Courseiva

CCNA Casp Engineering Crypto Questions

75 of 147 questions · Page 1/2 · Casp Engineering Crypto topic · Answers revealed

1
MCQmedium

A security administrator is configuring IPsec VPN between two sites. The data transmitted includes sensitive financial records. The administrator wants to ensure both confidentiality and integrity of the data, and also wants to authenticate the source. Which IPsec protocol and mode should be used?

A.ESP in tunnel mode
B.AH in tunnel mode
C.ESP in transport mode
D.AH in transport mode
AnswerA

ESP encrypts the payload and provides integrity plus data-origin authentication, meeting the confidentiality requirement that AH cannot. Tunnel mode encapsulates the whole packet between the site gateways, protecting the sensitive financial records across the untrusted link.

Why this answer

ESP (Encapsulating Security Payload) provides both confidentiality and integrity (optionally authentication). AH only provides integrity and authentication but not confidentiality. Transport mode encrypts only the payload, while tunnel mode encrypts the entire IP packet.

For site-to-site VPN, tunnel mode is typically used.

2
MCQmedium

A company is deploying IoT sensors that require secure firmware updates over the air (OTA). To ensure integrity and authenticity of the firmware, which of the following should be implemented?

A.Code signing with a trusted certificate
B.Secure boot on the device
C.Hash verification only
D.Encryption of the firmware image
AnswerA

Code signing with a trusted certificate lets each IoT sensor verify the firmware's signature against the vendor's public key before installation, confirming both integrity and origin. Unsigned or tampered images are rejected, satisfying the OTA authenticity requirement.

Why this answer

Code signing with a trusted certificate provides both integrity and authenticity: the firmware is hashed and signed by the vendor's private key, and the device verifies the signature using the vendor's public key. This ensures the firmware has not been tampered with and originates from a trusted source. Hash verification alone only checks integrity, not authenticity.

Exam trap

The trap is confusing integrity (hash) with authenticity (signature); candidates often pick hash verification thinking it covers both, but only code signing proves the source.

How to eliminate wrong answers

Option B is wrong because secure boot ensures the device only boots trusted firmware but does not by itself verify OTA update packages during download; it is a boot-time control, not an update-authenticity mechanism. Option C is wrong because a hash verifies integrity but not authenticity—an attacker could replace both the firmware and the hash. Option D is wrong because encryption provides confidentiality, not integrity or authenticity; an encrypted malicious image could still be installed.

3
MCQeasy

A security analyst is reviewing a packet capture and observes that a client and server negotiate a session key using ephemeral Diffie-Hellman, after which all application data is encrypted with a symmetric cipher. The analyst wants to document which security property the ephemeral key exchange provides that a static RSA key transport would not. Which property is that?

A.Perfect confidentiality of the server certificate, because the certificate is encrypted during the handshake.
B.Forward secrecy, because compromise of the long-term private key does not reveal past session keys.
C.Non-repudiation, because the ephemeral key pair proves the server's identity to the client.
D.Data integrity, because Diffie-Hellman produces a message authentication code over each record.
AnswerB

Ephemeral Diffie-Hellman generates a fresh key pair per session and discards it afterward, so the session key is never derivable from the server's long-term private key. Even if that long-term key is later compromised, previously recorded sessions remain protected. Static RSA key transport encrypts the premaster secret with the long-term key, so its compromise retroactively exposes past sessions, which is exactly the property ephemeral DH adds.

Why this answer

Ephemeral Diffie-Hellman creates a unique shared secret per session and erases the private ephemeral values, so a later compromise of the server's long-term key cannot decrypt previously captured traffic. Static RSA key transport ties the premaster secret to the long-term key, so that compromise exposes all recorded sessions. The distinguishing property is forward secrecy.

Exam trap

The trap here is confusing the authentication and integrity services of TLS with the key-agreement property, when the real benefit of ephemeral key exchange is protection of past sessions.

4
MCQhard

A security engineer is configuring a hardware security module (HSM) to protect a root certificate authority's private key. The requirement is that the key must never exist in plaintext outside the HSM and must be usable by multiple authorized administrators under dual control. Which configuration BEST satisfies these requirements?

A.Generate the CA key on a hardened offline workstation, wrap it with a passphrase-derived AES key, and import the wrapped blob into the HSM.
B.Generate the CA key inside the HSM as an extractable key so that a secure backup can be made, and rely on HSM role-based access control for administrator separation.
C.Generate the CA key inside the HSM and store a passphrase-protected copy in an encrypted configuration management database for disaster recovery.
D.Generate the CA key inside the HSM as a non-extractable key and configure M of N quorum authentication for administrative operations.
AnswerD

Generating the key inside the HSM with the non-extractable attribute ensures the private key material never leaves the cryptographic boundary in plaintext. M of N quorum authentication enforces dual control by requiring multiple smartcards or credentials to authorize sensitive operations, directly meeting both requirements.

Why this answer

The strongest protection is to have the HSM itself generate the key as non-extractable, so the private material is created and used only within the tamper-resistant boundary. Layering M of N quorum authentication ensures that no single administrator can perform sensitive CA operations, providing the dual control the scenario requires.

Exam trap

The trap here is treating encryption or passphrase wrapping of an externally generated key as equivalent to never exposing plaintext, when the key was already in plaintext during generation.

5
MCQmedium

A security engineer is configuring a secure boot process for a Linux server using UEFI. The engineer wants to ensure that only signed bootloaders and kernels are executed. Which of the following components is responsible for verifying the signature of the bootloader?

A.The UEFI signature database (db)
B.The bootloader's own signature check
C.The Key Exchange Key (KEK)
D.The UEFI firmware's Platform Key (PK)
AnswerA

The UEFI signature database (db) contains certificates and hashes of trusted bootloaders and drivers. During boot, the UEFI firmware verifies the signature of the bootloader against the entries in the db. If the bootloader's signature matches a trusted certificate in the db, it is allowed to execute. This is the component directly responsible for verification.

Why this answer

In UEFI Secure Boot, the firmware uses the signature database (db) to validate the bootloader's signature. The db contains trusted certificates and hashes. When the bootloader is loaded, the firmware checks its signature against the db.

If it matches, the bootloader runs; otherwise, boot is halted or an error is shown. This ensures only trusted code executes.

Exam trap

The trap here is thinking the PK or KEK directly verifies the bootloader, but they only establish the trust chain for the db.

6
MCQmedium

A security engineer is designing a system that must protect data at rest on a database server. The organization requires that the encryption keys never leave a hardware module and that the module be resistant to physical tampering. The engineer deploys a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. Which of the following BEST describes the security property provided by this validation level?

A.It provides zeroization of keys when the module is powered down, but does not require any authentication for administrative access.
B.It provides tamper-evident physical mechanisms and identity-based authentication to access cryptographic keys.
C.It provides the highest level of physical security with environmental failure protection and formal method verification.
D.It provides a software-only cryptographic module that can be deployed on any commodity server without hardware dependencies.
AnswerB

FIPS 140-2 Level 3 requires tamper-evident mechanisms such as epoxy encapsulation or tamper-detection circuitry that zeroizes keys upon intrusion, and it mandates identity-based authentication for all operators accessing the module. This directly meets the requirement that keys never leave the hardware and the module resists physical tampering. Level 3 is the correct validation level for this scenario because it adds physical security and identity-based authentication beyond Level 2's role-based authentication.

Why this answer

FIPS 140-2 Level 3 validation requires tamper-evident physical mechanisms and identity-based authentication, ensuring that keys remain within a hardened hardware boundary and that only authenticated operators can access them. This matches the stated requirements of keys never leaving the module and resistance to physical tampering. Levels 1 and 2 lack these physical protections, while Level 4 adds environmental protections beyond what is needed here.

Exam trap

The trap here is assuming that any HSM automatically provides tamper resistance, when the actual validation level determines the specific physical and authentication protections.

7
MCQmedium

A security engineer is configuring a web application firewall (WAF) to protect against injection attacks. The application uses a relational database and reflects user input in HTML pages. The engineer must choose a WAF rule set that provides the BEST protection with minimal false positives. Which approach should the engineer take?

A.Deploy the WAF in learning mode to baseline normal traffic, then enable targeted rules for SQL injection and XSS with virtual patching for known vulnerabilities.
B.Create custom regular expression rules that block any request containing single quotes, double quotes, or angle brackets.
C.Enable the WAF's generic SQL injection and cross-site scripting (XSS) rules in blocking mode with a default action of deny.
D.Rely solely on the database's parameterized queries and disable all WAF injection rules to avoid false positives.
AnswerA

Learning mode establishes a baseline of legitimate traffic, allowing the engineer to tune rules and reduce false positives. Targeted rules for SQL injection and XSS address the specific threats, and virtual patching protects against known vulnerabilities until code fixes are deployed. This approach balances protection with operational stability.

Why this answer

The best approach is to use learning mode to understand normal traffic, then enable targeted SQL injection and XSS rules along with virtual patching for known vulnerabilities. This minimizes false positives while providing strong protection. Generic blocking rules, overly broad regex, or disabling WAF rules entirely either cause operational issues or reduce defense-in-depth.

Exam trap

The trap here is assuming that the most aggressive blocking configuration always provides the best protection, when in practice tuning and targeted rules are needed to avoid false positives.

8
Multi-Selectmedium

A security engineer is hardening a Linux bastion host that provides administrative access to production servers. The organization requires that all administrative sessions be cryptographically bound to a hardware-backed credential and that session recordings be tamper-evident. Which TWO controls BEST satisfy these requirements? (Choose two.)

Select 2 answers
A.Enable PasswordAuthentication and enforce a 20-character complexity policy with quarterly rotation.
B.Configure sshd to permit only keyboard-interactive authentication with one-time passwords delivered by SMS.
C.Deploy a session recording solution that writes audit logs to a remote syslog server protected by TLS and stores a hash chain of each session.
D.Configure sshd with PubkeyAuthentication and require FIDO2-backed SSH keys using sk-ssh-ed25519 public keys.
E.Store session recordings locally on the bastion host in a directory writable only by root, and rely on file permissions for integrity.
AnswersC, D

Recording administrative sessions and protecting the log stream with TLS plus a hash chain makes the recordings tamper-evident: any modification breaks the chain and is detectable. Remote storage prevents a local attacker from altering or deleting recordings on the bastion host. This directly satisfies the tamper-evident session recording requirement while complementing hardware-backed authentication.

Why this answer

Hardware-backed authentication and tamper-evident recording are distinct requirements that need complementary controls. FIDO2-backed sk-ssh-ed25519 keys bind administrative sessions to a physical authenticator, while remote TLS-protected logging with a hash chain ensures session recordings cannot be altered undetectably. Together they satisfy both the credential-binding and recording-integrity objectives without relying on weaker password or SMS mechanisms.

Exam trap

The trap here is treating strong password policy or SMS one-time passwords as equivalent to hardware-backed authentication, and treating root-only file permissions as equivalent to cryptographic tamper evidence.

9
MCQeasy

An organization wants to implement passwordless authentication using FIDO2/WebAuthn. Which of the following best describes the primary security advantage of this approach over traditional password-based authentication?

A.It eliminates the need for multi-factor authentication
B.It prevents phishing by using cryptographic keys bound to the origin
C.It allows users to reuse the same password across services
D.It requires a hardware token for every login
AnswerB

FIDO2/WebAuthn credentials are bound to the relying party's origin, and the authenticator signs a challenge with a private key that never leaves the device. A phishing site on a different origin cannot obtain a valid assertion, eliminating credential replay regardless of password reuse.

Why this answer

FIDO2/WebAuthn uses public-key cryptography where the private key never leaves the authenticator, and the credential is cryptographically bound to the origin (relying party ID) during registration. This origin binding means a phishing site on a different domain cannot trigger the authenticator to produce a valid assertion, because the browser enforces the RP ID match. Even if a user is tricked into visiting a lookalike site, the signature will not validate against the legitimate server's expected origin.

Exam trap

The trap here is conflating 'passwordless' with 'no second factor' — candidates assume removing the password means removing MFA, when FIDO2 actually strengthens authentication by binding cryptographic credentials to the origin, which is the specific anti-phishing property the exam wants you to identify.

How to eliminate wrong answers

Option A is wrong because FIDO2/WebAuthn is itself a form of possession-based authentication and is often combined with a PIN or biometric (which acts as a second factor), so it does not eliminate MFA — it can actually implement it. Option C is wrong because FIDO2 does not involve passwords at all; there is no password to reuse, and reusing credentials across services is precisely the anti-pattern FIDO2 eliminates. Option D is wrong because FIDO2 supports platform authenticators (Windows Hello, Touch ID, Android biometrics) as well as roaming hardware keys, so a dedicated hardware token is not required for every login.

10
MCQeasy

A security administrator must ensure that log data collected from servers across multiple sites cannot be altered or deleted by an attacker who compromises a single server. Which of the following BEST achieves this?

A.Configure each server to write logs to a local encrypted volume and enable file integrity monitoring on the log directory
B.Increase local log retention to one year and rotate log files daily with compression enabled
C.Enable verbose logging on all servers and store the logs in a database that uses transparent data encryption
D.Forward logs in real time to a centralized logging platform with append-only storage and restricted administrative access
AnswerD

Shipping logs off-host in real time means a compromised server no longer holds the only copy, and append-only storage with tightly restricted administration prevents alteration or deletion. This directly satisfies the requirement that a single compromised server cannot tamper with the collected log data.

Why this answer

Centralizing logs with real-time forwarding removes the single point of failure and append-only storage with restricted access prevents tampering or deletion even if one server is fully compromised. Local encryption, retention changes, and database encryption all leave authoritative copies within reach of the compromised host.

Exam trap

The trap here is assuming that encrypting or retaining logs locally provides tamper resistance, when the attacker on that host controls both the logs and the keys.

11
MCQmedium

A security engineer is configuring a wireless network for a corporate office. The network must support 802.1X authentication with EAP-TLS, and the engineer wants to ensure that only devices with valid certificates issued by the corporate CA can connect. Which of the following should the engineer configure on the RADIUS server to enforce this requirement?

A.Configure EAP-TLS and validate client certificates against the corporate CA.
B.Enable PEAP with MSCHAPv2 and require domain credentials.
C.Deploy EAP-FAST with PACs and require machine authentication.
D.Implement EAP-TTLS with a tunneled authentication protocol and check user group membership.
AnswerA

EAP-TLS requires both the server and client to present certificates. By configuring the RADIUS server to trust only the corporate CA and to require client certificates, the engineer ensures that only devices with valid certificates issued by that CA can authenticate. This meets the requirement exactly and is considered the most secure EAP method.

Why this answer

EAP-TLS is the only method that mandates client-side certificates, allowing the RADIUS server to validate them against the corporate CA. This ensures that only devices with certificates from that CA can connect. The other methods either rely on user credentials, tunneled legacy authentication, or PACs, none of which enforce device certificate validation.

Exam trap

The trap here is assuming that any 802.1X method with strong encryption, like PEAP or EAP-TTLS, can enforce device certificate authentication, when only EAP-TLS requires client certificates.

12
MCQhard

A security engineer is configuring IPsec VPN between two sites. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode and protocol should be used?

A.Transport mode with AH
B.Tunnel mode with AH
C.Transport mode with ESP
D.Tunnel mode with ESP
AnswerD

Tunnel mode encapsulates the entire original IP packet, including its header, inside a new IP packet, whereas transport mode protects only the payload. ESP supplies the encryption, so tunnel mode with ESP encrypts the whole packet as the stem requires.

Why this answer

Tunnel mode with ESP encrypts the entire original IP packet and adds a new IP header, which is required for gateway-to-gateway VPNs. ESP provides encryption and optional authentication.

13
Multi-Selecthard

A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect needs to ensure that inter-service communication is secure, that services can authenticate each other, and that access to services is controlled based on identity. Which TWO of the following should be implemented? (Choose two.)

Select 2 answers
A.A shared secret used by all services for authentication
B.API keys stored in environment variables for each service
C.Network policies that allow all traffic within the cluster namespace
D.Mutual TLS (mTLS) between services using short-lived certificates
E.A service mesh with identity-based authorization policies
AnswersD, E

Mutual TLS with short-lived certificates provides strong authentication and encryption for inter-service communication. Short-lived certificates reduce the risk of key compromise and enable automatic rotation. This ensures that only authenticated services can communicate, and all traffic is encrypted, meeting the requirements for secure service-to-service communication.

Why this answer

Mutual TLS with short-lived certificates ensures encrypted and authenticated communication between services, while a service mesh with identity-based authorization policies provides centralized, fine-grained access control based on service identity. Together, they secure inter-service communication and enforce access control. The other options either lack encryption, use static secrets, or are overly permissive.

Exam trap

The trap here is thinking that network segmentation or static secrets alone can provide authentication and authorization for microservices, when identity-based controls are required.

14
Multi-Selectmedium

A security architect is designing a secure boot chain for an IoT device. Which THREE components are essential to ensure the integrity of the firmware update process? (Select THREE.)

Select 3 answers
A.Firmware update files signed with a private key
B.A mechanism to prevent firmware rollback to older versions
C.Encryption of firmware at rest on the device
D.Secure over-the-air (OTA) update delivery mechanism (e.g., TLS)
E.A hardware root of trust (e.g., read-only memory) storing the public key
AnswersA, D, E

Signed firmware images let the device verify authenticity and integrity before flashing, using the vendor’s public key to validate the private-key signature. This directly satisfies the stem’s requirement for a trustworthy update process, preventing tampered or malicious firmware from being installed on the IoT device.

Why this answer

Option A is correct because signing firmware update files with a private key lets the device verify authenticity and integrity using the corresponding public key, ensuring only authorized firmware is installed. Option D is correct because a secure OTA delivery mechanism such as TLS protects the update in transit against interception, tampering, and man-in-the-middle modification before it reaches the device. Option E is correct because a hardware root of trust, such as read-only memory storing the public key, provides an immutable anchor that validates the signature and boot chain, preventing attackers from substituting keys or firmware.

Option B is not essential to integrity itself; rollback prevention is an anti-downgrade control that addresses version freshness rather than cryptographic integrity. Option C is also not essential, since encryption of firmware at rest protects confidentiality, not the integrity of the update process.

Exam trap

CAS-005 often tests the difference between integrity and confidentiality controls — candidates select encryption at rest thinking it ensures firmware authenticity, when signing and root of trust are what actually provide integrity.

15
MCQhard

A security architect is designing a cross-domain solution that must move data between a classified network and an unclassified network. The requirement is to enforce a formally verified, non-bypassable policy that prevents any high-to-low leakage, while still permitting a controlled release of approved structured data. Which design element is MOST appropriate to satisfy this requirement?

A.A content-filtering proxy that performs deep packet inspection and blocks known malicious signatures
B.A stateful packet-filtering firewall with an explicit deny-all rule between the two enclaves
C.A data diode that permits only unidirectional physical-layer transmission from the unclassified to the classified network
D.A high-assurance cross-domain guard with a formally verified security kernel that filters and downgrades approved structured records
AnswerD

A high-assurance guard combines a formally verified security kernel with content filtering and a controlled release process, which is exactly what is needed to enforce a non-bypassable information-flow policy while permitting approved structured data to cross. The formal verification provides the assurance evidence that the policy cannot be bypassed, and the filtering performs the necessary sanitization.

Why this answer

Only a high-assurance cross-domain guard with a formally verified security kernel can enforce a non-bypassable information-flow policy and simultaneously release approved structured records. Firewalls and content-filtering proxies lack formal verification and structured-data transformation, and a data diode addresses flow direction rather than content policy. The guard is purpose-built for this multi-level release requirement.

Exam trap

The trap here is treating a data diode as a complete cross-domain solution, when it only enforces directionality and performs no content inspection or structured-record release.

16
MCQeasy

A network administrator needs to establish a secure VPN tunnel between two branch offices using IPsec. The requirement is to encrypt the entire IP packet, including the original IP header. Which IPsec mode should be used?

A.AH mode
B.IKEv1
C.Tunnel mode
D.Transport mode
AnswerC

Tunnel mode encapsulates the complete original IP packet inside a new IP packet, encrypting payload and original header together. Transport mode encrypts only the payload and leaves the original header intact, so tunnel mode is required to meet the stated requirement of encrypting the entire packet.

Why this answer

Tunnel mode encrypts the entire IP packet and adds a new IP header, making it suitable for VPNs between networks.

17
Multi-Selectmedium

A security operations center (SOC) is implementing a new SIEM and wants to improve detection of credential-based attacks. The team plans to ingest Windows Security event logs and create correlation rules. Which TWO event IDs should the SOC prioritize to detect a brute-force attack against local accounts? (Choose two.)

Select 2 answers
A.4624 (An account was successfully logged on)
B.4672 (Special privileges assigned to new logon)
C.4625 (An account failed to log on)
D.4740 (A user account was locked out)
E.1102 (The audit log was cleared)
AnswersC, D

Event ID 4625 is generated whenever a logon attempt fails, such as due to a bad password or unknown username. A high volume of 4625 events from a single source or against a single account within a short time frame is a classic indicator of a brute-force or password-spraying attack. Monitoring and alerting on this event is essential for early detection of credential attacks against local accounts.

Why this answer

Brute-force attacks against local accounts are characterized by repeated failed logon attempts, which generate Event ID 4625. When the number of failures exceeds the account lockout threshold, Event ID 4740 is logged. Correlating these two events allows the SOC to detect both the ongoing attack and its impact.

Other events like successful logons or privilege assignments are not direct indicators of the attack itself, and log clearing is a post-compromise action.

Exam trap

The trap here is focusing on successful logon events or privilege events, which may indicate a compromise after the fact, rather than the failed logon and lockout events that directly reveal the brute-force attempt.

18
MCQmedium

An organization is implementing IPsec VPNs between sites. The security team wants to ensure data integrity and authentication but is less concerned about confidentiality for this particular link. Which IPsec protocol and mode should they use?

A.ESP in tunnel mode
B.AH in tunnel mode
C.AH in transport mode
D.ESP in transport mode
AnswerB

AH provides data integrity and origin authentication through its ICV, but performs no encryption, matching the stated indifference to confidentiality. Tunnel mode encapsulates the entire original IP packet, protecting traffic between the two site gateways rather than just host-to-host flows.

Why this answer

IPsec AH (Authentication Header) provides data integrity and authentication but not confidentiality (no encryption). Tunnel mode encapsulates the entire IP packet, which is suitable for site-to-site VPNs. Since confidentiality is not a concern, AH in tunnel mode is the correct choice.

ESP would provide confidentiality, which is unnecessary here.

Exam trap

CAS-005 often tests the difference between AH and ESP; candidates may choose ESP for integrity, but ESP without encryption is not standard, and AH is specifically for integrity without confidentiality.

How to eliminate wrong answers

Option A is wrong because ESP in tunnel mode provides confidentiality via encryption, which is not needed and adds overhead. Option C is wrong because AH in transport mode only protects the payload, not the entire packet, and is typically used for host-to-host communications, not site-to-site VPNs. Option D is wrong because ESP in transport mode provides confidentiality and is not suitable for site-to-site VPNs that require integrity without encryption.

19
MCQmedium

A security engineer is configuring a Linux server to enforce encrypted remote administration. The requirement is that after the initial key exchange, session keys must be rotated periodically to limit the impact of a compromised session key. Which OpenSSH configuration directive should the engineer use to achieve this?

A.Set Ciphers to aes256-ctr in the sshd_config file.
B.Set MACs to hmac-sha2-512 in the sshd_config file.
C.Set RekeyLimit to 1G 1h in the sshd_config file.
D.Set KexAlgorithms to diffie-hellman-group-exchange-sha256 in the sshd_config file.
AnswerC

RekeyLimit specifies the maximum amount of data and/or time before the session key is renegotiated. Setting it to 1G 1h forces a new key exchange after 1 gigabyte of data or one hour, whichever comes first, thereby rotating session keys and limiting exposure if a key is compromised. This directly satisfies the requirement.

Why this answer

The RekeyLimit directive in OpenSSH allows administrators to enforce periodic rekeying based on data volume, time, or both. By setting it to 1G 1h, the session key is refreshed after 1 gigabyte of data or one hour, whichever occurs first. This limits the amount of data encrypted under a single key, reducing the impact of a key compromise.

Other directives control cipher selection, key exchange algorithms, or integrity algorithms but do not manage key rotation.

Exam trap

The trap here is confusing cipher selection with key rotation, assuming that choosing a strong cipher automatically provides forward secrecy or periodic rekeying.

20
MCQeasy

A security administrator is reviewing the configuration of a wireless network. The network uses WPA3-Enterprise with 802.1X authentication. The administrator wants to ensure that the authentication server validates the identity of the supplicant before granting network access. Which protocol should be used to encapsulate the authentication credentials?

A.EAP-MD5
B.EAP-TTLS
C.EAP-TLS
D.PEAP
AnswerC

EAP-TLS uses mutual certificate-based authentication, where both the supplicant and the authentication server present certificates. This ensures the server validates the supplicant's identity and vice versa, meeting the requirement. It is widely supported in WPA3-Enterprise and provides strong security without passwords, making it ideal for environments requiring robust mutual authentication.

Why this answer

EAP-TLS requires certificates on both the supplicant and the authentication server, enabling mutual authentication. This ensures the server validates the supplicant's identity before granting access. PEAP and EAP-TTLS typically authenticate only the server with a certificate, while EAP-MD5 lacks mutual authentication entirely.

Thus, EAP-TLS is the correct choice for strong mutual identity validation.

Exam trap

The trap here is confusing tunneled EAP methods like PEAP with true mutual certificate-based authentication.

21
MCQhard

A security architect is evaluating a hardware security module (HSM) deployment for a certificate authority. The requirement is that private keys must never leave the HSM in plaintext, and that key operations must be auditable. During a review, the architect learns that the HSM supports key wrapping for backup. Which of the following is the MOST important control to verify?

A.That the private keys are backed up to an encrypted network share using the HSM's built-in FTP client for offsite storage.
B.That the key wrapping key is stored in a separate, tamper-resistant HSM under a different administrator's control, and that wrapping operations are logged.
C.That the key wrapping key is stored in the same HSM and is itself exportable for disaster recovery.
D.That the HSM uses AES-128 in ECB mode for key wrapping to maximize performance during backup operations.
AnswerB

Separating the wrapping key into a distinct HSM under dual control enforces separation of duties and prevents a single compromised HSM from exposing backed-up keys. Logging wrapping operations provides the required auditability. This design ensures that even if the primary HSM is compromised, the attacker cannot unwrap exported blobs without also compromising the second HSM.

Why this answer

The strongest control is to separate the key wrapping key into an independent, tamper-resistant HSM under different administrative control and to log all wrapping operations. This enforces separation of duties and ensures that compromise of one HSM does not expose all backed-up private keys. Exportable wrapping keys, weak ciphers like ECB, or insecure transport channels all undermine the security of the backup process.

Exam trap

The trap here is focusing on encryption of the backup channel while overlooking that the wrapping key itself must be protected and separated from the keys it wraps.

22
MCQmedium

A security engineer must ensure that log data collected from production servers cannot be altered or deleted by an attacker who gains administrative access to those servers. The logs must remain verifiable for audit purposes. Which of the following designs BEST achieves this?

A.Configure log rotation with a short retention window and compress older files to save space.
B.Encrypt log files at rest on each server using a key stored in the server's local keystore.
C.Forward logs in real time to a centralized server that uses append-only storage and cryptographic hash chaining.
D.Store logs locally on each server with strict file permissions and enable file integrity monitoring.
AnswerC

Real-time forwarding removes logs from the source host before an attacker can tamper with them, and append-only storage with hash chaining makes any later modification detectable because each entry's hash depends on the previous one. An attacker with server administrative rights cannot rewrite records already transmitted to the hardened collector. This directly provides tamper evidence and verifiability.

Why this answer

Sending logs off-host in real time and storing them on a separate system with append-only writes and hash chaining ensures that a compromised server cannot retroactively change the audit record. The chained hashes let auditors detect any insertion, deletion, or modification, so the logs remain trustworthy even if the source host is fully compromised.

Exam trap

The trap here is relying on local file permissions or encryption on the source host, when an attacker with administrative rights on that host controls the keys and the files.

23
MCQhard

A security engineer is configuring a wireless network for a hospital. The network must support legacy medical devices that only support WPA2-Personal with pre-shared keys (PSK) and cannot be upgraded. The hospital also wants to prevent unauthorized devices from connecting and to detect rogue access points. Which of the following should the engineer implement to BEST meet these requirements?

A.WPA2-Enterprise with 802.1X authentication and a RADIUS server.
B.Open network with a captive portal and MAC address filtering.
C.WPA3-Enterprise with 192-bit mode and a RADIUS server.
D.WPA2-Personal with a strong, unique PSK and a wireless intrusion prevention system (WIPS).
AnswerD

WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.

Why this answer

WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.

Exam trap

The trap here is assuming that the most secure option (WPA3-Enterprise) is always best, but compatibility with legacy devices is a hard constraint that must be respected.

24
MCQeasy

A security administrator is configuring a firewall to allow only encrypted remote administration traffic to a server. The administrator wants to use a protocol that provides confidentiality and integrity for the management session. Which of the following should be used?

A.HTTP over port 8080
B.SSH
D.SNMPv3 without privacy
AnswerB

SSH provides strong encryption, integrity, and authentication for remote administration. It protects the session against eavesdropping and tampering. It is the standard protocol for secure command-line management. Using SSH meets the requirement for confidentiality and integrity of the management session.

Why this answer

SSH is designed for secure remote administration, providing encryption and integrity. Telnet and HTTP are plaintext, and SNMPv3 without privacy lacks encryption. Only SSH meets the requirement for encrypted management traffic.

Exam trap

The trap here is thinking that changing the port number (e.g., HTTP on 8080) provides security; it does not add encryption.

25
MCQmedium

A cloud security engineer is designing an architecture where workloads in a virtual private cloud must reach an on-premises database over a site-to-site VPN. The requirement is that only the database subnet can be reached, no other on-premises networks, and traffic must be encrypted in transit. Which design BEST satisfies this?

A.Deploy a transit gateway and attach every on-premises VPC to it with full route propagation
B.Use VPC peering between the workload VPC and the on-premises database VPC
C.Create an internet gateway and allow the workload subnet to reach the database's public IP over TLS
D.Configure a customer gateway and virtual private gateway with a static route limited to the database subnet CIDR
AnswerD

A site-to-site VPN with a customer gateway on-premises and a virtual private gateway in the cloud encrypts traffic via IPsec, and advertising only the database subnet CIDR in the static route confines reachable destinations to that network. This meets both the encryption requirement and the least-privilege routing constraint without exposing other on-premises ranges.

Why this answer

A site-to-site IPsec VPN between a customer gateway and a virtual private gateway encrypts traffic, and constraining the static route to the database subnet CIDR enforces least-privilege reachability. Transit gateway full propagation, VPC peering, and public-IP exposure either broaden access or fail to provide an encrypted private path to the on-premises database.

Exam trap

The trap here is treating any encrypted connection, such as TLS to a public endpoint, as equivalent to a scoped private VPN path.

26
Multi-Selectmedium

A security administrator is implementing TPM 2.0 for secure boot and measured boot on new laptops. Which TWO capabilities does TPM 2.0 provide that are directly related to ensuring the integrity of the boot process? (Select TWO.)

Select 2 answers
A.Remote attestation to verify boot measurements
B.Platform Configuration Registers (PCRs) for storing measurements
C.UEFI secure boot enforcement
D.Sealed storage to protect encryption keys
E.Generation of RSA keys for code signing
AnswersA, B

Remote attestation lets the TPM sign a quote over selected PCR values, allowing a remote verifier to confirm the boot chain matched expected measurements. This satisfies the integrity-verification requirement by detecting tampering with firmware or boot components before trust is granted.

Why this answer

Option A (Remote attestation to verify boot measurements) is correct because TPM 2.0 can produce a signed quote of PCR values that a remote verifier uses to attest that the boot chain matches expected measurements, directly ensuring boot-process integrity. Option B (Platform Configuration Registers (PCRs) for storing measurements) is correct because TPM 2.0 PCRs hold the cumulative hashes of boot components (firmware, bootloader, OS) that form the basis of measured boot and are the values attested in option A. Option C is not a TPM capability; UEFI Secure Boot enforcement is performed by UEFI firmware using signature databases (db, dbx, KEK, PK), though the TPM may record its state.

Option D, sealed storage, protects encryption keys by binding them to PCR values, but it is a data-protection feature rather than a direct boot-integrity capability. Option E, RSA key generation for code signing, is a general cryptographic function and not specifically tied to ensuring boot-process integrity.

27
MCQhard

A security architect is designing a network segmentation strategy for a critical industrial control system (ICS) environment. The architect must ensure that unauthorized devices cannot communicate with the ICS network even if they gain physical access to a network port. The architect decides to implement IEEE 802.1X with MAC Authentication Bypass (MAB) as a fallback. Which of the following is the MOST significant security weakness introduced by enabling MAB?

A.MAB transmits credentials in clear text, allowing an attacker to capture them and authenticate to the network.
B.MAB disables the use of RADIUS, forcing authentication to occur locally on the switch and reducing centralized control.
C.MAB allows any device to authenticate by spoofing a known MAC address, bypassing 802.1X authentication controls.
D.MAB requires the use of digital certificates on all endpoints, increasing administrative overhead and complexity.
AnswerC

MAB authenticates devices based on their MAC address, which is easily spoofable. An attacker with physical port access can configure a device with a permitted MAC address and gain network access without valid 802.1X credentials. This directly undermines the requirement that unauthorized devices cannot communicate, making MAB a significant weakness in this scenario.

Why this answer

MAB authenticates devices by their MAC address, which is not a secret and can be easily spoofed. In an ICS environment where physical port access might be possible, an attacker could clone a permitted MAC address and bypass 802.1X controls. This defeats the goal of preventing unauthorized devices from communicating.

Certificate-based methods or strict port security would be more robust, but MAB as a fallback introduces this spoofing vulnerability.

Exam trap

The trap here is focusing on encryption of credentials, when MAB's real weakness is that the MAC address itself is a trustable but easily forged identifier.

28
Multi-Selecteasy

A company is implementing MFA for remote access. Which TWO factors are considered possession factors?

Select 2 answers
A.A fingerprint scan
B.A hardware OTP token
C.A PIN
D.A push notification to a registered smartphone
E.A password
AnswersB, D

A hardware OTP token is a possession factor because authentication requires something the user physically holds, satisfying the MFA requirement for a possession-based credential. The device generates time-synchronised one-time codes, so access depends on possessing the hardware itself rather than knowledge or biometrics.

Why this answer

Option B (a hardware OTP token) is a possession factor because authentication depends on something the user physically has — the token device that generates or stores the one-time passcode. Option D (a push notification to a registered smartphone) is also a possession factor because the approval prompt is delivered to a specific device the user possesses, and possession of that enrolled phone is what enables the authentication. Option A (a fingerprint scan) is an inherence factor, since it relies on a biometric characteristic of the user.

Option C (a PIN) and Option E (a password) are both knowledge factors, because they rely on something the user knows rather than something the user has.

29
MCQmedium

A financial services company is deploying a new internal web application that must meet PCI DSS requirements for encrypting cardholder data in transit. The security engineer must configure TLS to ensure that only ephemeral key exchanges are used and that compromised long-term keys cannot decrypt past sessions. Which of the following should the engineer implement?

A.Deploy TLS 1.2 with AES-256-GCM and ensure the server certificate uses SHA-1 for signing.
B.Enable TLS 1.3 with cipher suites that use ephemeral Diffie-Hellman (DHE or ECDHE) key exchange.
C.Implement TLS 1.2 with static Diffie-Hellman parameters and a 4096-bit RSA certificate.
D.Configure the server to use TLS 1.2 with RSA key exchange and 2048-bit RSA certificates.
AnswerB

TLS 1.3 mandates forward secrecy by design, using ephemeral Diffie-Hellman key exchange for all cipher suites. Each session generates a unique ephemeral key pair that is discarded after the handshake, so compromise of the server's long-term private key cannot decrypt recorded past sessions. This directly satisfies the requirement and aligns with PCI DSS guidance for strong cryptography.

Why this answer

TLS 1.3 enforces forward secrecy by requiring ephemeral key exchange, so even if the server's long-term private key is compromised, past session keys remain secure. The other options either use static key exchanges that lack forward secrecy or include deprecated algorithms like SHA-1. For PCI DSS compliance, ephemeral Diffie-Hellman with TLS 1.3 is the most robust choice.

Exam trap

The trap here is assuming that simply using TLS 1.2 with a large RSA key or AES-256 provides forward secrecy, when the critical factor is the key exchange method, not the symmetric cipher or certificate size.

30
MCQeasy

A security engineer is deploying a new wireless network for a corporate campus and must ensure that all client traffic is protected with strong encryption and that the network does not rely on a pre-shared key. Which configuration should the engineer implement?

A.WPA2-Personal with a rotated pre-shared key every 30 days
B.WEP with 128-bit keys and MAC address filtering
C.WPA3-Enterprise with 802.1X authentication against a RADIUS server
D.Open authentication with a captive portal for guest access
AnswerC

WPA3-Enterprise uses 802.1X with EAP to authenticate each user or device against a RADIUS server, eliminating the shared-secret weakness of pre-shared keys. It also mandates stronger cryptographic protections, including protected management frames and, in WPA3-Enterprise 192-bit mode, GCMP-256 and SHA-384. This directly satisfies the requirement for strong encryption without a pre-shared key.

Why this answer

WPA3-Enterprise with 802.1X and RADIUS authentication meets both requirements: it provides strong, current cryptographic protections and authenticates each client individually, so no pre-shared key is used. WPA2-Personal retains a shared key, open authentication provides no encryption, and WEP is broken. The enterprise mode with 802.1X is the standard choice for corporate wireless deployments.

Exam trap

The trap here is assuming that rotating a pre-shared key converts WPA2-Personal into an enterprise-grade solution, when the fundamental shared-secret exposure remains.

31
MCQmedium

A company is implementing a Privileged Access Management (PAM) solution to manage admin credentials. Which feature allows administrators to request temporary elevated access for a specific task?

A.Session recording
B.Just-in-time access
C.Password vaulting
D.Break-glass accounts
AnswerB

Just-in-time access grants elevated privileges only when requested and approved for a defined window, then automatically revokes them. This matches the stem's requirement for temporary elevated access for a specific task, rather than standing permanent admin rights.

Why this answer

Just-in-time (JIT) access is a core PAM capability that grants elevated privileges only when needed, for a limited time, and often with approval workflows. It directly addresses the requirement for temporary elevated access for a specific task, reducing standing privileges and the attack surface. JIT typically integrates with identity governance to enforce least privilege and just-enough administration.

Exam trap

The trap here is confusing session recording (auditing) with access granting, or assuming break-glass accounts are for temporary elevation; CAS-005 often tests the distinction between monitoring, credential storage, emergency access, and just-in-time elevation.

How to eliminate wrong answers

Option A is wrong because session recording is a monitoring and auditing feature that captures privileged sessions for compliance and forensics, but it does not grant or manage temporary elevated access. Option C is wrong because password vaulting securely stores and manages privileged credentials, but it does not provide time-bound, request-based elevation; it is about credential checkout and rotation. Option D is wrong because break-glass accounts are emergency access accounts designed for use when normal access mechanisms fail, not for routine temporary elevation for specific tasks; they are typically highly privileged and heavily audited, but not intended for just-in-time requests.

32
MCQhard

A security architect is designing a network segmentation scheme for a containerized workload running on a Kubernetes cluster. The requirement is to enforce least-privilege communication between microservices at Layer 3 and Layer 4, and to ensure that only explicitly allowed traffic can flow between pods, even within the same namespace. Which of the following should the architect implement?

A.Pod Security Admission with the restricted profile applied to all namespaces.
B.A web application firewall (WAF) placed in front of the ingress controller.
C.Istio service mesh with mutual TLS (mTLS) enabled between all sidecars.
D.Kubernetes Network Policies with a default-deny ingress and egress policy.
AnswerD

Kubernetes Network Policies are the native mechanism to control pod-to-pod traffic at Layer 3 and Layer 4. By applying a default-deny policy for both ingress and egress in a namespace, all traffic is blocked unless explicitly allowed by a subsequent policy. This enforces least privilege and prevents lateral movement between microservices. It works with a CNI plugin that supports network policies, such as Calico or Cilium, and is the standard way to achieve microsegmentation in Kubernetes.

Why this answer

To enforce least-privilege communication between microservices at Layer 3 and Layer 4, the architect needs a mechanism that controls pod-to-pod traffic based on labels and ports. Kubernetes Network Policies with a default-deny stance provide exactly that: a whitelist model where only explicitly permitted flows are allowed. This prevents unauthorized lateral movement even within the same namespace and is the native, CNI-supported solution for microsegmentation in Kubernetes.

Exam trap

The trap here is confusing service mesh mTLS, which provides encryption and identity, with network segmentation, which controls reachability; mTLS alone does not restrict which services can connect.

33
MCQmedium

A company is implementing measured boot using TPM 2.0. What is the primary purpose of storing boot measurements in Platform Configuration Registers (PCRs)?

A.To speed up the boot process.
B.To provide a root of trust for storage (sealed storage).
C.To encrypt the bootloader.
D.To enable remote attestation of the system's boot state.
AnswerD

PCRs hold cumulative hashes of boot components, and their values can be signed by the TPM's attestation key. A remote verifier compares these quotes against known-good values, confirming the system booted untampered — the core mechanism enabling remote attestation of boot state.

Why this answer

PCRs store hashes of boot components; these measurements are used for remote attestation to verify the integrity of the boot process.

34
Multi-Selectmedium

A security team is deploying a hardware security module (HSM) to protect the root of trust for a code-signing pipeline. The team must ensure that signing keys cannot be extracted and that all signing operations are attributable to an authorized operator. Which TWO controls BEST meet these requirements? (Choose two.)

Select 2 answers
A.Store an encrypted backup of the HSM's key material on a network share protected by share-level permissions
B.Enable FIPS 140-3 validated mode on the HSM and publish the validation certificate internally
C.Configure the HSM to mark signing keys as non-extractable and perform all cryptographic operations inside the module
D.Enable per-operator authentication to the HSM and log each signing operation with the operator identity and key reference
E.Configure the HSM to allow a shared service account to perform signing so that automation is not interrupted
AnswersC, D

Non-extractable keys that never leave the HSM boundary ensure the private key cannot be copied or exfiltrated, satisfying the key-protection requirement. Because signing happens inside the module, the plaintext key is never exposed to the host OS or application memory, which is exactly the property needed for a code-signing root of trust.

Why this answer

Marking keys non-extractable and performing operations inside the module protects the signing key from extraction, while per-operator authentication with operation logging provides attribution. Backup exports and shared service accounts undermine both goals, and FIPS validation is a module-level compliance attribute rather than an operational control.

Exam trap

The trap here is accepting FIPS validation as if it automatically guarantees non-extractable keys and operator attribution, when those depend on configuration and identity management.

35
Multi-Selectmedium

A security engineer is deploying a wireless network for a corporate campus that must authenticate users with 802.1X and protect credentials from eavesdropping. The engineer configures a RADIUS server and WPA3-Enterprise. Which TWO additional configuration elements are required to establish a mutually authenticated, encrypted EAP tunnel before the supplicant's identity is exposed? (Choose two.)

Select 2 answers
A.An EAP method that establishes a TLS tunnel before transmitting the inner identity, such as EAP-TTLS or PEAP.
B.A preshared key distributed to all campus clients through group policy.
C.A server certificate issued by an internal CA and trusted by the supplicants.
D.WPA3-SAE on the access point to derive the pairwise master key from the passphrase.
E.A captive portal that redirects unauthenticated clients to a credential entry page.
AnswersA, C

EAP-TTLS and PEAP create an encrypted TLS tunnel using the server certificate, and the actual user identity and credentials are exchanged inside that tunnel. This protects the supplicant identity from passive eavesdroppers and prevents credential theft. A method that sends identity in the clear before the tunnel, such as EAP-MD5, does not meet the requirement.

Why this answer

A protected EAP deployment needs the supplicant to validate the authentication server via a trusted certificate, then negotiate a TLS tunnel in which the real identity and credentials travel. PEAP and EAP-TTLS both do this, whereas methods that expose identity before tunneling do not. Together the trusted server certificate and the tunneling EAP method deliver mutual authentication and credential protection.

Exam trap

The trap here is confusing WPA3-SAE, a personal-mode passphrase method, with WPA3-Enterprise 802.1X, which relies on certificates and a tunneling EAP method.

36
MCQmedium

An organization wants to implement passwordless authentication for its employees using FIDO2/WebAuthn. What is a primary security advantage of this approach over traditional password-based MFA?

A.It is resistant to phishing attacks because credentials are bound to the origin.
B.It eliminates the need for a second factor.
C.It allows users to reuse the same credential across multiple websites.
D.It does not require any client-side hardware.
AnswerA

FIDO2/WebAuthn credentials are cryptographically bound to the relying party's origin, so a credential registered for the genuine sign-in endpoint cannot be replayed against a look-alike phishing domain. This origin binding satisfies the stem's passwordless requirement while eliminating credential theft via reverse-proxy phishing kits such as Evilginx, which defeat OTP-based MFA.

Why this answer

FIDO2 uses public key cryptography; the private key never leaves the user's device, so phishing attacks cannot steal credentials. This provides strong resistance to phishing.

37
MCQhard

An organization wants to implement a privileged access management (PAM) solution to manage administrative credentials. They require that administrators request temporary access to privileged accounts and that these credentials are automatically rotated after each use. Which PAM approach best meets these requirements?

A.Password vaulting with checkout
B.Just-in-time access provisioning with credential rotation
C.Privileged account session management
D.Break-glass account procedures
AnswerB

Just-in-time access provisioning grants privileged accounts only for an approved, time-bound window, and credential rotation replaces the password after each session. Together these satisfy both stated requirements: temporary access on request and automatic rotation following use.

Why this answer

Option B is correct because just-in-time (JIT) access provisioning grants privileged credentials only for the duration of a task and automatically rotates or revokes them afterward, directly matching the requirement for temporary access with post-use rotation. This approach minimizes standing privileges and the attack surface. Password vaulting with checkout (A) provides temporary access but does not inherently rotate credentials after each use unless combined with rotation workflows.

Exam trap

CAS-005 often tests the confusion between password vaulting (which stores and checks out credentials) and JIT provisioning with rotation (which issues and automatically rotates credentials), causing candidates to pick vaulting when rotation after each use is explicitly required.

How to eliminate wrong answers

Option A is wrong because password vaulting with checkout typically checks out a credential for a period but does not guarantee automatic rotation after each use; the credential may remain valid until manually rotated. Option C is wrong because privileged account session management focuses on recording and monitoring sessions, not on issuing temporary credentials with automatic rotation. Option D is wrong because break-glass accounts are emergency, standing privileged accounts meant for disaster recovery, not for routine temporary access with rotation.

38
Multi-Selectmedium

A security architect is designing a PKI for a large enterprise that issues certificates to thousands of users and devices. The architect wants to implement a mechanism to efficiently check certificate revocation status without requiring clients to download a full CRL. Which TWO technologies should be considered?

Select 2 answers
A.CRL distribution points
B.Certificate transparency logs
C.OCSP stapling
D.Online Certificate Status Protocol (OCSP)
E.Delta CRL
AnswersC, D

OCSP stapling lets the server fetch a signed, timestamped revocation response and present it during the TLS handshake, so clients avoid downloading the full CRL or contacting the OCSP responder directly. This satisfies the stem's constraint of efficient revocation checking without full CRL downloads, while reducing latency and privacy leakage.

Why this answer

Option C (OCSP stapling) is correct because it lets the server obtain a signed, time-stamped OCSP response from the CA and present it during the TLS handshake, so clients get revocation status without contacting the OCSP responder themselves, reducing latency and load. Option D (Online Certificate Status Protocol, OCSP) is correct because it is the standard protocol for querying a responder about a single certificate's revocation status, returning good, revoked, or unknown, which avoids downloading an entire CRL. Option A (CRL distribution points) is not appropriate here because it points clients to full CRLs, which is exactly the bulk-download behavior the architect wants to avoid.

Option B (certificate transparency logs) is unrelated to revocation checking; CT logs provide public auditability of issued certificates, not revocation status. Option E (delta CRL) still relies on CRL downloads (a base CRL plus deltas), so it does not meet the goal of avoiding full CRL retrieval.

39
MCQmedium

A security engineer is implementing a solution to protect sensitive data stored in a database. The requirement is to ensure that even if the database files are stolen, the data cannot be read without access to a hardware security module (HSM). Which of the following should the engineer implement?

A.Application-level encryption with keys derived from a user password
B.Column-level encryption with keys stored in a configuration file
C.Transparent Data Encryption (TDE) with keys stored in an HSM
D.Disk encryption on the database server with keys stored in the operating system keyring
AnswerC

TDE encrypts the database files at rest, and storing the encryption keys in an HSM ensures that the keys are protected and never exposed in software. Without the HSM, the stolen files cannot be decrypted, meeting the requirement. This approach provides strong protection for data at rest with hardware-based key management.

Why this answer

Transparent Data Encryption with keys stored in an HSM ensures that the encryption keys are protected by hardware and never exposed in software or configuration files. This means that even if the database files are stolen, decryption is impossible without the HSM. The other options either store keys insecurely or do not provide hardware-based key protection.

Exam trap

The trap here is assuming that any encryption at rest is sufficient, without considering where the keys are stored and whether they are hardware-protected.

40
MCQhard

A security architect is designing a key management system for a multinational corporation that must comply with FIPS 140-3 Level 3. The system will store long-term asymmetric private keys used for digital signatures. The architect must ensure that the private keys are protected against physical extraction and that cryptographic operations are performed within a tamper-responsive environment. Which of the following is the MOST appropriate solution?

A.Use a Hardware Security Module (HSM) that is FIPS 140-3 Level 3 validated for key storage and cryptographic operations.
B.Implement a Trusted Platform Module (TPM) 2.0 on each server to store private keys and perform signing operations.
C.Store private keys in a cloud key management service (KMS) that uses FIPS 140-2 Level 2 validated hardware.
D.Store private keys in a software-based keystore encrypted with a passphrase and implement strict access controls.
AnswerA

A FIPS 140-3 Level 3 validated HSM provides tamper-responsive physical security, detects and responds to tampering by zeroizing keys, and performs cryptographic operations internally. It meets the requirements for protecting long-term private keys against extraction and ensures operations occur in a secure environment, making it the most appropriate solution.

Why this answer

FIPS 140-3 Level 3 requires tamper-responsive physical security and identity-based authentication. An HSM validated to this level provides a hardened environment that detects and responds to tampering, such as by zeroizing keys. It also performs cryptographic operations internally, preventing key exposure.

Software keystores, TPMs, and Level 2 cloud KMS solutions do not meet the tamper-responsive and physical extraction resistance requirements for Level 3.

Exam trap

The trap here is assuming that any hardware-based key storage, such as a TPM or a Level 2 HSM, automatically satisfies Level 3 requirements, when in fact Level 3 mandates tamper-responsive mechanisms and validated hardware.

41
MCQmedium

A security engineer is configuring a Linux web server that must accept TLS connections only from clients presenting a valid client certificate issued by the corporate internal CA. The engineer adds `SSLVerifyClient require` to the Apache configuration, restarts the service, and finds that all connections now fail with a handshake error. Which of the following is the MOST likely cause?

A.The server is missing an OCSP responder URL, so revocation checking fails and the handshake is rejected.
B.The client certificates were generated with ECDSA keys while the server is configured to accept only RSA client keys.
C.The `SSLCACertificateFile` directive pointing to the internal CA trust anchor is missing or incorrect.
D.The `SSLProtocol` directive allows only TLSv1.3, which does not support client certificate authentication.
AnswerC

With SSLVerifyClient require, the server must validate the client's chain against a configured trust anchor; without a correct SSLCACertificateFile (or SSLCACertificatePath) the handshake aborts because the presented certificate cannot be chained to a trusted root. Pointing this directive at the internal CA resolves the failure, which makes it the most likely cause here.

Why this answer

Requiring client certificates forces the server to build and validate a chain from each client certificate to a trusted anchor. If the CA file that contains the internal root is absent or wrong, every validation fails and the handshake is torn down. Configuring the correct SSLCACertificateFile restores trust and allows valid clients to complete the handshake.

Exam trap

The trap here is assuming that enabling SSLVerifyClient alone is sufficient, when the server also needs an explicit trust anchor to validate the client chain.

42
MCQhard

A security analyst is investigating a potential side-channel attack on an IoT device. The device's cryptographic operations show variable execution times based on the key and plaintext. Which mitigation is most effective against timing attacks?

A.Use a faster processor to reduce execution time.
B.Use constant-time cryptographic implementations.
C.Implement random delays in cryptographic operations.
D.Disable caching in the CPU during cryptographic operations.
AnswerB

Constant-time implementations execute identical instruction sequences and memory access patterns regardless of key or plaintext values, eliminating the timing variance the analyst observed. This removes the correlation between execution duration and secret data that enables timing attacks.

Why this answer

Timing attacks exploit variations in execution time. Using constant-time algorithms ensures that operations take the same amount of time regardless of input, preventing information leakage.

43
MCQmedium

An organization is deploying a just-in-time (JIT) privileged access management solution. What is a key benefit of JIT access compared to standing privileged accounts?

A.It allows users to permanently elevate privileges.
B.It eliminates the need for multi-factor authentication.
C.It requires no audit logging.
D.It reduces the window of exposure for privileged credentials.
AnswerD

JIT provisioning grants privileged rights only for the approved duration, then revokes them automatically. This directly shrinks the attack surface created by standing accounts, whose credentials remain valid indefinitely. The reduced exposure window satisfies the scenario's core requirement: limiting how long compromised or misused privileged credentials stay exploitable.

Why this answer

JIT access provides temporary privileges that are automatically revoked after use, reducing the attack surface and limiting lateral movement.

44
MCQhard

A security architect is designing segmentation for an industrial control network that runs Modbus/TCP between engineering workstations and programmable logic controllers. The architect wants to prevent an attacker who compromises a workstation from issuing unauthorized write commands to the controllers, while avoiding disruption of legitimate polling traffic. Which control BEST addresses the specific risk?

A.Apply network address translation so controllers are not directly reachable from the workstation subnet.
B.Enable 802.1X port-based authentication on the switches that connect the controllers.
C.Implement a deep packet inspection device that understands the protocol and blocks write function codes from workstations.
D.Deploy a stateful firewall that permits only the workstation-to-controller TCP port used by the protocol.
AnswerC

A protocol-aware inspection device parses Modbus/TCP function codes and can permit read or polling functions while dropping write functions from engineering workstations. This directly constrains what a compromised workstation can do to the controllers without blocking legitimate polling. Because it operates at the application layer of the industrial protocol, it addresses the specific unauthorized write risk.

Why this answer

The risk is a compromised workstation sending unauthorized write commands over a legitimate protocol. Only a control that inspects the industrial protocol at the application layer can distinguish reads from writes and block the dangerous function codes while allowing polling. Address, port, and device-authentication controls operate below that layer and cannot enforce command-level policy.

Exam trap

The trap here is trusting port-based or identity-based controls to stop malicious commands, when only protocol-aware inspection can distinguish a read from a write.

45
MCQmedium

A security engineer is designing a hybrid encryption solution for a messaging application. The requirement is that each message must be encrypted with a unique symmetric key, and that symmetric key must be delivered to the recipient without exposing it to the server. The solution must also support sender authentication. Which combination of cryptographic mechanisms BEST satisfies these requirements?

A.Use Diffie-Hellman key exchange to establish a shared secret, encrypt the message with that secret using AES-256-GCM, and rely on the shared secret itself to authenticate the sender.
B.Encrypt the message with AES-256-CBC using a key derived from the sender's password, and include the password hash in the message header for verification.
C.Encrypt the message with AES-256-GCM using a randomly generated key, encrypt that key with the recipient's RSA public key, and sign the ciphertext with the sender's RSA private key.
D.Encrypt the message directly with the recipient's RSA public key, and have the recipient verify authenticity by comparing a SHA-256 hash sent alongside the ciphertext.
AnswerC

This is the standard hybrid encryption pattern: AES-GCM provides confidentiality and integrity for the message, RSA-OAEP key wrapping delivers the unique symmetric key only to the recipient, and a sender signature provides authentication and non-repudiation. Because the symmetric key is random per message, compromise of one key does not affect other messages, and the server never sees the plaintext key.

Why this answer

Hybrid encryption combines asymmetric and symmetric cryptography to meet confidentiality, integrity, and authentication goals. A random AES-GCM key per message ensures unique symmetric keys, RSA key wrapping delivers that key confidentially to the recipient, and a sender signature binds the message to the sender's identity. The other options either leak key material, use impractical direct asymmetric encryption, or omit sender authentication.

Exam trap

The trap here is assuming that a shared secret from a key exchange inherently authenticates the sender, when it only proves possession of the key and not identity.

46
MCQeasy

An organization is implementing a PKI and wants to ensure that clients can quickly check if a certificate has been revoked without downloading a large list. Which protocol should be used?

A.Certificate Revocation List (CRL)
B.Online Certificate Status Protocol (OCSP)
C.Certificate Transparency (CT)
D.Simple Certificate Enrollment Protocol (SCEP)
AnswerB

OCSP returns a signed, per-certificate revocation status from a responder, so clients query one certificate rather than downloading and parsing an entire CRL. This satisfies the requirement for fast revocation checking without transferring a large list.

Why this answer

OCSP (Online Certificate Status Protocol) allows clients to check the revocation status of a single certificate in real time without downloading a full CRL.

47
MCQmedium

A financial services firm must protect cardholder data in a database and wants a control that renders the data unreadable to database administrators and to anyone who steals a backup, while still allowing the application to run equality lookups on the protected column. Which approach BEST meets these requirements?

A.Store the column encrypted with AES-256-GCM using a key held in an HSM, and let the application decrypt rows after retrieving them by primary key.
B.Store the column in plaintext but restrict table access with database roles and enable transparent data encryption on the tablespace.
C.Store a keyed hash of the column using HMAC-SHA-256 with a key held outside the database, and query by recomputing the hash of the search value.
D.Store the column encrypted with AES-256-CBC using a static initialization vector so identical plaintexts produce identical ciphertext for lookups.
AnswerC

A keyed hash is deterministic for a given input and key, so identical values produce identical digests and the database can index and match them for equality searches. Because the key lives outside the database, administrators and backup thieves see only digests they cannot reverse or verify without the key, meeting both the confidentiality and lookup requirements.

Why this answer

A keyed hash computed with a secret key held outside the database is deterministic, so equality predicates can be evaluated directly against the stored digest while the original values stay hidden from administrators and backup thieves. This preserves index-based lookups and satisfies the confidentiality goal, whereas randomized encryption breaks equality queries and static-IV encryption introduces serious cryptographic weaknesses.

Exam trap

The trap here is assuming that strong encryption such as AES-GCM automatically supports searchable equality lookups, when randomized encryption deliberately prevents them.

48
MCQhard

During a security audit, it is discovered that a critical server uses SSH with password authentication and supports weak key exchange algorithms. Which of the following is the most effective hardening step to prevent brute-force attacks and ensure forward secrecy?

A.Implement fail2ban to block IPs after failed attempts
B.Disable password authentication and restrict key exchange algorithms to curve25519-sha256
C.Change the SSH port to a non-default high port
D.Use RSA keys with 4096-bit length
AnswerB

Disabling password authentication removes the credential-guessing vector entirely, forcing key-based access that resists brute force. Restricting key exchange to curve25519-sha256 enforces ephemeral elliptic-curve Diffie-Hellman, delivering forward secrecy so compromised long-term keys cannot decrypt past sessions. Together these satisfy both the brute-force and forward-secrecy constraints in the stem.

Why this answer

Disabling password authentication forces the use of key-based authentication, which is resistant to brute-force attacks. Restricting key exchange algorithms to those providing forward secrecy (e.g., Curve25519) ensures that session keys cannot be compromised even if the long-term private key is exposed.

49
Multi-Selecthard

A security engineer is deploying a zero trust architecture for a hybrid cloud environment. The organization wants to enforce least privilege access to internal APIs. The engineer must select TWO mechanisms that provide continuous authentication and authorization for each API request. (Choose two.)

Select 2 answers
A.Mutual TLS (mTLS) with short-lived client certificates issued by an internal CA.
B.OAuth 2.0 access tokens with a one-hour expiry and no refresh tokens.
C.Static API keys stored in a configuration file and rotated every 90 days.
D.A service mesh sidecar proxy that enforces per-request authorization policies based on workload identity.
E.IP allowlisting based on the source subnet of the API caller.
AnswersA, D

mTLS ensures that both the client and server authenticate each other using certificates. Short-lived certificates limit the window of compromise and force frequent re-authentication, aligning with zero trust principles. This mechanism provides strong identity verification for each API request, and when combined with a policy engine, enables continuous authorization decisions based on certificate attributes.

Why this answer

Continuous authentication and authorization in zero trust require identity-based mechanisms that evaluate every request. Mutual TLS with short-lived certificates verifies the client's identity cryptographically, while a service mesh sidecar enforces per-request authorization policies based on workload identity. Together, they ensure that each API call is authenticated and authorized based on dynamic policy, not static network trust.

Exam trap

The trap here is equating network-level controls like IP allowlisting or long-lived tokens with continuous per-request identity verification, which zero trust explicitly rejects.

50
MCQmedium

An organization is implementing SSH hardening for server access. Which configuration change most effectively reduces the attack surface against brute-force and credential theft?

A.Change the default SSH port from 22 to a high-numbered port.
B.Enable public-key authentication and disable password authentication.
C.Set MaxAuthTries to 6 to limit login attempts.
D.Use TCP wrappers to restrict source IP addresses.
AnswerB

Public-key authentication replaces reusable passwords with a private key the client holds, so there is no shared secret to brute-force or steal through phishing. Disabling password authentication removes that credential path entirely, directly shrinking the attack surface.

Why this answer

Public-key authentication replaces the shared secret (password) with an asymmetric key pair, so there is no reusable credential an attacker can brute-force or steal via phishing/keylogging. Disabling password authentication also eliminates the entire class of credential-guessing attacks against SSH. This is the single most impactful hardening step because it removes the attack vector rather than merely slowing it down.

Exam trap

The trap here is confusing 'reducing attack surface' with 'obscuring the service' — candidates often pick port changes or rate-limiting because they sound like hardening, but only eliminating the password credential actually removes the attack vector.

How to eliminate wrong answers

Option A is wrong because changing the SSH port only obscures the service (security through obscurity) and does not stop brute-force tools that scan all ports or target the service directly. Option C is wrong because MaxAuthTries=6 actually permits more attempts than the default of 6 is not a reduction — the default is already 6, and raising or keeping it does not eliminate credential theft; it only throttles guessing. Option D is wrong because TCP wrappers restrict source IPs but do not prevent brute-force from allowed networks or credential theft via compromised hosts inside the permitted range.

51
MCQhard

A security architect must protect data at rest on a database server while allowing a backup application to read the raw encrypted files without ever holding the plaintext data key. The architect wants a design where a hardware security module (HSM) enforces key usage policy and keys never leave the module in plaintext. Which approach BEST satisfies these requirements?

A.Apply full-disk encryption with a passphrase-protected key and share the passphrase with the backup operators.
B.Encrypt the database with a key stored in a software keystore and grant the backup service read access to that keystore.
C.Store the data key in a TPM sealed to the database server's boot measurements and let the backup service request unsealing remotely.
D.Use envelope encryption where the data key is wrapped by a master key resident in the HSM, and decrypt the data key only inside the HSM for authorized operations.
AnswerD

Envelope encryption keeps bulk data encrypted under a data key, while the HSM holds the master key that wraps it. The backup application can copy ciphertext freely, but unwrapping the data key happens only inside the HSM under its usage policy, so the plaintext key never leaves the module. This satisfies both the at-rest protection and HSM-enforced control requirements.

Why this answer

Envelope encryption separates the bulk data key from a master key held inside the HSM. Backup processes can handle ciphertext without ever seeing the plaintext data key, because unwrapping occurs only within the HSM under its enforced policy. This design satisfies both the confidentiality requirement and the constraint that key material never leaves the hardware module.

Exam trap

The trap here is treating any hardware-rooted key storage as equivalent, when only an HSM enforcing wrap and unwrap policy keeps the plaintext data key from ever leaving the boundary.

52
MCQeasy

A systems administrator is hardening a Linux server that stores regulated data. The requirement is that the server's filesystem must detect unauthorized modification of files at rest, including offline tampering with the disk. Which control BEST meets this requirement?

A.Deploy file integrity monitoring that hashes files and compares them against a known-good baseline on a schedule.
B.Enable full-disk encryption with LUKS using a passphrase entered at boot.
C.Set the immutable attribute on critical files using chattr +i and restrict root access.
D.Enable dm-verity on the filesystem so that reads are validated against a signed hash tree.
AnswerD

dm-verity is a device-mapper target that stores a hash tree and verifies each block as it is read, with the root hash protected by a signature. If an attacker alters data offline, the recomputed hash will not match the tree and reads fail. This provides detection of at-rest tampering even when the disk is modified outside the running system, exactly matching the requirement.

Why this answer

dm-verity provides cryptographic verification of filesystem blocks against a signed hash tree, so any offline modification of the disk causes verification to fail when the data is read. Encryption, integrity monitoring, and filesystem attributes each address different threats and none of them reliably detects offline tampering of the protected volume.

Exam trap

The trap here is equating encryption with integrity, when encryption protects confidentiality and provides no reliable detection of offline modification.

53
MCQeasy

An organization is deploying a new IoT device that must securely update its firmware over the air (OTA). The device has limited processing power and memory. Which cryptographic solution would provide the BEST balance of security and performance for verifying firmware updates?

A.RSA-4096 digital signatures
B.Ed25519 digital signatures
C.HMAC-SHA256 with pre-shared key
D.AES-256-GCM for authentication
AnswerB

Ed25519 signatures verify firmware authenticity with minimal computation, satisfying the constrained processor and memory requirement. Its compact 64-byte signatures and 32-byte keys reduce storage and transmission overhead, while verification is far faster than RSA at equivalent security. This makes it ideal for OTA updates on resource-limited IoT devices.

Why this answer

Ed25519 is a fast and secure digital signature algorithm that performs well on constrained devices. RSA 4096 is computationally expensive. HMAC-SHA256 is a symmetric key technique and requires key management overhead.

AES-256-GCM is for encryption, not verification.

54
MCQmedium

A security architect is designing a data-at-rest protection scheme for a database that stores regulated records on a shared storage array. The requirement is to ensure that even if an administrator copies the raw storage volume, the data cannot be read, and that the keys are never accessible to the storage administrator. Which of the following BEST meets these requirements?

A.Transparent data encryption (TDE) enabled on the database instance with the master key stored in the database's internal keystore
B.Filesystem-level encryption on the database server with keys protected only by the operating system's file permissions
C.Application-level encryption of sensitive columns using keys held in a hardware security module (HSM) with strict role separation
D.Full-disk encryption using the storage array's built-in controller-based encryption with keys managed by the array firmware
AnswerC

Encrypting at the application layer with keys resident in an HSM means the ciphertext stored on the shared array is useless without the HSM, and role separation prevents the storage administrator from accessing key material. This directly satisfies both the confidentiality requirement for copied volumes and the key-access restriction.

Why this answer

The strongest control is application-level encryption whose keys live in an HSM with strict role separation, because the ciphertext on shared storage is meaningless without the HSM and the storage administrator cannot reach the keys. Controller, database, and filesystem encryption all leave key material accessible to privileged administrators in the same trust domain.

Exam trap

The trap here is assuming that any encryption at rest satisfies the key-separation requirement, when array, database, and OS-level encryption all expose keys to privileged administrators.

55
MCQhard

A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The architect plans to use full-disk encryption (FDE) with a TPM 2.0 module. Which of the following BEST describes a limitation of this approach that the architect must address?

A.FDE with TPM does not protect data if the operating system is running and an attacker gains remote access.
B.TPM 2.0 modules are vulnerable to cold boot attacks that can extract the encryption key from RAM.
C.TPM 2.0 requires a PIN to be entered at every boot, which is impractical for servers.
D.FDE with TPM cannot be used with self-encrypting drives (SEDs) or hardware encryption.
AnswerA

Full-disk encryption protects data only when the system is powered off or the volume is locked. Once the OS is running and the volume is decrypted, any process or remote attacker with sufficient privileges can read the data. The TPM unseals the key during boot, so the disk remains transparently accessible. This limitation means additional controls like file-level encryption or access controls are needed for runtime protection.

Why this answer

Full-disk encryption with TPM protects data at rest when the system is off or locked. Once the OS is running, the volume is decrypted and accessible to any process with sufficient privileges, including remote attackers. This runtime exposure is the key limitation.

Other options misstate TPM capabilities or conflate optional features with fundamental constraints.

Exam trap

The trap here is believing that full-disk encryption continues to protect data after the operating system has booted and unlocked the volume.

56
MCQeasy

A company wants to implement certificate pinning for its mobile application to prevent man-in-the-middle attacks. Which of the following is the BEST practice when implementing certificate pinning?

A.Disable certificate pinning after the first successful connection
B.Pin the root CA certificate only
C.Pin the public key of the server certificate
D.Pin the entire certificate chain
AnswerC

Pinning the public key rather than the full certificate lets the app continue trusting the server after certificate renewal, provided the key pair is reused. This maintains man-in-the-middle protection while avoiding outages from routine certificate rotation.

Why this answer

Pinning the public key rather than the entire certificate allows for certificate renewal without invalidating the pin.

57
MCQeasy

A security engineer is configuring a TLS 1.3 connection between a web server and client. Which feature is unique to TLS 1.3 and provides reduced latency for returning clients?

A.Cipher suite negotiation
B.0-RTT
C.Forward secrecy
D.Mutual authentication
AnswerB

0-RTT allows a returning client to send application data in the first flight using a previously established pre-shared key, eliminating a round trip. This satisfies the reduced-latency requirement unique to TLS 1.3, though it carries replay risk that deployments must mitigate.

Why this answer

0-RTT (zero round-trip time) resumption is a TLS 1.3 feature that lets a returning client send application data in the first flight using a previously established session ticket, eliminating the round trip needed for a full handshake. This reduces latency for repeat connections. It is unique to TLS 1.3 and not available in TLS 1.2.

Exam trap

CAS-005 often tests whether candidates confuse forward secrecy (a confidentiality property present since TLS 1.2) with 0-RTT (a TLS 1.3-only latency feature), so pick 0-RTT when the question mentions reduced latency for returning clients.

How to eliminate wrong answers

Option A is wrong because cipher suite negotiation exists in TLS 1.2 and earlier, not unique to 1.3. Option C is wrong because forward secrecy (via ECDHE) was introduced in TLS 1.2 and is mandatory in 1.3, but it is not unique to 1.3 nor does it reduce latency for returning clients. Option D is wrong because mutual authentication (client certificates) is supported in TLS 1.2 and earlier and is not a latency-reduction feature.

58
MCQeasy

A security team wants to implement a certificate pinning strategy for their mobile application to prevent man-in-the-middle attacks. Which of the following should be pinned in the application code?

A.The server's public key
B.The intermediate CA certificate
C.The server's IP address
D.The root CA certificate
AnswerA

Pinning the server's public key, rather than the whole certificate, survives certificate renewal because the key pair persists across reissues. This satisfies the mobile app's requirement to block man-in-the-middle attacks without breaking connectivity each time the certificate rotates.

Why this answer

Certificate pinning involves pinning the public key of the server's certificate or the certificate itself. Pinning the public key allows for certificate renewal without updating the app.

59
Multi-Selectmedium

A security engineer is reviewing how a Transport Layer Security session derives its keys and protects data. The engineer wants to identify the mechanisms that provide confidentiality and integrity for application data in TLS 1.3. (Choose two.)

Select 2 answers
A.HKDF-based key schedule using the transcript hash
B.The server certificate's RSA signature over the handshake
C.The ClientHello random value and session ID
D.AEAD ciphers such as AES-GCM and ChaCha20-Poly1305
E.Compression of the record payload before encryption
AnswersA, D

The TLS 1.3 key schedule uses HKDF to derive secrets from the shared ECDHE value and the handshake transcript hash, producing traffic keys for each direction. Those derived keys are what the AEAD ciphers use, so the key schedule underpins confidentiality and integrity by ensuring unique, context-bound keys per session and epoch.

Why this answer

In TLS 1.3, confidentiality and integrity for application data come from AEAD ciphers such as AES-GCM and ChaCha20-Poly1305, whose keys are produced by the HKDF-based key schedule bound to the handshake transcript. The certificate signature authenticates the peer, while randoms, session IDs, and compression do not protect record data.

Exam trap

The trap here is crediting the certificate's signature or handshake randoms with protecting application data, when only the AEAD layer and its derived keys do that.

60
Multi-Selecthard

A security assessor is evaluating an application that uses ChaCha20-Poly1305 for encryption. Which TWO of the following are true about this cryptographic algorithm?

Select 2 answers
A.It is based on the AES algorithm
B.It requires padding to achieve correct block sizes
C.It is a stream cipher
D.It provides authenticated encryption with additional data (AEAD)
E.It is a block cipher
AnswersC, D

ChaCha20 is a stream cipher, generating a keystream from a 256-bit key and nonce that is XORed with plaintext. This distinguishes it from block ciphers such as AES, and explains its efficiency in software without dedicated hardware acceleration.

Why this answer

Option C is correct because ChaCha20 is a stream cipher: it generates a keystream from a 256-bit key and a 96-bit nonce (with a 32-bit counter) and XORs it with the plaintext, so no block structure is involved. Option D is correct because the Poly1305 one-time authenticator is combined with ChaCha20 to form an AEAD construction, producing a 128-bit authentication tag that protects both the ciphertext and any additional authenticated data (AAD) such as headers. Option A is wrong because ChaCha20 is unrelated to AES; it was designed by Daniel J.

Bernstein as a variant of Salsa20 and does not use the Rijndael/AES structure or S-boxes. Option B is wrong because stream ciphers encrypt data byte-by-byte and require no padding to reach a block size. Option E is wrong because ChaCha20 is not a block cipher; it processes data as a continuous keystream rather than fixed-size blocks.

Exam trap

CAS-005 often tests the misconception that all modern ciphers are block ciphers or AES-based — candidates must recognize ChaCha20 as a stream cipher with AEAD properties and no padding requirement.

61
MCQeasy

A security architect is selecting a cipher suite for TLS 1.3 to ensure forward secrecy and high performance. Which cipher suite should be recommended?

A.TLS_RSA_WITH_AES_256_CBC_SHA
B.TLS_AES_256_GCM_SHA384
C.TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
D.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
AnswerB

TLS_AES_256_GCM_SHA384 uses ephemeral Diffie-Hellman key exchange, which is mandatory in TLS 1.3, delivering the required forward secrecy. AES-256-GCM provides authenticated encryption with hardware-accelerated performance, while SHA-384 strengthens the handshake. It satisfies both the forward secrecy and high-performance constraints.

Why this answer

TLS_AES_256_GCM_SHA384 is the only option that is a valid TLS 1.3 cipher suite. TLS 1.3 removed RSA key transport and all CBC-mode ciphers, mandating AEAD (Authenticated Encryption with Associated Data) ciphers and ephemeral key exchange for forward secrecy. This suite uses AES-256 in GCM mode for authenticated encryption and SHA-384 for the HKDF-based key schedule, delivering both high performance (AES-NI accelerated) and strong security.

Exam trap

The trap here is that candidates may select a TLS 1.2 cipher suite that includes ECDHE and GCM, thinking it provides forward secrecy and performance, but TLS 1.3 only accepts the simplified TLS_<AEAD>_<HASH> naming format and prohibits CBC and static RSA.

How to eliminate wrong answers

Option A is wrong because TLS_RSA_WITH_AES_256_CBC_SHA uses RSA key transport (no forward secrecy) and CBC mode, both of which were removed in TLS 1.3. Option C is wrong because TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 is a TLS 1.2 cipher suite name; TLS 1.3 renamed suites to the TLS_<AEAD>_<HASH> format and no longer specifies key exchange or authentication in the cipher suite string. Option D is wrong because TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 uses CBC mode and SHA-256 (not SHA-384), and is a TLS 1.2 suite; TLS 1.3 prohibits CBC and requires AEAD.

62
Multi-Selectmedium

A security engineer is implementing a secure boot process for an embedded device. The engineer needs to ensure that only trusted firmware is executed and that the integrity of the boot chain is maintained. Which TWO of the following are essential components of a secure boot implementation? (Choose two.)

Select 2 answers
A.Full disk encryption of the boot partition
B.Trusted Platform Module (TPM) for measured boot
C.Digital signature verification of each boot stage
D.Secure enclave for key storage
E.Root of trust in immutable hardware
AnswersC, E

Each boot stage must be digitally signed by a trusted authority, and the signature must be verified before execution. This ensures that only authorized code runs. Without verification, an attacker could replace a boot stage with malicious code. The verification uses the public key from the root of trust or a chain of trust.

Why this answer

Secure boot requires an immutable root of trust to anchor trust and digital signature verification at each stage to ensure only trusted code executes. Encryption, secure enclaves, and TPMs can complement security but are not essential for the fundamental secure boot process.

Exam trap

The trap here is equating measured boot with secure boot; measured boot records but does not enforce, while secure boot enforces.

63
MCQeasy

A security administrator is hardening a Linux server that hosts a public web application. The administrator wants to reduce the attack surface by restricting which services are accessible from the internet. Which of the following actions BEST achieves this?

A.Enable SELinux in enforcing mode and set the web server's context to httpd_sys_content_t for all files.
B.Configure the host-based firewall to allow only TCP ports 80 and 443 from any source, and drop all other inbound traffic.
C.Disable password authentication for SSH and require key-based authentication for all users.
D.Install and configure a host-based intrusion detection system (HIDS) to monitor for suspicious activity on all ports.
AnswerB

Allowing only ports 80 and 443 from any source restricts inbound access to the web services, which is exactly what the public web application requires. Dropping all other inbound traffic reduces the attack surface by preventing access to other services. This is a fundamental host-based firewall hardening step that directly addresses the requirement.

Why this answer

The most direct way to reduce the attack surface is to configure the host-based firewall to allow only the necessary ports (80 and 443) and drop all other inbound traffic. This ensures that only the web application is reachable from the internet. SELinux, HIDS, and SSH hardening are valuable but do not restrict network accessibility of services.

Exam trap

The trap here is confusing hardening a specific service with reducing the overall network attack surface, which requires controlling which ports are reachable.

64
MCQmedium

A security administrator is configuring SSH for a jump host used to access critical servers. Which of the following is the most secure configuration option to restrict authentication and reduce the attack surface?

A.Enable root login with a strong password
B.Allow only SSH protocol version 2
C.Change the default port to 2222
D.Allow only key-based authentication
AnswerD

Key-based authentication removes password brute-forcing and credential-replay vectors entirely, since possession of the private key is required. This directly reduces the attack surface on the jump host, satisfying the stem's requirement to restrict authentication to the most secure method.

Why this answer

Disabling password authentication and using only key-based authentication eliminates the risk of password brute force and credential theft. Listening on a non-standard port provides security through obscurity, which is not a strong control.

65
Multi-Selecthard

A security engineer is hardening an SSH server. The policy requires disabling all legacy algorithms and using only modern, secure cryptography. Which THREE of the following configurations should the engineer apply?

Select 3 answers
A.Set HMAC algorithms to use only SHA-2 or stronger.
B.Allow only SSH protocol version 1 for compatibility.
C.Enable root login with password for administrative convenience.
D.Disable password authentication and allow only key-based authentication.
E.Restrict key exchange algorithms to curve25519-sha256.
AnswersA, D, E

Restricting HMAC to SHA-2 or stronger removes MD5 and SHA-1 message authentication codes, which are collision-prone and deprecated. This directly satisfies the policy's requirement to disable legacy algorithms, since SSH MAC negotiation would otherwise still permit these weak integrity checks.

Why this answer

Option A is correct because configuring the MAC (HMAC) list to SHA-2 or stronger (e.g., hmac-sha2-256, hmac-sha2-512) removes weak legacy integrity algorithms such as hmac-md5 and hmac-sha1, which are vulnerable to collision and downgrade attacks. Option D is correct because disabling password authentication and permitting only public-key authentication eliminates brute-force and credential-replay risks, since SSH keys provide stronger, non-reusable cryptographic proof of identity. Option E is correct because restricting KEX algorithms to curve25519-sha256 uses modern elliptic-curve Diffie-Hellman with strong forward secrecy, excluding outdated groups like diffie-hellman-group1-sha1.

Option B is wrong because SSH protocol version 1 is deprecated and insecure (vulnerable to MITM and CRC-32 attacks); only SSH-2 should be allowed. Option C is wrong because enabling direct root login with a password violates least-privilege and hardening best practices, exposing the most privileged account to brute-force attacks.

Exam trap

CAS-005 often tests the temptation to allow legacy protocols or root password login 'for compatibility' — candidates must recognise that these options directly violate the hardening requirement and are never correct in a secure configuration context.

66
MCQeasy

Which key exchange algorithm provides perfect forward secrecy (PFS) and is recommended for use in TLS 1.3?

A.ECDHE
B.RSA key exchange
C.Pre-shared key (PSK)
D.Diffie-Hellman (DH)
AnswerA

ECDHE generates an ephemeral key pair per session, then discards the private key, so compromising the long-term certificate key cannot decrypt past sessions — satisfying TLS 1.3's PFS requirement. TLS 1.3 mandates ephemeral Diffie-Hellman, and ECDHE is its recommended elliptic-curve instantiation, unlike static RSA key transport.

Why this answer

ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) provides PFS as session keys are ephemeral.

67
MCQeasy

A security analyst is investigating a compromised Linux web server. The analyst needs to preserve volatile evidence before shutting the system down for forensic imaging. Which action should the analyst perform FIRST?

A.Create a forensic image of the server's disk drives.
B.Review the application and system logs for signs of intrusion.
C.Capture the contents of physical memory and the current network connections.
D.Shut down the server gracefully to prevent further attacker activity.
AnswerC

Order of volatility dictates that the most perishable evidence, such as RAM contents and active network connections, must be collected before anything else because it is lost on shutdown or even over time. Capturing memory and live connections first preserves artifacts that no disk image can recover.

Why this answer

Forensic handling follows the order of volatility, so the most transient data is collected first. RAM and network connections vanish on power loss or reboot, while disk contents persist. Capturing memory and live connections before imaging or analysis preserves evidence that would otherwise be unrecoverable.

Exam trap

The trap here is equating thoroughness with starting at the disk image, when the perishable memory and network state must be captured before any shutdown or lengthy disk operation.

68
Multi-Selectmedium

A company is evaluating multi-factor authentication methods. Which TWO are considered phishing-resistant? (Select TWO.)

Select 2 answers
A.FIDO2/WebAuthn
B.Biometric authentication on a smartphone
C.TOTP via mobile app
D.SMS one-time codes
E.Hardware security tokens (e.g., YubiKey)
AnswersA, E

FIDO2/WebAuthn binds credentials to the origin's domain via public-key cryptography, so a phishing site on a different domain cannot trigger or replay the authentication. This origin-binding satisfies the phishing-resistance requirement, unlike OTP or push methods vulnerable to real-time relay.

Why this answer

FIDO2/WebAuthn (A) is phishing-resistant because it uses public-key cryptography bound to the origin (relying party ID), so credentials created for one site cannot be replayed on a look-alike phishing domain. Hardware security tokens such as a YubiKey (E) are phishing-resistant for the same reason: they implement FIDO2/U2F and sign a challenge with a private key tied to the legitimate origin, and the private key never leaves the device. In contrast, biometric authentication on a smartphone (B) is only a local verification factor and, by itself, is not bound to the web origin, so it can be captured or relayed in a phishing flow.

TOTP via a mobile app (C) is a shared-secret code that a phishing site can proxy in real time, so it is not phishing-resistant. SMS one-time codes (D) are similarly replayable and additionally vulnerable to SIM-swapping and interception, making them the weakest option here.

69
MCQmedium

A security engineer is implementing a network access control (NAC) solution that must authenticate users and devices before granting access to the corporate network. The organization wants to use a protocol that supports both authentication and authorization and can carry attributes such as VLAN assignment and ACLs. The engineer decides to use RADIUS. Which of the following statements about RADIUS is correct?

A.RADIUS encrypts the entire authentication packet, including attributes, using a shared secret.
B.RADIUS supports the EAP framework natively without any additional encapsulation.
C.RADIUS uses UDP ports 1812 for authentication and 1813 for accounting.
D.RADIUS operates at the application layer and uses TCP for reliable delivery.
AnswerC

RADIUS traditionally uses UDP ports 1812 (authentication) and 1813 (accounting). These are the official IANA-assigned ports. While some legacy implementations use 1645 and 1646, the standard ports are 1812 and 1813. This is a correct statement about RADIUS.

Why this answer

RADIUS uses UDP ports 1812 for authentication and 1813 for accounting as assigned by IANA. It encrypts only the password field, not the whole packet, and it requires EAP encapsulation to support EAP methods. Understanding these details is essential for proper NAC implementation.

Exam trap

The trap here is assuming RADIUS encrypts all attributes or uses TCP, when it actually only encrypts the password and uses UDP, with EAP requiring encapsulation.

70
MCQhard

A security architect must protect a REST API that issues short-lived, signed access tokens. The design goal is to prevent a compromised authorization server from minting tokens that other resource servers will accept after the compromise is detected, without requiring resource servers to poll a central service on every request. Which design BEST meets this goal?

A.Publish a signed token status list that resource servers fetch and cache, allowing revoked or suspect token identifiers to be rejected until the list's next refresh.
B.Shorten the token lifetime to five minutes and require resource servers to validate the signature with the authorization server's public key.
C.Issue tokens bound to the client's TLS session so that a token is only usable from the connection on which it was issued.
D.Require mutual TLS between the authorization server and each resource server and pin the authorization server's certificate.
AnswerA

A signed, cacheable status list lets resource servers reject tokens that the authorization server (or a recovery process) marks as invalid without a per-request call to the issuer. Because the list is signed and versioned, resource servers can refresh it on a schedule and honor the most recent revocation state, bounding the acceptance window after a compromise while keeping request-path latency low.

Why this answer

The goal is to bound how long a fraudulent token remains acceptable without adding a synchronous dependency on the issuer. A signed, cacheable token status list gives resource servers an offline-checkable revocation signal that they can refresh periodically, so tokens minted after detection can be rejected within the refresh interval while normal request processing stays fast and resilient.

Exam trap

The trap here is treating signature validation or channel security as proof that the issuer was uncompromised, when neither addresses tokens minted during an issuer breach.

71
MCQmedium

A security engineer is configuring a Linux bastion host that must expose SFTP to external partners while preventing interactive shell access for those same partner accounts. Partner keys are already deployed in each account's authorized_keys file. Which sshd_config directive combination BEST satisfies this requirement?

A.Set Subsystem sftp /usr/lib/openssh/sftp-server and PermitTunnel no in the global sshd_config.
B.Set PasswordAuthentication no and PubkeyAuthentication yes for the partner group in sshd_config.
C.Set PermitRootLogin no and AllowUsers partner1 partner2 in the global sshd_config.
D.Set ForceCommand internal-sftp and ChrootDirectory /sftp/%u for the partner group in sshd_config.
AnswerD

ForceCommand internal-sftp makes the server run the built-in SFTP subsystem for every matched session regardless of what the client requests, so no shell is ever spawned, and ChrootDirectory confines each partner to their own directory tree with the path token expanded per account. This pairing delivers file transfer without interactive shell access.

Why this answer

Forcing the internal SFTP subsystem for matched sessions guarantees the connection can only perform file transfer, because the daemon never invokes the user's login shell. Combining that with a chroot directory confines each partner to a dedicated subtree and satisfies both the access and isolation goals with a single Match block. Authentication hardening alone does not change what a successfully authenticated session is allowed to do.

Exam trap

The trap here is assuming that strong authentication directives such as disabling passwords or restricting allowed users also restrict what the authenticated session can execute.

72
MCQhard

A security architect is designing a system that requires hardware-enforced isolation for sensitive computations. Which technology provides the strongest isolation by running code in a protected environment within the CPU?

A.HSM
B.TPM 2.0
C.Intel SGX
D.ARM TrustZone
AnswerC

Intel SGX creates hardware-isolated enclaves within the CPU, encrypting code and data in memory so even the operating system or hypervisor cannot read them. This directly satisfies the stem's requirement for hardware-enforced isolation of sensitive computations, providing stronger protection than virtualisation or process-level sandboxing alone.

Why this answer

Intel SGX provides enclaves that isolate code and data even from the operating system, offering strong hardware isolation.

73
MCQmedium

A security administrator is hardening SSH access to a jump host. The requirement is to allow only key-based authentication and restrict the use of weak cryptographic algorithms. Which of the following configurations accomplishes this?

A.Set PermitRootLogin prohibit-password and PasswordAuthentication yes
B.Set PubkeyAuthentication yes, PasswordAuthentication no, and configure Ciphers and MACs to strong algorithms only
C.Set PasswordAuthentication yes and use a strong password policy
D.Set AuthenticationMethods publickey,keyboard-interactive
AnswerB

Disabling PasswordAuthentication enforces key-only access, satisfying the key-based constraint, while explicitly restricting Ciphers and MACs to strong algorithms removes weak cryptographic suites. Together these directives harden the SSH daemon against both password brute force and downgrade attacks on the jump host.

Why this answer

Option B is correct because it explicitly enables public key authentication (PubkeyAuthentication yes), disables password-based authentication (PasswordAuthentication no), and restricts cryptographic algorithms by configuring the Ciphers and MACs directives to only strong algorithms. This directly satisfies both requirements: key-only authentication and elimination of weak crypto. The other options either leave password authentication enabled or do not address weak algorithms.

Exam trap

CAS-005 often tests the misconception that enabling a strong password policy or using keyboard-interactive with publickey satisfies key-only authentication, when in fact any form of password authentication must be explicitly disabled.

How to eliminate wrong answers

Option A is wrong because it sets PasswordAuthentication yes, which allows password-based logins, violating the key-only requirement. Option C is wrong because it enables PasswordAuthentication yes and relies on a strong password policy, which still permits password authentication and does not restrict weak cryptographic algorithms. Option D is wrong because AuthenticationMethods publickey,keyboard-interactive requires both public key and keyboard-interactive (which often includes passwords), so it does not enforce key-only authentication and does not address weak algorithms.

74
MCQmedium

An organization wants to implement a hardware root of trust for measuring system integrity at boot. Which technology should be used to store measurements in Platform Configuration Registers (PCRs) and support remote attestation?

A.HSM
B.Secure Enclave
C.TPM 2.0
D.UEFI Secure Boot
AnswerC

TPM 2.0 provides the hardware root of trust: it stores boot measurements in Platform Configuration Registers and holds the attestation key used for remote attestation. PCRs reside in shielded TPM memory, so software cannot rewrite them, satisfying the tamper-resistant integrity measurement constraint.

Why this answer

TPM 2.0 provides PCRs for measured boot and supports attestation, making it suitable for hardware root of trust.

75
MCQmedium

A security engineer is configuring a Linux bastion host that must use only the strongest key-exchange method available in OpenSSH, avoiding any Diffie-Hellman group that relies on finite-field modular exponentiation. Which sshd_config directive setting should the engineer apply?

A.KexAlgorithms diffie-hellman-group14-sha256
B.KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
C.HostKeyAlgorithms ssh-ed25519
D.Ciphers chacha20-poly1305@openssh.com
AnswerB

Curve25519-sha256 and its libssh.org alias implement X25519, an elliptic-curve Diffie-Hellman exchange that does not use finite-field modular exponentiation and provides strong forward secrecy. Restricting KexAlgorithms to these two entries removes all classic DH group1/group14-sha1 and ECDH NIST-curve options, satisfying the requirement to avoid finite-field DH based key exchange.

Why this answer

Restricting KexAlgorithms to the X25519-based curve25519-sha256 variants forces the server and client to use elliptic-curve Diffie-Hellman, eliminating all finite-field modular-exponentiation groups. The other directives govern ciphers or host-key signatures and leave the default key-exchange list, which still permits classic DH groups, intact. Only the KexAlgorithms restriction directly enforces the stated cryptographic constraint.

Exam trap

The trap here is confusing the directives that select ciphers or host-key signatures with the one that actually controls which key-exchange groups can be negotiated.

Page 1 of 2 · 147 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Casp Engineering Crypto questions.