CAS-004 Security Architecture Practice Question
An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?
⚠ Common exam trap
The trap is confusing CSPM with CASB or CWPP; candidates see 'cloud security' and pick the malware or access-brokering option without distinguishing posture management from runtime protection or access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Monitoring and remediating misconfigurations
CSPM tools continuously scan cloud environments for misconfigurations such as publicly exposed storage buckets, overly permissive IAM roles, and disabled logging, then alert or automatically remediate them. This aligns directly with option A. CSPM is a core pillar of cloud-native security alongside CWPP and CIEM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Monitoring and remediating misconfigurations
Why this is correct
CSPM continuously compares deployed cloud resource configurations against security baselines and compliance policies, then flags or automatically remediates drift such as public storage buckets or permissive security groups. That misconfiguration monitoring and remediation is precisely the primary function the scenario asks for.
- ✗
Brokering access to cloud apps
Why it's wrong here
Brokering access to cloud apps is the role of a cloud access security broker, which sits inline between users and SaaS providers to enforce policy. CSPM instead continuously assesses cloud configurations against benchmarks and flags misconfigurations. CASB would be chosen when the requirement is controlling sanctioned app usage and data movement.
- ✗
Protecting workloads from malware
Why it's wrong here
Malware protection on workloads belongs to endpoint or workload protection platforms, which inspect processes and files at runtime. CSPM evaluates control-plane configuration against security benchmarks and compliance standards. A workload protection platform is correct when the requirement is detecting and blocking malicious execution on running compute.
- ✗
Encrypting data at rest
Why it's wrong here
Encryption at rest is delivered by the cloud provider's storage-layer controls or customer-managed keys, not by CSPM. CSPM scans configurations and compliance posture, reporting on unencrypted resources rather than performing the encryption itself. It would be the right control when the requirement is cryptographic protection of stored data.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.