CAS-005 · domain
Security Engineering
Security Engineering is 31% of CAS-005 and covers designing and implementing secure systems. Expect scenario questions on MFA factor selection, certificate pinning, secure boot chains, firmware signing, and cryptographic protections across cloud, endpoint, and embedded environments. Answers hinge on matching controls to stated threats, not memorizing definitions.
Focused practice
Practice Security Engineering questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Engineering
You must design and validate layered controls: pick phishing-resistant MFA, pin the correct certificate, enforce a hardware-rooted boot chain, and require signed firmware. The single most important skill is mapping each control to the specific threat and trust boundary described in the scenario.
Selecting phishing-resistant MFA such as FIDO2/WebAuthn over TOTP or push
Pinning leaf or intermediate CA certificates in mobile app code
Verifying secure boot chain of trust from ROM to bootloader to kernel
Signing firmware and validating signatures before installation on IoT devices
Watch out for
Common Security Engineering exam traps
- ▸Choosing push-based MFA as phishing-resistant when only FIDO2/WebAuthn or certificate-based authentication meets that requirement
- ▸Pinning the root CA instead of the leaf or intermediate certificate, weakening protection against compromised intermediates
- ▸Assuming secure boot alone secures updates; firmware must also be signed and verified at install time
Question index
All Security Engineering questions (147)
Click any question to see the full explanation, or start a practice session above.
A security administrator is configuring IPsec VPN between two sites. The data transmitted includes sensitive financial records. The administrator wants to ensure both confidentiality and integrity of the data, and also wants to authenticate the source. Which IPsec protocol and mode should be used?
Medium2A company is deploying IoT sensors that require secure firmware updates over the air (OTA). To ensure integrity and authenticity of the firmware, which of the following should be implemented?
Medium3A security analyst is reviewing a packet capture and observes that a client and server negotiate a session key using ephemeral Diffie-Hellman, after which all application data is encrypted with a symmetric cipher. The analyst wants to document which security property the ephemeral key exchange provides that a static RSA key transport would not. Which property is that?
Easy4A security engineer is configuring a hardware security module (HSM) to protect a root certificate authority's private key. The requirement is that the key must never exist in plaintext outside the HSM and must be usable by multiple authorized administrators under dual control. Which configuration BEST satisfies these requirements?
Hard5A security engineer is configuring a secure boot process for a Linux server using UEFI. The engineer wants to ensure that only signed bootloaders and kernels are executed. Which of the following components is responsible for verifying the signature of the bootloader?
Medium6A security engineer is designing a system that must protect data at rest on a database server. The organization requires that the encryption keys never leave a hardware module and that the module be resistant to physical tampering. The engineer deploys a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. Which of the following BEST describes the security property provided by this validation level?
Medium7A security engineer is configuring a web application firewall (WAF) to protect against injection attacks. The application uses a relational database and reflects user input in HTML pages. The engineer must choose a WAF rule set that provides the BEST protection with minimal false positives. Which approach should the engineer take?
Medium8A security engineer is hardening a Linux bastion host that provides administrative access to production servers. The organization requires that all administrative sessions be cryptographically bound to a hardware-backed credential and that session recordings be tamper-evident. Which TWO controls BEST satisfy these requirements? (Choose two.)
Medium9An organization wants to implement passwordless authentication using FIDO2/WebAuthn. Which of the following best describes the primary security advantage of this approach over traditional password-based authentication?
Easy10A security administrator must ensure that log data collected from servers across multiple sites cannot be altered or deleted by an attacker who compromises a single server. Which of the following BEST achieves this?
Easy11A security engineer is configuring a wireless network for a corporate office. The network must support 802.1X authentication with EAP-TLS, and the engineer wants to ensure that only devices with valid certificates issued by the corporate CA can connect. Which of the following should the engineer configure on the RADIUS server to enforce this requirement?
Medium12A security engineer is configuring IPsec VPN between two sites. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode and protocol should be used?
Hard13A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect needs to ensure that inter-service communication is secure, that services can authenticate each other, and that access to services is controlled based on identity. Which TWO of the following should be implemented? (Choose two.)
Hard14A security architect is designing a secure boot chain for an IoT device. Which THREE components are essential to ensure the integrity of the firmware update process? (Select THREE.)
Medium15A security architect is designing a cross-domain solution that must move data between a classified network and an unclassified network. The requirement is to enforce a formally verified, non-bypassable policy that prevents any high-to-low leakage, while still permitting a controlled release of approved structured data. Which design element is MOST appropriate to satisfy this requirement?
Hard16A network administrator needs to establish a secure VPN tunnel between two branch offices using IPsec. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode should be used?
Easy17A security operations center (SOC) is implementing a new SIEM and wants to improve detection of credential-based attacks. The team plans to ingest Windows Security event logs and create correlation rules. Which TWO event IDs should the SOC prioritize to detect a brute-force attack against local accounts? (Choose two.)
Medium18An organization is implementing IPsec VPNs between sites. The security team wants to ensure data integrity and authentication but is less concerned about confidentiality for this particular link. Which IPsec protocol and mode should they use?
Medium19A security engineer is configuring a Linux server to enforce encrypted remote administration. The requirement is that after the initial key exchange, session keys must be rotated periodically to limit the impact of a compromised session key. Which OpenSSH configuration directive should the engineer use to achieve this?
Medium20A security administrator is reviewing the configuration of a wireless network. The network uses WPA3-Enterprise with 802.1X authentication. The administrator wants to ensure that the authentication server validates the identity of the supplicant before granting network access. Which protocol should be used to encapsulate the authentication credentials?
Easy21A security architect is evaluating a hardware security module (HSM) deployment for a certificate authority. The requirement is that private keys must never leave the HSM in plaintext, and that key operations must be auditable. During a review, the architect learns that the HSM supports key wrapping for backup. Which of the following is the MOST important control to verify?
Hard22A security engineer must ensure that log data collected from production servers cannot be altered or deleted by an attacker who gains administrative access to those servers. The logs must remain verifiable for audit purposes. Which of the following designs BEST achieves this?
Medium23A security engineer is configuring a wireless network for a hospital. The network must support legacy medical devices that only support WPA2-Personal with pre-shared keys (PSK) and cannot be upgraded. The hospital also wants to prevent unauthorized devices from connecting and to detect rogue access points. Which of the following should the engineer implement to BEST meet these requirements?
Hard24A security administrator is configuring a firewall to allow only encrypted remote administration traffic to a server. The administrator wants to use a protocol that provides confidentiality and integrity for the management session. Which of the following should be used?
Easy25A cloud security engineer is designing an architecture where workloads in a virtual private cloud must reach an on-premises database over a site-to-site VPN. The requirement is that only the database subnet can be reached, no other on-premises networks, and traffic must be encrypted in transit. Which design BEST satisfies this?
Medium26A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)
Medium27A security architect is designing a network segmentation strategy for a critical industrial control system (ICS) environment. The architect must ensure that unauthorized devices cannot communicate with the ICS network even if they gain physical access to a network port. The architect decides to implement IEEE 802.1X with MAC Authentication Bypass (MAB) as a fallback. Which of the following is the MOST significant security weakness introduced by enabling MAB?
Hard28A company is implementing MFA for remote access. Which TWO factors are considered possession factors?
Easy29A financial services company is deploying a new internal web application that must meet PCI DSS requirements for encrypting cardholder data in transit. The security engineer must configure TLS to ensure that only ephemeral key exchanges are used and that compromised long-term keys cannot decrypt past sessions. Which of the following should the engineer implement?
Medium30A security engineer is deploying a new wireless network for a corporate campus and must ensure that all client traffic is protected with strong encryption and that the network does not rely on a pre-shared key. Which configuration should the engineer implement?
Easy31A company is implementing a Privileged Access Management (PAM) solution to manage admin credentials. Which feature allows administrators to request temporary elevated access for a specific task?
Medium32A security architect is designing a network segmentation scheme for a containerized workload running on a Kubernetes cluster. The requirement is to enforce least-privilege communication between microservices at Layer 3 and Layer 4, and to ensure that only explicitly allowed traffic can flow between pods, even within the same namespace. Which of the following should the architect implement?
Hard33A company is implementing measured boot using TPM 2.0. What is the primary purpose of storing boot measurements in Platform Configuration Registers (PCRs)?
Medium34A security team is deploying a hardware security module (HSM) to protect the root of trust for a code-signing pipeline. The team must ensure that signing keys cannot be extracted and that all signing operations are attributable to an authorized operator. Which TWO controls BEST meet these requirements? (Choose two.)
Medium35A security engineer is deploying a wireless network for a corporate campus that must authenticate users with 802.1X and protect credentials from eavesdropping. The engineer configures a RADIUS server and WPA3-Enterprise. Which TWO additional configuration elements are required to establish a mutually authenticated, encrypted EAP tunnel before the supplicant's identity is exposed? (Choose two.)
Medium36An organization wants to implement passwordless authentication for its employees using FIDO2/WebAuthn. What is a primary security advantage of this approach over traditional password-based MFA?
Medium37An organization wants to implement a privileged access management (PAM) solution to manage administrative credentials. They require that administrators request temporary access to privileged accounts and that these credentials are automatically rotated after each use. Which PAM approach best meets these requirements?
Hard38A security architect is designing a PKI for a large enterprise that issues certificates to thousands of users and devices. The architect wants to implement a mechanism to efficiently check certificate revocation status without requiring clients to download a full CRL. Which TWO technologies should be considered?
Medium39A security engineer is implementing a solution to protect sensitive data stored in a database. The requirement is to ensure that even if the database files are stolen, the data cannot be read without access to a hardware security module (HSM). Which of the following should the engineer implement?
Medium40A security architect is designing a key management system for a multinational corporation that must comply with FIPS 140-3 Level 3. The system will store long-term asymmetric private keys used for digital signatures. The architect must ensure that the private keys are protected against physical extraction and that cryptographic operations are performed within a tamper-responsive environment. Which of the following is the MOST appropriate solution?
Hard41A security engineer is configuring a Linux web server that must accept TLS connections only from clients presenting a valid client certificate issued by the corporate internal CA. The engineer adds `SSLVerifyClient require` to the Apache configuration, restarts the service, and finds that all connections now fail with a handshake error. Which of the following is the MOST likely cause?
Medium42A security analyst is investigating a potential side-channel attack on an IoT device. The device's cryptographic operations show variable execution times based on the key and plaintext. Which mitigation is most effective against timing attacks?
Hard43An organization is deploying a just-in-time (JIT) privileged access management solution. What is a key benefit of JIT access compared to standing privileged accounts?
Medium44A security architect is designing segmentation for an industrial control network that runs Modbus/TCP between engineering workstations and programmable logic controllers. The architect wants to prevent an attacker who compromises a workstation from issuing unauthorized write commands to the controllers, while avoiding disruption of legitimate polling traffic. Which control BEST addresses the specific risk?
Hard45A security engineer is designing a hybrid encryption solution for a messaging application. The requirement is that each message must be encrypted with a unique symmetric key, and that symmetric key must be delivered to the recipient without exposing it to the server. The solution must also support sender authentication. Which combination of cryptographic mechanisms BEST satisfies these requirements?
Medium46An organization is implementing a PKI and wants to ensure that clients can quickly check if a certificate has been revoked without downloading a large list. Which protocol should be used?
Easy47A financial services firm must protect cardholder data in a database and wants a control that renders the data unreadable to database administrators and to anyone who steals a backup, while still allowing the application to run equality lookups on the protected column. Which approach BEST meets these requirements?
Medium48During a security audit, it is discovered that a critical server uses SSH with password authentication and supports weak key exchange algorithms. Which of the following is the most effective hardening step to prevent brute-force attacks and ensure forward secrecy?
Hard49A security engineer is deploying a zero trust architecture for a hybrid cloud environment. The organization wants to enforce least privilege access to internal APIs. The engineer must select TWO mechanisms that provide continuous authentication and authorization for each API request. (Choose two.)
Hard50An organization is implementing SSH hardening for server access. Which configuration change most effectively reduces the attack surface against brute-force and credential theft?
Medium51A security architect must protect data at rest on a database server while allowing a backup application to read the raw encrypted files without ever holding the plaintext data key. The architect wants a design where a hardware security module (HSM) enforces key usage policy and keys never leave the module in plaintext. Which approach BEST satisfies these requirements?
Hard52A systems administrator is hardening a Linux server that stores regulated data. The requirement is that the server's filesystem must detect unauthorized modification of files at rest, including offline tampering with the disk. Which control BEST meets this requirement?
Easy53An organization is deploying a new IoT device that must securely update its firmware over the air (OTA). The device has limited processing power and memory. Which cryptographic solution would provide the BEST balance of security and performance for verifying firmware updates?
Easy54A security architect is designing a data-at-rest protection scheme for a database that stores regulated records on a shared storage array. The requirement is to ensure that even if an administrator copies the raw storage volume, the data cannot be read, and that the keys are never accessible to the storage administrator. Which of the following BEST meets these requirements?
Medium55A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The architect plans to use full-disk encryption (FDE) with a TPM 2.0 module. Which of the following BEST describes a limitation of this approach that the architect must address?
Hard56A company wants to implement certificate pinning for its mobile application to prevent man-in-the-middle attacks. Which of the following is the BEST practice when implementing certificate pinning?
Easy57A security engineer is configuring a TLS 1.3 connection between a web server and client. Which feature is unique to TLS 1.3 and provides reduced latency for returning clients?
Easy58A security team wants to implement a certificate pinning strategy for their mobile application to prevent man-in-the-middle attacks. Which of the following should be pinned in the application code?
Easy59A security engineer is reviewing how a Transport Layer Security session derives its keys and protects data. The engineer wants to identify the mechanisms that provide confidentiality and integrity for application data in TLS 1.3. (Choose two.)
Medium60A security assessor is evaluating an application that uses ChaCha20-Poly1305 for encryption. Which TWO of the following are true about this cryptographic algorithm?
Hard61A security architect is selecting a cipher suite for TLS 1.3 to ensure forward secrecy and high performance. Which cipher suite should be recommended?
Easy62A security engineer is implementing a secure boot process for an embedded device. The engineer needs to ensure that only trusted firmware is executed and that the integrity of the boot chain is maintained. Which TWO of the following are essential components of a secure boot implementation? (Choose two.)
Medium63A security administrator is hardening a Linux server that hosts a public web application. The administrator wants to reduce the attack surface by restricting which services are accessible from the internet. Which of the following actions BEST achieves this?
Easy64A security administrator is configuring SSH for a jump host used to access critical servers. Which of the following is the most secure configuration option to restrict authentication and reduce the attack surface?
Medium65A security engineer is hardening an SSH server. The policy requires disabling all legacy algorithms and using only modern, secure cryptography. Which THREE of the following configurations should the engineer apply?
Hard66Which key exchange algorithm provides perfect forward secrecy (PFS) and is recommended for use in TLS 1.3?
Easy67A security analyst is investigating a compromised Linux web server. The analyst needs to preserve volatile evidence before shutting the system down for forensic imaging. Which action should the analyst perform FIRST?
Easy68A company is evaluating multi-factor authentication methods. Which TWO are considered phishing-resistant? (Select TWO.)
Medium69A security engineer is implementing a network access control (NAC) solution that must authenticate users and devices before granting access to the corporate network. The organization wants to use a protocol that supports both authentication and authorization and can carry attributes such as VLAN assignment and ACLs. The engineer decides to use RADIUS. Which of the following statements about RADIUS is correct?
Medium70A security architect must protect a REST API that issues short-lived, signed access tokens. The design goal is to prevent a compromised authorization server from minting tokens that other resource servers will accept after the compromise is detected, without requiring resource servers to poll a central service on every request. Which design BEST meets this goal?
Hard71A security engineer is configuring a Linux bastion host that must expose SFTP to external partners while preventing interactive shell access for those same partner accounts. Partner keys are already deployed in each account's authorized_keys file. Which sshd_config directive combination BEST satisfies this requirement?
Medium72A security architect is designing a system that requires hardware-enforced isolation for sensitive computations. Which technology provides the strongest isolation by running code in a protected environment within the CPU?
Hard73A security administrator is hardening SSH access to a jump host. The requirement is to allow only key-based authentication and restrict the use of weak cryptographic algorithms. Which of the following configurations accomplishes this?
Medium74An organization wants to implement a hardware root of trust for measuring system integrity at boot. Which technology should be used to store measurements in Platform Configuration Registers (PCRs) and support remote attestation?
Medium75A security engineer is configuring a Linux bastion host that must use only the strongest key-exchange method available in OpenSSH, avoiding any Diffie-Hellman group that relies on finite-field modular exponentiation. Which sshd_config directive setting should the engineer apply?
Medium76A company is deploying a just-in-time (JIT) privileged access management solution. Which of the following BEST describes a key security benefit of JIT access?
Hard77An IoT device manufacturer wants to ensure secure firmware updates. Which approach best protects against malicious firmware being installed on devices?
Medium78Which of the following is a primary advantage of using ChaCha20-Poly1305 over AES-256-GCM in certain environments?
Easy79An organization requires a cryptographic algorithm that provides both encryption and authentication in a single pass. Which algorithm should be selected?
Medium80A security architect is designing a microservices platform that runs on a shared Kubernetes cluster. Each service must be able to prove its identity to other services, and the design must avoid long-lived shared secrets and support automatic credential rotation when a pod is rescheduled. Which approach BEST meets these requirements?
Medium81A security engineer is implementing a hardware security module (HSM) to protect cryptographic keys used by a certificate authority (CA). The engineer must ensure that the HSM provides strong protections against key extraction and unauthorized use. Which of the following are security properties that the HSM should provide? (Choose two.)
Hard82A security architect is designing key management for a backup platform that stores encrypted archives in cloud object storage. The requirement is that destroying a single small piece of key material must render all archived data permanently unrecoverable, even if an attacker later obtains a full copy of the storage bucket and the wrapped data keys. Which design BEST meets this requirement?
Hard83A security engineer is implementing a secure enclave using Intel SGX for a sensitive application. The engineer must ensure that the enclave's memory is protected from a compromised operating system. Which of the following BEST describes how SGX achieves this protection?
Hard84A security administrator is reviewing the configuration of a wireless network that uses WPA3-Enterprise. The administrator wants to ensure that the authentication mechanism provides mutual authentication and supports centralized policy enforcement. Which of the following should be used?
Easy85A security architect is designing a PKI hierarchy for a large enterprise that issues certificates for internal users, devices, and code signing. Which of the following best practices should be implemented to minimize the impact of a CA compromise?
Medium86A security engineer must select a cryptographic hash function for a new code-signing service that will protect firmware for at least 15 years. The service must resist length-extension attacks and provide collision resistance against well-funded adversaries. The organization's policy requires FIPS 140-3 validated modules only. Which hash function BEST meets these requirements?
Hard87A security architect is designing a system that requires cryptographic separation of duties for key management. The organization wants to ensure that no single administrator can both generate and use a key without oversight. Which of the following key management practices BEST achieves this requirement?
Hard88A security engineer is reviewing the configuration of a web server that uses TLS 1.3. The engineer wants to ensure that the server supports perfect forward secrecy (PFS) and uses strong cipher suites. Which of the following cipher suites should be selected?
Medium89A security engineer is configuring a Linux web server that hosts a public-facing application. The server's SSH daemon must be hardened to prevent brute-force attacks and unauthorized access. The engineer has already disabled root login and password authentication. Which additional control should the engineer implement to restrict access to only authorized administrative users?
Medium90A security engineer is configuring a Linux server that hosts a web application. The server must accept connections only from the internal network 10.0.0.0/24 and must reject all other incoming traffic. The engineer decides to use iptables. Which command sequence correctly implements this requirement?
Medium91A system administrator needs to securely store cryptographic keys and perform signing operations in a tamper-resistant hardware device. Which solution should be used?
Easy92A security administrator is hardening a web server and wants to ensure that browsers cannot be tricked into sending requests over plain HTTP after an initial HTTPS visit. The administrator also wants to prevent protocol-downgrade attacks against the site. Which response header should be configured?
Easy93A security architect is designing a zero trust architecture for a hybrid environment where users access internal applications from managed and unmanaged devices. The requirement is that access decisions consider device health and user identity on every request rather than relying on network location. Which of the following BEST implements this requirement?
Hard94A security team is deploying a zero trust architecture for an enterprise campus. The design must verify every request as though it originated from an untrusted network and must limit lateral movement after a workstation compromise. Which TWO capabilities are essential to this design? (Choose two.)
Hard95A company is migrating its legacy VPN to use IPsec with IKEv2. The security team wants to ensure the strongest possible security. Which THREE configuration options should be selected?
Hard96A security architect is designing a just-in-time (JIT) privileged access management (PAM) solution. Which TWO of the following are key characteristics of JIT access?
Medium97A security engineer is hardening a containerized workload platform against attacks that escape a container and reach the host kernel. The team wants to reduce the kernel attack surface available to each container without breaking application functionality. Which TWO measures BEST accomplish this? (Choose two.)
Hard98A security engineer is configuring SSH for a jump host used to access critical servers. The engineer wants to restrict the cryptographic algorithms to the most secure options. Which of the following should be DISABLED?
Medium99A security team is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to prevent a compromised pod from reaching the cloud metadata service at 169.254.169.254 to steal node credentials, while still allowing pods to reach required external APIs. Which of the following should the team implement?
Hard100A security engineer is designing the key-management lifecycle for a hardware security module (HSM) that will hold a root certificate authority signing key. The requirement is that the private key must never exist in plaintext outside the HSM, even during backup, and that restoration must be possible after a total device failure. Which approach BEST satisfies these requirements?
Medium101A security engineer is implementing a secure software development lifecycle (SDLC) for a new application. The engineer needs to integrate security activities that help identify and mitigate vulnerabilities early in the development process. Which of the following activities should be included? (Choose two.)
Hard102A security analyst is reviewing cryptographic implementations for a new application. The application needs to support digital signatures that are quantum-resistant and provide high performance. Which TWO algorithms should the analyst consider? (Select TWO.)
Hard103A security administrator is configuring a Linux server to enforce mandatory access control (MAC) for a web application. The administrator wants to confine the web server process to only access its own files and network ports, even if the process is compromised. Which of the following should the administrator implement?
Medium104A security engineer is reviewing a TLS 1.3 configuration. Which of the following is a key feature of TLS 1.3 that improves security compared to earlier versions?
Hard105A PKI administrator is concerned about the risk of a compromised issuing CA. Which certificate transparency feature helps detect unauthorized certificate issuance?
Medium106A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The requirement is to prevent a compromised pod from reading another tenant's secrets and from making unauthorized network connections to other namespaces. Which of the following combinations BEST addresses both concerns?
Hard107An organization is implementing a PKI to issue certificates for internal applications. The security team wants to minimize the risk of compromise to the root CA. Which of the following is the BEST practice to protect the root CA?
Easy108A security engineer is configuring an internal certificate authority that must issue end-entity certificates to servers on a private network. Corporate policy requires that the CA's private key never reside on a network-connected host, and that certificate issuance be a deliberate, low-volume operation. Which of the following should the engineer implement to BEST meet these requirements?
Medium109A security architect is designing a network segmentation strategy for a data center that hosts both web servers and database servers. The architect wants to ensure that if a web server is compromised, the attacker cannot directly access the database servers. The architect plans to implement microsegmentation using software-defined networking (SDN). Which TWO of the following are essential components to achieve this goal? (Choose two.)
Hard110A company is implementing a privileged access management (PAM) solution to reduce the risk of standing privileges. Which feature allows users to request temporary elevated access for a specific task, which is automatically revoked after the task is completed?
Medium111A security engineer is implementing network segmentation to isolate a PCI DSS environment from the corporate network. The engineer plans to use VLANs and a firewall. Which TWO of the following are essential to ensure that the segmentation is effective and compliant? (Choose two.)
Medium112A security administrator is configuring a Linux server that will host a public-facing web application. The administrator wants to ensure that the server's SSH service is protected against brute-force attacks by limiting the number of failed authentication attempts and blocking offending IP addresses. Which of the following should the administrator implement?
Easy113An incident response team discovers that an attacker was able to forge a certificate for a legitimate domain. Which TWO mechanisms should the team implement to detect and prevent such misissuance in the future? (Select TWO.)
Hard114An organization uses a TPM 2.0 for measured boot and attestation. Which TPM feature ensures that the boot process has not been tampered with by measuring each component before it executes?
Medium115An enterprise is deploying a multi-factor authentication (MFA) solution. The security team requires a factor that is resistant to phishing and does not rely on shared secrets. Which of the following MFA types BEST meets this requirement?
Easy116An organization is planning to deploy a new internal CA hierarchy. Which THREE considerations are critical for ensuring the security and manageability of the PKI?
Hard117A security engineer is implementing a zero trust architecture for a corporate network. The engineer must ensure that all access requests are continuously verified and that least privilege is enforced. Which TWO components are essential to achieve these goals? (Choose two.)
Medium118A company is implementing a passwordless authentication solution using FIDO2/WebAuthn. What is the primary security advantage of this approach over traditional password-based authentication?
Easy119A security architect is designing a data-at-rest protection scheme for a multi-tenant SaaS platform. The requirement is that each tenant's data be encrypted with a unique key, and that compromise of one tenant's key never exposes another tenant's data. The platform must support cryptographic erasure of a single tenant without re-encrypting the entire database. Which design BEST satisfies these requirements?
Medium120A security engineer is configuring a VPN between two sites and needs to ensure data confidentiality and integrity. Which IPsec mode and protocol combination should be used to encrypt the entire IP packet including the header?
Easy121An IoT device manufacturer wants to ensure the security of over-the-air (OTA) firmware updates. Which TWO measures are essential to protect the update process?
Easy122A security architect is designing a network for a financial services firm. The firm requires that all data in transit between its internal microservices be encrypted and mutually authenticated, but the services run in a containerized environment where static IP addresses are not available. Which of the following is the MOST appropriate solution to meet these requirements?
Medium123A security architect is designing a VPN that requires both authentication and encryption. Which IPsec protocol provides both services in a single protocol?
Easy124During a penetration test, an assessor successfully exploits a timing side-channel attack to extract an ECDSA private key from a secure enclave. Which TWO mitigations should the development team implement to prevent such attacks? (Select TWO.)
Hard125A company is implementing privileged access management (PAM) for its critical servers. Which THREE practices should be included to enhance security? (Select THREE.)
Medium126A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for known attack patterns. The administrator wants to ensure that the NIDS can detect a specific SQL injection attempt that uses a particular string. Which Snort rule action and option combination will BEST accomplish this?
Medium127A security engineer is configuring a Linux server that hosts a web application. The engineer needs to ensure that the application runs with the least privilege necessary and that any compromise of the application is confined to a limited set of system resources. Which of the following should the engineer implement?
Medium128A security administrator is configuring a RADIUS server for a wireless network. The administrator wants to ensure that the shared secret between the access point and the RADIUS server is protected against eavesdropping. Which protocol should be used to encapsulate RADIUS traffic?
Easy129A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect must ensure that inter-service communication is encrypted, mutually authenticated, and that services can be authorized based on their identity. Which of the following should the architect implement to meet these requirements?
Hard130A security architect is designing a system that requires secure key exchange over an untrusted network. The system must provide perfect forward secrecy (PFS) and must be resistant to quantum computer attacks. Which key exchange algorithm BEST meets these requirements?
Hard131An IoT device uses a Trusted Platform Module (TPM) 2.0 for secure boot and attestation. Which THREE of the following functions does the TPM provide to support these security features?
Medium132A security architect is designing a new authentication system for a cloud-based application that requires strong multi-factor authentication. The solution must be resistant to phishing attacks and not rely on shared secrets. Which of the following is the BEST choice?
Medium133A security architect is designing a zero trust architecture for a hybrid workforce that accesses internal applications from managed and unmanaged devices. The architect wants to enforce continuous verification of device and user trust for every session. Which TWO controls are essential to meet this goal? (Choose two.)
Hard134A company is deploying IoT sensors in a harsh environment. The sensors have limited processing power and memory. Which of the following cryptographic algorithms is most suitable for ensuring data confidentiality with minimal overhead?
Medium135Which of the following certificate types is most appropriate for an organization that needs to validate the identity of individuals for email encryption and signing?
Easy136A security engineer is implementing a secure boot process for a Linux server. The requirement is to ensure that only signed and trusted kernel modules can be loaded, preventing rootkits from persisting. Which mechanism should the engineer enable?
Hard137A security administrator is configuring a wireless network for a small office. The requirement is to use the strongest available encryption and authentication method that is supported by modern devices and does not require a separate authentication server. Which of the following should the administrator choose?
Easy138An organization is setting up a PKI with a three-tier hierarchy (root CA, issuing CA, and registration authority). Which TWO of the following are best practices for securing the root CA?
Medium139A security architect is designing a secure boot process for a new line of embedded devices. The boot ROM loads the bootloader, which then loads the OS kernel. To ensure that only signed code is executed, which mechanism should the bootloader use to verify the kernel?
Medium140An organization is moving to a passwordless authentication approach. They require a solution that supports hardware-based cryptographic authentication and is resistant to phishing. Which standard should they implement?
Medium141A security engineer is implementing an integrity-monitoring solution for a fleet of Linux servers that must detect unauthorized changes to critical binaries and configuration files. The solution must provide a cryptographic baseline, resist tampering by an attacker with root privileges, and support automated verification. Which approach BEST meets these requirements?
Hard142A security engineer is designing a system that must enforce mandatory access control (MAC) based on security labels. The system must ensure that users cannot read data above their clearance level and cannot write data to lower classification levels. Which security model BEST fits these requirements?
Hard143A security architect must protect a hardware security module's firmware against an attacker who has physical access and can measure power consumption and electromagnetic emissions during signature operations. The architect wants a countermeasure that makes the secret key statistically uncorrelated with the observable side-channel leakage. Which approach BEST meets this goal?
Hard144A security engineer is implementing secure boot for an embedded Linux device that uses U-Boot. The requirement is to ensure that only authenticated firmware can execute, and that the root of trust is immutable. Which of the following should the engineer implement?
Hard145A security administrator is troubleshooting a web application that intermittently rejects valid user sessions. Logs show the application server's clock drifted several minutes behind the authentication service, and the tokens carry short validity windows with issued-at and expiry claims. Which action MOST directly resolves the intermittent rejections?
Easy146A security analyst is reviewing TLS 1.3 configuration for a web server. The analyst wants to ensure that the configuration provides forward secrecy and prevents the reuse of session keys. Which of the following is a characteristic of TLS 1.3 that supports these goals?
Medium147A security analyst is reviewing the configuration of a web application firewall (WAF) protecting an e-commerce site. The analyst notices that the WAF is in detection-only mode. The site has been experiencing SQL injection attacks that are not being blocked. Which of the following actions should the analyst take to BEST protect the site while minimizing false positives?
MediumOther domains
All CAS-005 exam domains
Frequently asked questions
- What does the Security Engineering domain cover on the CAS-005 exam?
- You must design and validate layered controls: pick phishing-resistant MFA, pin the correct certificate, enforce a hardware-rooted boot chain, and require signed firmware. The single most important skill is mapping each control to the specific threat and trust boundary described in the scenario.
- How many questions are in this domain?
- This page lists all 147 Security Engineering questions in the CAS-005 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Engineering questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.