Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?

⚠ Common exam trap

The trap here is conflating immutability with complete runtime security — candidates often assume that if containers cannot be modified, no runtime monitoring is needed, but immutability only protects the filesystem and image, not in-memory or process-level threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prevents unauthorized modifications to running containers

Immutable infrastructure means containers are deployed from a fixed, versioned image and are never modified in place — any change requires redeploying a new container. This design directly prevents unauthorized or accidental modifications to running containers, since the running instance is treated as read-only and any drift is discarded on replacement. The security benefit is integrity enforcement: attackers cannot persist by editing files inside a live container because the container is ephemeral and replaced from a trusted image.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Eliminates need for runtime security monitoring

    Why it's wrong here

    Immutability prevents in-place modification of running containers, yet runtime monitoring still detects exploitation, lateral movement and anomalous process behaviour inside them. Immutability instead shrinks configuration drift and persistence opportunities, and would be chosen to guarantee reproducible, tamper-resistant deployments.

  • ✓

    Prevents unauthorized modifications to running containers

    Why this is correct

    Immutability means running containers are never patched in place; any change requires redeploying a fresh image. Because the container filesystem and process are not writable by operators or attackers, unauthorised modification of a live container is prevented, satisfying the stem's requirement directly.

  • ✗

    Allows use of privileged containers securely

    Why it's wrong here

    Immutability freezes container filesystems at build time; it neither grants nor safely permits privileged mode, which requires kernel capabilities and seccomp restrictions. It is tempting because immutable images resist tampering, but privileged containers remain a host-escape risk regardless of image immutability.

  • ✗

    Reduces image scanning frequency

    Why it's wrong here

    Immutability prevents runtime drift, so containers are replaced rather than patched, but it does not remove the need to scan images for vulnerabilities before deployment. Scanning frequency is governed by your CI/CD pipeline and registry policies, not by whether running containers are immutable. This option would suit a question about optimising scanner scheduling.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.