mediumMultiple ChoiceObjective-mapped
CAS-004 Practice Question: Based on the exhibit, what vulnerability is…
Exhibit
Refer to the exhibit. Firewall rule: rule id 10: allow source 203.0.113.0/24 destination 10.0.1.100 service any
Based on the exhibit, what vulnerability is present in the firewall rule?
⚠ Common exam trap
The CASP+ exam often tests the distinction between overly permissive service definitions and broad source IP ranges. Candidates mistakenly focus on the source subnet being 'too broad' when the real flaw is the 'any' service specification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Overly permissive service specification
The firewall rule permits 'any' as the service, meaning all TCP/UDP ports and protocols are allowed through. This is overly permissive because it bypasses the principle of least privilege, exposing the internal network to unnecessary traffic and potential attacks. A proper rule should specify only required services (e.g., TCP/443 for HTTPS) to minimize the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Overly permissive service specification
Why this is correct
Allowing 'any' service gives full access to all ports and protocols.
- ✗
Source IP range is too broad
Why it's wrong here
The /24 subnet is a standard size and not overly broad.
- ✗
No logging is enabled
Why it's wrong here
While logging is good, its absence is not a vulnerability.
- ✗
Missing application ID control
Why it's wrong here
Application ID is not required for basic firewall rules.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.