Courseiva

CAS-005 · topic practice

Security Architecture practice questions

Security Architecture is the largest CAS-005 domain, covering how you design resilient systems: secure SDLC, zero trust, hybrid cloud connectivity, cryptographic agility, and network segmentation. Questions are scenario-based, asking you to select controls, principles, or technologies that satisfy stated requirements rather than recall isolated definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Architecture

What the exam tests

What to know about Security Architecture

Map each scenario to the correct architecture control: pick NIST PQC algorithms by use case, assign SDLC activities to the right phase, apply zero trust principles, and choose dedicated private connectivity for hybrid cloud. The key skill is matching stated requirements to the single best-fit design choice.

Selecting NIST-standardized post-quantum algorithms for key encapsulation versus digital signatures

Choosing secure SDLC activities belonging to development, testing, and deployment phases

Applying zero trust principles such as least privilege and explicit verification to designs

Designing hybrid cloud connectivity using dedicated private links instead of public internet

Watch out for

Common Security Architecture exam traps

  • ▸Confusing post-quantum KEM algorithms with signature algorithms, or assuming all NIST selections serve the same cryptographic purpose
  • ▸Placing requirements, threat modeling, or security testing in the wrong SDLC phase when asked to choose activities
  • ▸Treating zero trust as a product or VPN replacement rather than an architecture of continuous verification and least privilege

Practice set

Security Architecture questions

20 questions · select your answer, then reveal the explanation

A company is deploying a cloud access security broker (CASB) to gain visibility into shadow IT. Which mode of operation would allow the CASB to inspect traffic without requiring proxy configuration on endpoints?

A security analyst needs to ensure that only authorized containers run in a Kubernetes cluster. Which Kubernetes native security control should be configured?

An organization wants to enforce that only signed container images are deployed in production. Which of the following should be implemented?

A company is implementing a defense-in-depth strategy for its web application. Which THREE of the following are layers that should be included? (Select THREE.)

A security engineer is deploying a Cloud Access Security Broker (CASB) to protect a SaaS application. Which deployment mode allows the CASB to inspect encrypted traffic without requiring client software?

A company needs to connect its on-premises data center to a public cloud provider with low latency and high bandwidth while avoiding the public internet. Which connectivity method should be used?

A security architect is reviewing a Secure Access Service Edge (SASE) implementation. Which component of SASE provides security inspection for all traffic, regardless of location?

An organization is implementing a CASB to secure their SaaS applications. Which CASB deployment mode is most appropriate for monitoring and controlling data in transit between users and cloud apps without modifying the user's device?

A company is deploying containers in a Kubernetes cluster and needs to enforce that containers run with reduced capabilities. Which Linux security feature should be configured to drop unnecessary capabilities?

An organization is concerned about future quantum computer attacks on their public key infrastructure. Which NIST-standardized algorithm is designed for digital signatures and is resistant to quantum attacks?

Question 11mediummulti select
Study the full AAA explanation →

An organization is hardening its Kubernetes cluster. Which THREE of the following are effective controls to limit the blast radius of a compromised container?

A company is migrating sensitive workloads to the cloud and must comply with FedRAMP requirements. Which of the following is the most appropriate cloud deployment model?

An organization is deploying a Kubernetes cluster and needs to harden security. Which THREE controls should be implemented? (Choose three.)

An organization is implementing a zero trust architecture and needs to enforce identity-centric access for all resources. Which THREE components are essential to this approach?

An organization is implementing SASE to secure remote user access. Which component of SASE is responsible for enforcing identity-based access policies and inspecting traffic?

A security engineer is integrating API security for a RESTful service. Which mechanism is used to verify that the API request has not been tampered with and originates from a legitimate client?

An organization is planning to adopt quantum-resistant cryptography. According to NIST PQC standards, which algorithm is recommended for digital signatures?

An organization is planning to adopt quantum-resistant cryptography. According to NIST PQC standards, which THREE algorithms are currently selected for standardization? (Select THREE).

An enterprise is securing a hybrid cloud environment with on-premises and AWS workloads. They need to ensure that on-premises systems can privately access VPC resources without traversing the public internet. Which AWS service should they use?

An organization is designing a PKI for certificate lifecycle management. Which TWO practices are critical for maintaining the security of the certificate authority (CA)? (Select TWO.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Architecture sessions

Start a Security Architecture only practice session

Every question in these sessions is drawn from the Security Architecture domain — nothing else.

Related practice questions

Related CAS-005 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CAS-005 exam test about Security Architecture?
Map each scenario to the correct architecture control: pick NIST PQC algorithms by use case, assign SDLC activities to the right phase, apply zero trust principles, and choose dedicated private connectivity for hybrid cloud. The key skill is matching stated requirements to the single best-fit design choice.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Architecture questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Architecture domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CAS-005 topics?
Use the topic links above to move to related areas, or go back to the CAS-005 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CAS-005 exam covers. They are not copied from any real exam or dump site.