Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

An organization wants to enforce consistent security policies across multiple cloud providers (AWS, Azure, GCP). Which tool is designed to continuously monitor and remediate misconfigurations in cloud environments?

⚠ Common exam trap

CAS-005 often tests the confusion between CSPM (configuration posture) and CWPP (runtime workload protection) or CASB (data access control), so candidates must map the keyword 'misconfiguration' specifically to CSPM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Security Posture Management (CSPM)

CSPM (Cloud Security Posture Management) tools are purpose-built to continuously scan multi-cloud environments (AWS, Azure, GCP) against benchmarks like CIS, NIST, and PCI DSS, detecting misconfigurations such as public S3 buckets, overly permissive IAM roles, or unencrypted storage. They provide automated remediation workflows and drift detection across providers, which is exactly what the organization needs for consistent policy enforcement. CASB, SIEM, and CWPP address different layers (data access, log correlation, workload runtime) and do not natively deliver cross-cloud configuration posture management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Access Security Broker (CASB)

    Why it's wrong here

    A CASB brokers access between users and cloud services, enforcing data-loss and access policies, but it does not scan infrastructure configurations for misconfigurations. It is tempting because CASBs do span multiple clouds, yet they govern SaaS usage rather than remediate resource settings.

  • ✗

    Security Information and Event Management (SIEM)

    Why it's wrong here

    A SIEM aggregates and correlates log events for detection and alerting, but it does not itself remediate misconfigured cloud resources. It is tempting because SIEMs ingest multi-cloud telemetry, which suits threat detection and compliance reporting rather than configuration enforcement.

  • ✗

    Cloud Workload Protection Platform (CWPP)

    Why it's wrong here

    A CWPP secures running workloads such as containers and virtual machines, not the cloud resource configurations that cause misconfigurations. It is tempting because CWPPs operate across providers, but their scope is runtime protection, whereas configuration posture management is the required capability.

  • ✓

    Cloud Security Posture Management (CSPM)

    Why this is correct

    CSPM continuously monitors multi-cloud infrastructure for misconfigurations and automatically remediates drift, satisfying the requirement to enforce consistent policy across AWS, Azure and GCP. Unlike native tools that operate within a single provider, CSPM normalises posture assessment across heterogeneous environments, directly addressing the cross-provider constraint in the stem.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.