Courseiva

CCNA Casp Engineering Crypto Questions

72 of 147 questions · Page 2/2 · Casp Engineering Crypto topic · Answers revealed

76
MCQhard

A company is deploying a just-in-time (JIT) privileged access management solution. Which of the following BEST describes a key security benefit of JIT access?

A.It eliminates the need for multi-factor authentication
B.It replaces the need for a break-glass account
C.It reduces the risk of lateral movement by limiting the duration of elevated privileges
D.It provides continuous monitoring of all user actions
AnswerC

Just-in-time access issues credentials only for a bounded period, so stolen or misused sessions expire quickly. This shrinks the window attackers have to pivot between systems, directly delivering the reduced lateral-movement risk the stem asks for.

Why this answer

JIT access grants temporary privileges only when needed, reducing the attack surface and the risk of standing privileges being misused.

77
MCQmedium

An IoT device manufacturer wants to ensure secure firmware updates. Which approach best protects against malicious firmware being installed on devices?

A.Digitally sign the firmware with a private key
B.Compress the firmware to reduce size
C.Use a hash of the firmware for integrity verification
D.Encrypt the firmware with a symmetric key
AnswerA

Digitally signing firmware with a private key lets devices verify the signature using the corresponding public key before installation, so any tampered or forged image fails validation. This cryptographically ensures only vendor-authorised firmware is accepted.

Why this answer

Code signing with a trusted key ensures only authorized firmware can be installed.

78
MCQeasy

Which of the following is a primary advantage of using ChaCha20-Poly1305 over AES-256-GCM in certain environments?

A.Better hardware acceleration support
B.Higher security margin
C.Smaller ciphertext size
D.Faster performance on devices without AES-NI
AnswerD

ChaCha20-Poly1305 relies solely on ARX operations, which execute efficiently in software on CPUs lacking AES-NI hardware acceleration. AES-256-GCM depends on dedicated AES instructions for competitive throughput, so on such constrained devices ChaCha20-Poly1305 delivers markedly faster encryption, directly satisfying the stem's "certain environments" constraint.

Why this answer

ChaCha20-Poly1305 is designed to be faster in software that lacks AES hardware acceleration, making it suitable for mobile devices.

79
MCQmedium

An organization requires a cryptographic algorithm that provides both encryption and authentication in a single pass. Which algorithm should be selected?

A.AES-256-GCM
B.AES-256-CBC
C.SHA-256
D.RSA 4096
AnswerA

AES-256-GCM combines AES counter-mode encryption with GHASH authentication, producing ciphertext and a tag in one operation. This satisfies the stem's single-pass requirement, unlike separate encrypt-then-MAC schemes. It also delivers the confidentiality and integrity the organization demands, using a 256-bit key for strong protection.

Why this answer

AES-256-GCM (Galois/Counter Mode) is an authenticated encryption with associated data (AEAD) algorithm that provides both confidentiality (encryption) and integrity/authentication in a single pass. It combines AES counter mode encryption with GHASH for authentication, making it efficient and secure. This meets the requirement for a single algorithm that does both.

Exam trap

The trap is thinking CBC with a separate HMAC counts as 'single pass' or that RSA can do both; the exam expects you to recognize AEAD modes like GCM as the only single-pass encryption+authentication algorithms.

How to eliminate wrong answers

Option B is wrong because AES-256-CBC provides only encryption and requires a separate MAC (e.g., HMAC) for authentication, so it does not provide both in a single pass. Option C is wrong because SHA-256 is a hash function used for integrity, not encryption; it provides no confidentiality. Option D is wrong because RSA 4096 is an asymmetric encryption algorithm that provides encryption or digital signatures, but not both in a single pass, and it is not an AEAD cipher.

80
MCQmedium

A security architect is designing a microservices platform that runs on a shared Kubernetes cluster. Each service must be able to prove its identity to other services, and the design must avoid long-lived shared secrets and support automatic credential rotation when a pod is rescheduled. Which approach BEST meets these requirements?

A.Enable Kubernetes service account token projection with a 24-hour expiration and use the token as a bearer credential for inter-service calls.
B.Store a unique API key for each service in a Kubernetes Secret and require services to present the key in an HTTP header.
C.Issue each service a signed SPIFFE SVID through a SPIRE agent running as a DaemonSet, and use mTLS between services.
D.Configure Kubernetes NetworkPolicies to allow traffic only between approved service namespaces.
AnswerC

SPIFFE/SPIRE issues short-lived, cryptographically verifiable identities (SVIDs) to workloads based on attested node and pod attributes, and automatically rotates them. mTLS using these SVIDs lets each service authenticate peers without embedded static secrets, satisfying the rotation requirement when pods move.

Why this answer

Workload identity frameworks such as SPIFFE/SPIRE bind a cryptographic identity to the actual workload through node and pod attestation, then issue short-lived certificates that rotate automatically. Using mTLS with those identities gives mutual authentication and encryption without shared static secrets, which is exactly what the microservices platform needs.

Exam trap

The trap here is assuming that Kubernetes Secrets or NetworkPolicies provide workload identity, when they only store data or filter traffic and cannot cryptographically prove which service is calling.

81
Multi-Selecthard

A security engineer is implementing a hardware security module (HSM) to protect cryptographic keys used by a certificate authority (CA). The engineer must ensure that the HSM provides strong protections against key extraction and unauthorized use. Which of the following are security properties that the HSM should provide? (Choose two.)

Select 2 answers
A.Tamper-responsive mechanisms that zeroize keys upon physical intrusion.
B.FIPS 140-2 Level 1 validation for the cryptographic module.
C.Support for exporting private keys in plaintext for backup purposes.
D.Role-based access control with separation of duties for key management operations.
E.The ability to run arbitrary code within the HSM to extend functionality.
AnswersA, D

Tamper-responsive mechanisms detect physical intrusion attempts (e.g., drilling, voltage tampering) and automatically erase sensitive key material. This prevents attackers from extracting keys even if they gain physical access to the HSM. It is a critical security property for HSMs used in CAs, as it ensures that keys cannot be recovered from a compromised device.

Why this answer

Tamper-responsive mechanisms and role-based access control with separation of duties are essential security properties for an HSM protecting CA keys. Tamper responsiveness prevents physical key extraction, while RBAC with separation of duties prevents unauthorized logical access. The other options either provide insufficient protection or weaken security.

Exam trap

The trap here is assuming that any FIPS validation or key export capability is sufficient for an HSM, when higher-level physical protections and strict access controls are required for CA key security.

82
MCQhard

A security architect is designing key management for a backup platform that stores encrypted archives in cloud object storage. The requirement is that destroying a single small piece of key material must render all archived data permanently unrecoverable, even if an attacker later obtains a full copy of the storage bucket and the wrapped data keys. Which design BEST meets this requirement?

A.Encrypt all archives with a single long-lived storage key protected by a passphrase that is rotated quarterly and distributed to backup administrators.
B.Encrypt each archive with a unique data encryption key, wrap those keys with a customer-managed root key held in a hardware security module, and destroy the root key to crypto-shred the archives.
C.Encrypt each archive with a unique data encryption key and store those keys in the same object storage bucket alongside the ciphertext for operational simplicity.
D.Apply server-side encryption with provider-managed keys and rely on the cloud provider's internal key rotation schedule to invalidate old key versions over time.
AnswerB

Per-archive data keys limit the blast radius of any single key exposure, and wrapping them under a root key that never leaves the HSM means the wrapped copies stored alongside the archives are useless without it. Deleting the root key destroys the only means of unwrapping, so every archive becomes permanently unrecoverable even if the bucket is fully copied, satisfying crypto-shredding.

Why this answer

Envelope encryption with a hardware-protected root key separates the wrapped data keys from the material needed to use them, so deleting the root key makes every wrapped key permanently unusable and crypto-shreds the entire archive set in one action. Keeping the root key in an HSM prevents export or copying, so an attacker who later captures the bucket gains only undecryptable ciphertext.

Exam trap

The trap here is treating key rotation or provider-managed encryption as equivalent to destruction, when rotation preserves old versions and provider keys remain outside customer control.

83
MCQhard

A security engineer is implementing a secure enclave using Intel SGX for a sensitive application. The engineer must ensure that the enclave's memory is protected from a compromised operating system. Which of the following BEST describes how SGX achieves this protection?

A.The enclave runs in a separate virtual machine that is isolated by the hypervisor, preventing the OS from accessing its memory.
B.The enclave's memory is protected by a hardware-based access control list (ACL) that the OS cannot modify.
C.The enclave's memory is encrypted by the CPU's memory encryption engine (MEE) and integrity-protected, so the OS cannot read or tamper with it.
D.The enclave's code and data are stored in a dedicated secure element (SE) that is physically separate from the main CPU.
AnswerC

Intel SGX uses the CPU's memory encryption engine to encrypt enclave pages when they are written to DRAM and verify their integrity when read back. This ensures that even a privileged attacker like the OS or hypervisor cannot read or modify enclave memory. The encryption keys are managed by the CPU and never exposed to software.

Why this answer

Intel SGX protects enclave memory using the CPU's memory encryption engine, which encrypts data leaving the CPU and verifies integrity on return. This prevents a compromised OS from reading or altering enclave memory. Other options incorrectly describe SGX as using VMs, ACLs, or separate secure elements, which are not how SGX provides isolation.

Exam trap

The trap here is assuming that SGX relies on hypervisor isolation or simple access controls, when in fact it uses hardware memory encryption and integrity protection to defend against privileged attackers.

84
MCQeasy

A security administrator is reviewing the configuration of a wireless network that uses WPA3-Enterprise. The administrator wants to ensure that the authentication mechanism provides mutual authentication and supports centralized policy enforcement. Which of the following should be used?

A.WPA2-Enterprise with PEAP-MSCHAPv2
B.802.1X with EAP-TLS
C.WPA3-Personal with SAE
D.802.1X with EAP-TTLS/PAP
AnswerB

EAP-TLS provides mutual authentication using digital certificates for both the client and the server, and it integrates with a RADIUS server for centralized policy enforcement. This meets the requirements for WPA3-Enterprise, which mandates 802.1X authentication and supports EAP-TLS as a secure method.

Why this answer

EAP-TLS is the strongest EAP method for WPA3-Enterprise because it uses certificates for both client and server, enabling mutual authentication and centralized policy enforcement through RADIUS. The other methods either do not provide mutual certificate-based authentication, are designed for personal networks, or do not meet WPA3-Enterprise standards.

Exam trap

The trap here is assuming that any EAP method with 802.1X provides the same level of security, or confusing WPA3-Personal with Enterprise features.

85
MCQmedium

A security architect is designing a PKI hierarchy for a large enterprise that issues certificates for internal users, devices, and code signing. Which of the following best practices should be implemented to minimize the impact of a CA compromise?

A.Rely on certificate transparency logs to detect compromises
B.Keep the root CA online for immediate certificate revocation
C.Use a single CA for all certificate types to reduce complexity
D.Implement a segmented CA hierarchy with offline root CA and separate issuing CAs for each purpose
AnswerD

An offline root CA issues only to subordinate issuing CAs, each scoped to one purpose, so compromising a user-issuing CA cannot forge code-signing or device certificates. This satisfies the constraint of minimising compromise blast radius through cryptographic and operational separation.

Why this answer

Using a tiered CA hierarchy with a root CA that remains offline and issuing CAs for specific purposes limits exposure. If an issuing CA is compromised, only its certificates need to be revoked, and the root CA can issue a new subordinate CA.

86
MCQhard

A security engineer must select a cryptographic hash function for a new code-signing service that will protect firmware for at least 15 years. The service must resist length-extension attacks and provide collision resistance against well-funded adversaries. The organization's policy requires FIPS 140-3 validated modules only. Which hash function BEST meets these requirements?

A.SHA-256
B.MD5
C.SHA-1
D.SHA3-256
AnswerD

SHA3-256 uses the Keccak sponge construction rather than Merkle-Damgard, so it is inherently resistant to length-extension attacks. It is FIPS 202 approved and acceptable under FIPS 140-3 validated modules, and it provides 128-bit collision resistance, which is sufficient for a 15-year firmware-signing lifespan. It therefore satisfies every stated requirement without additional mitigations.

Why this answer

SHA3-256 is the only listed option that combines FIPS approval, strong collision resistance, and intrinsic resistance to length-extension attacks. The sponge construction avoids the Merkle-Damgard weakness that affects SHA-256, SHA-1, and MD5. Given the 15-year firmware-signing horizon and the explicit anti-length-extension requirement, SHA3-256 is the appropriate engineering choice.

Exam trap

The trap here is assuming that any FIPS-approved hash such as SHA-256 automatically satisfies all security requirements, when length-extension resistance is a construction-specific property that SHA-256 lacks.

87
MCQhard

A security architect is designing a system that requires cryptographic separation of duties for key management. The organization wants to ensure that no single administrator can both generate and use a key without oversight. Which of the following key management practices BEST achieves this requirement?

A.Using a hardware security module (HSM) to store all keys
B.Rotating keys automatically every 24 hours
C.Encrypting all keys with a master key stored in a software vault
D.Implementing dual control with split knowledge for key generation and usage
AnswerD

Dual control requires two or more individuals to authorize an action, and split knowledge ensures that no single person possesses the entire key or the means to use it. Together, they enforce separation of duties, preventing a lone administrator from generating and using a key without oversight. This is a fundamental principle in high-security key management, such as in FIPS 140-2 Level 3 or higher validated modules.

Why this answer

Dual control and split knowledge are specifically designed to enforce separation of duties. Dual control requires multiple authorizations, while split knowledge ensures that components of a key are divided among individuals. This combination prevents any single administrator from unilaterally generating and using a key, which is essential for high-assurance key management and compliance with standards like FIPS 140-2.

Exam trap

The trap here is assuming that an HSM automatically enforces separation of duties; it provides secure storage but not policy enforcement.

88
MCQmedium

A security engineer is reviewing the configuration of a web server that uses TLS 1.3. The engineer wants to ensure that the server supports perfect forward secrecy (PFS) and uses strong cipher suites. Which of the following cipher suites should be selected?

A.TLS_AES_256_GCM_SHA384
B.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
C.TLS_RSA_WITH_AES_256_GCM_SHA384
D.TLS_DHE_RSA_WITH_AES_128_CBC_SHA
AnswerA

TLS_AES_256_GCM_SHA384 is a TLS 1.3 cipher suite that uses AES-256 in GCM mode for encryption and SHA-384 for the hash. In TLS 1.3, all cipher suites provide forward secrecy by default because key exchange uses ephemeral Diffie-Hellman. This suite is strong and meets the requirements for PFS and strong encryption.

Why this answer

In TLS 1.3, all cipher suites provide forward secrecy because key exchange is always ephemeral. The only valid TLS 1.3 cipher suite among the options is TLS_AES_256_GCM_SHA384, which uses strong AES-256-GCM encryption. The others are TLS 1.2 suites or use weak algorithms.

Exam trap

The trap here is selecting a TLS 1.2 cipher suite that provides PFS but is not valid for TLS 1.3; TLS 1.3 cipher suite names do not specify key exchange.

89
MCQmedium

A security engineer is configuring a Linux web server that hosts a public-facing application. The server's SSH daemon must be hardened to prevent brute-force attacks and unauthorized access. The engineer has already disabled root login and password authentication. Which additional control should the engineer implement to restrict access to only authorized administrative users?

A.Enable ChallengeResponseAuthentication and configure PAM modules.
B.Configure AllowUsers in /etc/ssh/sshd_config to list authorized usernames.
C.Set PermitRootLogin to no in /etc/ssh/sshd_config.
D.Change the SSH port from 22 to a non-standard port.
AnswerB

AllowUsers explicitly defines which user accounts may authenticate via SSH. When password authentication is disabled and root login is prohibited, this directive further narrows access to only the named administrative accounts. It directly addresses the requirement to restrict access to authorized users and is a standard hardening step for SSH daemons on public-facing servers.

Why this answer

The AllowUsers directive in sshd_config explicitly whitelists user accounts permitted to authenticate over SSH. When combined with disabled password authentication and no root login, it ensures only named administrative users can connect, directly satisfying the hardening goal. Other options either add authentication methods or obscure the service without limiting user access.

Exam trap

The trap here is assuming that disabling root login and password authentication alone restricts SSH access to specific users.

90
MCQmedium

A security engineer is configuring a Linux server that hosts a web application. The server must accept connections only from the internal network 10.0.0.0/24 and must reject all other incoming traffic. The engineer decides to use iptables. Which command sequence correctly implements this requirement?

A.iptables -A INPUT -j DROP; iptables -A INPUT -s 10.0.0.0/24 -j ACCEPT
B.iptables -A INPUT -s 10.0.0.0/24 -j DROP; iptables -A INPUT -j ACCEPT
C.iptables -A INPUT -s 10.0.0.0/24 -j REJECT; iptables -A INPUT -j ACCEPT
D.iptables -A INPUT -s 10.0.0.0/24 -j ACCEPT; iptables -A INPUT -j DROP
AnswerD

This sequence appends an ACCEPT rule for the internal subnet, then appends a DROP rule for all other traffic. Because iptables processes rules in order, packets from 10.0.0.0/24 match the first rule and are accepted; all other packets fall through to the DROP rule. This correctly implements the requirement.

Why this answer

The requirement is to allow traffic only from 10.0.0.0/24 and drop everything else. In iptables, rules are evaluated in order, so the ACCEPT rule for the internal subnet must come before the DROP rule. Appending ACCEPT then DROP achieves this.

Other orderings either block legitimate traffic or permit unauthorized traffic, violating the stated policy.

Exam trap

The trap here is assuming that iptables rules are order-independent or that a default DROP policy exists without being explicitly configured.

91
MCQeasy

A system administrator needs to securely store cryptographic keys and perform signing operations in a tamper-resistant hardware device. Which solution should be used?

A.A Hardware Security Module (HSM) with FIPS 140-2 Level 3 certification.
B.A secure enclave like Intel SGX.
C.A software-based key store with encrypted files.
D.A Trusted Platform Module (TPM) 2.0.
AnswerA

An HSM provides dedicated tamper-resistant hardware that generates, stores and uses cryptographic keys internally, so keys never leave the device in plaintext. FIPS 140-2 Level 3 certification confirms physical tamper resistance, satisfying the requirement for secure signing in hardware.

Why this answer

An HSM (Hardware Security Module) is designed to securely generate, store, and manage cryptographic keys in a tamper-resistant environment.

92
MCQeasy

A security administrator is hardening a web server and wants to ensure that browsers cannot be tricked into sending requests over plain HTTP after an initial HTTPS visit. The administrator also wants to prevent protocol-downgrade attacks against the site. Which response header should be configured?

A.Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
B.Content-Security-Policy: default-src 'self'
C.X-Frame-Options: DENY
D.Referrer-Policy: no-referrer
AnswerA

The Strict-Transport-Security header instructs browsers to upgrade all future requests for the domain to HTTPS for the specified max-age, and includeSubDomains extends this to subdomains while preload allows inclusion in browser preload lists. This directly prevents protocol downgrade and plaintext requests after the first secure visit.

Why this answer

Strict-Transport-Security tells the browser to rewrite future requests for the domain to HTTPS and to refuse insecure connections for the max-age window, which blocks downgrade attacks. The other headers address resource loading, framing, and referrer leakage respectively, none of which enforce transport security or prevent a fallback to HTTP.

Exam trap

The trap here is assuming any modern security header, such as a content security policy, also enforces HTTPS transport.

93
MCQhard

A security architect is designing a zero trust architecture for a hybrid environment where users access internal applications from managed and unmanaged devices. The requirement is that access decisions consider device health and user identity on every request rather than relying on network location. Which of the following BEST implements this requirement?

A.Implement a policy engine that evaluates user identity and device posture from a device attestation service for each access request, brokered through a policy enforcement point
B.Segment the internal network into microsegments with host-based firewalls and require 802.1X for all wired and wireless access
C.Require all users to connect through a bastion host that performs multi-factor authentication before reaching internal applications
D.Deploy a next-generation firewall with IP-based allow lists for the corporate VPN address pool and enable TLS inspection
AnswerA

A policy engine that consumes identity and device-posture signals and enforces decisions through a policy enforcement point on every request is the core of zero trust. It removes implicit trust based on network location and makes access contingent on current device health and authenticated identity, matching the stated requirement precisely.

Why this answer

Zero trust requires a policy decision point that consumes identity and device-posture telemetry and a policy enforcement point that applies the decision to each request. Perimeter, bastion, and segmentation approaches all evaluate trust at connection or network admission time and do not continuously factor device health into every access decision.

Exam trap

The trap here is equating strong network segmentation or a hardened bastion with zero trust, when those still grant implicit trust based on location once the initial check passes.

94
Multi-Selecthard

A security team is deploying a zero trust architecture for an enterprise campus. The design must verify every request as though it originated from an untrusted network and must limit lateral movement after a workstation compromise. Which TWO capabilities are essential to this design? (Choose two.)

Select 2 answers
A.Implicit trust for traffic originating from the internal corporate VLAN.
B.Microsegmentation of workloads so that east-west traffic is denied by default and allowed only by explicit policy.
C.Policy decision and enforcement points that evaluate device posture and user identity for each session.
D.A VPN concentrator that grants full internal access after a single successful login.
E.A flat internal network with 802.1X port authentication at the access layer.
AnswersB, C

Microsegmentation enforces least privilege between workloads, so a compromised workstation cannot freely reach other systems. Combined with default-deny rules, it contains an intruder and is a core mechanism for limiting lateral movement in a zero trust design.

Why this answer

Zero trust replaces location-based trust with continuous, per-session evaluation of identity and device posture, enforced by policy decision and enforcement points. Microsegmentation supports that model by denying east-west traffic by default and permitting only explicitly authorized flows, which together prevent an intruder from moving freely.

Exam trap

The trap here is assuming that strong authentication at the perimeter, such as 802.1X or VPN login, constitutes zero trust, when the model requires ongoing per-session authorization and internal segmentation.

95
Multi-Selecthard

A company is migrating its legacy VPN to use IPsec with IKEv2. The security team wants to ensure the strongest possible security. Which THREE configuration options should be selected?

Select 3 answers
A.Use ECDSA P-384 for authentication
B.Use SHA-1 for integrity
C.Use AES-256-GCM for encryption
D.Use IKEv1 instead of IKEv2
E.Enable perfect forward secrecy (DHE)
AnswersA, C, E

ECDSA P-384 provides a 192-bit security strength, exceeding RSA-2048 and matching the strongest IKEv2 authentication options. It satisfies the stem's demand for maximum security by using elliptic-curve cryptography, which delivers equivalent strength with smaller keys and is approved for CNSA suite compliance.

Why this answer

Option A (ECDSA P-384) is correct because elliptic-curve signatures at the 384-bit level provide roughly 192-bit security strength, far exceeding RSA-2048, and are well supported in IKEv2 for strong peer authentication. Option C (AES-256-GCM) is correct because AES-256 gives a 256-bit key and GCM is an AEAD mode that provides both confidentiality and integrity in a single efficient primitive, making it the strongest symmetric choice here. Option E (perfect forward secrecy via DHE) is correct because Diffie-Hellman ephemeral key exchange ensures that compromise of the long-term key cannot decrypt previously captured sessions, which is essential for 'strongest possible security' in an IKEv2 deployment.

Option B (SHA-1) is not appropriate because SHA-1 is cryptographically broken for integrity and should be replaced by SHA-256 or stronger. Option D (IKEv1) is not appropriate because IKEv2 is more secure, more robust, and supports modern features like MOBIKE and stronger authentication methods.

Exam trap

The trap is selecting SHA-1 for integrity because it is a known algorithm, but SHA-1 is deprecated and insecure; the exam expects recognition that modern IPsec configurations must avoid SHA-1 and IKEv1.

96
Multi-Selectmedium

A security architect is designing a just-in-time (JIT) privileged access management (PAM) solution. Which TWO of the following are key characteristics of JIT access?

Select 2 answers
A.Privileges are permanent but require approval each time.
B.Access rights are automatically revoked after use or expiry.
C.Break-glass accounts are used for emergency access.
D.Privileges are granted on-demand for a limited time period.
E.Users have standing privileges for routine tasks.
AnswersB, D

Automatic revocation after use or expiry is fundamental to JIT: standing privileges are eliminated, so access exists only for the approved window. Once the task completes or the timer lapses, the entitlement is withdrawn without manual intervention, shrinking the attack surface.

Why this answer

Option B is correct because a defining property of JIT PAM is that elevated rights are time-bound and automatically revoked once the task completes or the approved window expires, eliminating lingering standing privileges. Option D is correct because JIT access grants privileges on-demand only when needed, for a limited duration, rather than provisioning them permanently in advance. Together, B and D capture the core JIT model: just-in-time, just-enough, and time-limited elevation.

Option A is wrong because JIT privileges are temporary, not permanent, even if approval workflows are involved. Option C is wrong because break-glass accounts are an emergency fallback mechanism, not a defining characteristic of JIT access itself. Option E is wrong because standing privileges for routine tasks directly contradict the JIT principle of eliminating always-on access.

97
Multi-Selecthard

A security engineer is hardening a containerized workload platform against attacks that escape a container and reach the host kernel. The team wants to reduce the kernel attack surface available to each container without breaking application functionality. Which TWO measures BEST accomplish this? (Choose two.)

Select 2 answers
A.Apply a seccomp profile that allows only the system calls the application actually uses and denies the rest by default.
B.Run the container runtime with the Docker socket mounted into every container so the platform can manage sibling containers.
C.Disable mandatory access control frameworks such as AppArmor or SELinux so the application is not blocked by policy denials.
D.Set the container to run as the root user inside its namespace to avoid file permission problems during deployment.
E.Drop all Linux capabilities and add back only the specific ones the application requires.
AnswersA, E

A default-deny seccomp profile removes access to the large majority of system calls a process never needs, shrinking the kernel interfaces an attacker can abuse from inside a compromised container. Because it is enforced per process by the kernel, a successful application exploit cannot pivot to unneeded calls such as those used to load modules or manipulate namespaces, directly reducing escape options.

Why this answer

Default-deny seccomp profiles and least-privilege capability sets both operate at the kernel boundary and remove entire classes of privileged operations from containerized processes. Together they ensure that even a fully exploited application lacks the system calls and capabilities needed to reach host kernel interfaces, which is precisely the attack surface reduction the team requires.

Exam trap

The trap here is equating stronger isolation with convenience features such as runtime socket mounting or running as root, which actually widen the path from container to host.

98
MCQmedium

A security engineer is configuring SSH for a jump host used to access critical servers. The engineer wants to restrict the cryptographic algorithms to the most secure options. Which of the following should be DISABLED?

A.Diffie-Hellman group-exchange with SHA-1
B.AES-256-CTR
C.Ed25519 for host keys
D.HMAC-SHA2-256
AnswerA

Diffie-Hellman group exchange with SHA-1 uses a deprecated hash for key exchange integrity, weakening SSH against collision-based attacks. Disabling it enforces stronger SHA-2-based key exchange algorithms, meeting the requirement to restrict the jump host to the most secure options.

Why this answer

Diffie-Hellman group exchange with SHA-1 uses the SHA-1 hash for key exchange integrity, and SHA-1 is cryptographically broken (collision attacks demonstrated) and deprecated by NIST. For a hardened jump host, this kex algorithm should be disabled in favor of SHA-2-based groups like diffie-hellman-group-exchange-sha256 or curve25519-sha256.

Exam trap

CAS-005 often tests whether candidates can distinguish deprecated hash-based algorithms (SHA-1 kex) from still-secure primitives (AES-256, Ed25519, HMAC-SHA2) — the trap is picking a strong cipher or MAC thinking it's weak because it sounds old.

How to eliminate wrong answers

Option B is wrong because AES-256-CTR is a strong, modern symmetric cipher with a 256-bit key and is considered secure for SSH transport encryption. Option C is wrong because Ed25519 is a modern elliptic-curve signature algorithm offering strong security and performance, and is recommended for host keys. Option D is wrong because HMAC-SHA2-256 is a secure message authentication code based on SHA-256, appropriate for SSH integrity protection.

99
MCQhard

A security team is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to prevent a compromised pod from reaching the cloud metadata service at 169.254.169.254 to steal node credentials, while still allowing pods to reach required external APIs. Which of the following should the team implement?

A.Apply a network policy that denies egress to the link-local metadata address while permitting approved external destinations.
B.Set the pod security context to run containers as a non-root user with a read-only root filesystem.
C.Configure role-based access control so that pods run under a service account with no RBAC permissions.
D.Enable mutual TLS between all pods and require SPIFFE identities for service-to-service calls.
AnswerA

Network policies can select pods and control egress by destination CIDR and port, so a rule denying 169.254.169.254 blocks the metadata path while a companion allow rule permits required external APIs. This is the least-disruptive control that directly removes the credential-theft vector without breaking legitimate traffic. It enforces the restriction at the pod network layer regardless of application behavior.

Why this answer

Blocking pod egress to the link-local metadata address removes the direct path a compromised workload would use to obtain node credentials, and pairing it with an allow rule for required external APIs preserves functionality. Network policy operates below the application, so it constrains all processes in the selected pods without relying on application cooperation.

Exam trap

The trap here is assuming that workload identity or RBAC hardening protects the metadata endpoint, when those controls govern different planes than the pod network path.

100
MCQmedium

A security engineer is designing the key-management lifecycle for a hardware security module (HSM) that will hold a root certificate authority signing key. The requirement is that the private key must never exist in plaintext outside the HSM, even during backup, and that restoration must be possible after a total device failure. Which approach BEST satisfies these requirements?

A.Configure the HSM to back up the key material using its secure backup mechanism to at least two geographically separate HSMs.
B.Store the key on the HSM and replicate it to a spare HSM using the vendor's plaintext export option, then destroy the source.
C.Encrypt the private key with AES-256 in software and store the ciphertext on a hardened file server accessible only to administrators.
D.Export the private key wrapped under a key-encryption key, store the wrapped blob on encrypted network storage, and re-import it after failure.
AnswerA

Many HSMs support cloning or secure backup where the key is transferred between devices in a wrapped, hardware-protected form and never exists as a recoverable plaintext blob. Storing the backup on a second, geographically separate HSM preserves availability after device failure while keeping the private key inside certified hardware boundaries, satisfying both the no-plaintext and restoration requirements.

Why this answer

The only approach that keeps the private key inside a hardware-protected boundary while still allowing recovery is a vendor-supported secure backup or cloning mechanism between HSMs. Wrapping, plaintext export, and software encryption all allow the key to exist in a form that can be recovered outside certified hardware, which the scenario explicitly forbids.

Exam trap

The trap here is assuming that wrapping a key under a key-encryption key keeps it 'inside the HSM,' when in fact the wrapped blob is exportable and recoverable.

101
Multi-Selecthard

A security engineer is implementing a secure software development lifecycle (SDLC) for a new application. The engineer needs to integrate security activities that help identify and mitigate vulnerabilities early in the development process. Which of the following activities should be included? (Choose two.)

Select 2 answers
A.Static application security testing (SAST) in the CI/CD pipeline.
B.Security awareness training for developers.
C.Penetration testing after production deployment.
D.Threat modeling during the design phase.
E.Dynamic application security testing (DAST) during the design phase.
AnswersA, D

SAST analyzes source code for vulnerabilities without executing it, enabling early detection of issues like SQL injection or buffer overflows. Integrating SAST into the CI/CD pipeline ensures continuous security checks. This helps developers fix flaws before deployment, reducing risk.

Why this answer

Threat modeling during design and SAST in the CI/CD pipeline are both early-stage activities that help identify and mitigate vulnerabilities before deployment. Threat modeling addresses design flaws, while SAST catches coding errors. Together, they shift security left and reduce remediation costs.

Exam trap

The trap here is selecting activities that are security-related but occur too late (like penetration testing) or are not directly vulnerability-identifying (like training).

102
Multi-Selecthard

A security analyst is reviewing cryptographic implementations for a new application. The application needs to support digital signatures that are quantum-resistant and provide high performance. Which TWO algorithms should the analyst consider? (Select TWO.)

Select 2 answers
A.Ed25519
B.XMSS (eXtended Merkle Signature Scheme)
C.ECDSA P-384
D.BLAKE3
E.CRYSTALS-Dilithium
AnswersB, E

XMSS is a stateful hash-based signature scheme whose security rests solely on hash-function collision resistance, so it resists quantum attacks via Shor's algorithm. It satisfies the quantum-resistance requirement while signing and verifying quickly, meeting the high-performance constraint. Its stateful nature, however, demands careful key-state management to prevent reuse of a one-time key.

Why this answer

XMSS (eXtended Merkle Signature Scheme) (B) is correct because it is a hash-based, post-quantum digital signature scheme standardized in NIST SP 800-208, whose security relies only on hash function properties and is therefore resistant to Shor's algorithm attacks from quantum computers. CRYSTALS-Dilithium (E) is correct because it is a lattice-based post-quantum digital signature algorithm selected by NIST (FIPS 204) that offers strong quantum resistance with efficient signing and verification performance, making it well suited for high-performance applications. Ed25519 (A) is not correct because it is an elliptic-curve signature scheme (EdDSA over Curve25519) that is vulnerable to quantum attacks via Shor's algorithm.

ECDSA P-384 (C) is not correct for the same reason: it is a classical elliptic-curve signature algorithm, not quantum-resistant. BLAKE3 (D) is not correct because it is a cryptographic hash function, not a digital signature algorithm, so it cannot fulfill the digital signature requirement.

103
MCQmedium

A security administrator is configuring a Linux server to enforce mandatory access control (MAC) for a web application. The administrator wants to confine the web server process to only access its own files and network ports, even if the process is compromised. Which of the following should the administrator implement?

A.A chroot jail for the web server process.
B.AppArmor in complain mode.
C.SELinux in enforcing mode with a targeted policy.
D.Standard Linux discretionary access control (DAC) with file permissions.
AnswerC

SELinux in enforcing mode applies mandatory access control, restricting processes to only the resources defined in the policy. A targeted policy confines specific services like the web server, limiting the impact of a compromise. This meets the requirement to confine the web server process even if exploited.

Why this answer

SELinux in enforcing mode applies mandatory access control, restricting processes to only the resources defined in the policy. A targeted policy confines specific services like the web server, limiting the impact of a compromise. This meets the requirement to confine the web server process even if exploited.

Exam trap

The trap here is confusing AppArmor's complain mode with enforce mode, or thinking that DAC or chroot provides mandatory access control.

104
MCQhard

A security engineer is reviewing a TLS 1.3 configuration. Which of the following is a key feature of TLS 1.3 that improves security compared to earlier versions?

A.Mandatory forward secrecy using ephemeral Diffie-Hellman
B.Support for RC4 cipher suite
C.Support for static RSA key exchange
D.Ability to downgrade to TLS 1.2
AnswerA

TLS 1.3 mandates ephemeral Diffie-Hellman key exchange for all cipher suites, so every session derives unique keys and compromise of the long-term key cannot decrypt past traffic. Earlier versions permitted static RSA key transport, which lacked this property.

Why this answer

TLS 1.3 mandates forward secrecy by requiring ephemeral Diffie-Hellman key exchange (DHE or ECDHE), which ensures that session keys cannot be recovered even if the server's long-term private key is later compromised. This is a core security improvement over TLS 1.2, where static RSA key exchange was allowed and lacked forward secrecy.

Exam trap

CAS-005 often tests the misconception that TLS 1.3 supports legacy ciphers like RC4 or static RSA, when in fact it removed them and mandates forward secrecy.

How to eliminate wrong answers

Option B is wrong because RC4 is a broken stream cipher and was removed in TLS 1.3; it is not supported. Option C is wrong because static RSA key exchange was removed in TLS 1.3 precisely because it lacks forward secrecy. Option D is wrong because TLS 1.3 does not support downgrading to TLS 1.2; while a client and server can negotiate TLS 1.2 if both support it, TLS 1.3 itself does not include a downgrade mechanism, and the protocol is designed to prevent downgrade attacks.

105
MCQmedium

A PKI administrator is concerned about the risk of a compromised issuing CA. Which certificate transparency feature helps detect unauthorized certificate issuance?

A.Certificate Transparency logs
B.CRL distribution points
C.OCSP stapling
D.Key usage extensions
AnswerA

Certificate Transparency logs are append-only, publicly auditable records of issued certificates. Monitoring them reveals certificates issued for a domain without authorisation, so a compromised issuing CA's rogue certificates become detectable, satisfying the requirement to detect unauthorised issuance.

Why this answer

Certificate Transparency (CT) logs are append-only, publicly auditable logs where CAs must record every certificate they issue (per RFC 6962). Because monitors and browsers can detect certificates that appear in logs without a corresponding legitimate request, unauthorized or mis-issued certificates from a compromised issuing CA become visible. This is the specific mechanism designed to detect rogue issuance, not just validate or revoke certificates.

Exam trap

The trap here is confusing revocation-checking mechanisms (CRL, OCSP) with issuance-transparency mechanisms (CT logs); candidates often pick OCSP stapling because it sounds like the most 'modern' certificate security feature.

How to eliminate wrong answers

Option B is wrong because CRL distribution points only publish revocation status for certificates the CA has already revoked — they cannot reveal a certificate that was fraudulently issued and not yet reported. Option C is wrong because OCSP stapling is a real-time revocation-checking optimization where the server staples a signed OCSP response to the TLS handshake; it validates current status, not issuance transparency. Option D is wrong because key usage extensions are X.509 fields that constrain how a key may be used (e.g., digitalSignature, keyEncipherment) and have nothing to do with detecting unauthorized issuance.

106
MCQhard

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The requirement is to prevent a compromised pod from reading another tenant's secrets and from making unauthorized network connections to other namespaces. Which of the following combinations BEST addresses both concerns?

A.Enable role-based access control (RBAC) for the API server and require TLS client certificates for all kubelet connections
B.Deploy a service mesh with mutual TLS between all pods and rotate the cluster's certificate authority on a fixed schedule
C.Use pod security admission to enforce the restricted profile and enable audit logging on the API server for all secret access
D.Apply network policies that deny ingress and egress by default and mount secrets only into pods that explicitly require them with least-privilege service accounts
AnswerD

Default-deny network policies stop unauthorized cross-namespace connections, while scoping secret mounts and service account permissions to only the pods that need them prevents a compromised pod from reading other tenants' secrets. Together they address both the network and secret-access requirements directly.

Why this answer

Default-deny network policies enforce network segmentation between namespaces, and least-privilege service accounts with scoped secret mounts enforce secret isolation at the API level. The other options harden adjacent layers such as control-plane access, admission, or transport encryption without preventing the two specific cross-tenant actions described.

Exam trap

The trap here is treating transport encryption or audit logging as if it prevents unauthorized access, when only authorization and segmentation controls actually block the actions.

107
MCQeasy

An organization is implementing a PKI to issue certificates for internal applications. The security team wants to minimize the risk of compromise to the root CA. Which of the following is the BEST practice to protect the root CA?

A.Delegate root CA responsibilities to a public CA
B.Keep the root CA offline and store its private key in a hardware security module
C.Install the root CA on a VM with strict firewall rules
D.Use a self-signed certificate for the root CA and distribute it manually
AnswerB

An offline root CA, with its private key held in a hardware security module, is unreachable from the network, so compromise of issuing or web servers cannot expose it. This directly minimises the risk the security team wants to avoid.

Why this answer

Keeping the root CA offline and using a hardware security module (HSM) for key storage ensures its private key is never exposed to network threats. This is a standard best practice.

108
MCQmedium

A security engineer is configuring an internal certificate authority that must issue end-entity certificates to servers on a private network. Corporate policy requires that the CA's private key never reside on a network-connected host, and that certificate issuance be a deliberate, low-volume operation. Which of the following should the engineer implement to BEST meet these requirements?

A.Configure a cross-certified bridge CA that exchanges certificates with external partners using automated enrollment.
B.Configure an offline root CA that signs an online issuing subordinate CA, which in turn issues end-entity certificates.
C.Issue self-signed certificates directly to each server and distribute them to clients through a configuration management tool.
D.Deploy a single online root CA that issues all end-entity certificates and keeps its key in a network HSM.
AnswerB

An offline root CA keeps the trust anchor's private key on an isolated system that is powered on only to sign the subordinate CA certificate. The online issuing subordinate CA handles routine end-entity issuance, so compromise of the issuing CA does not expose the root key, and the root cannot be used remotely. This directly satisfies both the isolation and low-volume issuance requirements.

Why this answer

Keeping the root CA offline and delegating routine issuance to an online subordinate CA separates the trust anchor from day-to-day operations. The root key is only used to sign the subordinate CA certificate, so it can stay on an isolated host, while the subordinate handles end-entity certificates. This limits exposure and matches the policy of deliberate, low-volume root signing.

Exam trap

The trap here is assuming that placing the CA key in a hardware security module satisfies an offline-key requirement, when an online issuing CA still exposes the signing service over the network.

109
Multi-Selecthard

A security architect is designing a network segmentation strategy for a data center that hosts both web servers and database servers. The architect wants to ensure that if a web server is compromised, the attacker cannot directly access the database servers. The architect plans to implement microsegmentation using software-defined networking (SDN). Which TWO of the following are essential components to achieve this goal? (Choose two.)

Select 2 answers
A.A hypervisor-based firewall that inspects traffic between virtual machines.
B.A centralized policy controller that defines and enforces security group rules.
C.A next-generation firewall (NGFW) at the perimeter of the data center.
D.A network tap or SPAN port for traffic monitoring and analysis.
E.A hardware security module (HSM) to store encryption keys for VPN tunnels.
AnswersA, B

A hypervisor-based firewall enforces security policies at the virtual switch level, controlling traffic between VMs even on the same host. This is critical for microsegmentation because it prevents lateral movement within the virtualized environment. It ensures that a compromised web server VM cannot communicate with database VMs unless explicitly allowed, directly supporting the goal.

Why this answer

Microsegmentation with SDN requires a centralized policy controller to define and distribute security rules, and a hypervisor-based firewall to enforce those rules between virtual machines. Together, they enable granular, dynamic segmentation that prevents lateral movement. HSMs, network taps, and perimeter NGFWs serve other purposes and do not provide the necessary internal enforcement.

Exam trap

The trap here is assuming that perimeter security controls or monitoring tools can prevent lateral movement between internal servers.

110
MCQmedium

A company is implementing a privileged access management (PAM) solution to reduce the risk of standing privileges. Which feature allows users to request temporary elevated access for a specific task, which is automatically revoked after the task is completed?

A.Break-glass accounts
B.Password vaulting
C.Session recording
D.Just-in-time (JIT) access provisioning
AnswerD

Just-in-time access provisioning grants elevated permissions only for the duration of a specific task, then automatically revokes them. This directly eliminates standing privileges, satisfying the stem's requirement that access be temporary and self-expiring. Microsoft Entra ID Privileged Identity Management implements this through time-bound role activation, with approvals and expiry enforced automatically.

Why this answer

Just-in-time (JIT) access provisioning grants temporary privileges that expire after use, reducing standing privileges. Break-glass accounts are emergency accounts, not time-based.

111
Multi-Selectmedium

A security engineer is implementing network segmentation to isolate a PCI DSS environment from the corporate network. The engineer plans to use VLANs and a firewall. Which TWO of the following are essential to ensure that the segmentation is effective and compliant? (Choose two.)

Select 2 answers
A.Implement 802.1Q VLAN tagging on all switch ports that connect to the PCI environment and ensure that native VLANs are not used on trunk ports.
B.Use private VLANs (PVLANs) to isolate hosts within the PCI VLAN from each other.
C.Deploy a dedicated intrusion prevention system (IPS) on the PCI VLAN to monitor all traffic.
D.Enable dynamic ARP inspection (DAI) and DHCP snooping on all VLANs to prevent IP spoofing.
E.Configure the firewall to deny all traffic between the PCI VLAN and other VLANs by default, allowing only explicitly required flows.
AnswersA, E

Proper VLAN tagging and avoiding native VLANs on trunk ports prevent VLAN hopping attacks, where an attacker could send double-tagged frames to access another VLAN. This ensures that the segmentation at Layer 2 is robust and that traffic cannot inadvertently cross VLAN boundaries.

Why this answer

Effective network segmentation for PCI DSS requires both Layer 3 access control and Layer 2 isolation. A default-deny firewall rule between the PCI VLAN and other networks ensures that only necessary traffic is allowed. Proper VLAN tagging and avoiding native VLANs on trunk ports prevent VLAN hopping attacks that could bypass segmentation.

Together, these controls establish a strong boundary. Other measures like DAI, IPS, and PVLANs enhance security but are not essential for the segmentation itself.

Exam trap

The trap here is focusing on additional security controls like IPS or DAI as segmentation mechanisms, when the core requirements are firewall rule sets and VLAN configuration to prevent cross-VLAN traffic.

112
MCQeasy

A security administrator is configuring a Linux server that will host a public-facing web application. The administrator wants to ensure that the server's SSH service is protected against brute-force attacks by limiting the number of failed authentication attempts and blocking offending IP addresses. Which of the following should the administrator implement?

A.Install and configure Fail2ban to monitor SSH logs and update firewall rules.
B.Enable SELinux in enforcing mode.
C.Configure TCP wrappers to allow only specific IP addresses.
D.Change the SSH port from 22 to a non-standard port.
AnswerA

Fail2ban monitors log files for failed authentication attempts and dynamically updates firewall rules to block offending IP addresses. It can be configured to limit failed SSH attempts and ban IPs for a specified duration. This directly meets the requirement of protecting against brute-force attacks by blocking sources after multiple failures.

Why this answer

Fail2ban actively monitors SSH authentication logs and, upon detecting repeated failures, inserts firewall rules to block the offending IP addresses. This provides dynamic brute-force protection. The other options either offer static access control, process confinement, or obscurity, none of which dynamically respond to failed authentication attempts.

Exam trap

The trap here is assuming that changing the SSH port or using TCP wrappers provides brute-force protection, when only a tool like Fail2ban dynamically blocks IPs based on failed authentication attempts.

113
Multi-Selecthard

An incident response team discovers that an attacker was able to forge a certificate for a legitimate domain. Which TWO mechanisms should the team implement to detect and prevent such misissuance in the future? (Select TWO.)

Select 2 answers
A.Certificate Revocation Lists (CRLs)
B.Implementing Extended Validation (EV) certificates
C.Online Certificate Status Protocol (OCSP) stapling
D.Certificate Transparency (CT) logging and monitoring
E.Certificate pinning in client applications
AnswersD, E

Certificate Transparency publishes every issued certificate to append-only, cryptographically verifiable logs, letting the team detect unauthorised or forged certificates for their domains. Monitoring these logs satisfies the misissuance detection requirement by exposing certificates the legitimate CA never intended to issue.

Why this answer

Certificate Transparency (CT) logging and monitoring (D) is correct because CT requires CAs to submit every issued certificate to public, append-only logs, so the team can monitor these logs for unauthorized or forged certificates for their domains and detect misissuance quickly. Certificate pinning in client applications (E) is correct because it hardcodes or constrains the expected certificate/public key for a domain, so a forged certificate issued by a rogue or compromised CA will be rejected by the client, preventing its use even if it chains to a trusted root. CRLs (A) and OCSP stapling (C) only convey revocation status of certificates and cannot detect or prevent a newly forged certificate that has not yet been revoked, and EV certificates (B) merely assert a higher validation level without providing any detection or pinning mechanism against misissuance.

114
MCQmedium

An organization uses a TPM 2.0 for measured boot and attestation. Which TPM feature ensures that the boot process has not been tampered with by measuring each component before it executes?

A.Platform Configuration Registers (PCRs)
B.Endorsement Key (EK)
C.Secure boot
D.Sealed storage
AnswerA

PCRs hold cumulative hash measurements of each boot component, extending values sequentially so any tampering alters the final register state. This satisfies the measured boot requirement, letting attestation compare PCR values against known-good baselines to detect modification before execution.

Why this answer

Platform Configuration Registers (PCRs) store hash measurements of boot components. Any change in the boot sequence will result in different PCR values, alerting to tampering.

115
MCQeasy

An enterprise is deploying a multi-factor authentication (MFA) solution. The security team requires a factor that is resistant to phishing and does not rely on shared secrets. Which of the following MFA types BEST meets this requirement?

A.Biometric fingerprint scanner
B.SMS one-time passcodes
C.FIDO2/WebAuthn security keys
D.TOTP via authenticator app
AnswerC

FIDO2/WebAuthn security keys satisfy both constraints: cryptographic challenge–response using per-origin public/private key pairs, so no shared secret traverses the wire, and origin binding prevents credential replay on lookalike phishing domains. Microsoft Entra ID supports these keys as phishing-resistant authentication, unlike OTP or push methods.

Why this answer

FIDO2/WebAuthn uses public-key cryptography, with the private key stored on the device, and the protocol is designed to be phishing-resistant by binding credentials to the origin. TOTP/HOTP rely on shared secrets and are vulnerable to phishing. Hardware tokens like YubiKey can implement FIDO2.

Biometrics are a factor but not inherently phishing-resistant alone.

116
Multi-Selecthard

An organization is planning to deploy a new internal CA hierarchy. Which THREE considerations are critical for ensuring the security and manageability of the PKI?

Select 3 answers
A.Keep the root CA offline and only bring it online for cross-certification or disaster recovery.
B.Use a 4096-bit RSA key for the root CA and at least 2048-bit for issuing CAs.
C.Use SHA-1 for certificate signing to ensure compatibility with legacy systems.
D.Use a single-tier CA to simplify management.
E.Ensure all certificates include CRL distribution points and OCSP responder URLs.
AnswersA, B, E

Keeping the root CA offline means its private key is never exposed on a network-connected host, so compromise of subordinate systems cannot forge the trust anchor. It is brought online only for cross-certification or disaster recovery, preserving hierarchy integrity and manageability.

Why this answer

Option A is correct because keeping the root CA offline (air-gapped) protects the trust anchor's private key from compromise, bringing it online only for cross-certification or disaster recovery, which is a foundational PKI best practice. Option B is correct because using a 4096-bit RSA key for the long-lived root CA and at least 2048-bit keys for issuing CAs provides adequate cryptographic strength for the hierarchy's lifetime and resists brute-force attacks. Option E is correct because embedding CRL distribution points and OCSP responder URLs in certificates enables timely revocation checking, which is essential for security and manageability of the PKI.

Option C is incorrect because SHA-1 is deprecated and vulnerable to collision attacks; SHA-256 or stronger should be used. Option D is incorrect because a single-tier CA exposes the root to online issuance risks and reduces flexibility, whereas a multi-tier hierarchy with an offline root is more secure and manageable.

117
Multi-Selectmedium

A security engineer is implementing a zero trust architecture for a corporate network. The engineer must ensure that all access requests are continuously verified and that least privilege is enforced. Which TWO components are essential to achieve these goals? (Choose two.)

Select 2 answers
A.A VPN concentrator that provides encrypted tunnels for all remote access.
B.A next-generation firewall (NGFW) that inspects all traffic at the network perimeter.
C.A policy administrator that establishes and maintains the trust relationship between the subject and the resource.
D.A security information and event management (SIEM) system that aggregates logs for analysis.
E.A policy engine that evaluates access requests based on identity, device posture, and context.
AnswersC, E

The policy administrator is responsible for executing the decisions made by the policy engine. It configures the data plane to allow or deny connections, often by instructing gateways or agents. It is essential for enforcing least privilege because it dynamically provisions access based on the policy engine's verdict. Together with the policy engine, it forms the control plane.

Why this answer

Zero trust architecture relies on a policy engine to make dynamic access decisions based on context, and a policy administrator to enforce those decisions by configuring the data plane. These two components form the control plane and are essential for continuous verification and least privilege. Other options like VPN, NGFW, and SIEM are supporting technologies but not core to the zero trust access decision process.

Exam trap

The trap here is confusing network security devices like VPNs and firewalls with the core zero trust control plane components that actually enforce dynamic access decisions.

118
MCQeasy

A company is implementing a passwordless authentication solution using FIDO2/WebAuthn. What is the primary security advantage of this approach over traditional password-based authentication?

A.It allows users to share passwords securely.
B.It reduces server storage requirements.
C.It eliminates the need for multi-factor authentication.
D.It prevents phishing attacks by using cryptographic keys.
AnswerD

FIDO2/WebAuthn binds the credential's private key to the relying party's origin, so a phishing site on a different domain cannot invoke it. This origin-scoped cryptographic assertion removes the shared-secret replay weakness inherent in password-based authentication.

Why this answer

FIDO2/WebAuthn uses public-key cryptography where the private key never leaves the authenticator (e.g., a security key or platform authenticator), and the origin is cryptographically bound to the credential. This origin binding means a phishing site with a different domain cannot trigger the authenticator to sign the challenge, effectively preventing credential phishing. Traditional passwords, by contrast, can be captured and replayed by phishing proxies.

Exam trap

The trap is selecting 'eliminates the need for multi-factor authentication' because candidates conflate passwordless with single-factor; in reality, FIDO2 can be one factor and the core advantage tested is phishing resistance via cryptographic origin binding.

How to eliminate wrong answers

Option A is wrong because FIDO2/WebAuthn is designed to eliminate shared secrets entirely — there are no passwords to share, and the private key is non-exportable. Option B is wrong because while the server stores a public key instead of a password hash, the primary security advantage is phishing resistance, not storage reduction; server storage is a secondary benefit at best. Option C is wrong because FIDO2/WebAuthn can serve as one factor (possession) and may still be combined with a PIN or biometric for multi-factor authentication; it does not inherently eliminate the need for MFA in all contexts, and claiming so misrepresents the standard.

119
MCQmedium

A security architect is designing a data-at-rest protection scheme for a multi-tenant SaaS platform. The requirement is that each tenant's data be encrypted with a unique key, and that compromise of one tenant's key never exposes another tenant's data. The platform must support cryptographic erasure of a single tenant without re-encrypting the entire database. Which design BEST satisfies these requirements?

A.Encrypt all tenant data with a single database master key and rely on row-level access controls to isolate tenants.
B.Use a per-tenant data encryption key wrapped by a key encryption key, and destroy the wrapped data key to erase that tenant.
C.Encrypt each tenant's data with a key derived from the tenant identifier using PBKDF2, and rotate the derivation salt to erase the tenant.
D.Store each tenant's data in a separate database encrypted with a shared HSM-backed key, and delete rows to erase a tenant.
AnswerB

Envelope encryption with a unique data encryption key per tenant ensures that compromising one tenant's key reveals only that tenant's data. The key encryption key wraps each data key, so destroying a single wrapped data key renders that tenant's ciphertext permanently unrecoverable, achieving cryptographic erasure without touching other tenants or re-encrypting the database. This satisfies isolation, erasure, and operational efficiency requirements.

Why this answer

Envelope encryption with a unique wrapped data key per tenant provides both cryptographic isolation and efficient cryptographic erasure. Destroying a single wrapped data key makes that tenant's ciphertext unrecoverable while leaving the key encryption key and all other tenants untouched. This avoids full-database re-encryption and ensures that one key compromise cannot cascade across tenants.

Exam trap

The trap here is confusing logical access controls or physical database separation with cryptographic isolation, when only per-tenant keys wrapped under a higher-level key deliver both isolation and crypto-erasure.

120
MCQeasy

A security engineer is configuring a VPN between two sites and needs to ensure data confidentiality and integrity. Which IPsec mode and protocol combination should be used to encrypt the entire IP packet including the header?

A.Transport mode with ESP
B.Transport mode with AH
C.Tunnel mode with AH
D.Tunnel mode with ESP
AnswerD

Tunnel mode encapsulates the complete original IP packet, header included, inside a new IP packet, so the original addresses are hidden. ESP provides confidentiality and integrity for that payload. Transport mode would leave the original header exposed, failing the stated requirement.

Why this answer

IPsec tunnel mode with ESP encrypts and authenticates the entire IP packet, providing confidentiality and integrity. Transport mode only encrypts the payload, and AH provides integrity without encryption.

121
Multi-Selecteasy

An IoT device manufacturer wants to ensure the security of over-the-air (OTA) firmware updates. Which TWO measures are essential to protect the update process?

Select 2 answers
A.Sign the firmware with a trusted code signing certificate
B.Use a simple checksum for integrity verification
C.Implement a secure boot chain that verifies the signature before applying the update
D.Encrypt the firmware using a hardcoded key
E.Allow firmware downgrades to previous versions
AnswersA, C

Code signing binds the firmware to a trusted publisher's private key, so devices can verify authenticity and integrity before flashing. This directly satisfies the OTA constraint: preventing attackers from pushing tampered or malicious firmware images to fielded devices.

Why this answer

Option A is correct because signing the firmware with a trusted code signing certificate lets the device verify authenticity and integrity via the vendor's public key, ensuring the OTA image genuinely originates from the manufacturer and has not been tampered with. Option C is correct because a secure boot chain validates that signature against a hardware-rooted trust anchor before the update is applied, preventing malicious or corrupted firmware from ever executing. Together, signing plus signature verification in a secure boot chain form the essential cryptographic trust path for OTA updates.

Option B is not sufficient because a simple checksum detects only accidental corruption, not deliberate tampering, since it is not cryptographically bound to a secret or key. Option D is wrong because a hardcoded key can be extracted from the device and reused by attackers, and encryption alone does not prove authenticity. Option E is wrong because permitting downgrades enables rollback attacks that reintroduce known vulnerabilities.

122
MCQmedium

A security architect is designing a network for a financial services firm. The firm requires that all data in transit between its internal microservices be encrypted and mutually authenticated, but the services run in a containerized environment where static IP addresses are not available. Which of the following is the MOST appropriate solution to meet these requirements?

A.Deploy a service mesh with mutual TLS (mTLS) between sidecar proxies.
B.Implement IPsec tunnels between each container host.
C.Configure a VPN concentrator that all microservices connect to for encrypted communication.
D.Use TLS with server-side certificates only for each microservice.
AnswerA

A service mesh with mTLS provides encryption and mutual authentication for service-to-service communication. It uses sidecar proxies to manage certificates and identity without relying on static IPs, which suits containerized environments. This directly meets the requirements for encrypted, mutually authenticated traffic in a dynamic infrastructure.

Why this answer

A service mesh with mutual TLS (mTLS) provides encryption and mutual authentication for service-to-service communication. It uses sidecar proxies to manage certificates and identity without relying on static IPs, which suits containerized environments. This directly meets the requirements for encrypted, mutually authenticated traffic in a dynamic infrastructure.

Exam trap

The trap here is assuming that any encryption method (like IPsec or server-side TLS) is sufficient, but the requirement for mutual authentication and dynamic environments points specifically to mTLS in a service mesh.

123
MCQeasy

A security architect is designing a VPN that requires both authentication and encryption. Which IPsec protocol provides both services in a single protocol?

A.AH in transport mode
B.IKEv2
C.ESP in tunnel mode
D.AH in tunnel mode
AnswerC

ESP encrypts the payload and authenticates its origin and integrity, delivering confidentiality plus authentication in one protocol. Tunnel mode encapsulates the entire original packet, so the site-to-site VPN's demand for both services is met without adding AH alongside.

Why this answer

ESP provides both encryption and optional authentication, while AH only provides authentication without encryption.

124
Multi-Selecthard

During a penetration test, an assessor successfully exploits a timing side-channel attack to extract an ECDSA private key from a secure enclave. Which TWO mitigations should the development team implement to prevent such attacks? (Select TWO.)

Select 2 answers
A.Implement constant-time cryptographic operations
B.Add random delays to cryptographic operations
C.Disable debug interfaces on the secure enclave
D.Use blinding techniques for ECDSA signing
E.Replace ECDSA with Ed25519
AnswersA, D

Constant-time cryptographic operations eliminate the data-dependent execution timing that leaks ECDSA nonce and scalar information, directly satisfying the stem's timing side-channel constraint. By ensuring every operation takes identical duration regardless of secret values, the attacker gains no exploitable timing variance to correlate against the private key.

Why this answer

Option A is correct because constant-time cryptographic operations ensure that execution time and memory access patterns do not depend on secret data, which directly eliminates the timing side-channel that leaked the ECDSA private key from the enclave. Option D is correct because ECDSA signing blinding (e.g., randomizing the nonce k and/or the private key d with a random value before the scalar multiplication) decorrelates the timing of the modular exponentiation/scalar multiplication from the actual secret, so an attacker cannot recover the key even if timing varies. Option B is not appropriate because adding random delays only obfuscates timing and is statistically defeatable by averaging many traces; it is not a sound cryptographic countermeasure.

Option C does not belong because disabling debug interfaces addresses physical/JTAG-style access, not a timing side-channel observed through normal cryptographic execution. Option E does not belong because Ed25519 is also vulnerable to timing side-channels if implemented without constant-time code and blinding, so simply swapping algorithms does not fix the root cause.

125
Multi-Selectmedium

A company is implementing privileged access management (PAM) for its critical servers. Which THREE practices should be included to enhance security? (Select THREE.)

Select 3 answers
A.Record and monitor all privileged sessions
B.Implement just-in-time (JIT) access provisioning
C.Use break-glass accounts for emergency access
D.Enforce multi-factor authentication for all users
E.Require periodic password rotation for all service accounts
AnswersA, B, C

Session recording and monitoring create an auditable trail of every privileged action on critical servers, satisfying the PAM requirement for accountability and detecting misuse or insider threats in real time. This directly supports the scenario's goal of enhancing security for privileged access to critical infrastructure.

Why this answer

Option A is correct because recording and monitoring all privileged sessions provides an audit trail and enables real-time detection of malicious or anomalous activity by administrators, which is a core PAM control. Option B is correct because just-in-time (JIT) access provisioning grants elevated privileges only when needed and for a limited time, reducing the standing attack surface and the window for credential misuse. Option C is correct because break-glass accounts provide controlled emergency access when normal PAM workflows fail, and when properly vaulted, monitored, and alerted on, they preserve availability without creating unmanaged privileged access.

Option D is not the best fit because MFA for all users is a general identity control, not a PAM-specific practice for critical server privileged access. Option E is not correct because periodic password rotation for service accounts is a legacy practice that can weaken security and is not a core PAM enhancement compared to session monitoring, JIT access, and break-glass procedures.

Exam trap

CAS-005 often tests whether candidates can distinguish PAM-specific controls from general IAM hygiene — MFA and password rotation are commonly selected but are not the PAM practices the question targets.

126
MCQmedium

A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for known attack patterns. The administrator wants to ensure that the NIDS can detect a specific SQL injection attempt that uses a particular string. Which Snort rule action and option combination will BEST accomplish this?

A.alert udp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
B.alert tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
C.drop tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
D.alert tcp any any -> any 443 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
AnswerB

This rule triggers an alert when the string '1=1' is found in TCP traffic destined for port 80. The content option performs a simple pattern match, which is effective for detecting known SQL injection strings. The alert action logs the event, allowing the administrator to be notified of potential attacks.

Why this answer

The goal is to detect a SQL injection attempt containing a specific string. Snort rules with the alert action and a content match on TCP port 80 are appropriate for unencrypted HTTP traffic. Using drop would block traffic, which is not required.

UDP or port 443 would not match typical SQL injection traffic. Thus, the rule with alert, TCP, port 80, and content match is correct.

Exam trap

The trap here is confusing detection with prevention, or assuming that HTTPS traffic can be inspected without decryption.

127
MCQmedium

A security engineer is configuring a Linux server that hosts a web application. The engineer needs to ensure that the application runs with the least privilege necessary and that any compromise of the application is confined to a limited set of system resources. Which of the following should the engineer implement?

A.Running the web server as a non-root user without additional controls
B.SELinux in enforcing mode with a targeted policy for the web server
C.chroot jail for the web server process
D.AppArmor with a complain-mode profile for the web server
AnswerB

SELinux in enforcing mode applies mandatory access controls that confine the web server process to only the resources defined in its policy. This limits the impact of a compromise by preventing the process from accessing files or network ports outside its defined domain, thus achieving least privilege and confinement.

Why this answer

SELinux in enforcing mode enforces a mandatory access control policy that restricts the web server to only the resources it needs, such as specific files and network ports. This provides strong confinement and least privilege. The other options either do not enforce restrictions, provide only partial isolation, or rely on traditional permissions that are insufficient for limiting a compromised process.

Exam trap

The trap here is confusing logging or permissive modes with actual enforcement, or assuming that a chroot or non-root user provides complete isolation.

128
MCQeasy

A security administrator is configuring a RADIUS server for a wireless network. The administrator wants to ensure that the shared secret between the access point and the RADIUS server is protected against eavesdropping. Which protocol should be used to encapsulate RADIUS traffic?

A.RADIUS with MS-CHAPv2
B.RADIUS over TLS (RadSec)
C.RADIUS over UDP with IPsec transport mode
D.RADIUS with EAP-TTLS
AnswerB

RadSec encapsulates RADIUS in TLS, providing encryption and integrity for the shared secret and all authentication traffic. Standard RADIUS uses a shared secret to obfuscate passwords but does not encrypt the entire packet, leaving it vulnerable to eavesdropping. RadSec protects against this by securing the entire communication channel.

Why this answer

RadSec (RADIUS over TLS) is the standard protocol for securely encapsulating RADIUS traffic. It uses TLS to encrypt the entire RADIUS conversation, including the shared secret, protecting against eavesdropping. Other options either do not encrypt the RADIUS packet fully or are authentication methods that do not address the shared secret protection.

Exam trap

The trap here is confusing authentication protocols like EAP-TTLS with transport protection mechanisms for RADIUS itself, or assuming that IPsec is the only way to secure RADIUS.

129
MCQhard

A security architect is designing a microservices-based application deployed on a Kubernetes cluster. The architect must ensure that inter-service communication is encrypted, mutually authenticated, and that services can be authorized based on their identity. Which of the following should the architect implement to meet these requirements?

A.Use Kubernetes Secrets to store TLS certificates and manually configure each service to use them.
B.Implement an API gateway that terminates TLS and performs authentication for all inbound traffic.
C.Deploy a service mesh with mutual TLS (mTLS) and identity-based authorization policies.
D.Configure Kubernetes Network Policies to allow only specific pod-to-pod traffic.
AnswerC

A service mesh such as Istio or Linkerd provides transparent mTLS for all inter-service communication, encrypting traffic and authenticating both ends using service identities (e.g., SPIFFE IDs). It also enables fine-grained authorization policies based on those identities. This directly satisfies the requirements for encryption, mutual authentication, and identity-based authorization.

Why this answer

A service mesh with mTLS provides transparent encryption and mutual authentication for all service-to-service communication, using verifiable identities. Its authorization policies can enforce access based on those identities, which is essential for zero-trust microservices. The other options either lack encryption, mutual authentication, or are limited to external traffic, failing to secure east-west communication.

Exam trap

The trap here is confusing network segmentation or API gateways with service mesh capabilities; only a service mesh provides built-in mTLS and identity-based authorization for inter-service traffic.

130
MCQhard

A security architect is designing a system that requires secure key exchange over an untrusted network. The system must provide perfect forward secrecy (PFS) and must be resistant to quantum computer attacks. Which key exchange algorithm BEST meets these requirements?

A.RSA key exchange with 4096-bit keys
B.Diffie-Hellman Ephemeral (DHE) with 2048-bit parameters
C.Post-quantum key exchange using lattice-based cryptography (e.g., Kyber)
D.Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) with Curve25519
AnswerC

Lattice-based key exchange mechanisms like Kyber are designed to be resistant to quantum attacks while also supporting ephemeral key generation to provide perfect forward secrecy. Kyber is a NIST-standardized post-quantum algorithm, making it the best choice for this scenario that demands both PFS and quantum resistance.

Why this answer

The requirements are perfect forward secrecy and resistance to quantum attacks. Traditional key exchanges like RSA, DHE, and ECDHE provide PFS but are vulnerable to quantum computers. Lattice-based post-quantum algorithms such as Kyber are designed to withstand quantum attacks and can be used in ephemeral modes to achieve PFS, making them the only suitable option.

Exam trap

The trap here is assuming that any ephemeral Diffie-Hellman variant provides quantum resistance, when in fact all classical DH and ECC are quantum-vulnerable.

131
Multi-Selectmedium

An IoT device uses a Trusted Platform Module (TPM) 2.0 for secure boot and attestation. Which THREE of the following functions does the TPM provide to support these security features?

Select 3 answers
A.Accelerated symmetric encryption
B.Platform Configuration Registers (PCRs) for storing measurements
C.Hardware random number generation
D.Sealed storage that decrypts data only if PCR values match expected measurements
E.Remote attestation using TPM_Quote to sign PCR values
AnswersB, D, E

PCRs are shielded registers that hold cumulative hashes of firmware and software measurements taken during boot. Secure boot compares these values against expected ones, and attestation reports them, so PCRs provide the measurement storage underpinning both features.

Why this answer

Option B is correct because TPM 2.0 provides Platform Configuration Registers (PCRs), which are shielded registers used to store cryptographic measurements (hashes) of firmware, boot loaders, and OS components during secure boot, forming the basis for integrity verification. Option D is correct because sealed storage binds a decryption key to specific PCR values, so the protected data can only be unsealed when the platform's measurements match the expected known-good state, enforcing secure boot integrity. Option E is correct because remote attestation relies on the TPM_Quote command, which signs the current PCR values with an Attestation Identity Key (AIK) so a remote verifier can confirm the device's boot state.

Option A is not correct because TPM 2.0 is not designed for accelerated bulk symmetric encryption; it only offers limited cryptographic operations and is far too slow for that purpose. Option C is not correct because, although TPM 2.0 includes a hardware random number generator, it is not one of the functions specifically supporting secure boot and attestation as described in this scenario.

132
MCQmedium

A security architect is designing a new authentication system for a cloud-based application that requires strong multi-factor authentication. The solution must be resistant to phishing attacks and not rely on shared secrets. Which of the following is the BEST choice?

A.HOTP with a hardware token
B.FIDO2/WebAuthn
C.TOTP via a mobile authenticator app
D.SMS one-time passcodes
AnswerB

FIDO2/WebAuthn satisfies both constraints by using public-key cryptography: the authenticator holds a private key, while the server stores only the public key, so no shared secret crosses the wire. Origin binding ties each credential to the legitimate domain, defeating phishing proxies that replay credentials against lookalike sites.

Why this answer

FIDO2/WebAuthn is a passwordless authentication protocol that uses public key cryptography and is resistant to phishing because the private key never leaves the user's device.

133
Multi-Selecthard

A security architect is designing a zero trust architecture for a hybrid workforce that accesses internal applications from managed and unmanaged devices. The architect wants to enforce continuous verification of device and user trust for every session. Which TWO controls are essential to meet this goal? (Choose two.)

Select 2 answers
A.Require all traffic to traverse a traditional perimeter firewall with static rules based on internal IP subnets.
B.Issue long-lived VPN credentials so users authenticate once and retain access for the duration of the workday.
C.Segment the internal network into VLANs and rely on switch ACLs to isolate application tiers.
D.Enforce identity-aware access proxies that mediate every session and apply the policy decision to each request.
E.Deploy a policy decision point that evaluates device posture, user identity, and contextual signals on each access request.
AnswersD, E

Policy decisions only matter if they are enforced inline. Identity-aware proxies act as policy enforcement points that terminate sessions and apply the decision point's verdict per request, which is how continuous verification becomes effective. They also hide application endpoints so that access cannot bypass the control path, supporting the zero trust principle of never trusting the network.

Why this answer

Continuous verification in zero trust depends on two functions working together: a policy decision point that evaluates identity, device posture, and context on every request, and identity-aware enforcement points that mediate sessions and apply those decisions inline. Together they replace implicit network trust with per-request authorization; perimeter rules, long-lived VPN sessions, and VLAN segmentation do not evaluate trust dynamically.

Exam trap

The trap here is assuming that network segmentation or a perimeter firewall constitutes zero trust, when those controls grant implicit trust based on network location rather than per-request evaluation.

134
MCQmedium

A company is deploying IoT sensors in a harsh environment. The sensors have limited processing power and memory. Which of the following cryptographic algorithms is most suitable for ensuring data confidentiality with minimal overhead?

A.RSA-4096
B.ChaCha20-Poly1305
C.SHA-256
D.AES-256-GCM
AnswerB

ChaCha20-Poly1305 is a stream cipher with AEAD that runs efficiently in software without AES hardware acceleration, suiting constrained IoT processors. Its low memory footprint and fast performance deliver confidentiality and integrity with minimal overhead in harsh environments.

Why this answer

ChaCha20-Poly1305 is a stream cipher that is fast in software, especially on devices without AES hardware acceleration, and provides authenticated encryption with low overhead.

135
MCQeasy

Which of the following certificate types is most appropriate for an organization that needs to validate the identity of individuals for email encryption and signing?

A.S/MIME certificate
B.Domain Validation (DV) certificate
C.Client authentication certificate
D.Code signing certificate
AnswerA

S/MIME certificates bind an individual's verified identity to a public key, enabling message signing and encryption within mail clients. This validates the sender's identity for email, precisely matching the stated requirement for individual identity validation.

Why this answer

S/MIME certificates are specifically designed for securing email. Client certificates are for authentication. Code signing is for software.

DV certificates are for websites.

136
MCQhard

A security engineer is implementing a secure boot process for a Linux server. The requirement is to ensure that only signed and trusted kernel modules can be loaded, preventing rootkits from persisting. Which mechanism should the engineer enable?

A.Integrity Measurement Architecture (IMA) with appraisal.
B.UEFI Secure Boot with a custom key enrollment.
C.Linux Security Modules (LSM) with SELinux in enforcing mode.
D.Kernel module signing enforcement (module.sig_enforce=1).
AnswerD

Enabling kernel module signing enforcement ensures that the kernel will only load modules that are signed with a trusted key. This prevents unsigned or malicious modules from being loaded, even by root, thus blocking rootkits that rely on kernel modules. This directly satisfies the requirement to allow only signed and trusted kernel modules.

Why this answer

Kernel module signing enforcement is the specific mechanism that requires all kernel modules to be signed with a trusted key before they can be loaded. When enabled via the module.sig_enforce=1 kernel parameter, the kernel rejects any module without a valid signature. This prevents rootkits that use kernel modules from persisting, as they cannot be loaded.

UEFI Secure Boot, SELinux, and IMA provide related but distinct protections that do not directly enforce module signing at load time.

Exam trap

The trap here is conflating Secure Boot with kernel module signing; Secure Boot only validates the boot chain, not modules loaded later, so it does not prevent unsigned module loading.

137
MCQeasy

A security administrator is configuring a wireless network for a small office. The requirement is to use the strongest available encryption and authentication method that is supported by modern devices and does not require a separate authentication server. Which of the following should the administrator choose?

A.WPA2-Enterprise with PEAP-MSCHAPv2
B.WEP with 128-bit key
C.WPA3-Personal with SAE
D.WPA2-Personal with AES-CCMP
AnswerC

WPA3-Personal with SAE (Simultaneous Authentication of Equals) is the strongest available method for a pre-shared key network. SAE replaces the WPA2 four-way handshake with a Dragonfly handshake that provides forward secrecy and protects against offline dictionary attacks. It does not require an authentication server and is supported by modern devices. This meets all requirements: strongest encryption/authentication and no separate server.

Why this answer

WPA3-Personal with SAE is the most secure method for a pre-shared key network. It provides forward secrecy and resists offline dictionary attacks, which are weaknesses in WPA2-Personal. It does not require a RADIUS server, satisfying the constraint.

WPA2-Enterprise requires a server, WEP is obsolete, and WPA2-Personal is weaker than WPA3-Personal. Therefore, WPA3-Personal is the correct choice.

Exam trap

The trap here is assuming that WPA2-Enterprise is always stronger than Personal modes, but it requires an authentication server, which the scenario explicitly rules out.

138
Multi-Selectmedium

An organization is setting up a PKI with a three-tier hierarchy (root CA, issuing CA, and registration authority). Which TWO of the following are best practices for securing the root CA?

Select 2 answers
A.Allow the root CA to be accessible over the network for certificate requests
B.Enable CRL distribution points on the root CA
C.Use the root CA to issue end-entity certificates directly
D.Keep the root CA offline and physically secured
E.Store the root CA private key in an HSM
AnswersD, E

Taking the root CA offline and physically securing it prevents network-based compromise and unauthorised access to the trust anchor. This satisfies the three-tier hierarchy requirement by isolating the root from the issuing CA and registration authority, so its private key is only used for signing subordinate CAs.

Why this answer

Option D is correct because the root CA should be kept offline and physically secured so its private key is never exposed to network-based attacks; it is only brought online for rare operations such as signing the issuing CA's certificate. Option E is correct because storing the root CA private key in a hardware security module (HSM) protects it with tamper-resistant hardware, enforces key non-exportability, and supports secure cryptographic operations. Option A is wrong because exposing the root CA to the network for certificate requests increases its attack surface and violates the offline-root best practice.

Option B is wrong because CRL distribution points belong on the issuing CA (and end-entity certificates), not on the offline root CA. Option C is wrong because end-entity certificates should be issued by the issuing CA, not directly by the root CA, to preserve the hierarchy and limit root key exposure.

139
MCQmedium

A security architect is designing a secure boot process for a new line of embedded devices. The boot ROM loads the bootloader, which then loads the OS kernel. To ensure that only signed code is executed, which mechanism should the bootloader use to verify the kernel?

A.Decrypt the kernel using a symmetric key stored in the boot ROM
B.Verify a digital signature on the kernel using a public key stored in the boot ROM
C.Check that the kernel file size matches the expected value
D.Compare the kernel hash against a list of known good hashes stored in the bootloader
AnswerB

The boot ROM's stored public key forms an immutable root of trust, so the bootloader verifies the kernel's digital signature before transferring control. This chains trust from ROM to kernel, enforcing the requirement that only signed code executes on the embedded device.

Why this answer

The bootloader should verify a digital signature on the kernel image using a public key embedded in the boot ROM or bootloader. This ensures both integrity and authenticity of the kernel.

140
MCQmedium

An organization is moving to a passwordless authentication approach. They require a solution that supports hardware-based cryptographic authentication and is resistant to phishing. Which standard should they implement?

A.TOTP (Time-based One-Time Password)
B.SMS-based one-time codes
C.FIDO2/WebAuthn
D.Password manager with autofill
AnswerC

FIDO2/WebAuthn binds credentials to the origin via public-key cryptography, so a phishing site on a lookalike domain cannot replay the assertion. Hardware authenticators such as security keys store the private key in tamper-resistant silicon, never exposing it. This satisfies the stem's twin constraints: hardware-based cryptographic authentication and phishing resistance.

Why this answer

FIDO2/WebAuthn uses public-key cryptography and hardware authenticators to provide phishing-resistant, passwordless authentication. TOTP is not passwordless and can be phished.

141
MCQhard

A security engineer is implementing an integrity-monitoring solution for a fleet of Linux servers that must detect unauthorized changes to critical binaries and configuration files. The solution must provide a cryptographic baseline, resist tampering by an attacker with root privileges, and support automated verification. Which approach BEST meets these requirements?

A.Deploy a file integrity monitoring agent that stores SHA-256 baselines in a remote, append-only repository and alerts on deviations
B.Schedule a nightly script that computes MD5 hashes of files under /etc and /usr/bin and emails the output to the security team
C.Enable the Linux auditd subsystem to log all file writes and review the audit log manually each week
D.Configure SELinux in enforcing mode with a strict policy that prevents writes to system directories
AnswerA

A file integrity monitoring agent using SHA-256 provides a strong cryptographic baseline, and storing it in a remote, append-only repository prevents a local root attacker from silently rewriting the reference data. Automated comparison against that trusted baseline detects unauthorized changes and generates alerts. This combination satisfies the cryptographic, tamper-resistance, and automation requirements.

Why this answer

The strongest approach combines a cryptographic baseline using SHA-256, remote append-only storage of that baseline to resist tampering by a local root attacker, and automated deviation alerting. MD5 is collision-prone, auditd logs lack baseline comparison and automation, and SELinux is preventive rather than detective. Only the agent with remote append-only baseline storage meets all three requirements.

Exam trap

The trap here is equating preventive controls such as SELinux or audit logging with integrity monitoring, when the requirement is cryptographic baseline comparison against tamper-resistant storage.

142
MCQhard

A security engineer is designing a system that must enforce mandatory access control (MAC) based on security labels. The system must ensure that users cannot read data above their clearance level and cannot write data to lower classification levels. Which security model BEST fits these requirements?

A.Bell-LaPadula model
B.Clark-Wilson model
C.Brewer-Nash model
D.Biba model
AnswerA

The Bell-LaPadula model enforces confidentiality through the no-read-up and no-write-down properties. The no-read-up rule prevents subjects from reading objects at a higher classification, and the no-write-down rule prevents writing to lower classifications. This directly matches the requirement to restrict reading above clearance and writing to lower levels.

Why this answer

The requirements describe the classic confidentiality model: prevent reading above clearance (no-read-up) and prevent writing to lower levels (no-write-down). The Bell-LaPadula model explicitly defines these properties. Biba is for integrity, Clark-Wilson for integrity transactions, and Brewer-Nash for conflict of interest.

Thus, Bell-LaPadula is the correct choice.

Exam trap

The trap here is mixing up confidentiality and integrity models, especially Bell-LaPadula and Biba, which have opposite rules.

143
MCQhard

A security architect must protect a hardware security module's firmware against an attacker who has physical access and can measure power consumption and electromagnetic emissions during signature operations. The architect wants a countermeasure that makes the secret key statistically uncorrelated with the observable side-channel leakage. Which approach BEST meets this goal?

A.Implement constant-time modular exponentiation with blinding of the base and exponent
B.Rate-limit signature operations to ten per second and log each attempt
C.Enable secure boot with a signed firmware image verified by an on-die ROM
D.Store the private key in encrypted form using an AES key derived from a PIN
AnswerA

Constant-time execution removes data-dependent branches and memory-access timing, while base blinding randomizes the operand and exponent blinding randomizes the private exponent value used in each operation. Together they decorrelate the power and EM traces from the actual secret key, directly defeating statistical side-channel analysis even when the attacker can physically measure the device.

Why this answer

Base and exponent blinding combined with constant-time arithmetic randomize the intermediate values on which the leakage depends, so power and EM traces no longer correlate with the secret exponent. Secure boot, at-rest encryption, and rate limiting all leave the runtime arithmetic unchanged and therefore do not stop differential power analysis by an attacker with physical measurement access.

Exam trap

The trap here is assuming that protecting the key's storage or the integrity of the firmware also hides the key's runtime leakage from physical measurement.

144
MCQhard

A security engineer is implementing secure boot for an embedded Linux device that uses U-Boot. The requirement is to ensure that only authenticated firmware can execute, and that the root of trust is immutable. Which of the following should the engineer implement?

A.Verified boot using a public key stored in one-time programmable (OTP) fuses to verify the bootloader signature.
B.Measured boot using a TPM to record hashes of each boot stage.
C.Encrypted boot using AES-256 to encrypt the kernel and root filesystem.
D.Secure boot using a symmetric key stored in the bootloader environment.
AnswerA

Storing the public key in OTP fuses creates an immutable root of trust that cannot be altered without physical tampering. The bootloader verifies its own signature or the next stage's signature using this key, establishing a chain of trust. This ensures that only firmware signed with the corresponding private key can execute, meeting the requirements for authentication and immutability. It is a standard approach for secure boot in embedded systems.

Why this answer

To ensure only authenticated firmware executes with an immutable root of trust, the engineer should use verified boot with a public key stored in OTP fuses. The fuses cannot be changed after programming, providing immutability. The bootloader uses the public key to verify signatures on subsequent stages, creating a chain of trust.

Encryption and measured boot do not enforce authentication, and symmetric keys in mutable storage are insecure.

Exam trap

The trap here is confusing measured boot with verified boot; measured boot only records measurements for attestation, while verified boot actually enforces signature checks and halts on failure.

145
MCQeasy

A security administrator is troubleshooting a web application that intermittently rejects valid user sessions. Logs show the application server's clock drifted several minutes behind the authentication service, and the tokens carry short validity windows with issued-at and expiry claims. Which action MOST directly resolves the intermittent rejections?

A.Increase the token validity window from five minutes to several hours so clock differences no longer matter.
B.Disable expiry claim validation on the application server so tokens are trusted until the session store marks them invalid.
C.Configure the application server and authentication service to synchronize their clocks with the same trusted NTP time sources.
D.Shorten the token validity window further so that affected tokens expire quickly and users reauthenticate more often.
AnswerC

Token validation compares the issued-at and expiry claims against the validator's own clock, so a multi-minute skew causes tokens that are genuinely valid to appear not-yet-valid or expired. Pointing both systems at the same authenticated NTP hierarchy removes the skew at its source and restores consistent validation without weakening token lifetimes.

Why this answer

Time-based token claims are only meaningful when the issuer and validator share a common time reference. Synchronizing both systems to the same authenticated NTP sources eliminates the skew that causes valid tokens to be judged expired or not yet valid, fixing the rejections without loosening token lifetimes or removing expiry enforcement.

Exam trap

The trap here is reaching for token lifetime or validation changes to stop the errors instead of correcting the clock skew that makes correct validation fail.

146
MCQmedium

A security analyst is reviewing TLS 1.3 configuration for a web server. The analyst wants to ensure that the configuration provides forward secrecy and prevents the reuse of session keys. Which of the following is a characteristic of TLS 1.3 that supports these goals?

A.0-RTT session resumption
B.Support for static RSA key exchange
C.Use of ephemeral Diffie-Hellman key exchange
D.Removal of CBC mode cipher suites
AnswerC

Ephemeral Diffie-Hellman generates a unique key pair per session, then discards it, so compromising the server's long-term private key cannot decrypt past traffic — satisfying the forward secrecy requirement. Because each handshake derives fresh session keys, reuse across sessions is impossible, meeting the stem's second constraint.

Why this answer

TLS 1.3 mandates the use of ephemeral Diffie-Hellman key exchange (DHE or ECDHE) for all handshakes, which provides forward secrecy by generating a unique session key for each session that cannot be derived from the server's long-term private key. This ensures that even if the server's private key is compromised later, past session keys remain secure and cannot be reused.

Exam trap

CAS-005 often tests the misconception that 0-RTT or static RSA provide forward secrecy, when in fact TLS 1.3's ephemeral Diffie-Hellman is the key mechanism for forward secrecy.

How to eliminate wrong answers

Option A is wrong because 0-RTT session resumption allows a client to send data in the first flight using a previously established pre-shared key, which can be vulnerable to replay attacks and does not provide forward secrecy for the resumed session. Option B is wrong because static RSA key exchange does not provide forward secrecy; it was removed in TLS 1.3 precisely for this reason. Option D is wrong because while TLS 1.3 does remove CBC mode cipher suites, that removal is about eliminating weaknesses like padding oracle attacks, not directly about forward secrecy or session key reuse.

147
MCQmedium

A security analyst is reviewing the configuration of a web application firewall (WAF) protecting an e-commerce site. The analyst notices that the WAF is in detection-only mode. The site has been experiencing SQL injection attacks that are not being blocked. Which of the following actions should the analyst take to BEST protect the site while minimizing false positives?

A.Switch the WAF to blocking mode immediately.
B.Review the WAF logs, create custom rules to address the SQL injection patterns, and then switch to blocking mode.
C.Disable the WAF and rely on input validation in the application code.
D.Configure the WAF to block only requests from known malicious IP addresses.
AnswerB

Reviewing logs allows the analyst to understand the attack patterns and identify false positives. Creating custom rules tailors the WAF to the specific application, reducing false positives. Switching to blocking mode after tuning ensures that legitimate traffic is not disrupted while attacks are blocked.

Why this answer

Reviewing logs allows the analyst to understand the attack patterns and identify false positives. Creating custom rules tailors the WAF to the specific application, reducing false positives. Switching to blocking mode after tuning ensures that legitimate traffic is not disrupted while attacks are blocked.

Exam trap

The trap here is thinking that simply enabling blocking mode will solve the problem, but without tuning, it can cause more harm than good.

← PreviousPage 2 of 2 · 147 questions total

Ready to test yourself?

Try a timed practice session using only Casp Engineering Crypto questions.