Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 526–600

973 questions total · 13pages · All types, answers revealed

Page 7

Page 8 of 13

Page 9
526
MCQmedium

A security analyst reviews a web application that accepts user-supplied data to generate PDF reports. The application uses a legacy library that directly inserts user input into SQL queries and also includes user input in the PDF generation without sanitization. Which is the most effective countermeasure?

A.Use parameterized queries and output encoding
B.Enable HTTPS and HSTS
C.Implement a web application firewall (WAF) to block malicious input
D.Deploy a SIEM to log all database queries and PDF generation events
AnswerA

Parameterised queries send SQL structure separately from user-supplied values, eliminating injection, while output encoding neutralises injected markup in the generated PDF. Together they address both the database and PDF generation flaws in the legacy library.

Why this answer

The application has two distinct vulnerabilities: SQL injection (from direct insertion of user input into SQL queries) and likely cross-site scripting or PDF injection (from unsanitized user input in PDF generation). Parameterized queries prevent SQL injection by separating code from data, while output encoding neutralizes malicious content before it is rendered in the PDF. Together, these address the root causes of both flaws, making A the most effective countermeasure.

Exam trap

CAS-005 often tests the misconception that a WAF is a sufficient countermeasure for injection flaws, when in fact it is only a compensating control and does not fix the root cause.

How to eliminate wrong answers

Option B is wrong because HTTPS and HSTS only protect data in transit, not the application-layer injection flaws described. Option C is wrong because a WAF is a compensating control that blocks known attack patterns but does not fix the underlying vulnerability; it can be bypassed and does not address the root cause. Option D is wrong because a SIEM provides logging and monitoring, which aids detection and response but does not prevent exploitation.

527
MCQhard

A security architect is designing a new cloud-native application for a healthcare provider. The application will process protected health information (PHI) and must comply with HIPAA. The architect must ensure that all data at rest and in transit is encrypted, and that access is logged and auditable. Which of the following controls BEST meets the requirement for auditing access to PHI?

A.Implement application-level logging that records user identity, timestamp, and the specific PHI records accessed, and store logs securely.
B.Use AWS Config to monitor resource configurations and alert on changes to security groups.
C.Deploy a web application firewall (WAF) to log all incoming HTTP requests and block malicious traffic.
D.Enable AWS CloudTrail to log all API activity and store logs in an immutable S3 bucket.
AnswerA

HIPAA requires audit controls that record and examine activity in information systems containing or using electronic protected health information (ePHI). Application-level logging that captures user identity, timestamp, and the specific records accessed directly satisfies this. Storing logs securely ensures integrity and availability for audits. This is the most precise control for auditing access to PHI.

Why this answer

HIPAA's Security Rule requires audit controls that record and examine activity in systems containing ePHI. Application-level logging that captures user identity, timestamp, and the specific PHI accessed provides the necessary audit trail. Other controls like CloudTrail, AWS Config, or WAFs address different aspects of security but do not provide the granular access auditing required for PHI.

Exam trap

The trap here is assuming that infrastructure logging tools like CloudTrail or WAF logs are sufficient for HIPAA audit controls, when they lack the granularity to track access to specific PHI records.

528
MCQhard

During a security assessment, a penetration tester discovers that a web application fails to validate the size of user input, leading to a buffer overflow. Which application security control would have BEST prevented this vulnerability?

A.Input validation
B.Static application security testing (SAST)
C.Web application firewall (WAF)
D.Rate limiting
AnswerA

Input validation enforces length and format checks on user-supplied data before processing, directly satisfying the constraint that input size must be bounded. By rejecting oversized payloads at the boundary, it prevents the buffer overflow the penetration tester exploited, whereas output encoding or parameterised queries address different vulnerability classes.

Why this answer

Input validation is the application security control that directly prevents buffer overflow by ensuring that user-supplied data does not exceed the allocated buffer size. It checks the length, type, and format of input before processing, thereby mitigating the vulnerability at its source.

Exam trap

CAS-005 often tests the difference between preventive and detective controls, and candidates may choose SAST or WAF as preventive measures when the question asks for the BEST control to prevent the vulnerability.

How to eliminate wrong answers

Option B (Static application security testing (SAST)) is wrong because SAST is a testing methodology that can identify potential buffer overflows in code, but it does not prevent them at runtime; it is a detection tool, not a preventive control. Option C (Web application firewall (WAF)) is incorrect because a WAF can block some malicious requests, but it is not a reliable prevention for buffer overflows as it may not catch all variations; it is a compensating control, not a primary fix. Option D (Rate limiting) is wrong because rate limiting controls the number of requests, not the size or content of input, and does not address buffer overflow.

529
MCQmedium

A SOC manager is considering implementing a SOAR platform. Which is the primary benefit of SOAR in day-to-day operations?

A.Automated playbook execution and orchestration of response actions
B.Centralized storage of all security logs
C.Elimination of the need for human analysts
D.Reduction in false positive alerts from the SIEM
AnswerA

SOAR's primary operational benefit is executing automated playbooks that orchestrate response actions across tools, cutting mean time to respond. It satisfies the stem's day-to-day operations focus by replacing manual, repetitive triage and containment steps with machine-speed, consistent workflows.

Why this answer

SOAR automates repetitive tasks and orchestrates workflows, enabling faster and consistent incident response. Option B is wrong because SOAR is not primarily for centralized log storage; that's typically a SIEM or log management system. Option C is wrong because SOAR does not replace human analysts; it augments them.

Option D is wrong because reducing false positive alerts is primarily a function of SIEM tuning, not SOAR. SOAR can help by automating responses, but it does not directly reduce false positives.

530
MCQhard

A financial services company uses a continuous integration/continuous delivery (CI/CD) pipeline to deploy microservices. The security team wants to ensure that no secrets (e.g., API keys, database passwords) are hard-coded in source code repositories. Which tool or practice is most appropriate for detecting secrets before they are committed?

A.Run dynamic application security testing (DAST) on deployed apps
B.Implement a pre-commit hook using git-secrets or similar
C.Perform static application security testing (SAST) in the build pipeline
D.Deploy runtime application self-protection (RASP)
AnswerB

A pre-commit hook scans staged changes locally and rejects commits containing detected secrets, preventing credentials from ever entering repository history. This shifts detection left of the commit, avoiding the costly history rewriting and key rotation that post-commit scanning requires.

Why this answer

A pre-commit hook using a tool like git-secrets scans staged changes for patterns matching common secret formats (e.g., AWS keys, passwords) before the commit is finalized. This prevents secrets from ever entering the local repository, which is the earliest and most effective point of control. Unlike later-stage scans, pre-commit hooks catch issues before they are pushed to shared branches or CI/CD pipelines.

Exam trap

CompTIA CASP+ often tests the distinction between 'detecting secrets before commit' (pre-commit hooks) versus 'scanning after commit' (SAST in build pipeline), where candidates mistakenly choose SAST because it is a familiar security testing method, but it fails to prevent the secret from entering the repository history.

How to eliminate wrong answers

Option A is wrong because DAST tests running applications for runtime vulnerabilities (e.g., SQL injection, XSS) and cannot inspect source code or detect hard-coded secrets in repositories. Option C is wrong because SAST scans source code in the build pipeline after code is committed, meaning secrets have already been stored in the repository history, making removal difficult and potentially exposing them in logs or artifacts. Option D is wrong because RASP protects applications at runtime by monitoring behavior and blocking attacks, but it does not scan source code or prevent secrets from being committed.

531
MCQeasy

A software company wants to demonstrate to prospective enterprise customers that its cloud-hosted product meets recognized security and availability controls without exposing its internal procedures. The security manager must select an attestation that an independent auditor issues after testing the design and operating effectiveness of controls over a period. Which report type should the manager obtain?

A.A SOC 1 Type II report covering the relevant trust services criteria.
B.A SOC 2 Type I report covering the relevant trust services criteria.
C.A SOC 3 general use report covering the relevant trust services criteria.
D.A SOC 2 Type II report covering the relevant trust services criteria.
AnswerD

A SOC 2 Type II report is issued by an independent auditor after testing whether controls were designed appropriately and operated effectively throughout a defined period, which is exactly the assurance enterprise customers seek when evaluating a cloud provider's security and availability posture.

Why this answer

A SOC 2 Type II report provides independent auditor testing of both control design and operating effectiveness across a review period, which is the standard evidence enterprise buyers request from cloud providers. Type I lacks the period of operation, SOC 3 omits the detail customers need, and SOC 1 targets financial reporting rather than trust services criteria.

Exam trap

The trap here is confusing the point-in-time design assurance of a Type I report with the period-based operating effectiveness testing of a Type II report.

532
MCQmedium

A healthcare provider is migrating patient records to a cloud EHR system. The security officer is concerned about data ownership and portability. Which contractual clause is MOST critical to include in the cloud service agreement?

A.A clause on data portability and format standards
B.A service level agreement guaranteeing 99.999% uptime
C.A stipulation that encryption keys are managed by the customer
D.A requirement for breach notification within 24 hours
AnswerA

Portability and format standards guarantee the provider returns records in a usable, structured form on exit, directly satisfying the security officer's data ownership and portability concern. Without defined formats, extraction becomes impractical, so this clause is the most critical contractual protection.

Why this answer

Data portability and format standards clauses directly address the security officer's concerns about data ownership and the ability to move patient records out of the cloud EHR system. Without such a clause, the provider could lock the healthcare organization into proprietary formats, making migration difficult or impossible. This is critical for compliance with regulations like HIPAA, which require patients to access and transfer their health information.

Exam trap

The CASP+ exam often tests the distinction between security controls (encryption, breach notification) and contractual governance clauses (data portability, ownership), leading candidates to pick a technically valid but contextually irrelevant option like customer-managed encryption keys.

How to eliminate wrong answers

Option B is wrong because a 99.999% uptime SLA addresses availability, not data ownership or portability; it does not ensure the customer can retrieve or transfer their data. Option C is wrong because customer-managed encryption keys protect data confidentiality but do not guarantee the ability to export data in a usable format; the cloud provider could still store data in a proprietary schema. Option D is wrong because a 24-hour breach notification clause is a security incident response requirement, not a contractual safeguard for data ownership or portability.

533
MCQeasy

Which of the following is the primary security benefit of using immutable infrastructure in automated deployments?

A.Reduces operational costs by reusing existing servers
B.Eliminates configuration drift and unauthorized changes
C.Increases system performance through hardware acceleration
D.Simplifies monitoring by reducing the number of servers
AnswerB

Immutable infrastructure replaces servers rather than modifying them, so no running instance accumulates manual tweaks. That directly satisfies the stem's constraint: configuration drift and unauthorised changes become impossible because every deployment provisions fresh, identical instances from a versioned image, and any deviation is discarded at replacement.

Why this answer

Immutable infrastructure ensures that servers are never modified after deployment; instead, updates are made by replacing the entire instance with a new, pre-configured image. This eliminates configuration drift because any unauthorized or unintended changes are wiped out on the next deployment cycle, enforcing a consistent, known-good state across all environments.

Exam trap

The trap here is that candidates confuse immutable infrastructure with traditional configuration management (e.g., Puppet, Ansible) that corrects drift by modifying existing servers, whereas immutable infrastructure prevents drift entirely by never modifying servers in place.

Why the other options are wrong

A

Immutable infrastructure typically increases costs because new instances are spun up instead of patching old ones.

C

Immutable infrastructure is about deployment methodology, not hardware performance.

D

Immutable infrastructure may actually increase server count due to frequent redeployments.

534
MCQeasy

During a security incident, the incident response team has identified the root cause and removed the threat from all affected systems. Which phase of the incident response lifecycle involves returning systems to normal operation and monitoring for any signs of recurrence?

A.Eradication
B.Containment
C.Recovery
D.Lessons Learned
AnswerC

Recovery restores systems to normal operation after eradication, then monitors for recurrence. The stem's constraint — root cause identified and threat removed — places the incident exactly at the transition from eradication into recovery, where validated restoration and post-restoration monitoring occur.

Why this answer

The Recovery phase of the incident response lifecycle focuses on restoring systems to normal operation after the threat has been eradicated. It involves bringing systems back online, validating their integrity, and monitoring for any signs of recurrence. This phase ensures that the organization can resume business operations securely.

Exam trap

CAS-005 often tests the order and definitions of incident response phases, and candidates may confuse Recovery with Eradication or Containment, especially when the question mentions removing the threat.

How to eliminate wrong answers

Option A is wrong because Eradication involves removing the threat from the environment, not returning systems to normal operation. Option B is wrong because Containment focuses on limiting the spread of the incident, not recovery. Option D is wrong because Lessons Learned is a post-incident phase where the team reviews the incident to improve future response, not the phase where systems are restored.

535
Multi-Selecthard

A security team is deploying a zero trust architecture for an enterprise campus. The design must verify every request as though it originated from an untrusted network and must limit lateral movement after a workstation compromise. Which TWO capabilities are essential to this design? (Choose two.)

Select 2 answers
A.Implicit trust for traffic originating from the internal corporate VLAN.
B.Microsegmentation of workloads so that east-west traffic is denied by default and allowed only by explicit policy.
C.Policy decision and enforcement points that evaluate device posture and user identity for each session.
D.A VPN concentrator that grants full internal access after a single successful login.
E.A flat internal network with 802.1X port authentication at the access layer.
AnswersB, C

Microsegmentation enforces least privilege between workloads, so a compromised workstation cannot freely reach other systems. Combined with default-deny rules, it contains an intruder and is a core mechanism for limiting lateral movement in a zero trust design.

Why this answer

Zero trust replaces location-based trust with continuous, per-session evaluation of identity and device posture, enforced by policy decision and enforcement points. Microsegmentation supports that model by denying east-west traffic by default and permitting only explicitly authorized flows, which together prevent an intruder from moving freely.

Exam trap

The trap here is assuming that strong authentication at the perimeter, such as 802.1X or VPN login, constitutes zero trust, when the model requires ongoing per-session authorization and internal segmentation.

536
MCQmedium

A security operations center (SOC) analyst is investigating a potential malware infection on a workstation. The analyst wants to perform static analysis on a suspicious executable. Which tool or technique is most appropriate for examining the executable without executing it?

A.Run the executable in a sandbox
B.Use a memory forensics tool like Volatility
C.Use the strings command to extract readable ASCII and Unicode strings
D.Perform a network traffic capture
AnswerC

The strings command extracts readable ASCII and Unicode sequences from a binary without executing it, revealing URLs, file paths and messages. This satisfies the stem's static analysis constraint, unlike dynamic tools that run the executable in a sandbox.

Why this answer

Static analysis involves examining an executable without running it. The strings command extracts readable ASCII and Unicode strings from a binary, which can reveal URLs, IP addresses, error messages, and other indicators without executing the code. This is a safe and quick method for initial triage of suspicious files.

Exam trap

CAS-005 often tests the distinction between static and dynamic analysis, and candidates may choose sandboxing (dynamic) when asked for a non-execution method.

How to eliminate wrong answers

Option A is wrong because running the executable in a sandbox is dynamic analysis, which involves execution and may be risky if the sandbox is not properly isolated. Option B is wrong because memory forensics tools like Volatility analyze memory dumps of running systems, not static executables. Option D is wrong because network traffic capture analyzes network communications, not the executable itself.

537
Multi-Selectmedium

A security administrator is evaluating ways to improve endpoint detection and response (EDR) capabilities. Which TWO of the following approaches would most effectively enhance the detection of fileless malware attacks?

Select 2 answers
A.Monitor PowerShell script block logging and execution events.
B.Install a network intrusion detection system (NIDS) to inspect traffic.
C.Monitor process creation chain events to detect anomalous parent-child relationships.
D.Enable file integrity monitoring (FIM) on critical system files.
E.Deploy advanced antivirus with machine learning signatures.
AnswersA, C

PowerShell script block logging captures deobfuscated script content and execution events directly within the engine, exposing fileless techniques that never write to disk. This satisfies the stem's requirement to detect fileless malware, which evades traditional file-scanning EDR by residing only in memory and script interpreters.

Why this answer

Option A is correct because fileless malware frequently abuses PowerShell to execute malicious code in memory, and enabling PowerShell script block logging (Event ID 4104) plus execution events (Event ID 4103/4104) captures the actual script content and commands, giving EDR the telemetry needed to detect these in-memory attacks. Option C is correct because fileless techniques typically spawn processes from unusual parents (e.g., winword.exe launching powershell.exe or wmic.exe), so monitoring process creation chains and parent-child relationships via tools like Sysmon (Event ID 1) or Windows Security Event ID 4688 exposes these anomalous execution patterns. Option B is not the best fit because a NIDS inspects network traffic and cannot see in-memory or script-based execution on the endpoint, so it misses the core of fileless attacks.

Option D is not ideal because FIM only detects changes to files on disk, whereas fileless malware resides in memory and leaves little or no file artifacts. Option E is not the best choice because signature- and ML-based antivirus primarily targets known or file-based malware and often fails against fileless techniques that never write a malicious file to disk.

Exam trap

CAS-005 often tests the misconception that adding more signature-based or network-layer tools (NIDS, ML antivirus, FIM) will catch fileless attacks, when in fact only behavioral endpoint telemetry — script logging and process lineage — provides the necessary visibility.

538
MCQhard

A Kubernetes pod is defined with the above manifest. Which security concern is most critical?

A.The image tag "latest" might pull an outdated image.
B.The pod has added capabilities NET_ADMIN and SYS_ADMIN, which could allow network manipulation and system administration.
C.The readOnlyRootFilesystem prevents logging.
D.The pod runs as root by default.
AnswerB

NET_ADMIN permits interface, routing and firewall manipulation, while SYS_ADMIN grants broad administrative operations such as mounting filesystems. Combined in one container, these capabilities enable privilege escalation and host or network compromise, outweighing the other manifest settings.

Why this answer

Granting NET_ADMIN and SYS_ADMIN capabilities to a container in a Kubernetes pod violates the principle of least privilege and can allow an attacker to manipulate network settings (e.g., iptables, routing) and perform system-level operations (e.g., mount, swapon) that break out of container isolation. These capabilities are not required for most workloads and directly undermine the security boundaries enforced by Linux namespaces and cgroups.

Exam trap

Candidates often mistakenly choose running as root as the most critical issue, but the added capabilities NET_ADMIN and SYS_ADMIN are more dangerous because they directly enable host-level attacks, bypassing container isolation.

How to eliminate wrong answers

Option A is wrong because while using the 'latest' tag is a bad practice for reproducibility and may pull an unintended version, it is not the most critical security concern; the image is still subject to the same registry and digest controls, and the risk is primarily operational rather than a direct privilege escalation. Option C is wrong because readOnlyRootFilesystem is actually a security hardening measure that prevents writes to the container's filesystem, reducing the attack surface; it does not prevent logging if logs are written to stdout/stderr or a mounted volume. Option D is wrong because running as root by default is a common but less critical issue compared to granting dangerous capabilities; root inside a container is still restricted by user namespaces and seccomp profiles, whereas capabilities like NET_ADMIN and SYS_ADMIN directly bypass those restrictions.

539
MCQmedium

A security architect at a defense contractor must protect Controlled Unclassified Information (CUI) that flows between an on-premises data center and a government cloud enclave. The requirement states that data must remain confidential even if a cloud provider's hypervisor is compromised, and the provider must not be able to access plaintext at any layer. The architect needs a control that cryptographically isolates tenant workloads from the provider and from other tenants. Which of the following BEST satisfies this requirement?

A.Encrypt all CUI at rest with customer-managed keys stored in a separate key management service outside the provider's control.
B.Implement confidential computing using hardware-based trusted execution environments (TEEs) such as AMD SEV-SNP or Intel TDX.
C.Deploy hardware security modules (HSMs) in the cloud provider's data center to store tenant encryption keys.
D.Require TLS 1.3 with mutual authentication for all data in transit between the data center and the cloud enclave.
AnswerB

Confidential computing encrypts guest memory with keys managed by the CPU, so even a compromised hypervisor or a malicious provider administrator sees only ciphertext. TEEs provide cryptographic isolation of tenant workloads from the provider and other tenants, directly meeting the requirement that plaintext never be exposed to the cloud provider at any layer.

Why this answer

Confidential computing with hardware TEEs encrypts guest memory using CPU-managed keys, so the hypervisor and provider administrators cannot read plaintext even during processing. The other controls protect keys, data in transit, or data at rest, but none prevent plaintext exposure in memory when the hypervisor is compromised, which is the specific threat in this scenario.

Exam trap

The trap here is assuming that encrypting data at rest and in transit is sufficient to keep a cloud provider from accessing plaintext, when the provider can still read decrypted data in guest memory unless confidential computing is used.

540
Multi-Selectmedium

Which TWO of the following are valid techniques to mitigate the risk of side-channel attacks on cryptographic implementations? (Select exactly 2.)

Select 2 answers
A.Obfuscating the source code of the cryptographic library.
B.Using a cryptographically secure random number generator for key generation.
C.Implementing constant-time algorithms to avoid timing variations.
D.Increasing the key length to 4096 bits.
E.Adding noise to power consumption or using power analysis resistant logic.
AnswersC, E

Constant-time algorithms execute identical operations regardless of secret data, eliminating the timing variations attackers correlate with key bits. This directly mitigates timing side-channel attacks, satisfying the stem's requirement for a valid cryptographic implementation technique that prevents secret-dependent execution paths.

Why this answer

Option C is correct because side-channel attacks such as timing attacks exploit measurable differences in execution time that depend on secret data; implementing constant-time algorithms ensures that branches, memory access patterns, and instruction counts do not vary with secret values, thereby removing the timing signal an attacker could correlate with the key. Option E is correct because power-analysis attacks (SPA/DPA) exploit variations in a device's power consumption correlated with the data being processed; adding noise or using power-analysis-resistant logic (e.g., masking, hiding, dual-rail logic) decorrelates the power trace from the secret, directly mitigating that side channel. Option A is not appropriate because obfuscating source code does not change the underlying physical or timing leakage of the implementation and is easily defeated by reverse engineering.

Option B does not belong because a CSPRNG ensures key unpredictability and strength against brute-force or prediction attacks, but it does nothing to prevent leakage through timing, power, or electromagnetic side channels. Option D is also incorrect because increasing key length to 4096 bits only raises the computational cost of brute-force attacks and does not address information leakage exploited by side-channel analysis.

Exam trap

CompTIA CASP+ often tests the misconception that cryptographic strength (e.g., key length or random number generation) can prevent side-channel attacks, but these attacks exploit implementation flaws, not algorithmic weaknesses.

541
MCQmedium

A security architect is designing a PKI for a large enterprise. Which component is used to protect private keys and perform cryptographic operations in a tamper-resistant environment?

A.Hardware Security Module (HSM)
B.Certificate Revocation List (CRL)
C.Key Management Service (KMS)
D.Certificate Authority (CA)
AnswerA

A Hardware Security Module provides tamper-resistant hardware that generates, stores and uses private keys without exposing them to host memory, satisfying the stem's requirement for protected keys and cryptographic operations in a tamper-resistant environment. Unlike software keystores, its physical and logical controls detect intrusion and zeroise key material, defeating extraction attempts.

Why this answer

A Hardware Security Module (HSM) is a dedicated tamper-resistant appliance that generates, stores, and uses cryptographic keys without exposing them, performing operations like signing and encryption inside the hardware boundary. It is the standard component for protecting private keys in an enterprise PKI. HSMs provide FIPS 140-2/3 validated protection and resist physical and logical extraction attempts.

Exam trap

CAS-005 often tests the confusion between KMS (a key management service) and HSM (the tamper-resistant hardware), tempting candidates to pick KMS when the question emphasizes hardware protection.

How to eliminate wrong answers

Option B is wrong because a CRL is a published list of revoked certificates; it contains no keys and performs no cryptographic operations. Option C is wrong because a Key Management Service (KMS) manages key lifecycle and can use HSMs as backing, but KMS itself is a software service and the question asks for the tamper-resistant component that protects keys and performs crypto operations. Option D is wrong because a Certificate Authority issues and signs certificates but relies on an HSM to protect its private key; the CA is a role/service, not the tamper-resistant hardware.

542
MCQhard

A security analyst is investigating a possible insider threat. The analyst has access to endpoint detection and response (EDR) telemetry, network flow logs, and authentication logs. The analyst suspects that a user is exfiltrating data by encoding it into DNS queries to a domain controlled by the attacker. Which data source and analysis technique would best confirm this activity?

A.Inspect DNS query logs for unusually long or high-entropy subdomain strings and repeated queries to the same domain.
B.Review authentication logs for anomalous login times or locations from the user's account.
C.Correlate EDR process creation events with network connections to known malicious IP addresses.
D.Analyze network flow logs for large outbound data transfers to external IP addresses.
AnswerA

DNS exfiltration often encodes data in subdomains, resulting in long, random-looking strings. Analyzing DNS query logs for such patterns, especially repeated queries to a single domain, can reveal tunneling. This directly addresses the scenario and uses the appropriate data source.

Why this answer

DNS exfiltration hides data in DNS queries, typically as encoded subdomains. The most direct way to confirm is to examine DNS query logs for indicators like long, high-entropy labels and repetitive queries to the same domain. Other data sources may show related activity but do not directly reveal the DNS-based channel.

Exam trap

The trap here is assuming that network flow logs will show large data transfers, but DNS exfiltration uses many small queries that may not exceed volume thresholds.

543
Multi-Selecthard

A company is migrating its legacy VPN to use IPsec with IKEv2. The security team wants to ensure the strongest possible security. Which THREE configuration options should be selected?

Select 3 answers
A.Use ECDSA P-384 for authentication
B.Use SHA-1 for integrity
C.Use AES-256-GCM for encryption
D.Use IKEv1 instead of IKEv2
E.Enable perfect forward secrecy (DHE)
AnswersA, C, E

ECDSA P-384 provides a 192-bit security strength, exceeding RSA-2048 and matching the strongest IKEv2 authentication options. It satisfies the stem's demand for maximum security by using elliptic-curve cryptography, which delivers equivalent strength with smaller keys and is approved for CNSA suite compliance.

Why this answer

Option A (ECDSA P-384) is correct because elliptic-curve signatures at the 384-bit level provide roughly 192-bit security strength, far exceeding RSA-2048, and are well supported in IKEv2 for strong peer authentication. Option C (AES-256-GCM) is correct because AES-256 gives a 256-bit key and GCM is an AEAD mode that provides both confidentiality and integrity in a single efficient primitive, making it the strongest symmetric choice here. Option E (perfect forward secrecy via DHE) is correct because Diffie-Hellman ephemeral key exchange ensures that compromise of the long-term key cannot decrypt previously captured sessions, which is essential for 'strongest possible security' in an IKEv2 deployment.

Option B (SHA-1) is not appropriate because SHA-1 is cryptographically broken for integrity and should be replaced by SHA-256 or stronger. Option D (IKEv1) is not appropriate because IKEv2 is more secure, more robust, and supports modern features like MOBIKE and stronger authentication methods.

Exam trap

The trap is selecting SHA-1 for integrity because it is a known algorithm, but SHA-1 is deprecated and insecure; the exam expects recognition that modern IPsec configurations must avoid SHA-1 and IKEv1.

544
MCQhard

A SOC analyst is investigating a suspicious process that is making outbound connections to an unknown IP address. The analyst wants to examine the process memory for injected code. Which Volatility plugin is most appropriate for detecting code injection by listing all Virtual Address Descriptors (VADs) that are mapped as executable and writable?

A.netscan
B.malfind
C.pslist
D.dlllist
AnswerB

The malfind plugin scans process memory for VAD regions marked both executable and writable, flagging likely injected code such as reflective DLL injection or shellcode. Other plugins enumerate handles, connections or loaded modules, but none specifically target executable-writable memory mappings.

Why this answer

The malfind Volatility plugin is designed to detect code injection by scanning for memory regions that are both executable and writable, which is atypical for legitimate code. It lists Virtual Address Descriptors (VADs) with these permissions and can identify injected code, such as that from malware. This directly addresses the analyst's need to examine process memory for injected code.

Exam trap

CAS-005 often tests the specific Volatility plugin for detecting code injection, and candidates may confuse malfind with pslist or dlllist, which do not analyze memory permissions.

How to eliminate wrong answers

Option A is wrong because netscan lists network connections and does not analyze memory for code injection. Option C is wrong because pslist lists running processes but does not inspect memory permissions or detect injected code. Option D is wrong because dlllist lists loaded DLLs but does not identify suspicious memory regions with executable and writable permissions.

545
MCQeasy

Which of the following is the primary advantage of using STIX and TAXII for threat intelligence sharing?

A.They replace the need for a SIEM system
B.They perform dynamic analysis of malware samples
C.They provide real-time blocking of malicious IPs
D.They allow automated sharing of threat intelligence in a standardized format
AnswerD

STIX provides a structured language for describing indicators, actors and campaigns, while TAXII defines the transport protocol for exchanging that content. Together they let platforms ingest and act on intelligence automatically, removing manual reformatting between vendors.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is a protocol for exchanging that intelligence. Together, they enable automated sharing of threat intelligence in a standardized format, improving interoperability and speed of information exchange.

Exam trap

CAS-005 often tests the purpose of STIX/TAXII, and candidates may confuse them with analysis or blocking tools, rather than standards for sharing.

How to eliminate wrong answers

Option A is wrong because STIX/TAXII do not replace SIEM systems; they complement them by providing threat intelligence feeds. Option B is wrong because STIX/TAXII are not analysis tools; they are for representation and exchange, not dynamic malware analysis. Option C is wrong because STIX/TAXII do not perform blocking; they facilitate sharing of intelligence that can be used by other systems to block threats.

546
Multi-Selectmedium

A security architect is designing a just-in-time (JIT) privileged access management (PAM) solution. Which TWO of the following are key characteristics of JIT access?

Select 2 answers
A.Privileges are permanent but require approval each time.
B.Access rights are automatically revoked after use or expiry.
C.Break-glass accounts are used for emergency access.
D.Privileges are granted on-demand for a limited time period.
E.Users have standing privileges for routine tasks.
AnswersB, D

Automatic revocation after use or expiry is fundamental to JIT: standing privileges are eliminated, so access exists only for the approved window. Once the task completes or the timer lapses, the entitlement is withdrawn without manual intervention, shrinking the attack surface.

Why this answer

Option B is correct because a defining property of JIT PAM is that elevated rights are time-bound and automatically revoked once the task completes or the approved window expires, eliminating lingering standing privileges. Option D is correct because JIT access grants privileges on-demand only when needed, for a limited duration, rather than provisioning them permanently in advance. Together, B and D capture the core JIT model: just-in-time, just-enough, and time-limited elevation.

Option A is wrong because JIT privileges are temporary, not permanent, even if approval workflows are involved. Option C is wrong because break-glass accounts are an emergency fallback mechanism, not a defining characteristic of JIT access itself. Option E is wrong because standing privileges for routine tasks directly contradict the JIT principle of eliminating always-on access.

547
MCQhard

A technology company suspects an insider threat is exfiltrating intellectual property. The security team has deployed user and entity behavior analytics (UEBA) and set up data loss prevention (DLP) rules. A UEBA alert flags a senior developer who is accessing the source code repository at 2 AM from a VPN connection that routes through a foreign country. The developer also recently downloaded a large quantity of source code—more than 10 times the normal volume. DLP policies are configured to block emails with attachments over 10 MB. Which of the following should the incident response team do FIRST?

A.Implement stricter DLP policies to block large downloads from the repository.
B.Conduct an informal interview with the developer to ask about the unusual activity.
C.Isolate the developer's workstation and revoke access to the source code repository immediately.
D.Review DLP logs to confirm that no emails containing source code were sent.
AnswerC

Isolating the workstation and revoking repository access contains the suspected exfiltration before more intellectual property leaves, satisfying the stem's FIRST-action constraint. UEBA already flagged anomalous foreign-VPN access at 2 AM and 10x download volume, so immediate containment precedes forensic imaging or DLP tuning.

Why this answer

The first step in incident response for a suspected insider threat with active exfiltration is to contain the threat by isolating the workstation and revoking access to prevent further data loss. This aligns with the containment phase of incident response. Conducting an interview or reviewing logs can come later, but immediate isolation is critical to stop ongoing exfiltration.

Exam trap

CAS-005 often tests the order of incident response steps, where candidates might choose investigation or policy changes before containment, but containment must always come first in an active threat.

How to eliminate wrong answers

Option A is wrong because implementing stricter DLP policies is a long-term preventive measure, not an immediate response to an active incident. Option B is wrong because interviewing the suspect could tip them off and allow them to destroy evidence or continue exfiltration. Option D is wrong because reviewing DLP logs is part of investigation, but it does not stop the ongoing threat; containment must come first.

548
Multi-Selectmedium

A security architect is designing a data lifecycle management program. Which TWO of the following are phases of the data lifecycle? (Select TWO.)

Select 2 answers
A.Data replication
B.Data anonymization
C.Data creation
D.Data destruction
E.Data monetization
AnswersC, D

Data creation is the lifecycle phase where new data is generated, captured or acquired, establishing the asset before any classification or protection controls apply. It satisfies the stem's requirement to identify genuine lifecycle phases within a data lifecycle management programme.

Why this answer

Option C (Data creation) is correct because the data lifecycle begins when data is generated or acquired, making creation the first recognized phase in lifecycle models such as the one described in ISO/IEC 27001 and NIST guidance. Option D (Data destruction) is correct because the lifecycle concludes with secure disposal or destruction of data once it is no longer needed, ensuring it cannot be recovered and reducing residual risk. Data replication (A) is a storage or availability technique, not a lifecycle phase.

Data anonymization (B) is a privacy-enhancing technique applied during processing, not a distinct lifecycle phase. Data monetization (E) is a business objective or use case, not a formal phase of the data lifecycle.

Exam trap

CAS-005 often tests whether candidates can distinguish lifecycle phases (creation, storage, usage, sharing, archiving, destruction) from techniques and business activities (replication, anonymization, monetization) — the distractors sound data-related but are not phases of the lifecycle.

549
Multi-Selecthard

Which THREE of the following are key components of a zero-trust security architecture? (Select THREE).

Select 3 answers
A.VPN concentrator
B.Micro-segmentation
C.Implicit trust for internal network traffic
D.Least privilege access control
E.Continuous monitoring of user and device behavior
AnswersB, D, E

Micro-segmentation satisfies the zero-trust requirement for granular, least-privilege access by dividing networks into isolated zones, each with its own policy controls. This limits lateral movement, so a compromised workload cannot reach unrelated resources, directly enforcing the "assume breach" principle central to zero-trust architecture.

Why this answer

Micro-segmentation (B) is a core zero-trust component because it divides the network into granular zones and enforces policy between workloads, preventing lateral movement even after a breach. Least privilege access control (D) is essential since zero trust grants only the minimum permissions needed for a specific task, typically enforced through just-in-time and just-enough-access policies rather than broad standing rights. Continuous monitoring of user and device behavior (E) is required because zero trust never assumes trust permanently; it continuously validates identity, device posture, and context through telemetry and analytics to make real-time access decisions.

By contrast, a VPN concentrator (A) reflects the traditional perimeter model of granting broad network access once authenticated, which contradicts zero-trust principles. Implicit trust for internal network traffic (C) is the exact opposite of zero trust, which assumes no implicit trust based on network location and verifies every request explicitly.

Exam trap

The trap here is that candidates confuse zero-trust with traditional perimeter-based security and select 'VPN concentrator' as a key component, not realizing that zero-trust replaces VPNs with identity-aware, per-application access (e.g., ZTNA) and that implicit trust for internal traffic is explicitly rejected in zero-trust models.

550
MCQmedium

A multinational retailer must comply with PCI DSS v4.0 for its cardholder data environment. The security manager is asked to define the scope of the CDE. Which of the following best describes the first step in scoping the CDE according to PCI DSS?

A.Conduct a penetration test on all internet-facing systems to determine which ones are in scope.
B.Review the PCI DSS Self-Assessment Questionnaire (SAQ) to determine which requirements apply.
C.Identify all system components that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD).
D.Segment the network by placing all cardholder data systems behind a firewall and then document the segmentation.
AnswerC

PCI DSS scoping begins with identifying all system components that store, process, or transmit CHD or SAD, as well as those that could impact the security of the CDE. This includes connected systems and security-impacting systems. Without this inventory, the scope cannot be accurately defined, and the assessment will be incomplete. This is the foundational step mandated by PCI DSS.

Why this answer

The correct answer is to identify all system components that store, process, or transmit CHD or SAD. PCI DSS scoping requires a thorough inventory of people, processes, and technologies that handle cardholder data or could impact its security. This inventory forms the basis for defining the CDE and determining which requirements apply.

Without it, segmentation and validation efforts are misdirected.

Exam trap

The trap here is assuming that network segmentation or penetration testing is the first step in PCI DSS scoping, when in fact a complete data-flow inventory must precede any scope-reduction technique.

551
Multi-Selectmedium

Which TWO of the following are key components of a governance framework? (Select TWO)

Select 2 answers
A.Policies and procedures
B.Vulnerability scanning schedule
C.Firewall rules
D.Penetration test results
E.Defined roles and responsibilities
AnswersA, E

Core governance documents

Why this answer

Policies and procedures are foundational to a governance framework because they define the rules, standards, and operational guidelines that an organization must follow to ensure compliance, security, and risk management. They establish the 'what' and 'how' for decision-making and behavior, aligning with frameworks like ISO 27001 or NIST SP 800-53. Without documented policies and procedures, governance lacks enforceable structure and accountability.

Exam trap

CompTIA often tests the distinction between governance components (policies, roles) and operational or technical controls (schedules, rules, results), leading candidates to mistake tactical activities for strategic framework elements.

552
Multi-Selecthard

A regional bank is preparing for its annual regulatory examination and must demonstrate that its third-party risk management program is mature. The examiner asks which practices provide continuous, rather than point-in-time, oversight of critical vendors. (Choose two.)

Select 2 answers
A.Establishing contractual rights to audit, receive breach notifications within defined timeframes, and obtain regular independent assurance reports
B.Relying on the vendor's own marketing materials and public certifications page to confirm its security posture
C.Ranking vendors solely by annual contract value and assigning oversight resources proportionally to spend
D.Collecting a completed security questionnaire from each vendor once during initial onboarding and archiving the response
E.Requiring critical vendors to submit to annual on-site or virtual control assessments with documented findings and remediation tracking
AnswersA, E

Contractual audit rights, notification obligations, and requirements for independent assurance such as SOC 2 reports give the bank ongoing visibility into vendor control status between assessments. These provisions create enforceable expectations and information flow, so the bank learns of control changes or incidents without waiting for the next scheduled review, which is exactly the continuous oversight the examiner seeks.

Why this answer

Continuous third-party oversight combines recurring independent validation with enforceable contractual information rights. Periodic assessments with remediation tracking confirm that identified weaknesses are corrected, while audit rights, breach notification clauses, and independent assurance requirements keep the bank informed between reviews. One-time questionnaires, spend-based ranking, and reliance on vendor marketing all capture stale or unverified information.

Exam trap

The trap here is confusing initial due diligence artifacts, such as an onboarding questionnaire, with the recurring validation and contractual visibility that constitute ongoing oversight.

553
MCQhard

Refer to the exhibit. The data classification policy defines levels and rules. During an audit, a database containing both PII and credit card numbers is found labeled as 'Internal'. Which of the following is the BEST first action?

A.Accept the risk as the data is not public
B.Remove the credit card numbers from the database
C.Create a new classification level for mixed data
D.Reclassify the database as 'Critical' to reflect the highest required level
AnswerD

Reclassifying to Critical immediately aligns the database's label with its actual contents, since credit card numbers demand the highest protection level under the policy. This corrects the mislabelling before any further remediation or access review.

Why this answer

When a database contains data spanning multiple classification levels, the governing principle is that the asset must be classified at the highest sensitivity level of any data it contains. Since credit card numbers (regulated as cardholder data under PCI DSS) are more sensitive than generic PII labeled 'Internal', the database must be reclassified to reflect that highest level. Reclassifying as 'Critical' aligns the label with the actual data sensitivity and triggers the appropriate handling controls.

Exam trap

CAS-005 often tests the 'highest sensitivity wins' rule for mixed-data assets, and candidates are tempted by remediation actions (removing data, creating new tiers) that sound proactive but skip the mandatory first step of correcting the classification label.

How to eliminate wrong answers

Option A is wrong because accepting the risk ignores the compliance violation — mislabeled cardholder data is a PCI DSS breach regardless of whether the data is publicly exposed, and 'not public' is not a valid risk acceptance rationale. Option B is wrong because removing credit card numbers is a data-minimization remediation that may not be feasible or authorized and does not address the immediate classification failure; it also skips the required first step of correcting the mislabel. Option C is wrong because creating a new classification level for mixed data fragments the classification scheme and is not how data classification policies work — the standard rule is to classify at the highest level present, not invent a hybrid tier.

554
Multi-Selecthard

A security engineer is hardening a containerized workload platform against attacks that escape a container and reach the host kernel. The team wants to reduce the kernel attack surface available to each container without breaking application functionality. Which TWO measures BEST accomplish this? (Choose two.)

Select 2 answers
A.Apply a seccomp profile that allows only the system calls the application actually uses and denies the rest by default.
B.Run the container runtime with the Docker socket mounted into every container so the platform can manage sibling containers.
C.Disable mandatory access control frameworks such as AppArmor or SELinux so the application is not blocked by policy denials.
D.Set the container to run as the root user inside its namespace to avoid file permission problems during deployment.
E.Drop all Linux capabilities and add back only the specific ones the application requires.
AnswersA, E

A default-deny seccomp profile removes access to the large majority of system calls a process never needs, shrinking the kernel interfaces an attacker can abuse from inside a compromised container. Because it is enforced per process by the kernel, a successful application exploit cannot pivot to unneeded calls such as those used to load modules or manipulate namespaces, directly reducing escape options.

Why this answer

Default-deny seccomp profiles and least-privilege capability sets both operate at the kernel boundary and remove entire classes of privileged operations from containerized processes. Together they ensure that even a fully exploited application lacks the system calls and capabilities needed to reach host kernel interfaces, which is precisely the attack surface reduction the team requires.

Exam trap

The trap here is equating stronger isolation with convenience features such as runtime socket mounting or running as root, which actually widen the path from container to host.

555
MCQmedium

A network administrator is configuring a firewall to block traffic from a specific IP address range. The firewall uses ACLs. Which ACL entry would deny traffic from 192.168.1.0/24?

A.deny ip 192.168.1.0 0.0.0.255 any
B.deny ip 192.168.1.0 0.0.0.0 any
C.deny ip 192.168.1.0 0.0.0.127 any
D.deny ip 192.168.1.0 255.255.255.0 any
AnswerA

Wildcard 0.0.0.255 matches the entire /24 subnet.

Why this answer

In Cisco ACL syntax, the wildcard mask 0.0.0.255 matches all addresses in the 192.168.1.0/24 network. The 'deny ip 192.168.1.0 0.0.0.255 any' entry blocks any IP traffic from the source subnet 192.168.1.0 through 192.168.1.255 to any destination.

Exam trap

The trap here is that candidates often confuse subnet masks with wildcard masks, selecting option D (255.255.255.0) instead of the correct wildcard mask 0.0.0.255.

How to eliminate wrong answers

Option B is wrong because the wildcard mask 0.0.0.0 matches only the single host 192.168.1.0, not the entire /24 subnet. Option C is wrong because the wildcard mask 0.0.0.127 matches only the first 128 addresses (192.168.1.0–192.168.1.127), which is a /25 range, not the full /24. Option D is wrong because 255.255.255.0 is a subnet mask, not a wildcard mask; ACLs require inverse (wildcard) masks, so this entry would be syntactically invalid or misinterpreted.

556
MCQmedium

A security analyst is performing a quantitative risk assessment for a server that processes payment card data. The server has an asset value of $50,000. Based on historical data, the exposure factor (EF) for a ransomware attack is 80%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

A.$20,000
B.$40,000
C.$50,000
D.$25,000
AnswerA

SLE equals asset value ($50,000) multiplied by exposure factor (0.80), giving $40,000. ALE is SLE multiplied by ARO (0.5), yielding $20,000. This quantifies expected annual loss for the payment card server, satisfying the quantitative assessment requirement.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). SLE is Asset Value (AV) times Exposure Factor (EF). Here, AV = $50,000, EF = 0.8, so SLE = $40,000.

ARO = 0.5, so ALE = $40,000 * 0.5 = $20,000.

Exam trap

CAS-005 often tests confusion between SLE and ALE, or misapplication of the formula by forgetting to multiply by ARO or using AV directly instead of SLE.

How to eliminate wrong answers

Option B is wrong because $40,000 is the SLE, not the ALE; it omits multiplication by ARO. Option C is wrong because $50,000 is the asset value, not the ALE. Option D is wrong because $25,000 would result from using AV * ARO without applying EF, or halving AV incorrectly.

557
MCQmedium

A security team is evaluating an EDR solution. Which of the following capabilities is a primary differentiator between EDR and traditional antivirus?

A.Centralized policy management
B.File integrity monitoring
C.Signature-based detection of known malware
D.Behavioral analysis and detection
AnswerD

Behavioural analysis and detection distinguishes EDR from signature-based antivirus, which matches only known file hashes. EDR continuously monitors process behaviour, registry changes and API calls, then correlates these events to identify anomalous activity such as living-off-the-land techniques that traditional antivirus, lacking behavioural telemetry, would miss entirely.

Why this answer

EDR's primary differentiator from traditional antivirus is its use of behavioral analysis and detection. Traditional AV relies on static signatures to identify known malware, whereas EDR continuously records endpoint telemetry (process trees, registry changes, network connections) and applies behavioral heuristics, machine learning, and threat intelligence to detect novel or fileless attacks. This allows EDR to identify malicious activity even when no signature exists, and to provide detection, investigation, and response capabilities rather than just prevention.

Exam trap

CAS-005 often tests the misconception that EDR is simply 'next-gen antivirus' with signatures plus a cloud console, causing candidates to pick centralized management or signature detection instead of behavioral analysis.

How to eliminate wrong answers

Option A is wrong because centralized policy management is a common feature of both traditional AV (via management consoles like Symantec Endpoint Protection Manager) and EDR platforms, so it is not a differentiator. Option B is wrong because file integrity monitoring (FIM) is a separate capability often provided by HIDS/HIPS or compliance tools (e.g., Tripwire, OSSEC) and is not the defining characteristic of EDR. Option C is wrong because signature-based detection of known malware is the core mechanism of traditional antivirus, not a differentiator—EDR actually de-emphasizes signatures in favor of behavioral analytics.

558
MCQeasy

An organization wants to deploy a technology that lures attackers into a controlled environment to observe their tactics, techniques, and procedures (TTPs). Which deception technology should the organization implement?

A.Honeytoken
B.EDR
C.Honeypot
D.SIEM
AnswerC

A honeypot is a decoy system deliberately exposed to attract attackers, letting defenders observe their tactics, techniques and procedures within a controlled, monitored environment. It satisfies the requirement to lure adversaries and record their behaviour without risking production assets.

Why this answer

A honeypot is a decoy system intentionally designed to attract and deceive attackers, allowing defenders to observe their tactics, techniques, and procedures (TTPs) in a controlled environment. It mimics vulnerable services or entire networks, and any interaction with it is inherently suspicious, providing high-fidelity threat intelligence with minimal false positives. This matches the requirement to 'lure attackers into a controlled environment' for TTP observation.

Exam trap

CAS-005 often tests the confusion between honeypots and honeytokens—candidates may pick honeytoken thinking it 'lures' attackers, but honeytokens are passive tripwires, not interactive decoy environments.

How to eliminate wrong answers

Option A is wrong because a honeytoken is a single fake artifact (e.g., a credential, file, or URL) used to detect unauthorized access or data exfiltration, not a full environment for observing attacker behavior. Option B is wrong because EDR is a defensive endpoint monitoring and response tool, not a deception technology designed to lure attackers. Option D is wrong because SIEM aggregates and correlates log data for detection and compliance, but it does not actively lure or deceive attackers.

559
MCQeasy

A developer is creating a REST API that handles sensitive data. Which HTTP method should be used for updates that are not idempotent?

A.DELETE
B.GET
C.PUT
D.POST
AnswerD

POST performs non-idempotent updates because each request can create a new subordinate resource or alter server state differently, satisfying the stem's requirement for updates that are not idempotent. Unlike PUT, which replaces a resource at a known URI idempotently, POST targets a collection or processing endpoint where repeated identical requests may produce distinct outcomes.

Why this answer

POST is correct because it is not idempotent, meaning multiple identical requests can result in different outcomes (e.g., creating a new resource each time). For updates that are not idempotent, POST is the appropriate HTTP method as it allows side effects such as appending data or triggering a process, unlike PUT which is idempotent and replaces the entire resource.

Exam trap

The key pitfall is that many candidates mistakenly believe PUT can be used for any update operation. However, PUT is idempotent, meaning it must result in the same state regardless of how many times it is applied. For non-idempotent updates (e.g., appending data), POST is the appropriate method because it can create side effects that change state differently with each request.

How to eliminate wrong answers

Option A is wrong because DELETE is idempotent (RFC 7231) and is used to remove a resource, not for updates. Option B is wrong because GET is a safe and idempotent method used only for retrieval, never for updates. Option C is wrong because PUT is idempotent (the same request always produces the same result) and is designed for full resource replacement, not for non-idempotent updates.

560
MCQmedium

A company uses Kubernetes for container orchestration. Which security control should be implemented to enforce that only specific images from a trusted registry can run in the cluster?

A.Pod security admission (PSA)
B.Admission controller (e.g., OPA/Gatekeeper)
C.Network policies
D.RBAC roles
AnswerB

An admission controller intercepts pod creation requests before persistence and evaluates them against policy. OPA/Gatekeeper enforces rules restricting image sources, so only images from the trusted registry are admitted, directly satisfying the stem's trusted-registry constraint.

Why this answer

An admission controller such as OPA/Gatekeeper intercepts API server requests before objects are persisted and can enforce policies — including image registry allow-lists — so only images from trusted registries are admitted to the cluster. Gatekeeper's ConstraintTemplates and Constraints let you write Rego policies that validate image fields in Pod specs.

Exam trap

CAS-005 often tests Kubernetes security controls by presenting several plausible-sounding controls (PSA, Network Policies, RBAC), so candidates who see 'only specific images' and pick PSA or RBAC miss that image provenance requires an admission controller with policy logic.

How to eliminate wrong answers

Option A is wrong because Pod Security Admission enforces Pod Security Standards (privileged, baseline, restricted) around privilege, host namespaces, and capabilities — it does not validate image registries. Option C is wrong because Network Policies control pod-to-pod and pod-to-external traffic at L3/L4; they govern network flow, not which images can run. Option D is wrong because RBAC controls who (users, service accounts) can perform which API actions; it does not inspect the content of Pod specs to enforce image provenance.

561
MCQmedium

A security engineer is configuring SSH for a jump host used to access critical servers. The engineer wants to restrict the cryptographic algorithms to the most secure options. Which of the following should be DISABLED?

A.Diffie-Hellman group-exchange with SHA-1
B.AES-256-CTR
C.Ed25519 for host keys
D.HMAC-SHA2-256
AnswerA

Diffie-Hellman group exchange with SHA-1 uses a deprecated hash for key exchange integrity, weakening SSH against collision-based attacks. Disabling it enforces stronger SHA-2-based key exchange algorithms, meeting the requirement to restrict the jump host to the most secure options.

Why this answer

Diffie-Hellman group exchange with SHA-1 uses the SHA-1 hash for key exchange integrity, and SHA-1 is cryptographically broken (collision attacks demonstrated) and deprecated by NIST. For a hardened jump host, this kex algorithm should be disabled in favor of SHA-2-based groups like diffie-hellman-group-exchange-sha256 or curve25519-sha256.

Exam trap

CAS-005 often tests whether candidates can distinguish deprecated hash-based algorithms (SHA-1 kex) from still-secure primitives (AES-256, Ed25519, HMAC-SHA2) — the trap is picking a strong cipher or MAC thinking it's weak because it sounds old.

How to eliminate wrong answers

Option B is wrong because AES-256-CTR is a strong, modern symmetric cipher with a 256-bit key and is considered secure for SSH transport encryption. Option C is wrong because Ed25519 is a modern elliptic-curve signature algorithm offering strong security and performance, and is recommended for host keys. Option D is wrong because HMAC-SHA2-256 is a secure message authentication code based on SHA-256, appropriate for SSH integrity protection.

562
Matchingmedium

Match each encryption standard or algorithm to its type.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Symmetric block cipher

Asymmetric public-key cryptosystem

Hash function (one-way)

Elliptic curve digital signature algorithm

Keyed-hash message authentication code

Why these pairings

The correct matches are AES with symmetric encryption, RSA with asymmetric encryption, and SHA-256 with hashing. Common confusions include mistaking AES for asymmetric or RSA for symmetric.

563
Multi-Selectmedium

A security manager is developing a third-party risk management program. The organization wants to ensure that vendors handling sensitive data are subject to appropriate oversight. Which two of the following are the most effective methods for ongoing monitoring of a vendor's security posture? (Choose two.)

Select 2 answers
A.Asking the vendor to self-attest to security compliance annually
B.Conducting periodic on-site security assessments of the vendor
C.Reviewing the vendor's marketing materials for security claims
D.Requiring the vendor to provide annual SOC 2 Type II reports
E.Monitoring the vendor's stock price for fluctuations
AnswersB, D

Periodic on-site assessments allow the organization to directly verify the vendor's security controls, practices, and compliance with contractual requirements. They provide firsthand evidence and can uncover issues not visible in documentation. This method is effective for ongoing monitoring, especially for critical vendors, and complements other oversight activities.

Why this answer

Effective ongoing vendor monitoring requires objective, independent evidence of security controls. SOC 2 Type II reports provide third-party attestation over time, and periodic on-site assessments allow direct verification. Other options like marketing materials, self-attestation, and stock price monitoring lack the rigor and specificity needed for security oversight.

Exam trap

The trap here is considering self-attestation or marketing claims as sufficient for vendor monitoring, when independent verification is necessary.

564
MCQmedium

A vulnerability scanner reports a critical vulnerability with a CVSS base score of 9.8 on a public-facing web server. However, the server has a compensating control: a Web Application Firewall (WAF) that blocks exploit attempts. How should the security team prioritize patching this vulnerability?

A.Schedule patching during the next maintenance window
B.Defer patching indefinitely since the WAF mitigates the risk
C.Immediately patch the vulnerability as soon as possible
D.Increase the WAF rule strictness and delay patching
AnswerC

A CVSS base score of 9.8 on an internet-facing server warrants immediate remediation; a WAF is a compensating detective or blocking control, not a substitute for patching, since bypasses and rule gaps exist. Delaying based on the WAF leaves the underlying exploitable flaw unaddressed.

Why this answer

The vulnerability has a CVSS base score of 9.8, which is Critical, and the server is public-facing, meaning it is directly exposed to potential attackers. While a WAF provides a compensating control, it is not a foolproof mitigation—WAFs can be bypassed through evasion techniques, misconfigurations, or zero-day exploits. Therefore, the security team should prioritize immediate patching to eliminate the underlying vulnerability, as recommended by risk management frameworks like NIST and CIS.

The WAF reduces immediate risk but does not eliminate it, so patching remains urgent.

Exam trap

CAS-005 often tests the misconception that a compensating control like a WAF can replace the need for immediate patching, but the exam expects candidates to recognize that critical vulnerabilities on public-facing systems require urgent remediation regardless of compensating controls.

How to eliminate wrong answers

Option A is wrong because scheduling patching during the next maintenance window delays remediation of a critical vulnerability on an internet-facing system, leaving a window of exposure that could be exploited if the WAF fails. Option B is wrong because deferring patching indefinitely based solely on a WAF is dangerous; WAFs are not infallible and can be bypassed, and the vulnerability remains unaddressed. Option D is wrong because increasing WAF rule strictness does not fix the underlying flaw and may cause false positives or operational issues, while still leaving the system vulnerable if the WAF is circumvented.

565
MCQmedium

A security analyst is reviewing a suspicious email reported by a user. The email contains a link to a domain that was registered three days ago and hosts a JavaScript file. The analyst wants to safely analyze the JavaScript file to understand its behavior without risking infection. Which of the following approaches is MOST appropriate?

A.Open the link in a sandboxed virtual machine with no network access and execute the JavaScript in a browser.
B.Download the JavaScript file and analyze its code using a text editor and a deobfuscation tool.
C.Submit the URL to a public online JavaScript sandbox and review the execution trace.
D.Use a command-line tool to fetch the JavaScript file and pipe it directly to a JavaScript engine for execution.
AnswerB

Downloading the file and performing static analysis with a text editor and deobfuscation tools allows the analyst to understand the script's logic, identify obfuscation techniques, and extract indicators without executing it. This avoids any risk of infection and is a standard safe practice for analyzing potentially malicious scripts.

Why this answer

Static analysis of the JavaScript file by downloading it and examining its code with deobfuscation tools is the safest and most informative approach. It allows the analyst to understand the script's functionality, extract indicators, and determine its malicious intent without any risk of executing the code. This method is preferred when the goal is to understand behavior without infection.

Exam trap

The trap here is assuming that any execution, even in a sandbox, is safe, when in fact static analysis avoids execution entirely and is often sufficient for JavaScript.

566
Multi-Selecthard

A company is developing a secure software development lifecycle (SDLC) and wants to integrate security testing early. Which THREE techniques should be used to find vulnerabilities in code during development? (Choose three.)

Select 3 answers
A.Penetration testing
B.Software Bill of Materials (SBOM) analysis
C.Threat modeling
D.Dynamic Application Security Testing (DAST)
E.Static Application Security Testing (SAST)
AnswersC, D, E

Threat modelling identifies design-level weaknesses by systematically analysing data flows, trust boundaries and attack paths before coding completes. Applying it early satisfies the stem's requirement to find vulnerabilities during development, complementing code-level scanning with architectural risk discovery.

Why this answer

Threat modeling (C) is correct because it is a design-phase activity that systematically identifies threats, attack surfaces, and mitigations before code is written, making it a foundational shift-left technique. SAST (E) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find flaws such as injection sinks and insecure coding patterns directly in the IDE or CI pipeline. DAST (D) is correct because it tests the running application from the outside, exercising inputs and runtime behavior to uncover vulnerabilities like authentication and configuration flaws that static analysis may miss.

Penetration testing (A) is not one of the three because it is typically a later, point-in-time adversarial assessment rather than an early development-phase code-testing technique, and SBOM analysis (B) is a supply-chain inventory and component-transparency practice, not a method for finding vulnerabilities in first-party code during development.

Exam trap

CAS-005 often tests which security activities belong 'early' in the SDLC, so candidates who include penetration testing (late-stage) or SBOM analysis (dependency inventory, not code testing) instead of the design/code/runtime trio of threat modeling, SAST, and DAST lose marks.

567
MCQeasy

A security analyst is reviewing the organization's risk register and notices a risk that has been assigned a risk score of 15 on a scale of 1 to 25. The risk owner has decided to purchase cyber insurance to transfer the financial impact of the risk. Which risk treatment strategy is being applied?

A.Risk acceptance
B.Risk mitigation
C.Risk transfer
D.Risk avoidance
AnswerC

Risk transfer involves shifting the financial impact of a risk to a third party, such as an insurance company. Purchasing cyber insurance is a classic example of risk transfer. The organization retains the risk but transfers the potential financial loss to the insurer, which aligns with the risk owner's decision in this scenario.

Why this answer

Purchasing cyber insurance shifts the financial consequences of a risk to an insurer, which is the definition of risk transfer. Risk avoidance would eliminate the activity, mitigation would reduce likelihood or impact, and acceptance would involve bearing the risk without transfer. The scenario clearly describes transfer.

Exam trap

The trap here is confusing risk transfer with risk mitigation, as both involve taking action, but transfer shifts financial impact while mitigation reduces the risk itself.

568
MCQeasy

Which of the following is the primary benefit of using infrastructure as code (IaC) for automating security configurations?

A.It eliminates the need for security testing
B.It ensures consistent and repeatable security configurations
C.It allows unapproved changes to be deployed faster
D.It increases manual oversight of security settings
AnswerB

IaC declares security configurations in version-controlled templates that are applied identically across every deployment, removing manual drift and configuration error. This repeatability satisfies the stem's primary-benefit question, distinguishing IaC from one-off scripting or documentation-based hardening.

Why this answer

Infrastructure as code (IaC) enables security configurations to be defined in declarative or procedural scripts (e.g., Terraform, AWS CloudFormation, Ansible). This ensures that every deployment applies the exact same security settings (e.g., firewall rules, IAM policies, encryption at rest) without drift, making configurations consistent and repeatable across environments. The primary benefit is eliminating manual, error-prone processes that lead to configuration inconsistencies.

Exam trap

The trap here is that candidates may think IaC eliminates the need for security testing (Option A) because automation implies perfection, but in reality, IaC code itself must be tested for security flaws, just like application code.

Why the other options are wrong

A

IaC does not eliminate testing; it automates deployment.

C

Unapproved changes are a risk, not a benefit.

D

IaC reduces manual oversight.

569
Matchingmedium

Match each security tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Protects web applications from attacks

Detects intrusions and alerts

Detects and blocks intrusions in real-time

Host-based intrusion detection system

Network-based intrusion detection system

Why these pairings

Correct matches: SIEM provides centralized log analysis, IDS monitors for malicious activity, and firewalls enforce traffic rules. Common confusions include mixing SIEM and firewall functions.

570
MCQhard

A security team is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to prevent a compromised pod from reaching the cloud metadata service at 169.254.169.254 to steal node credentials, while still allowing pods to reach required external APIs. Which of the following should the team implement?

A.Apply a network policy that denies egress to the link-local metadata address while permitting approved external destinations.
B.Set the pod security context to run containers as a non-root user with a read-only root filesystem.
C.Configure role-based access control so that pods run under a service account with no RBAC permissions.
D.Enable mutual TLS between all pods and require SPIFFE identities for service-to-service calls.
AnswerA

Network policies can select pods and control egress by destination CIDR and port, so a rule denying 169.254.169.254 blocks the metadata path while a companion allow rule permits required external APIs. This is the least-disruptive control that directly removes the credential-theft vector without breaking legitimate traffic. It enforces the restriction at the pod network layer regardless of application behavior.

Why this answer

Blocking pod egress to the link-local metadata address removes the direct path a compromised workload would use to obtain node credentials, and pairing it with an allow rule for required external APIs preserves functionality. Network policy operates below the application, so it constrains all processes in the selected pods without relying on application cooperation.

Exam trap

The trap here is assuming that workload identity or RBAC hardening protects the metadata endpoint, when those controls govern different planes than the pod network path.

571
MCQmedium

A penetration tester is performing a test against a web application. During active reconnaissance, the tester discovers that the application discloses version numbers in HTTP headers. Which phase of the penetration testing lifecycle does this activity belong to?

A.Reconnaissance
B.Post-exploitation
C.Exploitation
D.Reporting
AnswerA

Banner grabbing and header inspection gather information about the target's technology stack without exploiting it, which is active reconnaissance within the reconnaissance phase. It precedes scanning, exploitation and post-exploitation, satisfying the lifecycle stage where target intelligence is collected.

Why this answer

Active reconnaissance involves directly interacting with the target to gather information, such as by sending probes and analyzing responses. Discovering version numbers via HTTP headers is a form of active reconnaissance because the tester is making requests and inferring information from the responses.

572
MCQmedium

A security architect is designing a platform for a hospital network. Clinical staff must access patient records from managed workstations, while third-party billing contractors use unmanaged personal laptops. The architect wants a single architecture that continuously validates device posture and user identity before granting access to each microservice, regardless of network location. Which approach should the architect implement?

A.Deploy a next-generation firewall with VLAN segmentation for clinical and contractor traffic.
B.Implement a zero trust architecture using a policy engine and policy enforcement points at each microservice.
C.Establish an IPsec VPN concentrator that assigns contractors to a restricted subnet.
D.Configure 802.1X port-based authentication on all wired switch ports.
AnswerB

Zero trust architecture continuously evaluates identity and device posture through a policy engine and enforces decisions at policy enforcement points. Placing enforcement at each microservice allows the hospital to authorize every request based on user, device, and context regardless of network location, satisfying both the managed workstation and unmanaged contractor scenarios with one consistent model.

Why this answer

A zero trust architecture with a policy engine and enforcement points at each microservice continuously validates identity and device posture for every request, independent of network location. This single architecture covers managed clinical workstations and unmanaged contractor laptops alike, unlike network-centric controls that authenticate once and then trust the connection. Per-microservice enforcement also limits lateral movement if a device is compromised.

Exam trap

The trap here is assuming that strong network segmentation or VPN access alone achieves zero trust, when zero trust requires continuous, per-request identity and posture evaluation rather than one-time network admission.

573
MCQeasy

Which of the following is the correct order of the security policy hierarchy from highest to lowest?

A.Policy → Standard → Guideline → Procedure
B.Standard → Policy → Guideline → Procedure
C.Policy → Guideline → Standard → Procedure
D.Procedure → Guideline → Standard → Policy
AnswerA

Policy sits at the top of the hierarchy, establishing mandatory high-level intent, followed by standards that specify enforceable requirements. Guidelines then offer non-mandatory recommendations, and procedures come last, detailing the step-by-step actions needed to implement the higher-level directives. This ordering satisfies the stem's highest-to-lowest constraint.

Why this answer

The security policy hierarchy from highest to lowest is Policy, Standard, Guideline, Procedure. Policies are high-level statements of management intent. Standards are mandatory requirements that support policies.

Guidelines are recommendations. Procedures are step-by-step instructions for implementing policies and standards. This order reflects the decreasing level of authority and increasing level of detail.

Exam trap

CAS-005 often tests the misconception that guidelines are mandatory or that standards are higher than policies, confusing the hierarchy.

How to eliminate wrong answers

Option B is wrong because it places Standard above Policy, but policies are the highest-level documents that drive standards. Option C is wrong because it places Guideline above Standard, but standards are mandatory while guidelines are discretionary, so standards must be higher. Option D is wrong because it reverses the entire hierarchy, placing Procedure at the top, which is incorrect as procedures are the most detailed and lowest-level documents.

574
MCQmedium

A company processes personal data of EU citizens and wants to implement privacy by design. Which of the following is the BEST first step in this process?

A.Appointing a Data Protection Officer (DPO)
B.Implementing data encryption at rest and in transit
C.Developing a data retention policy
D.Conducting a Privacy Impact Assessment (PIA)
AnswerD

A Privacy Impact Assessment identifies what personal data is processed, why, and where risks arise, giving the documented basis for designing controls before processing begins. Conducting it first satisfies the privacy-by-design requirement to embed protection at the earliest stage of any EU personal-data initiative.

Why this answer

A Privacy Impact Assessment (PIA) — also called a Data Protection Impact Assessment (DPIA) under GDPR Article 35 — is the foundational first step in privacy by design because it forces the organization to systematically identify and mitigate privacy risks before processing begins. It maps data flows, identifies personal data elements, assesses legal bases, and evaluates risks to data subjects, which then informs all subsequent controls like encryption, retention, and DPO involvement. Without this assessment, other measures are implemented blindly and may not address the actual risks.

GDPR explicitly requires a DPIA for high-risk processing, making it a legal prerequisite in many cases.

Exam trap

The trap here is confusing a necessary governance role (DPO) or a common technical control (encryption) with the foundational risk-assessment step that must logically precede them; candidates often pick encryption because it feels concrete, but privacy by design starts with understanding risks, not applying fixes.

How to eliminate wrong answers

Option A is wrong because appointing a DPO is an organizational governance step that may be required for certain organizations, but it does not itself implement privacy by design; the DPO's role is to advise and monitor, not to perform the initial risk assessment. Option B is wrong because encryption is a technical safeguard that should be selected based on risks identified during a PIA; implementing it first without assessment may protect the wrong data or miss other privacy risks like excessive collection or lack of consent. Option C is wrong because a data retention policy is a downstream control that depends on knowing what data is collected, why, and for how long it is needed — all outputs of a PIA; creating it first would be premature and likely misaligned with actual processing purposes.

575
MCQmedium

A security analyst is reviewing a suspicious email reported by a user. The email contains an attachment named 'invoice.pdf.exe'. Which type of malware analysis technique should the analyst perform first to determine if the file is malicious?

A.Reverse engineering
B.Static analysis
C.Dynamic analysis in a sandbox
D.Memory forensics
AnswerB

Static analysis examines the file's structure, strings and headers without executing it, safely revealing the double extension and embedded indicators. This satisfies the stem's need to determine maliciousness first, before risking execution in a sandbox.

Why this answer

Static analysis examines the file without executing it, inspecting headers, strings, hashes, and embedded indicators (e.g., PE headers, suspicious imports) to quickly determine if it is malicious. For a double-extension file like 'invoice.pdf.exe', static analysis is the safest first step because it avoids any risk of execution and can often reveal known malware signatures or obfuscation. It is faster and less resource-intensive than dynamic analysis or reverse engineering, making it the standard initial triage technique.

Exam trap

CAS-005 often tests the confusion between static and dynamic analysis — candidates may think 'sandbox' is always first, but the safest and fastest initial triage for an unknown file is static analysis, not execution.

How to eliminate wrong answers

Option A is wrong because reverse engineering is a deep, time-consuming process used after initial triage confirms the file is suspicious; it is not the first step. Option C is wrong because dynamic analysis in a sandbox executes the malware, which carries risk and requires more setup; it is typically performed after static analysis indicates the file is likely malicious. Option D is wrong because memory forensics analyzes volatile memory (RAM) of a running system, not a file attachment, and is irrelevant to initial file triage.

576
MCQmedium

A security engineer needs to implement a solution that will detect and block command-and-control (C2) traffic from malware on the internal network. The solution must be able to inspect encrypted traffic and operate at the network layer. Which of the following is the BEST choice?

A.Implement a web application firewall (WAF) to filter outbound HTTP/HTTPS traffic.
B.Install a network-based intrusion detection/prevention system (IDS/IPS) with signature updates.
C.Use endpoint detection and response (EDR) agents on all workstations and servers.
D.Deploy a next-generation firewall (NGFW) with SSL/TLS inspection and application-level filtering.
AnswerD

An NGFW with SSL/TLS inspection decrypts encrypted sessions, then applies application-level filtering to identify and block C2 signatures at the network layer. This satisfies both constraints: inspecting encrypted traffic and operating inline at the network layer.

Why this answer

A next-generation firewall (NGFW) with SSL/TLS inspection and application-level filtering is the best choice because it can decrypt and inspect encrypted C2 traffic at the network layer, then apply application-aware rules to block malicious communications. This directly addresses the requirement to detect and block C2 traffic that uses encryption to evade traditional inspection.

Exam trap

The trap here is that candidates often choose a network-based IDS/IPS (Option B) thinking it can inspect encrypted traffic, but without SSL/TLS decryption, it can only see encrypted payloads and cannot detect C2 commands hidden inside the encrypted tunnel.

How to eliminate wrong answers

Option A is wrong because a web application firewall (WAF) is designed to protect web servers from application-layer attacks (e.g., SQL injection, XSS) and typically filters inbound HTTP/HTTPS traffic, not outbound C2 traffic from internal malware. Option B is wrong because a network-based IDS/IPS with signature updates can detect known C2 patterns but cannot inspect encrypted traffic without decryption, so it would miss C2 traffic tunneled over TLS/SSL. Option C is wrong because endpoint detection and response (EDR) agents operate at the host/endpoint layer, not the network layer, and the question specifically requires a solution that operates at the network layer.

577
Multi-Selecthard

A security engineer is reviewing the results of a penetration test. The tester successfully exploited a vulnerability in a web application and escalated privileges to domain admin. Which THREE of the following findings should be included in the technical report to provide actionable remediation steps? (Select THREE.)

Select 3 answers
A.The estimated financial loss from the exploit
B.The recommendation to patch the web application
C.The exact command used to exploit the vulnerability
D.The name and contact of the penetration tester
E.The step-by-step path from initial access to domain admin
AnswersB, C, E

Recommending the patch gives the remediation team the specific fix that closes the exploited web application vulnerability, addressing the initial access vector. This satisfies the stem's requirement for actionable remediation steps in the technical report.

Why this answer

Option B is correct because the technical report must provide actionable remediation, and recommending that the web application be patched directly addresses the exploited vulnerability and prevents recurrence. Option C is correct because documenting the exact command used to exploit the vulnerability gives defenders a reproducible proof of concept, enabling them to verify the flaw and test that remediation actually blocks the attack. Option E is correct because the step-by-step path from initial access to domain admin illustrates the full attack chain and privilege-escalation weaknesses, which is essential for prioritizing fixes to identity, segmentation, and tiered administration controls.

Option A does not belong because estimated financial loss is a business-impact or risk-management metric, not a technical remediation step. Option D does not belong because the tester's name and contact details are administrative metadata, not actionable technical remediation guidance.

Exam trap

CAS-005 often tests the distinction between technical remediation content and business/administrative content—candidates may incorrectly include financial loss or tester contact details, which belong in the executive summary or administrative section.

578
MCQmedium

A security architect is designing a data classification scheme. Which of the following is the MOST effective way to ensure consistent labeling across the organization?

A.Implementing DLP solutions.
B.Manual labeling by data owners.
C.User training and awareness.
D.Automated classification based on data content.
AnswerD

Content-based automated classification inspects actual data patterns and identifiers, applying labels consistently regardless of author or department. This satisfies the requirement for uniform labelling across the organisation, unlike manual schemes that depend on inconsistent human judgement.

Why this answer

Automated classification based on data content is the most effective method for ensuring consistent labeling across an organization because it removes human error and subjectivity. By using content inspection, pattern matching, and metadata analysis, the system can apply labels uniformly based on predefined rules, such as detecting credit card numbers (PCI-DSS) or personally identifiable information (PII). This approach enforces policy without relying on individual user judgment, which is critical for large-scale compliance.

Exam trap

The trap in this CASP+ question is that candidates may think DLP solutions are responsible for classification, but DLP typically enforces policies based on existing labels rather than creating the classification scheme. Automated classification is the most reliable method for consistent labeling.

How to eliminate wrong answers

Option A is wrong because DLP solutions are designed to monitor and prevent data exfiltration, not to assign classification labels; they can use labels but do not create them. Option B is wrong because manual labeling by data owners is inconsistent, error-prone, and scales poorly, as different owners may interpret classification criteria differently. Option C is wrong because user training and awareness, while important, cannot guarantee consistent labeling due to human error, fatigue, and varying interpretations of policy.

579
MCQmedium

A security engineer is designing the key-management lifecycle for a hardware security module (HSM) that will hold a root certificate authority signing key. The requirement is that the private key must never exist in plaintext outside the HSM, even during backup, and that restoration must be possible after a total device failure. Which approach BEST satisfies these requirements?

A.Configure the HSM to back up the key material using its secure backup mechanism to at least two geographically separate HSMs.
B.Store the key on the HSM and replicate it to a spare HSM using the vendor's plaintext export option, then destroy the source.
C.Encrypt the private key with AES-256 in software and store the ciphertext on a hardened file server accessible only to administrators.
D.Export the private key wrapped under a key-encryption key, store the wrapped blob on encrypted network storage, and re-import it after failure.
AnswerA

Many HSMs support cloning or secure backup where the key is transferred between devices in a wrapped, hardware-protected form and never exists as a recoverable plaintext blob. Storing the backup on a second, geographically separate HSM preserves availability after device failure while keeping the private key inside certified hardware boundaries, satisfying both the no-plaintext and restoration requirements.

Why this answer

The only approach that keeps the private key inside a hardware-protected boundary while still allowing recovery is a vendor-supported secure backup or cloning mechanism between HSMs. Wrapping, plaintext export, and software encryption all allow the key to exist in a form that can be recovered outside certified hardware, which the scenario explicitly forbids.

Exam trap

The trap here is assuming that wrapping a key under a key-encryption key keeps it 'inside the HSM,' when in fact the wrapped blob is exportable and recoverable.

580
Multi-Selecteasy

Which TWO of the following are key components of a successful incident response plan according to NIST SP 800-61?

Select 2 answers
A.Vulnerability scanning
B.Preparation
C.Patch management
D.User training
E.Detection and Analysis
AnswersB, E

Preparation is a foundational phase of the incident response lifecycle.

Why this answer

NIST SP 800-61 defines the incident response lifecycle as having four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Preparation (Option B) is the foundational phase that ensures the organization has the tools, policies, and trained personnel ready before an incident occurs. Detection and Analysis (Option E) is the second phase, focusing on identifying and validating security incidents through monitoring, alerting, and forensic analysis.

Exam trap

The CAS-004 exam often tests the distinction between activities that are part of the incident response lifecycle phases versus supporting security processes, leading candidates to mistakenly select vulnerability scanning or patch management as core components when they are actually separate operational tasks.

581
MCQhard

Based on the exhibit, which security issue does this IAM policy represent?

A.No versioning configured
B.Overly permissive resource access
C.Missing server-side encryption
D.Insufficient logging and monitoring
AnswerB

The policy grants actions on a wildcard resource, so principals can reach every object of that type rather than only those required. This violates least privilege by broadening access far beyond the intended scope, exposing unrelated resources to unintended modification or disclosure.

Why this answer

The IAM policy in the exhibit uses a wildcard (`*`) in the `Resource` element, granting access to all resources within the account. This violates the principle of least privilege by allowing overly permissive resource access, which could lead to unauthorized data exposure or modification. The correct answer is B because the policy does not restrict actions to specific resources, making it a classic example of excessive permissions.

Exam trap

CompTIA often tests the distinction between IAM policy syntax errors and security misconfigurations, and the trap here is that candidates may confuse a missing `Version` field (which is optional in most cases) with a security issue, when the real problem is the wildcard resource.

How to eliminate wrong answers

Option A is wrong because versioning is an S3 bucket-level setting, not an IAM policy attribute; IAM policies do not have a versioning configuration, and the absence of a policy version ID does not represent a security issue. Option C is wrong because server-side encryption is a data-at-rest protection mechanism configured on storage services like S3 or EBS, not something enforced or missing in an IAM policy. Option D is wrong because insufficient logging and monitoring relates to services like CloudTrail or CloudWatch, not to the permissions defined in an IAM policy document.

582
MCQhard

An organization is implementing a privacy by design approach for a new customer-facing application. Which of the following actions best exemplifies this principle?

A.Adding a privacy notice to the application post-launch
B.Conducting a privacy impact assessment after the application is deployed
C.Minimizing data collection to only what is necessary for the application's function
D.Encrypting data at rest and in transit
AnswerC

Privacy by design mandates data minimisation: collecting only what the application's function requires limits exposure and compliance risk at source. This is a structural safeguard embedded in design, unlike consent notices or retention policies applied after collection.

Why this answer

Privacy by design, codified in GDPR Article 25 as 'data protection by design and by default,' requires privacy to be embedded into systems from the outset. Data minimization — collecting only what is strictly necessary for the stated purpose — is a foundational PbD principle because it reduces the attack surface, limits breach impact, and satisfies the 'by default' requirement. It is a design-time decision, not a post-hoc control.

Exam trap

CAS-005 often tests the distinction between design-time principles (minimization, default settings) and post-deployment controls (notices, encryption, PIAs) — candidates must pick the action that reflects embedding privacy into the design itself.

How to eliminate wrong answers

Option A is wrong because adding a privacy notice post-launch is a transparency measure applied after the fact, not a design principle embedded into the application. Option B is wrong because a PIA conducted after deployment is reactive — PbD requires the assessment during design, before deployment. Option D is wrong because encryption is a security control that protects data once collected; it does not exemplify PbD's core tenet of minimizing collection in the first place (encryption is a supporting control, not the defining PbD action).

583
Multi-Selecthard

A security engineer is implementing a secure software development lifecycle (SDLC) for a new application. The engineer needs to integrate security activities that help identify and mitigate vulnerabilities early in the development process. Which of the following activities should be included? (Choose two.)

Select 2 answers
A.Static application security testing (SAST) in the CI/CD pipeline.
B.Security awareness training for developers.
C.Penetration testing after production deployment.
D.Threat modeling during the design phase.
E.Dynamic application security testing (DAST) during the design phase.
AnswersA, D

SAST analyzes source code for vulnerabilities without executing it, enabling early detection of issues like SQL injection or buffer overflows. Integrating SAST into the CI/CD pipeline ensures continuous security checks. This helps developers fix flaws before deployment, reducing risk.

Why this answer

Threat modeling during design and SAST in the CI/CD pipeline are both early-stage activities that help identify and mitigate vulnerabilities before deployment. Threat modeling addresses design flaws, while SAST catches coding errors. Together, they shift security left and reduce remediation costs.

Exam trap

The trap here is selecting activities that are security-related but occur too late (like penetration testing) or are not directly vulnerability-identifying (like training).

584
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

A.Identify vulnerabilities and threats
B.Identify critical business processes and their impact if disrupted
C.Determine recovery time objectives (RTOs)
D.Develop continuity strategies
AnswerB

A BIA identifies the organisation's critical business processes and quantifies the operational and financial impact of disrupting each one, producing the recovery priorities and timeframes that drive continuity planning. That impact analysis is its primary purpose.

Why this answer

The primary purpose of a business impact analysis (BIA) is to identify critical business processes and quantify the operational and financial impact if they were disrupted. This foundational step determines which systems and functions are essential to the organization's survival, directly informing the selection of recovery strategies and objectives. Without a BIA, continuity planning lacks a data-driven basis for prioritizing resources.

Exam trap

The trap here is that candidates confuse the BIA's role as a data-gathering and analysis phase with the subsequent planning outputs (RTOs, strategies), leading them to select a downstream deliverable instead of the primary purpose.

How to eliminate wrong answers

Option A is wrong because identifying vulnerabilities and threats is the primary purpose of a risk assessment, not a BIA; a BIA focuses on impact to business processes, not the specific threats that could cause disruption. Option C is wrong because determining recovery time objectives (RTOs) is an output derived from the BIA's impact analysis, not the primary purpose itself; the BIA provides the data (e.g., maximum tolerable downtime) that allows RTOs to be set. Option D is wrong because developing continuity strategies is a subsequent phase that uses the BIA's findings (critical processes and impact tolerances) to design recovery plans, not the BIA's core goal.

585
MCQhard

An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?

A.Risk mitigation
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
AnswerD

Purchasing cyber insurance shifts the financial consequence of a data breach to an insurer rather than eliminating or reducing the risk itself. This is risk transfer, matching the treatment plan's intent to cover potential breach costs through a third party.

Why this answer

Purchasing cyber insurance transfers the financial consequences of a data breach to a third-party insurer, which is the definition of risk transfer. The organization does not eliminate the risk or reduce its likelihood — it shifts the monetary impact to another party. This is a classic example of risk transfer in risk treatment planning.

Exam trap

The trap here is confusing risk transfer with risk mitigation, as both involve taking action; candidates may think insurance reduces risk, but it only shifts financial impact.

How to eliminate wrong answers

Option A is wrong because risk mitigation involves implementing controls (e.g., firewalls, encryption) to reduce the likelihood or impact of a threat, not shifting financial responsibility. Option B is wrong because risk avoidance means discontinuing the activity that introduces the risk entirely (e.g., not storing sensitive data), which is not what insurance does. Option C is wrong because risk acceptance means acknowledging the risk and taking no action to transfer or mitigate it, often with a formal sign-off.

586
Multi-Selectmedium

A security architect is implementing a zero trust architecture for a corporate network. Which TWO principles are fundamental to the zero trust approach? (Choose two.)

Select 2 answers
A.Grant access based on network location
B.Assume implicit trust for internal users
C.Use a single perimeter firewall
D.Verify every access request regardless of source
E.Implement least privilege access
AnswersD, E

Zero trust treats network location as insufficient evidence of trust, so every access request is authenticated and authorised explicitly, regardless of whether it originates inside or outside the corporate perimeter. Continuous verification replaces the implicit trust granted by legacy castle-and-moat designs.

Why this answer

Option D is correct because zero trust requires that every access request be authenticated and authorized explicitly, regardless of whether it originates inside or outside the traditional network perimeter—no user or device is trusted by default. Option E is correct because least privilege access is a core zero trust principle, granting users and devices only the minimum permissions needed for their tasks and limiting lateral movement if credentials are compromised. Options A, B, and C are incorrect because they reflect perimeter-based, castle-and-moat security models: granting access by network location, assuming implicit trust for internal users, and relying on a single perimeter firewall all contradict zero trust's 'never trust, always verify' philosophy.

Exam trap

CAS-005 often tests the misconception that zero trust is about strengthening the perimeter or trusting internal users more; the trap is confusing traditional perimeter security (like firewalls) with zero trust principles, leading candidates to select options that reinforce implicit trust or location-based access.

587
MCQmedium

An organization is implementing a risk management framework and wants to align with a standard that emphasizes a continuous, iterative process for identifying, assessing, and responding to risk. Which framework is most appropriate?

A.FAIR
B.ISO 27005
C.COBIT
D.NIST RMF
AnswerD

The NIST Risk Management Framework prescribes a continuous, iterative cycle — Prepare, Categorise, Select, Implement, Assess, Authorise and Monitor — so risk identification, assessment and response recur throughout the system lifecycle rather than as a one-off exercise.

Why this answer

The NIST Risk Management Framework (RMF) is explicitly designed as a continuous, iterative process for identifying, assessing, and responding to risk. It consists of six steps: Categorize, Select, Implement, Assess, Authorize, and Monitor, which are repeated throughout the system lifecycle. This aligns perfectly with the requirement for a continuous, iterative approach.

ISO 27005 provides guidelines for risk management but is not as prescriptive about the continuous process as NIST RMF. FAIR is a quantitative risk analysis methodology, and COBIT is a governance framework for IT management, not specifically a risk management framework with a continuous iterative process.

Exam trap

CAS-005 often tests the distinction between risk management frameworks and risk analysis methodologies, causing candidates to confuse FAIR (quantitative analysis) with a full framework like NIST RMF.

How to eliminate wrong answers

Option A is wrong because FAIR (Factor Analysis of Information Risk) is a quantitative risk analysis model, not a comprehensive risk management framework with a continuous iterative process. Option B is wrong because ISO 27005 provides risk management guidelines but does not emphasize a continuous, iterative process to the same extent as NIST RMF; it is more about the risk management process itself. Option C is wrong because COBIT is an IT governance framework that includes risk management as one component, but it is not primarily a risk management framework focused on continuous iterative risk identification, assessment, and response.

588
MCQmedium

A vulnerability management team is prioritizing patches for a set of critical vulnerabilities. Vulnerability A has a CVSS base score of 9.8, vulnerability B has a CVSS base score of 7.5, and vulnerability C has a CVSS base score of 8.2. However, vulnerability B is actively being exploited in the wild, while the others are not. Which vulnerability should be patched first according to best practices?

A.All three should be patched simultaneously
B.Vulnerability B because it is actively exploited
C.Vulnerability C because it has a higher base score than B
D.Vulnerability A because it has the highest base score
AnswerB

CVSS base scores measure intrinsic severity only, not real-world threat. Exploit availability and active exploitation are captured by temporal and threat metrics, which raise actual risk. Since B is being exploited in the wild, it poses immediate likelihood of compromise, so best practise prioritises it over higher-scoring but unexploited flaws.

Why this answer

Vulnerability B should be patched first because it is actively being exploited in the wild. While CVSS base scores indicate severity, active exploitation means the vulnerability poses an immediate and real threat. Best practices prioritize vulnerabilities with known exploits, especially those used in active attacks, over higher-scored but unexploited ones.

Exam trap

The trap is focusing solely on CVSS scores and ignoring the critical factor of active exploitation, which should override base score in prioritization.

How to eliminate wrong answers

Option A is wrong because patching all simultaneously may not be feasible and ignores prioritization based on risk; it also does not address the immediate threat of active exploitation. Option C is wrong because vulnerability C has a higher base score than B, but it is not actively exploited, so it is less urgent than B. Option D is wrong because vulnerability A has the highest base score, but without active exploitation, it is less urgent than B, which is being exploited.

589
MCQmedium

A security analyst is reviewing the following command executed on a Linux server: 'nmap -sS -Pn -p 80,443 192.168.1.0/24'. Which of the following BEST describes the purpose of this command?

A.Perform a ping sweep to identify live hosts on the subnet, then scan ports 80 and 443
B.Perform a TCP connect scan on all ports across the subnet, including host discovery
C.Perform a TCP SYN scan on ports 80 and 443 across the subnet, skipping host discovery
D.Perform a UDP scan on ports 80 and 443 across the subnet, skipping host discovery
AnswerC

The -sS flag initiates a TCP SYN scan (half-open scan), which is stealthy because it does not complete the TCP handshake. The -Pn flag disables host discovery (ping), treating all hosts as online. The -p 80,443 specifies ports 80 and 443. The target is the subnet 192.168.1.0/24. This command is used to quickly identify web servers on the network without performing a full port scan or host discovery, which can be noisy and slow.

Why this answer

The command uses -sS for a TCP SYN scan, -Pn to skip host discovery, and -p 80,443 to target specific ports. This is a common reconnaissance technique to quickly identify web servers on a subnet without the noise of a full port scan or host discovery. The other options misinterpret the flags or the scan type.

Exam trap

The trap here is confusing -Pn (skip host discovery) with -sn (ping sweep), and -sS (SYN scan) with -sT (connect scan).

590
Multi-Selecthard

A security architect is designing a microservices-based application deployed on containers in a Kubernetes cluster. The architect needs to implement controls that protect the application from lateral movement in case a container is compromised. Which TWO of the following controls best achieve this goal? (Choose two.)

Select 2 answers
A.Use a service mesh to enforce mutual TLS (mTLS) between all services and apply authorization policies based on service identity.
B.Enable role-based access control (RBAC) for the Kubernetes API and grant each service account the minimum permissions required.
C.Implement network policies that deny all ingress and egress traffic by default and allow only explicitly required communication between specific pods.
D.Store all application secrets in environment variables within the container images to simplify deployment.
E.Run all containers as privileged to ensure they have the necessary permissions to perform their functions.
AnswersA, C

A service mesh with mutual TLS authenticates and encrypts all service-to-service communication, and authorization policies can restrict which services are allowed to talk to each other based on identity. If a container is compromised, the attacker cannot impersonate another service or communicate with services that are not explicitly authorized, which significantly limits lateral movement. This is a strong control for microservices environments.

Why this answer

Default-deny network policies restrict pod-to-pod traffic to only what is explicitly allowed, and a service mesh with mutual TLS and authorization policies enforces identity-based communication between services. Together, these controls limit an attacker's ability to move laterally from a compromised container. RBAC, privileged containers, and secrets in environment variables do not prevent network-based lateral movement and may even increase risk.

Exam trap

The trap here is assuming that any security control, such as RBAC, automatically prevents lateral movement, when in fact lateral movement is primarily a network communication issue that requires network segmentation or service mesh authorization.

591
MCQhard

A DevOps team is implementing a CI/CD pipeline for a Java application. They want to ensure that all dependencies are scanned for known vulnerabilities before deployment. Which type of tool should they integrate into the pipeline?

A.Static Application Security Testing (SAST)
B.Dynamic Application Security Testing (DAST)
C.Software Composition Analysis (SCA)
D.Interactive Application Security Testing (IAST)
AnswerC

Why this answer

Software Composition Analysis (SCA) is the correct tool because it specifically analyzes open-source and third-party libraries (dependencies) for known vulnerabilities by cross-referencing them against databases like the National Vulnerability Database (NVD). In a CI/CD pipeline for a Java application, SCA tools (e.g., OWASP Dependency-Check, Snyk) scan build artifacts such as pom.xml or build.gradle to identify vulnerable components before deployment.

Exam trap

The CAS-004 exam often tests the distinction between SAST (source code analysis) and SCA (dependency analysis), so the trap here is that candidates mistakenly choose SAST because they think 'static' covers all pre-deployment scanning, but SAST does not analyze third-party libraries.

Why the other options are wrong

A

SAST analyzes source code for security flaws, not third-party libraries.

B

DAST tests running applications for vulnerabilities, not dependencies.

D

IAST combines SAST and DAST but still focuses on custom code, not dependencies.

592
Multi-Selecthard

A security analyst is reviewing cryptographic implementations for a new application. The application needs to support digital signatures that are quantum-resistant and provide high performance. Which TWO algorithms should the analyst consider? (Select TWO.)

Select 2 answers
A.Ed25519
B.XMSS (eXtended Merkle Signature Scheme)
C.ECDSA P-384
D.BLAKE3
E.CRYSTALS-Dilithium
AnswersB, E

XMSS is a stateful hash-based signature scheme whose security rests solely on hash-function collision resistance, so it resists quantum attacks via Shor's algorithm. It satisfies the quantum-resistance requirement while signing and verifying quickly, meeting the high-performance constraint. Its stateful nature, however, demands careful key-state management to prevent reuse of a one-time key.

Why this answer

XMSS (eXtended Merkle Signature Scheme) (B) is correct because it is a hash-based, post-quantum digital signature scheme standardized in NIST SP 800-208, whose security relies only on hash function properties and is therefore resistant to Shor's algorithm attacks from quantum computers. CRYSTALS-Dilithium (E) is correct because it is a lattice-based post-quantum digital signature algorithm selected by NIST (FIPS 204) that offers strong quantum resistance with efficient signing and verification performance, making it well suited for high-performance applications. Ed25519 (A) is not correct because it is an elliptic-curve signature scheme (EdDSA over Curve25519) that is vulnerable to quantum attacks via Shor's algorithm.

ECDSA P-384 (C) is not correct for the same reason: it is a classical elliptic-curve signature algorithm, not quantum-resistant. BLAKE3 (D) is not correct because it is a cryptographic hash function, not a digital signature algorithm, so it cannot fulfill the digital signature requirement.

593
MCQhard

During a security review, you find that a web application uses a Content Security Policy (CSP) header with the value: 'default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.example.com;'. Which attack is the application still vulnerable to?

A.Cross-site request forgery (CSRF)
B.Cross-site scripting (XSS) via inline script injection
C.SQL injection
D.Man-in-the-middle (MITM) attack due to CDN inclusion
AnswerB

Why this answer

The CSP includes 'unsafe-inline' in the script-src directive, which explicitly allows inline scripts. This bypasses the primary protection CSP offers against XSS, as an attacker can inject malicious JavaScript directly into the HTML (e.g., via a <script> tag or event handler) without violating the policy. The 'self' source only restricts external scripts to the same origin, but inline scripts remain permitted, leaving the application vulnerable to stored, reflected, or DOM-based XSS attacks.

Exam trap

The CAS-004 exam often tests the misconception that CSP alone prevents all XSS, but the trap here is that 'unsafe-inline' explicitly disables CSP's inline script protection, making XSS via script injection still possible despite the policy.

Why the other options are wrong

A

CSP does not directly prevent CSRF; CSRF is mitigated by anti-CSRF tokens.

C

CSP is a browser-side security mechanism and does not prevent server-side SQL injection.

D

The CDN is over HTTPS, so MITM is not the primary vulnerability; 'unsafe-inline' is the issue.

594
MCQhard

A security team is hardening a Kubernetes cluster. Which control should be implemented to restrict a container's system calls to only those required by the application?

A.Seccomp
B.AppArmor
C.Network policies
D.Pod security policies
AnswerA

Seccomp profiles filter the syscalls a container may invoke, blocking everything outside an explicit allowlist. This directly satisfies the stem's requirement to restrict system calls to only those the application needs, unlike AppArmor or SELinux, which enforce mandatory access control over file paths, network ports and capabilities rather than the syscall interface itself.

Why this answer

Seccomp (secure computing mode) is a Linux kernel feature that filters the system calls a process can make, using a BPF-based profile to allow or deny specific syscalls. In Kubernetes, seccomp profiles are applied via the securityContext.seccompProfile field (or the older seccomp.security.alpha.kubernetes.io/pod annotation), restricting a container to only the syscalls its application requires. This directly matches the requirement to limit a container's system calls.

Exam trap

CAS-005 often tests the confusion between seccomp (syscall filtering) and AppArmor/SELinux (mandatory access control on files and capabilities), so candidates who see 'restrict' and pick AppArmor miss the syscall-specific wording.

How to eliminate wrong answers

Option B is wrong because AppArmor enforces mandatory access control on file paths, network access, and capabilities via per-program profiles, but it does not filter system calls by number the way seccomp does. Option C is wrong because Network policies operate at L3/L4 to control pod-to-pod ingress and egress traffic, not the syscall surface of a container process. Option D is wrong because Pod security policies (deprecated in Kubernetes 1.21 and removed in 1.25, replaced by Pod Security Admission) governed pod-level settings like privileged mode and volume types, not syscall filtering.

595
Multi-Selecthard

A security analyst is reviewing a packet capture (PCAP) from a suspected command-and-control (C2) channel. The analyst observes periodic outbound connections to an external IP address over TCP port 443. The traffic is encrypted with TLS, but the analyst suspects it may be malicious. Which TWO of the following techniques would be MOST effective to identify the malicious nature of the traffic without decrypting the payload? (Choose two.)

Select 2 answers
A.Examine the packet sizes and timing intervals for patterns.
B.Run a vulnerability scanner against the external IP address.
C.Perform deep packet inspection (DPI) to examine the payload contents.
D.Analyze the TLS certificate presented by the external server for anomalies.
E.Decrypt the TLS traffic using the server's public key.
AnswersA, D

Even with encryption, the size and timing of packets can reveal patterns. C2 channels often exhibit regular beaconing intervals, consistent packet sizes, or specific request-response patterns. Analyzing these metadata can indicate automated malicious communication. This technique is effective because it does not require payload decryption and can be automated in network monitoring tools.

Why this answer

Analyzing the TLS certificate can reveal anomalies like self-signed or expired certificates, which are common in malicious C2 infrastructure. Examining packet sizes and timing intervals can expose beaconing patterns typical of automated C2 communication. Both techniques work without decrypting the payload.

Deep packet inspection requires decryption, using the public key for decryption is impossible, and vulnerability scanning does not analyze the traffic itself.

Exam trap

The trap here is assuming that deep packet inspection can reveal encrypted payload contents without decryption, or that the server's public key can decrypt TLS traffic.

596
MCQhard

A security manager at a defense contractor is reviewing the organization's risk register. A critical vulnerability in a widely used open-source library has been identified. The vendor has not released a patch, and the library is embedded in a custom application that cannot be easily replaced. The manager decides to implement a virtual patching solution at the network perimeter. Which risk treatment strategy does this represent?

A.Risk transfer
B.Risk mitigation
C.Risk avoidance
D.Risk acceptance
AnswerB

Virtual patching reduces the likelihood or impact of exploitation by blocking attack vectors, even without a vendor patch. This is a form of risk mitigation because it lowers the risk to an acceptable level through compensating controls. It does not eliminate the vulnerability but manages it effectively.

Why this answer

Virtual patching is a compensating control that reduces the likelihood of exploitation by filtering malicious traffic. Since the underlying vulnerability remains but its risk is lowered, this is risk mitigation. Transfer, acceptance, and avoidance do not involve actively reducing the risk through controls, making mitigation the correct classification.

Exam trap

The trap here is confusing virtual patching with risk transfer, because a third-party tool is used, but the risk remains with the organization.

597
MCQmedium

A company is implementing a secure software development lifecycle (SDLC). The security architect wants to ensure that vulnerabilities are identified early in the development process and that developers receive immediate feedback. Which of the following should be integrated into the CI/CD pipeline?

A.Static application security testing (SAST) integrated into the build process.
B.Interactive application security testing (IAST) run manually by the security team quarterly.
C.Software composition analysis (SCA) performed only before major releases.
D.Dynamic application security testing (DAST) run after deployment to production.
AnswerA

SAST analyzes source code or binaries for vulnerabilities without executing the application. Integrating it into the build process allows developers to receive immediate feedback on security issues as they commit code. This shifts security left, enabling early remediation and reducing the cost of fixes. SAST is ideal for identifying issues like SQL injection and cross-site scripting early in the SDLC.

Why this answer

Integrating SAST into the build process enables automated security testing on every code commit, providing immediate feedback to developers. This shifts security left, allowing vulnerabilities to be found and fixed early when they are cheaper and easier to remediate. SAST is well-suited for CI/CD pipelines because it does not require a running application and can be triggered automatically.

Exam trap

The trap here is confusing different types of security testing and their appropriate stages in the SDLC.

598
MCQeasy

A web application generates an Ansible playbook from user input as shown. What is the primary security risk?

A.The application is vulnerable to SQL injection.
B.The user input could be crafted to execute arbitrary Ansible modules.
C.The application is vulnerable to LDAP injection.
D.The playbook may fail to run if input contains special characters.
AnswerB

Crafted input can inject arbitrary Ansible module calls into the generated playbook, since Ansible executes whatever modules the YAML specifies. This directly satisfies the stem's constraint: untrusted user input flows into playbook generation without validation, enabling remote code execution on managed hosts under the automation controller's privileges.

Why this answer

The application directly incorporates user input into an Ansible playbook without sanitization or validation. An attacker can inject arbitrary YAML or Ansible module directives (e.g., `shell`, `command`, `raw`) to execute unauthorized commands on managed hosts. This is a classic injection vulnerability specific to automation frameworks, not a generic injection type.

Exam trap

CompTIA CASP+ often tests the distinction between generic injection types (SQL, LDAP) and technology-specific injection (Ansible modules, PowerShell, Terraform HCL), so candidates mistakenly choose a familiar injection type instead of recognizing the automation framework context.

How to eliminate wrong answers

Option A is wrong because SQL injection requires the input to be embedded in a SQL query string, but the context shows YAML/Ansible playbook generation, not database interaction. Option C is wrong because LDAP injection targets LDAP query syntax (e.g., filters like `(&(uid=*)(userPassword=*))`), which is irrelevant to Ansible playbook generation. Option D is wrong because while special characters might cause syntax errors, the primary security risk is arbitrary code execution via module injection, not mere playbook failure.

599
MCQmedium

A security administrator is configuring a Linux server to enforce mandatory access control (MAC) for a web application. The administrator wants to confine the web server process to only access its own files and network ports, even if the process is compromised. Which of the following should the administrator implement?

A.A chroot jail for the web server process.
B.AppArmor in complain mode.
C.SELinux in enforcing mode with a targeted policy.
D.Standard Linux discretionary access control (DAC) with file permissions.
AnswerC

SELinux in enforcing mode applies mandatory access control, restricting processes to only the resources defined in the policy. A targeted policy confines specific services like the web server, limiting the impact of a compromise. This meets the requirement to confine the web server process even if exploited.

Why this answer

SELinux in enforcing mode applies mandatory access control, restricting processes to only the resources defined in the policy. A targeted policy confines specific services like the web server, limiting the impact of a compromise. This meets the requirement to confine the web server process even if exploited.

Exam trap

The trap here is confusing AppArmor's complain mode with enforce mode, or thinking that DAC or chroot provides mandatory access control.

600
MCQeasy

Which of the following is a key benefit of using an Extended Detection and Response (XDR) solution over traditional Endpoint Detection and Response (EDR)?

A.XDR only works with a single vendor's products
B.XDR eliminates the need for SIEM and SOAR systems
C.XDR only focuses on network traffic analysis
D.XDR provides centralized visibility across multiple security layers including endpoints, network, and cloud
AnswerD

XDR natively ingests and correlates telemetry from endpoints, network, cloud and identity into one console, satisfying the stem's cross-layer visibility requirement. EDR's scope stops at the endpoint agent, so it cannot surface network or cloud signals. This broader correlation is the defining architectural difference between the two.

Why this answer

XDR extends detection beyond endpoints to include network, email, cloud, and other data sources, providing broader visibility and correlation across the entire environment.

Page 7

Page 8 of 13

Page 9