Courseiva
← Back to CompTIA SecurityX (CAS-005) questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise CompTIA SecurityX (CAS-005) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
CAS-005
exam code
CompTIA
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CAS-005 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit. Which security issue does this cloud storage bucket policy present?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "192.0.2.0/24"
        }
      }
    },
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}
Question 2mediummultiple choice
Full question →

Refer to the exhibit. A security analyst notices that traffic from external clients to the web server at 10.0.0.10 port 80 is being blocked. Which of the following is the MOST likely cause?

Exhibit

access-list 100 deny ip any any
access-list 100 permit tcp any host 10.0.0.10 eq 80
Question 3mediummultiple choice
Read the full VPN explanation →

A security operations center (SOC) analyst receives an alert from the SIEM indicating a user has logged into the corporate VPN from an unusual geographic location at 3 AM, which is outside the user's normal working hours. The user has not previously exhibited this behavior. Which advanced SIEM capability is most likely responsible for generating this alert?

Question 4hardmultiple choice
Full question →

Based on the exhibit, which security issue does this IAM policy represent?

Exhibit

Refer to the exhibit.
{
  "Effect": "Allow",
  "Principal": "*",
  "Action": "s3:GetObject",
  "Resource": "arn:aws:s3:::mybucket/*"
}
Question 5hardmultiple choice
Full question →

Refer to the exhibit. The data classification policy defines levels and rules. During an audit, a database containing both PII and credit card numbers is found labeled as 'Internal'. Which of the following is the BEST first action?

Exhibit

{
  "dataClassification": {
    "levels": ["Public", "Internal", "Confidential", "Critical"],
    "default": "Internal",
    "rules": [
      {"dataType": "PII", "level": "Confidential"},
      {"dataType": "PCI", "level": "Critical"}
    ]
  }
}
Question 6easymultiple choice
Full question →

Based on the exhibit, what type of attack is indicated?

Exhibit

Refer to the exhibit.
Log entry:
2025-02-14 09:23:45 VPN login FAILED from IP 192.0.2.10 user admin
2025-02-14 09:23:46 VPN login FAILED from IP 192.0.2.10 user admin
2025-02-14 09:23:47 VPN login FAILED from IP 192.0.2.10 user admin
2025-02-14 09:23:48 VPN login SUCCESS from IP 192.0.2.10 user admin
Question 7easymultiple choice
Full question →

Refer to the exhibit. A security architect is reviewing this S3 bucket policy. Which of the following security concerns is MOST evident?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::mybucket/*"
    }
  ]
}
Question 8easymultiple choice
Full question →

Based on the auth.log exhibit, what is the MOST appropriate immediate action to mitigate this attack?

Exhibit

Refer to the exhibit.

```
# auth.log excerpt
Mar 15 10:23:45 server sshd[1234]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 15 10:23:46 server sshd[1235]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 15 10:23:47 server sshd[1236]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 15 10:23:48 server sshd[1237]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 15 10:23:49 server sshd[1238]: Failed password for root from 192.168.1.100 port 22 ssh2
Mar 15 10:23:50 server sshd[1239]: Failed password for invalid user admin from 192.168.1.100 port 22 ssh2
Mar 15 10:23:51 server sshd[1240]: Failed password for admin from 192.168.1.100 port 22 ssh2
Mar 15 10:23:52 server sshd[1241]: Failed password for admin from 192.168.1.100 port 22 ssh2
```
Question 9hardmultiple choice
Full question →

An organization uses a SIEM to collect logs from multiple sources. The security team wants to identify users who are accessing resources outside of normal business hours and exhibiting unusual data transfer patterns. Which advanced SIEM capability would be most effective?

Question 10mediummultiple choice
Full question →

Refer to the exhibit. A security analyst notices that users from the internet can reach the web server at 10.0.1.100 on port 443, but they cannot reach it on port 8443. What is the most likely cause?

Exhibit

access-list extended OUTSIDE-IN
 permit tcp any host 10.0.1.100 eq 443
 permit tcp any host 10.0.1.100 eq 8443
 deny ip any any
Question 11hardmultiple choice
Full question →

Refer to the exhibit. A cloud security engineer is reviewing an AWS S3 bucket policy. What security issue does the policy contain?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}
Question 12hardmultiple choice
Full question →

A network administrator is troubleshooting connectivity issues. Based on the exhibit, which of the following is true about the iptables rules?

Exhibit

Refer to the exhibit.

```
# iptables -L FORWARD -v -n
Chain FORWARD (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  eth0   eth1    10.0.1.0/24          0.0.0.0/0            state NEW,ESTABLISHED
    0     0 ACCEPT     all  --  eth1   eth0    0.0.0.0/0            10.0.1.0/24          state ESTABLISHED
```
Question 13mediummultiple choice
Full question →

Based on the exhibit, what vulnerability is present in the firewall rule?

Exhibit

Refer to the exhibit.
Firewall rule:
rule id 10: allow source 203.0.113.0/24 destination 10.0.1.100 service any
Question 14mediummultiple choice
Full question →

Refer to the exhibit. This clause is a requirement of which of the following?

Exhibit

Refer to the exhibit.
```
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
  (a) the pseudonymization and encryption of personal data;
  (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.
```
Question 15mediummultiple choice
Full question →

Refer to the exhibit. A security analyst notices that the pod is running with a service account token mounted. Which security best practice should be implemented to reduce the risk of token theft in container environments?

Exhibit

# kubectl describe pod my-app-pod
Name:         my-app-pod
Namespace:    default
Node:         worker-node-1/192.168.1.10
Start Time:   Tue, 15 Aug 2023 14:30:00 UTC
Labels:       app=my-app
Annotations:  none
Status:       Running
Containers:
  my-app-container:
    Container ID:   docker://abc123
    Image:          myregistry.com/my-app:v1.0
    Image ID:       docker-pullable://myregistry.com/my-app@sha256:xyz
    Port:           8080/TCP
    Host Port:      0/TCP
    State:          Running
    Started:        Tue, 15 Aug 2023 14:30:05 UTC
    Ready:          True
    Restart Count:  0
    Environment:
      DB_PASSWORD:   <set to the key 'db-password' in secret 'db-secret'>  Optional: false
    Mounts:
      /var/run/secrets/kubernetes.io/serviceaccount from default-token-abc (ro)

These CAS-005 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style CAS-005 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.