Courseiva
hardMultiple Choice

CAS-004 Match automation security concepts Practice Question

Which automation security concept coordinates the deployment, scaling, and management of containers?

⚠ Common exam trap

It's easy for candidates to confuse related automation concepts: candidates might select Infrastructure as Code because it also involves automation and deployment, but IaC is about provisioning infrastructure, not coordinating containers. Similarly, immutable infrastructure is a principle, not a coordination tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Container orchestration

Container orchestration is the automation security concept that specifically handles the deployment, scaling, and management of containers. Tools like Kubernetes, Docker Swarm, and Amazon ECS coordinate container lifecycles, including scheduling, health monitoring, and scaling. While other options are related to automation and security, only container orchestration directly addresses the operational coordination of containers at scale.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immutable infrastructure

    Why it's wrong here

    Immutable infrastructure rebuilds servers from images rather than mutating them in place, addressing configuration drift, not container orchestration. It is tempting because containers are often deployed immutably, and it would be correct when the requirement is reproducible, replaceable server builds.

  • ✗

    Infrastructure as Code

    Why it's wrong here

    IaC defines and provisions infrastructure declaratively through templates, but it neither schedules containers nor performs scaling or lifecycle management. It is tempting because it automates deployment, and it would be correct when the requirement is repeatable, version-controlled provisioning of the underlying hosts and networks rather than runtime orchestration.

  • ✗

    Secret management

    Why it's wrong here

    Secret management stores and rotates credentials such as API keys and certificates, which containers may consume, but it does not schedule, scale or place container workloads. It is the right control when the requirement is protecting sensitive values, not coordinating container lifecycle.

  • ✓

    Container orchestration

    Why this is correct

    Container orchestration platforms schedule containers across hosts, scale replicas up or down, and manage lifecycle and networking automatically. This coordination of deployment, scaling and management is precisely the automation security concept the question describes, distinguishing it from image scanning or secrets management.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CAS-005 exam frequently reuses these exact scenarios with slightly different constraints.

✓Container orchestrationCorrect answer▾

Why this is correct

Container orchestration platforms schedule containers across hosts, scale replicas up or down, and manage lifecycle and networking automatically. This coordination of deployment, scaling and management is precisely the automation security concept the question describes, distinguishing it from image scanning or secrets management.

✗Immutable infrastructureWrong answer — click to see why▾

Why this is wrong here

Matched to correct description

✗Infrastructure as CodeWrong answer — click to see why▾

Why this is wrong here

Matched to correct description

✗Secret managementWrong answer — click to see why▾

Why this is wrong here

Matched to correct description

Analysis generated from the official CAS-005blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Match each automation security concept (left) with its corresponding best practice (right).

hard
  • CI/CD pipeline security scanning.Scan container images for vulnerabilities before deployment
  • Immutable infrastructure.Never modify a running instance; redeploy instead
  • Infrastructure as Code.Store all configuration files in version control
  • Secret management.Use a dedicated vault service to store credentials

Why : All four pairs are correct. Immutable infrastructure ensures that instances are never modified after deployment; Infrastructure as Code mandates version control for all configuration files; Secret management relies on a dedicated vault for credentials; CI/CD pipeline security scanning involves scanning container images before deployment.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.