CAS-004 Security Architecture Practice Question
An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?
⚠ Common exam trap
CAS-005 often tests the confusion between FedRAMP's focus on security controls and other cloud concerns like data residency or cost — candidates must remember that FedRAMP is fundamentally a security assessment framework for CSPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security controls of the cloud service provider
FedRAMP most directly assesses the security controls of the cloud service provider (CSP). The entire FedRAMP process is designed to evaluate, authorise, and continuously monitor the security posture of a CSP's offering against NIST SP 800-53 controls. While data residency, cost, and performance may be considerations, they are not the primary focus of FedRAMP assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data residency compliance
Why it's wrong here
FedRAMP evaluates the implementation of NIST SP 800-53 security controls; data residency is a separate sovereignty and contractual concern, not a FedRAMP control family. It is tempting because residency often appears in government cloud discussions, but it would be the deciding factor under data-sovereignty mandates, not FedRAMP.
- ✗
Cost optimization of cloud resources
Why it's wrong here
FedRAMP assesses security controls against NIST SP 800-53 baselines for authorisation; cost optimisation falls under FinOps and commercial governance, not the assessment. It is tempting because cloud cost management is a common compliance-adjacent concern, but it would be relevant to financial accountability reviews, not FedRAMP authorisation.
- ✓
Security controls of the cloud service provider
Why this is correct
FedRAMP authorisation directly evaluates the cloud service provider's implementation of NIST SP 800-53 security controls, satisfying the stem's compliance constraint. Assessment covers the provider's control environment, not customer-side configurations or data classification. This makes the CSP's security controls the object of FedRAMP review under Microsoft Entra ID-governed environments.
- ✗
Performance SLA
Why it's wrong here
FedRAMP assesses security controls from NIST SP 800-53, not service-level performance metrics. It is tempting because availability and uptime matter operationally, but FedRAMP authorisation reviews confidentiality, integrity and availability controls; SLAs are contractual, not part of the assessment boundary.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.