCQhard

During a risk assessment, a residual risk is identified as high. What should be the NEXT step?

A.Transfer the risk to a third party
B.Implement additional controls to reduce the risk to an acceptable level
C.Ignore the risk because it is residual
D.Accept the residual risk as is
AnswerB

A high residual risk exceeds the organisation's acceptable threshold, so the next step is implementing additional controls to reduce it to an acceptable level. Acceptance is only valid once residual risk falls within tolerance, making further mitigation the required action.

Why this answer

When residual risk remains high after applying controls, the correct next step is to implement additional controls to reduce it to an acceptable level. This aligns with the risk treatment process in NIST SP 800-37, where residual risk must be evaluated against the organization's risk appetite and, if unacceptable, further mitigation is required. Simply transferring, ignoring, or accepting a high residual risk without analysis violates governance principles.

Exam trap

In CASP+, a common misconception is that residual risk is automatically acceptable or can be ignored, when in fact it must be actively managed and reduced if it exceeds the defined risk appetite.

How to eliminate wrong answers

Option A is wrong because transferring a high residual risk (e.g., via cyber insurance or outsourcing) does not eliminate the underlying risk; the organization retains residual liability and compliance exposure, and transfer is a treatment option for inherent risk, not a default response to residual risk. Option C is wrong because ignoring a high residual risk violates the fundamental risk management principle that residual risk must be continuously monitored and addressed if it exceeds the risk appetite; it is never acceptable to simply ignore it. Option D is wrong because accepting a high residual risk as-is is only permissible if it falls within the organization's risk appetite after formal risk acceptance by senior management; automatic acceptance without documentation or justification is a governance failure.

465
MCQhard

A security architect is designing key management for a backup platform that stores encrypted archives in cloud object storage. The requirement is that destroying a single small piece of key material must render all archived data permanently unrecoverable, even if an attacker later obtains a full copy of the storage bucket and the wrapped data keys. Which design BEST meets this requirement?

A.Encrypt all archives with a single long-lived storage key protected by a passphrase that is rotated quarterly and distributed to backup administrators.
B.Encrypt each archive with a unique data encryption key, wrap those keys with a customer-managed root key held in a hardware security module, and destroy the root key to crypto-shred the archives.
C.Encrypt each archive with a unique data encryption key and store those keys in the same object storage bucket alongside the ciphertext for operational simplicity.
D.Apply server-side encryption with provider-managed keys and rely on the cloud provider's internal key rotation schedule to invalidate old key versions over time.
AnswerB

Per-archive data keys limit the blast radius of any single key exposure, and wrapping them under a root key that never leaves the HSM means the wrapped copies stored alongside the archives are useless without it. Deleting the root key destroys the only means of unwrapping, so every archive becomes permanently unrecoverable even if the bucket is fully copied, satisfying crypto-shredding.

Why this answer

Envelope encryption with a hardware-protected root key separates the wrapped data keys from the material needed to use them, so deleting the root key makes every wrapped key permanently unusable and crypto-shreds the entire archive set in one action. Keeping the root key in an HSM prevents export or copying, so an attacker who later captures the bucket gains only undecryptable ciphertext.

Exam trap

The trap here is treating key rotation or provider-managed encryption as equivalent to destruction, when rotation preserves old versions and provider keys remain outside customer control.

466
MCQmedium

A global financial firm must comply with GDPR and SOX. The CISO wants to consolidate controls across frameworks using a single set of controls. Which approach best addresses this requirement?

A.Adopt a unified control framework such as NIST SP 800-53
B.Focus only on the most stringent regulation
C.Implement automated GRC tools without changing controls
D.Maintain separate control sets for each regulation
AnswerA

Allows mapping to multiple regulations

Why this answer

Adopting a unified control framework such as NIST SP 800-53 allows the firm to map controls from GDPR and SOX into a single, comprehensive set, reducing duplication and ensuring consistent compliance. This approach leverages the framework's catalog of controls, which can be tailored to meet the specific requirements of multiple regulations simultaneously, aligning with the CISO's goal of consolidation.

Exam trap

The CAS-004 exam often tests the misconception that simply automating compliance with GRC tools or focusing on the strictest regulation is sufficient, but the correct approach requires a unified framework that harmonizes controls across all applicable regulations.

How to eliminate wrong answers

Option B is wrong because focusing only on the most stringent regulation ignores unique requirements of other regulations (e.g., GDPR's data subject rights or SOX's financial reporting controls), leading to compliance gaps. Option C is wrong because implementing automated GRC tools without changing controls merely automates existing inefficiencies and does not consolidate or harmonize the control sets across frameworks. Option D is wrong because maintaining separate control sets for each regulation increases administrative overhead, audit complexity, and the risk of control conflicts, contradicting the requirement for consolidation.

467
MCQmedium

A company is deploying a new web application that handles sensitive customer data. The application is built using a microservices architecture running in containers on a Kubernetes cluster. The security team wants to implement mutual TLS (mTLS) for service-to-service communication. However, they are concerned about the operational overhead of certificate management. Which approach minimizes management overhead while still ensuring strong authentication?

A.Generate self-signed certificates for each service and manually distribute them
B.Use a service mesh that provides automatic mTLS and certificate rotation
C.Use a single certificate for all services with Subject Alternative Names
D.Implement TLS termination at the ingress and use plaintext inside the cluster
AnswerB

A service mesh sidecar proxy intercepts pod traffic and performs automatic mTLS, issuing and rotating certificates without application changes. This satisfies the strong service-to-service authentication requirement while eliminating the manual certificate lifecycle overhead the team flagged as their concern.

Why this answer

A service mesh (e.g., Istio, Linkerd) automates mTLS by injecting sidecar proxies that handle certificate issuance, validation, and rotation via a built-in certificate authority (CA). This eliminates manual certificate management while ensuring strong, per-service authentication and encryption, directly addressing the operational overhead concern.

Exam trap

A common trap is assuming that a single shared certificate or TLS termination at the edge is sufficient for internal security. However, mTLS requires per-service identity and encryption end-to-end, not just at the perimeter.

How to eliminate wrong answers

Option A is wrong because manually generating and distributing self-signed certificates for each service introduces significant operational overhead and does not scale; it also lacks automated rotation, leading to certificate expiry issues and potential security gaps. Option C is wrong because using a single certificate with Subject Alternative Names (SANs) for all services violates the principle of least privilege—if compromised, an attacker can impersonate any service, and it does not provide per-service authentication. Option D is wrong because terminating TLS at the ingress and using plaintext inside the cluster exposes sensitive inter-service traffic to eavesdropping and tampering, completely defeating the purpose of mTLS and violating security best practices.

468
MCQhard

A company is considering adopting the NIST Risk Management Framework (RMF). Which of the following steps is unique to NIST RMF compared to ISO 27005?

A.System categorization
B.Risk identification
C.Risk treatment
D.Risk assessment
AnswerA

System categorisation, assigning impact levels (low, moderate, high) based on confidentiality, integrity and availability, is a distinctive early step in the NIST RMF. ISO 27005 addresses risk assessment and treatment without mandating this formal categorisation phase, making it the unique element.

Why this answer

System categorization is a step unique to the NIST RMF (Step 1: Categorize) that uses FIPS 199 to classify information systems by impact level (Low, Moderate, High). ISO 27005 focuses on risk management processes — risk identification, assessment, and treatment — but does not include a formal system categorization step as part of its framework. This makes system categorization the correct differentiator.

Exam trap

CAS-005 often tests framework-specific terminology, and candidates may incorrectly assume that risk assessment or treatment is unique to NIST RMF when these are shared with ISO 27005; the unique step is system categorization via FIPS 199.

How to eliminate wrong answers

Option B is wrong because risk identification is a core component of both NIST RMF (within Step 2/3) and ISO 27005, so it is not unique to NIST RMF. Option C is wrong because risk treatment is explicitly covered in ISO 27005 as well as NIST RMF, so it is not unique. Option D is wrong because risk assessment is a shared element of both frameworks, appearing in NIST RMF Step 2 and ISO 27005's risk assessment process.

469
MCQmedium

A financial services firm's third-party risk team is onboarding a new SaaS payroll provider. The provider refuses to share its internal audit reports but will allow the firm to send its own assessor on-site to inspect the provider's controls. Which risk assessment method should the firm use to obtain assurance in this situation?

A.Review of the provider's SOC 2 Type I report
B.Acceptance of the provider's ISO/IEC 27001 certificate as sufficient evidence
C.On-site assessment performed by the firm's own assessors
D.Self-assessment questionnaire completed by the provider's security team
AnswerC

The provider has blocked access to internal audit reports but explicitly permits the firm to send assessors on-site. A direct on-site assessment lets the firm independently inspect the provider's controls, interview staff, and review evidence first-hand, generating the assurance the questionnaire or report-based approaches could not deliver under these constraints.

Why this answer

Because the provider withholds internal audit reports yet allows assessors on-site, the only method that yields independently verified, first-hand evidence of control effectiveness is a direct on-site assessment. Self-assessments and certifications provide weaker, provider-controlled evidence, and the SOC 2 report is unavailable by the provider's own refusal, leaving the on-site inspection as the reliable path.

Exam trap

The trap here is assuming that any recognized artifact such as a SOC 2 report or ISO certificate automatically satisfies third-party assurance needs, when the actual constraint is what evidence the provider will permit access to.

470
Multi-Selecthard

A DevOps engineer is automating container orchestration using Kubernetes. Which of the following are security best practices to include in the automation? (Choose two.)

Select 2 answers
A.Disable RBAC to simplify automation scripts
B.Enforce Pod Security Policies to restrict privileged containers
C.Allow all network traffic between pods for simplicity
D.Implement network policies to restrict pod-to-pod communication
AnswersB, D

Why this answer

Enforcing Pod Security Policies (PSPs) is a critical security best practice in Kubernetes because it restricts the creation of privileged containers, prevents host namespace sharing, and enforces read-only root filesystems. This reduces the attack surface by ensuring that containers run with the least privilege necessary, mitigating risks of container breakout or host compromise. Disabling PSPs or failing to enforce them would allow developers to deploy containers with excessive capabilities, violating the principle of least privilege.

Exam trap

CompTIA often tests the misconception that disabling security features like RBAC or network policies simplifies automation and is acceptable in a DevOps pipeline, when in fact automation should enforce security controls, not bypass them.

Why the other options are wrong

A

RBAC is a critical security control.

C

Network policies should restrict traffic.

471
MCQmedium

A development team is using Docker containers for microservices. The security team wants to scan containers for vulnerabilities during the CI/CD pipeline. Which approach is most effective?

A.Use a runtime security tool that scans containers only when they are running.
B.Scan the container image only after deployment to production.
C.Rely on the developers to manually check for vulnerabilities.
D.Integrate image scanning into the pipeline before promoting images to the registry, using a tool like Trivy.
AnswerD

Scanning images in the pipeline before they reach the registry blocks vulnerable artefacts from ever being stored or deployed, satisfying the CI/CD constraint by shifting detection left rather than scanning after promotion, when remediation requires rebuilding and republishing.

Why this answer

Integrating image scanning into the CI/CD pipeline before promoting images to the registry ensures vulnerabilities are detected early, preventing insecure images from being deployed. Tools like Trivy scan container layers against known vulnerability databases (e.g., CVE databases) at build time, aligning with DevSecOps principles of shifting security left. This approach is more effective than runtime-only scanning or post-deployment checks, as it stops vulnerable images from reaching production.

Exam trap

A common misconception is that runtime security scanning is sufficient for vulnerability management. However, runtime tools detect active threats but not static vulnerabilities in image layers, which must be caught earlier in the pipeline via image scanning.

How to eliminate wrong answers

Option A is wrong because runtime security tools (e.g., Falco) monitor container behavior during execution, not the image itself, and may miss vulnerabilities in unused packages or layers that are never executed. Option B is wrong because scanning only after deployment to production introduces risk by allowing vulnerable images to run in production, violating the principle of early detection in CI/CD. Option C is wrong because relying on developers to manually check for vulnerabilities is error-prone, inconsistent, and does not scale, especially in microservices environments with frequent builds.

472
MCQmedium

During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?

A.Threat modeling
B.Penetration testing
C.Dynamic application security testing (DAST)
D.Static application security testing (SAST)
AnswerA

Threat modelling examines data flows, trust boundaries and architecture during design, exposing flaws before code exists, when remediation is cheapest. It directly satisfies the requirement to identify design flaws early, unlike code scanning or penetration testing, which occur later.

Why this answer

Threat modeling is a structured design-phase activity that identifies potential threats, attack vectors, and design weaknesses before code is written. It uses frameworks like STRIDE or PASTA to map data flows and trust boundaries, surfacing architectural flaws early when they're cheapest to fix. This aligns exactly with the goal of identifying design flaws during the design phase.

Exam trap

CAS-005 often tests the mapping of security activities to SDLC phases — candidates confuse SAST (code/implementation) and DAST (testing/runtime) with design-phase activities, forgetting that threat modeling is the only one that works before code exists.

How to eliminate wrong answers

Option B is wrong because penetration testing is a post-deployment or late-stage activity that exploits running systems, not a design-phase technique. Option C is wrong because DAST tests running applications for runtime vulnerabilities, requiring a deployed build. Option D is wrong because SAST analyzes source code — it requires code to exist, so it belongs to the implementation phase, not design.

473
MCQhard

A security operations center (SOC) analyst is tuning a SIEM correlation rule to detect lateral movement using pass-the-hash attacks. The analyst wants to minimize false positives while ensuring detection of true positives. Which approach is most effective for reducing false positives in this scenario?

A.Alert on any use of NTLM authentication
B.Alert on multiple failed logins followed by a successful login from a different workstation
C.Disable NTLM authentication across the network
D.Compare authentication events against a baseline of normal user behavior and alert on anomalies
AnswerD

Baselining normal authentication behaviour lets the rule flag deviations such as a single account authenticating to many hosts rapidly, which typifies pass-the-hash lateral movement. This behavioural axis, rather than static signature matching, suppresses benign administrative logons and reduces false positives while retaining true-positive detection.

Why this answer

Comparing authentication events against a baseline of normal user behavior and alerting on anomalies is the most effective approach to reduce false positives while detecting pass-the-hash attacks. Pass-the-hash involves using stolen NTLM hashes to authenticate, often from unusual workstations or at unusual times. A baseline of normal behavior can identify deviations such as a user authenticating from a new workstation or at odd hours, which are strong indicators of compromise.

This approach is more precise than blanket rules.

Exam trap

The trap is choosing overly broad rules (like any NTLM) or generic patterns (failed logins) that cause false positives; the question emphasizes minimizing false positives, so behavior baselining is the best answer.

How to eliminate wrong answers

Option A is wrong because alerting on any NTLM authentication would generate massive false positives, as NTLM is still widely used for legitimate authentication. Option B is wrong because multiple failed logins followed by a successful login from a different workstation is a generic pattern that may indicate brute force or other issues, but it is not specific to pass-the-hash and can generate false positives. Option C is wrong because disabling NTLM authentication across the network is a drastic mitigation, not a detection tuning approach, and may break legacy applications.

474
MCQhard

A security engineer is implementing a secure enclave using Intel SGX for a sensitive application. The engineer must ensure that the enclave's memory is protected from a compromised operating system. Which of the following BEST describes how SGX achieves this protection?

A.The enclave runs in a separate virtual machine that is isolated by the hypervisor, preventing the OS from accessing its memory.
B.The enclave's memory is protected by a hardware-based access control list (ACL) that the OS cannot modify.
C.The enclave's memory is encrypted by the CPU's memory encryption engine (MEE) and integrity-protected, so the OS cannot read or tamper with it.
D.The enclave's code and data are stored in a dedicated secure element (SE) that is physically separate from the main CPU.
AnswerC

Intel SGX uses the CPU's memory encryption engine to encrypt enclave pages when they are written to DRAM and verify their integrity when read back. This ensures that even a privileged attacker like the OS or hypervisor cannot read or modify enclave memory. The encryption keys are managed by the CPU and never exposed to software.

Why this answer

Intel SGX protects enclave memory using the CPU's memory encryption engine, which encrypts data leaving the CPU and verifies integrity on return. This prevents a compromised OS from reading or altering enclave memory. Other options incorrectly describe SGX as using VMs, ACLs, or separate secure elements, which are not how SGX provides isolation.

Exam trap

The trap here is assuming that SGX relies on hypervisor isolation or simple access controls, when in fact it uses hardware memory encryption and integrity protection to defend against privileged attackers.

475
MCQmedium

An organization is deploying containerized applications and needs to enforce security policies that restrict the system calls a container can make. Which Linux security module should be used?

A.seccomp
B.AppArmor
C.chroot
D.SELinux
AnswerA

seccomp operates as a syscall filter, restricting which system calls a process may invoke. Applied to containers, it blocks dangerous calls such as those used in privilege-escalation exploits, directly satisfying the requirement to limit the system calls a container can make.

Why this answer

seccomp (secure computing mode) is a Linux kernel feature that filters system calls made by a process. In container security, seccomp profiles define which syscalls a containerized process can invoke, directly restricting its ability to interact with the kernel. This is the primary mechanism used by container runtimes like Docker and containerd to enforce syscall-level restrictions.

Exam trap

CAS-005 often tests the distinction between seccomp (syscall filtering) and other Linux security modules like AppArmor or SELinux (access control), causing candidates to confuse the layer of enforcement.

How to eliminate wrong answers

Option B is wrong because AppArmor is a mandatory access control framework that confines programs via security profiles based on file paths and capabilities, not syscall filtering. Option C is wrong because chroot only changes the apparent root directory for a process, providing filesystem isolation but not syscall restriction. Option D is wrong because SELinux enforces mandatory access controls through security contexts and type enforcement, not by filtering individual system calls.

476
MCQeasy

A company is implementing a risk management framework to comply with PCI DSS. Which type of control is a firewall rule that blocks all inbound traffic except HTTP and HTTPS?

A.Corrective
B.Compensating
C.Preventive
D.Detective
AnswerC

A firewall rule permitting only HTTP and HTTPS denies all other inbound traffic before it reaches the target, which is the defining characteristic of a preventive control. This satisfies the stem's PCI DSS scenario by stopping unauthorised access attempts rather than detecting them afterwards.

Why this answer

A firewall rule that blocks all inbound traffic except HTTP (port 80) and HTTPS (port 443) is a preventive control because it actively enforces a security policy by denying unauthorized traffic before it can reach internal systems. This aligns with PCI DSS Requirement 1, which mandates a firewall configuration to restrict inbound traffic to only necessary services, thereby reducing the attack surface. Preventive controls are designed to stop security incidents from occurring, which is exactly what this rule accomplishes by filtering traffic at the network layer.

Exam trap

The trap here is that candidates often confuse 'preventive' with 'detective' because they think of firewall logs as detective, but the rule itself is a preventive control that stops traffic, while logging is a separate detective function.

How to eliminate wrong answers

Option A is wrong because corrective controls are used to remediate or restore systems after an incident has occurred (e.g., patching a vulnerability or restoring from backup), not to block traffic preemptively. Option B is wrong because compensating controls are alternative measures used when an organization cannot meet a PCI DSS requirement due to technical or business constraints (e.g., using a WAF instead of network segmentation), but this firewall rule directly satisfies the requirement without needing a substitute. Option D is wrong because detective controls identify and log malicious activity after it has happened (e.g., IDS alerts or log monitoring), whereas a firewall rule that blocks traffic is proactive, not reactive.

477
MCQmedium

A security analyst is using Volatility to analyze a memory dump from a compromised Windows system. The analyst suspects that a rootkit is hiding processes. Which Volatility plugin should the analyst use to detect hidden processes?

A.pslist
B.psxview
C.malfind
D.pstree
AnswerB

psxview cross-references multiple process-listing sources, including EPROCESS linked lists, CSRSS handles and session structures, exposing processes hidden from any single view. Rootkits unlink entries from the standard list, so this plugin's comparison directly satisfies the requirement to detect hidden processes.

Why this answer

The 'psxview' plugin compares process listings from different sources (e.g., EPROCESS list, PspCidTable) to find discrepancies, which can reveal hidden processes.

478
MCQhard

During an incident response, a forensic analyst captures the memory of a compromised Windows system. Using Volatility, the analyst runs the 'pslist' command and sees a suspicious process 'svchost.exe' with a parent process 'explorer.exe'. Which Volatility plugin should the analyst use next to detect potential process hollowing?

A.netscan
B.psxview
C.dlllist
D.malfind
AnswerD

malfind scans process memory for injected code by locating regions with executable permissions lacking a mapped file on disk, the hallmark of process hollowing. Given the suspicious svchost.exe parented by explorer.exe, it directly tests the injected-code hypothesis pslist cannot confirm.

Why this answer

The malfind plugin is specifically designed to detect injected code and process hollowing by scanning process memory for regions with suspicious characteristics such as PAGE_EXECUTE_READWRITE permissions and MZ/PE headers in non-image memory. Given the suspicious svchost.exe parented by explorer.exe (svchost should normally be parented by services.exe), malfind is the correct next step to confirm hollowing or injection.

Exam trap

The trap is picking a plugin that sounds memory-related (psxview, dlllist) but actually serves a different purpose — only malfind scans for injected/hollowed executable memory regions.

How to eliminate wrong answers

Option A is wrong because netscan enumerates network connections and listening ports; it can show C2 traffic but does not detect process hollowing or injected code in memory. Option B is wrong because psxview cross-references multiple process-listing methods to find hidden processes (rootkit detection), which is useful for DKOM hiding but not for identifying hollowed process memory. Option C is wrong because dlllist lists loaded DLLs per process; while it can reveal missing or unexpected modules, it does not scan for injected executable memory regions the way malfind does.

479
MCQeasy

A SOC analyst is investigating a potential lateral movement within the network. Which log source is most critical for detecting lateral movement using pass-the-hash or pass-the-ticket attacks?

A.Authentication logs (e.g., Windows Event ID 4624)
B.Antivirus logs
C.DNS logs
D.Firewall logs
AnswerA

Pass-the-hash and pass-the-ticket reuse stolen credential material, producing authentication events such as Windows Event ID 4624 with anomalous logon types or source hosts. Authentication logs therefore expose the credential reuse that reveals lateral movement, unlike firewall or DNS data.

Why this answer

Authentication logs, such as Windows Event ID 4624, are the most critical for detecting lateral movement via pass-the-hash or pass-the-ticket attacks because they record logon events across systems, revealing when an attacker uses stolen credentials to access other machines. Option B (antivirus logs) is less relevant as they focus on malware, not authentication patterns. Option C (DNS logs) shows name resolution but not authentication.

Option D (firewall logs) indicate network flows but lack authentication context.

480
MCQmedium

A security analyst calculates the annual loss expectancy (ALE) for a critical asset. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the annual loss expectancy?

A.$0
B.$10,000
C.$50,200
D.$250,000
AnswerB

Multiplying the single loss expectancy of $50,000 by the annualised rate of occurrence of 0.2 yields $10,000, satisfying the stem's quantitative risk calculation. This figure represents the expected yearly financial loss from the asset, enabling cost-benefit comparison against proposed security controls.

Why this answer

Annualized Loss Expectancy is calculated as ALE = SLE × ARO. With SLE = $50,000 and ARO = 0.2 (meaning the loss event is expected 0.2 times per year, i.e., once every five years), ALE = 50,000 × 0.2 = $10,000. This represents the expected yearly financial loss from the risk and is used to justify whether a control costing less than $10,000 per year is worth implementing.

Exam trap

CAS-005 often tests whether candidates remember ALE = SLE × ARO rather than adding, dividing, or inverting the operands — the distractors are deliberately built from those arithmetic mistakes.

How to eliminate wrong answers

Option A is wrong because $0 would only result if either SLE or ARO were zero — neither is, so there is a non-zero expected annual loss. Option C is wrong because $50,200 results from adding SLE and ARO (50,000 + 0.2) instead of multiplying them, which is a formula error. Option D is wrong because $250,000 results from dividing SLE by ARO (50,000 ÷ 0.2) instead of multiplying, another formula inversion.

481
Multi-Selecthard

A security architect is designing a data loss prevention (DLP) strategy for a hybrid environment where sensitive records are stored on-premises and synchronized to a SaaS productivity suite. The architect needs to ensure that policy enforcement follows the data regardless of location and that violations are detected before data leaves the organization. Which TWO of the following capabilities are most critical to achieve these goals? (Choose two.)

Select 2 answers
A.Full-disk encryption (FDE) on all endpoints and servers storing sensitive records.
B.Endpoint DLP agents with content-aware rules on managed workstations.
C.Cloud access security broker (CASB) with inline data inspection for the SaaS suite.
D.Security information and event management (SIEM) correlation of DLP alerts.
E.Network segmentation between the on-premises data center and the SaaS provider.
AnswersB, C

Endpoint DLP agents monitor and block sensitive data at the source, such as copying files to removable media or pasting into web forms. In a hybrid environment, this complements inline cloud inspection by covering local egress paths that network-based controls cannot see, ensuring enforcement follows the data.

Why this answer

Inline CASB inspection enforces DLP policy at the cloud egress point, while endpoint DLP agents enforce policy at the source on managed devices. Together they cover both network and local egress paths, ensuring that sensitive data is inspected and blocked before it leaves the organization and that policy follows the data across hybrid locations.

Exam trap

The trap here is treating encryption or SIEM correlation as DLP enforcement, when only inline content inspection at the cloud edge and endpoint content-aware agents can actually block sensitive data before it leaves.

482
MCQeasy

A company's security policy requires that all remote access be conducted via VPN. An employee uses a personal device without VPN to access company email. Which type of policy violation is this?

A.Legal violation
B.Standards violation
C.Regulatory compliance violation
D.Organizational policy violation
AnswerD

The employee breached the company's own mandated VPN requirement, so the violation is against an organisational policy. It is not a legal, regulatory or technical-control failure; the defining factor is contravention of internally defined remote-access rules.

Why this answer

The employee's action directly violates the company's internal security policy requiring VPN for all remote access. This is a policy violation, not a legal or regulatory one, as the company has established a mandatory rule that the employee failed to follow. The use of a personal device without VPN to access company email is a clear breach of organizational policy, which is a governance issue within the company's risk management framework.

Exam trap

The trap here is that candidates often confuse 'organizational policy violation' with 'regulatory compliance violation,' mistakenly thinking that any security breach automatically involves a regulatory mandate, when in fact the question explicitly describes a breach of internal policy.

How to eliminate wrong answers

Option A is wrong because a legal violation involves breaking a law (e.g., data protection statutes like GDPR or HIPAA), and while the action may have legal implications, the question specifically asks about a policy violation, not a legal one. Option B is wrong because a standards violation refers to non-compliance with industry or technical standards (e.g., ISO 27001, NIST SP 800-53), not internal company rules. Option C is wrong because a regulatory compliance violation involves failing to meet external regulatory requirements (e.g., PCI DSS, SOX), and the scenario describes a breach of internal policy, not a specific regulatory mandate.

483
Multi-Selecthard

Which THREE of the following are essential components of a secure software development lifecycle (SSDLC) to ensure security engineering? (Select exactly 3.)

Select 3 answers
A.Dynamic application security testing (DAST) and penetration testing before release.
B.User acceptance testing (UAT) to validate business requirements.
C.Static application security testing (SAST) in the development phase.
D.Daily stand-up meetings for developers.
E.Threat modeling during design phase.
AnswersA, C, E

DAST and penetration testing exercise the running application, exposing exploitable flaws in authentication, input handling and configuration before release. This satisfies the SSDLC requirement for pre-release security validation, complementing static analysis and threat modelling rather than replacing them.

Why this answer

Option A is correct because dynamic application security testing (DAST) and penetration testing exercise the running application before release, detecting runtime vulnerabilities such as injection, authentication flaws, and misconfigurations that static analysis cannot see. Option C is correct because static application security testing (SAST) analyzes source code or binaries during development, catching insecure coding patterns like buffer overflows and hardcoded secrets early when remediation is cheapest. Option E is correct because threat modeling during the design phase systematically identifies assets, trust boundaries, data flows, and threats (e.g., via STRIDE), allowing architectural security controls to be built in before code exists.

Option B does not belong because user acceptance testing validates functional business requirements, not security engineering controls. Option D does not belong because daily stand-ups are an Agile project-management ceremony with no direct security engineering function.

484
MCQmedium

A security operations team is deploying a new endpoint agent. They want to enforce a policy that only executables signed by trusted publishers and with a valid certificate chain are allowed to run, even if the user has local administrator rights. Which Windows feature should they configure to meet this requirement?

A.Windows Defender Application Control (WDAC)
B.User Account Control (UAC)
C.Software Restriction Policies (SRP)
D.AppLocker
AnswerA

WDAC is a kernel-enforced code integrity feature that can enforce policies requiring all executables to be signed by trusted publishers with a valid certificate chain. It operates at the kernel level and cannot be bypassed by local administrators, making it suitable for this strict requirement. It also supports audit mode and multiple policy formats.

Why this answer

Windows Defender Application Control (WDAC) is the correct choice because it enforces code integrity at the kernel level, requiring all executables to have a valid certificate chain from a trusted publisher. It cannot be bypassed by local administrators, unlike AppLocker or SRP. UAC only manages elevation prompts and does not validate signatures, so it fails to meet the strict policy requirement.

Exam trap

The trap here is confusing application control features like AppLocker with kernel-enforced code integrity like WDAC, assuming they provide the same level of certificate validation.

485
MCQeasy

A security administrator is reviewing the configuration of a wireless network that uses WPA3-Enterprise. The administrator wants to ensure that the authentication mechanism provides mutual authentication and supports centralized policy enforcement. Which of the following should be used?

A.WPA2-Enterprise with PEAP-MSCHAPv2
B.802.1X with EAP-TLS
C.WPA3-Personal with SAE
D.802.1X with EAP-TTLS/PAP
AnswerB

EAP-TLS provides mutual authentication using digital certificates for both the client and the server, and it integrates with a RADIUS server for centralized policy enforcement. This meets the requirements for WPA3-Enterprise, which mandates 802.1X authentication and supports EAP-TLS as a secure method.

Why this answer

EAP-TLS is the strongest EAP method for WPA3-Enterprise because it uses certificates for both client and server, enabling mutual authentication and centralized policy enforcement through RADIUS. The other methods either do not provide mutual certificate-based authentication, are designed for personal networks, or do not meet WPA3-Enterprise standards.

Exam trap

The trap here is assuming that any EAP method with 802.1X provides the same level of security, or confusing WPA3-Personal with Enterprise features.

486
MCQeasy

During a security assessment, it is discovered that an organization's DMZ hosts can initiate outbound connections to the internal network. Which architectural change would best mitigate the risk of a DMZ compromise spreading to the internal network?

A.Allow only specific IPs in the DMZ to connect to internal servers
B.Replace the DMZ firewall with a next-generation firewall that includes IPS
C.Configure the DMZ firewall to block all outbound connections from DMZ to the internal network, and use a reverse proxy for inbound services
D.Move all DMZ services to a cloud provider and use a site-to-site VPN
AnswerC

This ensures that DMZ hosts cannot be used as a pivot point into the internal network.

Why this answer

The most effective way to prevent a compromised DMZ host from pivoting into the internal network is to enforce a unidirectional traffic flow. By blocking all outbound connections from the DMZ to the internal network at the firewall and using a reverse proxy (e.g., HAProxy, Nginx, or Apache with mod_proxy) to handle inbound requests, the DMZ hosts never directly initiate connections to internal resources. This eliminates the lateral movement path even if a DMZ host is fully compromised, as the reverse proxy terminates the external connection and forwards requests to internal servers without allowing the DMZ host to establish a new outbound session.

Exam trap

The CAS-004 exam often tests the misconception that adding more security features (like IPS or IP allowlists) to an existing architecture is sufficient, when the real solution requires a fundamental change in traffic flow direction (unidirectional vs. bidirectional) to eliminate the attack vector entirely.

How to eliminate wrong answers

Option A is wrong because allowing only specific IPs in the DMZ to connect to internal servers still permits outbound connections from the DMZ, which means a compromised host could still initiate a connection to an internal server if its IP is on the allowlist, failing to fully contain a breach. Option B is wrong because replacing the DMZ firewall with a next-generation firewall (NGFW) that includes IPS does not change the fundamental architecture of allowing outbound connections from the DMZ; while IPS can detect some malicious traffic, it cannot prevent a zero-day exploit or a sophisticated attacker from using allowed protocols to pivot into the internal network. Option D is wrong because moving DMZ services to a cloud provider and using a site-to-site VPN does not inherently block outbound connections from the DMZ to the internal network; the VPN would still allow bidirectional traffic between the cloud DMZ and the internal network unless explicit egress filtering is applied, and it introduces additional complexity without addressing the core architectural flaw.

487
MCQmedium

A security architect is designing a PKI hierarchy for a large enterprise that issues certificates for internal users, devices, and code signing. Which of the following best practices should be implemented to minimize the impact of a CA compromise?

A.Rely on certificate transparency logs to detect compromises
B.Keep the root CA online for immediate certificate revocation
C.Use a single CA for all certificate types to reduce complexity
D.Implement a segmented CA hierarchy with offline root CA and separate issuing CAs for each purpose
AnswerD

An offline root CA issues only to subordinate issuing CAs, each scoped to one purpose, so compromising a user-issuing CA cannot forge code-signing or device certificates. This satisfies the constraint of minimising compromise blast radius through cryptographic and operational separation.

Why this answer

Using a tiered CA hierarchy with a root CA that remains offline and issuing CAs for specific purposes limits exposure. If an issuing CA is compromised, only its certificates need to be revoked, and the root CA can issue a new subordinate CA.

488
MCQeasy

A security architect is reviewing the network design for a new branch office. The organization wants to ensure that all traffic from the branch is inspected for malware and that users are authenticated before accessing cloud applications, regardless of their location. Which technology should the architect recommend?

A.A remote access VPN concentrator at headquarters with split tunneling disabled
B.A software-defined wide area network (SD-WAN) overlay with local internet breakout
C.A Secure Access Service Edge (SASE) solution with integrated secure web gateway and zero trust network access
D.A next-generation firewall (NGFW) at the branch perimeter with IPsec VPN to headquarters
AnswerC

SASE converges network and security functions in the cloud, providing secure web gateway for malware inspection and zero trust network access for user authentication before accessing applications. It enforces policy consistently regardless of user location, meeting the branch's needs without backhauling traffic. This makes it the correct recommendation.

Why this answer

SASE delivers converged network and security services from the cloud, including secure web gateway for malware inspection and zero trust network access for user authentication. It enforces policy consistently for users anywhere, without backhauling traffic. This directly satisfies the branch office requirements for inspection and authentication before cloud access.

Exam trap

The trap here is assuming that an NGFW or VPN concentrator alone can provide both malware inspection and identity-based authentication for cloud access, when they typically require backhauling and lack integrated zero trust capabilities.

489
MCQhard

A security engineer must select a cryptographic hash function for a new code-signing service that will protect firmware for at least 15 years. The service must resist length-extension attacks and provide collision resistance against well-funded adversaries. The organization's policy requires FIPS 140-3 validated modules only. Which hash function BEST meets these requirements?

A.SHA-256
B.MD5
C.SHA-1
D.SHA3-256
AnswerD

SHA3-256 uses the Keccak sponge construction rather than Merkle-Damgard, so it is inherently resistant to length-extension attacks. It is FIPS 202 approved and acceptable under FIPS 140-3 validated modules, and it provides 128-bit collision resistance, which is sufficient for a 15-year firmware-signing lifespan. It therefore satisfies every stated requirement without additional mitigations.

Why this answer

SHA3-256 is the only listed option that combines FIPS approval, strong collision resistance, and intrinsic resistance to length-extension attacks. The sponge construction avoids the Merkle-Damgard weakness that affects SHA-256, SHA-1, and MD5. Given the 15-year firmware-signing horizon and the explicit anti-length-extension requirement, SHA3-256 is the appropriate engineering choice.

Exam trap

The trap here is assuming that any FIPS-approved hash such as SHA-256 automatically satisfies all security requirements, when length-extension resistance is a construction-specific property that SHA-256 lacks.

490
MCQeasy

A newly hired CISO is reviewing the organization's risk register and finds that a legacy payment application carries a high inherent risk rating, but after accounting for the web application firewall, tokenization, and quarterly penetration testing already in place, the rating drops substantially. Which risk concept explains the difference between these two ratings?

A.Inherent risk
B.Residual risk
C.Control risk
D.Risk appetite
AnswerB

Residual risk is what remains after existing controls are applied to an inherent risk. The firewall, tokenization, and recurring penetration tests reduce the likelihood and impact of exploitation, so the lower rating reflects residual risk. The scenario explicitly describes inherent risk dropping once current controls are considered, which is the definition of residual risk.

Why this answer

The high rating represents inherent risk, the exposure before safeguards are considered. Once the firewall, tokenization, and recurring penetration tests are factored in, the remaining exposure is residual risk. Risk appetite is a tolerance threshold, inherent risk is the pre-control baseline, and control risk concerns control failure rather than the net exposure level.

Exam trap

The trap here is conflating residual risk with risk appetite, since both involve deciding whether an exposure is acceptable, when only residual risk measures what remains after controls are applied.

491
MCQhard

A container security team wants to enforce that containers run with the least privileges possible. Which Linux security module can be used to restrict system calls available to a container?

A.Pod Security Policy
B.AppArmor
C.SELinux
D.seccomp
AnswerD

seccomp filters the system calls a container may invoke, using a profile to block unused or dangerous calls such as ptrace or mount. This reduces the kernel attack surface, directly enforcing least privilege at the syscall layer rather than through filesystem or capability controls.

Why this answer

seccomp (secure computing mode) is a Linux kernel feature that filters system calls, allowing a container to be restricted to only the syscalls it needs. In container runtimes like Docker, containerd, and Kubernetes, seccomp profiles are applied per container to enforce least privilege at the syscall level. This directly answers 'restrict system calls available to a container.'

Exam trap

CAS-005 often tests the distinction between Linux Security Modules (AppArmor, SELinux) and seccomp — candidates pick AppArmor or SELinux for syscall restriction, but only seccomp filters system calls; LSMs enforce resource access control.

How to eliminate wrong answers

Option A is wrong because Pod Security Policy (deprecated in Kubernetes 1.21, replaced by Pod Security Admission) is a cluster-level admission control for pod specs (privileged, hostNetwork, etc.), not a Linux security module that filters syscalls. Option B is wrong because AppArmor is a Linux Security Module that enforces mandatory access control on file paths, capabilities, and network — it profiles program behavior but does not filter syscalls the way seccomp does. Option C is wrong because SELinux is also an LSM that labels processes and files for mandatory access control; it restricts access to resources but is not the syscall-filtering mechanism.

492
MCQmedium

A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?

A.Mean time to detect (MTTD) security incidents
B.Number of critical vulnerabilities exceeding the risk appetite threshold
C.Percentage of systems patched within 30 days
D.Number of security incidents per month
AnswerB

A KRI signals exposure against a defined risk appetite, not operational throughput. Critical vulnerabilities breaching that threshold indicate the security posture has moved beyond acceptable tolerance, prompting escalation. KPIs, by contrast, measure performance such as patch coverage or mean time to remediate, so this metric is the risk indicator.

Why this answer

A Key Risk Indicator (KRI) measures risk exposure and whether it is approaching or exceeding the organization's risk appetite — the number of critical vulnerabilities exceeding the risk appetite threshold is a direct measure of unacceptable risk exposure. KRIs are forward-looking indicators that signal when risk levels are becoming dangerous.

Exam trap

The trap is that many security metrics (MTTD, patch rate, incident count) sound risk-related but are actually KPIs measuring process performance; only metrics tied to risk appetite thresholds qualify as KRIs.

How to eliminate wrong answers

Option A is wrong because Mean Time to Detect (MTTD) is a performance metric measuring how quickly the security team detects incidents, which is a KPI about operational efficiency, not a risk exposure indicator. Option C is wrong because the percentage of systems patched within 30 days is a KPI measuring the effectiveness and timeliness of the patching process, not a measure of risk threshold breach. Option D is wrong because the number of security incidents per month is a lagging performance/volume metric (a KPI) describing incident frequency, not a forward-looking indicator of risk appetite breach.

493
MCQhard

A security architect is designing a system that requires cryptographic separation of duties for key management. The organization wants to ensure that no single administrator can both generate and use a key without oversight. Which of the following key management practices BEST achieves this requirement?

A.Using a hardware security module (HSM) to store all keys
B.Rotating keys automatically every 24 hours
C.Encrypting all keys with a master key stored in a software vault
D.Implementing dual control with split knowledge for key generation and usage
AnswerD

Dual control requires two or more individuals to authorize an action, and split knowledge ensures that no single person possesses the entire key or the means to use it. Together, they enforce separation of duties, preventing a lone administrator from generating and using a key without oversight. This is a fundamental principle in high-security key management, such as in FIPS 140-2 Level 3 or higher validated modules.

Why this answer

Dual control and split knowledge are specifically designed to enforce separation of duties. Dual control requires multiple authorizations, while split knowledge ensures that components of a key are divided among individuals. This combination prevents any single administrator from unilaterally generating and using a key, which is essential for high-assurance key management and compliance with standards like FIPS 140-2.

Exam trap

The trap here is assuming that an HSM automatically enforces separation of duties; it provides secure storage but not policy enforcement.

494
MCQhard

An organization is implementing a zero-trust architecture for remote access. Which component is essential for continuous authentication?

A.VPN concentrator
B.Identity provider with continuous evaluation
C.Firewall with deep packet inspection
D.Network access control (NAC)
AnswerB

An identity provider with continuous evaluation satisfies zero-trust's demand for ongoing verification rather than one-time login. Microsoft Entra ID's Continuous Access Evaluation enforces near-real-time revocation of tokens when user risk, location or policy conditions change, closing the window between session issuance and threat detection that static authentication leaves open.

Why this answer

In a zero-trust architecture, continuous authentication requires an identity provider (IdP) that can evaluate user and device attributes in real time, such as risk scores, location, and behavior patterns, to maintain trust throughout a session. Unlike static authentication at login, continuous evaluation ensures that access is revoked immediately if conditions change, which is essential for zero-trust remote access.

Exam trap

The trap here is that candidates confuse the initial authentication and encryption provided by a VPN concentrator with the continuous, adaptive trust evaluation required by zero-trust, leading them to choose Option A instead of recognizing that an identity provider with continuous evaluation is the core component.

How to eliminate wrong answers

Option A is wrong because a VPN concentrator provides encrypted tunnels and initial authentication but does not perform continuous evaluation of user or device trust after the session is established. Option C is wrong because a firewall with deep packet inspection inspects traffic content and enforces policies at the network layer, but it does not handle identity-based continuous authentication or session-level trust decisions. Option D is wrong because network access control (NAC) typically authenticates devices at the network edge and enforces compliance at initial connection, but it lacks the continuous, risk-based evaluation of user identity and behavior required for zero-trust.

495
Multi-Selecthard

A security team is implementing a secure SDLC for a new application. Which THREE activities should be included as part of the development phase? (Choose three.)

Select 3 answers
A.Runtime application self-protection (RASP) deployment
B.Penetration testing on production environment
C.Static application security testing (SAST)
D.Threat modeling
E.Dependency analysis for open-source libraries
AnswersC, D, E

SAST scans source code statically during development, identifying injection flaws, insecure patterns and coding errors before compilation or deployment. Running it in the development phase satisfies the shift-left constraint, giving developers immediate feedback while remediation remains cheapest.

Why this answer

Static application security testing (SAST) (C) belongs in the development phase because it analyzes source code or bytecode without executing the application, letting developers find injection flaws, insecure coding patterns, and other defects while code is still being written. Threat modeling (D) is a development-phase design activity that systematically identifies assets, trust boundaries, data flows, and threats (e.g., via STRIDE) so that controls are built into the architecture before coding is complete. Dependency analysis for open-source libraries (E) is also a development-phase activity, typically implemented as software composition analysis (SCA) that inspects manifests such as package.json, pom.xml, or requirements.txt to detect vulnerable or outdated third-party components and their transitive dependencies.

By contrast, RASP (A) is a runtime protection mechanism that instruments the executing application in production or test, so it is a deployment/operations control rather than a development activity, and penetration testing on production (B) is an assurance activity performed after deployment against a running system, not during development.

Exam trap

CAS-005 often tests the misconception that runtime protections like RASP or production pen testing are 'development' activities, when they actually belong to the operations/deployment phase.

496
Matchingmedium

Match each acronym to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cloud Access Security Broker

Data Loss Prevention

Identity and Access Management

Security Information and Event Management

Security Orchestration, Automation, and Response

Why these pairings

The correct matches are: SIEM - Security Information and Event Management, SOAR - Security Orchestration, Automation and Response, DLP - Data Loss Prevention, IAM - Identity and Access Management, PAM - Privileged Access Management. Option F is incorrect because it incorrectly pairs SIEM with the definition for SOAR.

497
MCQhard

During a third-party risk assessment, a security architect discovers that a vendor's data retention policy does not align with the organization's legal requirements. Which of the following is the BEST course of action?

A.Request the vendor to update its retention policy to align with legal requirements.
B.Accept the risk and document it in the risk register.
C.Immediately terminate the vendor contract.
D.Implement compensating controls to enforce data deletion after the required period.
AnswerA

Requesting the vendor to align its retention policy with the organisation's legal requirements directly closes the identified compliance gap while preserving the vendor relationship. Termination or acceptance would leave the organisation exposed to legal and regulatory breach, so remediation is the best course.

Why this answer

The vendor's data retention policy must comply with the organization's legal requirements, such as GDPR or HIPAA, which mandate specific data lifecycle controls. Requesting the vendor to update its policy is the most direct and effective way to achieve compliance, as it addresses the root cause without prematurely terminating a business relationship or relying on compensating controls that may not fully satisfy regulatory obligations.

Exam trap

CompTIA often tests the misconception that compensating controls can fully substitute for vendor compliance, but the trap here is that legal requirements demand the vendor's own policy and processes be compliant, not just the organization's technical workarounds.

How to eliminate wrong answers

Option B is wrong because accepting the risk without attempting to remediate a legal compliance gap is not acceptable; risk acceptance requires that the risk be within the organization's risk appetite, and legal non-compliance typically exceeds that threshold. Option C is wrong because immediately terminating the contract is an extreme response that ignores the possibility of remediation through contractual negotiation, which is a standard third-party risk management practice. Option D is wrong because implementing compensating controls, such as automated data deletion scripts, does not absolve the vendor of its contractual and legal responsibility to align its own policy; the vendor's non-compliant policy remains a liability, and compensating controls may not satisfy regulatory audit requirements for vendor due diligence.

498
MCQmedium

A security engineer is reviewing the configuration of a web server that uses TLS 1.3. The engineer wants to ensure that the server supports perfect forward secrecy (PFS) and uses strong cipher suites. Which of the following cipher suites should be selected?

A.TLS_AES_256_GCM_SHA384
B.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
C.TLS_RSA_WITH_AES_256_GCM_SHA384
D.TLS_DHE_RSA_WITH_AES_128_CBC_SHA
AnswerA

TLS_AES_256_GCM_SHA384 is a TLS 1.3 cipher suite that uses AES-256 in GCM mode for encryption and SHA-384 for the hash. In TLS 1.3, all cipher suites provide forward secrecy by default because key exchange uses ephemeral Diffie-Hellman. This suite is strong and meets the requirements for PFS and strong encryption.

Why this answer

In TLS 1.3, all cipher suites provide forward secrecy because key exchange is always ephemeral. The only valid TLS 1.3 cipher suite among the options is TLS_AES_256_GCM_SHA384, which uses strong AES-256-GCM encryption. The others are TLS 1.2 suites or use weak algorithms.

Exam trap

The trap here is selecting a TLS 1.2 cipher suite that provides PFS but is not valid for TLS 1.3; TLS 1.3 cipher suite names do not specify key exchange.

499
MCQeasy

A security team is adopting the NIST risk management framework. Which step should they perform first?

A.Categorize.
B.Select.
C.Implement.
D.Assess.
AnswerA

Categorize comes first in the NIST RMF, establishing the system's impact level by assessing confidentiality, integrity and availability. This determines the baseline controls selected in later steps, so performing it first satisfies the framework's mandated sequence.

Why this answer

The NIST Risk Management Framework (RMF) begins with the Categorize step, where the information system and the information it processes, stores, and transmits are categorized based on an impact analysis (low, moderate, high) per FIPS 199. This initial step establishes the security categorization that drives all subsequent RMF steps, including control selection, implementation, and assessment. Without proper categorization, the organization cannot determine which baseline controls from NIST SP 800-53 are appropriate for the system's risk profile.

Exam trap

In CASP+, candidates often confuse the order of NIST RMF steps, incorrectly assuming 'Select' comes first. However, the RMF mandates categorization first to establish the impact level, which then guides control selection. Without categorization, control selection lacks a baseline.

How to eliminate wrong answers

Option B (Select) is wrong because the Select step occurs after Categorize; you cannot select appropriate security controls until you know the system's impact level. Option C (Implement) is wrong because implementation of controls happens after they have been selected and tailored in the Select step. Option D (Assess) is wrong because assessment of control effectiveness occurs only after controls have been implemented, making it the fourth step in the RMF sequence.

500
MCQmedium

A company is migrating to a public cloud and wants to ensure they understand their security responsibilities. According to the shared responsibility model, which of the following is typically the responsibility of the cloud customer?

A.Hypervisor security
B.Physical security of data centers
C.Network infrastructure security
D.Identity and access management
AnswerD

Under the shared responsibility model, the cloud customer always owns identity and access management — defining users, roles, permissions and authentication. The provider secures the underlying infrastructure, but customer identities and their access rights remain the customer's responsibility.

Why this answer

Under the shared responsibility model, the cloud customer is always responsible for their own data, identities, and access management, including IAM policies, users, roles, and credentials. The provider secures the underlying infrastructure, but the customer controls who can access what within their tenant. IAM is therefore a customer responsibility across IaaS, PaaS, and SaaS.

Exam trap

CAS-005 often tests the misconception that the provider handles 'everything security-related,' when in fact IAM, data, and customer-side configurations always remain the customer's responsibility.

How to eliminate wrong answers

Option A is wrong because hypervisor security is a provider responsibility — the cloud vendor owns the virtualization layer that separates tenants. Option B is wrong because physical security of data centers is always the provider's responsibility; customers have no physical access. Option C is wrong because the core network infrastructure (routers, switches, backbone) is managed by the provider, though customers may be responsible for virtual network controls like security groups.

501
MCQmedium

A virtualization administrator needs to ensure that virtual machines (VMs) from different customers cannot communicate with each other unless explicitly allowed. Which network security control should be implemented on the hypervisor?

A.Patch the hypervisor regularly
B.Assign each VM to a different physical server
C.Use a virtual firewall to create per-VM security groups
D.Enable hypervisor memory overcommitment
AnswerC

A virtual firewall enforcing per-VM security groups provides microsegmentation at the hypervisor layer, filtering east-west traffic between VMs regardless of subnet. This directly satisfies the requirement that different customers' VMs cannot communicate unless explicitly permitted, since policy is applied per virtual machine rather than relying on physical network boundaries.

Why this answer

A virtual firewall applied at the hypervisor level can enforce per-VM security groups, micro-segmentation, and explicit allow rules between VMs, which is exactly what is needed to prevent cross-customer communication unless permitted. This is the standard control for multi-tenant isolation at the virtualization layer.

Exam trap

CAS-005 often tests whether candidates confuse host-hardening controls (patching) with network-isolation controls (virtual firewalls) — the question's emphasis on 'cannot communicate' points to segmentation, not patching.

How to eliminate wrong answers

Option A is wrong because patching the hypervisor addresses vulnerabilities but does nothing to control east-west traffic between VMs. Option B is wrong because spreading VMs across physical servers is a placement strategy, not a security control — VMs on the same host could still communicate, and the approach is operationally impractical. Option D is wrong because memory overcommitment is a resource-utilization feature with no security function; it can even increase risk by enabling side-channel attacks like memory deduplication leaks.

502
Multi-Selectmedium

A financial services company is conducting a risk assessment for a new online banking platform. The risk team must prioritize identified risks. Which TWO of the following factors are most critical in determining the priority for risk treatment? (Choose two.)

Select 2 answers
A.Number of open vulnerabilities
B.Vendor's market share
C.Potential impact on business objectives
D.Cost of the security control
E.Likelihood of occurrence
AnswersC, E

Impact measures the severity of consequences if a risk materializes, including financial loss, reputational damage, and regulatory penalties. For an online banking platform, impact directly ties to customer trust and compliance. Prioritizing risks with high impact ensures that treatment addresses threats that could severely disrupt operations or violate regulations, aligning security efforts with business resilience.

Why this answer

Risk prioritization hinges on assessing the likelihood of a risk event and its potential impact on business objectives. These two factors form the basis of risk scoring (e.g., risk = likelihood × impact) and guide where to focus treatment efforts. Cost, vendor market share, and vulnerability counts are secondary or irrelevant to determining which risks are most urgent for the online banking platform.

Exam trap

The trap here is focusing on the number of vulnerabilities or control cost as prioritization factors, when the core of risk prioritization is the combination of likelihood and business impact.

503
MCQmedium

An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?

A.Risk acceptance
B.Risk avoidance
C.Risk mitigation
D.Risk transfer
AnswerA

Acceptance fits because the legacy system cannot be patched, remains operationally critical, and the mitigation cost exceeds the potential loss. Retaining the residual risk formally, with documented sign-off and monitoring, is the proportionate treatment rather than transfer, avoidance or further mitigation.

Why this answer

Risk acceptance is the appropriate treatment when a vulnerability cannot be mitigated (legacy system, no patch available), the system is critical to operations (so avoidance is not feasible), and the cost of mitigation exceeds the potential loss. The organization formally acknowledges the residual risk and documents the decision, often with compensating controls and management sign-off. This is a deliberate, documented business decision rather than neglect.

Exam trap

CAS-005 often tests the confusion between risk acceptance and risk avoidance when a system is critical — candidates must recognize that acceptance is chosen when the system must remain operational and mitigation is infeasible or cost-prohibitive, whereas avoidance requires eliminating the activity entirely.

How to eliminate wrong answers

Option B is wrong because risk avoidance means eliminating the activity or system that introduces the risk — but the system is critical for operations, so shutting it down is not viable. Option C is wrong because risk mitigation means applying controls to reduce the likelihood or impact of the vulnerability — but the question states the system cannot be patched and mitigation cost exceeds potential loss, so mitigation is not the most appropriate choice. Option D is wrong because risk transfer shifts the financial impact to a third party (e.g., cyber insurance or outsourcing), but transfer does not address the underlying unpatched vulnerability and is typically used alongside acceptance, not as the primary treatment when the cost-benefit analysis favors acceptance.

504
MCQeasy

A company is implementing a SIEM solution and needs to ensure that logs from network devices, servers, and endpoints are collected in a consistent format. Which protocol should be used to transport logs securely?

A.Syslog over UDP
B.Syslog over TLS
C.SFTP
D.SNMP traps
AnswerB

Syslog over TLS encrypts log transport on port 6514, satisfying the requirement to move logs securely while preserving the standard syslog message format that network devices, servers and endpoints already emit, so the SIEM ingests consistent records without proprietary agents.

Why this answer

Syslog over TLS (often called syslog-ng or rsyslog with TLS) is the correct choice because it provides a standardized method to transport syslog messages securely over the network. Syslog itself is the de facto standard for log collection from network devices, servers, and endpoints, and adding TLS ensures confidentiality and integrity during transmission. This meets the requirement for consistent log format (syslog) and secure transport (TLS).

Exam trap

The trap here is confusing secure transport with secure log collection; candidates might pick SFTP because it is secure, but it is not designed for real-time log streaming, or they might pick SNMP traps because they are used for network device alerts, but they are not a general log transport protocol.

How to eliminate wrong answers

Option A is wrong because Syslog over UDP lacks encryption and integrity checks, making it vulnerable to eavesdropping and tampering; UDP also does not guarantee delivery. Option C is wrong because SFTP is a file transfer protocol, not a real-time log transport mechanism; it would require polling or scheduled transfers, which is inefficient for continuous log collection. Option D is wrong because SNMP traps are used for network management alerts, not for general log collection, and they are typically sent over UDP without encryption (SNMPv3 adds security but is still not designed for bulk log transport).

505
MCQmedium

A company uses a CASB to monitor cloud application usage. Which primary function does a CASB provide for enforcing security policies between users and cloud services?

A.Encryption key management for cloud storage
B.Vulnerability scanning of cloud infrastructure
C.Policy enforcement point for cloud services
D.Workload protection runtime monitoring
AnswerC

A CASB acts as an inline policy enforcement point between users and cloud services, applying access, data-loss prevention and threat policies regardless of device or location. This satisfies the requirement to enforce security policies on cloud application traffic.

Why this answer

A CASB (Cloud Access Security Broker) acts as a policy enforcement point (PEP) that sits between users and cloud service providers, intercepting traffic to apply security policies such as authentication, authorization, data loss prevention (DLP), and compliance controls. It provides visibility and control over cloud application usage, ensuring that only authorized actions and data flows are permitted. Unlike other cloud security tools, the CASB's primary role is to enforce policies in real time, not to manage keys or scan for vulnerabilities.

Thus, option C correctly identifies the core function.

Exam trap

CAS-005 often tests the misconception that a CASB is a comprehensive cloud security tool that includes encryption key management or vulnerability scanning, when its primary function is specifically policy enforcement for cloud access.

How to eliminate wrong answers

Option A is wrong because encryption key management is typically handled by a cloud provider's KMS or a dedicated key management service, not a CASB; CASBs may integrate with KMS but do not primarily manage keys. Option B is wrong because vulnerability scanning of cloud infrastructure is the domain of CSPM or vulnerability management tools, not CASBs, which focus on policy enforcement for user-to-cloud interactions. Option D is wrong because workload protection runtime monitoring is a function of CWPP or container security platforms, not CASBs, which operate at the network and API level for cloud access control.

506
MCQmedium

A security analyst is writing a Python script to parse network logs and automatically block IP addresses that exceed a threshold of failed login attempts. Which security consideration is most critical when implementing this automation?

A.Using the most efficient parsing algorithm
B.Ensuring the script runs with root privileges
C.Validating and sanitizing all input from logs
D.Writing detailed audit logs of script actions
AnswerC

Log fields are attacker-influenceable, so unsanitised values could inject commands or malformed data into the blocking logic. Validating and sanitising all log input prevents the automation from being subverted, satisfying the critical security consideration for this script.

Why this answer

Log files can contain maliciously crafted entries designed to exploit parsing logic. Without input validation and sanitization, an attacker could inject commands or manipulate the script into blocking legitimate IPs or executing unintended actions, leading to a denial-of-service or compromise of the automation system itself.

Exam trap

CompTIA often tests the misconception that automation security is about efficiency or privilege escalation, when the real trap is that log data is untrusted input that must be validated to prevent injection attacks.

Why the other options are wrong

A

Efficiency is secondary; security is paramount.

B

Least privilege principle suggests non-root.

D

Auditing is important but not the most critical.

507
Drag & Dropmedium

Drag and drop the steps to perform a vulnerability scan using Nessus into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Vulnerability scanning: configure policy, set targets, run scan, review results, and report.

508
Multi-Selectmedium

A company is adopting a secure software development lifecycle (SDLC). Which two practices are most effective for identifying vulnerabilities early in the development process? (Select TWO.)

Select 2 answers
A.Runtime application self-protection (RASP)
B.Dynamic application security testing (DAST)
C.Regular code reviews with security focus
D.Static application security testing (SAST) integrated into the IDE
E.Penetration testing after deployment
AnswersC, D

Security-focused code reviews catch flaws at the source, before code merges or reaches testing. Reviewers inspect authentication logic, input validation and cryptographic usage against the team's secure coding standards, satisfying the stem's requirement to identify vulnerabilities early in development rather than after deployment. This shifts remediation to the cheapest possible point in the lifecycle.

Why this answer

Option C (regular code reviews with security focus) is correct because peer review of source code during development catches insecure patterns, logic flaws, and missing input validation before code is merged, making it an early-phase practice in a secure SDLC. Option D (SAST integrated into the IDE) is correct because static analysis examines source code without executing it and, when embedded in the developer's IDE, flags vulnerabilities such as injection flaws or hardcoded secrets at the moment of coding, which is the earliest practical detection point. Option A (RASP) is not correct here because RASP instruments a running application to detect and block attacks at runtime, which is a production protection mechanism rather than an early development-phase identification practice.

Option B (DAST) is not correct because it tests a deployed, running application from the outside, so it occurs later in the lifecycle and cannot inspect source code early. Option E (penetration testing after deployment) is not correct because it is a post-deployment, point-in-time assessment that identifies vulnerabilities only after the code is already in production.

Exam trap

CompTIA often tests the distinction between early-phase (SAST, code reviews) and late-phase (DAST, RASP, pentesting) security practices, and the trap here is that candidates may confuse DAST or RASP as 'early' because they are automated, when in fact they require a running application.

509
MCQmedium

A security compliance officer is mapping the organization's controls to the NIST Cybersecurity Framework (CSF) 2.0. The officer needs to ensure that the organization's governance and risk management processes are adequately covered. Which CSF 2.0 function primarily addresses the development and implementation of cybersecurity policies, procedures, and risk management strategies?

A.Detect (DE)
B.Govern (GV)
C.Identify (ID)
D.Protect (PR)
AnswerB

The Govern function, new in CSF 2.0, focuses on establishing and monitoring cybersecurity strategy, policies, and risk management. It ensures that governance structures are in place to support the other functions. This directly addresses the development and implementation of policies and procedures for managing risk.

Why this answer

CSF 2.0 introduced the Govern function to emphasize cybersecurity governance and risk management. It encompasses organizational context, risk management strategy, roles and responsibilities, and policy. This function ensures that cybersecurity is integrated into enterprise risk management, making it the correct choice for policy and procedure development.

Exam trap

The trap here is selecting Identify because it also deals with risk, but Govern specifically covers policy and strategy development.

510
MCQmedium

A security engineer is configuring a Linux web server that hosts a public-facing application. The server's SSH daemon must be hardened to prevent brute-force attacks and unauthorized access. The engineer has already disabled root login and password authentication. Which additional control should the engineer implement to restrict access to only authorized administrative users?

A.Enable ChallengeResponseAuthentication and configure PAM modules.
B.Configure AllowUsers in /etc/ssh/sshd_config to list authorized usernames.
C.Set PermitRootLogin to no in /etc/ssh/sshd_config.
D.Change the SSH port from 22 to a non-standard port.
AnswerB

AllowUsers explicitly defines which user accounts may authenticate via SSH. When password authentication is disabled and root login is prohibited, this directive further narrows access to only the named administrative accounts. It directly addresses the requirement to restrict access to authorized users and is a standard hardening step for SSH daemons on public-facing servers.

Why this answer

The AllowUsers directive in sshd_config explicitly whitelists user accounts permitted to authenticate over SSH. When combined with disabled password authentication and no root login, it ensures only named administrative users can connect, directly satisfying the hardening goal. Other options either add authentication methods or obscure the service without limiting user access.

Exam trap

The trap here is assuming that disabling root login and password authentication alone restricts SSH access to specific users.

511
Multi-Selectmedium

A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)

Select 2 answers
A.Detection of compliance violations
B.Web application firewall (WAF) management
C.Vulnerability scanning of container images
D.DDoS protection
E.Continuous monitoring of cloud resource configurations
AnswersA, E

CSPM tools continuously assess cloud configurations against benchmarks and policies, surfacing misconfigurations and regulatory breaches. Detecting compliance violations is a core capability, directly matching the stem's request for typical CSPM functions rather than runtime workload protection.

Why this answer

Option A (Detection of compliance violations) is correct because CSPM tools continuously assess cloud environments against regulatory and industry benchmarks such as CIS, PCI DSS, HIPAA, and NIST, flagging misconfigurations and policy breaches that constitute compliance violations. Option E (Continuous monitoring of cloud resource configurations) is correct because the core function of CSPM is to continuously discover and monitor cloud resources (e.g., storage buckets, IAM policies, security groups) across providers like AWS, Azure, and GCP, detecting drift and risky configuration changes in near real time. Option B is incorrect because WAF management is a web application protection function typically handled by dedicated WAF services or WAAP platforms, not CSPM.

Option C is incorrect because container image vulnerability scanning belongs to container security or vulnerability management tools (e.g., Trivy, Clair, or cloud-native registries), not CSPM. Option D is incorrect because DDoS protection is a network-layer availability control provided by services such as AWS Shield or Azure DDoS Protection, which is outside the CSPM scope of posture and compliance assessment.

Exam trap

CAS-005 often tests the boundary between CSPM and CWPP — candidates incorrectly attribute workload-level capabilities like container image scanning or WAF management to CSPM, which only covers configuration posture and compliance.

512
MCQmedium

A security engineer is configuring a Linux server that hosts a web application. The server must accept connections only from the internal network 10.0.0.0/24 and must reject all other incoming traffic. The engineer decides to use iptables. Which command sequence correctly implements this requirement?

A.iptables -A INPUT -j DROP; iptables -A INPUT -s 10.0.0.0/24 -j ACCEPT
B.iptables -A INPUT -s 10.0.0.0/24 -j DROP; iptables -A INPUT -j ACCEPT
C.iptables -A INPUT -s 10.0.0.0/24 -j REJECT; iptables -A INPUT -j ACCEPT
D.iptables -A INPUT -s 10.0.0.0/24 -j ACCEPT; iptables -A INPUT -j DROP
AnswerD

This sequence appends an ACCEPT rule for the internal subnet, then appends a DROP rule for all other traffic. Because iptables processes rules in order, packets from 10.0.0.0/24 match the first rule and are accepted; all other packets fall through to the DROP rule. This correctly implements the requirement.

Why this answer

The requirement is to allow traffic only from 10.0.0.0/24 and drop everything else. In iptables, rules are evaluated in order, so the ACCEPT rule for the internal subnet must come before the DROP rule. Appending ACCEPT then DROP achieves this.

Other orderings either block legitimate traffic or permit unauthorized traffic, violating the stated policy.

Exam trap

The trap here is assuming that iptables rules are order-independent or that a default DROP policy exists without being explicitly configured.

513
MCQeasy

A system administrator needs to securely store cryptographic keys and perform signing operations in a tamper-resistant hardware device. Which solution should be used?

A.A Hardware Security Module (HSM) with FIPS 140-2 Level 3 certification.
B.A secure enclave like Intel SGX.
C.A software-based key store with encrypted files.
D.A Trusted Platform Module (TPM) 2.0.
AnswerA

An HSM provides dedicated tamper-resistant hardware that generates, stores and uses cryptographic keys internally, so keys never leave the device in plaintext. FIPS 140-2 Level 3 certification confirms physical tamper resistance, satisfying the requirement for secure signing in hardware.

Why this answer

An HSM (Hardware Security Module) is designed to securely generate, store, and manage cryptographic keys in a tamper-resistant environment.

514
Multi-Selecthard

A security analyst is using the MITRE ATT&CK framework to map adversarial behaviors. Which THREE of the following are tactics defined by ATT&CK? (Select THREE.)

Select 3 answers
A.Incident response
B.Privilege escalation
C.Persistence
D.Exfiltration
E.Phishing
AnswersB, C, D

Privilege escalation is one of the fourteen enterprise tactics in MITRE ATT&CK, describing the adversary's goal of gaining higher-level permissions. It sits alongside discovery and lateral movement as a tactical category, under which specific techniques such as exploitation for privilege escalation are catalogued.

Why this answer

Privilege escalation (B) is a valid ATT&CK tactic (TA0004) describing techniques adversaries use to gain higher-level permissions on a system or network, such as exploiting vulnerabilities or abusing elevation control mechanisms. Persistence (C) is a valid tactic (TA0003) covering techniques like scheduled tasks, registry Run keys, or creating accounts that let adversaries maintain their foothold across restarts or credential changes. Exfiltration (D) is a valid tactic (TA0010) describing techniques used to steal data from the target network, such as exfiltration over C2 channel or over alternative protocols.

Incident response (A) is not an ATT&CK tactic; it is a defensive workflow, and ATT&CK's tactics are adversary goals, not response phases. Phishing (E) is not a tactic but a technique (T1566) that falls under the Initial Access tactic, so it does not qualify as a tactic itself.

515
MCQeasy

A security administrator is hardening a web server and wants to ensure that browsers cannot be tricked into sending requests over plain HTTP after an initial HTTPS visit. The administrator also wants to prevent protocol-downgrade attacks against the site. Which response header should be configured?

A.Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
B.Content-Security-Policy: default-src 'self'
C.X-Frame-Options: DENY
D.Referrer-Policy: no-referrer
AnswerA

The Strict-Transport-Security header instructs browsers to upgrade all future requests for the domain to HTTPS for the specified max-age, and includeSubDomains extends this to subdomains while preload allows inclusion in browser preload lists. This directly prevents protocol downgrade and plaintext requests after the first secure visit.

Why this answer

Strict-Transport-Security tells the browser to rewrite future requests for the domain to HTTPS and to refuse insecure connections for the max-age window, which blocks downgrade attacks. The other headers address resource loading, framing, and referrer leakage respectively, none of which enforce transport security or prevent a fallback to HTTP.

Exam trap

The trap here is assuming any modern security header, such as a content security policy, also enforces HTTPS transport.

516
MCQmedium

An organization is implementing a SOAR solution to automate responses to common incidents. They want to create a playbook for phishing email handling. Which of the following actions should be automated in the playbook after a user reports a suspicious email?

A.Extract URLs and attachments, query threat intel feeds, and if malicious, block indicators and isolate the affected endpoint
B.Call the user to confirm they clicked the link
C.Send a warning email to all users
D.Immediately delete the email from all user inboxes
AnswerA

Extracting URLs and attachments, querying threat intelligence, then blocking indicators and isolating the endpoint chains deterministic enrichment and containment actions that require no human judgement, satisfying the stem's automation requirement. These steps execute faster than manual triage while preserving analyst review for ambiguous verdicts.

Why this answer

A phishing-handling playbook should automate the enrichment and containment steps: extract URLs and attachments, query threat intelligence feeds, and if indicators are malicious, block them and isolate the affected endpoint. This is the standard SOAR pattern of 'enrich, decide, contain' that reduces mean time to respond and removes manual toil. It is deterministic, API-driven, and safe to automate.

Exam trap

CAS-005 often tests whether candidates pick a manual or overly broad action (call the user, warn everyone, delete all emails) instead of the targeted enrich-and-contain automation that SOAR is designed for.

How to eliminate wrong answers

Option B is wrong because calling the user to confirm a click is a manual, human-dependent step that does not scale and is not a reliable automated action. Option C is wrong because blasting a warning email to all users is a broad communication action, not a targeted response, and can cause panic or be ignored. Option D is wrong because immediately deleting the email from all inboxes is a blunt action that can destroy evidence and may not be technically feasible or appropriate before analysis.

517
Multi-Selecthard

A threat intelligence analyst is profiling a threat actor that has been targeting the energy sector. Which THREE of the following attributes are most important to include in a threat actor profile? Select THREE.

Select 3 answers
A.Vulnerabilities exploited (CVEs)
B.Motivations and objectives
C.Targeted industries and regions
D.Tactics, Techniques, and Procedures (TTPs)
E.List of known indicators of compromise (IOCs)
AnswersB, C, D

Motivations and objectives reveal why the actor targets the energy sector, guiding attribution and prioritisation of defences against likely campaigns. Including intent distinguishes state-sponsored espionage from financially driven crimeware, shaping the strategic response beyond raw indicators.

Why this answer

Option B (Motivations and objectives) is correct because understanding why an actor targets the energy sector — whether for espionage, disruption, or financial gain — drives their targeting logic, persistence, and operational tempo, which is essential for prioritizing defenses. Option C (Targeted industries and regions) is correct because identifying the specific industries and geographic regions the actor focuses on enables sector-specific and region-specific threat modeling and intelligence sharing for energy organizations. Option D (Tactics, Techniques, and Procedures (TTPs)) is correct because TTPs describe the actor's behavioral patterns and tradecraft, which are more durable than atomic indicators and directly inform detection engineering and defensive countermeasures.

Option A (Vulnerabilities exploited) is not among the three most important profile attributes because specific CVEs are tactical, time-bound details that change frequently and are better tracked as vulnerability intelligence rather than core actor profiling. Option E (List of known indicators of compromise) is also not among the three most important because IOCs are volatile, easily changed by the adversary, and represent artifacts rather than the actor's enduring characteristics.

Exam trap

CAS-005 often tests the difference between strategic threat actor attributes (motivation, targets, TTPs) and tactical artifacts (CVEs, IOCs), tricking candidates into selecting volatile indicators as core profile elements.

518
MCQhard

A security architect is evaluating a cloud service provider's ability to support a customer's compliance with PCI DSS. The customer will store cardholder data in the cloud. The architect needs to determine which party is responsible for configuring encryption of the data at rest and managing the encryption keys. According to the shared responsibility model, which of the following is the MOST accurate statement?

A.The customer is responsible for enabling encryption at rest and managing keys, but the provider may offer key management services.
B.The customer is responsible for physical security of the data center, and the provider handles encryption.
C.PCI DSS compliance is solely the cloud provider's responsibility because they own the infrastructure.
D.The cloud provider is always responsible for encrypting cardholder data at rest and managing keys.
AnswerA

Under the shared responsibility model, the customer is responsible for securing data in the cloud, including enabling encryption at rest and managing encryption keys. The cloud provider may offer key management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS, but the customer must configure and use them appropriately to meet PCI DSS requirements.

Why this answer

In the shared responsibility model, the customer is responsible for securing data in the cloud, including enabling encryption at rest and managing keys. The cloud provider may offer key management services, but the customer must configure them to meet PCI DSS requirements. The other options either reverse responsibilities or incorrectly assign full responsibility to one party.

Exam trap

The trap here is assuming that because the cloud provider owns the infrastructure, it also owns all data protection responsibilities, including encryption and key management.

519
MCQeasy

A startup is building a new application on a public cloud and wants to minimize the attack surface of its virtual machines. The security architect recommends replacing SSH key-based administration with a model where no inbound management ports are exposed and access is granted per session with short-lived credentials. Which of the following should be implemented?

A.Security groups that allow SSH only from the administrator's home IP address.
B.A bastion host in a public subnet with SSH restricted to the corporate CIDR range.
C.A just-in-time access broker that issues short-lived certificates and proxies sessions.
D.VPN concentrators that place administrators on the same private network as the VMs.
AnswerC

A just-in-time access broker grants per-session, short-lived credentials and proxies administrative connections without exposing inbound management ports on the virtual machines. This directly reduces the attack surface by removing persistent SSH access and eliminating standing credentials, matching the architect's recommendation.

Why this answer

A just-in-time access broker removes standing inbound management access by issuing short-lived credentials and proxying sessions only when needed. This eliminates persistent SSH keys and exposed ports, directly minimizing the attack surface on the virtual machines while still allowing controlled administrative access.

Exam trap

The trap here is believing that IP-restricted SSH or a bastion host minimizes attack surface, when both still leave inbound management ports and long-lived credentials in place.

520
MCQmedium

A security architect is reviewing the architecture of a critical web application that handles sensitive financial transactions. The application is deployed across three tiers: a web server, an application server, and a database server. The application is protected by a web application firewall (WAF) and a network-based intrusion detection system (IDS). Recent penetration testing identified a SQL injection vulnerability in the application's search feature. The architect needs to propose a remediation that minimizes performance impact and maintains defense in depth. The development team is slow to fix code due to legacy dependencies. What should the security architect recommend as the MOST effective immediate control?

A.Disable the search feature until the code is fixed.
B.Isolate the database server on a separate network segment with strict firewall rules.
C.Add a WAF rule to block common SQL injection payloads and signatures.
D.Increase the IDS sensitivity to detect SQL injection attempts and automatically block them.
AnswerC

A WAF rule blocks SQL injection payloads at the perimeter without touching legacy code, giving immediate virtual patching while developers work. It satisfies the constraint of minimising performance impact and preserving defence in depth alongside the existing IDS and network controls.

Why this answer

The development team is slow to fix the SQL injection vulnerability in code, so an immediate control is needed. Adding a WAF rule (option C) can block common SQL injection payloads at the perimeter without code changes, minimizing performance impact and maintaining defense in depth. Option A (disable search) is too disruptive.

Option B (isolate database server) is a good defense-in-depth measure but does not address the vulnerability at the application layer. Option D (increase IDS sensitivity) only detects, not prevents. Therefore, C is the most effective immediate control.

521
MCQeasy

Which risk management framework is specifically designed for U.S. federal agencies and includes a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor?

A.ISO 27005
B.COBIT
C.NIST RMF
D.FAIR
AnswerC

NIST RMF is the U.S. federal framework built on the six-step lifecycle: Categorize, Select, Implement, Assess, Authorize and Monitor. It satisfies the stem's requirement for a federal-specific process, unlike ISO 31000 or COSO ERM, which lack this mandated authorisation step and U.S. federal alignment.

Why this answer

The NIST Risk Management Framework (RMF) is the framework specifically designed for U.S. federal agencies and is defined by NIST SP 800-37. It prescribes exactly the six-step process named in the question: Categorize, Select, Implement, Assess, Authorize, and Monitor. This lifecycle aligns with FISMA requirements for federal information systems.

Exam trap

CAS-005 often tests whether candidates can distinguish NIST RMF's six-step federal authorization process from ISO 27005's risk management process and COBIT's governance domains — all three involve 'risk' but only NIST RMF has the Categorize/Select/Implement/Assess/Authorize/Monitor sequence.

How to eliminate wrong answers

Option A is wrong because ISO/IEC 27005 is an international information security risk management guideline that describes the risk management process (identification, analysis, evaluation, treatment) but does not define a six-step Categorize/Select/Implement/Assess/Authorize/Monitor workflow and is not U.S. federal-specific. Option B is wrong because COBIT is an IT governance and management framework from ISACA focused on aligning IT with business objectives across five domains — it is not a federal risk authorization process. Option D is wrong because FAIR (Factor Analysis of Information Risk) is a quantitative risk analysis methodology for measuring cyber risk in financial terms, not a six-step authorization framework.

522
MCQhard

A security architect is designing a zero trust architecture for a hybrid environment where users access internal applications from managed and unmanaged devices. The requirement is that access decisions consider device health and user identity on every request rather than relying on network location. Which of the following BEST implements this requirement?

A.Implement a policy engine that evaluates user identity and device posture from a device attestation service for each access request, brokered through a policy enforcement point
B.Segment the internal network into microsegments with host-based firewalls and require 802.1X for all wired and wireless access
C.Require all users to connect through a bastion host that performs multi-factor authentication before reaching internal applications
D.Deploy a next-generation firewall with IP-based allow lists for the corporate VPN address pool and enable TLS inspection
AnswerA

A policy engine that consumes identity and device-posture signals and enforces decisions through a policy enforcement point on every request is the core of zero trust. It removes implicit trust based on network location and makes access contingent on current device health and authenticated identity, matching the stated requirement precisely.

Why this answer

Zero trust requires a policy decision point that consumes identity and device-posture telemetry and a policy enforcement point that applies the decision to each request. Perimeter, bastion, and segmentation approaches all evaluate trust at connection or network admission time and do not continuously factor device health into every access decision.

Exam trap

The trap here is equating strong network segmentation or a hardened bastion with zero trust, when those still grant implicit trust based on location once the initial check passes.

523
Multi-Selecthard

A financial services firm is selecting a cloud provider to host regulated customer data. The vendor risk team wants contractual language that lets the firm independently verify the provider's security posture over time rather than relying only on the provider's self-reported questionnaires. (Choose two.)

Select 2 answers
A.A clause requiring the provider to deliver current SOC 2 Type II reports at least annually
B.A limitation-of-liability cap tied to twelve months of fees
C.A service level agreement specifying 99.99% uptime credits
D.A most-favored-nation pricing clause
E.A right-to-audit clause permitting on-site inspections and evidence collection
AnswersA, E

Requiring current SOC 2 Type II reports gives the firm an independent auditor's opinion on the design and operating effectiveness of the provider's controls over a period of time. Delivering them annually ensures the assurance stays valid rather than relying on a one-time snapshot. This directly supports ongoing, third-party-verified visibility into the provider's security posture and complements other contractual safeguards.

Why this answer

Ongoing independent visibility into a provider's security posture requires contractual rights that produce evidence rather than self-reporting. A right-to-audit establishes the legal ability to inspect and test controls, and a requirement for current SOC 2 Type II reports supplies recurring auditor-attested evidence of control effectiveness. Uptime SLAs, liability caps, and pricing clauses govern availability, financial exposure, and cost, none of which verify how the provider actually secures regulated data.

Exam trap

The trap here is treating any vendor contract term as security assurance, when only provisions that grant inspection rights or recurring independent audit evidence actually verify the provider's controls.

524
MCQhard

A company is migrating to immutable infrastructure for its production environment. The security architect needs to ensure that any changes to the infrastructure are made by replacing instances, not by modifying existing ones. Which security advantage does immutable infrastructure provide?

A.It eliminates all security vulnerabilities in the infrastructure
B.It removes the need for vulnerability scanning of base images
C.It simplifies compliance by eliminating the need for patching
D.It prevents attackers from establishing persistence by modifying system files
AnswerD

Immutable infrastructure replaces instances rather than patching them, so any attacker modification to system files is discarded when the instance is rebuilt. This removes the persistence mechanism attackers rely on to survive reboots and remediation.

Why this answer

Immutable infrastructure means servers are never patched or modified in place; instead, a new image is built and instances are replaced. This prevents attackers from establishing persistence via modified system files, backdoors, or rootkits, because any tampering is discarded when the instance is recycled. It also makes the deployed state deterministic and auditable.

Exam trap

CAS-005 often tests the misconception that immutability 'eliminates vulnerabilities' or 'removes patching,' when it actually changes the patching model to image rebuilds and still requires scanning.

How to eliminate wrong answers

Option A is wrong because immutability does not eliminate vulnerabilities — a base image can still contain vulnerable software until it is rebuilt. Option B is wrong because base images still require vulnerability scanning; immutability changes how fixes are deployed, not whether scanning is needed. Option C is wrong because patching is not eliminated — it is shifted from in-place updates to rebuilding and redeploying images, and compliance still requires evidence of patched images.

525
Multi-Selectmedium

A security officer is reviewing continuous compliance monitoring tools. Which TWO of the following are primary benefits of implementing such tools? (Select TWO.)

Select 2 answers
A.Guarantees 100% compliance with all regulations
B.Provides real-time visibility into compliance posture
C.Reduces the need for periodic audits by enabling ongoing tracking
D.Replaces the need for a risk management framework
E.Eliminates all security risks
AnswersB, C

Continuous compliance monitoring continuously assesses controls against frameworks, so drift and misconfigurations surface immediately rather than at periodic audits. This satisfies the stem's requirement for a primary benefit: real-time visibility into compliance posture, enabling prompt remediation before gaps escalate into reportable findings.

Why this answer

Option B is correct because continuous compliance monitoring tools continuously collect and analyze telemetry from systems, configurations, and controls, giving organizations real-time (or near-real-time) visibility into their current compliance posture rather than a point-in-time snapshot. Option C is correct because this ongoing tracking allows deviations and drift to be detected as they occur, reducing reliance on infrequent periodic audits and enabling faster remediation. Option A is incorrect because no tool can guarantee 100% compliance with all regulations; compliance depends on people, processes, and legal interpretation, and monitoring only provides evidence and alerts.

Option D is incorrect because a risk management framework (such as NIST RMF or ISO 31000) is a governance and process structure that tools support but cannot replace. Option E is incorrect because no tool can eliminate all security risks; monitoring reduces and manages risk but residual risk always remains.

Exam trap

The trap here is the absolutist language — 'guarantees 100% compliance,' 'replaces the framework,' 'eliminates all risks' — CAS-005 often tests whether candidates recognize that no security tool provides absolute guarantees.

Page 6

Page 7 of 13

Page 8