Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?

⚠ Common exam trap

CAS-005 often tests the confusion between FedRAMP's focus on security controls and other cloud concerns like data residency or cost — candidates must remember that FedRAMP is fundamentally a security assessment framework for CSPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security controls of the cloud service provider

FedRAMP most directly assesses the security controls of the cloud service provider (CSP). The entire FedRAMP process is designed to evaluate, authorise, and continuously monitor the security posture of a CSP's offering against NIST SP 800-53 controls. While data residency, cost, and performance may be considerations, they are not the primary focus of FedRAMP assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data residency compliance

    Why it's wrong here

    FedRAMP evaluates the implementation of NIST SP 800-53 security controls; data residency is a separate sovereignty and contractual concern, not a FedRAMP control family. It is tempting because residency often appears in government cloud discussions, but it would be the deciding factor under data-sovereignty mandates, not FedRAMP.

  • ✗

    Cost optimization of cloud resources

    Why it's wrong here

    FedRAMP assesses security controls against NIST SP 800-53 baselines for authorisation; cost optimisation falls under FinOps and commercial governance, not the assessment. It is tempting because cloud cost management is a common compliance-adjacent concern, but it would be relevant to financial accountability reviews, not FedRAMP authorisation.

  • ✓

    Security controls of the cloud service provider

    Why this is correct

    FedRAMP authorisation directly evaluates the cloud service provider's implementation of NIST SP 800-53 security controls, satisfying the stem's compliance constraint. Assessment covers the provider's control environment, not customer-side configurations or data classification. This makes the CSP's security controls the object of FedRAMP review under Microsoft Entra ID-governed environments.

  • ✗

    Performance SLA

    Why it's wrong here

    FedRAMP assesses security controls from NIST SP 800-53, not service-level performance metrics. It is tempting because availability and uptime matter operationally, but FedRAMP authorisation reviews confidentiality, integrity and availability controls; SLAs are contractual, not part of the assessment boundary.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.