Courseiva

CCNA Casp Security Architecture Questions

75 of 188 questions · Page 2/3 · Casp Security Architecture topic · Answers revealed

76
Multi-Selecthard

A security architect is designing a data loss prevention (DLP) program for a multinational retailer that processes payment card data and personally identifiable information. The program must discover sensitive data at rest across on-premises file shares and cloud storage, and it must prevent sensitive data from leaving the organization through email and web uploads. Which two capabilities are essential for this program? (Choose two.)

Select 2 answers
A.Security information and event management (SIEM) correlation of DLP alerts with threat intelligence feeds.
B.Content inspection using pattern matching and data classifiers to identify regulated data types.
C.Enforcement policies applied at egress points such as email gateways and secure web gateways.
D.Full-disk encryption on all endpoint devices and servers that store regulated data.
E.Network segmentation of the cardholder data environment using internal firewalls.
AnswersB, C

Content inspection with pattern matching and classifiers is the foundation of any DLP program because it identifies regulated data such as card numbers and PII within files, messages, and uploads. Without accurate classification, neither discovery at rest nor prevention in motion can distinguish sensitive content from ordinary business data, so this capability is essential to meet both stated requirements.

Why this answer

A functioning DLP program needs both accurate identification of regulated content and an enforcement point where policy can act. Content inspection with classifiers supplies the identification, while egress enforcement at email and web gateways supplies the prevention. Encryption, SIEM correlation, and segmentation are valuable controls but do not deliver either of the two required DLP capabilities.

Exam trap

The trap here is selecting adjacent data-protection controls such as encryption or segmentation that secure data but do not inspect content or enforce egress policy, which are the actual DLP functions.

77
MCQmedium

A security architect is designing a PKI for an organization that requires high assurance certificates. The architect needs to protect the root CA private key. Which solution provides the highest level of security for the root CA key?

A.Store the key in an encrypted file on a secure server
B.Generate the key on a dedicated virtual machine
C.Use a Hardware Security Module (HSM) for key management
D.Keep the key on a smart card stored in a safe
AnswerC

An HSM is tamper-resistant hardware that generates and stores the root CA private key internally, performing signing operations without exposing the key to software or memory. This provides the physical protection and non-exportability that high-assurance root key custody demands.

Why this answer

A Hardware Security Module (HSM) is a tamper-resistant physical device that generates, stores, and uses cryptographic keys within its protected boundary, never exposing the private key in plaintext. For a root CA — the trust anchor of the entire PKI — an HSM provides FIPS 140-2 Level 3 (or higher) assurance, key backup/recovery controls, and audit logging that no software-based or portable storage method can match. This is the industry-standard approach for high-assurance root CA key protection.

Exam trap

CAS-005 often tests whether candidates equate 'encrypted storage' or 'dedicated VM' with high-assurance key protection, when only an HSM provides tamper-resistant, non-exportable key custody for a root CA.

How to eliminate wrong answers

Option A is wrong because storing a root CA key in an encrypted file on a server exposes it to memory scraping, disk theft, and OS compromise; encryption at rest does not protect the key when decrypted for use. Option B is wrong because a dedicated VM still runs a general-purpose OS with hypervisor and memory attack surface, and the key exists in RAM during signing operations. Option D is wrong because a smart card in a safe is offline and lacks the tamper-resistant, high-throughput signing, and audited key lifecycle management that an HSM provides for a root CA.

78
MCQmedium

An organization wants to implement infrastructure as code (IaC) with immutable infrastructure. Which security benefit does immutable infrastructure provide?

A.Better performance through caching
B.Reduced attack surface due to consistent configurations
C.Simpler network segmentation
D.Easier patch management
AnswerB

Immutable infrastructure replaces rather than patches instances, so every deployment derives from one hardened image. Drift and configuration creep disappear, and no lingering services or stale packages accumulate, which is precisely the consistent-configuration reduction of attack surface the stem asks for.

Why this answer

Immutable infrastructure means servers and components are never modified after deployment — instead, changes require replacing the entire instance with a newly built, tested image. This eliminates configuration drift, ensures every instance matches a known-good baseline, and removes the accumulated patches, leftover packages, and ad-hoc changes that attackers exploit, thereby reducing the attack surface. The other options describe operational or performance benefits, not the core security advantage.

Exam trap

CAS-005 often tests whether candidates confuse immutable infrastructure's security benefit (consistent, drift-free configurations reducing attack surface) with operational benefits like easier patching or performance gains.

How to eliminate wrong answers

Option A is wrong because caching is a performance optimization unrelated to immutability; immutable infrastructure may actually reduce caching opportunities since instances are frequently replaced. Option C is wrong because network segmentation is a separate architectural control (VPCs, subnets, security groups) and is not inherently simplified by immutable infrastructure. Option D is wrong because patch management is not necessarily easier — immutability shifts patching from in-place updates to rebuilding images, which can be more complex, though it does improve consistency.

79
Multi-Selecthard

A security architect is designing a microsegmentation strategy for a data center that hosts both legacy virtual machines and modern containerized workloads. The architect must ensure that security policies follow the workload regardless of its location and that lateral movement is restricted even if a host is compromised. (Choose two.)

Select 2 answers
A.Implement a host-based firewall on each virtual machine that enforces allow-list rules based on workload tags
B.Use a software-defined networking (SDN) overlay that applies security groups based on workload identity rather than IP address
C.Enable port security on all physical switch ports to limit MAC addresses
D.Deploy a centralized next-generation firewall (NGFW) at the data center perimeter to inspect all north-south traffic
E.Segment the network into VLANs based on physical rack location and apply ACLs between VLANs
AnswersA, B

Host-based firewalls with tag-based rules enforce policy at the workload level, so protections move with the VM even if it is migrated. This restricts lateral movement because only explicitly allowed traffic can reach the workload, regardless of network topology or host compromise.

Why this answer

Host-based firewalls with tag-based rules and an SDN overlay using identity-based security groups both enforce policy at the workload level, ensuring that protections follow the workload regardless of location. These controls restrict lateral movement even if a host is compromised, unlike perimeter or physical segmentation approaches.

Exam trap

The trap here is equating network segmentation with microsegmentation; traditional VLANs and perimeter firewalls do not provide identity-based, workload-following policy enforcement.

80
MCQhard

A security architect is designing a secure connectivity solution between an on-premises data center and a public cloud provider. The solution must provide low latency, high bandwidth, and avoid traversing the public internet. Which approach BEST meets these requirements?

B.SD-WAN over internet
C.Direct Connect
D.Site-to-site VPN over internet
AnswerC

Direct Connect provisions a dedicated private circuit between the on-premises data centre and the cloud provider, bypassing the public internet entirely. This satisfies all three stated constraints simultaneously: low latency, high bandwidth, and no internet traversal, which VPN or internet-based alternatives cannot guarantee.

Why this answer

AWS Direct Connect (and equivalent dedicated cloud interconnects) provides a private, dedicated network connection from on-premises to the cloud provider, bypassing the public internet entirely. This delivers consistent low latency, high bandwidth (up to 100 Gbps per port with link aggregation), and predictable performance that internet-based options cannot guarantee.

Exam trap

The trap here is assuming that any encrypted tunnel (VPN) satisfies 'private connectivity' — CAS-005 often tests the distinction between encryption over the public internet versus a physically dedicated private circuit.

How to eliminate wrong answers

Option A is wrong because an SSL VPN still tunnels traffic over the public internet, so it cannot guarantee low latency or high bandwidth and is subject to internet congestion. Option B is wrong because SD-WAN over internet optimizes and prioritizes traffic but still traverses public internet paths, so it fails the 'avoid public internet' requirement. Option D is wrong because a site-to-site VPN over internet is encrypted but still rides the public internet, offering no bandwidth or latency guarantees.

81
MCQhard

An organization must comply with FedRAMP requirements for a cloud service. Which aspect of cloud security is most directly assessed under FedRAMP?

A.Data residency compliance
B.Cost optimization of cloud resources
C.Security controls of the cloud service provider
D.Performance SLA
AnswerC

FedRAMP authorisation directly evaluates the cloud service provider's implementation of NIST SP 800-53 security controls, satisfying the stem's compliance constraint. Assessment covers the provider's control environment, not customer-side configurations or data classification. This makes the CSP's security controls the object of FedRAMP review under Microsoft Entra ID-governed environments.

Why this answer

FedRAMP most directly assesses the security controls of the cloud service provider (CSP). The entire FedRAMP process is designed to evaluate, authorise, and continuously monitor the security posture of a CSP's offering against NIST SP 800-53 controls. While data residency, cost, and performance may be considerations, they are not the primary focus of FedRAMP assessment.

Exam trap

CAS-005 often tests the confusion between FedRAMP's focus on security controls and other cloud concerns like data residency or cost — candidates must remember that FedRAMP is fundamentally a security assessment framework for CSPs.

How to eliminate wrong answers

Option A is wrong because data residency compliance is a separate legal/regulatory concern (e.g., GDPR, data sovereignty laws) and is not the core of FedRAMP; FedRAMP focuses on security controls, not where data is stored. Option B is wrong because cost optimisation is a business concern, not a security compliance requirement; FedRAMP does not assess cost efficiency. Option D is wrong because performance SLAs are operational metrics, not security controls; FedRAMP assesses security, not performance guarantees.

82
MCQmedium

A security architect is designing a zero trust architecture for a financial services company. Which component is MOST critical to enforce identity-centric access control in a zero trust model?

A.Network firewall
C.Software-defined perimeter
D.VPN concentrator
AnswerC

A software-defined perimeter creates identity-based, need-to-know network segments, so access to resources is granted per user and device rather than by network location. This enforces identity-centric control, satisfying zero trust's requirement that trust be continuously verified before any connection is established.

Why this answer

A software-defined perimeter (SDP) is the most critical component for enforcing identity-centric access control in zero trust because it creates a 'black cloud' where resources are invisible until users and devices are authenticated and authorized. SDP uses a controller that brokers connections based on identity, device posture, and policy, rather than network location. This directly implements the zero trust principle of 'never trust, always verify' at the access layer.

Exam trap

The trap is confusing network security appliances (firewalls, IPS, VPNs) with identity-centric access control mechanisms; candidates must recognize that zero trust requires an identity-aware proxy or SDP, not just perimeter defenses.

How to eliminate wrong answers

Option A is wrong because a network firewall enforces perimeter-based, IP/port-centric rules and does not natively perform identity-centric access control or hide resources from unauthenticated users. Option B is wrong because an intrusion prevention system (IPS) detects and blocks malicious traffic patterns but does not authenticate users or enforce identity-based access decisions. Option D is wrong because a VPN concentrator grants broad network-level access after authentication, which contradicts zero trust micro-segmentation and least-privilege principles.

83
Multi-Selectmedium

A security architect is designing a zero trust network architecture and needs to implement micro-segmentation. Which TWO of the following techniques are commonly used to achieve micro-segmentation? (Select TWO).

Select 2 answers
A.Network Access Control (NAC)
B.Software-defined networking (SDN) policies
C.IPsec VPN tunnels between subnets
D.Host-based firewalls
E.VLAN segmentation
AnswersB, D

Software-defined networking policies centralise control and enforce per-workload rules through a programmable controller, segmenting traffic independently of physical topology. This satisfies micro-segmentation's requirement for granular, identity- and workload-based east-west controls, unlike VLANs or subnet ACLs, which segment only at coarser network boundaries and cannot isolate individual workloads dynamically.

Why this answer

Option B (Software-defined networking (SDN) policies) is correct because SDN centralizes control-plane policy and lets you program fine-grained, workload-level segmentation rules (e.g., via flow tables and distributed policy enforcement) rather than relying only on coarse network boundaries. Option D (Host-based firewalls) is correct because enforcing allow/deny rules directly on each workload's OS (e.g., Windows Defender Firewall, iptables/nftables, or a host agent) provides identity- and workload-centric micro-segmentation that follows the host even across network changes. Option A (NAC) is not the intended answer here because NAC primarily controls device admission and compliance at the network edge, not granular east-west workload-to-workload policy.

Option C (IPsec VPN tunnels between subnets) is not correct because it provides encrypted connectivity between subnets, not the fine-grained segmentation policy itself. Option E (VLAN segmentation) is not correct because VLANs are coarse Layer 2 broadcast-domain partitions, not the granular, often identity-based micro-segmentation required in zero trust.

Exam trap

CAS-005 often tests the confusion between traditional network segmentation (VLANs, VPNs, NAC) and true micro-segmentation (SDN policies, host-based firewalls), causing candidates to select coarse-grained network controls instead of workload-level enforcement.

84
MCQmedium

An organization is adopting SASE to converge network and security functions. Which component of SASE provides secure web gateway (SWG) capabilities?

A.ZTNA
B.SD-WAN
C.Secure Web Gateway
D.CASB
AnswerC

The secure web gateway is the SASE component that inspects and filters web traffic, enforcing acceptable-use and malware policies. Converging it into SASE delivers SWG filtering from the cloud edge, satisfying the requirement to combine network and security functions in one architecture.

Why this answer

Secure Web Gateway (SWG) is itself the SASE component that provides SWG capabilities — it filters web traffic, enforces URL categorization, blocks malicious content, and applies acceptable-use policies. In SASE architectures, SWG is one of the core security pillars delivered from the cloud edge, alongside CASB, ZTNA, and FWaaS. ZTNA, SD-WAN, and CASB serve different functions and do not deliver SWG's web filtering and threat inspection.

Exam trap

CAS-005 often tests whether candidates can map each SASE capability to its correct component, so they must not confuse SWG (web filtering) with CASB (cloud app governance) or ZTNA (private app access).

How to eliminate wrong answers

Option A is wrong because ZTNA (Zero Trust Network Access) provides identity- and context-based access to private applications, replacing VPN, not web content filtering. Option B is wrong because SD-WAN is the networking pillar of SASE that optimizes WAN connectivity and routing; it does not inspect or filter web traffic. Option D is wrong because CASB governs cloud application usage and data (shadow IT, DLP), not general web browsing traffic that SWG handles.

85
Multi-Selecthard

An organization is migrating to a zero trust model and wants to implement identity-centric security. Which THREE of the following are key principles of an identity-centric zero trust approach? (Select THREE.)

Select 3 answers
A.Implicit trust based on network location
B.Least privilege access with just-in-time privileges
C.Continuous verification of identity and device health
D.Multi-factor authentication (MFA) for all users
E.Single static firewall perimeter
AnswersB, C, D

Standing admin rights violate zero trust's assume-breach stance. Just-in-time privilege elevation grants access only when needed, then revokes it, shrinking the blast radius of compromised accounts. This directly satisfies the identity-centric requirement that entitlements are scoped and time-bound rather than permanent.

Why this answer

Option B is correct because identity-centric zero trust enforces least privilege access, granting users only the minimum permissions needed and elevating privileges just-in-time rather than permanently, which limits the blast radius of compromised accounts. Option C is correct because zero trust requires continuous verification of identity and device health on every access request, rather than trusting a session once authenticated, using signals such as device compliance and risk scores. Option D is correct because MFA for all users strengthens identity assurance by requiring multiple factors, directly supporting the identity-centric principle that no user is trusted by default.

Option A is incorrect because implicit trust based on network location is the opposite of zero trust, which assumes no implicit trust regardless of where the request originates. Option E is incorrect because a single static firewall perimeter reflects the traditional castle-and-moat model, whereas zero trust replaces perimeter-based trust with identity- and policy-based controls.

Exam trap

CAS-005 often tests the confusion between zero trust and traditional perimeter security — candidates pick 'implicit trust based on network location' or 'static firewall perimeter' because those are familiar concepts, missing that zero trust explicitly rejects both.

86
MCQhard

A multinational retailer operates an on-premises data center and two public cloud regions. Regulations require that customer payment data never leave the home country, but the company wants centralized security analytics. The architect needs a design that keeps raw payment records local while enabling global threat detection. Which design best meets these constraints?

A.Keep raw payment records in the home country and forward only normalized security telemetry to a central SIEM.
B.Replicate the full payment database to a central cloud data lake for analytics.
C.Deploy independent SIEM instances per region with no cross-region data sharing.
D.Encrypt payment records with a customer-managed key and store them in the nearest cloud region.
AnswerA

Keeping raw payment records local satisfies data residency, while forwarding normalized telemetry such as authentication events, network flows, and alerts gives the central SIEM the visibility needed for global threat detection. The telemetry is stripped of payment data, so no regulated records cross borders, and correlation across regions remains possible for detecting coordinated attacks.

Why this answer

Local retention of raw payment records meets the residency regulation, while exporting only normalized security telemetry to a central SIEM preserves the global correlation needed for threat detection. This separates regulated data from operational telemetry. Full replication, per-region silos, and encrypted offsite storage each either move regulated records across borders or prevent the centralized analytics the company requires.

Exam trap

The trap here is believing that encryption or tokenization automatically resolves data residency, when regulations govern where the records are stored and processed regardless of their encryption state.

87
MCQmedium

A security architect is designing a hybrid cloud environment. The organization requires low-latency, private connectivity between on-premises and a public cloud provider, bypassing the public internet. Which solution best meets this requirement?

A.Site-to-site VPN over the internet
B.Private link (e.g., AWS PrivateLink)
C.Direct Connect / ExpressRoute
D.SD-WAN with internet breakout
AnswerC

Direct Connect and ExpressRoute provide dedicated private circuits from on-premises into the cloud provider's network, so traffic never traverses the public internet. This satisfies the low-latency, private connectivity constraint, unlike site-to-site VPNs, which still ride the internet.

Why this answer

Direct Connect (AWS) and ExpressRoute (Azure) provide dedicated private circuits from on-premises to the cloud provider, bypassing the public internet entirely. This delivers predictable low latency, higher bandwidth, and stronger security than internet-based options. It directly satisfies the 'private connectivity, bypassing the public internet' requirement.

Exam trap

CAS-005 often tests the distinction between 'private connectivity to cloud services' (PrivateLink) and 'dedicated private circuit to on-premises' (Direct Connect/ExpressRoute) — candidates conflate the two because both use the word 'private.'

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN traverses the public internet, introducing variable latency and exposure that the question explicitly wants to avoid. Option B is wrong because AWS PrivateLink provides private connectivity to services within or across VPCs/accounts, not a dedicated on-premises-to-cloud circuit. Option D is wrong because SD-WAN with internet breakout still uses public internet paths, failing the bypass requirement.

88
MCQmedium

A security architect is designing a hybrid environment in which on-premises applications must consume APIs hosted in a public cloud. The architect wants to ensure that if the primary cloud region fails, API consumers continue to receive responses without changing client configuration. Which design element BEST satisfies this requirement?

A.Deploy a global server load balancing tier that performs health-checked DNS failover across regional API endpoints.
B.Configure a forward proxy on the on-premises network that caches API responses for the duration of the outage.
C.Place the API behind a reverse proxy that terminates TLS and inspects request payloads for malicious content.
D.Implement API versioning so consumers can switch to an alternate endpoint when the primary region becomes unavailable.
AnswerA

Health-checked global server load balancing continuously probes each regional API endpoint and withdraws a failed region from DNS answers, so existing clients resolve to a healthy region on their next lookup without any client-side change. This directly addresses regional failover for API consumers while preserving a single stable hostname.

Why this answer

Continuity across regions for API consumers is achieved by abstracting endpoints behind a health-aware global load balancing layer that removes failed regions from resolution and returns healthy ones. Caching, versioning, and single-region reverse proxies all leave the consumer dependent on the failed region or require client changes, so they do not meet the requirement.

Exam trap

The trap here is assuming that caching or API versioning provides availability, when neither redirects traffic to a surviving region.

89
MCQeasy

A security administrator is reviewing an architecture diagram for a new web application. The diagram shows the application servers in a private subnet, a database in a separate private subnet, and a public load balancer in a public subnet. The administrator wants to ensure that the application servers can retrieve software updates from the internet without being directly reachable from it. Which of the following should the administrator recommend?

A.Configure the application servers to use a proxy server hosted in the database subnet for all outbound update requests.
B.Place a NAT gateway in a public subnet and route the application subnet's outbound traffic through it.
C.Assign public IP addresses to the application servers and use a security group that permits only outbound port 443.
D.Attach an internet gateway directly to the application server subnet and allow outbound traffic on port 443.
AnswerB

A NAT gateway in a public subnet allows instances in a private subnet to initiate outbound connections to the internet while preventing unsolicited inbound connections. This is exactly the pattern needed for software updates. The application servers remain unreachable from the internet, and the NAT gateway handles address translation and return traffic, preserving the private subnet's isolation while still permitting necessary outbound access.

Why this answer

A NAT gateway located in a public subnet lets private application servers initiate outbound connections for updates while blocking unsolicited inbound connections from the internet. This preserves the private subnet's isolation and keeps the application tier unreachable externally. Direct internet gateway attachment, public IP assignment, and placing egress components in the database tier all either expose the servers or violate the intended tier separation.

Exam trap

The trap here is confusing outbound internet access with public reachability, when a NAT gateway provides the former without granting the latter.

90
MCQeasy

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer when using an Infrastructure as a Service (IaaS) model?

A.Configuration of the hypervisor
B.Network infrastructure maintenance
C.Physical security of data centers
D.Encryption of data at rest within the environment
AnswerD

Under IaaS, the customer controls everything above the hypervisor, including guest operating systems, applications and data. Encrypting data at rest within that environment therefore falls to the customer, whereas the provider secures the physical hosts, network fabric and underlying storage infrastructure.

Why this answer

In an IaaS model, the cloud provider manages the physical infrastructure, network, and hypervisor, while the customer is responsible for everything from the guest OS upward, including data encryption at rest. Encrypting data at rest within the environment is a customer responsibility because the customer controls the data and the encryption keys. The provider secures the underlying storage but does not automatically encrypt customer data unless the customer configures it.

Exam trap

The trap is assuming the cloud provider encrypts all data by default; candidates often forget that in IaaS, data encryption at rest is a customer responsibility, not the provider's.

How to eliminate wrong answers

Option A is wrong because hypervisor configuration is part of the virtualization layer managed by the cloud provider in IaaS, not the customer. Option B is wrong because network infrastructure maintenance (physical routers, switches, cabling) is the provider's responsibility. Option C is wrong because physical security of data centers is always the provider's responsibility in any cloud model.

91
MCQeasy

A security analyst is investigating an API that uses JSON Web Tokens (JWT) for authentication. Which field in a JWT contains the token expiration time?

A.exp
B.iss
C.iat
D.sub
AnswerA

The exp claim is a registered JWT payload field holding the expiration time as a NumericDate, after which the token must be rejected. Validating exp lets the analyst determine whether the token has lapsed, directly answering which field carries the expiration time.

Why this answer

The 'exp' (expiration time) claim in a JWT is a NumericDate value representing the UTC time after which the token MUST NOT be accepted, as defined in RFC 7519. Validating 'exp' is the standard mechanism for enforcing token lifetime and limiting the window of abuse if a token is stolen.

Exam trap

The trap is confusing the temporal claims — candidates mix up 'iat' (issued at) with 'exp' (expires), or assume 'nbf' means expiration when it actually means 'not before'.

How to eliminate wrong answers

Option B is wrong because 'iss' (issuer) identifies the principal that issued the JWT and is used for trust validation, not expiration. Option C is wrong because 'iat' (issued at) records when the token was created and is used for age checks or as a nonce, but it does not define when the token expires. Option D is wrong because 'sub' (subject) identifies the principal the token is about (typically the user ID), which is an identity claim, not a temporal one.

92
MCQmedium

During a secure SDLC, a security architect wants to identify design flaws early. Which activity is most appropriate for the design phase?

A.Threat modeling
B.Penetration testing
C.Dynamic application security testing (DAST)
D.Static application security testing (SAST)
AnswerA

Threat modelling examines data flows, trust boundaries and architecture during design, exposing flaws before code exists, when remediation is cheapest. It directly satisfies the requirement to identify design flaws early, unlike code scanning or penetration testing, which occur later.

Why this answer

Threat modeling is a structured design-phase activity that identifies potential threats, attack vectors, and design weaknesses before code is written. It uses frameworks like STRIDE or PASTA to map data flows and trust boundaries, surfacing architectural flaws early when they're cheapest to fix. This aligns exactly with the goal of identifying design flaws during the design phase.

Exam trap

CAS-005 often tests the mapping of security activities to SDLC phases — candidates confuse SAST (code/implementation) and DAST (testing/runtime) with design-phase activities, forgetting that threat modeling is the only one that works before code exists.

How to eliminate wrong answers

Option B is wrong because penetration testing is a post-deployment or late-stage activity that exploits running systems, not a design-phase technique. Option C is wrong because DAST tests running applications for runtime vulnerabilities, requiring a deployed build. Option D is wrong because SAST analyzes source code — it requires code to exist, so it belongs to the implementation phase, not design.

93
MCQmedium

An organization is deploying containerized applications and needs to enforce security policies that restrict the system calls a container can make. Which Linux security module should be used?

A.seccomp
B.AppArmor
C.chroot
D.SELinux
AnswerA

seccomp operates as a syscall filter, restricting which system calls a process may invoke. Applied to containers, it blocks dangerous calls such as those used in privilege-escalation exploits, directly satisfying the requirement to limit the system calls a container can make.

Why this answer

seccomp (secure computing mode) is a Linux kernel feature that filters system calls made by a process. In container security, seccomp profiles define which syscalls a containerized process can invoke, directly restricting its ability to interact with the kernel. This is the primary mechanism used by container runtimes like Docker and containerd to enforce syscall-level restrictions.

Exam trap

CAS-005 often tests the distinction between seccomp (syscall filtering) and other Linux security modules like AppArmor or SELinux (access control), causing candidates to confuse the layer of enforcement.

How to eliminate wrong answers

Option B is wrong because AppArmor is a mandatory access control framework that confines programs via security profiles based on file paths and capabilities, not syscall filtering. Option C is wrong because chroot only changes the apparent root directory for a process, providing filesystem isolation but not syscall restriction. Option D is wrong because SELinux enforces mandatory access controls through security contexts and type enforcement, not by filtering individual system calls.

94
Multi-Selecthard

A security architect is designing a data loss prevention (DLP) strategy for a hybrid environment where sensitive records are stored on-premises and synchronized to a SaaS productivity suite. The architect needs to ensure that policy enforcement follows the data regardless of location and that violations are detected before data leaves the organization. Which TWO of the following capabilities are most critical to achieve these goals? (Choose two.)

Select 2 answers
A.Full-disk encryption (FDE) on all endpoints and servers storing sensitive records.
B.Endpoint DLP agents with content-aware rules on managed workstations.
C.Cloud access security broker (CASB) with inline data inspection for the SaaS suite.
D.Security information and event management (SIEM) correlation of DLP alerts.
E.Network segmentation between the on-premises data center and the SaaS provider.
AnswersB, C

Endpoint DLP agents monitor and block sensitive data at the source, such as copying files to removable media or pasting into web forms. In a hybrid environment, this complements inline cloud inspection by covering local egress paths that network-based controls cannot see, ensuring enforcement follows the data.

Why this answer

Inline CASB inspection enforces DLP policy at the cloud egress point, while endpoint DLP agents enforce policy at the source on managed devices. Together they cover both network and local egress paths, ensuring that sensitive data is inspected and blocked before it leaves the organization and that policy follows the data across hybrid locations.

Exam trap

The trap here is treating encryption or SIEM correlation as DLP enforcement, when only inline content inspection at the cloud edge and endpoint content-aware agents can actually block sensitive data before it leaves.

95
MCQeasy

A security architect is reviewing the network design for a new branch office. The organization wants to ensure that all traffic from the branch is inspected for malware and that users are authenticated before accessing cloud applications, regardless of their location. Which technology should the architect recommend?

A.A remote access VPN concentrator at headquarters with split tunneling disabled
B.A software-defined wide area network (SD-WAN) overlay with local internet breakout
C.A Secure Access Service Edge (SASE) solution with integrated secure web gateway and zero trust network access
D.A next-generation firewall (NGFW) at the branch perimeter with IPsec VPN to headquarters
AnswerC

SASE converges network and security functions in the cloud, providing secure web gateway for malware inspection and zero trust network access for user authentication before accessing applications. It enforces policy consistently regardless of user location, meeting the branch's needs without backhauling traffic. This makes it the correct recommendation.

Why this answer

SASE delivers converged network and security services from the cloud, including secure web gateway for malware inspection and zero trust network access for user authentication. It enforces policy consistently for users anywhere, without backhauling traffic. This directly satisfies the branch office requirements for inspection and authentication before cloud access.

Exam trap

The trap here is assuming that an NGFW or VPN concentrator alone can provide both malware inspection and identity-based authentication for cloud access, when they typically require backhauling and lack integrated zero trust capabilities.

96
MCQhard

A container security team wants to enforce that containers run with the least privileges possible. Which Linux security module can be used to restrict system calls available to a container?

A.Pod Security Policy
B.AppArmor
C.SELinux
D.seccomp
AnswerD

seccomp filters the system calls a container may invoke, using a profile to block unused or dangerous calls such as ptrace or mount. This reduces the kernel attack surface, directly enforcing least privilege at the syscall layer rather than through filesystem or capability controls.

Why this answer

seccomp (secure computing mode) is a Linux kernel feature that filters system calls, allowing a container to be restricted to only the syscalls it needs. In container runtimes like Docker, containerd, and Kubernetes, seccomp profiles are applied per container to enforce least privilege at the syscall level. This directly answers 'restrict system calls available to a container.'

Exam trap

CAS-005 often tests the distinction between Linux Security Modules (AppArmor, SELinux) and seccomp — candidates pick AppArmor or SELinux for syscall restriction, but only seccomp filters system calls; LSMs enforce resource access control.

How to eliminate wrong answers

Option A is wrong because Pod Security Policy (deprecated in Kubernetes 1.21, replaced by Pod Security Admission) is a cluster-level admission control for pod specs (privileged, hostNetwork, etc.), not a Linux security module that filters syscalls. Option B is wrong because AppArmor is a Linux Security Module that enforces mandatory access control on file paths, capabilities, and network — it profiles program behavior but does not filter syscalls the way seccomp does. Option C is wrong because SELinux is also an LSM that labels processes and files for mandatory access control; it restricts access to resources but is not the syscall-filtering mechanism.

97
Multi-Selecthard

A security team is implementing a secure SDLC for a new application. Which THREE activities should be included as part of the development phase? (Choose three.)

Select 3 answers
A.Runtime application self-protection (RASP) deployment
B.Penetration testing on production environment
C.Static application security testing (SAST)
D.Threat modeling
E.Dependency analysis for open-source libraries
AnswersC, D, E

SAST scans source code statically during development, identifying injection flaws, insecure patterns and coding errors before compilation or deployment. Running it in the development phase satisfies the shift-left constraint, giving developers immediate feedback while remediation remains cheapest.

Why this answer

Static application security testing (SAST) (C) belongs in the development phase because it analyzes source code or bytecode without executing the application, letting developers find injection flaws, insecure coding patterns, and other defects while code is still being written. Threat modeling (D) is a development-phase design activity that systematically identifies assets, trust boundaries, data flows, and threats (e.g., via STRIDE) so that controls are built into the architecture before coding is complete. Dependency analysis for open-source libraries (E) is also a development-phase activity, typically implemented as software composition analysis (SCA) that inspects manifests such as package.json, pom.xml, or requirements.txt to detect vulnerable or outdated third-party components and their transitive dependencies.

By contrast, RASP (A) is a runtime protection mechanism that instruments the executing application in production or test, so it is a deployment/operations control rather than a development activity, and penetration testing on production (B) is an assurance activity performed after deployment against a running system, not during development.

Exam trap

CAS-005 often tests the misconception that runtime protections like RASP or production pen testing are 'development' activities, when they actually belong to the operations/deployment phase.

98
MCQmedium

A company is migrating to a public cloud and wants to ensure they understand their security responsibilities. According to the shared responsibility model, which of the following is typically the responsibility of the cloud customer?

A.Hypervisor security
B.Physical security of data centers
C.Network infrastructure security
D.Identity and access management
AnswerD

Under the shared responsibility model, the cloud customer always owns identity and access management — defining users, roles, permissions and authentication. The provider secures the underlying infrastructure, but customer identities and their access rights remain the customer's responsibility.

Why this answer

Under the shared responsibility model, the cloud customer is always responsible for their own data, identities, and access management, including IAM policies, users, roles, and credentials. The provider secures the underlying infrastructure, but the customer controls who can access what within their tenant. IAM is therefore a customer responsibility across IaaS, PaaS, and SaaS.

Exam trap

CAS-005 often tests the misconception that the provider handles 'everything security-related,' when in fact IAM, data, and customer-side configurations always remain the customer's responsibility.

How to eliminate wrong answers

Option A is wrong because hypervisor security is a provider responsibility — the cloud vendor owns the virtualization layer that separates tenants. Option B is wrong because physical security of data centers is always the provider's responsibility; customers have no physical access. Option C is wrong because the core network infrastructure (routers, switches, backbone) is managed by the provider, though customers may be responsible for virtual network controls like security groups.

99
MCQmedium

A company uses a CASB to monitor cloud application usage. Which primary function does a CASB provide for enforcing security policies between users and cloud services?

A.Encryption key management for cloud storage
B.Vulnerability scanning of cloud infrastructure
C.Policy enforcement point for cloud services
D.Workload protection runtime monitoring
AnswerC

A CASB acts as an inline policy enforcement point between users and cloud services, applying access, data-loss prevention and threat policies regardless of device or location. This satisfies the requirement to enforce security policies on cloud application traffic.

Why this answer

A CASB (Cloud Access Security Broker) acts as a policy enforcement point (PEP) that sits between users and cloud service providers, intercepting traffic to apply security policies such as authentication, authorization, data loss prevention (DLP), and compliance controls. It provides visibility and control over cloud application usage, ensuring that only authorized actions and data flows are permitted. Unlike other cloud security tools, the CASB's primary role is to enforce policies in real time, not to manage keys or scan for vulnerabilities.

Thus, option C correctly identifies the core function.

Exam trap

CAS-005 often tests the misconception that a CASB is a comprehensive cloud security tool that includes encryption key management or vulnerability scanning, when its primary function is specifically policy enforcement for cloud access.

How to eliminate wrong answers

Option A is wrong because encryption key management is typically handled by a cloud provider's KMS or a dedicated key management service, not a CASB; CASBs may integrate with KMS but do not primarily manage keys. Option B is wrong because vulnerability scanning of cloud infrastructure is the domain of CSPM or vulnerability management tools, not CASBs, which focus on policy enforcement for user-to-cloud interactions. Option D is wrong because workload protection runtime monitoring is a function of CWPP or container security platforms, not CASBs, which operate at the network and API level for cloud access control.

100
Multi-Selectmedium

A security architect is evaluating Cloud Security Posture Management (CSPM) tools. Which TWO capabilities are typically provided by CSPM? (Choose two.)

Select 2 answers
A.Detection of compliance violations
B.Web application firewall (WAF) management
C.Vulnerability scanning of container images
D.DDoS protection
E.Continuous monitoring of cloud resource configurations
AnswersA, E

CSPM tools continuously assess cloud configurations against benchmarks and policies, surfacing misconfigurations and regulatory breaches. Detecting compliance violations is a core capability, directly matching the stem's request for typical CSPM functions rather than runtime workload protection.

Why this answer

Option A (Detection of compliance violations) is correct because CSPM tools continuously assess cloud environments against regulatory and industry benchmarks such as CIS, PCI DSS, HIPAA, and NIST, flagging misconfigurations and policy breaches that constitute compliance violations. Option E (Continuous monitoring of cloud resource configurations) is correct because the core function of CSPM is to continuously discover and monitor cloud resources (e.g., storage buckets, IAM policies, security groups) across providers like AWS, Azure, and GCP, detecting drift and risky configuration changes in near real time. Option B is incorrect because WAF management is a web application protection function typically handled by dedicated WAF services or WAAP platforms, not CSPM.

Option C is incorrect because container image vulnerability scanning belongs to container security or vulnerability management tools (e.g., Trivy, Clair, or cloud-native registries), not CSPM. Option D is incorrect because DDoS protection is a network-layer availability control provided by services such as AWS Shield or Azure DDoS Protection, which is outside the CSPM scope of posture and compliance assessment.

Exam trap

CAS-005 often tests the boundary between CSPM and CWPP — candidates incorrectly attribute workload-level capabilities like container image scanning or WAF management to CSPM, which only covers configuration posture and compliance.

101
MCQhard

A security architect is evaluating a cloud service provider's ability to support a customer's compliance with PCI DSS. The customer will store cardholder data in the cloud. The architect needs to determine which party is responsible for configuring encryption of the data at rest and managing the encryption keys. According to the shared responsibility model, which of the following is the MOST accurate statement?

A.The customer is responsible for enabling encryption at rest and managing keys, but the provider may offer key management services.
B.The customer is responsible for physical security of the data center, and the provider handles encryption.
C.PCI DSS compliance is solely the cloud provider's responsibility because they own the infrastructure.
D.The cloud provider is always responsible for encrypting cardholder data at rest and managing keys.
AnswerA

Under the shared responsibility model, the customer is responsible for securing data in the cloud, including enabling encryption at rest and managing encryption keys. The cloud provider may offer key management services such as AWS KMS, Azure Key Vault, or Google Cloud KMS, but the customer must configure and use them appropriately to meet PCI DSS requirements.

Why this answer

In the shared responsibility model, the customer is responsible for securing data in the cloud, including enabling encryption at rest and managing keys. The cloud provider may offer key management services, but the customer must configure them to meet PCI DSS requirements. The other options either reverse responsibilities or incorrectly assign full responsibility to one party.

Exam trap

The trap here is assuming that because the cloud provider owns the infrastructure, it also owns all data protection responsibilities, including encryption and key management.

102
MCQeasy

A startup is building a new application on a public cloud and wants to minimize the attack surface of its virtual machines. The security architect recommends replacing SSH key-based administration with a model where no inbound management ports are exposed and access is granted per session with short-lived credentials. Which of the following should be implemented?

A.Security groups that allow SSH only from the administrator's home IP address.
B.A bastion host in a public subnet with SSH restricted to the corporate CIDR range.
C.A just-in-time access broker that issues short-lived certificates and proxies sessions.
D.VPN concentrators that place administrators on the same private network as the VMs.
AnswerC

A just-in-time access broker grants per-session, short-lived credentials and proxies administrative connections without exposing inbound management ports on the virtual machines. This directly reduces the attack surface by removing persistent SSH access and eliminating standing credentials, matching the architect's recommendation.

Why this answer

A just-in-time access broker removes standing inbound management access by issuing short-lived credentials and proxying sessions only when needed. This eliminates persistent SSH keys and exposed ports, directly minimizing the attack surface on the virtual machines while still allowing controlled administrative access.

Exam trap

The trap here is believing that IP-restricted SSH or a bastion host minimizes attack surface, when both still leave inbound management ports and long-lived credentials in place.

103
MCQhard

A company is migrating to immutable infrastructure for its production environment. The security architect needs to ensure that any changes to the infrastructure are made by replacing instances, not by modifying existing ones. Which security advantage does immutable infrastructure provide?

A.It eliminates all security vulnerabilities in the infrastructure
B.It removes the need for vulnerability scanning of base images
C.It simplifies compliance by eliminating the need for patching
D.It prevents attackers from establishing persistence by modifying system files
AnswerD

Immutable infrastructure replaces instances rather than patching them, so any attacker modification to system files is discarded when the instance is rebuilt. This removes the persistence mechanism attackers rely on to survive reboots and remediation.

Why this answer

Immutable infrastructure means servers are never patched or modified in place; instead, a new image is built and instances are replaced. This prevents attackers from establishing persistence via modified system files, backdoors, or rootkits, because any tampering is discarded when the instance is recycled. It also makes the deployed state deterministic and auditable.

Exam trap

CAS-005 often tests the misconception that immutability 'eliminates vulnerabilities' or 'removes patching,' when it actually changes the patching model to image rebuilds and still requires scanning.

How to eliminate wrong answers

Option A is wrong because immutability does not eliminate vulnerabilities — a base image can still contain vulnerable software until it is rebuilt. Option B is wrong because base images still require vulnerability scanning; immutability changes how fixes are deployed, not whether scanning is needed. Option C is wrong because patching is not eliminated — it is shifted from in-place updates to rebuilding and redeploying images, and compliance still requires evidence of patched images.

104
MCQhard

During a security assessment, a penetration tester discovers that a web application fails to validate the size of user input, leading to a buffer overflow. Which application security control would have BEST prevented this vulnerability?

A.Input validation
B.Static application security testing (SAST)
C.Web application firewall (WAF)
D.Rate limiting
AnswerA

Input validation enforces length and format checks on user-supplied data before processing, directly satisfying the constraint that input size must be bounded. By rejecting oversized payloads at the boundary, it prevents the buffer overflow the penetration tester exploited, whereas output encoding or parameterised queries address different vulnerability classes.

Why this answer

Input validation is the application security control that directly prevents buffer overflow by ensuring that user-supplied data does not exceed the allocated buffer size. It checks the length, type, and format of input before processing, thereby mitigating the vulnerability at its source.

Exam trap

CAS-005 often tests the difference between preventive and detective controls, and candidates may choose SAST or WAF as preventive measures when the question asks for the BEST control to prevent the vulnerability.

How to eliminate wrong answers

Option B (Static application security testing (SAST)) is wrong because SAST is a testing methodology that can identify potential buffer overflows in code, but it does not prevent them at runtime; it is a detection tool, not a preventive control. Option C (Web application firewall (WAF)) is incorrect because a WAF can block some malicious requests, but it is not a reliable prevention for buffer overflows as it may not catch all variations; it is a compensating control, not a primary fix. Option D (Rate limiting) is wrong because rate limiting controls the number of requests, not the size or content of input, and does not address buffer overflow.

105
MCQmedium

A security architect at a defense contractor must protect Controlled Unclassified Information (CUI) that flows between an on-premises data center and a government cloud enclave. The requirement states that data must remain confidential even if a cloud provider's hypervisor is compromised, and the provider must not be able to access plaintext at any layer. The architect needs a control that cryptographically isolates tenant workloads from the provider and from other tenants. Which of the following BEST satisfies this requirement?

A.Encrypt all CUI at rest with customer-managed keys stored in a separate key management service outside the provider's control.
B.Implement confidential computing using hardware-based trusted execution environments (TEEs) such as AMD SEV-SNP or Intel TDX.
C.Deploy hardware security modules (HSMs) in the cloud provider's data center to store tenant encryption keys.
D.Require TLS 1.3 with mutual authentication for all data in transit between the data center and the cloud enclave.
AnswerB

Confidential computing encrypts guest memory with keys managed by the CPU, so even a compromised hypervisor or a malicious provider administrator sees only ciphertext. TEEs provide cryptographic isolation of tenant workloads from the provider and other tenants, directly meeting the requirement that plaintext never be exposed to the cloud provider at any layer.

Why this answer

Confidential computing with hardware TEEs encrypts guest memory using CPU-managed keys, so the hypervisor and provider administrators cannot read plaintext even during processing. The other controls protect keys, data in transit, or data at rest, but none prevent plaintext exposure in memory when the hypervisor is compromised, which is the specific threat in this scenario.

Exam trap

The trap here is assuming that encrypting data at rest and in transit is sufficient to keep a cloud provider from accessing plaintext, when the provider can still read decrypted data in guest memory unless confidential computing is used.

106
MCQmedium

A security architect is designing a PKI for a large enterprise. Which component is used to protect private keys and perform cryptographic operations in a tamper-resistant environment?

A.Hardware Security Module (HSM)
B.Certificate Revocation List (CRL)
C.Key Management Service (KMS)
D.Certificate Authority (CA)
AnswerA

A Hardware Security Module provides tamper-resistant hardware that generates, stores and uses private keys without exposing them to host memory, satisfying the stem's requirement for protected keys and cryptographic operations in a tamper-resistant environment. Unlike software keystores, its physical and logical controls detect intrusion and zeroise key material, defeating extraction attempts.

Why this answer

A Hardware Security Module (HSM) is a dedicated tamper-resistant appliance that generates, stores, and uses cryptographic keys without exposing them, performing operations like signing and encryption inside the hardware boundary. It is the standard component for protecting private keys in an enterprise PKI. HSMs provide FIPS 140-2/3 validated protection and resist physical and logical extraction attempts.

Exam trap

CAS-005 often tests the confusion between KMS (a key management service) and HSM (the tamper-resistant hardware), tempting candidates to pick KMS when the question emphasizes hardware protection.

How to eliminate wrong answers

Option B is wrong because a CRL is a published list of revoked certificates; it contains no keys and performs no cryptographic operations. Option C is wrong because a Key Management Service (KMS) manages key lifecycle and can use HSMs as backing, but KMS itself is a software service and the question asks for the tamper-resistant component that protects keys and performs crypto operations. Option D is wrong because a Certificate Authority issues and signs certificates but relies on an HSM to protect its private key; the CA is a role/service, not the tamper-resistant hardware.

107
MCQmedium

A company uses Kubernetes for container orchestration. Which security control should be implemented to enforce that only specific images from a trusted registry can run in the cluster?

A.Pod security admission (PSA)
B.Admission controller (e.g., OPA/Gatekeeper)
C.Network policies
D.RBAC roles
AnswerB

An admission controller intercepts pod creation requests before persistence and evaluates them against policy. OPA/Gatekeeper enforces rules restricting image sources, so only images from the trusted registry are admitted, directly satisfying the stem's trusted-registry constraint.

Why this answer

An admission controller such as OPA/Gatekeeper intercepts API server requests before objects are persisted and can enforce policies — including image registry allow-lists — so only images from trusted registries are admitted to the cluster. Gatekeeper's ConstraintTemplates and Constraints let you write Rego policies that validate image fields in Pod specs.

Exam trap

CAS-005 often tests Kubernetes security controls by presenting several plausible-sounding controls (PSA, Network Policies, RBAC), so candidates who see 'only specific images' and pick PSA or RBAC miss that image provenance requires an admission controller with policy logic.

How to eliminate wrong answers

Option A is wrong because Pod Security Admission enforces Pod Security Standards (privileged, baseline, restricted) around privilege, host namespaces, and capabilities — it does not validate image registries. Option C is wrong because Network Policies control pod-to-pod and pod-to-external traffic at L3/L4; they govern network flow, not which images can run. Option D is wrong because RBAC controls who (users, service accounts) can perform which API actions; it does not inspect the content of Pod specs to enforce image provenance.

108
Multi-Selecthard

A company is developing a secure software development lifecycle (SDLC) and wants to integrate security testing early. Which THREE techniques should be used to find vulnerabilities in code during development? (Choose three.)

Select 3 answers
A.Penetration testing
B.Software Bill of Materials (SBOM) analysis
C.Threat modeling
D.Dynamic Application Security Testing (DAST)
E.Static Application Security Testing (SAST)
AnswersC, D, E

Threat modelling identifies design-level weaknesses by systematically analysing data flows, trust boundaries and attack paths before coding completes. Applying it early satisfies the stem's requirement to find vulnerabilities during development, complementing code-level scanning with architectural risk discovery.

Why this answer

Threat modeling (C) is correct because it is a design-phase activity that systematically identifies threats, attack surfaces, and mitigations before code is written, making it a foundational shift-left technique. SAST (E) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find flaws such as injection sinks and insecure coding patterns directly in the IDE or CI pipeline. DAST (D) is correct because it tests the running application from the outside, exercising inputs and runtime behavior to uncover vulnerabilities like authentication and configuration flaws that static analysis may miss.

Penetration testing (A) is not one of the three because it is typically a later, point-in-time adversarial assessment rather than an early development-phase code-testing technique, and SBOM analysis (B) is a supply-chain inventory and component-transparency practice, not a method for finding vulnerabilities in first-party code during development.

Exam trap

CAS-005 often tests which security activities belong 'early' in the SDLC, so candidates who include penetration testing (late-stage) or SBOM analysis (dependency inventory, not code testing) instead of the design/code/runtime trio of threat modeling, SAST, and DAST lose marks.

109
MCQmedium

A security architect is designing a platform for a hospital network. Clinical staff must access patient records from managed workstations, while third-party billing contractors use unmanaged personal laptops. The architect wants a single architecture that continuously validates device posture and user identity before granting access to each microservice, regardless of network location. Which approach should the architect implement?

A.Deploy a next-generation firewall with VLAN segmentation for clinical and contractor traffic.
B.Implement a zero trust architecture using a policy engine and policy enforcement points at each microservice.
C.Establish an IPsec VPN concentrator that assigns contractors to a restricted subnet.
D.Configure 802.1X port-based authentication on all wired switch ports.
AnswerB

Zero trust architecture continuously evaluates identity and device posture through a policy engine and enforces decisions at policy enforcement points. Placing enforcement at each microservice allows the hospital to authorize every request based on user, device, and context regardless of network location, satisfying both the managed workstation and unmanaged contractor scenarios with one consistent model.

Why this answer

A zero trust architecture with a policy engine and enforcement points at each microservice continuously validates identity and device posture for every request, independent of network location. This single architecture covers managed clinical workstations and unmanaged contractor laptops alike, unlike network-centric controls that authenticate once and then trust the connection. Per-microservice enforcement also limits lateral movement if a device is compromised.

Exam trap

The trap here is assuming that strong network segmentation or VPN access alone achieves zero trust, when zero trust requires continuous, per-request identity and posture evaluation rather than one-time network admission.

110
Multi-Selectmedium

A security architect is implementing a zero trust architecture for a corporate network. Which TWO principles are fundamental to the zero trust approach? (Choose two.)

Select 2 answers
A.Grant access based on network location
B.Assume implicit trust for internal users
C.Use a single perimeter firewall
D.Verify every access request regardless of source
E.Implement least privilege access
AnswersD, E

Zero trust treats network location as insufficient evidence of trust, so every access request is authenticated and authorised explicitly, regardless of whether it originates inside or outside the corporate perimeter. Continuous verification replaces the implicit trust granted by legacy castle-and-moat designs.

Why this answer

Option D is correct because zero trust requires that every access request be authenticated and authorized explicitly, regardless of whether it originates inside or outside the traditional network perimeter—no user or device is trusted by default. Option E is correct because least privilege access is a core zero trust principle, granting users and devices only the minimum permissions needed for their tasks and limiting lateral movement if credentials are compromised. Options A, B, and C are incorrect because they reflect perimeter-based, castle-and-moat security models: granting access by network location, assuming implicit trust for internal users, and relying on a single perimeter firewall all contradict zero trust's 'never trust, always verify' philosophy.

Exam trap

CAS-005 often tests the misconception that zero trust is about strengthening the perimeter or trusting internal users more; the trap is confusing traditional perimeter security (like firewalls) with zero trust principles, leading candidates to select options that reinforce implicit trust or location-based access.

111
Multi-Selecthard

A security architect is designing a microservices-based application deployed on containers in a Kubernetes cluster. The architect needs to implement controls that protect the application from lateral movement in case a container is compromised. Which TWO of the following controls best achieve this goal? (Choose two.)

Select 2 answers
A.Use a service mesh to enforce mutual TLS (mTLS) between all services and apply authorization policies based on service identity.
B.Enable role-based access control (RBAC) for the Kubernetes API and grant each service account the minimum permissions required.
C.Implement network policies that deny all ingress and egress traffic by default and allow only explicitly required communication between specific pods.
D.Store all application secrets in environment variables within the container images to simplify deployment.
E.Run all containers as privileged to ensure they have the necessary permissions to perform their functions.
AnswersA, C

A service mesh with mutual TLS authenticates and encrypts all service-to-service communication, and authorization policies can restrict which services are allowed to talk to each other based on identity. If a container is compromised, the attacker cannot impersonate another service or communicate with services that are not explicitly authorized, which significantly limits lateral movement. This is a strong control for microservices environments.

Why this answer

Default-deny network policies restrict pod-to-pod traffic to only what is explicitly allowed, and a service mesh with mutual TLS and authorization policies enforces identity-based communication between services. Together, these controls limit an attacker's ability to move laterally from a compromised container. RBAC, privileged containers, and secrets in environment variables do not prevent network-based lateral movement and may even increase risk.

Exam trap

The trap here is assuming that any security control, such as RBAC, automatically prevents lateral movement, when in fact lateral movement is primarily a network communication issue that requires network segmentation or service mesh authorization.

112
MCQhard

A security team is hardening a Kubernetes cluster. Which control should be implemented to restrict a container's system calls to only those required by the application?

A.Seccomp
B.AppArmor
C.Network policies
D.Pod security policies
AnswerA

Seccomp profiles filter the syscalls a container may invoke, blocking everything outside an explicit allowlist. This directly satisfies the stem's requirement to restrict system calls to only those the application needs, unlike AppArmor or SELinux, which enforce mandatory access control over file paths, network ports and capabilities rather than the syscall interface itself.

Why this answer

Seccomp (secure computing mode) is a Linux kernel feature that filters the system calls a process can make, using a BPF-based profile to allow or deny specific syscalls. In Kubernetes, seccomp profiles are applied via the securityContext.seccompProfile field (or the older seccomp.security.alpha.kubernetes.io/pod annotation), restricting a container to only the syscalls its application requires. This directly matches the requirement to limit a container's system calls.

Exam trap

CAS-005 often tests the confusion between seccomp (syscall filtering) and AppArmor/SELinux (mandatory access control on files and capabilities), so candidates who see 'restrict' and pick AppArmor miss the syscall-specific wording.

How to eliminate wrong answers

Option B is wrong because AppArmor enforces mandatory access control on file paths, network access, and capabilities via per-program profiles, but it does not filter system calls by number the way seccomp does. Option C is wrong because Network policies operate at L3/L4 to control pod-to-pod ingress and egress traffic, not the syscall surface of a container process. Option D is wrong because Pod security policies (deprecated in Kubernetes 1.21 and removed in 1.25, replaced by Pod Security Admission) governed pod-level settings like privileged mode and volume types, not syscall filtering.

113
MCQmedium

A company is implementing a secure software development lifecycle (SDLC). The security architect wants to ensure that vulnerabilities are identified early in the development process and that developers receive immediate feedback. Which of the following should be integrated into the CI/CD pipeline?

A.Static application security testing (SAST) integrated into the build process.
B.Interactive application security testing (IAST) run manually by the security team quarterly.
C.Software composition analysis (SCA) performed only before major releases.
D.Dynamic application security testing (DAST) run after deployment to production.
AnswerA

SAST analyzes source code or binaries for vulnerabilities without executing the application. Integrating it into the build process allows developers to receive immediate feedback on security issues as they commit code. This shifts security left, enabling early remediation and reducing the cost of fixes. SAST is ideal for identifying issues like SQL injection and cross-site scripting early in the SDLC.

Why this answer

Integrating SAST into the build process enables automated security testing on every code commit, providing immediate feedback to developers. This shifts security left, allowing vulnerabilities to be found and fixed early when they are cheaper and easier to remediate. SAST is well-suited for CI/CD pipelines because it does not require a running application and can be triggered automatically.

Exam trap

The trap here is confusing different types of security testing and their appropriate stages in the SDLC.

114
MCQeasy

In the shared responsibility model for cloud security, which of the following is typically the responsibility of the customer?

A.Data classification and encryption
B.Physical security of data centers
C.Network infrastructure security
D.Hypervisor security
AnswerA

Data classification and encryption remain customer responsibilities because the provider cannot determine sensitivity or manage keys without the tenant's context. In the shared responsibility model, the customer always owns data governance, including classifying information and controlling encryption keys, while Microsoft Entra ID and the underlying infrastructure stay with the provider.

Why this answer

In the shared responsibility model for cloud security, the customer is always responsible for the security of their data, including classification and encryption. This includes determining data sensitivity, applying appropriate encryption at rest and in transit, and managing encryption keys. The cloud provider is responsible for security of the cloud (physical, network, hypervisor), while the customer is responsible for security in the cloud.

Exam trap

CAS-005 often tests the shared responsibility model by presenting responsibilities that seem like they could be either party's. The trap is assuming the provider handles data encryption because they offer encryption tools, but the customer must still configure and manage it.

How to eliminate wrong answers

Option B is wrong because physical security of data centers is always the responsibility of the cloud provider, as customers have no access to or control over the physical infrastructure. Option C is wrong because network infrastructure security (e.g., routers, switches, physical network) is managed by the cloud provider under the shared responsibility model. Option D is wrong because hypervisor security is part of the virtualization layer managed by the cloud provider; customers do not have access to the hypervisor in public cloud environments.

115
Multi-Selecthard

A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?

Select 3 answers
A.Network segmentation
B.Dependency analysis
C.Container image scanning
D.Runtime application self-protection
E.Software Bill of Materials (SBOM)
AnswersB, C, E

Dependency analysis inspects third-party libraries and transitive packages for known CVEs before they enter the build, directly satisfying the supply chain security requirement. It catches vulnerable or malicious components at the point of integration, preventing compromised dependencies from reaching production artefacts.

Why this answer

Dependency analysis (B) is correct because it inspects third-party libraries and transitive dependencies for known CVEs (e.g., via SCA tools like OWASP Dependency-Check, Snyk, or Trivy) before artifacts are built, directly protecting the software supply chain from vulnerable or malicious packages. Container image scanning (C) is correct because it examines image layers and installed packages against vulnerability databases (e.g., Clair, Trivy, Grype) so compromised base images or components are caught in the CI/CD pipeline before deployment. Software Bill of Materials (E) is correct because an SBOM (e.g., SPDX or CycloneDX format) provides a machine-readable inventory of components and dependencies, enabling provenance tracking, rapid impact analysis when new CVEs emerge, and compliance with supply chain mandates.

Network segmentation (A) is a runtime infrastructure control that limits lateral movement but does not secure the build and delivery pipeline itself, and runtime application self-protection (D) is a runtime defense that detects and blocks attacks in a running application, not a CI/CD supply chain practice.

Exam trap

CAS-005 often tests the specific practices that directly address supply chain security versus general security controls. Candidates may select network segmentation or RASP because they sound security-related, but they do not address supply chain risks in the CI/CD pipeline.

116
MCQhard

A company is preparing for post-quantum cryptography migration. According to NIST PQC standards, which algorithm is a candidate for key encapsulation?

A.CRYSTALS-Dilithium
B.SPHINCS+
C.Falcon
D.CRYSTALS-Kyber
AnswerD

CRYSTALS-Kyber is the NIST-standardised key encapsulation mechanism (ML-KEM, FIPS 203), built on module learning-with-errors. It satisfies the stem's requirement for a PQC KEM candidate by enabling two parties to establish a shared symmetric key over a public channel, unlike CRYSTALS-Dilithium, which is a digital signature scheme.

Why this answer

CRYSTALS-Kyber is the NIST-standardized algorithm for key encapsulation (KEM), selected in the post-quantum cryptography standardization process. It is designed for secure key exchange and is efficient for both client and server. NIST selected Kyber as the primary KEM standard (FIPS 203).

Exam trap

The trap is mixing up KEM and digital signature algorithms — candidates may pick Dilithium or Falcon because they are also NIST PQC standards, but only Kyber is a KEM.

How to eliminate wrong answers

Option A is wrong because CRYSTALS-Dilithium is a digital signature algorithm, not a KEM. Option B is wrong because SPHINCS+ is a stateless hash-based signature scheme, not a KEM. Option C is wrong because Falcon is a lattice-based digital signature algorithm, not a KEM.

117
MCQeasy

A security analyst is reviewing a Kubernetes cluster's security configuration. Which component should be used to ensure that only authorized pods can communicate with each other?

A.Pod Security Policies (PSP)
B.Seccomp profiles
C.Network Policies
D.RBAC roles
AnswerC

Network Policies enforce pod-level ingress and egress rules, restricting traffic to explicitly authorised pod selectors within the cluster. This directly satisfies the requirement that only authorised pods communicate, since default Kubernetes networking permits all pod-to-pod traffic. Unlike service mesh or firewall controls, Network Policies operate at layer 3/4 using label selectors native to the cluster.

Why this answer

Network Policies in Kubernetes are the native mechanism for controlling pod-to-pod traffic. They use label selectors to define which pods can communicate with which other pods on specified ports and protocols, effectively acting as a firewall at the pod level. Without a Network Policy, all pods in a cluster can communicate freely by default, so applying one is the correct way to restrict east-west traffic to only authorized flows.

Exam trap

The trap here is conflating 'pod security' with 'network security' — candidates see 'authorized pods' and reach for PSP or RBAC, but authorization in the network sense means Network Policies, not admission control or API authorization.

How to eliminate wrong answers

Option A is wrong because Pod Security Policies (deprecated in Kubernetes 1.21, replaced by Pod Security Admission) govern pod-level security settings like privileged mode, host networking, and volume types — they do not control network communication between pods. Option B is wrong because Seccomp profiles restrict which Linux system calls a containerized process can make, addressing syscall-level attack surface, not network reachability. Option D is wrong because RBAC roles control which users or service accounts can perform API operations against the Kubernetes API server (authorization), not whether pod A can open a TCP connection to pod B.

118
MCQhard

A company must protect cryptographic keys used to sign financial transactions. The solution must be FIPS 140-2 Level 3 compliant and provide tamper-resistant hardware. Which technology should be deployed?

A.Software-based key management system
B.Hardware security module
C.Cloud KMS
D.TPM
AnswerB

A hardware security module provides tamper-resistant, FIPS 140-2 Level 3 validated hardware that generates and stores cryptographic keys internally, preventing extraction. This satisfies the requirement to protect signing keys for financial transactions with physical tamper resistance.

Why this answer

A Hardware Security Module (HSM) is a dedicated physical appliance that generates, stores, and protects cryptographic keys inside a tamper-resistant boundary. FIPS 140-2 Level 3 requires physical tamper-resistance, identity-based authentication, and key zeroization on intrusion — capabilities that only validated hardware appliances like HSMs deliver. HSMs are the standard for signing high-value financial transactions because private keys never leave the cryptographic boundary in plaintext.

Exam trap

The trap here is conflating 'cloud KMS' with 'HSM' — candidates assume any managed key service is automatically FIPS 140-2 Level 3, when only HSM-backed offerings with dedicated hardware meet the tamper-resistance requirement.

How to eliminate wrong answers

Option A is wrong because software-based key management stores keys in memory or disk, which cannot satisfy FIPS 140-2 Level 3's physical tamper-resistance requirement. Option C is wrong because cloud KMS offerings are typically FIPS 140-2 Level 2 or Level 3 only when backed by dedicated HSM hardware — a generic cloud KMS service alone does not guarantee Level 3 tamper-resistant hardware. Option D is wrong because a TPM is a discrete chip bound to a single host, designed for platform integrity and disk encryption, not for high-throughput multi-party transaction signing or FIPS 140-2 Level 3 certification as a standalone module.

119
Multi-Selectmedium

A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?

Select 2 answers
A.Using long-lived access tokens to reduce authentication frequency
B.Enforcing short-lived access tokens with refresh token rotation
C.Encrypting JWT payloads with a symmetric key
D.Implementing token binding to bind tokens to a specific client session
E.Implementing rate limiting on the token endpoint
AnswersB, D

Short expiry limits the window in which an intercepted token remains usable, directly mitigating replay. Refresh token rotation invalidates the prior refresh token on each exchange, so a stolen refresh token is detected and rejected once the legitimate client rotates, satisfying the replay-resistance requirement.

Why this answer

Option B is correct because enforcing short-lived access tokens limits the window in which a stolen token can be replayed, and refresh token rotation invalidates the old refresh token each time a new one is issued, so a captured refresh token cannot be reused indefinitely. Option D is correct because token binding cryptographically ties an access or refresh token to a specific client session or TLS channel, so a token intercepted and replayed from a different session or connection will be rejected. Option A is wrong because long-lived access tokens increase the replay window and worsen the impact of interception.

Option C is wrong because encrypting JWT payloads provides confidentiality of claims but does not prevent an attacker who captures the token from replaying it. Option E is wrong because rate limiting on the token endpoint only mitigates brute-force or flooding attempts; it does not stop interception or replay of a valid token.

Exam trap

CAS-005 often tests the misconception that encrypting a JWT (JWE) prevents replay, when encryption only protects confidentiality — replay protection requires short lifetimes, rotation, or proof-of-possession binding.

120
Multi-Selecteasy

A company is implementing API security for its web services. Which THREE of the following are considered best practices for securing APIs? (Select THREE).

Select 3 answers
A.Rely solely on symmetric encryption for data at rest
B.Validate all input
C.Use WPA3 for transport encryption
D.Implement rate limiting
E.Use OAuth 2.0 for authorization
AnswersB, D, E

Validating all input defends against injection attacks such as SQL injection and cross-site scripting by rejecting malformed or malicious payloads before processing. This directly satisfies the requirement to secure web service APIs against untrusted client-supplied data.

Why this answer

Option B (Validate all input) is correct because input validation defends against injection attacks such as SQL injection and cross-site scripting (XSS) by ensuring data conforms to expected formats, types, and lengths before processing. Option D (Implement rate limiting) is correct because throttling requests per client or API key mitigates brute-force, credential-stuffing, and denial-of-service abuse, and protects backend resources from being overwhelmed. Option E (Use OAuth 2.0 for authorization) is correct because OAuth 2.0 provides delegated, token-based authorization with scoped access, allowing APIs to grant limited permissions without exposing user credentials.

Option A does not belong because relying solely on symmetric encryption for data at rest ignores transport security, key management, and other layers of defense. Option C does not belong because WPA3 is a Wi-Fi (802.11) security standard for wireless LANs, not a transport encryption mechanism for web APIs, which should use TLS.

Exam trap

CAS-005 often tests the confusion between encryption at rest and in transit, and between wireless security protocols (WPA3) and transport security (TLS), tricking candidates into selecting irrelevant or incomplete measures when asked for API security best practices.

121
MCQmedium

A security architect at a financial services firm is designing the network segmentation for a new containerized trading platform running on Kubernetes. The platform must isolate workloads so that a compromise of the public-facing web tier cannot directly reach the database tier. The architect wants to enforce this isolation natively within the cluster and have policies applied automatically as new pods are scheduled. Which of the following should the architect implement?

A.NetworkPolicies applied to namespaces and selected pods
B.A service mesh with mutual TLS between all sidecars
C.VLAN segmentation on the underlying hypervisor
D.An ingress controller with TLS termination and WAF rules
AnswerA

Kubernetes NetworkPolicies are the native mechanism for pod-level segmentation. They select pods via labels and define ingress and egress rules that allow or deny traffic between namespaces, pods, and CIDR blocks. Because the CNI plugin enforces them dynamically, newly scheduled pods that match a label selector inherit the policy automatically, giving the architect the isolation and automation required without external appliances.

Why this answer

Kubernetes NetworkPolicies provide label-based, pod-level segmentation enforced by the CNI plugin, so isolation follows workloads wherever they are scheduled. The architect can default-deny traffic in a namespace and then allow only the specific web-to-API and API-to-database flows, which prevents a compromised front end from reaching the database tier. Encryption and edge controls address different concerns and do not restrict lateral movement inside the cluster.

Exam trap

The trap here is assuming that encrypting service traffic with a mesh also restricts which services can communicate, when encryption and authorization are separate controls.

122
MCQeasy

A security architect is designing a zero trust architecture for a financial institution. Which principle is fundamental to the zero trust model?

A.Trust but verify all network traffic
B.Use VPNs for all remote access
C.Perimeter-based security is sufficient
D.Assume breach and verify explicitly
AnswerD

Zero trust removes implicit trust based on network location. Assuming breach means every request is treated as potentially hostile, so each access is verified explicitly using identity, device and context signals before granting least-privilege access, which is fundamental to the model.

Why this answer

The fundamental principle of zero trust is 'assume breach and verify explicitly,' meaning no user or device is trusted by default, regardless of location. Every access request must be authenticated and authorized based on multiple factors, and least privilege is enforced. This principle is core to zero trust architecture as defined by NIST SP 800-207.

Exam trap

CAS-005 often tests zero trust principles by offering variations of 'trust but verify' or 'VPN for all access.' The trap is confusing zero trust with traditional defense-in-depth, which still relies on perimeter trust.

How to eliminate wrong answers

Option A is wrong because 'trust but verify' is a traditional perimeter-based approach that assumes internal network is trusted; zero trust does not trust anything by default. Option B is wrong because using VPNs for all remote access is a legacy approach that extends the perimeter but does not align with zero trust, which requires continuous verification regardless of network. Option C is wrong because perimeter-based security is explicitly rejected by zero trust, which assumes the perimeter is already breached.

123
MCQmedium

An organization is designing a PKI to issue certificates to thousands of IoT devices. Which architectural decision will BEST support automated certificate lifecycle management?

A.Online root CA with self-signed certificates
B.Automated enrollment using SCEP
C.Using a public CA for all IoT devices
D.Offline root CA with manual issuance
AnswerB

SCEP provides a standardised protocol for devices to request and receive certificates automatically from a CA, enabling enrolment without manual intervention. For thousands of IoT devices, this automates issuance, renewal and revocation workflows, which is the lifecycle management constraint the stem demands.

Why this answer

Automated enrollment using SCEP (Simple Certificate Enrollment Protocol) is the best choice because it enables scalable, automated certificate issuance and renewal for thousands of IoT devices without manual intervention. SCEP is widely supported by IoT devices and integrates with PKI to streamline lifecycle management, including renewal and revocation.

Exam trap

CAS-005 often tests PKI design for IoT by presenting options that seem scalable but are not automated. Candidates may choose a public CA for convenience, but it lacks integration with internal lifecycle management and is cost-prohibitive.

How to eliminate wrong answers

Option A is wrong because an online root CA with self-signed certificates is insecure; the root CA should be offline to protect the trust anchor, and self-signed certificates are not suitable for a managed PKI. Option C is wrong because using a public CA for all IoT devices is costly, impractical for internal devices, and may not support automated lifecycle management at scale. Option D is wrong because an offline root CA with manual issuance does not support automation and is not scalable for thousands of devices.

124
MCQmedium

An enterprise is implementing a cloud security posture management (CSPM) solution. What is the primary function of CSPM?

A.Monitoring and remediating misconfigurations
B.Brokering access to cloud apps
C.Protecting workloads from malware
D.Encrypting data at rest
AnswerA

CSPM continuously compares deployed cloud resource configurations against security baselines and compliance policies, then flags or automatically remediates drift such as public storage buckets or permissive security groups. That misconfiguration monitoring and remediation is precisely the primary function the scenario asks for.

Why this answer

CSPM tools continuously scan cloud environments for misconfigurations such as publicly exposed storage buckets, overly permissive IAM roles, and disabled logging, then alert or automatically remediate them. This aligns directly with option A. CSPM is a core pillar of cloud-native security alongside CWPP and CIEM.

Exam trap

The trap is confusing CSPM with CASB or CWPP; candidates see 'cloud security' and pick the malware or access-brokering option without distinguishing posture management from runtime protection or access control.

How to eliminate wrong answers

Option B is wrong because brokering access to cloud apps is the function of a Cloud Access Security Broker (CASB), not CSPM. Option C is wrong because protecting workloads from malware is the domain of Cloud Workload Protection Platform (CWPP) tools, which focus on runtime and host-level threats. Option D is wrong because encrypting data at rest is a data protection control handled by cloud provider encryption services, key management systems, or database encryption features, not by CSPM.

125
MCQhard

A security architect is designing an API security strategy for a microservices-based application. The architect needs to ensure that only authenticated and authorized clients can invoke APIs, and that rate limiting is enforced to prevent abuse. Which technology should be placed in front of the microservices?

A.API Gateway
B.Web Application Firewall (WAF)
C.Reverse proxy
AnswerA

An API gateway terminates client requests and enforces authentication, authorisation and rate limiting centrally before forwarding to microservices, so only validated clients invoke backends. This satisfies the requirement for centralised access control and abuse prevention.

Why this answer

An API Gateway is designed to handle authentication, authorization, rate limiting, and other cross-cutting concerns for APIs in a microservices architecture. It acts as a single entry point for all API calls, enforcing security policies before requests reach the microservices. This centralizes API security and simplifies management.

Exam trap

CAS-005 often tests the difference between API Gateway and WAF. Candidates may choose WAF because it sounds security-focused, but WAF does not provide API authentication and rate limiting for microservices.

How to eliminate wrong answers

Option B is wrong because a WAF protects web applications from common attacks (e.g., SQL injection, XSS) but does not provide API-specific authentication, authorization, or rate limiting for microservices. Option C is wrong because a reverse proxy forwards requests but lacks built-in API security features like authentication and rate limiting. Option D is wrong because a load balancer distributes traffic but does not enforce API security policies.

126
MCQeasy

A security administrator needs to ensure that only authorized devices can access the corporate network. Which technology would best enforce this requirement at the network access layer?

A.TLS 1.3
D.DNSSEC
AnswerC

802.1X performs port-based network access control, requiring devices to authenticate via EAP before gaining Layer 2 connectivity. This enforces the requirement that only authorised devices reach the corporate network, blocking rogue hardware at the access layer.

Why this answer

802.1X is an IEEE standard for port-based network access control (NAC) that authenticates devices before granting access to the network. It ensures that only authorized devices can connect to a switch port or wireless access point, enforcing access control at the network access layer.

Exam trap

CAS-005 often tests network access control by offering VPN or TLS as options. Candidates may confuse remote access security with local network access control, but 802.1X is specifically for authenticating devices at the network edge.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 is a cryptographic protocol for securing communications, not for network access control. Option B is wrong because IPsec VPN provides secure tunnels for remote access but does not enforce device authorization at the network access layer for local connections. Option D is wrong because DNSSEC secures DNS responses but does not control network access.

127
MCQhard

An organization wants to implement an immutable infrastructure for its containerized applications. Which security benefit is most directly achieved by immutability?

A.Eliminates need for runtime security monitoring
B.Prevents unauthorized modifications to running containers
C.Allows use of privileged containers securely
D.Reduces image scanning frequency
AnswerB

Immutability means running containers are never patched in place; any change requires redeploying a fresh image. Because the container filesystem and process are not writable by operators or attackers, unauthorised modification of a live container is prevented, satisfying the stem's requirement directly.

Why this answer

Immutable infrastructure means containers are deployed from a fixed, versioned image and are never modified in place — any change requires redeploying a new container. This design directly prevents unauthorized or accidental modifications to running containers, since the running instance is treated as read-only and any drift is discarded on replacement. The security benefit is integrity enforcement: attackers cannot persist by editing files inside a live container because the container is ephemeral and replaced from a trusted image.

Exam trap

The trap here is conflating immutability with complete runtime security — candidates often assume that if containers cannot be modified, no runtime monitoring is needed, but immutability only protects the filesystem and image, not in-memory or process-level threats.

How to eliminate wrong answers

Option A is wrong because immutability does not remove the need for runtime security monitoring — runtime threats such as memory exploits, cryptomining, and anomalous process execution still occur inside immutable containers, so tools like Falco or runtime EDR remain necessary. Option C is wrong because immutability does nothing to make privileged containers safe; a privileged container still has host-level capabilities and kernel access, so immutability does not mitigate that risk. Option D is wrong because immutability does not reduce image scanning frequency — images still need scanning for CVEs at build time and on registry updates, and immutable deployments often increase the need for consistent scanning pipelines.

128
MCQmedium

A company uses a hybrid cloud model with workloads on AWS and on-premises. They need to ensure secure connectivity between the two environments with high bandwidth and low latency, bypassing the public internet. Which solution should they implement?

A.Configure AWS Direct Connect for dedicated private connectivity
B.Implement SD-WAN with integrated security
C.Establish a site-to-site VPN over the internet
D.Use AWS PrivateLink to access VPC endpoints
AnswerA

AWS Direct Connect provisions a dedicated private network link between on-premises infrastructure and AWS, bypassing the public internet. This satisfies the hybrid requirement for high bandwidth, low latency and consistent connectivity, unlike VPN tunnels that traverse public networks.

Why this answer

AWS Direct Connect provides a dedicated, private network connection between on-premises infrastructure and AWS, bypassing the public internet entirely. It delivers consistent high bandwidth and low latency, which is exactly what hybrid workloads requiring predictable performance need. Because traffic never traverses the public internet, Direct Connect also improves security posture by reducing exposure to internet-based threats.

Exam trap

The trap is confusing 'private connectivity' solutions — candidates pick PrivateLink or VPN thinking they provide dedicated bandwidth, but only Direct Connect offers a dedicated, non-internet circuit with guaranteed performance characteristics.

How to eliminate wrong answers

Option B is wrong because SD-WAN with integrated security optimizes and secures traffic over multiple WAN links, but it still typically uses public internet or MPLS transports and does not provide the dedicated private AWS connectivity the scenario requires. Option C is wrong because a site-to-site VPN runs over the public internet, which introduces variable latency, jitter, and bandwidth constraints — it does not meet the 'bypassing the public internet' requirement. Option D is wrong because AWS PrivateLink provides private connectivity to specific VPC endpoints and services within AWS, not a dedicated high-bandwidth link between on-premises and AWS.

129
MCQhard

A healthcare provider is designing a new system to process protected health information (PHI) in a public cloud. The security architect must ensure that data is encrypted at rest and that the organization retains full control over the encryption keys, including the ability to revoke access immediately if a cloud administrator account is compromised. The cloud provider must not be able to decrypt the data. Which of the following key management approaches BEST meets these requirements?

A.Customer-managed keys (CMK) stored in the cloud provider's KMS with key rotation enabled
B.Provider-managed keys stored in the cloud provider's key management service (KMS)
C.Bring Your Own Key (BYOK) where the customer imports keys into the provider's KMS
D.Hold Your Own Key (HYOK) with keys stored in an external hardware security module (HSM) under the organization's control
AnswerD

HYOK keeps the root keys in an external HSM managed by the organization, outside the cloud provider's control. The provider only receives wrapped data keys, so it cannot decrypt data. Revoking access is immediate by disabling the external HSM or key, satisfying all requirements.

Why this answer

HYOK with an external HSM ensures the organization retains sole control of root keys, preventing the cloud provider from decrypting data. Because the external HSM is outside the provider's environment, access can be revoked immediately by disabling the key, which meets the strict confidentiality and revocation requirements for PHI.

Exam trap

The trap here is conflating BYOK with HYOK; BYOK imports keys into the provider's KMS, where the provider can still access them, whereas HYOK keeps keys external and under customer control.

130
Multi-Selectmedium

A security architect is implementing network segmentation in a hybrid cloud environment. Which TWO controls are most effective for reducing east-west traffic risks?

Select 2 answers
A.Micro-segmentation
B.VPN concentrator
D.East-west traffic inspection
E.Perimeter firewall
AnswersA, D

Micro-segmentation enforces granular firewall rules at the workload or pod level, using distributed virtual firewalls or network security groups to restrict lateral movement between application tiers. This directly reduces east-west traffic risks in a hybrid cloud by limiting the blast radius of a compromised host, satisfying the constraint of controlling internal, cross-subnet communication rather than perimeter ingress.

Why this answer

Micro-segmentation (A) is correct because it applies granular, workload-level security policies—typically via host-based agents or SDN constructs—that restrict lateral (east-west) movement between workloads even inside the same subnet or VPC, directly reducing east-west risk. East-west traffic inspection (D) is correct because it examines internal traffic flows (e.g., via next-generation firewalls, IDS/IPS, or virtual taps) to detect and block lateral movement, malicious scanning, and exfiltration that perimeter controls would miss. VPN concentrator (B) is not correct because it secures remote-access or site-to-site north-south connectivity, not internal lateral traffic.

NAT gateway (C) is not correct because it provides outbound internet address translation and does not inspect or segment internal east-west flows. Perimeter firewall (E) is not correct because it primarily enforces north-south boundary controls and does not address lateral movement within the segmented environment.

Exam trap

The trap is mixing north-south and east-west controls — candidates select perimeter firewalls or VPN concentrators, which protect the boundary or remote access, instead of controls that specifically govern lateral internal traffic.

131
MCQhard

A healthcare provider must allow clinicians to access a SaaS electronic health record from unmanaged personal devices without installing agents. The security architect needs to enforce contextual access decisions based on device posture, user identity, and location, while keeping the EHR session isolated from the local browser. Which of the following should the architect implement?

A.A next-generation firewall (NGFW) with TLS inspection and application control.
B.A cloud access security broker (CASB) in API mode with data loss prevention policies.
C.A virtual desktop infrastructure (VDI) environment hosted in the provider's data center.
D.A Secure Access Service Edge (SASE) platform with a remote browser isolation (RBI) component and identity-based policies.
AnswerD

SASE converges network and security functions with identity-aware policy. Remote browser isolation renders the EHR session in a disposable cloud container, so no data touches the unmanaged device, and access decisions can incorporate user identity, device posture signals, and geolocation. This satisfies agentless access and contextual enforcement while isolating the session.

Why this answer

The need is agentless access from unmanaged devices with contextual decisions and session isolation. A SASE platform with remote browser isolation and identity-based policies enforces access based on user, device posture, and location while keeping the EHR session in a cloud container. VDI, API-mode CASB, and NGFW each address parts of the problem but fail to deliver the combined agentless, contextual, isolated access.

Exam trap

The trap here is treating CASB as sufficient for unmanaged device access, when API-mode CASB governs data at rest and does not isolate or control the live browser session.

132
MCQmedium

A security architect is implementing a zero trust model for a financial services company. The goal is to prevent lateral movement in the data center. Which approach best achieves this objective?

A.Using a software-defined perimeter to hide network resources
B.Implementing identity-centric access controls across all resources
C.Applying defense-in-depth layering by adding multiple security controls
D.Deploying micro-segmentation to isolate workloads and enforce granular policies
AnswerD

Micro-segmentation enforces least-privilege east-west controls between individual workloads, so a compromised host cannot reach unrelated systems. This directly satisfies the stem's constraint of preventing lateral movement inside the data centre, unlike perimeter or identity-only controls that leave internal traffic largely trusted.

Why this answer

Micro-segmentation isolates workloads and enforces granular, identity- and label-based policies on east-west traffic, which directly prevents lateral movement inside the data center. In a zero trust model, micro-segmentation operationalizes the 'never trust, always verify' principle at the workload level, so a compromised host cannot freely reach other workloads. This is the most direct and effective control for the stated objective of stopping lateral movement.

Exam trap

The trap is selecting a broad zero trust principle (identity-centric controls, defense-in-depth) instead of the specific technical control — micro-segmentation — that directly addresses lateral movement in the data center.

How to eliminate wrong answers

Option A is wrong because a software-defined perimeter (SDP) hides resources from unauthorized users and is primarily used for secure application access (north-south), not for containing lateral movement between internal workloads. Option B is wrong because identity-centric access controls are foundational to zero trust but address authentication and authorization at access points; they do not by themselves segment workload-to-workload traffic inside the data center. Option C is wrong because defense-in-depth layering adds controls but is a general strategy, not a specific mechanism that prevents lateral movement the way micro-segmentation does.

133
MCQeasy

A security architect is designing a network for a small business that wants to allow employees to use their personal smartphones and tablets to access corporate email and files. The company wants to enforce screen lock, encryption, and remote wipe on these devices without managing the entire device. Which of the following should the architect implement?

A.Mobile device management (MDM) with full device enrollment for all personal devices.
B.Network access control (NAC) that checks personal devices for compliance before granting access to the corporate network.
C.Virtual desktop infrastructure (VDI) accessed from personal devices through a web browser.
D.Mobile application management (MAM) with containerization of corporate applications.
AnswerD

MAM with containerization allows the company to enforce policies such as screen lock, encryption, and remote wipe on the corporate applications and data only, without managing the entire personal device. This preserves employee privacy and is the appropriate solution for a BYOD scenario where the company wants to control corporate data but not the whole device. It directly meets the stated requirements.

Why this answer

Mobile application management (MAM) with containerization enforces policies on corporate applications and data without managing the entire personal device. It supports screen lock, encryption, and remote wipe for corporate data, preserving employee privacy. Full MDM enrollment controls the whole device, VDI does not enforce device-level policies, and NAC only checks compliance at network access time, so MAM is the correct choice.

Exam trap

The trap here is conflating mobile device management with mobile application management, when the scenario explicitly requires controlling corporate data without managing the entire personal device.

134
MCQeasy

A security architect is reviewing the company's incident response plan and wants to ensure that the team can detect and respond to threats in real time across endpoints, networks, and cloud workloads. The architect needs a solution that correlates events from multiple sources and provides automated response actions. Which technology should the architect recommend?

A.Security information and event management (SIEM) with security orchestration, automation, and response (SOAR) capabilities.
B.Endpoint detection and response (EDR) deployed only on servers.
C.Network detection and response (NDR) with full packet capture at the perimeter.
D.A vulnerability scanner with scheduled scans of all assets.
AnswerA

SIEM aggregates and correlates logs from multiple sources, while SOAR provides automated response actions and orchestration. Together they enable real-time detection and automated response across endpoints, networks, and cloud workloads, meeting the requirement for correlated events and automation.

Why this answer

A SIEM with SOAR capabilities is the correct choice because it centralizes log collection and correlation from diverse sources and enables automated response workflows. This combination provides the real-time detection and orchestrated response across endpoints, networks, and cloud workloads that the incident response plan requires.

Exam trap

The trap here is thinking that a single-domain tool such as EDR or NDR can cover all environments, when the requirement specifically calls for cross-domain correlation and automation.

135
MCQmedium

A security architect is designing a secure connection between an on-premises data center and a cloud provider's virtual network. The connection must be private, low-latency, and not traverse the public internet. Which solution should they recommend?

A.Software-Defined WAN (SD-WAN)
B.Cloud Access Security Broker (CASB)
C.Site-to-site VPN over the internet
D.Direct Connect / ExpressRoute
AnswerD

Direct Connect and ExpressRoute provide dedicated private circuits between on-premises infrastructure and the cloud provider's network, bypassing the public internet entirely. This satisfies the private, low-latency, non-internet-traversing constraints that site-to-site VPN over the internet cannot guarantee.

Why this answer

Direct Connect (AWS) and ExpressRoute (Azure) are dedicated private circuits from the on-premises data center to the cloud provider's network, providing low-latency, high-bandwidth connectivity that never traverses the public internet. This matches all three stated requirements: private, low-latency, and no public internet traversal.

Exam trap

The trap is assuming 'VPN = private' — candidates select site-to-site VPN because it is encrypted, but encryption does not change the fact that IPsec VPN traffic still traverses the public internet, which the question explicitly forbids.

How to eliminate wrong answers

Option A is wrong because SD-WAN optimizes and manages WAN traffic across multiple transports (often including the internet) but does not inherently provide a private, non-internet path to a specific cloud VNet. Option B is wrong because a CASB is a policy/visibility control for cloud service usage, not a network transport mechanism. Option C is wrong because a site-to-site VPN over the internet is encrypted but still traverses the public internet, violating the 'not traverse the public internet' requirement and typically adding latency variability.

136
MCQhard

A security architect is designing a hybrid cloud environment with workloads in AWS and on-premises. The architect needs to ensure secure, low-latency connectivity between the two environments without traversing the internet. Which solution should be used?

A.AWS Direct Connect
B.Site-to-site VPN over the internet
C.AWS Client VPN
D.AWS Transit Gateway with internet gateway
AnswerA

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet entirely. This satisfies both constraints in the stem: low latency, since traffic avoids internet routing variability, and security, since data never traverses public infrastructure. Site-to-Site VPN would encrypt traffic but still traverse the internet, failing the no-internet requirement.

Why this answer

AWS Direct Connect provides dedicated private network connectivity from on-premises to AWS, offering low latency and security without internet exposure.

137
MCQmedium

A security architect is designing a defense-in-depth strategy for a web application. Which combination of controls provides overlapping protection against SQL injection attacks?

A.Encryption and hashing
B.Input validation and parameterized queries
C.Intrusion detection system (IDS) and antivirus
D.Web application firewall (WAF) and network segmentation
AnswerB

Input validation rejects malformed or suspicious input at the boundary, while parameterised queries ensure user-supplied values are treated as data, never executable SQL. Together they provide overlapping defence: if validation is bypassed, parameterisation still prevents injected statements from altering query structure.

Why this answer

Input validation and parameterized queries provide overlapping, defense-in-depth protection against SQL injection: input validation rejects malformed or malicious input at the application boundary, while parameterized queries ensure user input is treated as data, not executable SQL, even if validation is bypassed. Together they address the root cause of SQLi at multiple layers.

Exam trap

CAS-005 often tests defense-in-depth by presenting perimeter controls (WAF, IDS) as tempting answers — candidates must recognize that overlapping protection against a specific application flaw requires controls at the application layer, not just the network layer.

How to eliminate wrong answers

Option A is wrong because encryption and hashing protect data confidentiality and integrity at rest or in transit, but they do not prevent SQL injection — an attacker can still inject SQL into an encrypted database connection. Option C is wrong because IDS and antivirus are detective/preventive controls for network and endpoint threats, not application-layer injection flaws; IDS may alert after the fact but does not stop SQLi. Option D is wrong because a WAF and network segmentation are perimeter controls — a WAF can block known SQLi patterns but is bypassable with obfuscation, and network segmentation does not address the application's query construction flaw, so they do not provide the overlapping application-layer protection the question requires.

138
Multi-Selectmedium

A financial institution is implementing a secure software development lifecycle (SSDLC) for a new web application that will handle sensitive transactions. The security architect must ensure that application security testing is integrated into the development process. Which THREE testing techniques should be used to identify vulnerabilities early and throughout the lifecycle? (Choose THREE.)

Select 3 answers
A.Static Application Security Testing (SAST)
B.Runtime Application Self-Protection (RASP)
C.Interactive Application Security Testing (IAST)
D.Dynamic Application Security Testing (DAST)
E.Threat modeling
AnswersA, C, D

SAST analyses source code without executing it, flagging injection flaws, insecure patterns and coding errors during development. This satisfies the SSDLC requirement to identify vulnerabilities early, before code reaches testing or production, reducing remediation cost for the sensitive-transaction application.

Why this answer

SAST (A) is correct because it analyzes source code, bytecode, or binaries without executing the application, allowing developers to find flaws such as injection patterns, insecure coding, and hardcoded secrets early in the SSDLC, even in CI pipelines. IAST (C) is correct because it instruments the running application and combines static and dynamic analysis to detect vulnerabilities during functional testing with high accuracy and code-level context, fitting continuous integration. DAST (D) is correct because it tests the deployed application from the outside by sending crafted requests to find runtime and configuration issues such as SQL injection, XSS, and authentication flaws in the running web app.

RASP (B) is not a testing technique but a runtime protection mechanism that detects and blocks attacks in production, so it does not identify vulnerabilities early in development. Threat modeling (E) is a design-phase risk analysis activity, not an application security testing technique, so it does not satisfy the requirement for testing throughout the lifecycle.

Exam trap

The trap is treating RASP as a testing tool because it shares the 'application security' label — candidates must distinguish runtime protection (RASP) from vulnerability discovery techniques (SAST/DAST/IAST).

139
MCQmedium

A company uses a multi-cloud strategy with workloads in AWS and Azure. They need a centralized solution to enforce consistent security policies across both cloud environments. Which type of tool should they deploy?

A.Cloud Access Security Broker (CASB)
B.Cloud Security Posture Management (CSPM)
C.Cloud Workload Protection Platform (CWPP)
D.Security Information and Event Management (SIEM)
AnswerB

CSPM continuously assesses configurations across AWS and Azure against a unified policy baseline, detecting misconfigurations and compliance drift in both environments. This directly satisfies the stem's requirement for centralised, consistent policy enforcement spanning multiple clouds, since CSPM ingests native APIs from each provider rather than relying on a single-vendor security stack.

Why this answer

CSPM continuously monitors cloud configurations against security benchmarks and compliance frameworks across multiple providers, providing a centralized view and policy enforcement for misconfigurations, drift, and compliance violations in AWS and Azure. This directly addresses the need for consistent security policy enforcement across both clouds.

Exam trap

The trap is conflating CSPM with CWPP — candidates pick CWPP because it also 'secures the cloud,' but the question is about configuration posture and policy consistency, not workload runtime protection.

How to eliminate wrong answers

Option A is wrong because a CASB focuses on governing SaaS and cloud service usage (shadow IT, DLP, access control) rather than assessing IaaS/PaaS configuration posture across providers. Option C is wrong because CWPP protects workloads (VMs, containers, serverless) at runtime — vulnerability scanning, EDR, and workload firewalling — not the configuration posture of the cloud control plane. Option D is wrong because a SIEM aggregates and correlates logs for detection and response; it does not enforce configuration policies or assess posture across clouds.

140
MCQmedium

A security architect at a healthcare provider must ensure that electronic protected health information (ePHI) stored in an on-premises Microsoft SQL Server database is unreadable if the physical media is stolen. The organization has strict performance requirements and cannot tolerate application changes or key management outside its own hardware security modules (HSMs). Which SQL Server feature BEST meets these requirements?

A.Dynamic Data Masking (DDM)
B.Always Encrypted with secure enclaves
C.Transparent Data Encryption (TDE)
D.Row-Level Security (RLS)
AnswerC

TDE performs real-time I/O encryption and decryption of the data and log files at the page level, protecting data at rest without application changes. It uses a database encryption key protected by a certificate stored in the master database, and the certificate can be backed by an HSM via Extensible Key Management, satisfying the key custody requirement while maintaining performance.

Why this answer

Transparent Data Encryption (TDE) encrypts the database files at rest without requiring application changes and supports key protection through an HSM via Extensible Key Management. The other options either require application modifications or do not encrypt data at rest, leaving the stolen media scenario unresolved.

Exam trap

The trap here is assuming that any SQL Server security feature that mentions encryption, such as Always Encrypted, will satisfy a data-at-rest requirement without considering application changes or key custody constraints.

141
MCQeasy

During a secure SDLC, a development team wants to identify vulnerabilities in running code. Which type of testing should be performed?

A.IAST
B.SAST
C.DAST
D.RASP
AnswerC

DAST tests a running application from the outside, exercising it as an attacker would and observing responses. This detects vulnerabilities in executing code, including runtime and configuration flaws that static analysis of source cannot reveal, matching the team's requirement.

Why this answer

DAST (Dynamic Application Security Testing) tests running applications from the outside by simulating attacks against a live deployment, which is exactly what is needed to identify vulnerabilities in running code. It analyzes the application in its deployed state, including runtime configuration and environment-specific issues.

Exam trap

CAS-005 often tests the SAST vs. DAST vs. IAST distinction — candidates may pick SAST because it is 'code testing,' but the key phrase 'running code' signals DAST, which tests the live application.

How to eliminate wrong answers

Option A is wrong because IAST (Interactive Application Security Testing) instruments the application from within during runtime, often combined with DAST or unit tests, but the question asks for testing running code from a black-box perspective — IAST requires agent instrumentation and is not the primary answer for identifying vulnerabilities in running code. Option B is wrong because SAST analyzes source code or binaries statically without executing the application, so it cannot find runtime or deployment-specific vulnerabilities. Option D is wrong because RASP (Runtime Application Self-Protection) is a protection mechanism that detects and blocks attacks at runtime, not a testing methodology for identifying vulnerabilities during SDLC.

142
MCQhard

An organization is implementing a hybrid cloud architecture and must ensure secure connectivity between its on-premises network and a public cloud VPC. The traffic includes sensitive data that must not traverse the internet. The solution must provide high bandwidth and low latency. Which connectivity option should the architect choose?

A.AWS Direct Connect
B.Site-to-Site VPN over the internet
C.AWS Client VPN
D.Internet gateway with encryption
AnswerA

AWS Direct Connect establishes a dedicated private network link from on-premises infrastructure to the VPC, keeping sensitive traffic off the internet. It delivers the required high bandwidth and low latency, satisfying the stem's explicit prohibition on internet traversal.

Why this answer

AWS Direct Connect provides a dedicated private network connection between on-premises and AWS that does not traverse the internet, delivering high bandwidth and consistent low latency. It is the only option that satisfies both the 'must not traverse the internet' and 'high bandwidth, low latency' requirements.

Exam trap

The trap is that candidates may choose a VPN because it encrypts traffic, but the question's hard constraint is that traffic must not traverse the internet — only Direct Connect satisfies that, and encryption can be layered on top separately.

How to eliminate wrong answers

Option B is wrong because a Site-to-Site VPN runs over the public internet, so sensitive traffic traverses the internet and latency is variable, violating the requirement. Option C is wrong because AWS Client VPN is a managed remote-access VPN for individual users, not a high-bandwidth site-to-site link between an on-premises network and a VPC. Option D is wrong because an internet gateway routes traffic over the public internet; adding encryption does not change the fact that traffic traverses the internet, and it does not provide dedicated bandwidth or low latency.

143
MCQeasy

A security architect is implementing defense-in-depth for a critical application. Which of the following is an example of a detective control?

AnswerD

An intrusion detection system monitors network or host activity and raises alerts on malicious patterns, which is detection after the fact rather than prevention. That matches the detective control requirement, unlike firewalls or access controls, which block activity and are preventive.

Why this answer

An intrusion detection system (IDS) is a detective control because it monitors network or host activity and generates alerts when it identifies suspicious or malicious behavior, allowing security teams to respond. Detective controls are designed to identify and log incidents after or during their occurrence, rather than preventing them outright. Encryption, ACLs, and firewalls are preventive controls that stop unauthorized access or protect data before an incident occurs.

Exam trap

The trap here is confusing preventive controls (encryption, ACLs, firewalls) with detective controls (IDS), as candidates often assume any security tool that 'protects' is detective, when in fact only monitoring/alerting tools qualify.

How to eliminate wrong answers

Option A is wrong because data encryption is a preventive control that protects confidentiality by making data unreadable to unauthorized parties, not a detective control. Option B is wrong because an access control list is a preventive control that enforces authorization decisions, blocking unauthorized access rather than detecting it. Option C is wrong because a firewall is a preventive control that filters traffic based on rules to block unwanted connections, not a monitoring or detection mechanism.

144
MCQhard

To protect against quantum computing attacks, a security architect is planning to transition to post-quantum cryptography. Which algorithm has been selected by NIST for general encryption (key encapsulation) in the PQC standard?

A.Falcon
B.CRYSTALS-Dilithium
C.CRYSTALS-Kyber
D.SPHINCS+
AnswerC

CRYSTALS-Kyber is the NIST-selected key encapsulation mechanism, standardised as ML-KEM (FIPS 203), designed for general encryption against quantum attacks. It satisfies the stem's requirement for a post-quantum key encapsulation algorithm, unlike CRYSTALS-Dilithium or Falcon, which NIST selected for digital signatures rather than encryption.

Why this answer

NIST selected CRYSTALS-Kyber as the primary standard for general encryption and key encapsulation (FIPS 203) in its post-quantum cryptography program. Kyber is a lattice-based KEM designed for efficient key establishment, making it the correct choice for general encryption.

Exam trap

The trap is confusing NIST's PQC selections — candidates must remember Kyber is the KEM for encryption, while Dilithium, Falcon, and SPHINCS+ are signature algorithms.

How to eliminate wrong answers

Option A is wrong because Falcon is a lattice-based digital signature algorithm selected by NIST for signatures (FIPS 206 draft), not for key encapsulation. Option B is wrong because CRYSTALS-Dilithium is a lattice-based digital signature algorithm (FIPS 204), not a KEM. Option D is wrong because SPHINCS+ is a stateless hash-based digital signature scheme (FIPS 205), also for signatures, not encryption.

145
MCQmedium

A healthcare organization is designing a new system to store patient records. The security architect must ensure that data at rest is encrypted and that cryptographic keys are rotated regularly without re-encrypting the entire database. Which of the following techniques should be used?

A.Transparent data encryption (TDE) with a single certificate used to encrypt the database.
B.Envelope encryption using a data encryption key (DEK) per record and a key encryption key (KEK) managed by a key management service (KMS).
C.Full database encryption with a single master key stored in a hardware security module (HSM).
D.Column-level encryption using a static symmetric key stored in a configuration file.
AnswerB

Envelope encryption uses a DEK to encrypt each record and a KEK to encrypt the DEK. To rotate keys, only the KEK needs to be rotated, and the DEKs are re-encrypted with the new KEK, not the data itself. This allows regular key rotation without re-encrypting the entire database. It also limits the scope of a compromised DEK to a single record.

Why this answer

Envelope encryption separates data encryption keys from key encryption keys. Each record is encrypted with a unique DEK, and the DEK is encrypted with a KEK. Rotating the KEK only requires re-encrypting the DEKs, not the data, enabling regular key rotation without massive re-encryption.

This is efficient, scalable, and limits the blast radius of a compromised key, making it ideal for healthcare data with strict compliance.

Exam trap

The trap here is assuming that any encryption at rest supports easy key rotation, when in fact full-database encryption often requires re-encryption.

146
MCQhard

A security architect is designing a microsegmentation strategy for a data center hosting both legacy monolithic applications and modern containerized workloads. The organization wants to enforce least-privilege network access between workloads without relying on IP addresses or VLANs, and it requires the ability to define policy based on workload identity and tags that follow the workload across environments. Which technology best meets these requirements?

A.Traditional stateful firewalls with static IP-based rules
B.Host-based microsegmentation using identity and tag-based policies
C.Software-defined networking (SDN) with VLAN segmentation
D.Network access control (NAC) with 802.1X port-based authentication
AnswerB

Host-based microsegmentation enforces security policy at the workload level using identity and tags rather than IP addresses. This allows policies to follow workloads across environments, including containers and legacy systems, and supports least-privilege access between individual workloads. It meets the requirement to decouple policy from network topology.

Why this answer

Host-based microsegmentation is the only option that enforces policy based on workload identity and tags, decoupling security from IP addresses and VLANs. This allows consistent least-privilege enforcement across legacy and containerized workloads and supports policy portability across environments.

Exam trap

The trap here is equating VLAN segmentation or NAC with microsegmentation, when true microsegmentation requires identity-based policy that follows the workload rather than the network location.

147
Multi-Selectmedium

A security architect is evaluating a CSPM tool for a multi-cloud environment. Which TWO capabilities should the architect consider essential for the CSPM? (Choose two.)

Select 2 answers
A.Continuous compliance monitoring against frameworks like CIS
B.Vulnerability scanning of container images
C.Configuration drift detection
D.Real-time web application firewall
E.Data loss prevention for cloud storage
AnswersA, C

Continuous compliance monitoring against benchmarks such as CIS satisfies the multi-cloud requirement by evaluating configurations across AWS, Azure and Google Cloud against a common control baseline, detecting drift as it occurs. This provides the ongoing assurance the architect needs, rather than a one-off point-in-time assessment.

Why this answer

Option A (Continuous compliance monitoring against frameworks like CIS) is essential because a CSPM's core purpose is to continuously assess cloud configurations against recognized benchmarks and standards such as CIS, PCI DSS, and NIST, providing ongoing assurance across the multi-cloud estate. Option C (Configuration drift detection) is also essential since CSPM must detect when resources deviate from approved secure baselines, whether through manual changes, automation, or IaC mismatches, and alert or remediate accordingly. Option B (Vulnerability scanning of container images) belongs to container/image scanning tools (e.g., Trivy, Clair) rather than CSPM, which focuses on cloud resource configuration posture.

Option D (Real-time web application firewall) is a runtime application protection control typically delivered by a WAF, not a posture management function. Option E (Data loss prevention for cloud storage) is a separate data-security capability (DLP) and, while complementary, is not a defining CSPM requirement.

Exam trap

CAS-005 often tests the boundary between CSPM (configuration/posture) and adjacent tools like CWPP, WAF, and DLP — candidates pick 'vulnerability scanning' or 'WAF' because they sound security-relevant, but CSPM is strictly about configuration posture and compliance.

148
MCQeasy

Which of the following is a core principle of the Zero Trust security model?

A.Perimeter-based trust
B.Never trust, always verify
C.Trust based on network location
D.Trust but verify
AnswerB

Zero Trust removes implicit trust based on network location, requiring every access request to be authenticated and authorised explicitly before granting resources. "Never trust, always verify" captures that continuous verification principle, which is the model's foundational tenet.

Why this answer

The core principle of Zero Trust is 'never trust, always verify,' which means that no user or device is trusted by default, regardless of whether they are inside or outside the network perimeter. Every access request must be authenticated, authorized, and encrypted before access is granted. This principle eliminates implicit trust based on network location.

Exam trap

The trap is selecting 'trust but verify' because it sounds similar to 'never trust, always verify,' but 'trust but verify' still implies initial trust, which contradicts Zero Trust's core tenet.

How to eliminate wrong answers

Option A is wrong because perimeter-based trust is the opposite of Zero Trust; it assumes that everything inside the network is trusted, which Zero Trust explicitly rejects. Option C is wrong because trusting based on network location is a traditional security model that Zero Trust replaces; Zero Trust does not grant trust based on being on the corporate network. Option D is wrong because 'trust but verify' is a Russian proverb often used in security, but it still implies an initial trust; Zero Trust starts with no trust and verifies every request.

149
MCQeasy

A security architect is reviewing the authentication design for a new customer portal that will be accessed by partners from multiple external organizations. The business wants partners to use their existing corporate identities, avoid creating new passwords for the portal, and allow the home organization to remain the authoritative source for disabling accounts. Which of the following should the architect recommend?

A.A shared partner account with per-user activity logging
B.Local account provisioning with mandatory password complexity and rotation
C.Certificate-based authentication with manually distributed client certificates
D.Federated identity using SAML or OpenID Connect with the partner identity providers
AnswerD

Federation trusts the partner's identity provider to authenticate users and assert identity claims to the portal. Partners keep their existing corporate credentials, and when the home organization disables an account, the next authentication attempt fails because the portal never holds the credential. This directly satisfies single sign-on, no new passwords, and home-organization authority over access.

Why this answer

Federated identity lets the portal rely on each partner organization's identity provider for authentication and account lifecycle. Partners use existing credentials, and disabling an account at the home organization immediately prevents new sessions because the portal consumes assertions rather than storing passwords. This is the standard pattern for business-to-business access with external identity sources.

Exam trap

The trap here is focusing on password strength for new accounts when the requirement is to avoid creating portal-managed credentials altogether.

150
MCQhard

An organization is migrating critical workloads to the cloud and must comply with FedRAMP. Which cloud service model provides the most customer control over security configuration while still leveraging the provider's FedRAMP authorization?

A.Software as a Service (SaaS)
B.Infrastructure as a Service (IaaS)
C.Platform as a Service (PaaS)
D.Function as a Service (FaaS)
AnswerB

IaaS lets the organisation manage its own operating systems, middleware and applications, giving maximum control over security configuration, while the provider's FedRAMP authorisation covers the underlying infrastructure. PaaS and SaaS shift more configuration responsibility to the provider, reducing customer control.

Why this answer

IaaS gives the customer control over the operating system, middleware, runtime, and applications while the provider manages the physical infrastructure, hypervisor, and network fabric. Under FedRAMP, the provider's authorization covers the underlying infrastructure, but the customer retains responsibility for configuring and securing everything above the hypervisor — offering the most security configuration control among the listed models while still leveraging the provider's FedRAMP package.

Exam trap

CAS-005 often tests the inverse relationship between abstraction level and customer control — candidates may assume PaaS or SaaS offers more control because it 'does more,' when in fact IaaS gives the customer the most configuration responsibility.

How to eliminate wrong answers

Option A is wrong because SaaS abstracts nearly all layers — the customer only controls data and user access, giving the least security configuration control. Option C is wrong because PaaS manages the OS, runtime, and middleware, leaving the customer with only application and data-layer control, which is less than IaaS. Option D is wrong because FaaS (serverless) abstracts even more than PaaS, with the customer controlling only function code and configuration, offering the least control of the compute models.

← PreviousPage 2 of 3 · 188 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Casp Security Architecture questions.