Courseiva

CCNA Casp Security Architecture Questions

75 of 188 questions · Page 1/3 · Casp Security Architecture topic · Answers revealed

1
MCQhard

A security architect for a financial services firm is designing a new data protection scheme for account numbers stored in a PostgreSQL database. The business requires that the same account number always transforms to the same ciphertext so that existing equality-based lookups and unique constraints continue to work, while the raw values must remain unreadable to database administrators. Which cryptographic approach should the architect select?

A.SHA-256 hashing of the account number with a per-row salt
B.Deterministic encryption using AES-SIV
C.RSA-4096 OAEP encryption of each account number
D.AES-256-GCM with a random 96-bit nonce per record
AnswerB

AES-SIV is a misuse-resistant AEAD mode that produces a deterministic ciphertext for a given plaintext and associated data, so identical account numbers map to identical ciphertext. This preserves equality searches, joins, and unique indexes while keeping values unreadable to DBAs who lack the key, satisfying the stated business requirement.

Why this answer

The requirement for repeatable ciphertext that still supports equality lookups points to a deterministic authenticated encryption mode. AES-SIV derives its nonce from the plaintext and associated data, so the same input always yields the same output while still providing integrity. Randomized modes and salted hashing break the equality-search property the database design depends on.

Exam trap

The trap here is assuming that any authenticated encryption mode preserves equality lookups, when in fact only deterministic modes do so.

2
MCQmedium

An organization is implementing a Secure Access Service Edge (SASE) architecture to support remote workers. Which key capability does SASE provide that traditional VPNs lack?

A.Software-defined WAN (SD-WAN) functionality
B.Network-layer encryption using IPsec
C.Identity-based access with zero trust principles
D.Web content filtering and DLP
AnswerC

SASE couples identity-based, zero trust access with cloud-delivered security inspection, evaluating each session against user identity and device posture rather than granting broad network reach. Traditional VPNs authenticate once and then place the user on the network, which is the gap the stem highlights.

Why this answer

SASE converges networking and security functions into a cloud-delivered service, with zero trust network access (ZTNA) as a core pillar. Unlike traditional VPNs that grant broad network-level access after authentication, SASE enforces identity-based, context-aware access policies per application or resource. This aligns with zero trust principles: never trust, always verify, and least-privilege access.

Exam trap

The trap here is confusing SASE with traditional security or networking features that are components but not the key differentiator; candidates often pick SD-WAN or encryption because they are familiar, missing the zero trust identity-based access emphasis.

How to eliminate wrong answers

Option A is wrong because SD-WAN is a networking capability often integrated into SASE but not unique to it; traditional VPNs can coexist with SD-WAN. Option B is wrong because IPsec network-layer encryption is a standard VPN feature, not a SASE differentiator. Option D is wrong because web content filtering and DLP are security services that can be provided by standalone secure web gateways, not exclusive to SASE.

3
Multi-Selectmedium

A security architect is designing a microsegmentation strategy for a data center hosting legacy and modern applications. The architect must ensure that workloads can only communicate with explicitly authorized peers and that policy follows the workload even if it is migrated between hosts. Which two of the following controls best meet these requirements? (Choose two.)

Select 2 answers
A.VLAN segmentation with ACLs applied at the core switch.
B.A next-generation firewall with a single perimeter zone for all internal servers.
C.Host-based firewall agents that enforce allow-list rules based on workload identity tags.
D.A software-defined networking overlay that enforces policy based on workload labels.
E.802.1X port-based network access control for all server NICs.
AnswersC, D

Host-based firewall agents enforce policy at the workload level and can use identity tags rather than IP addresses, so rules remain valid when the workload moves between hosts. This satisfies both explicit peer authorization and policy portability, making it a core microsegmentation control.

Why this answer

Microsegmentation requires policy that is based on workload identity and portable across hosts. Host-based firewall agents with identity-tag rules and an SDN overlay enforcing label-based policy both deliver explicit peer authorization and follow workloads during migration. VLAN ACLs, a single perimeter zone, and 802.1X either tie policy to topology or address admission rather than ongoing east-west control.

Exam trap

The trap here is equating VLAN segmentation with microsegmentation, when VLANs tie policy to network location and do not follow a workload that migrates.

4
MCQhard

A security architect is evaluating a third-party SaaS provider for a critical business function. The provider will process sensitive customer data and must demonstrate compliance with the organization's security requirements. The architect needs to obtain assurance about the provider's security controls without conducting an on-site audit. Which of the following should the architect request?

A.Self-attestation questionnaire completed by the provider
B.SOC 2 Type II report
C.SOC 2 Type I report
D.Penetration test summary from the provider
AnswerB

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls over a period of time, covering security, availability, and confidentiality. It gives assurance without an on-site audit and is specifically designed for service providers handling sensitive data.

Why this answer

A SOC 2 Type II report provides independent validation of control effectiveness over a period, directly addressing the need for assurance without an on-site audit. It is the standard mechanism for assessing SaaS providers' security and compliance posture.

Exam trap

The trap here is accepting a SOC 2 Type I report or self-attestation as equivalent to a Type II report, which covers operating effectiveness over time.

5
MCQhard

A security architect is designing a network for a hospital that must keep its electronic health record (EHR) servers completely isolated from the internet while still allowing a small group of vendors to perform remote maintenance. The vendors use laptops that are not managed by the hospital. The architect proposes a jump host architecture. Which of the following designs best satisfies the requirement while minimizing risk?

A.Publish the EHR servers through a reverse proxy with client certificate authentication, and let vendors connect directly to the EHR web interface without a jump host.
B.Deploy a hardened jump host in a screened subnet, require vendor laptops to connect through a VPN with MFA, and then RDP to the EHR servers from the jump host after session recording is enabled.
C.Deploy a jump host directly on the same VLAN as the EHR servers, allow vendors to connect to it over RDP from the internet after authenticating with a local account, and disable session logging to protect vendor privacy.
D.Create a site-to-site IPsec tunnel from each vendor's office to the EHR VLAN, and allow the vendors to use their own remote administration tools directly against the EHR servers.
AnswerB

This design places the jump host in a screened subnet so it is reachable from the internet, but the EHR servers remain on an isolated internal segment. Requiring VPN with MFA authenticates the unmanaged vendor laptops, and RDP from the jump host provides a controlled, recorded session. Session recording gives the hospital an audit trail of every vendor action, which is essential for compliance and incident response.

Why this answer

The correct design uses a jump host in a screened subnet, VPN with MFA, and RDP with session recording. This combination isolates the EHR servers, authenticates the unmanaged vendor laptops, and provides an auditable path for maintenance. The other options either place the jump host on the protected VLAN, expose RDP directly, or use a reverse proxy that does not support direct server maintenance, all of which weaken isolation or control.

Exam trap

The trap here is assuming that any remote access method, such as a VPN or reverse proxy, provides the same isolation and auditability as a properly placed jump host with session recording.

6
MCQmedium

A security engineer is designing a secure hybrid cloud connection between an on-premises data center and AWS. Which service provides a dedicated, private network connection that bypasses the public internet?

A.Site-to-Site VPN
B.Transit Gateway
C.Direct Connect
D.VPC Peering
AnswerC

AWS Direct Connect provisions a dedicated 1 Gbps or 10 Gbps fibre cross-connect from your on-premises data centre to an AWS Direct Connect location, carrying traffic over private circuits rather than the public internet. This satisfies the stem's requirement for a private connection that bypasses internet routing entirely, unlike site-to-site VPN, which still traverses the public internet.

Why this answer

AWS Direct Connect provides a dedicated, private physical network connection from an on-premises data center to AWS, bypassing the public internet entirely. It is provisioned through a Direct Connect location or partner and offers consistent latency and higher bandwidth than internet-based options. This is the only option that guarantees a private, non-internet path by design.

Exam trap

The trap is assuming Site-to-Site VPN is 'private' because it is encrypted — candidates forget that IPsec VPN still traverses the public internet, whereas Direct Connect is the only option that physically bypasses it.

How to eliminate wrong answers

Option A is wrong because Site-to-Site VPN tunnels run over the public internet (IPsec over the internet), so they do not bypass it, even though traffic is encrypted. Option B is wrong because Transit Gateway is a regional hub for connecting VPCs, VPNs, and Direct Connect attachments — it is a routing construct, not a private circuit to on-premises. Option D is wrong because VPC Peering connects two VPCs within AWS (or across regions) and has nothing to do with on-premises connectivity.

7
MCQhard

A security architect is designing a system that must detect tampering with archived audit logs even if an attacker later gains administrative access to the log storage. The logs must remain verifiable for seven years without exposing their contents to the storage provider. Which design BEST meets these requirements?

A.Encrypt each log file with a symmetric key stored alongside the files and rely on file permissions to prevent modification.
B.Upload plaintext logs to object storage with versioning enabled and enable a write-once retention lock on the bucket.
C.Replicate logs to a second region and compare file checksums between regions during quarterly audits.
D.Compute a hash chain over log entries, sign each checkpoint with a private key held in an offline hardware security module, and encrypt logs with keys the provider cannot access.
AnswerD

A hash chain makes any alteration detectable because it breaks subsequent links, while offline hardware security module signing prevents an attacker with storage access from forging new checkpoints. Encrypting with keys unavailable to the provider keeps contents confidential, satisfying all stated requirements simultaneously.

Why this answer

Tamper-evident archival requires cryptographic binding of entries plus signatures produced with a key the attacker cannot reach, combined with encryption whose keys the storage provider does not hold. Hash chains detect alteration, offline hardware security module signing prevents forgery of new checkpoints, and provider-inaccessible keys preserve confidentiality across the retention period.

Exam trap

The trap here is assuming immutability features such as object locks or versioning provide tamper evidence, when they only restrict deletion and overwrite.

8
MCQmedium

A security architect is designing a cryptographic system for a government agency that must protect classified data for the next 30 years. The agency is concerned about the threat from quantum computers. Which NIST post-quantum cryptography algorithm is recommended for key encapsulation?

A.ECDH with NIST P-384
B.CRYSTALS-Kyber
C.CRYSTALS-Dilithium
D.RSA-4096
AnswerB

CRYSTALS-Kyber is a lattice-based key encapsulation mechanism selected by NIST for post-quantum standardisation, resisting attacks from both classical and quantum computers. Its Module-LWE hardness underpins the 30-year confidentiality requirement, unlike RSA or ECC, which Shor's algorithm breaks.

Why this answer

CRYSTALS-Kyber is the NIST-selected post-quantum algorithm for key encapsulation (KEM), standardized as FIPS 203 (ML-KEM). It is designed to resist attacks from both classical and quantum computers, making it appropriate for long-lived classified data. CRYSTALS-Dilithium is for digital signatures, not key encapsulation, and the classical algorithms (ECDH, RSA) are vulnerable to Shor's algorithm on a sufficiently powerful quantum computer.

Exam trap

The trap is mixing up the two CRYSTALS algorithms — candidates see 'CRYSTALS' and pick Dilithium, forgetting that Kyber is the KEM and Dilithium is the signature scheme.

How to eliminate wrong answers

Option A is wrong because ECDH with P-384 is a classical elliptic-curve key agreement scheme and is broken by Shor's algorithm on a quantum computer — it offers no post-quantum protection. Option C is wrong because CRYSTALS-Dilithium is NIST's selected post-quantum digital signature algorithm (FIPS 204, ML-DSA), not a key encapsulation mechanism. Option D is wrong because RSA-4096 is a classical public-key algorithm also vulnerable to Shor's algorithm; increasing key size does not defend against quantum attacks.

9
MCQhard

A financial services company is designing a secure multi-tenant SaaS application hosted on AWS. The security architect must ensure that each tenant's data is isolated and that encryption keys are unique per tenant, while allowing the company to manage keys centrally. Which AWS service should the architect use to meet these requirements?

A.AWS Certificate Manager (ACM) with a wildcard certificate per tenant.
B.AWS CloudHSM with a single cluster shared across all tenants.
C.AWS Key Management Service (KMS) with customer managed keys (CMKs) and encryption context per tenant.
D.AWS Secrets Manager with automatic rotation for each tenant's database credentials.
AnswerC

AWS KMS customer managed keys allow the company to create and manage unique keys per tenant, and encryption context can enforce tenant-specific authorization. This provides centralized key management with per-tenant cryptographic isolation, meeting the requirement for unique encryption keys and central control.

Why this answer

AWS KMS with customer managed keys allows the architect to create a unique key for each tenant and use encryption context to enforce that only the intended tenant can decrypt its data. This centralizes key management while providing cryptographic isolation, satisfying both the per-tenant key requirement and the need for central administration.

Exam trap

The trap here is confusing data-in-transit certificate management or secret storage with encryption key management for data at rest, which requires a dedicated key management service such as KMS.

10
MCQmedium

A security architect is designing a public key infrastructure (PKI). Which component is responsible for issuing and revoking certificates?

A.Validation Authority
B.Certificate Repository
C.Registration Authority
D.Certificate Authority
AnswerD

The Certificate Authority is the trusted entity that signs, issues and publishes revocation status for certificates within the PKI hierarchy. It satisfies the stem's requirement by performing both lifecycle functions, using CRLs or OCSP to distribute revocation data to relying parties.

Why this answer

The Certificate Authority (CA) is the trusted entity that issues digital certificates and maintains Certificate Revocation Lists (CRLs) or supports OCSP for revocation.

11
MCQmedium

A company uses an API gateway to manage their microservices. Which security control should the gateway enforce to prevent abuse from excessive API calls?

A.JWT verification
B.Input validation
C.Rate limiting
D.OAuth 2.0
AnswerC

Rate limiting caps the number of requests a client may make within a defined window, throttling or blocking once the threshold is exceeded. This directly prevents abuse from excessive API calls, the specific threat named in the stem, while preserving availability for legitimate consumers.

Why this answer

Rate limiting is the API gateway control that caps the number of requests a client can make within a defined time window (e.g., 100 requests/minute), directly preventing abuse from excessive API calls, brute-force attempts, and denial-of-service. It is enforced at the gateway before requests reach backend microservices.

Exam trap

The trap is conflating authentication/authorization with abuse prevention — candidates pick JWT or OAuth because they sound security-related, but only rate limiting addresses request volume.

How to eliminate wrong answers

Option A is wrong because JWT verification authenticates the caller's identity and integrity of the token, but a valid token can still be used to flood the API — authentication does not equal throttling. Option B is wrong because input validation checks the shape and content of request payloads to prevent injection attacks, not the volume of requests. Option D is wrong because OAuth 2.0 is an authorization framework that grants scoped access tokens; it controls what a client can do, not how often they can do it.

12
MCQeasy

Which of the following is a key principle of the zero trust security model?

A.Trust all internal traffic
B.Verify once, trust forever
C.Trust but verify
D.Never trust, always verify
AnswerD

The zero trust model enforces authentication and authorisation at every access request, regardless of network location, by requiring continuous verification of identity, device health, and session context before granting resource access. This satisfies the stem’s requirement for a foundational principle, as it directly opposes the traditional perimeter-based trust model. In Microsoft Entra ID, conditional access policies implement this by evaluating real-time signals for each request.

Why this answer

Zero trust is built on the principle 'never trust, always verify' — no user, device, or network segment is implicitly trusted based on location. Every access request must be authenticated, authorized, and continuously validated regardless of whether it originates inside or outside the traditional perimeter. This is the foundational tenet articulated in NIST SP 800-207.

Exam trap

CAS-005 often tests the confusion between 'trust but verify' (a legacy phrase implying baseline trust) and 'never trust, always verify' (the actual zero trust mantra), since both sound security-conscious but only one reflects the model.

How to eliminate wrong answers

Option A is wrong because trusting all internal traffic is the exact opposite of zero trust — it reflects the legacy castle-and-moat perimeter model that zero trust was designed to replace. Option B is wrong because 'verify once, trust forever' describes a one-time authentication model; zero trust requires continuous verification of session context, device posture, and behavior. Option C is wrong because 'trust but verify' is a Cold War-era phrase implying implicit trust with spot checks, whereas zero trust starts from a position of no trust and requires explicit verification for every request.

13
MCQhard

A multinational retailer needs to protect cardholder data across its e-commerce platform, which spans on-premises and multiple cloud providers. The security architect must implement a solution that discovers sensitive data, classifies it consistently, and enforces encryption and access policies wherever the data resides, without relying on a single cloud provider's native tools. Which of the following should the architect implement?

A.A hardware security module (HSM) cluster in the primary data center.
B.A data security posture management (DSPM) solution with centralized policy and encryption key management.
C.A web application firewall (WAF) deployed in front of each e-commerce site.
D.A cloud security posture management (CSPM) tool integrated with each cloud provider.
AnswerB

DSPM discovers and classifies sensitive data across on-premises and multi-cloud environments, then applies consistent protection policies. With centralized key management, it can enforce encryption and access controls regardless of where the data resides, meeting the cross-provider, data-centric requirement without vendor lock-in.

Why this answer

The requirement is data-centric protection across on-premises and multiple clouds with consistent discovery, classification, encryption, and access policy. DSPM with centralized key management delivers cross-provider visibility and enforcement. CSPM addresses configuration, WAF addresses application attacks, and HSM addresses key operations, none of which provide the complete data discovery and policy enforcement needed.

Exam trap

The trap here is confusing CSPM with DSPM, when CSPM evaluates cloud configuration posture and DSPM evaluates and protects the data itself.

14
MCQhard

A financial services firm is designing a microsegmentation strategy for its VMware-based private cloud. The security team wants to enforce east-west policy based on workload identity rather than IP address, and it must survive IP address changes during automated redeployments. Which approach best satisfies these requirements?

A.Create VLANs per application tier and enforce inter-VLAN access control lists on the core switches.
B.Deploy a next-generation firewall between the data center core and aggregation layers and define zones by subnet.
C.Use 802.1Q trunking to isolate each application into a dedicated broadcast domain and apply private VLANs.
D.Install host-based firewall agents on each virtual machine and manage rules through a central console keyed to workload labels.
AnswerD

Host-based enforcement keyed to workload labels decouples policy from IP addresses and network topology. Because the agent travels with the workload, rules continue to apply correctly after automated redeployments change IP addresses, and policy can be expressed in terms of workload identity such as application tier or environment, satisfying both stated requirements.

Why this answer

Microsegmentation requires policy that follows the workload rather than the network. Host-based enforcement managed by workload labels keeps rules valid across IP changes caused by automated redeployments and allows east-west policy expressed in terms of identity. VLAN, private VLAN, and perimeter firewall approaches all bind policy to topology, which the scenario explicitly rules out.

Exam trap

The trap here is equating microsegmentation with VLAN or subnet zoning, when true microsegmentation enforces policy at the workload level using identity labels that persist across IP changes.

15
MCQhard

A financial services firm must allow third-party partners to call internal REST APIs. Partners authenticate with their own OAuth 2.0 authorization servers, and the firm must validate tokens without sharing secrets and enforce per-partner rate limits and scopes. Which approach BEST meets these requirements?

A.Terminate partner tokens at the gateway and reissue firm-issued session cookies for subsequent API calls.
B.Configure the API gateway to trust partner-issued JWTs by validating signatures against published JSON Web Key Sets and mapping claims to scopes and rate limits.
C.Require partners to connect through a dedicated VPN and authenticate with client certificates issued by the firm's internal certificate authority.
D.Issue each partner a shared symmetric key and validate HMAC-signed requests at the API gateway.
AnswerB

Validating partner-issued JWTs against their published JSON Web Key Sets lets the gateway verify authenticity using public keys, so no shared secret is exchanged. Claims such as issuer, audience, scope, and subject can then drive authorization decisions and per-partner throttling policies at the gateway.

Why this answer

Trusting externally issued tokens through published JSON Web Key Sets allows signature verification with public keys, eliminating secret sharing. Claim mapping at the gateway then enforces scopes and per-partner throttling, which is exactly the combination the scenario demands. Symmetric keys, VPN client certificates, and session reissuance each fail at least one stated requirement.

Exam trap

The trap here is treating network-level trust such as VPN or client certificates as equivalent to token-based authorization with scopes.

16
MCQhard

A healthcare provider must allow clinicians to access patient records from personal mobile devices while ensuring that data cannot be copied to unauthorized apps or stored locally. The organization wants to enforce this without managing the entire device. Which of the following should the security architect implement?

A.Virtual desktop infrastructure (VDI) with clipboard redirection disabled
B.Mobile threat defense (MTD) with behavioral anomaly detection
C.Mobile device management (MDM) with full device wipe capability
D.Mobile application management (MAM) with app-level encryption and containerization
AnswerD

MAM applies policy to specific apps rather than the whole device, allowing personal use while preventing data leakage. App-level encryption and containerization keep patient data within the managed app and block copy/paste or local storage to unauthorized apps. This matches the requirement to avoid full device management.

Why this answer

MAM with app-level encryption and containerization enforces data protection at the application layer, allowing personal device use while preventing patient data from being copied to unauthorized apps or stored locally. It avoids the privacy concerns of full device management and directly addresses the data leakage requirement.

Exam trap

The trap here is conflating mobile device management with mobile application management; MDM controls the whole device, while MAM controls only the app.

17
MCQmedium

An organization uses a hardware security module (HSM) to protect cryptographic keys. Which aspect of key management does an HSM primarily address?

A.Key rotation
B.Key escrow
C.Secure key storage and cryptographic operations
D.Digital certificate issuance
AnswerC

An HSM is tamper-resistant hardware that generates, stores and uses cryptographic keys internally, so keys never exist in plaintext outside the module. This directly addresses secure key storage and cryptographic operations, unlike software keystores where keys reside in memory or on disk.

Why this answer

An HSM (Hardware Security Module) is a tamper-resistant physical device whose primary purpose is to securely generate, store, and use cryptographic keys without ever exposing them in plaintext outside the device boundary. It performs cryptographic operations (signing, encryption, key derivation) internally, so keys never leave the protected hardware. This directly addresses secure key storage and cryptographic operations.

Exam trap

The trap is conflating HSM capabilities with broader key-management lifecycle functions (rotation, escrow, issuance) — candidates must recognize that the HSM's core value is protecting keys and performing crypto, not managing policy.

How to eliminate wrong answers

Option A is wrong because key rotation is a policy/process activity that can be performed by a KMS or key management application; the HSM only stores and protects the keys, it does not decide when to rotate them. Option B is wrong because key escrow is a governance practice of storing key copies with a trusted third party for recovery — an HSM can hold escrowed keys but escrow itself is not what an HSM primarily addresses. Option D is wrong because digital certificate issuance is a PKI/CA function; an HSM may sign certificates, but issuing certificates is not its primary key-management role.

18
MCQmedium

A global retailer is deploying a microsegmentation strategy in its data center to limit lateral movement after a breach. The security architect must enforce policy based on workload identity and allow only required east-west flows, even when workloads are migrated between hosts. Which of the following should be implemented?

A.VLAN segmentation with ACLs applied on the core switches.
B.A next-generation firewall (NGFW) deployed at the data center perimeter.
C.802.1X port-based network access control on all switch ports.
D.Host-based firewalls with workload identity labels and a central policy controller.
AnswerD

Host-based firewalls with identity labels enforce policy at the workload level regardless of host or IP changes, and a central controller distributes consistent rules. This allows only required east-west flows and follows workloads across migrations, directly satisfying the microsegmentation requirement in a dynamic data center.

Why this answer

Host-based firewalls with identity labels and a central policy controller enforce microsegmentation based on workload identity rather than IP addresses. This design allows only necessary east-west flows and automatically follows workloads during migration, which is essential in a dynamic data center where lateral movement must be contained.

Exam trap

The trap here is assuming that network-layer segmentation such as VLANs or perimeter firewalls provides microsegmentation, when only identity-based host enforcement can follow workloads and control east-west flows.

19
Multi-Selectmedium

A security architect is evaluating cryptographic agility for a system that must be resistant to quantum computing attacks. Which TWO algorithms are part of the NIST PQC standards? (Select TWO.)

Select 2 answers
A.RSA-4096
B.CRYSTALS-Dilithium
C.AES-256
D.SHA-256
E.CRYSTALS-Kyber
AnswersB, E

CRYSTALS-Dilithium is a lattice-based digital signature scheme selected by NIST for post-quantum cryptography standardisation, providing quantum-resistant authentication. It satisfies the stem's requirement for cryptographic agility against quantum attacks, unlike RSA or ECDSA, whose security collapses under Shor's algorithm. Its selection as a NIST PQC standard confirms its suitability.

Why this answer

CRYSTALS-Dilithium (option B) is correct because NIST selected it in July 2022 as a post-quantum digital signature algorithm, standardized in FIPS 204 (ML-DSA), designed to resist quantum attacks via lattice-based cryptography. CRYSTALS-Kyber (option E) is also correct because NIST selected it as the post-quantum key-encapsulation mechanism (KEM), standardized in FIPS 203 (ML-KEM), also based on module-lattice hardness. RSA-4096 (option A) is not a PQC algorithm; its security relies on integer factorization, which Shor's algorithm on a quantum computer can break.

AES-256 (option C) is a symmetric cipher, not a NIST PQC standard, though it retains quantum resistance via Grover only reducing effective strength to 128 bits. SHA-256 (option D) is a hash function, not a PQC algorithm, and is likewise not part of the NIST PQC standardization selections.

Exam trap

CAS-005 often tests whether candidates can distinguish between NIST PQC asymmetric algorithms and classical symmetric/hash algorithms; a common mistake is selecting AES or SHA as PQC standards because they are quantum-resistant.

20
MCQmedium

A financial services firm runs its customer portal on a Kubernetes cluster in AWS. During a penetration test, an attacker who compromised a front-end pod moved laterally to a database pod by directly connecting to its IP address, even though no NetworkPolicy existed. The security architect must implement a control that enforces least-privilege communication between pods and blocks all unauthorized east-west traffic by default. Which of the following should the architect implement?

A.Enable AWS Security Groups for the worker nodes and restrict inbound rules to the node CIDR block.
B.Deploy a service mesh sidecar proxy and enforce mutual TLS between all services.
C.Apply egress-only internet gateway rules to prevent pods from reaching external networks.
D.Configure a Kubernetes NetworkPolicy with a default-deny ingress rule and explicit allow rules for required pod-to-pod flows.
AnswerD

NetworkPolicy is the native Kubernetes mechanism to enforce pod-level segmentation. A default-deny ingress policy blocks all traffic not explicitly allowed, satisfying least privilege and stopping lateral movement. Explicit allow rules then permit only the required database access from the front end. This directly addresses the scenario's requirement to block unauthorized east-west traffic without adding external components.

Why this answer

The requirement is to enforce least-privilege pod-to-pod communication and block unauthorized east-west traffic by default. Kubernetes NetworkPolicy is the native control that operates at the pod level and can implement a default-deny posture with explicit allow rules. Node-level Security Groups and egress gateways do not provide pod-level segmentation, and mTLS without authorization policy does not deny connections.

Exam trap

The trap here is assuming that encrypting service traffic with mutual TLS automatically prevents lateral movement, when authorization policy is what actually denies unauthorized connections.

21
MCQhard

A financial services firm is designing a hybrid identity architecture. Employees authenticate on-premises to Active Directory Domain Services, while applications are hosted in multiple SaaS and IaaS providers. The security architect must ensure that a compromised on-premises domain controller cannot be used to forge tokens that grant access to cloud applications, and that cloud access decisions reflect real-time on-premises risk signals. Which of the following BEST achieves these goals?

A.Implement a cloud-based identity provider with conditional access that ingests on-premises risk telemetry through a secure API and uses short-lived tokens.
B.Use password hash synchronization with seamless single sign-on and enforce smart card authentication for all on-premises users.
C.Extend Active Directory Domain Services to the cloud using domain controllers deployed in IaaS virtual networks and replicate credentials.
D.Federate on-premises Active Directory Federation Services with each cloud provider using SAML or OIDC, and require MFA at the federation layer.
AnswerA

A cloud identity provider with conditional access evaluates real-time signals such as device compliance and on-premises risk before issuing short-lived tokens. Because token issuance happens in the cloud and does not trust on-premises domain controllers to sign tokens, a compromised domain controller cannot forge cloud access, satisfying both requirements.

Why this answer

A cloud identity provider that uses conditional access and consumes on-premises risk telemetry issues short-lived tokens based on real-time evaluation, so cloud trust does not depend on on-premises token-signing keys. This prevents a compromised domain controller from forging cloud tokens while allowing risk signals to influence access decisions across SaaS and IaaS applications.

Exam trap

The trap here is equating identity federation or directory extension with protection from token forgery, when only moving token issuance to a cloud identity provider that evaluates real-time risk removes trust in on-premises signing keys.

22
Multi-Selecteasy

Which TWO of the following are key benefits of using a software-defined perimeter (SDP) in a zero trust architecture? (Select TWO.)

Select 2 answers
A.Reduces the attack surface by hiding network resources
B.Automates patch management
C.Eliminates the need for encryption
D.Provides identity-based access control
E.Simplifies network architecture by removing firewalls
AnswersA, D

SDP uses a deny-by-default model with single-packet authorisation, keeping resources invisible to unauthenticated users. Attackers cannot scan or target what they cannot see, so the exploitable attack surface shrinks — the specific benefit the zero trust scenario requires.

Why this answer

Option A is correct because SDP uses a "black cloud" or dark network approach where resources are cloaked and do not respond to unauthenticated probes, so attackers cannot see or scan them, directly shrinking the attack surface. Option D is correct because SDP enforces access decisions based on verified user and device identity (often via mutual TLS, SAML, or OIDC with a controller and gateway), which is the core identity-centric principle of zero trust. Option B is wrong because patch management is a vulnerability/patch lifecycle function, not a benefit of SDP.

Option C is wrong because SDP actually depends on strong encryption such as mTLS and IPsec/TLS tunnels rather than eliminating it. Option E is wrong because SDP complements rather than removes firewalls, and it typically adds controller/gateway components instead of simplifying the architecture by deleting firewalls.

Exam trap

The trap is selecting 'eliminates the need for encryption' or 'removes firewalls' because SDP sounds like a replacement for traditional perimeter security — in reality SDP depends on encryption and coexists with firewalls.

23
Multi-Selectmedium

A security architect is designing a defense-in-depth strategy for a cloud-native application. Which TWO controls are most effective for protecting east-west traffic between microservices?

Select 2 answers
A.Service mesh with mutual TLS
B.Intrusion detection system (IDS) on the gateway
C.Micro-segmentation of virtual networks
D.Web application firewall (WAF)
E.Network access control lists (ACLs) at the perimeter
AnswersA, C

Mutual TLS in a service mesh authenticates and encrypts every service-to-service call, giving cryptographic workload identity rather than relying on network location. This directly protects east-west traffic inside the cluster, where perimeter controls cannot inspect lateral microservice communication.

Why this answer

Option A (Service mesh with mutual TLS) is correct because a service mesh provides identity-based, encrypted, and authenticated communication between microservices, and mutual TLS ensures both sides of an east-west connection verify each other's certificates, preventing spoofing and eavesdropping inside the cluster. Option C (Micro-segmentation of virtual networks) is correct because it enforces least-privilege reachability between workloads by applying granular policies at the virtual network or workload level, which directly limits lateral movement if a microservice is compromised. Option B is not the best fit because an IDS on the gateway monitors north-south traffic entering the environment rather than internal service-to-service flows, and it is detective rather than preventive.

Option D is not appropriate because a WAF protects HTTP/HTTPS applications from external web attacks at the edge, not east-west microservice traffic. Option E is not appropriate because perimeter ACLs filter traffic at the network boundary and do not provide the identity-aware, workload-level controls needed for internal microservice communication.

Exam trap

CAS-005 often tests the distinction between north-south and east-west controls; candidates frequently select perimeter tools like WAF or gateway IDS, which do not address internal microservice traffic.

24
Multi-Selectmedium

A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)

Select 2 answers
A.Penetration testing results
B.Employee background checks
C.List of all open-source components and their versions
D.Network flow logs
E.Dependency analysis to identify known vulnerabilities
AnswersC, E

An SBOM must enumerate every open-source library and its exact version, because version data is what lets you map components to advisories and licences. Without this inventory, the supply chain constraint of knowing what ships inside your software cannot be met.

Why this answer

Option C is correct because an SBOM's core purpose is to enumerate every software component — including open-source libraries and their exact versions — so that downstream consumers can identify what is inside a product and trace provenance. Option E is correct because SBOMs enable dependency analysis, allowing organizations to correlate listed components and versions against vulnerability databases (e.g., NVD/CVE feeds) to detect known vulnerabilities in the supply chain. Together, these two form the essential SBOM strategy: knowing what components exist and analyzing their dependencies for risk.

Option A (penetration testing results) is a point-in-time security assessment, not a component inventory, so it is not an SBOM element. Option B (employee background checks) is a personnel security control unrelated to software composition. Option D (network flow logs) captures runtime traffic metadata, not the software components or dependencies that an SBOM documents.

Exam trap

CAS-005 often tests the distinction between SBOM as a component inventory plus dependency/vulnerability analysis versus generic security activities (pentesting, background checks, flow logs) that sound security-related but have nothing to do with software composition.

25
Multi-Selecthard

An organization is architecting a hybrid cloud environment with AWS and on-premises resources. Which THREE considerations are essential for meeting data residency requirements? (Choose three.)

Select 3 answers
A.Selecting the correct AWS region for data storage
B.Using only on-premises storage for all data
C.Storing encryption keys in the same region as the data
D.Implementing data classification policies
E.Using a global AWS account without region constraints
AnswersA, C, D

Data residency requires that stored data physically remains within a permitted jurisdiction. Choosing the correct AWS region determines the physical location of the data at rest, directly satisfying the legal constraint that data must not leave the approved territory.

Why this answer

Option A is correct because data residency is fundamentally about geography: choosing the correct AWS Region (e.g., eu-west-1 for EU data) ensures data at rest and in transit stays within the legally required jurisdiction, since AWS Regions are isolated geographic areas. Option C is correct because encryption keys are themselves regulated data; keeping KMS keys in the same Region as the encrypted data (or using a customer-managed KMS key in that Region) prevents cross-border key movement and satisfies residency controls such as those in GDPR or data-sovereignty mandates. Option D is correct because you cannot enforce residency without first knowing what data you hold; data classification policies identify regulated/sensitive data so it can be tagged, mapped, and placed only in approved Regions and on-premises locations.

Option B is not required because hybrid architectures can store data in compliant AWS Regions, so mandating all-on-premises storage is overly restrictive and defeats the hybrid design. Option E is wrong because a global AWS account without Region constraints allows resources and data to be created in any Region, directly violating data residency requirements.

Exam trap

CAS-005 often tests the nuances of data residency in hybrid cloud, and candidates may overlook the importance of encryption key location or think that on-premises storage is required, missing the essential considerations.

26
MCQeasy

An organization is adopting a cloud-first strategy and needs to ensure compliance with SOC 2. Which cloud service model places the most responsibility on the customer for security?

B.FaaS
AnswerA

IaaS leaves the customer responsible for the guest OS, runtime, middleware, applications and data, whereas PaaS and SaaS shift those layers to the provider. This maximal customer ownership of the stack is precisely what satisfies the stem's requirement for the model placing the most security responsibility on the customer.

Why this answer

IaaS (Infrastructure as a Service) places the most security responsibility on the customer because the provider only manages the physical hardware, hypervisor, and network fabric. The customer is responsible for the guest OS, middleware, runtime, applications, and data — including patching, hardening, IAM, and encryption. Under SOC 2, this means the customer must implement and evidence most of the Trust Services Criteria controls themselves.

Exam trap

CAS-005 often tests the shared responsibility model by asking which model places the MOST responsibility on the customer — candidates incorrectly pick SaaS or PaaS because they confuse 'cloud-first' with 'provider-managed.'

How to eliminate wrong answers

Option B is wrong because FaaS (Function as a Service) abstracts the runtime and OS, so the provider handles more of the stack — the customer only secures function code, IAM, and data. Option C is wrong because SaaS places the least responsibility on the customer; the provider manages nearly everything except user access and data classification. Option D is wrong because PaaS sits between IaaS and SaaS — the provider manages the OS and runtime, leaving the customer responsible mainly for applications and data, which is less than IaaS.

27
MCQmedium

A software company wants to strengthen the integrity of its build pipeline. Developers currently commit code directly to the main branch, and build servers pull dependencies from public repositories without verification. The security architect must ensure that only reviewed code is built and that dependencies have not been tampered with. Which combination of controls best addresses these requirements?

A.Store build artifacts in an encrypted repository and enable versioning on the storage bucket.
B.Enforce signed commits with mandatory peer review and verify dependency signatures against a trusted allowlist.
C.Run static application security testing on every build and block releases with high-severity findings.
D.Require developers to use multi-factor authentication when pushing to the repository.
AnswerB

Signed commits prove the author's identity and, combined with mandatory peer review and branch protection, ensure only reviewed code reaches the build. Verifying dependency signatures against a trusted allowlist detects tampered or substituted packages before they enter the artifact. Together these controls directly address both code provenance and dependency integrity in the pipeline.

Why this answer

Signed commits with mandatory peer review and branch protection ensure only reviewed, attributable code is built, while verifying dependency signatures against a trusted allowlist confirms that third-party components match their publishers' originals. These preventive controls address both halves of the requirement. Authentication, static analysis, and artifact storage protections each cover different concerns and leave the provenance and dependency integrity gaps open.

Exam trap

The trap here is equating strong developer authentication or code scanning with supply chain integrity, when provenance requires cryptographic verification of both commits and dependencies.

28
Multi-Selectmedium

A healthcare organization is architecting a microsegmentation strategy for its hybrid data center. The security architect must limit lateral movement between workloads, enforce policy based on workload identity rather than IP addresses, and maintain visibility into inter-workload flows. Which TWO of the following controls BEST support these requirements? (Choose two.)

Select 2 answers
A.Enable dynamic ARP inspection and DHCP snooping on all access-layer switches.
B.Deploy a software-defined perimeter (SDP) controller that authenticates endpoints before granting access to protected workload segments.
C.Use a service mesh with mutual TLS and identity-based authorization policies between microservices.
D.Place all workloads behind a next-generation firewall and create zone-based policies for north-south traffic.
E.Implement host-based firewalls with rules based on IP address ranges that mirror the existing VLAN segmentation.
AnswersB, C

A software-defined perimeter authenticates and authorizes endpoints before any network access is granted, creating identity-based, need-to-know connectivity between workloads. This directly limits lateral movement because unauthenticated workloads cannot reach protected segments, and it supports policy based on workload identity rather than static IP addresses.

Why this answer

A software-defined perimeter and a service mesh with mutual TLS both base access decisions on authenticated workload identity rather than IP addresses, which limits lateral movement and supports visibility into inter-workload flows. The other controls either rely on static IP or zone constructs, or address layer 2 threats without providing identity-based segmentation.

Exam trap

The trap here is treating host firewalls or zone-based firewalls as sufficient for microsegmentation, when they still rely on IP or zone constructs and do not enforce policy by cryptographic workload identity.

29
MCQmedium

A financial services company is designing a hybrid cloud environment. The security architect must ensure that data in transit between the on-premises data center and the cloud provider is protected against interception and that the cloud provider cannot read the data. The company also needs to meet strict compliance requirements for key management. Which of the following should the architect implement to BEST meet these requirements?

A.Implement a dedicated AWS Direct Connect connection with MACsec encryption.
B.Use TLS 1.3 with mutual authentication for all data transfers and store private keys in a cloud-based key management service.
C.Configure a site-to-site VPN using IPsec with pre-shared keys managed by the cloud provider.
D.Deploy a customer-managed VPN gateway with hardware security modules (HSMs) for key storage and use IPsec with customer-managed certificates.
AnswerD

This approach uses a customer-managed VPN gateway and HSMs to store keys, ensuring that the cloud provider does not have access to the encryption keys. IPsec with customer-managed certificates provides strong encryption and authentication. This meets the requirements for data confidentiality against the provider and compliance with strict key management controls.

Why this answer

The requirement is to protect data in transit from interception and ensure the cloud provider cannot read it, while meeting strict key management compliance. A customer-managed VPN gateway with HSMs and customer-managed certificates ensures that encryption keys are controlled by the company, not the provider. IPsec provides strong encryption, and HSMs offer secure key storage, satisfying both security and compliance.

Exam trap

The trap here is assuming that any encryption in transit is sufficient, without considering who controls the encryption keys.

30
MCQhard

An organization is migrating to an immutable infrastructure model for its containerized applications. Which practice is essential to ensure the integrity of the immutable infrastructure?

A.Regular patching of running containers
B.Image scanning and signing in the CI/CD pipeline
C.Runtime security monitoring with seccomp
D.Use of configuration management tools like Ansible
AnswerB

Scanning detects vulnerabilities and embedded secrets, while signing produces a cryptographic attestation of image provenance. Enforcing signature verification at deploy time ensures only unaltered, approved images run, directly preserving the integrity guarantee that immutable infrastructure depends on.

Why this answer

In an immutable infrastructure model, containers are never modified after deployment — instead, new images replace old ones. Therefore, integrity must be enforced at build time: scanning images for vulnerabilities and cryptographically signing them in the CI/CD pipeline ensures only trusted, verified artifacts are deployed. This shifts security left and guarantees that what runs in production is exactly what was tested and approved.

Exam trap

CAS-005 often tests the misconception that 'patching' or 'runtime monitoring' secures immutable infrastructure, when the exam expects you to recognize that integrity is guaranteed at build/deploy time via scanning and signing.

How to eliminate wrong answers

Option A is wrong because patching running containers violates immutability — you would mutate a live container instead of replacing it with a newly built image. Option C is wrong because runtime security monitoring with seccomp is a detective/preventive control at runtime, not a mechanism for ensuring the integrity of the immutable artifact itself. Option D is wrong because configuration management tools like Ansible are designed for mutable, state-enforced configuration of long-lived hosts, which is the opposite of the immutable infrastructure philosophy.

31
MCQeasy

Which cryptographic best practice ensures that a private key remains protected even if the server it is stored on is compromised?

A.Storing keys in a hardware security module (HSM)
B.Encrypting keys with AES-256
C.Using short key rotation intervals
D.Using strong key derivation functions
AnswerA

An HSM performs cryptographic operations internally, so the private key never leaves the tamper-resistant hardware. Compromising the host server yields no usable key material, satisfying the requirement that the key stay protected despite server compromise.

Why this answer

A hardware security module (HSM) is a dedicated physical device that securely generates, stores, and manages cryptographic keys, ensuring the private key never leaves the tamper-resistant hardware. Even if the server is compromised, the attacker cannot extract the key from the HSM. This provides the strongest protection for private keys.

Exam trap

CAS-005 often tests the misconception that encrypting a key at rest (e.g., with AES) is sufficient; candidates overlook that the encryption key must also be protected, and only an HSM ensures the private key never exists in an extractable form.

How to eliminate wrong answers

Option B is wrong because encrypting keys with AES-256 still requires storing the encryption key somewhere on the server, which could be compromised along with the encrypted key. Option C is wrong because short key rotation intervals reduce the window of exposure but do not protect the key if the server is actively compromised during its lifetime. Option D is wrong because strong key derivation functions protect weak passwords or passphrases, not the private key itself once it is in use on a compromised server.

32
MCQmedium

A company is migrating to AWS and needs to comply with SOC 2. Which cloud-native service would BEST help monitor and enforce security configurations across the AWS environment?

A.AWS CloudTrail
B.AWS WAF
C.AWS Config
D.AWS Shield
AnswerC

AWS Config continuously records resource configurations and evaluates them against rules, flagging non-compliant changes across the account. This satisfies the SOC 2 monitoring and enforcement constraint by providing auditable configuration history and automated remediation triggers.

Why this answer

AWS Config is the service purpose-built for continuously assessing, auditing, and evaluating AWS resource configurations against desired baselines. It records configuration changes, evaluates them against Config Rules (including SOC 2-aligned conformance packs), and flags noncompliant resources. This directly maps to SOC 2's change management, monitoring, and configuration control criteria.

CloudTrail, WAF, and Shield serve different purposes — API activity logging, web attack filtering, and DDoS mitigation respectively — none of which provide configuration compliance assessment.

Exam trap

CAS-005 often tests the confusion between CloudTrail (who did what — API activity) and AWS Config (what is the configuration state — compliance), since both are 'monitoring' services and candidates frequently swap them under time pressure.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and who did what, but does not evaluate whether resource configurations meet a compliance baseline — it is an audit log, not a configuration compliance engine. Option B is wrong because AWS WAF filters HTTP/S traffic against web exploits like SQLi and XSS at the application layer; it has no visibility into resource configuration state. Option D is wrong because AWS Shield provides DDoS protection at Layers 3/4 (and Shield Advanced at Layer 7), which is unrelated to configuration monitoring or SOC 2 configuration controls.

33
MCQeasy

In a zero trust architecture, which concept ensures that an attacker who compromises one segment cannot move laterally to other segments?

A.Software-defined perimeter
B.Defense-in-depth layering
C.Identity-centric access
D.Micro-segmentation
AnswerD

Micro-segmentation applies granular, workload-level security controls and policies between individual segments, so a compromised host cannot reach neighbouring workloads. This directly satisfies the zero trust requirement that no implicit trust exists between network segments, blocking lateral movement even after one segment falls.

Why this answer

Micro-segmentation divides a network into granular, isolated segments — often down to individual workloads or identities — and enforces policy between each segment so that compromise of one segment does not grant lateral movement to others. In zero trust, micro-segmentation is the enforcement mechanism that operationalizes 'never trust, always verify' at the network layer, typically using software-defined policies rather than physical firewalls.

Exam trap

CAS-005 often tests the confusion between micro-segmentation (the lateral-movement prevention mechanism) and SDP or defense-in-depth (broader principles), so candidates pick the more familiar-sounding architectural term.

How to eliminate wrong answers

Option A is wrong because a Software-Defined Perimeter (SDP) creates a logical boundary around resources and hides them from unauthorized users, but it does not itself prevent east-west lateral movement between internal segments the way micro-segmentation does. Option B is wrong because defense-in-depth is a layered security strategy (multiple overlapping controls) — it is a principle, not the specific mechanism that isolates segments. Option C is wrong because identity-centric access controls who can authenticate to what, but without network segmentation an attacker with valid credentials can still move laterally across a flat network.

34
MCQmedium

A company is implementing a zero trust architecture. Which of the following BEST describes the principle of micro-segmentation in this model?

A.Creating a single perimeter around the entire network
B.Isolating workloads at the virtual network interface level with granular security policies
C.Using VLANs to separate departments
D.Implementing a VPN for remote access
AnswerB

Micro-segmentation creates granular, workload-level security policies enforced at each virtual network interface, so lateral movement between workloads is blocked regardless of subnet boundaries. This satisfies zero trust's requirement to isolate individual workloads rather than trusting the network perimeter.

Why this answer

Micro-segmentation in a zero trust architecture isolates individual workloads at the virtual network interface level and enforces granular, per-workload security policies. This limits lateral movement because each workload becomes its own security zone, and traffic between workloads is explicitly allowed or denied based on identity and policy rather than network location. It is a foundational zero trust control that assumes no implicit trust based on being 'inside' the network.

Exam trap

The trap here is confusing traditional network segmentation (VLANs, subnets, perimeter firewalls) with micro-segmentation, which operates at the workload/vNIC level with granular per-workload policies.

How to eliminate wrong answers

Option A is wrong because a single perimeter around the entire network is the traditional castle-and-moat model that zero trust explicitly rejects — it assumes everything inside is trusted. Option C is wrong because VLANs provide coarse-grained Layer 2 segmentation by department, not the fine-grained, workload-level isolation and policy enforcement that micro-segmentation requires. Option D is wrong because a VPN for remote access only secures the transport path for remote users; it does not segment internal workloads or enforce east-west zero trust policies.

35
MCQhard

A security architect is designing a system that must provide confidentiality and integrity for data at rest and in transit. The organization wants to minimize the risk of key compromise and ensure that a single compromised key does not expose all data. Which key management strategy best meets these requirements?

A.Derive all encryption keys from a single password using PBKDF2
B.Use a single master key to encrypt all data, stored in a hardware security module (HSM)
C.Store all encryption keys in a centralized key vault without additional wrapping
D.Implement a hierarchical key management system with data encryption keys wrapped by key encryption keys
AnswerD

A hierarchical key management system uses unique data encryption keys (DEKs) for each data object or session, and wraps them with key encryption keys (KEKs). Compromise of one DEK exposes only the data it protects, not the entire dataset. This minimizes risk and meets the requirement that a single compromised key does not expose all data.

Why this answer

A hierarchical key management system with unique data encryption keys wrapped by key encryption keys ensures that compromise of one data key only affects the data it protects. This limits the blast radius and meets the requirement that a single compromised key does not expose all data. Other strategies create single points of failure.

Exam trap

The trap here is assuming that storing a single master key in an HSM or a centralized vault is sufficient, when in fact it creates a single point of failure that violates the requirement for key isolation.

36
MCQmedium

A security team is hardening a Kubernetes cluster. Which resource should be used to define fine-grained rules for which pods can communicate with each other?

A.Admission Controller
B.PodSecurityPolicy
C.RBAC
D.NetworkPolicy
AnswerD

NetworkPolicy objects select pods via label selectors and enforce ingress and egress rules at layer 3/4, restricting traffic to explicitly permitted pod, namespace, or CIDR combinations. This satisfies the stem's requirement for fine-grained pod-to-pod communication control, which Kubernetes denies by default until a policy selects the pod.

Why this answer

NetworkPolicy is the Kubernetes resource used to define fine-grained rules for pod-to-pod communication. It acts as a firewall for pods, allowing or denying traffic based on labels, namespaces, and ports. This is essential for microsegmentation and hardening cluster security.

Exam trap

CAS-005 often tests the distinction between NetworkPolicy and other Kubernetes security resources like RBAC or PodSecurityPolicy, leading candidates to choose RBAC for network segmentation.

How to eliminate wrong answers

Option A is wrong because Admission Controllers are used to enforce policies during resource creation, not for runtime network communication. Option B is wrong because PodSecurityPolicy (deprecated in Kubernetes 1.21) defines security contexts for pods, not network rules. Option C is wrong because RBAC controls access to the Kubernetes API, not pod-to-pod traffic.

37
Multi-Selectmedium

An organization is deploying a cloud workload protection platform (CWPP). Which TWO capabilities are essential for protecting workloads in a hybrid cloud?

Select 2 answers
A.Security information and event management
B.Identity and access management
C.Data loss prevention
D.Runtime protection
E.Vulnerability management
AnswersD, E

Runtime protection continuously monitors executing workloads for malicious behaviour such as process injection or fileless attacks, then blocks or alerts in real time. This satisfies the hybrid cloud constraint because on-premises and cloud workloads share the same runtime threat surface, which static scanning alone cannot address.

Why this answer

Runtime protection (D) is essential because a CWPP must continuously monitor executing processes, detect malicious behavior such as fileless attacks or cryptomining, and block threats in real time across VMs, containers, and serverless workloads in hybrid environments. Vulnerability management (E) is equally essential since CWPPs must scan workloads for missing patches, misconfigurations, and known CVEs (e.g., via agents or agentless snapshots) to prioritize remediation before exploitation. Options A, B, and C, while valuable security disciplines, are typically delivered by SIEM, IAM, and DLP platforms respectively, and are not the defining workload-protection capabilities of a CWPP.

Exam trap

CAS-005 often tests whether candidates can distinguish CWPP's workload-centric capabilities (runtime protection, vulnerability management) from adjacent enterprise security domains (SIEM, IAM, DLP) that are frequently bundled in vendor marketing but are not core CWPP functions.

38
MCQmedium

A security architect is designing a network for a company that requires high availability and confidentiality for data in transit between two data centers. The company wants to use a protocol that operates at the network layer, supports perfect forward secrecy (PFS), and can be implemented in hardware for high throughput. Which protocol BEST meets these requirements?

A.IPsec with IKEv2
B.Secure Shell (SSH) tunneling
C.Datagram Transport Layer Security (DTLS)
D.Transport Layer Security (TLS) 1.3
AnswerA

IPsec operates at the network layer and can be implemented in hardware for high throughput. IKEv2 supports perfect forward secrecy through Diffie-Hellman key exchange, ensuring that compromise of long-term keys does not compromise past session keys. This combination provides confidentiality and high availability for data in transit between data centers.

Why this answer

IPsec with IKEv2 operates at the network layer, supports perfect forward secrecy through Diffie-Hellman, and is widely implemented in hardware for high throughput. The other protocols either operate at higher layers or are not typically hardware-accelerated for site-to-site network-layer encryption.

Exam trap

The trap here is selecting a transport-layer protocol like TLS 1.3 because it also supports perfect forward secrecy, without considering the network-layer and hardware acceleration requirements.

39
Multi-Selectmedium

A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and new containerized workloads. The architect must reduce lateral movement while minimizing disruption to existing traffic flows. (Choose two.)

Select 2 answers
A.Apply identical static access control lists to every subnet regardless of the workloads hosted there.
B.Replace all existing firewalls with a single perimeter appliance that inspects north-south traffic at the data center edge.
C.Disable all inter-tier communication by default and require application teams to open ports manually after each deployment.
D.Map application dependencies and traffic flows before defining segmentation policy so that legitimate communication paths are preserved.
E.Enforce segmentation policy at the workload level using identity-based rules rather than relying solely on network address ranges.
AnswersD, E

Dependency and flow mapping establishes which systems genuinely need to communicate, which is the prerequisite for writing allow-list policy that does not break production. Without this baseline, microsegmentation rules either block required traffic or remain so permissive that lateral movement is still possible.

Why this answer

Effective microsegmentation starts with understanding real traffic dependencies, then enforces least-privilege rules anchored to workload identity so policy survives address churn in mixed legacy and container environments. Blanket deny-with-manual-opening, perimeter-only appliances, and uniform static lists either disrupt operations or fail to constrain east-west movement.

Exam trap

The trap here is equating perimeter firewalling or uniform ACLs with microsegmentation, when the objective is workload-level east-west control.

40
Multi-Selecthard

A security architect at a financial services firm is designing a microsegmentation strategy for a data center running both virtual machines and containerized workloads. The architect must reduce east-west lateral movement and enforce least-privilege communication between tiers. Which TWO design elements are most appropriate? (Choose two.)

Select 2 answers
A.Enable promiscuous-mode intrusion detection on a SPAN port for all internal traffic.
B.Use a service mesh with mutual TLS and authorization policies for service-to-service communication.
C.Deploy a single perimeter firewall with rules based on source and destination IP ranges.
D.Rely on VLAN segmentation between application tiers to control east-west traffic.
E.Apply host-based firewall policies tied to workload identity rather than IP address.
AnswersB, E

A service mesh with mutual TLS authenticates both ends of every service connection using cryptographic identities and enforces authorization policies for which services may call which endpoints. This directly limits east-west movement between containerized tiers and provides visibility into service dependencies, complementing host-based controls for workloads that sit outside the mesh.

Why this answer

Identity-based host firewall policies and a service mesh with mutual TLS and authorization policies both enforce least-privilege communication at the workload level. Identity-based rules survive IP changes across VMs and containers, while the mesh cryptographically authenticates and authorizes service-to-service calls. Together they reduce east-west lateral movement, whereas perimeter, VLAN, and monitoring-only controls cannot enforce per-workload segmentation.

Exam trap

The trap here is treating VLANs or a perimeter firewall as microsegmentation, when true microsegmentation enforces policy at the individual workload using identity rather than network location.

41
Multi-Selectmedium

A security architect is designing a zero trust network access (ZTNA) solution for a company with remote workers. The architect must ensure that access to internal applications is granted based on user identity and device posture, without exposing applications to the internet. Which TWO design elements are essential for this ZTNA implementation? (Choose two.)

Select 2 answers
A.An outbound-only connection from the application to the trust broker, so the application is never directly exposed to the internet.
B.A public DNS record that maps each internal application to a routable IP address for direct access.
C.A next-generation firewall (NGFW) in the DMZ that performs deep packet inspection on all inbound traffic to internal applications.
D.A site-to-site VPN between each remote worker's home router and the corporate data center.
E.A trust broker that authenticates users and devices and evaluates access policies before granting access to applications.
AnswersA, E

ZTNA typically uses outbound-only connections from the application to the trust broker, which hides the application from the internet and prevents inbound exposure. This design ensures that users connect through the broker and that the application remains protected behind the broker's policy enforcement.

Why this answer

ZTNA requires a trust broker to authenticate users and devices and enforce access policies, and it relies on outbound-only connections from applications to the broker to avoid exposing them to the internet. Together, these elements ensure that access is granted based on identity and device posture rather than network location, which is the core of zero trust.

Exam trap

The trap here is assuming that a traditional VPN or firewall can provide zero trust access, when in fact ZTNA requires a brokered, identity-aware connection that does not expose applications to the internet.

42
MCQmedium

A security architect is designing a cloud security strategy for a company that uses multiple cloud providers. The architect needs a solution that provides visibility into cloud application usage, enforces security policies, and protects data. Which technology is most appropriate?

A.Cloud Workload Protection Platform (CWPP)
B.Cloud Access Security Broker (CASB)
C.Cloud Security Posture Management (CSPM)
D.Secure Access Service Edge (SASE)
AnswerB

A CASB sits between users and multiple cloud providers, delivering the required visibility into sanctioned and unsanctioned application usage, policy enforcement, and data protection such as DLP and encryption. This directly satisfies the multi-cloud visibility and policy constraint in the stem.

Why this answer

A Cloud Access Security Broker (CASB) sits between cloud consumers and cloud providers to provide visibility into cloud application usage, enforce security policies (e.g., DLP, access control), and protect data across multiple cloud services. It is specifically designed for multi-cloud visibility and policy enforcement.

Exam trap

CAS-005 often tests the overlap between CASB, CSPM, and CWPP; candidates must distinguish CASB's focus on application usage and data policy from CSPM's focus on configuration compliance.

How to eliminate wrong answers

Option A is wrong because CWPP focuses on protecting workloads (VMs, containers, serverless) at the compute layer, not on providing visibility into cloud application usage or enforcing SaaS policies. Option C is wrong because CSPM focuses on identifying misconfigurations in cloud infrastructure (e.g., open S3 buckets, overly permissive IAM) rather than monitoring application usage or enforcing data policies across SaaS. Option D is wrong because SASE converges networking and security (SD-WAN, SWG, ZTNA, CASB) into a cloud-delivered service, but the question specifically asks for visibility into cloud application usage and policy enforcement, which is the CASB function, not the entire SASE stack.

43
MCQhard

A security architect is designing a data loss prevention (DLP) program for a global enterprise that uses Microsoft 365, endpoint devices, and a custom web application. The requirement is to detect and block sensitive data exfiltration across all three channels while minimizing false positives caused by legitimate business data that resembles regulated data. The architect needs a control that classifies data consistently and applies policy at the point of egress. Which of the following BEST meets this requirement?

A.Require full-disk encryption on all endpoints and enforce TLS for all data in transit to external destinations.
B.Implement database activity monitoring on all repositories and alert on bulk read operations of sensitive tables.
C.Apply sensitivity labels with unified DLP policies that use exact data match and trainable classifiers across Microsoft 365, endpoints, and the custom application.
D.Deploy network DLP appliances at each internet egress point and configure regex patterns for regulated data types.
AnswerC

Sensitivity labels persist with the data and provide consistent classification across Microsoft 365, endpoints, and integrated applications. Unified DLP policies using exact data match and trainable classifiers reduce false positives by matching actual regulated records and learning business context, and they enforce policy at egress points across all three channels.

Why this answer

Sensitivity labels with unified DLP policies classify data persistently and apply consistent enforcement across Microsoft 365, endpoints, and integrated applications. Exact data match and trainable classifiers improve accuracy by matching real regulated records and learning business context, which reduces false positives while blocking exfiltration at egress points across all channels.

Exam trap

The trap here is assuming that network DLP with regex patterns is sufficient for cross-channel protection, when it lacks persistent classification and generates false positives that only exact data match and trainable classifiers can mitigate.

44
MCQhard

A security architect is designing segmentation for a manufacturing network where legacy programmable logic controllers cannot be patched or run endpoint agents. The architect wants to prevent a compromised business workstation from initiating connections to the controllers while still allowing the controllers to send telemetry to a historian server. Which of the following design elements best achieves this objective?

A.Network address translation between the business network and the controller subnet with private addressing
B.An intrusion prevention system deployed inline on the business network with industrial protocol signatures
C.A unidirectional gateway enforcing one-way data flow from the controller network out to the historian
D.A stateful firewall rule permitting any internal source to reach the controller subnet on the industrial protocol port
AnswerC

A unidirectional gateway physically or logically enforces one-way traffic, so controllers can emit telemetry toward the historian while no path exists for inbound connections from the business network. This directly satisfies the requirement to block workstation-initiated access to unpatched controllers. It is purpose-built for this exact industrial constraint, where endpoints cannot defend themselves.

Why this answer

A unidirectional gateway enforces that data can flow only from the protected controller network outward, so telemetry reaches the historian while no inbound path exists from the business network. This protects unpatched controllers that cannot run agents or be hardened, precisely matching the constraint that a compromised workstation must never initiate connections to them.

Exam trap

The trap here is relying on inspection-based controls like IPS or permissive firewall rules, which still allow a compromised host to initiate sessions with controllers.

45
MCQmedium

An organization is adopting a DevSecOps approach and wants to integrate security early in the development lifecycle. Which practice involves creating visual representations of threats and identifying potential attack vectors during the design phase?

A.Threat modeling
B.Dynamic application security testing (DAST)
C.Static application security testing (SAST)
D.Runtime application self-protection (RASP)
AnswerA

Threat modelling produces structured diagrams of systems, data flows and trust boundaries, then enumerates potential attack vectors against them. Conducted during design, it shifts security left, satisfying the DevSecOps goal of integrating security early in the development lifecycle.

Why this answer

Threat modeling is a structured process that visually maps system components, data flows, and trust boundaries to identify potential threats and attack vectors during the design phase. It aligns with DevSecOps by shifting security left, enabling teams to address risks before code is written. Frameworks like STRIDE and tools like Microsoft Threat Modeling Tool are commonly used to create these visual representations.

Exam trap

The trap here is confusing design-phase activities with testing or runtime protection; candidates often pick SAST or DAST because they are familiar security practices, but the key phrase 'during the design phase' and 'visual representations' points exclusively to threat modeling.

How to eliminate wrong answers

Option B is wrong because DAST is a black-box testing technique performed on running applications to find vulnerabilities from an external attacker's perspective, not during design. Option C is wrong because SAST analyzes source code or binaries for security flaws without executing the program, typically during coding or build phases, not design. Option D is wrong because RASP instruments an application at runtime to detect and block attacks in real time, which is a runtime protection mechanism, not a design-phase activity.

46
MCQhard

A DevOps team integrates security into the CI/CD pipeline. They want to identify vulnerabilities in open-source libraries used by their application. Which tool or practice is specifically designed for this purpose?

A.Software Bill of Materials (SBOM) and dependency analysis
B.Runtime Application Self-Protection (RASP)
C.Static Application Security Testing (SAST)
D.Dynamic Application Security Testing (DAST)
AnswerA

SBOM generation plus dependency analysis inventories every open-source component and its transitive dependencies, then cross-references them against vulnerability databases to flag known CVEs. This directly satisfies the stem's constraint: identifying vulnerabilities in open-source libraries, which static code scanning or container hardening would not target at the dependency layer.

Why this answer

SBOM and dependency analysis are specifically designed to inventory open-source components and their transitive dependencies, then cross-reference them against vulnerability databases like the NVD or OSV. This directly addresses the need to identify vulnerabilities in third-party libraries, which is a core part of software supply chain security. Unlike code analysis tools that focus on first-party code, SBOM-driven scanning targets the exact problem of open-source component risk.

Exam trap

CAS-005 often tests the confusion between SAST, DAST, RASP, and SBOM, where candidates mistakenly pick SAST for third-party library vulnerabilities because it sounds like 'code analysis' — but SAST only scans first-party source code, not dependencies.

How to eliminate wrong answers

Option B is wrong because RASP operates at runtime inside the application, monitoring execution to block attacks, but it does not inventory or analyze open-source libraries for known vulnerabilities. Option C is wrong because SAST analyzes proprietary source code for coding flaws like SQL injection or buffer overflows, not third-party library vulnerabilities. Option D is wrong because DAST tests a running application from the outside, simulating attacks, but it cannot identify which open-source libraries are used or their specific CVEs.

47
MCQmedium

A company is migrating critical workloads to AWS and must secure data at rest. They need to maintain control over the encryption keys. Which service should they use to meet this requirement?

A.AWS Secrets Manager
B.AWS Certificate Manager (ACM)
C.AWS CloudHSM
D.AWS Shield
AnswerC

CloudHSM provides dedicated, single-tenant hardware security modules where the organisation retains sole control of key material; AWS cannot access the keys. This satisfies the stem's requirement to maintain control over encryption keys for data at rest, unlike KMS, where AWS manages the underlying key infrastructure.

Why this answer

AWS CloudHSM provides dedicated hardware security modules that give the customer full control over encryption keys, including key generation, storage, and management. It meets the requirement of maintaining control over keys for data at rest because the keys are stored in tamper-resistant hardware and are not accessible to AWS. Other services like Secrets Manager and ACM manage keys but do not offer the same level of customer-controlled key custody.

Exam trap

CAS-005 often tests the difference between key management services, and candidates may confuse CloudHSM with KMS or Secrets Manager, overlooking the need for dedicated hardware control.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is for storing and rotating secrets like database credentials, not for managing encryption keys for data at rest. Option B is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates, not encryption keys for data at rest. Option D is wrong because AWS Shield is a DDoS protection service, unrelated to encryption key management.

48
MCQeasy

Which of the following is a benefit of using an immutable infrastructure approach?

A.Reduced need for configuration management
B.Easier manual patching of running servers
C.Elimination of configuration drift
D.Lower cost due to reusable hardware
AnswerC

Immutable infrastructure replaces servers rather than modifying them in place, so every deployment starts from an identical known image. Because running instances are never patched or hand-edited, configuration drift between environments is eliminated, which is the stated benefit.

Why this answer

Immutable infrastructure means servers are never modified in place — instead, new instances are built from a known-good image and old ones are replaced. This eliminates configuration drift because every instance is identical to its image, and any change requires a new image and redeployment. Manual patching and hardware reuse are not benefits of this model.

Exam trap

CAS-005 often tests the misconception that immutable infrastructure means 'no configuration management' or 'easier manual patching' — the trap is confusing immutability with reduced operational discipline, when it actually shifts discipline to image pipelines.

How to eliminate wrong answers

Option A is wrong because immutable infrastructure does not reduce the need for configuration management — it shifts it to image build time (e.g., Packer, Ansible in the image pipeline), so configuration management is still required, just applied earlier. Option B is wrong because immutable infrastructure explicitly discourages manual patching of running servers; patching is done by rebuilding images and replacing instances, not by logging in and updating live systems. Option D is wrong because immutable infrastructure does not inherently lower cost through reusable hardware — it often increases resource churn (new instances replace old), and cost benefits come from elasticity and right-sizing, not hardware reuse.

49
MCQmedium

A company is adopting a defense-in-depth strategy. Which of the following is an example of a preventive control at the network layer?

A.Intrusion Detection System (IDS)
B.Security Information and Event Management (SIEM)
C.Network segmentation
D.Penetration testing
AnswerC

Network segmentation restricts lateral movement by dividing the network into isolated zones with enforced access rules, blocking traffic before it reaches targets. This preventive, network-layer control satisfies the defense-in-depth requirement by stopping intrusion attempts rather than merely detecting them.

Why this answer

Network segmentation is a preventive control because it proactively restricts lateral movement by dividing the network into isolated segments using firewalls, VLANs, or subnets. This limits an attacker's ability to move freely after compromising a host, thereby preventing the spread of an attack. It operates at the network layer (Layer 3) and enforces access control policies between segments, making it a classic example of a preventive control in a defense-in-depth strategy.

Exam trap

The trap here is confusing detective controls (IDS, SIEM) with preventive controls; candidates often assume that monitoring tools prevent attacks, but they only detect and alert.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) is a detective control—it monitors and alerts on malicious activity but does not prevent it. Option B is wrong because a SIEM is also a detective and logging control that aggregates and correlates events for analysis, not prevention. Option D is wrong because penetration testing is an assessment or testing control that identifies vulnerabilities but does not prevent attacks; it is not a preventive control at the network layer.

50
MCQmedium

During a threat modeling exercise for a new web application, the team identifies a risk of API abuse due to lack of rate limiting. Which security control should be implemented at the API gateway to mitigate this risk?

A.Input validation
B.OAuth 2.0 scopes
C.Rate limiting policies
D.JWT token expiration
AnswerC

Rate limiting policies at the API gateway cap the number of requests a client may make within a defined window, throttling or blocking excessive calls. This directly mitigates the identified API abuse risk arising from absent rate limiting.

Why this answer

Rate limiting policies are the direct control to mitigate API abuse by restricting the number of requests a client can make within a time window. Implemented at the API gateway, they prevent denial-of-service, brute-force, and excessive consumption of backend resources. While other controls like input validation or OAuth scopes address different threats, rate limiting specifically targets the risk of API abuse due to lack of throttling.

Exam trap

CAS-005 often tests the confusion between authentication/authorisation controls (OAuth scopes, JWT expiration) and availability/abuse controls (rate limiting) — candidates must match the control to the specific risk of API abuse via excessive requests.

How to eliminate wrong answers

Option A is wrong because input validation protects against injection attacks (e.g., SQLi, XSS) by ensuring data conforms to expected formats, but it does not limit the volume or frequency of API calls, so it cannot mitigate abuse via excessive requests. Option B is wrong because OAuth 2.0 scopes define authorisation boundaries (what resources a token can access), not how often; they do not prevent a legitimate token from being used to flood the API. Option D is wrong because JWT token expiration limits the lifetime of a token, reducing the window for misuse if stolen, but it does not throttle request rates and thus does not address API abuse through high-frequency calls.

51
MCQhard

An organization is implementing network segmentation to limit lateral movement. It wants to isolate application tiers at the virtual network level in a cloud environment. Which technology enforces policies on east-west traffic between VMs in different subnets?

A.Micro-segmentation
B.Transport Layer Security (TLS)
C.Virtual Private Network (VPN)
D.Secure Access Service Edge (SASE)
AnswerA

Micro-segmentation enforces granular, workload-level policies on east-west traffic, isolating application tiers across subnets within a virtual network. Unlike perimeter controls, it inspects inter-VM flows directly, satisfying the requirement to limit lateral movement between tiers at the virtual network level.

Why this answer

Micro-segmentation enforces security policies at the virtual network level, isolating workloads (e.g., VMs in different subnets) and controlling east-west traffic between them. It typically uses distributed firewalls or security groups applied to individual workloads, allowing granular policy enforcement regardless of subnet boundaries. This directly limits lateral movement by ensuring that even if an attacker compromises one VM, they cannot freely communicate with others.

Exam trap

CAS-005 often tests the confusion between connectivity technologies (VPN, TLS) and segmentation technologies (micro-segmentation) — candidates must recognise that only micro-segmentation enforces east-west policies between VMs in different subnets.

How to eliminate wrong answers

Option B is wrong because TLS is a cryptographic protocol for securing data in transit (encryption and authentication), not a segmentation technology; it does not enforce network-level access policies between VMs. Option C is wrong because a VPN extends a private network over a public network (e.g., site-to-site or remote access), but it does not provide micro-segmentation or east-west traffic control within a cloud environment; it is about secure connectivity, not isolation. Option D is wrong because SASE is a cloud-delivered architecture converging networking (SD-WAN) and security (SWG, CASB, ZTNA) for branch and remote users, not a mechanism for enforcing east-west policies between VMs in different subnets within a cloud VPC.

52
MCQmedium

A security architect is designing a zero-trust architecture for a multi-cloud environment. Which principle is essential for enforcing identity-centric micro-segmentation?

A.Identity-based access policies
B.VPN concentrators
D.Perimeter firewalls
AnswerA

Identity-based access policies evaluate each request against user identity and context rather than network location, which is what enables micro-segmentation to be enforced per identity across multiple clouds. Network-centric controls alone cannot deliver identity-centric segmentation in a multi-cloud estate.

Why this answer

Identity-based access policies are essential for zero-trust micro-segmentation because they authorize every request based on the verified identity of the user, device, or workload — not on network location. In a multi-cloud zero-trust model, policy decisions follow the identity (via IAM, OIDC, SPIFFE, or mTLS) so that workloads are segmented by who they are, not where they sit. This is the core of identity-centric micro-segmentation.

Exam trap

The trap is equating network controls (VPNs, firewalls, NAT) with zero-trust — candidates pick perimeter firewalls because they 'segment the network,' but zero-trust requires identity-based, per-request authorization, not location-based trust.

How to eliminate wrong answers

Option B is wrong because VPN concentrators extend network-level trust — once connected, a user often has broad access, which contradicts zero-trust's 'never trust, always verify' model. Option C is wrong because NAT is an address-translation mechanism for connectivity and IP conservation; it provides no identity-based authorization. Option D is wrong because perimeter firewalls enforce coarse, location-based trust at the network edge, which zero-trust explicitly rejects in favor of per-request, identity-driven decisions.

53
MCQmedium

An organization wants to enforce consistent security policies across multiple cloud providers (AWS, Azure, GCP). Which tool is designed to continuously monitor and remediate misconfigurations in cloud environments?

A.Cloud Access Security Broker (CASB)
B.Security Information and Event Management (SIEM)
C.Cloud Workload Protection Platform (CWPP)
D.Cloud Security Posture Management (CSPM)
AnswerD

CSPM continuously monitors multi-cloud infrastructure for misconfigurations and automatically remediates drift, satisfying the requirement to enforce consistent policy across AWS, Azure and GCP. Unlike native tools that operate within a single provider, CSPM normalises posture assessment across heterogeneous environments, directly addressing the cross-provider constraint in the stem.

Why this answer

CSPM (Cloud Security Posture Management) tools are purpose-built to continuously scan multi-cloud environments (AWS, Azure, GCP) against benchmarks like CIS, NIST, and PCI DSS, detecting misconfigurations such as public S3 buckets, overly permissive IAM roles, or unencrypted storage. They provide automated remediation workflows and drift detection across providers, which is exactly what the organization needs for consistent policy enforcement. CASB, SIEM, and CWPP address different layers (data access, log correlation, workload runtime) and do not natively deliver cross-cloud configuration posture management.

Exam trap

CAS-005 often tests the confusion between CSPM (configuration posture) and CWPP (runtime workload protection) or CASB (data access control), so candidates must map the keyword 'misconfiguration' specifically to CSPM.

How to eliminate wrong answers

Option A is wrong because a CASB governs access to cloud services and enforces data-centric policies (DLP, shadow IT discovery) rather than continuously scanning infrastructure configurations for misconfigurations. Option B is wrong because a SIEM aggregates and correlates log/event data for detection and response; it does not perform configuration assessment or automated remediation of cloud resources. Option C is wrong because a CWPP protects running workloads (VMs, containers, serverless) at runtime via vulnerability scanning and behavioral monitoring, not the cloud control plane's configuration posture.

54
MCQeasy

In the shared responsibility model for cloud security, which of the following is generally the responsibility of the cloud customer?

A.Configuration of network access controls
B.Hardware maintenance of servers
C.Hypervisor vulnerability patching
D.Physical security of data centers
AnswerA

Under the shared responsibility model, the provider secures the cloud infrastructure, but customers configure their own network access controls, security groups and firewall rules. This makes network access control configuration a customer responsibility, matching the stem's question.

Why this answer

In the cloud shared responsibility model, the customer is always responsible for 'security IN the cloud' — their data, configurations, and access controls. Network access control configuration (security groups, NACLs, firewall rules) is a customer-managed setting in IaaS/PaaS, so option A is correct. The provider handles 'security OF the cloud' — physical, host, and hypervisor layers.

Exam trap

CAS-005 often tests the misconception that the cloud provider secures everything once data is migrated, when in fact the customer retains responsibility for configuration, identity, and data protection layers.

How to eliminate wrong answers

Option B is wrong because hardware maintenance of servers is performed by the cloud provider, who owns and operates the physical infrastructure. Option C is wrong because hypervisor vulnerability patching is a provider responsibility — the hypervisor sits below the customer's visibility boundary in IaaS and is fully managed in PaaS/SaaS. Option D is wrong because physical security of data centers is always the provider's responsibility, as customers have no physical access to cloud facilities.

55
MCQmedium

A security architect is designing a zero trust architecture for a company with a large remote workforce. The requirement is to verify device health and user identity for every session to internal applications, regardless of network location, and to prevent session hijacking after initial authentication. Which of the following BEST meets these requirements?

A.Require all remote users to connect through a cloud access security broker (CASB) that applies data loss prevention policies to cloud applications.
B.Use a reverse proxy with mutual TLS client certificates and enforce certificate revocation checks at each connection.
C.Implement a zero trust network access (ZTNA) service that continuously evaluates identity and device posture and issues per-session, context-bound tokens.
D.Deploy a VPN concentrator with split tunneling and require users to authenticate with a username and password plus a one-time code.
AnswerC

ZTNA brokers access per application based on continuous evaluation of user identity and device posture, and it issues context-bound tokens that are validated for each session. This prevents session hijacking because tokens are tied to the session context and cannot be replayed from a different device or location, meeting both requirements.

Why this answer

ZTNA continuously evaluates identity and device posture and issues per-session tokens bound to context, so every access request is verified regardless of network location. Because tokens are tied to the session and device context, a stolen token cannot be replayed elsewhere, which directly prevents session hijacking after initial authentication.

Exam trap

The trap here is treating strong initial authentication such as VPN with MFA or mutual TLS as sufficient, when zero trust requires continuous per-session verification and context-bound tokens to prevent session hijacking.

56
MCQmedium

An organization uses a multi-cloud strategy with workloads on AWS, Azure, and GCP. They need a single tool to monitor and enforce security configurations across all cloud environments. Which cloud security solution is best suited for this requirement?

A.Secure Access Service Edge (SASE)
B.Cloud Access Security Broker (CASB)
C.Cloud Workload Protection Platform (CWPP)
D.Cloud Security Posture Management (CSPM)
AnswerD

CSPM continuously assesses configurations against benchmarks and compliance frameworks across AWS, Azure and GCP through native APIs, satisfying the single-tool, multi-cloud monitoring and enforcement constraint. It detects misconfigurations such as public storage buckets and overly permissive IAM policies, unlike single-cloud native tooling.

Why this answer

CSPM is correct because it continuously monitors cloud configurations against security benchmarks (CIS, NIST, PCI) and detects misconfigurations across AWS, Azure, and GCP from a single pane of glass. It is purpose-built for multi-cloud posture management — identifying publicly exposed buckets, overly permissive IAM roles, and unencrypted storage. This directly matches the requirement to monitor and enforce security configurations across all three clouds.

Exam trap

CAS-005 often tests the CSPM vs. CWPP vs. CASB distinction — candidates pick CWPP or CASB because they 'secure the cloud,' but only CSPM continuously monitors and enforces configuration posture across multiple clouds.

How to eliminate wrong answers

Option A is wrong because SASE converges networking and security (SD-WAN, SWG, ZTNA, CASB) at the network edge for user traffic — it does not assess cloud resource configurations. Option B is wrong because CASB governs access to and data in cloud services (shadow IT, DLP, API control), not the security posture of cloud infrastructure. Option C is wrong because CWPP protects running workloads (VMs, containers, serverless) at runtime — it addresses workload security, not configuration compliance across cloud accounts.

57
MCQmedium

An organization is implementing a Secure Access Service Edge (SASE) architecture. Which of the following is a key component of SASE?

A.Demilitarized Zone (DMZ)
B.Cloud Access Security Broker (CASB)
C.Intrusion Prevention System (IPS)
D.Virtual Private Network (VPN)
AnswerB

A CASB enforces data-security policy between users and cloud services, delivering the threat protection, data-loss prevention and visibility SASE requires for cloud-bound traffic. It satisfies the stem's SASE component requirement because SASE converges networking with exactly these cloud-security functions, alongside SWG, ZTNA and FWaaS, rather than relying on on-premises appliances.

Why this answer

SASE (Secure Access Service Edge) converges networking (SD-WAN) with a stack of cloud-delivered security services, and CASB is one of its core security pillars alongside SWG, ZTNA, and FWaaS. CASB provides visibility and control over cloud application usage, enforces DLP, and detects shadow IT — functions that SASE delivers from a globally distributed edge. DMZ, IPS, and VPN are traditional on-premises or point-solution constructs that SASE is explicitly designed to replace or absorb, not core defining components.

Exam trap

CAS-005 often tests whether candidates can distinguish SASE's core components (CASB, SWG, ZTNA, FWaaS, SD-WAN) from legacy security appliances like DMZ, IPS, and VPN that SASE replaces.

How to eliminate wrong answers

Option A is wrong because a DMZ is a legacy network segmentation pattern for hosting public-facing services; SASE eliminates the need for backhauling traffic to a DMZ by enforcing policy at the cloud edge. Option C is wrong because an IPS is a network security appliance/function; while FWaaS within SASE may include IPS capabilities, IPS itself is not a named core SASE component. Option D is wrong because a traditional VPN is a remote-access tunneling technology that SASE supersedes with ZTNA's identity-based, per-application access model.

58
MCQhard

During an API security review, an assessor finds that the API uses JSON Web Tokens (JWT) with a symmetric key shared among multiple services. Which of the following is the MOST significant security concern?

A.The token is not encrypted
B.Multiple services share the same symmetric key
C.The token does not include audience claim
D.Token expiration is not set
AnswerB

A shared symmetric key means any compromised service can forge valid tokens for every other service, breaking per-service authentication boundaries. Asymmetric signing with per-service keys, or centralised issuance, would contain the blast radius of a single compromised credential.

Why this answer

The most significant security concern is that multiple services share the same symmetric key. With a shared symmetric key, any service can forge tokens that are accepted by other services, leading to a lack of non-repudiation and increased blast radius if one service is compromised. This violates the principle of least privilege and increases the risk of token forgery.

Exam trap

CAS-005 often tests the misconception that encryption is the primary concern for JWTs, but the bigger risk is often key management and sharing, which enables token forgery.

How to eliminate wrong answers

Option A is wrong because while not encrypting the token (using JWS instead of JWE) means the payload is readable, it is not the most significant concern if the token is transmitted over HTTPS and contains no sensitive data; integrity is still protected. Option C is wrong because missing audience claim can lead to token misuse across services, but it is less severe than a shared symmetric key, as the audience claim is a defense-in-depth measure. Option D is wrong because missing expiration increases the window of opportunity for token misuse, but again, it is less critical than a shared key that allows token forgery.

59
MCQmedium

A security architect is reviewing the identity architecture for a company that uses a hybrid cloud. Employees authenticate to an on-premises Active Directory Domain Services (AD DS) domain and also need to access SaaS applications. The company wants to avoid storing separate passwords for each SaaS application and wants to enforce on-premises account status and group membership in real time. Which of the following should the architect implement?

A.Deploy a standalone LDAP directory in the cloud and synchronize user passwords from AD DS using a one-way hash, then point each SaaS application to the cloud LDAP service.
B.Configure each SaaS application with a separate local account for every employee, and use a password manager to generate and store unique passwords.
C.Implement RADIUS authentication between the SaaS applications and the on-premises AD DS, and rely on RADIUS attributes to convey group membership.
D.Federate the on-premises AD DS with each SaaS application using SAML 2.0, and configure the SaaS applications to trust the on-premises identity provider.
AnswerD

Federating AD DS with SAML 2.0 allows the on-premises domain to act as the identity provider, so employees use their existing AD credentials and the SaaS application receives assertions about group membership and account status. This avoids separate passwords and enforces on-premises account state in real time because the identity provider evaluates the account at each authentication. It is the standard approach for hybrid identity with SaaS.

Why this answer

Federating on-premises AD DS with SAML 2.0 makes the domain the identity provider for SaaS applications. Users authenticate once with their AD credentials, and the SaaS application receives assertions about group membership and account status at each login. This satisfies the requirements for no separate passwords and real-time enforcement of on-premises account state, unlike cloud LDAP, local accounts, or RADIUS.

Exam trap

The trap here is confusing authentication protocols that sound similar, such as LDAP or RADIUS, with the SAML federation that SaaS applications actually use for browser-based single sign-on.

60
MCQeasy

Which of the following is a primary function of a Cloud Access Security Broker (CASB)?

A.Scan container images for vulnerabilities
B.Provide IAM for cloud infrastructure
C.Enforce security policies between users and cloud applications
D.Monitor network traffic at the packet level
AnswerC

A CASB sits inline or via APIs between users and cloud services, enforcing policy at that boundary. This directly satisfies the stem's requirement for a primary function: it governs access and data flows to sanctioned and unsanctioned cloud applications, providing visibility and control.

Why this answer

A CASB sits between users and cloud applications and enforces security policies such as data loss prevention, access control, encryption, and compliance monitoring. Its core purpose is to provide visibility and control over cloud service usage, which is exactly what Option C describes.

Exam trap

CAS-005 often tests the boundary between CASB and adjacent technologies — candidates confuse CASB with IAM, container security, or network monitoring because all involve 'cloud security'.

How to eliminate wrong answers

Option A is wrong because scanning container images for vulnerabilities is the function of a container security scanner (e.g., Trivy, Aqua, Twistlock), not a CASB. Option B is wrong because IAM for cloud infrastructure is provided by the cloud provider's native IAM service (e.g., AWS IAM, Azure Entra ID) or third-party IAM tools, not a CASB. Option D is wrong because packet-level network monitoring is performed by firewalls, IDS/IPS, or network TAPs — a CASB operates at the application/API layer, not the packet layer.

61
MCQmedium

Which of the following is a key feature of TLS 1.3 compared to earlier versions?

A.Mandatory use of static RSA key exchange
B.Support for RC4 cipher
C.Backward compatibility with SSL 3.0
D.Reduced handshake latency
AnswerD

TLS 1.3 cuts the handshake to a single round trip by combining key exchange and authentication, and supports zero round-trip resumption for repeat connections. This directly satisfies the question's comparison against earlier versions, which required two round trips, thereby reducing latency.

Why this answer

TLS 1.3 reduces handshake latency by combining the ClientHello and key share into a single round trip (1-RTT) and supporting 0-RTT resumption for repeat connections. It also removes legacy features like static RSA key exchange, RC4, and SSL 3.0 compatibility. The net effect is faster connection establishment without sacrificing security.

Exam trap

CAS-005 often tests the misconception that TLS 1.3 is merely an incremental update — candidates must remember it removed legacy algorithms and backward compatibility rather than adding them.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 removed static RSA key exchange entirely, mandating forward-secret key exchanges like ECDHE. Option B is wrong because RC4 was deprecated and removed from TLS 1.3 due to known cryptographic weaknesses. Option C is wrong because TLS 1.3 explicitly dropped backward compatibility with SSL 3.0 (and even TLS 1.0/1.1) to eliminate downgrade attacks.

62
MCQhard

A government agency is designing a system that processes highly sensitive data on a need-to-know basis. The security architect must ensure that access decisions consider the user's clearance level, the data's classification label, and the user's current role, and that users cannot change their own labels. Which of the following access control models best fits these requirements?

A.Role-based access control, where permissions are assigned to roles and users are placed into roles by their manager.
B.Discretionary access control, where data owners set permissions on the objects they own.
C.Attribute-based access control, where a policy evaluates any combination of user, resource, and environment attributes.
D.Mandatory access control, where the system compares the subject's clearance and the object's classification label and enforces the result.
AnswerD

Mandatory access control enforces access decisions by comparing the subject's clearance level with the object's classification label, and the labels are managed by the system rather than by users. This directly satisfies the requirement to consider clearance and classification together and prevents users from changing their own labels. It is the standard model for need-to-know enforcement in government and defense environments handling sensitive data.

Why this answer

Mandatory access control is designed for environments where the system, not the user, manages sensitivity labels and clearance levels. It compares the subject's clearance to the object's classification and enforces the result, which directly implements need-to-know. Role-based and discretionary models lack this mandatory label comparison, and attribute-based access control, while flexible, does not inherently guarantee that labels remain outside user control.

Exam trap

The trap here is assuming that any model which can evaluate multiple attributes is equivalent to mandatory access control, when the defining property is that labels are system-managed and not user-modifiable.

63
MCQmedium

A company is required to comply with FedRAMP for its cloud deployment. Which of the following is a key requirement for FedRAMP compliance?

A.Continuous monitoring and incident response
B.Third-party assessment by an accredited organization
C.Implementation of AES-256 encryption for all data
D.Annual penetration testing by internal team
AnswerB

FedRAMP requires an independent assessment by a Third-Party Assessment Organization accredited under the programme, which validates the cloud service's security controls against NIST baselines before an agency can grant authorisation. This external evaluation is the key requirement the stem asks for.

Why this answer

FedRAMP requires that cloud service offerings undergo an independent third-party assessment by a FedRAMP-accredited Third Party Assessment Organization (3PAO) to validate security controls against NIST SP 800-53. This assessment is a cornerstone of the FedRAMP authorization process, ensuring an unbiased evaluation before a Joint Authorization Board (JAB) or agency grants an Authority to Operate (ATO). While continuous monitoring and incident response are also required, the key differentiator is the mandatory third-party assessment.

Exam trap

CAS-005 often tests the misconception that FedRAMP is just about encryption or continuous monitoring — candidates must recognise that the mandatory third-party assessment by an accredited 3PAO is the defining requirement.

How to eliminate wrong answers

Option A is wrong because continuous monitoring and incident response, while required by FedRAMP, are also common to many frameworks (e.g., FISMA, ISO 27001) and are not unique to FedRAMP; the question asks for a key requirement that distinguishes FedRAMP. Option C is wrong because AES-256 encryption is a best practice and often required for data at rest, but FedRAMP does not mandate a specific algorithm; it requires encryption based on NIST guidelines, which may include AES-256 but also allows other FIPS 140-2 validated algorithms. Option D is wrong because annual penetration testing by an internal team is not a FedRAMP requirement; FedRAMP requires annual penetration testing by a 3PAO or qualified independent party, and continuous monitoring includes vulnerability scanning.

64
MCQhard

A financial services firm is designing a new internal API platform. The security architect must ensure that every service-to-service call is authenticated, that a compromised service cannot impersonate another service, and that credentials are short-lived and automatically rotated. The platform runs on Kubernetes and uses an external secrets manager. Which of the following designs best meets these requirements?

A.Rely on network policies that restrict pod-to-pod traffic to approved namespaces and assume that only authorized services can reach each other.
B.Issue a long-lived shared API key to each service and store it in a Kubernetes Secret mounted as an environment variable.
C.Use mutual TLS with certificates issued by a service mesh certificate authority that binds each certificate to the service's Kubernetes service account and rotates it automatically.
D.Require services to present a JSON Web Token signed with a symmetric key that is distributed to all services in the cluster.
AnswerC

Mutual TLS with certificates bound to a Kubernetes service account gives each service a cryptographic identity that cannot be transferred to another service without its private key. A service mesh certificate authority can issue short-lived certificates and rotate them automatically, and the service account binding ensures a compromised pod cannot claim a different service identity. This satisfies authentication, non-impersonation, and automated rotation in one design.

Why this answer

Binding a cryptographic identity to each service's Kubernetes service account through a service mesh certificate authority ensures that a compromised service cannot present another service's identity. Mutual TLS authenticates both ends of every call, and the mesh can issue short-lived certificates and rotate them automatically without manual intervention. The other options either share secrets across services, rely only on network reachability, or use long-lived credentials that are not bound to a specific service identity.

Exam trap

The trap here is treating network segmentation or a shared secret as equivalent to cryptographic service identity, when only a per-service credential bound to an identity prevents impersonation.

65
Multi-Selecthard

A company is implementing a secure SDLC and wants to integrate application security testing early. Which THREE tools are most appropriate for shift-left security? (Select THREE.)

Select 3 answers
A.Runtime Application Self-Protection (RASP)
B.Static Application Security Testing (SAST)
C.Interactive Application Security Testing (IAST)
D.Software Composition Analysis (SCA)
E.Dynamic Application Security Testing (DAST)
AnswersB, C, D

SAST analyses source code without executing it, detecting vulnerabilities during development and satisfying shift-left by finding flaws before deployment. It integrates into CI pipelines and IDEs, unlike DAST, which requires a running application and therefore tests later in the lifecycle.

Why this answer

SAST (B) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find vulnerabilities like injection flaws during coding in the IDE or CI pipeline — the essence of shift-left. IAST (C) is correct because it instruments the running application (often via agents) during functional testing to detect vulnerabilities in real time with code-level detail, fitting early integration into dev/test workflows. SCA (D) is correct because it scans dependencies and third-party libraries for known CVEs and license issues, which is critical for shifting left since most modern code is composed of open-source components.

RASP (A) is not appropriate here because it runs inside the application at runtime in production, protecting against live attacks rather than enabling early pre-deployment testing. DAST (E) is not selected because it tests a deployed running application from the outside (black-box), typically later in the pipeline, making it less aligned with early shift-left integration than SAST, IAST, and SCA.

66
MCQeasy

An organization is adopting a cloud-first strategy and wants to ensure proper security responsibilities are understood. Which concept defines the division of security responsibilities between the cloud provider and the customer?

A.Zero trust
B.Shared responsibility model
C.Software-defined perimeter
D.Defense in depth
AnswerB

The shared responsibility model defines the security boundary between provider and customer, satisfying the cloud-first scenario's need to clarify who secures what. The provider secures the cloud infrastructure, while the customer secures data, identities, and access in the cloud. This division varies by service model (IaaS, PaaS, SaaS), directly answering the stem's requirement.

Why this answer

The shared responsibility model defines which security tasks are handled by the provider (e.g., physical security) and which by the customer (e.g., data access).

67
MCQmedium

A security architect is designing a microsegmentation strategy for a data center hosting a three-tier application (web, application, database). The organization wants to enforce least-privilege east-west traffic without relying on IP addresses, and must ensure that workloads can move between hypervisors without requiring rule changes. Which technology best meets these requirements?

A.A next-generation firewall deployed at the perimeter with application-aware rules
B.Software-defined networking with distributed firewalls that apply policy based on workload identity tags
C.VLAN segmentation with access control lists applied on the core switch
D.Host-based intrusion prevention systems installed on each virtual machine
AnswerB

Distributed firewalls in an SDN fabric enforce policy at the hypervisor level using workload identity tags rather than IP addresses. This allows rules to follow the workload as it migrates between hosts, maintaining least-privilege east-west controls. It directly satisfies the requirements of identity-based enforcement and mobility without rule changes, making it the correct architectural choice.

Why this answer

Microsegmentation requires granular, identity-based policy enforcement for east-west traffic that remains consistent as workloads move. Distributed firewalls integrated with SDN use workload tags to apply rules regardless of IP changes, providing least-privilege segmentation. Perimeter firewalls, VLAN ACLs, and host IPS lack the combination of identity awareness and mobility support needed here.

Exam trap

The trap here is assuming that traditional VLAN segmentation or perimeter firewalls provide sufficient microsegmentation, when they actually depend on static IP addresses and cannot follow mobile workloads.

68
MCQhard

A healthcare provider is designing a data protection scheme for patient records stored in a cloud object store. Regulatory requirements mandate that encryption keys never leave the organization's on-premises hardware security modules (HSMs), while the cloud provider must still be able to perform server-side encryption on upload. The architect needs a key management approach that satisfies both constraints. Which of the following should the architect implement?

A.Provider-managed customer master keys stored in the cloud KMS
B.Client-side encryption with locally generated data keys
C.External key store backed by on-premises HSMs integrated with the cloud KMS
D.Envelope encryption using a customer-provided key uploaded to the KMS
AnswerC

An external key store lets the cloud KMS delegate cryptographic operations to key material held in the organization's own HSM, so plaintext keys never enter the provider's infrastructure. The provider still performs server-side encryption using the externally held key, satisfying both the residency mandate and the server-side encryption requirement. This is the designed pattern for exactly this regulatory scenario.

Why this answer

An external key store keeps the root key material inside the organization's HSMs while allowing the cloud KMS to call out for encrypt and decrypt operations, so server-side encryption still occurs without the provider holding plaintext keys. This satisfies the dual constraint of regulatory key residency and provider-side encryption. The other approaches either place key custody with the provider or shift encryption to the client, breaking one of the two requirements.

Exam trap

The trap here is treating any customer-controlled key option as equivalent, when importing a key into the cloud KMS still transfers custody to the provider.

69
MCQmedium

A multinational corporation is designing a hybrid cloud architecture that spans an on-premises data center and two public cloud regions. The security architect needs to ensure that all administrative access to cloud resources is brokered through a central identity provider, that access decisions consider device posture, and that no long-lived credentials are stored in the cloud. Which combination of technologies should the architect implement?

A.SAML federation with the on-premises identity provider and role-based access control (RBAC) in each cloud
B.A cloud identity provider with SAML/OIDC federation, conditional access policies, and short-lived credentials issued via just-in-time elevation
C.OIDC federation combined with a cloud access security broker (CASB) and just-in-time access
D.A hardware security module (HSM) for key storage and a VPN for administrative access
AnswerB

Federation through SAML or OIDC centralizes authentication with the identity provider, while conditional access policies evaluate device posture and other signals. Just-in-time elevation issues short-lived credentials, eliminating long-lived secrets in the cloud. Together, these satisfy all three architectural requirements.

Why this answer

Centralizing administrative access through federation, evaluating device posture with conditional access, and issuing short-lived credentials via just-in-time elevation collectively meet the requirements. This design removes long-lived credentials from the cloud and ensures that access decisions are context-aware, which is essential for a hybrid, multi-region architecture.

Exam trap

The trap here is assuming that federation alone eliminates long-lived credentials, when in fact static service accounts often persist unless just-in-time access is also implemented.

70
Multi-Selecthard

A security architect is designing a Zero Trust architecture for a multinational corporation. The organization wants to enforce least-privilege access to applications based on device health, user identity, and contextual factors, and it requires continuous verification of trust. Which TWO of the following are core enforcement mechanisms that should be implemented to achieve these goals? (Choose two.)

Select 2 answers
A.Microsegmentation with identity-based policies
B.Static VPN access with split tunneling for all employees
C.A single-factor password authentication for all internal applications
D.Implicit trust for devices on the corporate LAN
E.Policy Decision Point (PDP) and Policy Enforcement Point (PEP) separation
AnswersA, E

Microsegmentation with identity-based policies enforces least-privilege access between workloads and applications by using identity and context rather than IP addresses. It supports continuous verification and limits lateral movement, aligning with Zero Trust. This mechanism is essential for dynamically controlling access based on device health and user identity.

Why this answer

The PDP/PEP separation and microsegmentation with identity-based policies are core Zero Trust enforcement mechanisms. The PDP/PEP model enables dynamic, context-aware access decisions, while identity-based microsegmentation enforces least privilege and limits lateral movement, together supporting continuous verification and device health evaluation.

Exam trap

The trap here is assuming that network location such as the corporate LAN or a VPN implies trust, when Zero Trust explicitly rejects implicit trust and requires continuous, context-aware verification.

71
MCQhard

An organization is deploying a containerized application on Kubernetes and must enforce that only approved container images are allowed to run, and that containers cannot escalate privileges. Which combination of controls should the architect implement?

A.Seccomp and AppArmor profiles with RBAC
B.Kubernetes network policies and RBAC
C.Admission controllers with image signing and PodSecurityPolicy
D.Container image scanning and network policies
AnswerC

Admission controllers intercept API requests before pods are created, rejecting unsigned or unapproved images, while PodSecurityPolicy restricts privileged escalation and capability use. Together they enforce image provenance and prevent privilege escalation, matching both stem constraints.

Why this answer

Admission controllers are the Kubernetes mechanism that intercepts API server requests before objects are persisted, so they can reject pods that violate policy. Combined with image signing (e.g., via cosign/Notary or an admission webhook that verifies signatures), they enforce that only approved images run. PodSecurityPolicy (or its successor, Pod Security Admission with restricted/baseline profiles) blocks privilege escalation by restricting privileged containers, hostPath mounts, and capabilities.

Exam trap

CAS-005 often tests the misconception that runtime hardening tools like Seccomp/AppArmor or RBAC alone satisfy 'only approved images' requirements, when admission control plus image signing is the actual enforcement point.

How to eliminate wrong answers

Option A is wrong because Seccomp and AppArmor constrain syscall and file-access behavior at runtime but do not gate which images are admitted or prevent privileged pod specs from being scheduled; RBAC only governs API verbs, not workload content. Option B is wrong because network policies only control pod-to-pod traffic flows and RBAC only controls API authorization — neither validates image provenance nor blocks privileged containers. Option D is wrong because image scanning detects vulnerabilities after the fact but does not enforce admission of only signed images, and network policies do not address privilege escalation.

72
Multi-Selectmedium

A security architect is reviewing supply chain security for a software product. Which TWO artifacts are most important for verifying the integrity and provenance of third-party components?

Select 2 answers
A.Penetration test results
B.Software bill of materials (SBOM)
C.Dependency analysis report
D.Network flow logs
E.Database encryption configuration
AnswersB, C

An SBOM enumerates every component and version in the product, giving the inventory needed to trace third-party dependencies. Combined with provenance attestation, it lets the architect verify what was supplied and detect tampering or unexpected inclusions, satisfying the integrity and provenance requirement.

Why this answer

Option B, the software bill of materials (SBOM), is correct because it enumerates every third-party and open-source component, library, and version in the product, which is the foundation for verifying provenance and detecting tampered or vulnerable dependencies. Option C, the dependency analysis report, is correct because it maps direct and transitive dependencies and flags known vulnerabilities, license conflicts, and unexpected or unvetted components, directly supporting integrity verification of the supply chain. Together, the SBOM provides the authoritative component inventory while the dependency analysis validates those components against known-good and known-bad data.

Option A, penetration test results, is not correct because pen testing assesses exploitable weaknesses in a running system, not the provenance or integrity of third-party components. Option D, network flow logs, is not correct because they record traffic metadata for monitoring and forensics, not component-level supply chain integrity. Option E, database encryption configuration, is not correct because it addresses data-at-rest protection and is unrelated to verifying third-party component provenance.

73
Multi-Selecthard

An organization is implementing a software-defined perimeter (SDP) for zero trust network access. Which THREE characteristics are typical of an SDP architecture? (Choose three.)

Select 3 answers
A.Relies on IP-based allowlists
B.Applications are invisible to unauthorized users
C.Creates encrypted tunnels per session
D.Uses a single shared firewall for all traffic
E.Requires device authentication before granting network access
AnswersB, C, E

SDP employs a deny-by-default model where the controller authenticates and authorises both endpoints before any connection is brokered, so applications never respond to unauthenticated probes. This satisfies the zero trust requirement that resources remain hidden from unauthorised users, mitigating scanning and reconnaissance.

Why this answer

Option B is correct because a core SDP principle is the "dark cloud" or black cloud model, where protected applications do not respond to unauthenticated probes and remain invisible until a user and device are authenticated and authorized by the controller. Option C is correct because SDP establishes dynamic, per-session encrypted connections (for example, mutual TLS or DTLS tunnels) between the initiating host and the accepting host, rather than granting broad network-level access. Option E is correct because SDP enforces device authentication and posture checks through the controller before any connection to the accepting host is brokered, which is fundamental to zero trust network access.

Option A is not correct because SDP deliberately moves away from static IP-based allowlists and perimeter rules, relying instead on identity- and context-based authorization. Option D is not correct because SDP does not funnel all traffic through a single shared firewall; it uses distributed controllers and gateways to broker individualized, least-privilege connections.

Exam trap

CAS-005 often tests the misconception that SDP is just a next-gen VPN or firewall, when its defining trait is application invisibility and identity-based per-session tunnels.

74
MCQeasy

A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?

A.Trust based on device compliance
B.Never trust, always verify
C.Trust based on network location
D.Trust but verify
AnswerB

Never trust, always verify requires every access request to be authenticated and authorised explicitly, regardless of network location, replacing implicit trust with continuous verification. This is the foundational tenet from which all other zero trust controls derive.

Why this answer

Zero trust assumes no implicit trust; every access request must be verified regardless of origin.

75
MCQmedium

A security architect is designing a hybrid identity solution for a company that wants to enforce device-based conditional access for Microsoft 365. Employees use personal Android and iOS devices, and the company wants to ensure that only compliant devices can access email and SharePoint. The architect must minimize on-premises infrastructure and avoid a full VPN. Which solution should the architect recommend?

A.Configure a full-tunnel VPN that routes all mobile traffic through the corporate network and enforce network access control (NAC) at the edge.
B.Implement Active Directory Federation Services (AD FS) with a Web Application Proxy and require certificate-based authentication for all devices.
C.Use Microsoft Entra ID with Security Defaults enabled and require multi-factor authentication (MFA) for all users.
D.Deploy Microsoft Entra ID with Conditional Access policies that require device compliance, and enroll devices in Microsoft Intune.
AnswerD

Entra ID Conditional Access can require that a device be marked compliant by Intune before granting access to Microsoft 365. Intune enforces device configuration and compliance on Android and iOS without requiring on-premises infrastructure or VPN, directly meeting the requirement to restrict access to compliant devices.

Why this answer

Microsoft Entra ID Conditional Access combined with Intune device compliance is the correct approach because it enforces device-based access decisions for cloud applications without requiring on-premises infrastructure or a full VPN. Conditional Access evaluates signals such as device compliance state and can block or grant access to Microsoft 365 accordingly, while Intune manages device configuration and compliance for both Android and iOS.

Exam trap

The trap here is assuming that multi-factor authentication alone satisfies a device-based conditional access requirement, when in fact device compliance must be evaluated and enforced through a management channel such as Intune.

Page 1 of 3 · 188 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Casp Security Architecture questions.