Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?

⚠ Common exam trap

The trap is confusing CSPM with CASB or CWPP; candidates see 'cloud security' and pick the malware or access-brokering option without distinguishing posture management from runtime protection or access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitoring and remediating misconfigurations

CSPM tools continuously scan cloud environments for misconfigurations such as publicly exposed storage buckets, overly permissive IAM roles, and disabled logging, then alert or automatically remediate them. This aligns directly with option A. CSPM is a core pillar of cloud-native security alongside CWPP and CIEM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Monitoring and remediating misconfigurations

    Why this is correct

    CSPM continuously compares deployed cloud resource configurations against security baselines and compliance policies, then flags or automatically remediates drift such as public storage buckets or permissive security groups. That misconfiguration monitoring and remediation is precisely the primary function the scenario asks for.

  • ✗

    Brokering access to cloud apps

    Why it's wrong here

    Brokering access to cloud apps is the role of a cloud access security broker, which sits inline between users and SaaS providers to enforce policy. CSPM instead continuously assesses cloud configurations against benchmarks and flags misconfigurations. CASB would be chosen when the requirement is controlling sanctioned app usage and data movement.

  • ✗

    Protecting workloads from malware

    Why it's wrong here

    Malware protection on workloads belongs to endpoint or workload protection platforms, which inspect processes and files at runtime. CSPM evaluates control-plane configuration against security benchmarks and compliance standards. A workload protection platform is correct when the requirement is detecting and blocking malicious execution on running compute.

  • ✗

    Encrypting data at rest

    Why it's wrong here

    Encryption at rest is delivered by the cloud provider's storage-layer controls or customer-managed keys, not by CSPM. CSPM scans configurations and compliance posture, reporting on unencrypted resources rather than performing the encryption itself. It would be the right control when the requirement is cryptographic protection of stored data.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.