Courseiva

CompTIA SecurityX (CAS-005) (CAS-005) — Questions 601–675

973 questions total · 13pages · All types, answers revealed

Page 8

Page 9 of 13

Page 10
601
MCQeasy

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?

A.Data classification and encryption
B.Physical security of data centers
C.Network infrastructure security
D.Hypervisor security
AnswerA

Data classification and encryption remain customer responsibilities because the provider cannot determine sensitivity or manage keys without the tenant's context. In the shared responsibility model, the customer always owns data governance, including classifying information and controlling encryption keys, while Microsoft Entra ID and the underlying infrastructure stay with the provider.

Why this answer

In the shared responsibility model for cloud security, the customer is always responsible for the security of their data, including classification and encryption. This includes determining data sensitivity, applying appropriate encryption at rest and in transit, and managing encryption keys. The cloud provider is responsible for security of the cloud (physical, network, hypervisor), while the customer is responsible for security in the cloud.

Exam trap

CAS-005 often tests the shared responsibility model by presenting responsibilities that seem like they could be either party's. The trap is assuming the provider handles data encryption because they offer encryption tools, but the customer must still configure and manage it.

How to eliminate wrong answers

Option B is wrong because physical security of data centers is always the responsibility of the cloud provider, as customers have no access to or control over the physical infrastructure. Option C is wrong because network infrastructure security (e.g., routers, switches, physical network) is managed by the cloud provider under the shared responsibility model. Option D is wrong because hypervisor security is part of the virtualization layer managed by the cloud provider; customers do not have access to the hypervisor in public cloud environments.

602
Multi-Selecthard

A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?

Select 3 answers
A.Network segmentation
B.Dependency analysis
C.Container image scanning
D.Runtime application self-protection
E.Software Bill of Materials (SBOM)
AnswersB, C, E

Dependency analysis inspects third-party libraries and transitive packages for known CVEs before they enter the build, directly satisfying the supply chain security requirement. It catches vulnerable or malicious components at the point of integration, preventing compromised dependencies from reaching production artefacts.

Why this answer

Dependency analysis (B) is correct because it inspects third-party libraries and transitive dependencies for known CVEs (e.g., via SCA tools like OWASP Dependency-Check, Snyk, or Trivy) before artifacts are built, directly protecting the software supply chain from vulnerable or malicious packages. Container image scanning (C) is correct because it examines image layers and installed packages against vulnerability databases (e.g., Clair, Trivy, Grype) so compromised base images or components are caught in the CI/CD pipeline before deployment. Software Bill of Materials (E) is correct because an SBOM (e.g., SPDX or CycloneDX format) provides a machine-readable inventory of components and dependencies, enabling provenance tracking, rapid impact analysis when new CVEs emerge, and compliance with supply chain mandates.

Network segmentation (A) is a runtime infrastructure control that limits lateral movement but does not secure the build and delivery pipeline itself, and runtime application self-protection (D) is a runtime defense that detects and blocks attacks in a running application, not a CI/CD supply chain practice.

Exam trap

CAS-005 often tests the specific practices that directly address supply chain security versus general security controls. Candidates may select network segmentation or RASP because they sound security-related, but they do not address supply chain risks in the CI/CD pipeline.

603
MCQhard

An organization's business continuity plan (BCP) includes a recovery time objective (RTO) of 4 hours for its critical ERP system. During a disaster, the system is restored in 5 hours. Which of the following is the MOST significant impact?

A.Unacceptable business downtime and potential contractual penalties
B.Need to reroute network traffic to the DR site
C.Higher cost for cyber insurance premiums
D.Increased recovery point objective (RPO) for the last backup
AnswerA

Exceeding the four-hour RTO by one hour means the ERP system was unavailable beyond the maximum tolerable outage the business agreed, so operations and contractual service commitments were breached. The impact is measured against the RTO constraint itself, not the recovery cost or data loss.

Why this answer

The RTO of 4 hours defines the maximum acceptable downtime for the ERP system. Restoring it in 5 hours exceeds this threshold, resulting in unacceptable business downtime. This can trigger contractual penalties if service-level agreements (SLAs) specify a 4-hour RTO, as the organization failed to meet its recovery commitment.

Exam trap

CompTIA often tests the distinction between RTO and RPO, where candidates confuse exceeding the RTO with affecting the RPO, but the trap here is that the most significant impact is the business downtime and contractual penalties, not the technical recovery steps or insurance costs.

How to eliminate wrong answers

Option B is wrong because rerouting network traffic to the DR site is a standard operational step during disaster recovery and does not represent the most significant impact; it is a procedural action, not a consequence of missing the RTO. Option C is wrong because cyber insurance premiums are influenced by overall risk posture and claims history, not by a single RTO miss; the direct impact is operational and contractual, not an immediate premium increase. Option D is wrong because the recovery point objective (RPO) is a separate metric defining acceptable data loss (e.g., time between backups), and exceeding the RTO does not inherently change the RPO; the RPO remains defined by the backup schedule, not the restoration time.

604
MCQhard

A security analyst is investigating a potential data exfiltration incident. Network logs show a large volume of outbound traffic from an internal database server to an unfamiliar external IP address over port 443. The traffic occurs daily at 02:00 and lasts for exactly 15 minutes. The analyst suspects the use of a covert channel. Which of the following techniques is the analyst MOST likely observing?

A.Scheduled data transfer using a covert channel over HTTPS
B.DNS tunneling
C.ICMP exfiltration
D.Domain fronting
AnswerA

The traffic is outbound on port 443 (HTTPS), occurs at a fixed time daily, and lasts a consistent duration. This pattern suggests an automated, scheduled exfiltration using a covert channel that blends with normal HTTPS traffic. The use of port 443 helps evade detection that focuses on non-standard ports, and the regularity indicates a scripted task rather than interactive user activity.

Why this answer

The combination of HTTPS (port 443), a fixed daily schedule, and a consistent short duration strongly suggests an automated exfiltration script using a covert channel that mimics legitimate web traffic. This method allows data to leave the network without raising alarms based on port or protocol anomalies. The unfamiliar external IP and the database server as the source further point to a compromised host exfiltrating data via an encrypted channel.

Exam trap

The trap here is focusing on the term 'covert channel' and jumping to DNS tunneling or ICMP, when the port and traffic pattern clearly indicate HTTPS-based exfiltration.

605
Multi-Selecteasy

A security architect is reviewing firewall rules for a new application tier. Which TWO of the following principles should be applied when designing the firewall policy? (Choose two.)

Select 2 answers
A.Log all denied traffic
B.Use static IP addresses for all servers
C.Implement stateful packet inspection
D.Default allow all traffic
E.Allow only necessary ports and protocols
AnswersC, E

Stateful inspection tracks connection state, automatically permitting return traffic for established sessions while blocking unsolicited inbound packets. This satisfies the firewall-policy design constraint by enforcing bidirectional flow control without separate reverse rules for every permitted service.

Why this answer

Allowing only necessary ports and protocols (E) implements least privilege, and implementing stateful packet inspection (C) enables intelligent traffic filtering. Default allow (D) is insecure, static IPs (B) are not a design principle, and logging (A) is operational, not a design principle.

606
MCQhard

A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?

A.CRYSTALS-Dilithium
B.SPHINCS+
C.Falcon
D.CRYSTALS-Kyber
AnswerD

CRYSTALS-Kyber is the NIST-standardised key encapsulation mechanism (ML-KEM, FIPS 203), built on module learning-with-errors. It satisfies the stem's requirement for a PQC KEM candidate by enabling two parties to establish a shared symmetric key over a public channel, unlike CRYSTALS-Dilithium, which is a digital signature scheme.

Why this answer

CRYSTALS-Kyber is the NIST-standardized algorithm for key encapsulation (KEM), selected in the post-quantum cryptography standardization process. It is designed for secure key exchange and is efficient for both client and server. NIST selected Kyber as the primary KEM standard (FIPS 203).

Exam trap

The trap is mixing up KEM and digital signature algorithms — candidates may pick Dilithium or Falcon because they are also NIST PQC standards, but only Kyber is a KEM.

How to eliminate wrong answers

Option A is wrong because CRYSTALS-Dilithium is a digital signature algorithm, not a KEM. Option B is wrong because SPHINCS+ is a stateless hash-based signature scheme, not a KEM. Option C is wrong because Falcon is a lattice-based digital signature algorithm, not a KEM.

607
MCQeasy

Which of the following is the primary purpose of a honeypot in a security operations environment?

A.To encrypt sensitive data at rest
B.To replace the need for traditional firewalls
C.To block malicious traffic at the network perimeter
D.To provide early detection of unauthorized activity
AnswerD

A honeypot is a decoy system with no legitimate production role, so any interaction with it is inherently suspicious. This lets the SOC detect unauthorised activity early, before attackers reach real assets, satisfying the requirement for early warning rather than prevention or attribution.

Why this answer

A honeypot is a decoy system designed to attract and detect attackers. Its primary purpose is to provide early detection of unauthorized activity by luring attackers away from real systems and alerting security teams to their presence and methods.

Exam trap

CAS-005 often tests the misconception that honeypots are preventive controls like firewalls, when they are actually detective controls focused on early warning and intelligence gathering.

How to eliminate wrong answers

Option A is wrong because encryption of sensitive data at rest is a data protection measure, not the purpose of a honeypot. Option B is wrong because honeypots do not replace firewalls; they are complementary tools for detection, not prevention. Option C is wrong because blocking malicious traffic at the perimeter is the role of firewalls and intrusion prevention systems, not honeypots, which are designed to monitor and deceive.

608
MCQmedium

A security analyst receives an alert from the SIEM indicating multiple failed logon attempts from an external IP address followed by a successful logon for a domain admin account. Which phase of the incident response lifecycle is the analyst currently in?

A.Lessons learned
B.Containment
C.Detection
D.Preparation
AnswerC

Detection covers monitoring and identifying security events, so receiving and triaging the SIEM alert places the analyst squarely in this phase. The failed logons followed by a successful domain admin logon constitute the indicator being detected, before any containment, eradication or recovery activity begins.

Why this answer

The analyst is in the Detection phase because they are analyzing an alert from the SIEM indicating suspicious activity. Detection involves monitoring and identifying potential security incidents through alerts, logs, and other tools. The analyst has not yet moved to containment or other phases; they are still assessing the alert.

Exam trap

CAS-005 often tests the confusion between Detection and Containment; candidates may think that receiving an alert means they are already containing, but containment requires active steps to limit damage.

How to eliminate wrong answers

Option A is wrong because Lessons Learned occurs after an incident is resolved, to improve future response. Option B is wrong because Containment involves taking action to stop the spread of an incident, which has not happened yet. Option D is wrong because Preparation involves establishing plans and capabilities before an incident occurs, not responding to an alert.

609
MCQeasy

A security analyst is reviewing a Kubernetes cluster's security configuration. Which component should be used to ensure that only authorized pods can communicate with each other?

A.Pod Security Policies (PSP)
B.Seccomp profiles
C.Network Policies
D.RBAC roles
AnswerC

Network Policies enforce pod-level ingress and egress rules, restricting traffic to explicitly authorised pod selectors within the cluster. This directly satisfies the requirement that only authorised pods communicate, since default Kubernetes networking permits all pod-to-pod traffic. Unlike service mesh or firewall controls, Network Policies operate at layer 3/4 using label selectors native to the cluster.

Why this answer

Network Policies in Kubernetes are the native mechanism for controlling pod-to-pod traffic. They use label selectors to define which pods can communicate with which other pods on specified ports and protocols, effectively acting as a firewall at the pod level. Without a Network Policy, all pods in a cluster can communicate freely by default, so applying one is the correct way to restrict east-west traffic to only authorized flows.

Exam trap

The trap here is conflating 'pod security' with 'network security' — candidates see 'authorized pods' and reach for PSP or RBAC, but authorization in the network sense means Network Policies, not admission control or API authorization.

How to eliminate wrong answers

Option A is wrong because Pod Security Policies (deprecated in Kubernetes 1.21, replaced by Pod Security Admission) govern pod-level security settings like privileged mode, host networking, and volume types — they do not control network communication between pods. Option B is wrong because Seccomp profiles restrict which Linux system calls a containerized process can make, addressing syscall-level attack surface, not network reachability. Option D is wrong because RBAC roles control which users or service accounts can perform API operations against the Kubernetes API server (authorization), not whether pod A can open a TCP connection to pod B.

610
MCQhard

A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?

A.Software-based key management system
B.Hardware security module
C.Cloud KMS
D.TPM
AnswerB

A hardware security module provides tamper-resistant, FIPS 140-2 Level 3 validated hardware that generates and stores cryptographic keys internally, preventing extraction. This satisfies the requirement to protect signing keys for financial transactions with physical tamper resistance.

Why this answer

A Hardware Security Module (HSM) is a dedicated physical appliance that generates, stores, and protects cryptographic keys inside a tamper-resistant boundary. FIPS 140-2 Level 3 requires physical tamper-resistance, identity-based authentication, and key zeroization on intrusion — capabilities that only validated hardware appliances like HSMs deliver. HSMs are the standard for signing high-value financial transactions because private keys never leave the cryptographic boundary in plaintext.

Exam trap

The trap here is conflating 'cloud KMS' with 'HSM' — candidates assume any managed key service is automatically FIPS 140-2 Level 3, when only HSM-backed offerings with dedicated hardware meet the tamper-resistance requirement.

How to eliminate wrong answers

Option A is wrong because software-based key management stores keys in memory or disk, which cannot satisfy FIPS 140-2 Level 3's physical tamper-resistance requirement. Option C is wrong because cloud KMS offerings are typically FIPS 140-2 Level 2 or Level 3 only when backed by dedicated HSM hardware — a generic cloud KMS service alone does not guarantee Level 3 tamper-resistant hardware. Option D is wrong because a TPM is a discrete chip bound to a single host, designed for platform integrity and disk encryption, not for high-throughput multi-party transaction signing or FIPS 140-2 Level 3 certification as a standalone module.

611
Multi-Selectmedium

A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?

Select 2 answers
A.Using long-lived access tokens to reduce authentication frequency
B.Enforcing short-lived access tokens with refresh token rotation
C.Encrypting JWT payloads with a symmetric key
D.Implementing token binding to bind tokens to a specific client session
E.Implementing rate limiting on the token endpoint
AnswersB, D

Short expiry limits the window in which an intercepted token remains usable, directly mitigating replay. Refresh token rotation invalidates the prior refresh token on each exchange, so a stolen refresh token is detected and rejected once the legitimate client rotates, satisfying the replay-resistance requirement.

Why this answer

Option B is correct because enforcing short-lived access tokens limits the window in which a stolen token can be replayed, and refresh token rotation invalidates the old refresh token each time a new one is issued, so a captured refresh token cannot be reused indefinitely. Option D is correct because token binding cryptographically ties an access or refresh token to a specific client session or TLS channel, so a token intercepted and replayed from a different session or connection will be rejected. Option A is wrong because long-lived access tokens increase the replay window and worsen the impact of interception.

Option C is wrong because encrypting JWT payloads provides confidentiality of claims but does not prevent an attacker who captures the token from replaying it. Option E is wrong because rate limiting on the token endpoint only mitigates brute-force or flooding attempts; it does not stop interception or replay of a valid token.

Exam trap

CAS-005 often tests the misconception that encrypting a JWT (JWE) prevents replay, when encryption only protects confidentiality — replay protection requires short lifetimes, rotation, or proof-of-possession binding.

612
MCQmedium

Refer to the exhibit. A security analyst notices that traffic from external clients to the web server at 10.0.0.10 port 80 is being blocked. Which of the following is the MOST likely cause?

A.The ACL lacks a log statement
B.The ACL is misordered (deny before permit)
C.The web server is using port 443
D.The destination IP is incorrect
AnswerB

ACLs process rules sequentially, so a deny statement placed above the matching permit blocks port 80 traffic before the permit is ever evaluated. The exhibit's external-to-10.0.0.10:80 flow satisfies the deny entry first, producing the observed block despite a valid permit existing lower in the list.

Why this answer

The ACL is misordered because Cisco ACLs process rules sequentially from top to bottom, and a 'deny any' statement placed before a 'permit' statement will block all traffic, including the desired web traffic to 10.0.0.10 port 80. Since the exhibit shows a deny statement preceding the permit, the permit is never evaluated, causing the block.

Exam trap

The trap here is that candidates focus on the ACL content (deny vs permit) rather than the order of entries, assuming that a permit statement anywhere in the ACL will allow traffic, when in fact the first matching rule determines the action.

How to eliminate wrong answers

Option A is wrong because the absence of a log statement does not cause traffic to be blocked; logging only records matches and does not affect the permit/deny action. Option C is wrong because the question specifies traffic to port 80, and even if the web server also uses port 443, the ACL is explicitly blocking port 80 traffic due to the misordered deny rule, not because of port mismatch. Option D is wrong because the destination IP 10.0.0.10 is correct for the web server; the issue is the ACL order, not an incorrect IP address.

613
MCQhard

A security engineer is reviewing a TLS 1.3 configuration. Which of the following is a key feature of TLS 1.3 that improves security compared to earlier versions?

A.Mandatory forward secrecy using ephemeral Diffie-Hellman
B.Support for RC4 cipher suite
C.Support for static RSA key exchange
D.Ability to downgrade to TLS 1.2
AnswerA

TLS 1.3 mandates ephemeral Diffie-Hellman key exchange for all cipher suites, so every session derives unique keys and compromise of the long-term key cannot decrypt past traffic. Earlier versions permitted static RSA key transport, which lacked this property.

Why this answer

TLS 1.3 mandates forward secrecy by requiring ephemeral Diffie-Hellman key exchange (DHE or ECDHE), which ensures that session keys cannot be recovered even if the server's long-term private key is later compromised. This is a core security improvement over TLS 1.2, where static RSA key exchange was allowed and lacked forward secrecy.

Exam trap

CAS-005 often tests the misconception that TLS 1.3 supports legacy ciphers like RC4 or static RSA, when in fact it removed them and mandates forward secrecy.

How to eliminate wrong answers

Option B is wrong because RC4 is a broken stream cipher and was removed in TLS 1.3; it is not supported. Option C is wrong because static RSA key exchange was removed in TLS 1.3 precisely because it lacks forward secrecy. Option D is wrong because TLS 1.3 does not support downgrading to TLS 1.2; while a client and server can negotiate TLS 1.2 if both support it, TLS 1.3 itself does not include a downgrade mechanism, and the protocol is designed to prevent downgrade attacks.

614
Multi-Selecteasy

A company is implementing API security for its web services. Which THREE of the following are considered best practices for securing APIs? (Select THREE).

Select 3 answers
A.Rely solely on symmetric encryption for data at rest
B.Validate all input
C.Use WPA3 for transport encryption
D.Implement rate limiting
E.Use OAuth 2.0 for authorization
AnswersB, D, E

Validating all input defends against injection attacks such as SQL injection and cross-site scripting by rejecting malformed or malicious payloads before processing. This directly satisfies the requirement to secure web service APIs against untrusted client-supplied data.

Why this answer

Option B (Validate all input) is correct because input validation defends against injection attacks such as SQL injection and cross-site scripting (XSS) by ensuring data conforms to expected formats, types, and lengths before processing. Option D (Implement rate limiting) is correct because throttling requests per client or API key mitigates brute-force, credential-stuffing, and denial-of-service abuse, and protects backend resources from being overwhelmed. Option E (Use OAuth 2.0 for authorization) is correct because OAuth 2.0 provides delegated, token-based authorization with scoped access, allowing APIs to grant limited permissions without exposing user credentials.

Option A does not belong because relying solely on symmetric encryption for data at rest ignores transport security, key management, and other layers of defense. Option C does not belong because WPA3 is a Wi-Fi (802.11) security standard for wireless LANs, not a transport encryption mechanism for web APIs, which should use TLS.

Exam trap

CAS-005 often tests the confusion between encryption at rest and in transit, and between wireless security protocols (WPA3) and transport security (TLS), tricking candidates into selecting irrelevant or incomplete measures when asked for API security best practices.

615
MCQmedium

During a digital forensics investigation, an analyst needs to acquire the contents of RAM from a compromised server. Which order of volatility should the analyst follow?

A.Capture the swap file first, then RAM
B.Capture network connections first, then RAM
C.Capture the hard drive image first, then RAM
D.Capture RAM first, then the hard drive
AnswerD

RAM is volatile and lost on power-off, so it must be captured before the hard drive, which retains data persistently. This ordering follows the RFC 3227 volatility principle, satisfying the stem's requirement to acquire the most perishable evidence first.

Why this answer

The order of volatility (RFC 3227) dictates that the most volatile evidence be collected first: CPU registers and cache, then RAM, then swap/pagefile, then network state, then disk. RAM is far more volatile than disk, so it must be captured before the hard drive image. This preserves evidence like running processes, encryption keys, and network connections that vanish on power-off.

Exam trap

CAS-005 often tests the order of volatility — candidates pick 'hard drive first' because disk imaging is the most familiar forensic step, but the rule is always most-volatile-first, and RAM beats disk every time.

How to eliminate wrong answers

Option A is wrong because the swap file resides on disk and is less volatile than RAM — capturing it first violates the order of volatility and risks losing RAM contents. Option B is wrong because while network connections are volatile, they are captured as part of or alongside RAM acquisition (e.g., via netstat output saved to the forensic image), and the question asks for the correct overall order — RAM precedes disk, and network state is typically captured during live response before or with RAM, not as a separate first step ahead of RAM in this framing. Option C is wrong because imaging the hard drive first is the classic order-of-volatility violation — disk is the least volatile of the listed items, so doing it first destroys or overlooks the more volatile RAM evidence.

616
MCQeasy

A development team wants to deploy a microservices application using containers. They need a solution to automate the deployment, scaling, and management of the containers across a cluster. Which technology is most suitable?

A.VMware vSphere with container support.
B.Jenkins with Docker plugins.
C.Docker Compose with manual scaling.
D.Kubernetes with Helm charts.
AnswerD

Kubernetes provides the cluster-wide orchestration layer for scheduling, scaling and self-healing containers, while Helm charts package and version the microservices' manifests for repeatable automated deployment. Together they meet the automation, scaling and management requirements across the cluster.

Why this answer

Kubernetes is the de facto standard for container orchestration, providing automated deployment, scaling, and management of containerized applications across a cluster. Helm charts add package management, templating, and release versioning, which are essential for managing complex microservices deployments. Together, they directly address the requirement to automate deployment, scaling, and management across a cluster.

Exam trap

The trap here is confusing CI/CD tools (Jenkins) or single-host orchestration (Docker Compose) with full cluster orchestration, or assuming that virtualization platforms like vSphere provide native container orchestration; candidates must recognize that Kubernetes (often with Helm) is the dedicated solution for automated deployment, scaling, and management across a cluster.

How to eliminate wrong answers

Option A is wrong because VMware vSphere with container support (e.g., vSphere Integrated Containers or Tanzu) provides infrastructure for running containers but does not itself offer the full orchestration layer—automated scaling, self-healing, and service discovery—that Kubernetes does; it is often used to host Kubernetes rather than replace it. Option B is wrong because Jenkins is a CI/CD automation server, not a container orchestrator; Docker plugins allow building and pushing images, but Jenkins lacks native cluster scheduling, scaling, and lifecycle management for containers. Option C is wrong because Docker Compose is a tool for defining and running multi-container Docker applications on a single host, with no built-in clustering, automated scaling, or self-healing; manual scaling is not automation and does not work across a cluster.

617
MCQhard

An organization must satisfy a regulatory requirement to demonstrate that security controls operate effectively over time, not just that they are documented. The compliance manager proposes collecting screenshots of control configurations taken on the last day of each quarter. Which approach should the security manager recommend instead to provide stronger, continuous assurance?

A.Annual third-party penetration testing of the in-scope systems
B.A control self-assessment survey completed by each system owner twice a year
C.Quarterly screenshots retained with a documented review sign-off
D.Continuous control monitoring that ingests configuration and log data from the control systems
AnswerD

Continuous control monitoring automatically collects and evaluates configuration and log evidence from the systems enforcing each control, providing near-real-time assurance that controls operate as intended across the entire period. This directly answers the regulator's demand for evidence of sustained effectiveness and is far stronger than periodic screenshots that capture only a single moment.

Why this answer

The regulator wants proof that controls operate effectively over time, not merely that they were configured correctly on specific dates. Continuous control monitoring ingests live configuration and log data and evaluates it automatically, producing objective evidence across the full period. Penetration tests, quarterly screenshots, and semi-annual self-assessments all sample control state at isolated points and cannot demonstrate sustained operation.

Exam trap

The trap here is equating more frequent manual evidence collection with continuous assurance, when any periodic snapshot still leaves the gaps between captures unverified and unaudited.

618
MCQmedium

A PKI administrator is concerned about the risk of a compromised issuing CA. Which certificate transparency feature helps detect unauthorized certificate issuance?

A.Certificate Transparency logs
B.CRL distribution points
C.OCSP stapling
D.Key usage extensions
AnswerA

Certificate Transparency logs are append-only, publicly auditable records of issued certificates. Monitoring them reveals certificates issued for a domain without authorisation, so a compromised issuing CA's rogue certificates become detectable, satisfying the requirement to detect unauthorised issuance.

Why this answer

Certificate Transparency (CT) logs are append-only, publicly auditable logs where CAs must record every certificate they issue (per RFC 6962). Because monitors and browsers can detect certificates that appear in logs without a corresponding legitimate request, unauthorized or mis-issued certificates from a compromised issuing CA become visible. This is the specific mechanism designed to detect rogue issuance, not just validate or revoke certificates.

Exam trap

The trap here is confusing revocation-checking mechanisms (CRL, OCSP) with issuance-transparency mechanisms (CT logs); candidates often pick OCSP stapling because it sounds like the most 'modern' certificate security feature.

How to eliminate wrong answers

Option B is wrong because CRL distribution points only publish revocation status for certificates the CA has already revoked — they cannot reveal a certificate that was fraudulently issued and not yet reported. Option C is wrong because OCSP stapling is a real-time revocation-checking optimization where the server staples a signed OCSP response to the TLS handshake; it validates current status, not issuance transparency. Option D is wrong because key usage extensions are X.509 fields that constrain how a key may be used (e.g., digitalSignature, keyEncipherment) and have nothing to do with detecting unauthorized issuance.

619
MCQmedium

During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?

A.It provides assurance over the design and operating effectiveness of controls over a period.
B.It offers a snapshot of the vendor's security posture at a single point in time.
C.It provides a real-time vulnerability scan of the vendor's network.
D.It verifies the vendor's compliance with PCI DSS.
AnswerA

A SOC 2 Type II report covers an audit period, not a single point in time, so it evidences that controls were designed and actually operated effectively throughout that window. This lets the analyst judge sustained control performance rather than relying on a Type I snapshot.

Why this answer

A SOC 2 Type II report provides assurance over the design and operating effectiveness of a service organization's controls over a specified period, typically 3–12 months. This period-based testing distinguishes it from Type I, which only assesses design at a point in time. For vendor risk management, Type II gives the analyst evidence that controls actually operated effectively throughout the audit window.

Exam trap

CAS-005 often tests the Type I vs Type II distinction — candidates pick 'point-in-time snapshot' thinking it sounds rigorous, but that describes Type I, not Type II.

How to eliminate wrong answers

Option B is wrong because a point-in-time snapshot of security posture describes a SOC 2 Type I report, not Type II. Option C is wrong because SOC 2 is an attestation of controls, not a real-time vulnerability scan; it does not provide live network scanning data. Option D is wrong because SOC 2 is based on the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) and does not certify PCI DSS compliance — PCI DSS has its own ROC/SAQ process.

620
MCQmedium

A security analyst is investigating a potential insider threat. The analyst has access to logs from a Data Loss Prevention (DLP) system that flagged an employee for sending a large number of documents to a personal cloud storage account. The analyst needs to determine if this is a malicious exfiltration attempt or legitimate business activity. Which of the following actions should the analyst take FIRST?

A.Review the DLP alert details, including the file names, sizes, and destination, and compare with the employee's normal behavior.
B.Immediately disable the employee's account to prevent further data loss.
C.Escalate to the legal department to prepare for potential litigation.
D.Interview the employee's manager to ask if the employee is authorized to share documents externally.
AnswerA

Reviewing the alert details and comparing with the employee's baseline behavior helps determine if the activity is anomalous. This initial triage provides context to decide if further investigation or escalation is needed. It is non-disruptive and gathers evidence before taking action, which is the correct first step in incident response.

Why this answer

The first step in investigating a potential insider threat is to review the DLP alert details and compare them with the employee's normal behavior. This triage helps determine whether the activity is anomalous and warrants further investigation. It is non-disruptive and preserves the ability to gather additional evidence before taking any action that could alert the employee or disrupt business.

Exam trap

The trap here is jumping to containment actions like disabling the account or escalating to legal before confirming the activity is actually malicious.

621
MCQmedium

A SOC team is implementing a SOAR playbook to automate response to phishing emails reported by users. Which step should be included in the playbook to prevent other users from accessing the malicious link?

A.Isolate the reporter's workstation
B.Reset the reporter's password
C.Block the malicious URL in the web proxy
D.Delete the email from all mailboxes
AnswerC

A web proxy enforces URL filtering at the egress path, so adding the malicious URL to its blocklist stops any user from resolving or reaching that link. This satisfies the requirement to prevent other users accessing it, containing the campaign before further credentials or payloads are delivered.

Why this answer

Blocking the malicious URL in the web proxy prevents all users from accessing the phishing link, effectively containing the threat. This step is proactive and protects the entire organization, not just the reporter.

Exam trap

CAS-005 often tests the difference between containment and remediation actions, leading candidates to choose actions that address the reporter's device rather than organization-wide protection.

How to eliminate wrong answers

Option A is wrong because isolating the reporter's workstation is a reactive measure that only contains the incident on one device and does not prevent others from clicking the link. Option B is wrong because resetting the reporter's password is only necessary if credentials were compromised, and it does not block the URL. Option D is wrong because deleting the email from all mailboxes is a good step but does not prevent users who may have already clicked or received the link via other means; blocking the URL is more comprehensive.

622
MCQeasy

A company is developing a new mobile app that will process users' biometric data for authentication. The legal team is concerned about compliance with the GDPR's data protection by design. Which of the following is the MOST appropriate control to implement?

A.Obtain explicit consent from users before data collection.
B.Store biometric data in hashed form on the device.
C.Implement strong encryption for data in transit and at rest.
D.Conduct a Data Protection Impact Assessment (DPIA) before development.
AnswerD

A DPIA is the GDPR's prescribed mechanism for demonstrating data protection by design when processing biometric data, which is special category data. Conducting it before development ensures privacy risks are identified and mitigated at the design stage, satisfying the legal team's compliance concern.

Why this answer

Conducting a Data Protection Impact Assessment (DPIA) before development is the most appropriate control because GDPR Article 35 mandates a DPIA when processing biometric data is likely to result in high risk to individuals' rights and freedoms. This aligns with the principle of data protection by design (Article 25), requiring privacy considerations to be embedded into the development process from the outset, not added later.

Exam trap

CompTIA CASP+ often tests the distinction between security controls (encryption, hashing, consent) and governance/compliance controls (DPIA), tricking candidates into picking a technical safeguard instead of the mandated privacy-by-design assessment.

How to eliminate wrong answers

Option A is wrong because obtaining explicit consent, while necessary under GDPR for biometric data, is a legal basis for processing, not a technical or organizational control that implements data protection by design; it does not address the proactive, risk-based assessment required by Article 25. Option B is wrong because storing biometric data in hashed form on the device is a security measure, but hashing biometric data is not recommended due to its low entropy and the risk of dictionary attacks; GDPR's data protection by design requires a DPIA to evaluate whether such storage is appropriate and to consider alternatives like on-device matching without raw data retention. Option C is wrong because implementing strong encryption for data in transit and at rest is a necessary security control but is a reactive measure; it does not fulfill the proactive requirement of a DPIA to assess risks and design the system with privacy in mind from the start.

623
MCQhard

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The requirement is to prevent a compromised pod from reading another tenant's secrets and from making unauthorized network connections to other namespaces. Which of the following combinations BEST addresses both concerns?

A.Enable role-based access control (RBAC) for the API server and require TLS client certificates for all kubelet connections
B.Deploy a service mesh with mutual TLS between all pods and rotate the cluster's certificate authority on a fixed schedule
C.Use pod security admission to enforce the restricted profile and enable audit logging on the API server for all secret access
D.Apply network policies that deny ingress and egress by default and mount secrets only into pods that explicitly require them with least-privilege service accounts
AnswerD

Default-deny network policies stop unauthorized cross-namespace connections, while scoping secret mounts and service account permissions to only the pods that need them prevents a compromised pod from reading other tenants' secrets. Together they address both the network and secret-access requirements directly.

Why this answer

Default-deny network policies enforce network segmentation between namespaces, and least-privilege service accounts with scoped secret mounts enforce secret isolation at the API level. The other options harden adjacent layers such as control-plane access, admission, or transport encryption without preventing the two specific cross-tenant actions described.

Exam trap

The trap here is treating transport encryption or audit logging as if it prevents unauthorized access, when only authorization and segmentation controls actually block the actions.

624
MCQmedium

A financial services firm operates in several countries and must demonstrate that its security controls are effective and independently validated for regulators and enterprise customers. Executives want a report that auditors can rely on regarding the design and operating effectiveness of controls over a period of time. Which document should the security team provide?

A.SOC 2 Type II report
B.SOC 2 Type I report
C.SOC 3 general use report
D.ISO/IEC 27001 certificate
AnswerA

A SOC 2 Type II report covers the design and operating effectiveness of controls over a defined review period, using the Trust Services Criteria. Because it tests controls across time rather than a single moment, it gives regulators and customers independently validated evidence that controls operated effectively throughout the period, matching the stated objective.

Why this answer

A SOC 2 Type II report is the appropriate artifact because it attests to both the design and operating effectiveness of controls across a defined period. Type I reports only cover design at a point in time, and the other documents do not provide period-wide control testing evidence.

Exam trap

The trap here is treating a SOC 2 Type I report or an ISO/IEC 27001 certificate as equivalent evidence of control effectiveness over time when neither tests operating effectiveness across a period.

625
Multi-Selectmedium

Which TWO of the following are advantages of using a hardware security module (HSM) over a software-based cryptographic module? (Select exactly 2.)

Select 2 answers
A.Easier to deploy in cloud environments than software.
B.Automatically receive security patches without manual intervention.
C.Physical tamper resistance and protection against key extraction.
D.Lower cost than software modules.
E.Faster cryptographic operations due to dedicated hardware accelerators.
AnswersC, E

HSMs are hardened appliances that zeroise keys when tampering is detected, so keys never exist in extractable form. Software modules store keys in memory or on disk, where malware with sufficient privilege can copy them.

Why this answer

Option C is correct because an HSM is a dedicated physical device designed with tamper-resistant and tamper-evident mechanisms (such as epoxy encapsulation, sensors, and zeroization) that protect cryptographic keys from extraction even under physical attack, which a software module running on general-purpose hardware cannot guarantee. Option E is correct because HSMs include dedicated cryptographic accelerators and optimized processors that offload symmetric and asymmetric operations from the host CPU, yielding higher throughput and lower latency for bulk encryption and key operations. Option A is not generally true, since HSMs can be harder to deploy and integrate in cloud environments than pure software modules, which are simply installed or linked.

Option B is incorrect because HSM firmware updates typically require manual or vendor-managed intervention and are not automatically applied like some software patch pipelines. Option D is incorrect because HSMs are typically far more expensive than software-based cryptographic modules due to specialized hardware, certification, and management overhead.

Exam trap

CAS-005 often tests the misconception that HSMs are cheaper or easier to deploy than software modules, when in fact they are more expensive and complex but offer superior security and performance.

626
MCQeasy

An organization is implementing a PKI to issue certificates for internal applications. The security team wants to minimize the risk of compromise to the root CA. Which of the following is the BEST practice to protect the root CA?

A.Delegate root CA responsibilities to a public CA
B.Keep the root CA offline and store its private key in a hardware security module
C.Install the root CA on a VM with strict firewall rules
D.Use a self-signed certificate for the root CA and distribute it manually
AnswerB

An offline root CA, with its private key held in a hardware security module, is unreachable from the network, so compromise of issuing or web servers cannot expose it. This directly minimises the risk the security team wants to avoid.

Why this answer

Keeping the root CA offline and using a hardware security module (HSM) for key storage ensures its private key is never exposed to network threats. This is a standard best practice.

627
MCQeasy

Which document in a security policy hierarchy provides specific step-by-step instructions for performing a task?

A.Guideline
B.Procedure
C.Standard
D.Policy
AnswerB

A procedure sits below policy and standard in the hierarchy, translating them into detailed, sequential steps for a specific task. It tells staff exactly how to perform the activity, unlike policy, which states intent and mandatory requirements.

Why this answer

A procedure is the only document in a security policy hierarchy that provides detailed, step-by-step instructions for performing a specific task. It translates high-level policies and standards into actionable steps that employees can follow to ensure consistency and compliance. Procedures are operational in nature and answer 'how' to implement the requirements.

Exam trap

The trap here is confusing the terms 'standard' and 'procedure' because both are more specific than policy; candidates may forget that procedures are the only ones with step-by-step instructions, while standards specify requirements without steps.

How to eliminate wrong answers

Option A is wrong because a guideline offers recommendations and best practices, not mandatory step-by-step instructions. Option C is wrong because a standard defines specific technical or operational requirements (e.g., password length, encryption algorithms) but does not provide procedural steps. Option D is wrong because a policy is a high-level statement of management intent that outlines principles and responsibilities without detailing how to execute tasks.

628
MCQeasy

A security analyst is configuring an EDR solution to detect a specific fileless attack technique where malicious code is injected into the memory of a legitimate process. The analyst wants to trigger an alert when a process attempts to write to the memory of another process. Which Windows API function should the EDR monitor to detect this activity?

A.NtCreateThreadEx
B.CreateRemoteThread
C.WriteProcessMemory
D.VirtualAllocEx
AnswerC

WriteProcessMemory is the Windows API function used to write data to the memory of another process. Monitoring this API will directly detect attempts to inject code or modify memory in a remote process, which is a common step in fileless attacks. This aligns precisely with the requirement to detect memory writing to another process.

Why this answer

The correct API to monitor for detecting memory writes to another process is WriteProcessMemory. This function is commonly used in process injection and fileless malware to place malicious code into a legitimate process's memory space. Monitoring it provides direct visibility into the injection attempt.

Other APIs like CreateRemoteThread or VirtualAllocEx are related but do not directly capture the write operation.

Exam trap

The trap here is confusing memory allocation or thread creation APIs with the actual memory writing API, leading to monitoring the wrong function.

629
MCQhard

A cloud provider's security team is preparing for a regulatory examination and must demonstrate that a specific production system meets a documented set of security requirements. The regulator wants evidence of who approved the requirements, what was tested, when testing occurred, and what exceptions were granted. Which activity produces this evidence MOST directly?

A.Running an unauthenticated external vulnerability scan against the production system
B.Publishing the system's configuration baseline to the internal configuration management database
C.Performing a formal security assessment or authorization review with documented approval and exception records
D.Conducting an internal control self-assessment questionnaire with system owners
AnswerC

A formal assessment and authorization process, such as an Authority to Operate review, produces exactly the artifacts described: approved security requirements, the assessment scope and methods, testing dates, findings, and documented exceptions with risk acceptance. It establishes accountability by naming the authorizing official, which is why it directly satisfies a regulator asking for traceable governance evidence.

Why this answer

A formal security assessment and authorization review generates the full chain of evidence the regulator wants: approved requirements, the authorizing official's decision, assessment scope and methods, testing dates, and documented exceptions with risk acceptance. Scanning, self-assessment, and configuration baselines each contribute supporting data but none produce the approval, scope, timing, and exception record together in a traceable form.

Exam trap

The trap here is treating a technical scan or self-assessment as equivalent to a formal authorization decision with documented approvals and exceptions.

630
MCQmedium

A company is implementing a zero-trust network architecture. Which of the following components is essential for enforcing micro-segmentation?

A.Security information and event management (SIEM) system
B.Software-defined networking (SDN) with distributed firewalls
C.Multi-factor authentication (MFA)
D.Network access control (NAC)
AnswerB

SDN centralises control-plane policy while distributed firewalls enforce it at each workload's vNIC, delivering the east-west isolation micro-segmentation demands. This satisfies zero trust's requirement to verify every flow between segments rather than trusting perimeter placement.

Why this answer

Software-defined networking (SDN) with distributed firewalls is essential for enforcing micro-segmentation because it enables granular, policy-based traffic control at the virtual network layer, independent of physical topology. SDN centralizes policy management and pushes firewall rules to hypervisor-level or host-level enforcement points, allowing east-west traffic to be segmented between individual workloads or application tiers without relying on traditional perimeter firewalls.

Exam trap

The trap here is that candidates often confuse network access control (NAC) with micro-segmentation, but NAC controls access at the network edge (e.g., port-based authentication) rather than providing the workload-level, distributed traffic filtering that SDN with distributed firewalls enables.

How to eliminate wrong answers

Option A is wrong because a SIEM system is a log aggregation and analysis tool, not an enforcement point; it cannot block or filter traffic to create micro-segments. Option C is wrong because multi-factor authentication (MFA) is an identity verification mechanism that controls user access, not network traffic segmentation between workloads. Option D is wrong because network access control (NAC) primarily authenticates and authorizes devices at the network edge (e.g., 802.1X), but it does not provide the granular, workload-level traffic filtering required for micro-segmentation within a data center or cloud environment.

631
MCQmedium

A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Which of the following would be the BEST evidence to provide?

A.A report of employee security training completion
B.A signed copy of the access control policy
C.Access review logs showing periodic reviews of user permissions
D.A network diagram of the IT infrastructure
AnswerC

Access review logs directly evidence periodic recertification of user permissions, satisfying HIPAA's access control and audit requirements for ePHI. Unlike configuration screenshots or policy documents, these logs prove ongoing enforcement through documented reviewer decisions and timestamps, demonstrating that least-privilege access is actively maintained rather than merely defined.

Why this answer

Access review logs showing periodic reviews of user permissions provide direct evidence that access controls are being enforced and monitored over time. HIPAA requires covered entities to implement policies and procedures to authorize and supervise access to ePHI, and periodic reviews demonstrate ongoing compliance. A policy alone does not prove implementation, and training or network diagrams do not show actual access control effectiveness.

Exam trap

The trap is selecting a policy document or training record as evidence of access controls, when auditors require proof of implementation and monitoring, such as logs or review records.

How to eliminate wrong answers

Option A is wrong because employee security training completion only shows awareness, not the actual access controls in place for ePHI. Option B is wrong because a signed policy is a document stating intent, but it does not provide evidence that the controls are implemented or effective. Option D is wrong because a network diagram shows infrastructure layout, not access control enforcement or review processes.

632
MCQhard

During a security assessment, a penetration tester discovers that a web application's session tokens are predictable. The application uses a custom session management system. Which of the following is the MOST effective remediation to ensure secure session tokens?

A.Generate session tokens using a cryptographically secure random number generator (CSPRNG) with at least 128 bits of entropy.
B.Regenerate the session token on each page request.
C.Implement a short session timeout of 5 minutes.
D.Generate tokens using HMAC-SHA256 of a timestamp and a secret key.
AnswerA

A CSPRNG seeded with sufficient entropy removes the predictability that let attackers forecast tokens. The 128-bit minimum makes brute-force guessing infeasible, directly addressing the custom session system's weakness by replacing deterministic generation with cryptographically strong randomness.

Why this answer

Predictable session tokens arise from insufficient randomness. Using a cryptographically secure random number generator (CSPRNG) with at least 128 bits of entropy ensures that tokens are statistically unpredictable and resistant to brute-force or guessing attacks, which is the foundational requirement for secure session management per NIST SP 800-63B and OWASP guidelines.

Exam trap

CompTIA often tests the misconception that regenerating tokens frequently or using HMAC with a secret key is sufficient, when in fact the core issue is insufficient entropy in the token generation process.

How to eliminate wrong answers

Option B is wrong because regenerating the session token on every page request introduces unnecessary overhead and can break application state (e.g., concurrent AJAX calls), but more critically, it does not address the root cause of predictability—if the generation algorithm itself is weak, regenerating frequently still produces predictable tokens. Option C is wrong because a short session timeout of 5 minutes only limits the window of opportunity for an attacker to use a stolen or guessed token; it does not prevent the token from being predictable in the first place, so an attacker can still precompute valid tokens. Option D is wrong because HMAC-SHA256 of a timestamp and a secret key can still produce predictable tokens if the timestamp granularity is coarse (e.g., seconds) and the secret key is static; an attacker who observes a few tokens can reverse-engineer the pattern, especially if the timestamp is included in plaintext or can be inferred, making this approach weaker than a CSPRNG-based token.

633
MCQmedium

A healthcare organization subject to HIPAA must ensure that patients can access their medical records. This requirement is an example of which data subject right under privacy regulations?

A.Right to be forgotten
B.Right to data portability
C.Right to rectification
D.Right to access
AnswerD

HIPAA's patient right to inspect and obtain a copy of their medical records maps directly to the right to access. It lets individuals obtain their own data, distinct from rectification, erasure or portability, satisfying the requirement that records be made available on request.

Why this answer

The right to access under privacy regulations (including HIPAA's patient rights and GDPR Article 15) gives individuals the ability to obtain a copy of their personal data and confirm what is being processed. HIPAA's Privacy Rule specifically grants patients the right to inspect and obtain a copy of their protected health information. This maps directly to the right to access.

Exam trap

CAS-005 often tests the distinction between the right to access and the right to data portability — candidates conflate 'getting my data' with portability, but access is simply viewing/receiving a copy.

How to eliminate wrong answers

Option A is wrong because the right to be forgotten (erasure) allows individuals to request deletion of their data, which is not what the scenario describes. Option B is wrong because the right to data portability allows individuals to receive their data in a structured, machine-readable format and transmit it to another controller — a distinct right from mere access. Option C is wrong because the right to rectification allows individuals to correct inaccurate data, not simply view it.

634
MCQhard

An organization is using the FAIR framework to quantify risk. The analyst estimates the probable loss event frequency (LEF) as 4 per year and the probable loss magnitude (LM) as $25,000 per event. What is the annualized loss expectancy (ALE) under FAIR?

A.$6,250
B.$125,000
C.$100,000
D.$25,000
AnswerC

FAIR derives annualised loss expectancy by multiplying loss event frequency by loss magnitude, so 4 × $25,000 yields $100,000. This satisfies the stem's requirement to quantify ALE from the supplied LEF and LM values, giving the expected yearly loss the organisation faces from that risk scenario.

Why this answer

Under the FAIR (Factor Analysis of Information Risk) framework, Annualized Loss Expectancy (ALE) is calculated as Loss Event Frequency (LEF) multiplied by Loss Magnitude (LM). Here, LEF = 4 events per year and LM = $25,000 per event, so ALE = 4 × $25,000 = $100,000. This represents the expected annual financial loss from the risk scenario.

Exam trap

The trap here is confusing ALE with Loss Magnitude (LM) or inverting the formula (LM ÷ LEF); candidates must remember ALE = LEF × LM and not simply pick the per-event dollar figure.

How to eliminate wrong answers

Option A ($6,250) is wrong because it results from dividing LM by LEF (25,000 / 4), which is not a FAIR formula. Option B ($125,000) is wrong because it results from multiplying LEF by 5 × LM or some other incorrect arithmetic — it does not correspond to 4 × 25,000. Option D ($25,000) is wrong because it is simply the single-event loss magnitude (LM), not the annualized figure; it ignores the frequency of 4 events per year.

635
MCQmedium

A security analyst is reviewing the organization's third-party risk management program. The organization recently onboarded a new SaaS provider that will process sensitive customer data. The provider has provided a SOC 2 Type II report, but the analyst notices that the report is over 18 months old and covers a different service than the one being used. Which of the following should the analyst recommend?

A.Accept the existing SOC 2 Type II report since it demonstrates the provider's overall security posture.
B.Request a current SOC 2 Type II report that specifically covers the service being used, or conduct an on-site assessment if one is not available.
C.Perform a penetration test against the provider's service to validate its security controls.
D.Rely on the provider's self-attestation of compliance with industry best practices.
AnswerB

A SOC 2 Type II report must be current and scoped to the relevant service to provide assurance. An outdated report covering a different service is insufficient. Requesting an updated report or performing an on-site assessment ensures the organization obtains accurate, relevant information about the provider's controls, enabling informed risk decisions and compliance with due diligence requirements.

Why this answer

Third-party risk management requires current and relevant assurance. A SOC 2 Type II report must be recent and cover the specific service in use. Requesting an updated report or conducting an on-site assessment ensures the organization has accurate information to assess the provider's controls.

Other options rely on outdated, unverified, or inappropriate methods.

Exam trap

The trap here is assuming that any SOC 2 report is sufficient, when in fact its recency and scope are critical for it to be meaningful for the specific service.

636
MCQhard

A healthcare organization is planning to migrate patient data to a cloud provider. The risk assessment identifies that the provider's SOC 2 report does not cover HIPAA controls. What is the BEST course of action?

A.Request the provider's most recent SOC 3 report
B.Accept the risk and proceed with migration
C.Require the provider to sign a Business Associate Agreement (BAA)
D.Require the provider to encrypt all data at rest and in transit
AnswerC

A BAA is legally required under HIPAA before a business associate handles protected health information. Since the SOC 2 report omits HIPAA controls, the BAA contractually binds the provider to safeguard patient data, satisfying the compliance obligation the report cannot evidence.

Why this answer

Under HIPAA, a covered entity must have a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. A SOC 2 report that does not cover HIPAA controls does not satisfy the requirement; the BAA is the contractual mechanism that binds the cloud provider to HIPAA safeguards and breach notification obligations. Therefore, requiring the provider to sign a BAA is the best course of action before migrating PHI.

Exam trap

The trap is treating a SOC 2 report as sufficient evidence of HIPAA compliance — candidates must recognize that SOC 2 and HIPAA are different frameworks, and only a BAA creates the legal obligation required by HIPAA.

How to eliminate wrong answers

Option A is wrong because a SOC 3 report is a public, high-level attestation with even less detail than SOC 2 and does not address HIPAA-specific controls or establish a legal obligation. Option B is wrong because accepting the risk and proceeding without a BAA violates HIPAA and exposes the organization to severe penalties — risk acceptance is not permissible for a regulatory non-compliance gap. Option D is wrong because encryption alone, while a HIPAA safeguard, does not replace the required BAA; the provider could still be non-compliant in access controls, auditing, or breach response.

637
MCQmedium

A multinational financial services firm is preparing to adopt a new enterprise risk management approach. The CISO wants a quantitative method that expresses risk in monetary terms to prioritize investments. Which of the following should the CISO implement?

A.NIST Risk Management Framework (RMF)
B.OCTAVE Allegro
C.Factor Analysis of Information Risk (FAIR)
D.ISO/IEC 27005
AnswerC

FAIR is a quantitative risk analysis framework that expresses risk in financial terms by modeling loss event frequency and loss magnitude. It enables the CISO to prioritize investments based on monetary impact, aligning with the goal of expressing risk in monetary terms. Unlike qualitative approaches, FAIR provides defensible, data-driven estimates for enterprise risk management.

Why this answer

The CISO needs a quantitative risk analysis method that expresses risk in monetary terms. FAIR is specifically designed to quantify risk in financial terms, enabling prioritization of investments based on potential monetary loss. Other options are either qualitative or framework-oriented without inherent financial quantification.

Exam trap

The trap here is confusing comprehensive risk management frameworks with quantitative risk analysis methodologies that express risk in monetary terms.

638
MCQmedium

A security architect at a financial services firm is designing the network segmentation for a new containerized trading platform running on Kubernetes. The platform must isolate workloads so that a compromise of the public-facing web tier cannot directly reach the database tier. The architect wants to enforce this isolation natively within the cluster and have policies applied automatically as new pods are scheduled. Which of the following should the architect implement?

A.NetworkPolicies applied to namespaces and selected pods
B.A service mesh with mutual TLS between all sidecars
C.VLAN segmentation on the underlying hypervisor
D.An ingress controller with TLS termination and WAF rules
AnswerA

Kubernetes NetworkPolicies are the native mechanism for pod-level segmentation. They select pods via labels and define ingress and egress rules that allow or deny traffic between namespaces, pods, and CIDR blocks. Because the CNI plugin enforces them dynamically, newly scheduled pods that match a label selector inherit the policy automatically, giving the architect the isolation and automation required without external appliances.

Why this answer

Kubernetes NetworkPolicies provide label-based, pod-level segmentation enforced by the CNI plugin, so isolation follows workloads wherever they are scheduled. The architect can default-deny traffic in a namespace and then allow only the specific web-to-API and API-to-database flows, which prevents a compromised front end from reaching the database tier. Encryption and edge controls address different concerns and do not restrict lateral movement inside the cluster.

Exam trap

The trap here is assuming that encrypting service traffic with a mesh also restricts which services can communicate, when encryption and authorization are separate controls.

639
Multi-Selecthard

A security architect is designing a secure software development lifecycle (SSDLC). Which of the following practices are essential for integrating security into the development process? (Select TWO.)

Select 2 answers
A.Conducting static application security testing (SAST) during coding
B.Performing penetration testing only after production deployment
C.Using dependency scanning to check for known vulnerabilities in libraries
D.Implementing runtime application self-protection (RASP) in development
E.Deploying a web application firewall (WAF) in staging
AnswersA, C

Why this answer

Static application security testing (SAST) analyzes source code, bytecode, or binaries without executing the program, allowing developers to identify vulnerabilities such as buffer overflows, SQL injection, and cross-site scripting during the coding phase. Integrating SAST early in the SSDLC reduces the cost and effort of fixing security flaws by catching them before they reach later stages like testing or production.

Exam trap

The CAS-004 exam often tests the distinction between security controls applied during development (SAST, dependency scanning) versus runtime controls (RASP, WAF) or post-deployment activities (penetration testing), leading candidates to select options that are valid security measures but not essential to the SSDLC itself.

Why the other options are wrong

B

Pen testing is important but occurs later; it's not integrated into the development process early.

D

RASP is a runtime control, not typically integrated into the development phase.

E

WAF is a network security control, not a development practice.

640
MCQeasy

A security architect is designing a zero trust architecture for a financial institution. Which principle is fundamental to the zero trust model?

A.Trust but verify all network traffic
B.Use VPNs for all remote access
C.Perimeter-based security is sufficient
D.Assume breach and verify explicitly
AnswerD

Zero trust removes implicit trust based on network location. Assuming breach means every request is treated as potentially hostile, so each access is verified explicitly using identity, device and context signals before granting least-privilege access, which is fundamental to the model.

Why this answer

The fundamental principle of zero trust is 'assume breach and verify explicitly,' meaning no user or device is trusted by default, regardless of location. Every access request must be authenticated and authorized based on multiple factors, and least privilege is enforced. This principle is core to zero trust architecture as defined by NIST SP 800-207.

Exam trap

CAS-005 often tests zero trust principles by offering variations of 'trust but verify' or 'VPN for all access.' The trap is confusing zero trust with traditional defense-in-depth, which still relies on perimeter trust.

How to eliminate wrong answers

Option A is wrong because 'trust but verify' is a traditional perimeter-based approach that assumes internal network is trusted; zero trust does not trust anything by default. Option B is wrong because using VPNs for all remote access is a legacy approach that extends the perimeter but does not align with zero trust, which requires continuous verification regardless of network. Option C is wrong because perimeter-based security is explicitly rejected by zero trust, which assumes the perimeter is already breached.

641
MCQmedium

Refer to the exhibit. A security analyst notices that the pod is running with a service account token mounted. Which security best practice should be implemented to reduce the risk of token theft in container environments?

A.Store the token in a Kubernetes secret and mount it.
B.Use a different container runtime.
C.Disable the service account for the pod.
D.Set automountServiceAccountToken to false in the pod spec.
AnswerD

Setting automountServiceAccountToken to false stops Kubernetes projecting the service account token into the pod's filesystem, so a compromised container cannot read or exfiltrate it. This directly satisfies the requirement to reduce token theft risk by removing the credential from the pod entirely.

Why this answer

Setting automountServiceAccountToken to false in the pod spec prevents the default service account token from being automatically mounted into the pod's filesystem. This reduces the risk of token theft because the token is not present unless explicitly mounted. This is a Kubernetes security best practice for pods that do not need to interact with the Kubernetes API.

Exam trap

CAS-005 often tests the misconception that storing tokens in secrets or using different runtimes improves security, but the most direct mitigation is to not mount the token at all.

How to eliminate wrong answers

Option A is wrong because storing the token in a Kubernetes secret and mounting it still exposes the token to the pod, and secrets are not inherently more secure if the pod is compromised. Option B is wrong because changing the container runtime does not address the token mounting issue. Option C is wrong because disabling the service account entirely may break functionality if the pod needs to authenticate to the API; setting automountServiceAccountToken to false is more granular.

642
MCQmedium

A security engineer is configuring an internal certificate authority that must issue end-entity certificates to servers on a private network. Corporate policy requires that the CA's private key never reside on a network-connected host, and that certificate issuance be a deliberate, low-volume operation. Which of the following should the engineer implement to BEST meet these requirements?

A.Configure a cross-certified bridge CA that exchanges certificates with external partners using automated enrollment.
B.Configure an offline root CA that signs an online issuing subordinate CA, which in turn issues end-entity certificates.
C.Issue self-signed certificates directly to each server and distribute them to clients through a configuration management tool.
D.Deploy a single online root CA that issues all end-entity certificates and keeps its key in a network HSM.
AnswerB

An offline root CA keeps the trust anchor's private key on an isolated system that is powered on only to sign the subordinate CA certificate. The online issuing subordinate CA handles routine end-entity issuance, so compromise of the issuing CA does not expose the root key, and the root cannot be used remotely. This directly satisfies both the isolation and low-volume issuance requirements.

Why this answer

Keeping the root CA offline and delegating routine issuance to an online subordinate CA separates the trust anchor from day-to-day operations. The root key is only used to sign the subordinate CA certificate, so it can stay on an isolated host, while the subordinate handles end-entity certificates. This limits exposure and matches the policy of deliberate, low-volume root signing.

Exam trap

The trap here is assuming that placing the CA key in a hardware security module satisfies an offline-key requirement, when an online issuing CA still exposes the signing service over the network.

643
Multi-Selecteasy

Which TWO are key metrics used in business continuity planning?

Select 2 answers
A.Mean Time to Repair (MTTR)
B.Recovery Time Objective (RTO)
C.Recovery Point Objective (RPO)
D.Service Level Agreement (SLA)
E.Mean Time Between Failures (MTBF)
AnswersB, C

RTO is the maximum acceptable downtime.

Why this answer

Recovery Time Objective (RTO) is a key metric in business continuity planning because it defines the maximum acceptable downtime for a system or service after a disruption. It directly drives the design of failover mechanisms, backup strategies, and resource allocation to meet the target recovery time. Without a defined RTO, continuity plans lack a measurable goal for restoring operations.

Exam trap

In CompTIA CASP+, the trap is confusing RTO/RPO (business continuity metrics) with MTTR/MTBF (reliability metrics) or thinking SLA is a metric rather than a contractual agreement. Candidates often mistakenly select MTTR or MTBF because they sound similar to recovery terms.

644
MCQeasy

A company is deploying a new cloud-based application that processes sensitive customer data. The security architect has proposed a zero-trust architecture to secure remote access. The architecture includes identity-aware proxies, microsegmentation, and continuous monitoring. During the transition, several remote users report being unable to access the application. The security architect verifies that the identity-aware proxy is correctly configured and that users are authenticated via SSO. However, access attempts are still failing. The architect suspects that the issue may be related to the microsegmentation rules. What should the security architect do FIRST to resolve the problem?

A.Deploy a VPN to provide a secure tunnel for remote users.
B.Reset the affected users' credentials and force them to re-authenticate.
C.Review the microsegmentation firewall rules to ensure that traffic to the application's subnet is permitted.
D.Increase logging verbosity on the identity-aware proxy to capture more details.
AnswerC

Microsegmentation rules govern east-west traffic between workloads, so overly restrictive firewall rules on the application subnet would block authenticated users even when the identity-aware proxy and SSO function correctly; verifying those rules first isolates the suspected cause.

Why this answer

In a zero-trust architecture with microsegmentation, access failures after authentication often stem from network policies blocking traffic. The security architect should first review the microsegmentation firewall rules to ensure traffic to the application's subnet is permitted, as the identity-aware proxy and SSO are confirmed working. This directly addresses the suspected cause and is the most logical first step before other remediations.

Exam trap

The trap is focusing on authentication or adding network layers (VPN) when the issue is authorization/network policy; candidates may overlook that microsegmentation rules must permit traffic even after successful authentication.

How to eliminate wrong answers

Option A is wrong because deploying a VPN contradicts zero-trust principles and does not address the microsegmentation issue; it adds a network path rather than fixing the policy. Option B is wrong because resetting credentials is unnecessary since SSO authentication is already verified as working. Option D is wrong because increasing logging verbosity may help diagnose but is not the first action to resolve the problem; reviewing and correcting the microsegmentation rules is more direct.

645
MCQeasy

A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR agent can detect and block malicious activities in real-time. Which of the following capabilities is MOST essential for the EDR agent to achieve this goal?

A.Periodic full disk scans scheduled during off-hours.
B.Integration with a security information and event management (SIEM) system.
C.User behavior analytics (UBA) to detect insider threats.
D.Continuous monitoring of process and file system activity.
AnswerD

EDR solutions rely on continuous monitoring of endpoint activities such as process creation, file modifications, and network connections to detect malicious behavior in real-time. This telemetry is essential for identifying indicators of compromise and triggering automated responses. Without continuous monitoring, the EDR would lack the data needed to detect and block threats as they occur.

Why this answer

EDR agents must continuously monitor endpoint activities such as process execution, file system changes, and network connections to detect and block malicious behavior in real-time. This telemetry enables behavioral analysis and immediate response. SIEM integration, scheduled scans, and UBA are valuable but do not provide the real-time detection and blocking capability that continuous monitoring offers.

Exam trap

The trap here is confusing SIEM integration or scheduled scans with the real-time monitoring that is fundamental to EDR's detection and blocking capabilities.

646
MCQhard

An organization is implementing continuous compliance monitoring. Which of the following metrics would best indicate whether the organization is maintaining compliance with PCI DSS Requirement 10 (log management)?

A.Number of failed login attempts per day
B.Percentage of systems with centralized logging enabled
C.Mean time to detect (MTTD) for security incidents
D.Vulnerability scan pass rate
AnswerB

Requirement 10 depends on audit logs being captured and retained centrally for correlation and review. The proportion of in-scope systems forwarding logs to the central platform directly measures coverage of that control, exposing any system whose logs remain local and therefore unmonitored.

Why this answer

PCI DSS Requirement 10 requires that audit logs be collected, retained, and reviewed, and centralized logging is a key control to ensure logs from all in-scope systems are captured in a tamper-resistant manner. The percentage of systems with centralized logging enabled directly measures coverage of this control. A high percentage indicates the organization is maintaining the log management requirement across its cardholder data environment.

Exam trap

CAS-005 often tests the mapping of metrics to specific PCI DSS requirements — candidates pick a security-sounding metric like MTTD or failed logins when the question asks about log management coverage specifically.

How to eliminate wrong answers

Option A is wrong because failed login attempts per day is a security event metric, not a compliance coverage metric for Requirement 10. Option C is wrong because MTTD measures incident response effectiveness, which relates more to Requirement 12 (security policies) than to log management coverage. Option D is wrong because vulnerability scan pass rate relates to PCI DSS Requirement 11 (security testing), not Requirement 10 (log management).

647
Multi-Selecthard

A security architect is designing a network segmentation strategy for a data center that hosts both web servers and database servers. The architect wants to ensure that if a web server is compromised, the attacker cannot directly access the database servers. The architect plans to implement microsegmentation using software-defined networking (SDN). Which TWO of the following are essential components to achieve this goal? (Choose two.)

Select 2 answers
A.A hypervisor-based firewall that inspects traffic between virtual machines.
B.A centralized policy controller that defines and enforces security group rules.
C.A next-generation firewall (NGFW) at the perimeter of the data center.
D.A network tap or SPAN port for traffic monitoring and analysis.
E.A hardware security module (HSM) to store encryption keys for VPN tunnels.
AnswersA, B

A hypervisor-based firewall enforces security policies at the virtual switch level, controlling traffic between VMs even on the same host. This is critical for microsegmentation because it prevents lateral movement within the virtualized environment. It ensures that a compromised web server VM cannot communicate with database VMs unless explicitly allowed, directly supporting the goal.

Why this answer

Microsegmentation with SDN requires a centralized policy controller to define and distribute security rules, and a hypervisor-based firewall to enforce those rules between virtual machines. Together, they enable granular, dynamic segmentation that prevents lateral movement. HSMs, network taps, and perimeter NGFWs serve other purposes and do not provide the necessary internal enforcement.

Exam trap

The trap here is assuming that perimeter security controls or monitoring tools can prevent lateral movement between internal servers.

648
MCQmedium

During a vendor risk assessment, a third-party vendor refuses to provide a SOC 2 report but offers a completed security questionnaire. The vendor handles sensitive customer data. Which of the following is the BEST course of action?

A.Immediately terminate the relationship.
B.Lower the data classification to reduce risk.
C.Require a right-to-audit clause to conduct an on-site assessment.
D.Accept the questionnaire as sufficient evidence.
AnswerC

A right-to-audit clause contractually grants the company the ability to assess the vendor's controls directly, compensating for the missing SOC 2 report. Since the vendor handles sensitive customer data, on-site assessment provides independent verification that a self-completed questionnaire alone cannot.

Why this answer

When a vendor handling sensitive customer data refuses to provide a SOC 2 report, the best course is to require a right-to-audit clause in the contract and conduct an on-site assessment. This gives the organization direct assurance over the vendor's controls without relying solely on self-attested questionnaires, which are not independent evidence.

Exam trap

CAS-005 often tests vendor risk management judgment — candidates either overreact (terminate) or underreact (accept the questionnaire), missing the balanced control of a right-to-audit clause for independent verification.

How to eliminate wrong answers

Option A is wrong because immediately terminating the relationship is a disproportionate response — it may be unnecessary if the vendor can demonstrate adequate controls through an audit, and it could disrupt business operations. Option B is wrong because lowering the data classification to reduce risk is a form of risk avoidance by mislabeling, which is unethical and does not actually reduce the risk to the data — it just hides it. Option D is wrong because a self-completed security questionnaire is not independent evidence; it is vendor-asserted and lacks the assurance of a third-party audit like SOC 2.

649
MCQmedium

A company is implementing a privileged access management (PAM) solution to reduce the risk of standing privileges. Which feature allows users to request temporary elevated access for a specific task, which is automatically revoked after the task is completed?

A.Break-glass accounts
B.Password vaulting
C.Session recording
D.Just-in-time (JIT) access provisioning
AnswerD

Just-in-time access provisioning grants elevated permissions only for the duration of a specific task, then automatically revokes them. This directly eliminates standing privileges, satisfying the stem's requirement that access be temporary and self-expiring. Microsoft Entra ID Privileged Identity Management implements this through time-bound role activation, with approvals and expiry enforced automatically.

Why this answer

Just-in-time (JIT) access provisioning grants temporary privileges that expire after use, reducing standing privileges. Break-glass accounts are emergency accounts, not time-based.

650
MCQmedium

An organization is designing a PKI to issue certificates to thousands of IoT devices. Which architectural decision will BEST support automated certificate lifecycle management?

A.Online root CA with self-signed certificates
B.Automated enrollment using SCEP
C.Using a public CA for all IoT devices
D.Offline root CA with manual issuance
AnswerB

SCEP provides a standardised protocol for devices to request and receive certificates automatically from a CA, enabling enrolment without manual intervention. For thousands of IoT devices, this automates issuance, renewal and revocation workflows, which is the lifecycle management constraint the stem demands.

Why this answer

Automated enrollment using SCEP (Simple Certificate Enrollment Protocol) is the best choice because it enables scalable, automated certificate issuance and renewal for thousands of IoT devices without manual intervention. SCEP is widely supported by IoT devices and integrates with PKI to streamline lifecycle management, including renewal and revocation.

Exam trap

CAS-005 often tests PKI design for IoT by presenting options that seem scalable but are not automated. Candidates may choose a public CA for convenience, but it lacks integration with internal lifecycle management and is cost-prohibitive.

How to eliminate wrong answers

Option A is wrong because an online root CA with self-signed certificates is insecure; the root CA should be offline to protect the trust anchor, and self-signed certificates are not suitable for a managed PKI. Option C is wrong because using a public CA for all IoT devices is costly, impractical for internal devices, and may not support automated lifecycle management at scale. Option D is wrong because an offline root CA with manual issuance does not support automation and is not scalable for thousands of devices.

651
MCQmedium

A security analyst discovers that a web application is vulnerable to directory traversal. Which of the following is the MOST effective mitigation?

A.Whitelist of allowed file paths
B.Encrypting all files on the server
C.Chroot jail
D.Input validation that rejects paths containing '..'
AnswerA

An allowlist constrains file access to explicitly permitted paths, so traversal sequences such as ../ cannot resolve to arbitrary files outside the intended directory. This neutralises the vulnerability at the input-validation layer rather than relying on pattern filtering, which is bypassable.

Why this answer

A whitelist of allowed file paths is the most effective mitigation because it defines an explicit set of permissible paths, preventing any unauthorized file access regardless of traversal attempts. Unlike input validation, which can be bypassed with encoding or alternative traversal sequences, a whitelist enforces a positive security model that blocks all unspecified paths, including those using '..' or symbolic links. This approach directly addresses the root cause of directory traversal by restricting the application to only known-safe resources.

Exam trap

CompTIA often tests the misconception that input validation (e.g., blocking '..') is sufficient, but the trap here is that attackers can bypass such filters with encoding or alternative traversal techniques, making a whitelist the only truly effective mitigation.

How to eliminate wrong answers

Option B is wrong because encrypting files on the server does not prevent an attacker from reading them via directory traversal; encryption protects data at rest but does not enforce access controls on the file system path. Option C is wrong because a chroot jail restricts the process's view of the filesystem but can be escaped if the application runs with sufficient privileges or if there are misconfigurations (e.g., missing chroot breakouts via /proc or open file descriptors), and it does not prevent the application from serving files outside the intended web root if the jail is not properly set up. Option D is wrong because input validation that rejects paths containing '..' can be bypassed using URL encoding (e.g., %2e%2e%2f), double encoding, or alternative traversal patterns like '....//' or absolute paths, making it an incomplete and unreliable defense.

652
MCQmedium

A software company is acquiring a smaller competitor that maintains its own identity provider, endpoint management platform, and network infrastructure. The integration team must fold the acquired company's users and devices into the parent's environment without disrupting business operations. Which activity should occur first to establish governance over the combined environment?

A.Migrate the acquired company's production workloads into the parent's cloud tenancy to consolidate billing
B.Perform a security assessment of the acquired company's identity, endpoint, and network controls to identify gaps before integration
C.Immediately federate the acquired company's identity provider with the parent's directory to unify single sign-on
D.Deploy the parent's endpoint detection agents to all acquired devices during the first maintenance window
AnswerB

Merger and acquisition integration begins with due diligence on the acquired environment so leadership understands inherited risk, control gaps, and remediation cost before merging identities or networks. Assessing the identity provider, endpoint management, and network controls first produces the risk picture that drives integration sequencing, budget, and acceptance decisions, preventing the parent from unknowingly absorbing compromised or unmanaged assets.

Why this answer

Merger and acquisition security governance starts with assessment. Before identities, endpoints, or workloads are merged, the acquiring organization must understand the inherited risk posture so it can prioritize remediation, set integration sequencing, and make informed acceptance decisions. Federating identities, deploying agents, or migrating workloads first can import vulnerabilities and weaken the parent's controls rather than extend them.

Exam trap

The trap here is choosing the most visible integration action, such as identity federation, instead of the assessment that must precede any trust or control changes.

653
MCQhard

A security analyst is investigating a malware sample and wants to determine its capabilities without executing it. The analyst examines the binary's imports, strings, and structure. What type of analysis is being performed?

A.Memory analysis
B.Static analysis
C.Reverse engineering
D.Dynamic analysis
AnswerB

Static analysis examines a binary's code, imports, strings and structure without running it, directly satisfying the stem's constraint of determining capabilities without execution. Unlike dynamic analysis, which observes runtime behaviour in a sandbox, static analysis reveals potential functionality through inspection alone, making it the appropriate technique here.

Why this answer

Static analysis involves examining a file's code, structure, and metadata without running it. By inspecting imports, strings, and headers, the analyst gains insight into potential functionality (e.g., API calls, embedded URLs) without risking execution. This is the definition of static analysis, as opposed to dynamic analysis which requires running the sample.

Reverse engineering is a broader process that includes static and dynamic techniques, but the specific actions described are classic static analysis.

Exam trap

The trap here is confusing static analysis with reverse engineering, as both involve examining code without execution, but reverse engineering is a broader process that includes static and dynamic methods; the question specifically describes non-execution inspection of imports, strings, and structure, which is static analysis.

How to eliminate wrong answers

Option A is wrong because memory analysis involves examining volatile memory (RAM) to capture running processes, network connections, or injected code, which requires the malware to have executed. Option C is wrong because reverse engineering is a more comprehensive discipline that often includes disassembly, debugging, and behavioral analysis; while static analysis is a part of it, the question specifically describes the non-execution examination of imports, strings, and structure, which is static analysis. Option D is wrong because dynamic analysis requires executing the malware in a controlled environment to observe its behavior, such as monitoring file system changes, registry modifications, or network traffic.

654
MCQmedium

An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?

A.Monitoring and remediating misconfigurations
B.Brokering access to cloud apps
C.Protecting workloads from malware
D.Encrypting data at rest
AnswerA

CSPM continuously compares deployed cloud resource configurations against security baselines and compliance policies, then flags or automatically remediates drift such as public storage buckets or permissive security groups. That misconfiguration monitoring and remediation is precisely the primary function the scenario asks for.

Why this answer

CSPM tools continuously scan cloud environments for misconfigurations such as publicly exposed storage buckets, overly permissive IAM roles, and disabled logging, then alert or automatically remediate them. This aligns directly with option A. CSPM is a core pillar of cloud-native security alongside CWPP and CIEM.

Exam trap

The trap is confusing CSPM with CASB or CWPP; candidates see 'cloud security' and pick the malware or access-brokering option without distinguishing posture management from runtime protection or access control.

How to eliminate wrong answers

Option B is wrong because brokering access to cloud apps is the function of a Cloud Access Security Broker (CASB), not CSPM. Option C is wrong because protecting workloads from malware is the domain of Cloud Workload Protection Platform (CWPP) tools, which focus on runtime and host-level threats. Option D is wrong because encrypting data at rest is a data protection control handled by cloud provider encryption services, key management systems, or database encryption features, not by CSPM.

655
MCQmedium

A security architect is designing a secure coding standard for a web application. Which of the following should be prioritized to mitigate cross-site scripting (XSS) risks?

A.Input validation
B.Output encoding
C.Secure cookies
D.Parameterized queries
AnswerB

Output encoding converts untrusted data into inert text before it reaches the browser, so injected script is rendered rather than executed. This directly neutralises XSS at the point of output, satisfying the secure coding standard's priority.

Why this answer

Output encoding is the primary defense against cross-site scripting (XSS) because it neutralizes injected scripts by converting special characters (e.g., <, >, &, ") into their HTML entity equivalents (e.g., &lt; &gt; &amp; &quot;) before the data is rendered in the browser. This ensures that user-supplied data is treated as text, not executable code, regardless of how it entered the application. Input validation alone is insufficient because it can be bypassed via alternate encodings or allowed characters that are still dangerous in certain contexts.

Exam trap

CompTIA often tests the misconception that input validation is the best defense against XSS, when in fact output encoding is the definitive control because it addresses the root cause — untrusted data being interpreted as code — regardless of input filtering.

How to eliminate wrong answers

Option A is wrong because input validation (e.g., allowlists, sanitization) can reduce XSS risk but is not prioritized as the primary mitigation; attackers can bypass validation using alternate encodings or allowed characters that become dangerous in different output contexts (e.g., JavaScript, CSS). Option C is wrong because secure cookies (e.g., HttpOnly, Secure, SameSite flags) protect against session theft via XSS but do not prevent the injection or execution of malicious scripts in the first place. Option D is wrong because parameterized queries (prepared statements) are designed to prevent SQL injection, not XSS; they have no effect on how data is rendered in HTML or JavaScript contexts.

656
MCQeasy

An organization needs to ensure compliance with GDPR regarding data subject access requests. What is the MOST important control to implement?

A.Encrypt all personal data at rest and in transit
B.Minimize the collection of personal data
C.Implement a process to respond to access requests within one month
D.Appoint a Data Protection Officer (DPO)
AnswerC

GDPR Article 12(3) obliges controllers to provide data subject access request information without undue delay and within one month of receipt. A defined response process enforces that statutory deadline, making it the most important operational control for access-request compliance.

Why this answer

GDPR Article 12(3) requires organizations to respond to data subject access requests without undue delay and at the latest within one month. The most important control is a documented process that ensures timely identification, validation, and fulfillment of these requests, as failure to meet the deadline constitutes a direct compliance violation. Without this process, technical controls like encryption alone cannot satisfy the regulatory requirement for a verifiable response.

Exam trap

CompTIA often tests the distinction between security controls (like encryption) and compliance controls (like process and procedure), and the trap here is that candidates confuse data protection (confidentiality) with data subject rights (accessibility and timeliness), leading them to pick a technical control over a procedural one.

How to eliminate wrong answers

Option A is wrong because encrypting personal data at rest and in transit is a security control that protects confidentiality, but it does not address the operational requirement to locate, retrieve, and provide the data to the data subject within the mandated timeframe. Option B is wrong because data minimization is a GDPR principle (Article 5(1)(c)) that reduces risk, but it is not the most important control for responding to access requests; even minimized data must be retrievable and provided on request. Option D is wrong because appointing a Data Protection Officer (DPO) is a governance requirement under Article 37, but the DPO advises and monitors compliance; the actual operational control to respond to access requests is a separate process that must be implemented regardless of whether a DPO is appointed.

657
Multi-Selecteasy

A security analyst is reviewing CVSS scores for vulnerability prioritization. Which TWO of the following are component metric groups in CVSS v3?

Select 2 answers
A.Impact
B.Temporal
C.Exploitability
D.Environmental
E.Attack Vector
AnswersB, D

Temporal metrics capture characteristics that change over time, such as exploit code maturity, remediation level and report confidence, modifying the Base score without altering the intrinsic vulnerability. CVSS v3 defines exactly three metric groups: Base, Temporal and Environmental.

Why this answer

In CVSS v3, the score is built from three metric groups: Base, Temporal, and Environmental. Option B (Temporal) is correct because it is one of the three metric groups, capturing characteristics that change over time such as Exploit Code Maturity, Remediation Level, and Report Confidence. Option D (Environmental) is also correct because it is a metric group that lets analysts customize the score based on their own environment, including Confidentiality/Integrity/Availability Requirements and modified base metrics.

The unmarked options do not belong because Impact, Exploitability, and Attack Vector are not metric groups; Impact and Exploitability are Base metric sub-scores, and Attack Vector is a single Base metric, not a group.

Exam trap

CAS-005 often tests the distinction between CVSS metric groups and their sub-metrics, tricking candidates into selecting Impact or Exploitability as standalone groups when they are actually Base sub-components.

658
MCQhard

A security architect is designing an API security strategy for a microservices-based application. The architect needs to ensure that only authenticated and authorized clients can invoke APIs, and that rate limiting is enforced to prevent abuse. Which technology should be placed in front of the microservices?

A.API Gateway
B.Web Application Firewall (WAF)
C.Reverse proxy
D.Load balancer
AnswerA

An API gateway terminates client requests and enforces authentication, authorisation and rate limiting centrally before forwarding to microservices, so only validated clients invoke backends. This satisfies the requirement for centralised access control and abuse prevention.

Why this answer

An API Gateway is designed to handle authentication, authorization, rate limiting, and other cross-cutting concerns for APIs in a microservices architecture. It acts as a single entry point for all API calls, enforcing security policies before requests reach the microservices. This centralizes API security and simplifies management.

Exam trap

CAS-005 often tests the difference between API Gateway and WAF. Candidates may choose WAF because it sounds security-focused, but WAF does not provide API authentication and rate limiting for microservices.

How to eliminate wrong answers

Option B is wrong because a WAF protects web applications from common attacks (e.g., SQL injection, XSS) but does not provide API-specific authentication, authorization, or rate limiting for microservices. Option C is wrong because a reverse proxy forwards requests but lacks built-in API security features like authentication and rate limiting. Option D is wrong because a load balancer distributes traffic but does not enforce API security policies.

659
Multi-Selectmedium

A security engineer is implementing network segmentation to isolate a PCI DSS environment from the corporate network. The engineer plans to use VLANs and a firewall. Which TWO of the following are essential to ensure that the segmentation is effective and compliant? (Choose two.)

Select 2 answers
A.Implement 802.1Q VLAN tagging on all switch ports that connect to the PCI environment and ensure that native VLANs are not used on trunk ports.
B.Use private VLANs (PVLANs) to isolate hosts within the PCI VLAN from each other.
C.Deploy a dedicated intrusion prevention system (IPS) on the PCI VLAN to monitor all traffic.
D.Enable dynamic ARP inspection (DAI) and DHCP snooping on all VLANs to prevent IP spoofing.
E.Configure the firewall to deny all traffic between the PCI VLAN and other VLANs by default, allowing only explicitly required flows.
AnswersA, E

Proper VLAN tagging and avoiding native VLANs on trunk ports prevent VLAN hopping attacks, where an attacker could send double-tagged frames to access another VLAN. This ensures that the segmentation at Layer 2 is robust and that traffic cannot inadvertently cross VLAN boundaries.

Why this answer

Effective network segmentation for PCI DSS requires both Layer 3 access control and Layer 2 isolation. A default-deny firewall rule between the PCI VLAN and other networks ensures that only necessary traffic is allowed. Proper VLAN tagging and avoiding native VLANs on trunk ports prevent VLAN hopping attacks that could bypass segmentation.

Together, these controls establish a strong boundary. Other measures like DAI, IPS, and PVLANs enhance security but are not essential for the segmentation itself.

Exam trap

The trap here is focusing on additional security controls like IPS or DAI as segmentation mechanisms, when the core requirements are firewall rule sets and VLAN configuration to prevent cross-VLAN traffic.

660
MCQeasy

A security administrator needs to ensure that only authorized devices can access the corporate network. Which technology would best enforce this requirement at the network access layer?

A.TLS 1.3
B.IPsec VPN
C.802.1X
D.DNSSEC
AnswerC

802.1X performs port-based network access control, requiring devices to authenticate via EAP before gaining Layer 2 connectivity. This enforces the requirement that only authorised devices reach the corporate network, blocking rogue hardware at the access layer.

Why this answer

802.1X is an IEEE standard for port-based network access control (NAC) that authenticates devices before granting access to the network. It ensures that only authorized devices can connect to a switch port or wireless access point, enforcing access control at the network access layer.

Exam trap

CAS-005 often tests network access control by offering VPN or TLS as options. Candidates may confuse remote access security with local network access control, but 802.1X is specifically for authenticating devices at the network edge.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 is a cryptographic protocol for securing communications, not for network access control. Option B is wrong because IPsec VPN provides secure tunnels for remote access but does not enforce device authorization at the network access layer for local connections. Option D is wrong because DNSSEC secures DNS responses but does not control network access.

661
MCQhard

During a forensic investigation, the examiner discovers that the chain of custody documentation was not properly maintained for a critical hard drive. What is the most likely consequence?

A.The evidence may be ruled inadmissible in legal proceedings
B.The investigation can continue without any impact
C.The data on the drive is automatically deleted
D.The drive must be returned to the owner immediately
AnswerA

Broken chain of custody undermines the evidence's authenticity and integrity, so opposing counsel can challenge its admissibility. Courts require documented, unbroken control from seizure to presentation; gaps create reasonable doubt about tampering. This satisfies the stem's legal-proceedings consequence, as the hard drive's evidentiary value is likely rejected.

Why this answer

Proper chain of custody documentation is essential for evidence to be admissible in legal proceedings. If the chain of custody is not maintained, the integrity of the evidence is questioned, and it may be ruled inadmissible. This is because the court cannot verify that the evidence was not tampered with or altered from the time it was collected to its presentation in court.

Therefore, the most likely consequence is that the evidence will be excluded.

Exam trap

The trap is assuming that a documentation error only affects administrative processes, when in fact it can render critical evidence inadmissible, undermining the entire legal case.

How to eliminate wrong answers

Option B is wrong because a broken chain of custody directly impacts the admissibility and weight of evidence, so the investigation is affected. Option C is wrong because data is not automatically deleted due to documentation errors; deletion requires a separate action. Option D is wrong because returning the drive to the owner is not an automatic consequence; the evidence may still be used if the chain of custody can be reconstructed, but typically it becomes inadmissible.

662
MCQmedium

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which of the following techniques would be most effective for identifying valid credentials that could be reused on the database server?

A.Running a port scan on the internal network
B.Deploying a web shell for persistent access
C.Conducting a SQL injection on the database server
D.Using Mimikatz to dump credentials from memory
AnswerD

Mimikatz extracts plaintext passwords, NTLM hashes and Kerberos tickets from LSASS memory on the compromised host. Reused local or domain credentials harvested this way frequently authenticate to the database server, satisfying the objective of finding valid reusable credentials.

Why this answer

Mimikatz extracts plaintext passwords, NTLM hashes, and Kerberos tickets from LSASS memory on a compromised Windows host. Because administrators frequently reuse local or domain credentials across servers, harvested credentials can be replayed against the database server via SMB, RDP, or native database authentication. This directly satisfies the objective of identifying reusable valid credentials for lateral movement.

Exam trap

CAS-005 often tests the distinction between reconnaissance actions (port scanning, web shell deployment) and credential-access techniques, tricking candidates into selecting an option that provides access or persistence rather than the credential discovery the question explicitly asks for.

How to eliminate wrong answers

Option A is wrong because a port scan only enumerates open ports and services, revealing reachability but never yielding credential material. Option B is wrong because a web shell provides persistent remote code execution on the already-compromised web server; it does not extract or discover credentials for other systems. Option C is wrong because SQL injection against the database server targets data extraction or query manipulation, not credential harvesting from the web server's memory, and it assumes an exploitable injection point that may not exist.

663
MCQmedium

A security operations center (SOC) analyst is investigating a potential phishing incident. The analyst has a suspicious email and wants to safely analyze any URLs without directly visiting them from a corporate workstation. Which of the following techniques should the analyst use to examine the URL's reputation and content?

A.Copy the URL into a text editor and inspect the domain for typosquatting, then use a WHOIS lookup to determine the registrar.
B.Forward the email to a personal email account and open the URL on a personal device to see if it is malicious.
C.Use a URL sandboxing service that detonates the URL in an isolated environment and provides a screenshot and network traffic analysis.
D.Use a command-line tool like curl to fetch the URL headers and HTML content, then analyze the response for malicious scripts.
AnswerC

URL sandboxing services, such as VirusTotal or URLScan.io, allow analysts to submit a URL and have it rendered in a controlled, isolated environment. This reveals the final destination, any drive-by downloads, and network connections without risking the corporate workstation. It is a safe and efficient method for initial triage of suspicious URLs.

Why this answer

URL sandboxing services are designed to safely analyze URLs by rendering them in an isolated environment. They provide valuable information such as screenshots, final URL, and network requests, which help determine if the URL is malicious. This approach protects the analyst's workstation and the corporate network while gathering actionable intelligence.

Exam trap

The trap here is assuming that passive inspection or using local tools like curl is sufficient for safe analysis, when in fact dynamic sandboxing is required to observe behavior without risk.

664
Matchingmedium

Match each security feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Trust relationships between identity providers

Controls and monitors admin accounts

Restricts access based on physical location

Obfuscates sensitive data in non-production environments

Replaces sensitive data with non-sensitive placeholders

Why these pairings

These features are covered in identity and access management and data protection domains.

665
MCQeasy

A security administrator is configuring a Linux server that will host a public-facing web application. The administrator wants to ensure that the server's SSH service is protected against brute-force attacks by limiting the number of failed authentication attempts and blocking offending IP addresses. Which of the following should the administrator implement?

A.Install and configure Fail2ban to monitor SSH logs and update firewall rules.
B.Enable SELinux in enforcing mode.
C.Configure TCP wrappers to allow only specific IP addresses.
D.Change the SSH port from 22 to a non-standard port.
AnswerA

Fail2ban monitors log files for failed authentication attempts and dynamically updates firewall rules to block offending IP addresses. It can be configured to limit failed SSH attempts and ban IPs for a specified duration. This directly meets the requirement of protecting against brute-force attacks by blocking sources after multiple failures.

Why this answer

Fail2ban actively monitors SSH authentication logs and, upon detecting repeated failures, inserts firewall rules to block the offending IP addresses. This provides dynamic brute-force protection. The other options either offer static access control, process confinement, or obscurity, none of which dynamically respond to failed authentication attempts.

Exam trap

The trap here is assuming that changing the SSH port or using TCP wrappers provides brute-force protection, when only a tool like Fail2ban dynamically blocks IPs based on failed authentication attempts.

666
MCQeasy

Which of the following is a key difference between a security guideline and a security procedure?

A.Both are equally enforceable
B.Procedures are high-level; guidelines are detailed
C.Guidelines are recommended; procedures are mandatory
D.Guidelines are mandatory; procedures are optional
AnswerC

Guidelines provide discretionary recommendations, whereas procedures are mandatory step-by-step instructions that must be followed. This distinction satisfies the stem's requirement for a key difference: guidelines advise on achieving objectives, while procedures enforce specific actions, making compliance compulsory rather than optional within a security framework.

Why this answer

A security guideline is a recommended, non-mandatory statement of best practice that advises how to align with policy, while a security procedure is a mandatory, step-by-step instruction that must be followed to accomplish a specific task. This distinction in enforceability and specificity is the defining difference between the two document types. Guidelines offer flexibility; procedures prescribe exact actions.

Exam trap

The trap is reversing the enforceability and specificity of guidelines versus procedures — candidates often assume guidelines are mandatory because they sound authoritative.

How to eliminate wrong answers

Option A is wrong because guidelines and procedures are not equally enforceable — guidelines are recommendations, while procedures are mandatory. Option B is wrong because it reverses the hierarchy: procedures are detailed and operational, while guidelines are high-level recommendations. Option D is wrong because it inverts the definitions — guidelines are not mandatory, and procedures are not optional.

667
MCQhard

An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?

A.Eliminates need for runtime security monitoring
B.Prevents unauthorized modifications to running containers
C.Allows use of privileged containers securely
D.Reduces image scanning frequency
AnswerB

Immutability means running containers are never patched in place; any change requires redeploying a fresh image. Because the container filesystem and process are not writable by operators or attackers, unauthorised modification of a live container is prevented, satisfying the stem's requirement directly.

Why this answer

Immutable infrastructure means containers are deployed from a fixed, versioned image and are never modified in place — any change requires redeploying a new container. This design directly prevents unauthorized or accidental modifications to running containers, since the running instance is treated as read-only and any drift is discarded on replacement. The security benefit is integrity enforcement: attackers cannot persist by editing files inside a live container because the container is ephemeral and replaced from a trusted image.

Exam trap

The trap here is conflating immutability with complete runtime security — candidates often assume that if containers cannot be modified, no runtime monitoring is needed, but immutability only protects the filesystem and image, not in-memory or process-level threats.

How to eliminate wrong answers

Option A is wrong because immutability does not remove the need for runtime security monitoring — runtime threats such as memory exploits, cryptomining, and anomalous process execution still occur inside immutable containers, so tools like Falco or runtime EDR remain necessary. Option C is wrong because immutability does nothing to make privileged containers safe; a privileged container still has host-level capabilities and kernel access, so immutability does not mitigate that risk. Option D is wrong because immutability does not reduce image scanning frequency — images still need scanning for CVEs at build time and on registry updates, and immutable deployments often increase the need for consistent scanning pipelines.

668
Multi-Selecthard

An incident response team discovers that an attacker was able to forge a certificate for a legitimate domain. Which TWO mechanisms should the team implement to detect and prevent such misissuance in the future? (Select TWO.)

Select 2 answers
A.Certificate Revocation Lists (CRLs)
B.Implementing Extended Validation (EV) certificates
C.Online Certificate Status Protocol (OCSP) stapling
D.Certificate Transparency (CT) logging and monitoring
E.Certificate pinning in client applications
AnswersD, E

Certificate Transparency publishes every issued certificate to append-only, cryptographically verifiable logs, letting the team detect unauthorised or forged certificates for their domains. Monitoring these logs satisfies the misissuance detection requirement by exposing certificates the legitimate CA never intended to issue.

Why this answer

Certificate Transparency (CT) logging and monitoring (D) is correct because CT requires CAs to submit every issued certificate to public, append-only logs, so the team can monitor these logs for unauthorized or forged certificates for their domains and detect misissuance quickly. Certificate pinning in client applications (E) is correct because it hardcodes or constrains the expected certificate/public key for a domain, so a forged certificate issued by a rogue or compromised CA will be rejected by the client, preventing its use even if it chains to a trusted root. CRLs (A) and OCSP stapling (C) only convey revocation status of certificates and cannot detect or prevent a newly forged certificate that has not yet been revoked, and EV certificates (B) merely assert a higher validation level without providing any detection or pinning mechanism against misissuance.

669
MCQhard

A SOC analyst notices that a containerized application is making unexpected outbound connections. The container runs with minimal privileges. Which step should the analyst take first to investigate without compromising the environment?

A.Restore the container from a trusted image and re-deploy.
B.Use `docker exec` to attach a shell and run network diagnostic commands.
C.Immediately kill the container and analyze its filesystem from a backup.
D.Capture a network packet dump from the host and correlate with container logs.
AnswerD

Capturing a host-level packet dump preserves volatile network evidence of the unexpected outbound connections while the container keeps running, and correlating with container logs identifies the process responsible. This satisfies the stem's constraint of investigating without altering the minimal-privilege environment or tipping off an attacker.

Why this answer

Capturing a network packet dump from the host allows the analyst to observe the unexpected outbound connections without altering the container's state or risking privilege escalation. By correlating the packet capture (e.g., using tcpdump or Wireshark) with container logs, the analyst can identify the destination IPs, ports, and protocols involved while maintaining the container's minimal privileges and preserving forensic integrity.

Exam trap

The trap here is that candidates often choose to kill or exec into the container (options B or C) because they assume immediate containment or interactive access is necessary, but the exam tests the understanding that passive network monitoring from the host is the safest and most forensically sound first step.

How to eliminate wrong answers

Option A is wrong because restoring from a trusted image destroys the current container's state, eliminating the ability to investigate the root cause of the unexpected connections. Option B is wrong because using `docker exec` to attach a shell could escalate privileges beyond the container's minimal set, potentially triggering security alerts or altering the runtime environment, and it may not provide network-level visibility. Option C is wrong because immediately killing the container loses volatile data (e.g., active network connections, memory-resident processes) and may prevent capturing the outbound traffic in real time, compromising forensic analysis.

670
MCQmedium

A multinational financial services firm is expanding operations into a new jurisdiction. The legal team has identified that the new country requires all personal data of its citizens to be stored on servers physically located within its borders. The security architect must recommend an approach that satisfies this requirement while maintaining the firm's global security standards. Which of the following should the architect recommend?

A.Implement tokenization so that only non-sensitive tokens are stored in the new jurisdiction while actual data remains in the central repository.
B.Use a content delivery network (CDN) to cache personal data at edge locations closest to the new jurisdiction's users.
C.Encrypt all personal data with customer-managed keys and store it in the firm's existing central data center.
D.Implement data localization by deploying dedicated infrastructure in the new jurisdiction and applying the firm's global security baselines to those systems.
AnswerD

Data localization laws require data to remain within the jurisdiction's borders. Deploying dedicated in-country infrastructure and enforcing the firm's global security baselines satisfies the legal requirement without compromising security consistency. This approach directly addresses the sovereignty mandate while allowing the organization to maintain its standard controls, monitoring, and hardening practices across all environments.

Why this answer

Data localization laws require that personal data of a jurisdiction's citizens be stored on physical servers within that jurisdiction. Deploying dedicated in-country infrastructure and applying the organization's global security baselines directly satisfies this legal requirement while ensuring consistent security controls. Other options either store data outside the jurisdiction or fail to guarantee in-country residency.

Exam trap

The trap here is assuming that encryption or tokenization eliminates the need for physical data residency, when the law explicitly requires data to be stored within the jurisdiction's borders.

671
MCQmedium

A company is implementing a new vendor risk management program. Which of the following is the BEST approach to assess third-party security controls?

A.Check the vendor’s financial stability
B.Use a standardized security questionnaire and conduct on-site audits
C.Rely on the vendor’s self-assessment questionnaire
D.Review only public breach reports about the vendor
AnswerB

Standardised questionnaires give consistent, comparable evidence across every vendor, while on-site audits verify that claimed controls actually operate in practise. Together they satisfy the requirement to assess third-party security controls rather than relying on vendor self-attestation alone.

Why this answer

The best approach to assess third-party security controls is to use a standardized security questionnaire (e.g., based on ISO 27001, NIST, or SIG) combined with on-site audits. This provides a structured, verifiable assessment that goes beyond self-reported claims and allows the organization to validate the vendor's actual security posture.

Exam trap

CAS-005 often tests whether candidates recognize that self-assessment alone is insufficient for vendor risk assessment — the trap is picking 'rely on the vendor's self-assessment questionnaire' because it sounds efficient, but the BEST approach requires independent verification through standardized questionnaires plus audits.

How to eliminate wrong answers

Option A is wrong because financial stability is a business viability concern, not a security control assessment — a financially stable vendor can still have weak security practices. Option C is wrong because relying solely on a vendor's self-assessment questionnaire is insufficient; self-reported data can be inaccurate or incomplete, and without independent verification (audits, evidence review), the assessment lacks rigor. Option D is wrong because reviewing only public breach reports is reactive and incomplete — it only captures known incidents and does not assess the vendor's current controls, policies, or readiness.

672
MCQmedium

A company uses a hybrid cloud model with workloads on AWS and on-premises. They need to ensure secure connectivity between the two environments with high bandwidth and low latency, bypassing the public internet. Which solution should they implement?

A.Configure AWS Direct Connect for dedicated private connectivity
B.Implement SD-WAN with integrated security
C.Establish a site-to-site VPN over the internet
D.Use AWS PrivateLink to access VPC endpoints
AnswerA

AWS Direct Connect provisions a dedicated private network link between on-premises infrastructure and AWS, bypassing the public internet. This satisfies the hybrid requirement for high bandwidth, low latency and consistent connectivity, unlike VPN tunnels that traverse public networks.

Why this answer

AWS Direct Connect provides a dedicated, private network connection between on-premises infrastructure and AWS, bypassing the public internet entirely. It delivers consistent high bandwidth and low latency, which is exactly what hybrid workloads requiring predictable performance need. Because traffic never traverses the public internet, Direct Connect also improves security posture by reducing exposure to internet-based threats.

Exam trap

The trap is confusing 'private connectivity' solutions — candidates pick PrivateLink or VPN thinking they provide dedicated bandwidth, but only Direct Connect offers a dedicated, non-internet circuit with guaranteed performance characteristics.

How to eliminate wrong answers

Option B is wrong because SD-WAN with integrated security optimizes and secures traffic over multiple WAN links, but it still typically uses public internet or MPLS transports and does not provide the dedicated private AWS connectivity the scenario requires. Option C is wrong because a site-to-site VPN runs over the public internet, which introduces variable latency, jitter, and bandwidth constraints — it does not meet the 'bypassing the public internet' requirement. Option D is wrong because AWS PrivateLink provides private connectivity to specific VPC endpoints and services within AWS, not a dedicated high-bandwidth link between on-premises and AWS.

673
MCQeasy

A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

A.$0
B.$5,200
C.$1,000
D.$25,000
AnswerC

Multiplying SLE by ARO gives $5,000 × 0.2 = $1,000, the annualised loss expectancy. This satisfies the stem's requirement to quantify expected yearly loss from the server risk, expressing exposure as a single monetary figure rather than a frequency or per-incident cost.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as SLE × ARO. With an SLE of $5,000 and an ARO of 0.2, the ALE is $5,000 × 0.2 = $1,000. This represents the expected yearly financial loss from the risk event, factoring in how often it is expected to occur.

Exam trap

CAS-005 often tests whether candidates confuse the ALE formula (SLE × ARO) with related formulas like SLE (AV × EF) or with additive/multiplicative errors, catching those who add SLE and ARO or invert the division.

How to eliminate wrong answers

Option A is wrong because $0 would imply either no loss (SLE=0) or no occurrence (ARO=0), neither of which applies here. Option B is wrong because $5,200 is the sum of SLE and ARO, which is not a valid risk formula — ALE is multiplicative, not additive. Option D is wrong because $25,000 is SLE divided by ARO (5,000 / 0.2), which is the inverse of the correct calculation and has no meaning in risk analysis.

674
MCQhard

A healthcare provider is designing a new system to process protected health information (PHI) in a public cloud. The security architect must ensure that data is encrypted at rest and that the organization retains full control over the encryption keys, including the ability to revoke access immediately if a cloud administrator account is compromised. The cloud provider must not be able to decrypt the data. Which of the following key management approaches BEST meets these requirements?

A.Customer-managed keys (CMK) stored in the cloud provider's KMS with key rotation enabled
B.Provider-managed keys stored in the cloud provider's key management service (KMS)
C.Bring Your Own Key (BYOK) where the customer imports keys into the provider's KMS
D.Hold Your Own Key (HYOK) with keys stored in an external hardware security module (HSM) under the organization's control
AnswerD

HYOK keeps the root keys in an external HSM managed by the organization, outside the cloud provider's control. The provider only receives wrapped data keys, so it cannot decrypt data. Revoking access is immediate by disabling the external HSM or key, satisfying all requirements.

Why this answer

HYOK with an external HSM ensures the organization retains sole control of root keys, preventing the cloud provider from decrypting data. Because the external HSM is outside the provider's environment, access can be revoked immediately by disabling the key, which meets the strict confidentiality and revocation requirements for PHI.

Exam trap

The trap here is conflating BYOK with HYOK; BYOK imports keys into the provider's KMS, where the provider can still access them, whereas HYOK keeps keys external and under customer control.

675
MCQmedium

An organization discovers that a vendor's data breach exposed customer PII. The contract with the vendor does not address breach notification. What is the BEST way to prevent this in the future?

A.Purchase cyber insurance covering vendor breaches
B.Terminate the vendor relationship immediately
C.Add a breach notification clause in vendor contracts
D.Conduct more frequent vendor risk assessments
AnswerC

A contractual breach notification clause obliges the vendor to inform the organisation within a defined window, restoring the visibility the current agreement lacks. This is a preventive, contractual control, unlike monitoring or insurance, which only detect or offset harm after the PII exposure occurs.

Why this answer

Adding a breach notification clause directly addresses the contractual gap that left the organization without recourse or timely notification when the vendor suffered a data breach. This contractual remedy ensures that future incidents trigger a predefined notification process, aligning with regulatory requirements such as GDPR or HIPAA that mandate breach notification obligations for data processors. Without such a clause, the organization has no enforceable mechanism to compel the vendor to report breaches, regardless of other risk management activities.

Exam trap

CompTIA often tests the distinction between preventive controls (contractual clauses) and detective/reactive controls (assessments, insurance), leading candidates to choose 'more frequent risk assessments' because it sounds proactive, but only a contract clause creates a binding obligation.

How to eliminate wrong answers

Option A is wrong because cyber insurance covers financial losses after a breach but does not prevent the breach or ensure notification; it is a reactive financial tool, not a preventive contractual control. Option B is wrong because terminating the vendor relationship immediately does not address the root cause—lack of contractual safeguards—and may disrupt operations without guaranteeing that a replacement vendor will have better terms. Option D is wrong because conducting more frequent vendor risk assessments can identify risks but cannot enforce notification obligations; without a contractual clause, the vendor has no legal duty to report breaches discovered during or after assessments.

Page 8

Page 9 of 13

Page 10