Courseiva

CAS-005 · topic practice

Security Engineering practice questions

Security Engineering is 31% of CAS-005 and covers designing and implementing secure systems. Expect scenario questions on MFA factor selection, certificate pinning, secure boot chains, firmware signing, and cryptographic protections across cloud, endpoint, and embedded environments. Answers hinge on matching controls to stated threats, not memorizing definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Engineering

What the exam tests

What to know about Security Engineering

You must design and validate layered controls: pick phishing-resistant MFA, pin the correct certificate, enforce a hardware-rooted boot chain, and require signed firmware. The single most important skill is mapping each control to the specific threat and trust boundary described in the scenario.

Selecting phishing-resistant MFA such as FIDO2/WebAuthn over TOTP or push

Pinning leaf or intermediate CA certificates in mobile app code

Verifying secure boot chain of trust from ROM to bootloader to kernel

Signing firmware and validating signatures before installation on IoT devices

Watch out for

Common Security Engineering exam traps

  • ▸Choosing push-based MFA as phishing-resistant when only FIDO2/WebAuthn or certificate-based authentication meets that requirement
  • ▸Pinning the root CA instead of the leaf or intermediate certificate, weakening protection against compromised intermediates
  • ▸Assuming secure boot alone secures updates; firmware must also be signed and verified at install time

Practice set

Security Engineering questions

20 questions · select your answer, then reveal the explanation

A security architect is designing a new authentication system for a high-security environment. The system must support passwordless authentication while providing strong protection against phishing attacks. Which of the following protocols best meets these requirements?

A security engineer is reviewing a PKI deployment where the root CA is kept offline. The issuing CA signs certificates for internal applications. Recently, a subordinate CA was compromised, and the engineer needs to revoke all certificates issued by that CA. Which of the following is the most efficient method to revoke these certificates?

A company requires a cryptographic hash function for integrity verification of large files. The solution must be resistant to length extension attacks and provide high performance. Which of the following is the best choice?

A security analyst is configuring a TPM 2.0 for a new fleet of laptops. The requirement is to ensure that only authorized operating systems can boot and that any tampering with the boot process is detected. Which TPM feature should be used?

A web server is configured to use TLS 1.3. Which of the following is a key security benefit of TLS 1.3 over earlier versions?

A security engineer is selecting an asymmetric encryption algorithm for a system that must provide non-repudiation and long-term security (at least 20 years). The system has limited computational resources. Which of the following is the best choice?

During a security assessment, an analyst discovers that an HSM used for key generation is FIPS 140-2 Level 2 compliant. The organization requires a higher level of physical security to prevent tampering. Which upgrade would best address this requirement?

An organization is implementing a PKI with a three-tier hierarchy (root CA, intermediate CA, issuing CA). The security team wants to ensure that certificate revocation information is available quickly and efficiently. Which TWO mechanisms should they implement? (Select TWO.)

A company is migrating from RSA to elliptic curve cryptography for digital signatures. They require a signature algorithm that provides at least 128 bits of security strength and is resistant to quantum computing attacks in the foreseeable future. Which TWO algorithms meet these requirements? (Select TWO.)

A security engineer is evaluating hardware security modules (HSMs) for key management. The HSM must support key generation, storage, and cryptographic operations without exposing private keys. Additionally, the solution must comply with FIPS 140-2 Level 3. Which THREE features are essential for this requirement? (Select THREE.)

A security architect is designing a new web application that must meet strict data confidentiality and integrity requirements. The application will run in a cloud environment and must support low-latency operations. The architect is considering cipher suites for TLS 1.3. Which combination of algorithms would best meet these requirements?

A company is migrating its internal services to use SSH key-based authentication instead of passwords. The security policy requires using the strongest supported algorithms. The SSH server supports the following key exchange algorithms: diffie-hellman-group14-sha256, ecdh-sha2-nistp384, curve25519-sha256. Which algorithm should the administrator choose to meet the policy?

A security auditor is reviewing the cryptographic controls of a financial application that processes transactions. The application uses digital signatures with RSA 4096 and SHA-256. The auditor recommends migrating to a stronger algorithm due to concerns about long-term security and quantum resistance. Which of the following would be the MOST appropriate replacement?

A security engineer is configuring a new web server to support TLS 1.3. The server must provide forward secrecy and support clients that may not have updated certificates frequently. Which of the following is a feature of TLS 1.3 that addresses these requirements?

An organization is implementing a Windows Hello for Business deployment to enable passwordless authentication. The solution uses TPM 2.0 for key storage. Which of the following TPM features ensures that the system has not been tampered with before the user authenticates?

A security architect is evaluating hardware security modules (HSMs) for a new PKI deployment. The HSM must be compliant with FIPS 140-2 Level 3. Which of the following is a requirement for Level 3 that distinguishes it from Level 2?

An organization uses a PKI with a three-tier hierarchy: root CA, issuing CA, and registration authority. The root CA is kept offline. An intermediate CA certificate must be renewed. Which of the following is the correct process?

During a security assessment, a penetration tester discovers that a smart card used for authentication is vulnerable to a timing attack. The card uses a cryptographic algorithm that has data-dependent timing variations. Which of the following algorithms is MOST likely being used on the smart card?

An organization is planning to deploy digital certificates for various use cases. Which TWO of the following certificate types are typically used for email security?

A company wants to implement certificate pinning for its mobile app to prevent man-in-the-middle attacks. Which approach is most secure and maintainable?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Engineering sessions

Start a Security Engineering only practice session

Every question in these sessions is drawn from the Security Engineering domain — nothing else.

Related practice questions

Related CAS-005 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CAS-005 exam test about Security Engineering?
You must design and validate layered controls: pick phishing-resistant MFA, pin the correct certificate, enforce a hardware-rooted boot chain, and require signed firmware. The single most important skill is mapping each control to the specific threat and trust boundary described in the scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Engineering questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Engineering domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CAS-005 topics?
Use the topic links above to move to related areas, or go back to the CAS-005 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CAS-005 exam covers. They are not copied from any real exam or dump site.