CAS-004 Security Architecture Practice Question
An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?
⚠ Common exam trap
The trap here is conflating immutability with complete runtime security — candidates often assume that if containers cannot be modified, no runtime monitoring is needed, but immutability only protects the filesystem and image, not in-memory or process-level threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prevents unauthorized modifications to running containers
Immutable infrastructure means containers are deployed from a fixed, versioned image and are never modified in place — any change requires redeploying a new container. This design directly prevents unauthorized or accidental modifications to running containers, since the running instance is treated as read-only and any drift is discarded on replacement. The security benefit is integrity enforcement: attackers cannot persist by editing files inside a live container because the container is ephemeral and replaced from a trusted image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eliminates need for runtime security monitoring
Why it's wrong here
Immutability prevents in-place modification of running containers, yet runtime monitoring still detects exploitation, lateral movement and anomalous process behaviour inside them. Immutability instead shrinks configuration drift and persistence opportunities, and would be chosen to guarantee reproducible, tamper-resistant deployments.
- ✓
Prevents unauthorized modifications to running containers
Why this is correct
Immutability means running containers are never patched in place; any change requires redeploying a fresh image. Because the container filesystem and process are not writable by operators or attackers, unauthorised modification of a live container is prevented, satisfying the stem's requirement directly.
- ✗
Allows use of privileged containers securely
Why it's wrong here
Immutability freezes container filesystems at build time; it neither grants nor safely permits privileged mode, which requires kernel capabilities and seccomp restrictions. It is tempting because immutable images resist tampering, but privileged containers remain a host-escape risk regardless of image immutability.
- ✗
Reduces image scanning frequency
Why it's wrong here
Immutability prevents runtime drift, so containers are replaced rather than patched, but it does not remove the need to scan images for vulnerabilities before deployment. Scanning frequency is governed by your CI/CD pipeline and registry policies, not by whether running containers are immutable. This option would suit a question about optimising scanner scheduling.
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.