hardMultiple Choice
CAS-004 Practice Question: During a compliance audit, an organization's…
During a compliance audit, an organization's security team discovers that sensitive data in a legacy database is stored in plaintext. The database is critical for operations and cannot be taken offline for patching until the next maintenance window in three months. Which of the following is the BEST compensating control to reduce risk immediately?
⚠ Common exam trap
The key trap is that encryption solutions like TDE or file-level encryption require database downtime or reconfiguration, which is not permitted in the scenario. Network access control provides immediate risk reduction without touching the database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict network access to the database to only authorized applications
Restricting network access to the database to only authorized applications is the best compensating control because it immediately reduces the attack surface without requiring any changes to the database itself. By implementing a host-based firewall or network ACLs that limit inbound connections to only specific application servers (e.g., via IP whitelisting and port restrictions), the organization can prevent unauthorized users or malware from directly querying the plaintext data. This control is operational immediately, does not require downtime, and aligns with the principle of least privilege, making it the most practical short-term risk mitigation while awaiting the maintenance window.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict network access to the database to only authorized applications
Why this is correct
Restricting network access to authorised applications only shrinks the attack surface without touching the database, so it can be applied immediately while patching waits three months. It directly mitigates exposure of plaintext data by preventing unauthorised hosts from reaching the database.
- ✗
Use file-level encryption on the database storage volume
Why it's wrong here
Volume-level encryption protects data only when the storage medium is offline or detached; while the database runs, the volume is mounted and decrypted, leaving plaintext readable. It is tempting because full-disk encryption is the standard control for lost laptops or stolen drives, which is a different threat model from live database access.
- ✗
Implement transparent database encryption (TDE)
Why it's wrong here
TDE requires database engine changes and typically a restart or schema-level configuration, which the three-month no-downtime constraint rules out. It is tempting because TDE is the canonical at-rest encryption control for databases, and it would be correct if the maintenance window were available now.
- ✗
Apply a digital signature to the database files
Why it's wrong here
Signing database files provides integrity and authenticity verification, not confidentiality, so plaintext remains fully readable to anyone with file access. It is tempting because digital signatures do detect tampering, and they would be the right control where the requirement is proving data has not been altered rather than hiding its contents.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.