Courseiva

CCNA Casp Security Architecture Questions

38 of 188 questions · Page 3/3 · Casp Security Architecture topic · Answers revealed

151
MCQmedium

A healthcare organization is architecting a secure data exchange with a partner hospital. The partners need to share patient records in near real time, but they do not want to expose their internal databases directly. The security architect must ensure that only specific, authorized fields are exchanged, that the data is validated against a predefined schema, and that the exchange is auditable and resistant to tampering. Which approach best satisfies these requirements?

A.A shared message queue using AMQP with no message signing
B.A mutually authenticated API gateway with schema validation and signed messages
C.SFTP file drops of full database exports on a scheduled basis
D.Direct database replication between the two organizations over a VPN
AnswerB

A mutually authenticated API gateway allows the partners to expose only specific endpoints and fields, enforce schema validation, and log all exchanges for auditability. Digital signatures on messages provide tamper resistance and non-repudiation. This approach avoids direct database exposure and meets the real-time, least-privilege, and audit requirements.

Why this answer

A mutually authenticated API gateway with schema validation and signed messages enables selective field exchange, real-time communication, strict schema enforcement, and tamper-resistant auditing. It avoids exposing internal databases and provides the necessary security controls for partner data sharing.

Exam trap

The trap here is underestimating the need for schema validation and message signing, and assuming that any encrypted transport such as a VPN or SFTP is sufficient for secure data exchange.

152
MCQmedium

An organization is concerned about quantum computer attacks on its current cryptographic infrastructure. Which of the following NIST-approved post-quantum cryptographic algorithms is designed for key encapsulation?

A.RSA-4096
B.CRYSTALS-Kyber
C.ECDHE
D.CRYSTALS-Dilithium
AnswerB

CRYSTALS-Kyber is a lattice-based key encapsulation mechanism (KEM), standardised by NIST as ML-KEM, which secures symmetric keys through public-key encryption. It directly satisfies the stem's requirement for a post-quantum algorithm designed for key encapsulation, unlike CRYSTALS-Dilithium or SPHINCS+, which are digital signature schemes.

Why this answer

CRYSTALS-Kyber is a NIST-approved post-quantum cryptographic algorithm designed for key encapsulation (KEM), selected in the NIST PQC standardization process. It is based on module learning with errors (MLWE) and provides secure key exchange resistant to quantum attacks. RSA-4096 and ECDHE are classical algorithms vulnerable to quantum computers, and CRYSTALS-Dilithium is designed for digital signatures, not key encapsulation.

Exam trap

The trap is confusing key encapsulation with digital signatures; candidates may pick CRYSTALS-Dilithium because it is also a NIST PQC algorithm, but it is for signatures, not KEM.

How to eliminate wrong answers

Option A is wrong because RSA-4096 is a classical public-key algorithm based on integer factorization, which is vulnerable to Shor's algorithm on a quantum computer. Option C is wrong because ECDHE is a classical key exchange based on elliptic-curve discrete logarithms, also vulnerable to quantum attacks. Option D is wrong because CRYSTALS-Dilithium is a NIST-approved post-quantum algorithm for digital signatures, not key encapsulation.

153
MCQmedium

A security architect is evaluating a SASE solution. Which capability is expected to be part of a SASE platform?

A.Intrusion prevention system (IPS) at the data center
B.Network segmentation via VLANs
C.Secure web gateway (SWG)
D.Virtual private network (VPN) concentrator
AnswerC

Secure web gateway is a core SASE capability, filtering web traffic and enforcing acceptable-use and threat policies at the cloud edge. SASE converges SWG with CASB, ZTNA and FWaaS, so SWG satisfies the expected-capability constraint rather than endpoint or on-premises controls.

Why this answer

Secure Web Gateway (SWG) is one of the core converged capabilities of a SASE platform, alongside CASB, ZTNA, FWaaS, and SD-WAN. SASE merges network and security functions into a cloud-delivered service, and SWG provides web filtering, malware inspection, and policy enforcement for user web traffic. It is explicitly expected in a SASE architecture.

Exam trap

CAS-005 often tests whether candidates can distinguish legacy on-premises controls (IPS appliances, VPN concentrators, VLANs) from the cloud-delivered converged services that define SASE — SWG is the canonical correct answer.

How to eliminate wrong answers

Option A is wrong because an IPS deployed at the data center is a traditional perimeter security control, not a cloud-delivered SASE component; SASE expects FWaaS/IPS capabilities delivered from the cloud edge, not a data-center appliance. Option B is wrong because VLAN-based network segmentation is a legacy LAN construct and is not a SASE capability — SASE uses identity- and policy-based microsegmentation delivered from the cloud. Option D is wrong because a VPN concentrator is a traditional remote-access appliance; SASE replaces this with ZTNA and cloud-delivered secure access rather than a centralized concentrator.

154
MCQmedium

A financial services firm is designing a new online banking platform. The security architect must ensure that if the session token issued to a customer is stolen via a cross-site scripting attack, the attacker cannot use it from a different device or network. Which of the following should be implemented to meet this requirement?

A.Shortening the session token lifetime to five minutes and requiring re-authentication.
B.Token binding that cryptographically ties the session token to the client's TLS connection.
C.Encrypting the session token with AES-256 before writing it to the client's local storage.
D.Storing the session token in an HttpOnly cookie with the Secure and SameSite attributes.
AnswerB

Token binding uses the TLS layer to cryptographically associate the token with the client's key pair, so a stolen token cannot be replayed from a different TLS connection or device. This directly blocks the cross-device reuse scenario described, even if the token value is exfiltrated through XSS.

Why this answer

Token binding is the only mechanism that cryptographically links the session token to the client's TLS connection, so a token stolen via XSS cannot be replayed from a different device or network. Lifetime reduction, cookie flags, and local storage encryption mitigate other risks but do not satisfy the explicit cross-device reuse requirement.

Exam trap

The trap here is assuming that cookie security flags or shorter lifetimes prevent token replay across devices, when only cryptographic binding to the client's TLS session actually stops cross-device reuse.

155
MCQhard

A healthcare provider must ensure that electronic protected health information (ePHI) stored in a public cloud object storage bucket is unreadable to the cloud provider and remains confidential even if the provider's infrastructure is compromised. The security architect wants to use a customer-managed key that never leaves the organization's on-premises hardware security module (HSM). Which approach should the architect implement?

A.Configure default encryption on the bucket using a provider-managed key and enable versioning
B.Enable provider-side encryption with a customer-provided key (SSE-C) and upload the key with each object request
C.Implement bucket policies that restrict access to a specific VPC endpoint and enable access logging
D.Use client-side encryption with a key stored in an on-premises HSM, encrypting data before it is uploaded to the bucket
AnswerD

Client-side encryption performed before upload ensures that the cloud provider only receives ciphertext and never has access to the plaintext or the encryption key. Keeping the key in an on-premises HSM prevents the provider from decrypting data even if its infrastructure is compromised, fully meeting the confidentiality requirement.

Why this answer

Client-side encryption with keys held in an on-premises HSM ensures that data is encrypted before it reaches the cloud, so the provider only stores ciphertext and never possesses the key. This architecture preserves confidentiality even if the provider's infrastructure is breached, which is essential for ePHI under strict regulatory requirements.

Exam trap

The trap here is confusing provider-side encryption options, such as SSE-C, with true customer-controlled encryption where the key never leaves the customer's premises.

156
MCQhard

A security architect is designing a PKI for a large organization. The architect wants to ensure that private keys are stored securely and that cryptographic operations are performed in a tamper-resistant environment. Which solution should be used?

A.Trusted Platform Module (TPM)
B.Hardware Security Module (HSM)
C.Software-based keystore
D.Key Management Service (KMS) in the cloud
AnswerB

An HSM stores private keys in tamper-resistant hardware and performs cryptographic operations internally, so keys are never exposed in software memory. This satisfies both stem constraints: secure private key storage and execution within a tamper-resistant environment.

Why this answer

An HSM is a dedicated, tamper-resistant hardware appliance that generates, stores, and uses cryptographic keys without ever exposing them to the host OS or application memory. It provides FIPS 140-2/3 validated key protection and performs crypto operations (signing, encryption, key wrapping) inside the secure boundary. For a PKI requiring secure private key storage and tamper-resistant cryptographic operations at scale, an HSM (or cloud HSM service) is the correct answer.

Exam trap

CAS-005 often tests the distinction between KMS (managed, software-centric key service) and HSM (dedicated tamper-resistant hardware); candidates pick KMS because it 'manages keys' but miss the tamper-resistant hardware requirement.

How to eliminate wrong answers

Option A is wrong because a TPM is a single-chip, host-bound module designed to protect keys for one machine (e.g., BitLocker, measured boot); it is not a scalable, network-accessible PKI key store and does not provide the throughput or multi-tenant key management an enterprise PKI requires. Option C is wrong because a software-based keystore stores keys in files or memory protected only by OS permissions — keys can be extracted via memory dumps or privilege escalation, and there is no tamper-resistant hardware boundary. Option D is wrong because a general cloud KMS provides managed key storage and rotation, but it is typically a multi-tenant software service (unless backed by Cloud HSM); it does not by itself guarantee a dedicated tamper-resistant hardware boundary for all cryptographic operations the way an HSM does.

157
MCQhard

An organization is adopting a SASE architecture to provide secure access to cloud applications. Which component is essential for enforcing security policies based on user identity and device posture?

A.Zero Trust Network Access (ZTNA)
B.Firewall as a Service (FWaaS)
C.Secure Web Gateway (SWG)
D.Cloud Access Security Broker (CASB)
AnswerA

ZTNA brokers each session, verifying user identity and device posture before granting least-privilege access to specific applications rather than the whole network. This identity- and posture-based policy enforcement satisfies the SASE requirement, unlike IP-centric VPNs or proxy-only controls.

Why this answer

Zero Trust Network Access (ZTNA) is essential for enforcing security policies based on user identity and device posture in a SASE architecture. ZTNA provides secure, identity-based access to applications, ensuring that only authenticated and authorized users with compliant devices can connect, regardless of location.

Exam trap

CAS-005 often tests the confusion between SASE components. Candidates may select CASB or SWG because they are also part of SASE, but only ZTNA enforces policies based on user identity and device posture.

How to eliminate wrong answers

Option B is wrong because Firewall as a Service (FWaaS) provides network-level security but does not enforce policies based on user identity and device posture; it focuses on traffic filtering. Option C is wrong because Secure Web Gateway (SWG) primarily filters web traffic and enforces acceptable use policies, but it does not provide identity-based access to applications. Option D is wrong because Cloud Access Security Broker (CASB) provides visibility and control over cloud services, but it does not enforce access based on device posture; it focuses on data security and compliance.

158
MCQeasy

Which of the following best describes the security benefit of using an API gateway in a microservices architecture?

A.It eliminates the need for input validation in individual microservices
B.It encrypts all data between the client and server using mTLS
C.It enforces security policies such as authentication and rate limiting centrally
D.It automatically load balances traffic to ensure high availability
AnswerC

An API gateway sits in front of microservices and applies authentication, authorisation, throttling and rate limiting at that single ingress point. This centralises enforcement, so individual services need not each implement these controls, satisfying the requirement for consistent, centrally managed security policy.

Why this answer

An API gateway sits in front of microservices and acts as a single entry point for all client requests, making it the ideal enforcement point for cross-cutting security controls. Centralizing authentication (e.g., OAuth2/JWT validation), authorization, rate limiting, and threat protection at the gateway means individual microservices don't each need to reimplement these policies. This reduces attack surface and ensures consistent policy enforcement across the entire API estate.

Exam trap

The trap here is conflating availability features (load balancing) with security features, or assuming the gateway replaces rather than centralizes security controls — candidates often pick the 'eliminates validation' answer because it sounds efficient.

How to eliminate wrong answers

Option A is wrong because input validation must still occur within each microservice — the gateway can perform schema validation but cannot replace service-level business logic validation, and relying solely on the gateway violates defense-in-depth. Option B is wrong because while API gateways can terminate TLS and support mTLS, they do not inherently 'encrypt all data' — encryption depends on configuration, and mTLS is a mutual authentication mechanism, not a blanket encryption guarantee. Option D is wrong because load balancing is an availability/scalability function, not a security benefit, and it does not describe the security value the question asks about.

159
MCQmedium

A security architect is evaluating a SASE solution. Which component of SASE is primarily responsible for inspecting encrypted traffic for threats?

A.Zero Trust Network Access (ZTNA)
B.Next-generation firewall (NGFW)
C.Secure web gateway (SWG)
D.SD-WAN edge
AnswerC

The secure web gateway performs full TLS inspection, decrypting outbound sessions, applying URL filtering, malware scanning and data-loss rules, then re-encrypting traffic. That decryption capability is what lets SASE inspect encrypted traffic for threats, unlike components such as SD-WAN or zero-trust network access.

Why this answer

The Secure Web Gateway (SWG) is the SASE component that proxies outbound user web traffic and performs full TLS inspection, URL filtering, malware scanning, and DLP on decrypted content. Because it terminates and re-originates TLS sessions, it can inspect encrypted traffic for threats. This is its core function within the SASE stack.

Exam trap

CAS-005 often tests the SASE component mapping; candidates confuse ZTNA (access to private apps) with SWG (inspection of outbound web traffic), or assume NGFW handles all inspection in a SASE model.

How to eliminate wrong answers

Option A is wrong because ZTNA provides identity- and context-based access to internal applications (replacing VPN), not inspection of outbound web traffic for threats; it enforces access, it does not decrypt and scan content. Option B is wrong because an NGFW enforces network-layer policy (L3-L7) at the perimeter or between segments, but in SASE architectures the SWG — not the NGFW — is the component designed for full web traffic TLS inspection and content threat scanning. Option D is wrong because the SD-WAN edge handles WAN transport optimization, path selection, and connectivity, not content inspection or TLS decryption.

160
MCQmedium

A company is migrating its workloads to a public cloud and wants to ensure it understands the division of security responsibilities. Which model defines the demarcation of security controls between the cloud provider and the customer?

A.Cloud Security Posture Management (CSPM)
B.Zero trust architecture
C.Cloud Access Security Broker (CASB)
D.Shared responsibility model
AnswerD

The shared responsibility model divides security controls along the cloud service model's boundary: the provider secures the physical hosts, network and hypervisor up to the layer it operates, while the customer secures what they configure, such as data, identities and access policies. This directly answers the stem's need to understand the demarcation of controls between provider and customer.

Why this answer

The shared responsibility model clearly delineates which security tasks are handled by the cloud provider and which by the customer, varying by service type (IaaS, PaaS, SaaS).

161
Multi-Selecthard

A security architect is designing a data loss prevention (DLP) program for a company that uses Microsoft 365 and a SaaS CRM. The architect must reduce false positives while still detecting sensitive data leaving the environment. Which TWO capabilities should be prioritized? (Choose two.)

Select 2 answers
A.Blocking all outbound email attachments larger than 10 MB
B.Keyword lists built from common industry terms such as 'confidential' and 'internal use'
C.Trainable classifiers that learn from labeled examples of the organization's confidential documents
D.Exact data matching (EDM) against a hashed fingerprint of the organization's customer records
E.Regular expressions that match any nine-digit number as a potential account identifier
AnswersC, D

Trainable classifiers use machine learning on labeled samples to recognize categories such as contracts or source code, which pattern matching cannot. Combining them with EDM lets the program detect both known records and semantic categories, improving coverage without flooding analysts with false positives from generic regex rules.

Why this answer

High-fidelity DLP combines exact data matching, which fingerprints the organization's own sensitive records, with trainable classifiers that recognize document categories from labeled examples. Together they detect both known data and semantically sensitive content while avoiding the noise of generic regex or keyword rules. Size limits and broad patterns do not target sensitive content and increase false positives.

Exam trap

The trap here is assuming broader detection rules always improve DLP, when in fact overly broad patterns and keywords drive false positives and analyst fatigue.

162
MCQeasy

Which of the following is a cloud-native security control provided by a cloud service provider to manage user permissions and access to resources?

A.Virtual Private Cloud (VPC)
B.CloudTrail
C.Key Management Service (KMS)
D.Identity and Access Management (IAM)
AnswerD

IAM is the cloud-native control plane through which a provider exposes permission management: it defines principals, roles and policies that grant or deny actions on resources. This directly satisfies the stem's requirement to manage user permissions and access, without customer-deployed tooling.

Why this answer

IAM is the cloud-native service that manages identities, roles, and permissions, controlling who can do what on which resources. It is the foundational access control plane in every major cloud provider (AWS IAM, Azure Entra ID/RBAC, GCP IAM). The question asks specifically about managing user permissions and access, which is IAM's core purpose.

Exam trap

CAS-005 often tests service-purpose mapping; candidates confuse CloudTrail (audit logging) with IAM (access control), or pick KMS because it 'manages' something security-related.

How to eliminate wrong answers

Option A is wrong because a VPC is a network isolation construct (subnets, route tables, security groups), not an identity or permission management service. Option B is wrong because CloudTrail is an audit/logging service that records API activity; it observes actions after the fact, it does not grant or manage permissions. Option C is wrong because KMS manages cryptographic keys and encryption operations, not user identities or resource access policies.

163
MCQmedium

A security architect at a healthcare provider must design a solution that lets clinicians access patient records from managed laptops and personal tablets without exposing the internal electronic health record (EHR) network. The requirement is that no inbound firewall ports be opened and that access decisions evaluate device posture and user identity on every session. Which solution best meets these requirements?

A.Publish the EHR through a reverse proxy in the DMZ and require digital certificates on all client devices.
B.Implement a Zero Trust Network Access (ZTNA) service that brokers outbound-only connections after continuous identity and device-posture checks.
C.Segment the clinical VLAN and apply 802.1X port-based authentication to all wired and wireless access switches.
D.Deploy a hardware VPN concentrator in the DMZ and issue IPsec client profiles to all clinical endpoints.
AnswerB

ZTNA brokers application access over outbound-only connections, so no inbound firewall ports are opened and the EHR network is never directly exposed. It performs identity and device-posture evaluation per session, satisfying the continuous verification requirement for both managed laptops and personal tablets without placing users on the internal network.

Why this answer

Zero Trust Network Access matches the stated constraints because it inverts the traditional model: users connect outbound to a broker, the internal EHR network is never published, and authorization is continuously re-evaluated based on identity and device posture. VPN concentrators, reverse proxies, and network access control all require either inbound exposure or do not deliver per-session verification.

Exam trap

The trap here is assuming that any encrypted remote-access tunnel satisfies Zero Trust, when the defining requirement is outbound-only brokering with continuous per-session identity and posture evaluation.

164
MCQmedium

A security architect for a healthcare provider must ensure that a new patient portal can exchange data with an external partner's system without the two organizations having to share or manage each other's identity credentials. The portal must support SAML assertions, provide centralized session revocation, and allow attribute-based authorization decisions at the relying party. Which of the following should the architect implement?

A.Configure the partner as a trusted certificate authority in the portal's internal PKI and issue client certificates to partner users.
B.Publish the portal's user directory as an LDAP endpoint and require partner applications to bind directly against it during authentication.
C.Deploy an identity federation gateway that consumes SAML assertions from the partner IdP and maps attributes to local authorization roles.
D.Create duplicate local accounts for every partner user in the portal's directory and synchronize passwords on a nightly schedule.
AnswerC

An identity federation gateway lets the portal trust assertions from the partner's identity provider, so credentials never cross organizational boundaries. It consumes SAML assertions, maps attributes to local roles for attribute-based authorization, and can participate in centralized session revocation through SAML single logout. This directly satisfies the requirement to avoid shared credential management while supporting SAML and attribute-driven decisions at the relying party.

Why this answer

Federating identities through a gateway that consumes SAML assertions allows the portal to trust the partner's identity provider without exchanging credentials. Attributes carried in assertions can drive authorization decisions locally, and SAML single logout supports centralized session termination. The other approaches either require shared or duplicated credentials, lack SAML support, or expose internal directory services to an external party, none of which meet the stated interoperability and revocation requirements.

Exam trap

The trap here is assuming that any trust relationship between organizations requires sharing or replicating credentials, when federation is specifically designed to avoid that.

165
MCQmedium

A security architect at a financial services firm is designing the network for a new containerized trading platform. The platform must enforce Layer 7 policy, provide mutual TLS between all microservices, and eliminate the need to reconfigure each application for cryptographic identity. Which architecture should the architect implement?

A.A VPN concentrator that creates an encrypted overlay network between all container hosts
B.A network intrusion prevention system (NIPS) deployed inline at the cluster edge
C.An API gateway that terminates TLS and routes requests to backend microservices
D.A service mesh that uses sidecar proxies to intercept all service-to-service traffic and perform mutual TLS
AnswerD

A service mesh with sidecar proxies transparently intercepts pod traffic, enforces Layer 7 policy, and performs mutual TLS without application code changes, satisfying all three requirements in this scenario. It centralizes cryptographic identity through the control plane, so each microservice does not need to be reconfigured individually.

Why this answer

The service mesh architecture uses sidecar proxies to intercept all service-to-service communication, enabling transparent mutual TLS and Layer 7 policy enforcement without modifying application code. This satisfies the demand for cryptographic identity across microservices and eliminates per-application reconfiguration, making it the appropriate design for a containerized trading platform.

Exam trap

The trap here is assuming an API gateway can secure east-west microservice traffic, when it is primarily designed for north-south ingress traffic.

166
MCQeasy

A security analyst is reviewing a Kubernetes cluster and wants to ensure that only authorized users can create or modify pods. Which Kubernetes object should be configured to enforce this?

A.Admission controllers
B.Pod security policies
C.RBAC
D.Network policies
AnswerC

RBAC binds Roles or ClusterRoles, which define verbs such as create and modify on pods, to users or groups via RoleBindings. This satisfies the authorisation constraint by restricting pod write operations to explicitly granted subjects.

Why this answer

Kubernetes RBAC (Role-Based Access Control) uses Roles/ClusterRoles bound to users, groups, or service accounts via RoleBindings/ClusterRoleBindings to authorize actions like create or modify on pods. Configuring RBAC with verbs such as create, update, and patch on the pods resource enforces exactly who can manipulate pods.

Exam trap

CAS-005 often tests the confusion between authorization (RBAC) and admission control or pod security, tricking candidates into choosing admission controllers when the question is about who can perform API actions.

How to eliminate wrong answers

Option A is wrong because admission controllers intercept and mutate/validate requests after authentication and authorization — they enforce policy on object content, not user identity-based permissions. Option B is wrong because Pod Security Policies (deprecated in 1.21, replaced by Pod Security Admission) control pod security settings like privileged mode, not who can create pods. Option D is wrong because Network Policies control pod-to-pod network traffic (L3/L4), not API-level authorization for creating or modifying pods.

167
Multi-Selecteasy

An organization is planning to modernize its cryptographic infrastructure to protect sensitive data for the next 10 years. The security architect must consider future threats from quantum computing. Which TWO quantum-resistant algorithms should the architect prioritize for key encapsulation and digital signatures? (Choose TWO.)

Select 2 answers
A.CRYSTALS-Dilithium
B.AES-256 with GCM
C.ECDSA with P-521
D.RSA-4096
E.CRYSTALS-Kyber
AnswersA, E

CRYSTALS-Dilithium is a lattice-based post-quantum signature scheme, selected by NIST for digital signatures. It resists Shor's algorithm attacks on RSA and ECC, satisfying the digital signature half of the quantum-resistant requirement for long-term data protection.

Why this answer

CRYSTALS-Dilithium (A) is correct because it is a NIST-selected post-quantum digital signature algorithm based on lattice cryptography, designed to resist attacks from both classical and quantum computers, making it suitable for long-term signing needs. CRYSTALS-Kyber (E) is correct because it is the NIST-selected post-quantum key encapsulation mechanism (KEM), also lattice-based, intended for establishing shared secrets resistant to quantum cryptanalysis. Together they cover the two required functions: Kyber for key encapsulation and Dilithium for digital signatures.

AES-256 with GCM (B) is a symmetric cipher and does not provide quantum-resistant key encapsulation or signatures, though symmetric keys are less affected by quantum attacks. ECDSA with P-521 (C) and RSA-4096 (D) are classical asymmetric algorithms whose security would be broken by Shor's algorithm on a sufficiently large quantum computer, so they are not quantum-resistant.

Exam trap

CAS-005 often tests the confusion between symmetric encryption (like AES) and asymmetric algorithms for key encapsulation and digital signatures, or assumes that increasing key size of classical algorithms (RSA, ECDSA) provides quantum resistance, which is false.

168
MCQeasy

A retail company is designing a new payment processing environment and wants to reduce the scope of its PCI DSS assessment. The architect proposes isolating the cardholder data environment from the rest of the corporate network so that most systems fall outside the audit boundary. Which of the following design approaches best supports this goal?

A.A segmented enclave with strict ingress and egress controls, dedicated management, and no shared authentication with corporate systems
B.Outsourcing card processing to a validated service provider while keeping card data in local point-of-sale databases
C.A flat network with VLANs for logical separation and a shared domain for authentication
D.Encrypting card data at rest in the corporate data warehouse and granting broad read access to analysts
AnswerA

A tightly segmented enclave with controlled ingress and egress, dedicated administrative access, and no shared authentication isolates the cardholder data environment so that corporate systems are not connected to it. Assessors can then exclude those systems from the audit scope. This is the recognized way to reduce PCI DSS scope while maintaining a defensible boundary around payment systems.

Why this answer

Isolating the cardholder data environment in a segmented enclave with strict ingress and egress filtering, dedicated administration, and no shared authentication lets assessors treat the surrounding corporate network as out of scope. This directly reduces the number of systems subject to the audit while keeping a defensible, monitored boundary around the payment systems that handle card data.

Exam trap

The trap here is assuming that VLANs or encryption alone shrink audit scope, when scope reduction depends on true isolation and the absence of shared trust paths.

169
MCQmedium

A software company wants to ensure that every container image deployed to production is free of known critical vulnerabilities and is cryptographically signed by its build pipeline. The security architect must implement controls that verify the signature and vulnerability status before the container runtime starts the image. Which of the following should the architect implement?

A.A container image scanner in the registry with automated alerts to the security team.
B.A runtime security agent that monitors container behavior and kills suspicious processes.
C.A Kubernetes admission controller that validates image signatures and vulnerability scan results before allowing a pod to run.
D.A static application security testing (SAST) tool integrated into the CI pipeline.
AnswerC

An admission controller intercepts pod creation and can reject images that lack a valid signature or that contain critical vulnerabilities, enforcing policy before the runtime starts the container. This directly meets the requirement to verify signature and vulnerability status at deployment time.

Why this answer

The requirement is to verify image signatures and vulnerability status before the container runtime starts the image. A Kubernetes admission controller enforces these checks at pod creation, rejecting non-compliant images. SAST analyzes code, registry scanning only alerts, and runtime agents act after startup, so none provide the required pre-runtime enforcement.

Exam trap

The trap here is assuming that registry scanning alone enforces security, when without an admission controller the scan results do not block deployment.

170
MCQeasy

A security architect is designing a system that must ensure the confidentiality and integrity of data at rest on a database server. The organization wants to minimize the impact on application performance and avoid modifying the application code. Which of the following should the architect implement?

A.Application-level encryption of each field before storage
B.Full disk encryption (FDE) on the database server's storage volumes
C.Transparent data encryption (TDE) at the database level
D.Network encryption using TLS for all database connections
AnswerC

TDE encrypts data at rest at the database file level and is transparent to applications, requiring no code changes. It protects confidentiality if storage media is stolen and maintains integrity through encryption. Performance impact is generally low because encryption is handled by the database engine.

Why this answer

Transparent data encryption encrypts database files at rest without requiring application changes, providing confidentiality and integrity with minimal performance impact. It is specifically designed for the scenario's constraints, unlike application-level encryption or transit encryption.

Exam trap

The trap here is confusing encryption in transit with encryption at rest; TLS protects data on the wire, not on disk.

171
Multi-Selectmedium

A security engineer is hardening a Kubernetes environment. Which THREE of the following are effective controls for securing the cluster? (Select THREE.)

Select 3 answers
A.Configuring load balancers for high availability
B.Enabling Pod Security Admission (PSA) to enforce pod security standards
C.Implementing RBAC for API server access
D.Using Network Policies to isolate workloads
E.Installing antivirus on all nodes
AnswersB, C, D

Pod Security Admission enforces the Privileged, Baseline or Restricted pod security standards at namespace level, rejecting pods that request excessive capabilities, host networking or root execution. This satisfies hardening by preventing risky pod specifications from being admitted to the cluster.

Why this answer

Option B is correct because Pod Security Admission (PSA) is a built-in Kubernetes admission controller that enforces the Privileged, Baseline, and Restricted Pod Security Standards at the namespace level, preventing pods from running with dangerous settings like privileged containers or hostPath mounts. Option C is correct because RBAC (Role-Based Access Control) restricts who can perform which verbs on which API resources via Roles/ClusterRoles and RoleBindings/ClusterRoleBindings, directly limiting unauthorized API server access and privilege escalation. Option D is correct because Network Policies are the native Kubernetes mechanism (enforced by a CNI such as Calico or Cilium) to control ingress and egress traffic between pods and namespaces, providing workload segmentation and limiting lateral movement.

Option A is not a security control—load balancers configured for high availability address availability and resilience, not confidentiality, integrity, or access control. Option E is not appropriate for Kubernetes hardening: node-level antivirus does not secure the cluster's control plane, API access, or pod-level isolation, and containerized workloads are typically immutable and scanned via image scanning instead.

Exam trap

CAS-005 often tests whether candidates pick generic infrastructure controls (load balancers, antivirus) instead of Kubernetes-native security primitives (PSA, RBAC, Network Policies) that actually address cluster-specific threats.

172
MCQhard

A company is deploying containerized applications on Kubernetes and needs to ensure that only authorized images are run in the cluster. Which Kubernetes resource should be used to enforce policies on what containers can run, including image source restrictions?

A.Role-Based Access Control (RBAC)
B.Network policies
C.Seccomp profiles
D.Admission controllers
AnswerD

Admission controllers intercept API server requests before persistence, so a ValidatingAdmissionWebhook can reject pods whose images fail source or signature checks. This enforces policy at creation time, which is exactly the image-authorisation constraint the stem requires.

Why this answer

Admission controllers intercept requests to the Kubernetes API server before objects are persisted, and can validate or mutate them — including rejecting pods whose images come from unauthorized registries or lack required signatures. This is the correct enforcement point for cluster-wide policy on what containers may run.

Exam trap

CAS-005 often tests the RBAC-vs-admission-control boundary; candidates pick RBAC because it 'controls access,' but RBAC governs who can act, not what images are allowed to run.

How to eliminate wrong answers

Option A is wrong because RBAC controls which users/service accounts can perform API actions (create, get, delete), not which images are allowed to run; a user with pod-create rights can still deploy a malicious image. Option B is wrong because network policies govern pod-to-pod and pod-to-external traffic at L3/L4, not image source or container runtime policy. Option C is wrong because seccomp profiles restrict the syscalls a container process can invoke at runtime — a hardening mechanism, not a deployment-time image policy.

173
MCQhard

During a threat modeling exercise for a new web application, the team identifies that the application uses JWT for authentication. Which vulnerability is most likely if the server does not properly verify the JWT signature?

A.Cross-site scripting
B.SQL injection
C.JWT tampering
D.Insecure direct object reference
AnswerC

Without signature verification, an attacker can alter JWT claims, such as changing a role or user identifier, and the server will accept the forged token. This is JWT tampering: the integrity guarantee fails because the signature is never validated against the signing key.

Why this answer

When a server fails to verify the JWT signature, an attacker can modify the token's payload (e.g., change the 'sub' or 'role' claim) and re-encode it without needing the signing key, because the server will accept any token whose signature it never validates. This is JWT tampering — the attacker forges or alters claims to impersonate another user or escalate privileges. The vulnerability is specific to improper cryptographic validation of the token, not to input handling or access control logic.

Exam trap

CAS-005 often tests whether candidates conflate authentication token weaknesses with generic web vulnerabilities (XSS, SQLi, IDOR), so the trap is picking a familiar OWASP Top 10 item instead of the token-specific flaw.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) is a client-side injection flaw where untrusted input is rendered as HTML/JavaScript in a browser, unrelated to JWT signature validation. Option B is wrong because SQL injection involves unsanitized input being concatenated into SQL queries, which has nothing to do with JWT signature verification. Option D is wrong because insecure direct object reference (IDOR) is an access control flaw where an application exposes internal object identifiers without authorization checks, not a failure of token signature validation.

174
Multi-Selecthard

A financial services firm is designing its identity architecture for a Zero Trust program. Auditors require that authentication strength be continuously evaluated and that a compromised endpoint lose access to sensitive trading applications even after the user has already authenticated. The security architect must select TWO capabilities that directly support continuous, context-aware authorization decisions. (Choose two.)

Select 2 answers
A.A single sign-on portal that caches user credentials for the trading session
B.Password complexity rules requiring rotation every 30 days for all identities
C.Continuous access evaluation that revokes active sessions when risk signals change
D.Longer-lived refresh tokens to reduce reauthentication prompts for trading users
E.Device posture and health attestation sent to the policy decision point
AnswersC, E

Continuous access evaluation lets the policy engine react to new risk signals, such as a disabled account, a changed network location, or a flagged device, and revoke or re-challenge active sessions in near real time. This directly meets the auditor requirement that a compromised endpoint lose access even after successful authentication, rather than waiting for token expiry.

Why this answer

Continuous access evaluation and device posture attestation together give the policy engine live signals to make and revisit authorization decisions. Continuous access evaluation enforces revocation the moment risk changes, while posture attestation supplies the endpoint trust data that fuels those decisions. Combined, they ensure that a compromised device loses access to sensitive applications mid-session, satisfying the auditors' requirement.

Exam trap

The trap here is equating stronger initial authentication or longer token lifetimes with continuous authorization, when the requirement is real-time re-evaluation after login.

175
MCQmedium

A software company is designing an internal developer platform where engineers need short-lived credentials to access production databases. The security architect wants to eliminate long-lived static database passwords, bind access to the identity of the calling workload, and automatically revoke credentials when a deployment is removed. Which of the following should the architect implement?

A.Configure database native auditing and alert on anomalous query patterns
B.Issue dynamic, lease-based database credentials through a secrets engine tied to workload identity
C.Enable TLS client certificate authentication for all database connections
D.Store database passwords in a centralized secrets manager and inject them at runtime
AnswerB

Dynamic secrets engines generate credentials on demand with a defined lease time and revoke them automatically when the lease expires or the workload is removed. When integrated with workload identity, the credential is issued only after the platform authenticates the calling pod or service, binding access to that identity. This eliminates long-lived passwords and provides automatic revocation, exactly as the scenario requires.

Why this answer

Dynamic secrets with workload identity binding issue credentials only after the platform verifies the caller, and the credentials expire automatically with their lease. This removes static passwords from the environment and ensures that deleting a deployment terminates its database access without manual intervention. Secrets storage, mutual TLS, and auditing each address part of the problem but do not deliver identity-bound, automatically revoked credentials.

Exam trap

The trap here is equating centralized secret storage with dynamic secrets, when stored passwords remain static and shared regardless of how securely they are delivered.

176
MCQmedium

A company is deploying a SASE architecture. Which component is responsible for securing web traffic and enforcing acceptable use policies at the edge?

A.Zero Trust Network Access (ZTNA)
B.Secure Web Gateway (SWG)
C.Cloud Access Security Broker (CASB)
D.SD-WAN
AnswerB

Secure Web Gateway sits at the edge and inspects outbound web traffic, enforcing acceptable use policies, URL filtering and threat protection. It satisfies the stem's requirement to secure web traffic and apply acceptable use controls within the SASE architecture.

Why this answer

A Secure Web Gateway (SWG) sits at the network edge and inspects outbound web traffic, enforcing URL filtering, malware blocking, and acceptable use policies — exactly the function described. In a SASE architecture, SWG is the component that governs user web access regardless of location, applying policy based on categories, reputation, and content inspection. It is distinct from ZTNA (which controls application access), CASB (which governs cloud service usage), and SD-WAN (which optimizes WAN transport).

Exam trap

CAS-005 often tests the blurry boundary between SWG, CASB, and ZTNA — candidates pick CASB for 'cloud app control' or ZTNA for 'edge security' when the question specifically describes web traffic filtering and acceptable use, which is SWG's domain.

How to eliminate wrong answers

Option A is wrong because ZTNA provides identity- and context-based access to internal applications, not web traffic filtering or acceptable use enforcement. Option C is wrong because CASB focuses on discovery, governance, and policy enforcement for cloud applications (SaaS/IaaS), not general web browsing policy. Option D is wrong because SD-WAN is a networking technology for optimizing and routing WAN traffic; it does not perform security inspection or acceptable use enforcement.

177
MCQeasy

Which technology is used to discover and control cloud applications, enforce security policies, and provide visibility into cloud usage?

A.Cloud Workload Protection Platform (CWPP)
B.Cloud Access Security Broker (CASB)
C.Cloud Security Posture Management (CSPM)
D.Secure Access Service Edge (SASE)
AnswerB

A CASB sits between users and cloud services, discovering shadow IT, enforcing policy and logging usage for visibility. It provides the control and monitoring layer the stem describes, unlike SWG or DLP, which address different traffic types.

Why this answer

A Cloud Access Security Broker (CASB) is specifically designed to discover cloud applications in use (shadow IT), enforce security policies, and provide visibility and governance over cloud service usage. It sits between users and cloud providers, applying policy via inline proxies or API integrations. This matches the question's three requirements — discovery, policy enforcement, and visibility — which are CASB's core functions.

Exam trap

CAS-005 often tests the CASB vs. CSPM vs. CWPP distinction — candidates pick CSPM for 'cloud visibility' or CWPP for 'cloud control' when the question specifically mentions application discovery and usage governance, which is CASB's role.

How to eliminate wrong answers

Option A is wrong because CWPP protects workloads (VMs, containers, serverless) at runtime — vulnerability scanning, workload hardening, and runtime protection — not cloud application discovery or usage visibility. Option C is wrong because CSPM focuses on identifying misconfigurations and compliance drift in cloud infrastructure (e.g., open S3 buckets, overly permissive IAM), not on discovering or controlling SaaS applications. Option D is wrong because SASE is a broader architecture that bundles SWG, CASB, ZTNA, and FWaaS; it is not the specific component responsible for cloud app discovery and control.

178
MCQmedium

An organization wants to protect cryptographic keys used for TLS termination. Which hardware solution should be deployed to prevent key extraction?

A.KMS
B.TPM
C.UEFI
D.HSM
AnswerD

A hardware security module performs cryptographic operations internally, so private keys never leave the tamper-resistant boundary — satisfying the requirement to prevent key extraction during TLS termination. Unlike software keystores or TPMs, an HSM is purpose-built for high-volume server-side TLS, keeping keys non-exportable while Microsoft Entra ID governs access.

Why this answer

A Hardware Security Module (HSM) is a dedicated tamper-resistant hardware appliance designed to generate, store, and manage cryptographic keys, with physical and logical protections that prevent key extraction. For TLS termination, HSMs provide FIPS 140-2/3 validated key storage and can perform cryptographic operations without exposing private keys. This directly addresses the requirement to prevent key extraction.

Exam trap

CAS-005 often tests the KMS vs. HSM distinction — candidates pick KMS because it 'manages keys,' missing that the question demands hardware-level prevention of key extraction, which only an HSM provides.

How to eliminate wrong answers

Option A is wrong because KMS (Key Management Service) is a software service for managing keys centrally, but it does not provide the hardware-level tamper resistance and extraction prevention of an HSM; KMS often uses HSMs internally but is not itself the hardware solution. Option B is wrong because a TPM (Trusted Platform Module) is a chip on a motherboard used for platform integrity, secure boot, and disk encryption key storage — it is not designed for high-volume TLS key operations or as a standalone cryptographic appliance. Option C is wrong because UEFI is firmware that initializes hardware and supports secure boot; it has no role in cryptographic key protection for TLS.

179
MCQeasy

In a cloud shared responsibility model, which of the following is typically the customer's responsibility for IaaS?

A.Hypervisor security
B.Guest OS patch management
C.Hardware maintenance
D.Physical security of data centers
AnswerB

Under IaaS, the provider secures the hypervisor, physical hosts and network fabric, while the customer retains control of everything from the guest OS upward. Patching the guest operating system therefore remains the customer's duty, unlike managed PaaS where the provider handles runtime patching.

Why this answer

In the cloud shared responsibility model for IaaS, the customer is responsible for managing the guest operating system, including patch management, security updates, and configuration. The cloud provider is responsible for the hypervisor, hardware, and physical security of data centers. Therefore, guest OS patch management is the customer's responsibility.

Exam trap

The trap is confusing the responsibilities across service models; candidates may think the cloud provider patches the guest OS in IaaS, but the exam expects knowledge that the customer is responsible for guest OS patching in IaaS, while the provider handles the hypervisor and physical security.

How to eliminate wrong answers

Option A is wrong because hypervisor security is the responsibility of the cloud provider, not the customer, in an IaaS model; the provider manages the virtualization layer. Option C is wrong because hardware maintenance is handled by the cloud provider, who owns and operates the physical infrastructure. Option D is wrong because physical security of data centers is always the cloud provider's responsibility, as customers have no access to the physical facilities.

180
Multi-Selectmedium

A company is implementing a defense-in-depth strategy for its web application. Which THREE security controls should be included in the architecture? (Choose three.)

Select 3 answers
A.Web application firewall (WAF)
B.Load balancer with SSL termination
C.Runtime application self-protection (RASP)
D.Single sign-on (SSO)
E.Network segmentation
AnswersA, C, E

A web application firewall inspects inbound HTTP requests, blocking SQL injection, cross-site scripting and similar attacks before they reach the application. Sitting at the network edge, it forms one independent layer in defence in depth, complementing secure coding, RASP and monitoring controls.

Why this answer

A web application firewall (WAF) is correct because it inspects and filters HTTP/HTTPS traffic at Layer 7, blocking common attacks such as SQL injection and cross-site scripting before they reach the application, which is a core element of defense-in-depth for a web app. Runtime application self-protection (RASP) is correct because it instruments the application from within the runtime, detecting and blocking attacks like deserialization or injection in real time based on actual execution context, complementing perimeter controls. Network segmentation is correct because it limits lateral movement by isolating the web tier from databases and internal services using VLANs, subnets, or security groups, so a compromised web server cannot freely reach other assets.

A load balancer with SSL termination is not a security control in this context; it primarily provides availability and offloads TLS processing, and while it may support TLS, it does not itself enforce application-layer threat protection. Single sign-on (SSO) is an authentication convenience and access-management mechanism, not a defense-in-depth control for protecting the web application against attacks.

Exam trap

The trap here is confusing availability/identity controls (load balancer, SSO) with security controls — candidates pick them because they sound 'enterprise-grade' but they do not block or contain attacks.

181
Multi-Selecthard

A global company must comply with data residency regulations that require customer data to stay within specific geographic boundaries. The company uses a multi-cloud architecture. Which THREE strategies should the architect implement to ensure compliance?

Select 3 answers
A.Using cloud provider's region-specific services and data centers
B.Encrypting all data at rest and in transit
C.Implementing strict identity and access management (IAM) policies
D.Configuring data classification tags to identify regulated data
E.Deploying data loss prevention (DLP) policies to block cross-border data transfers
AnswersA, D, E

Selecting region-specific services and data centres keeps storage and processing physically inside the mandated geography, satisfying the residency boundary directly. In a multi-cloud estate, each provider's regional endpoints must be chosen so customer data never replicates outside the permitted jurisdiction.

Why this answer

Option A is correct because using region-specific services and data centers ensures that data is physically stored and processed within the required geographic boundaries, directly satisfying data residency mandates. Option D is correct because data classification tags identify which data is subject to residency regulations, enabling architects to apply location-based controls and policies only to regulated data. Option E is correct because DLP policies can detect and block cross-border transfers of regulated data, preventing accidental or unauthorized movement outside approved regions.

Option B is not correct because encryption at rest and in transit protects confidentiality but does not restrict where data is stored or transferred, so it does not ensure residency. Option C is not correct because IAM policies control who can access data, not where data resides or whether it crosses borders.

Exam trap

CAS-005 often tests the confusion between data security controls (encryption, IAM) and data residency controls, so candidates must focus on geographic restrictions rather than general security measures.

182
Multi-Selecthard

A security architect is designing a microsegmentation strategy for a hybrid cloud environment. The organization wants to enforce least-privilege network access between workloads, prevent lateral movement, and maintain visibility into east-west traffic. Which TWO of the following controls are MOST appropriate to achieve these goals? (Choose two.)

Select 2 answers
A.Network address translation (NAT) at the perimeter
B.Spanning Tree Protocol (STP) tuning on all switches
C.Software-defined networking (SDN) overlay with distributed policy enforcement
D.Host-based firewalls with workload identity tags
E.Virtual private network (VPN) concentrators between all subnets
AnswersC, D

An SDN overlay with distributed policy enforcement allows security policies to be applied consistently across hybrid cloud workloads regardless of underlying network topology. It enables microsegmentation by defining security groups and rules based on workload attributes, and it provides flow-level visibility into east-west traffic. This approach scales across on-premises and cloud environments.

Why this answer

Host-based firewalls with workload identity tags and an SDN overlay with distributed policy enforcement both enable granular, identity-aware microsegmentation across hybrid cloud environments. They enforce least-privilege access, limit lateral movement, and provide east-west visibility. The other options either provide broad connectivity, address non-security concerns, or operate only at the perimeter.

Exam trap

The trap here is confusing network connectivity mechanisms such as VPNs or NAT with segmentation controls that enforce least privilege between individual workloads.

183
MCQeasy

A security architect is evaluating a software-defined wide area network (SD-WAN) solution to connect branch offices to cloud services. The architect wants to ensure that traffic from branches to cloud applications is inspected for threats without backhauling all traffic to the data center. Which capability should the architect prioritize?

A.Dynamic multipoint VPN (DMVPN) with hub-and-spoke topology
B.Quality of service (QoS) policies that prioritize business-critical applications
C.Application-aware routing that selects the best path based on performance metrics
D.Local internet breakout with integrated next-generation firewall (NGFW) and secure web gateway (SWG) at the branch
AnswerD

Local internet breakout allows branch traffic to go directly to the cloud, and integrating NGFW and SWG at the branch ensures that this traffic is still inspected for threats. This avoids backhauling while maintaining security, directly addressing the architect's requirement.

Why this answer

Local internet breakout with integrated NGFW and SWG at the branch enables direct cloud access while still inspecting traffic for threats. This design eliminates the need to backhaul traffic to a central data center for security inspection, balancing performance and security for branch offices.

Exam trap

The trap here is assuming that SD-WAN's performance features, such as application-aware routing, also provide security inspection, when they are separate functions.

184
MCQmedium

A security architect is implementing an API gateway to protect microservices. Which security capability is uniquely provided by an API gateway compared to a traditional web application firewall (WAF)?

A.TLS termination
B.SQL injection prevention
C.Cross-site scripting (XSS) filtering
D.Rate limiting per API consumer
AnswerD

An API gateway understands individual consumers via keys, OAuth scopes or tokens, so it can apply quotas and throttling per client. A WAF inspects HTTP traffic for attack signatures but lacks this per-consumer identity context, making per-consumer rate limiting the unique capability.

Why this answer

Rate limiting per API consumer is a capability unique to API gateways because the gateway understands API keys, OAuth tokens, and consumer identities, allowing it to enforce quotas and throttling on a per-client basis. A traditional WAF operates at the network/HTTP layer and inspects traffic patterns for attacks but does not natively identify API consumers or apply per-consumer quotas. This makes per-consumer rate limiting the distinguishing capability in this comparison.

Exam trap

CAS-005 often tests the overlap between WAF and API gateway capabilities, tricking candidates into picking a generic web security control (TLS, SQLi, XSS) that both devices can perform instead of the consumer-aware capability unique to the gateway.

How to eliminate wrong answers

Option A is wrong because TLS termination is a generic capability provided by load balancers, reverse proxies, and WAFs alike — it is not unique to API gateways. Option B is wrong because SQL injection prevention is a core WAF signature/rule capability (e.g., OWASP CRS rules) and is not the differentiator. Option C is wrong because XSS filtering is likewise a standard WAF function via signature and anomaly detection rules, not unique to API gateways.

185
MCQeasy

A company is modernizing its security operations center and wants to correlate logs from firewalls, endpoints, and cloud services in a single platform that supports long-term retention and custom detection rules. Which technology best fits this requirement?

A.A network performance monitoring (NPM) appliance.
B.A vulnerability management scanner.
C.A security information and event management (SIEM) platform.
D.A configuration management database (CMDB).
AnswerC

A SIEM collects and normalizes logs from disparate sources such as firewalls, endpoints, and cloud services, correlates events across them, retains data for long-term analysis, and supports custom detection rules and alerts. This directly matches the requirement for centralized correlation, retention, and customizable detections in a security operations center.

Why this answer

The described need is centralized ingestion, normalization, correlation, retention, and custom detection across many log sources, which is the core purpose of a SIEM. Vulnerability scanners, network performance monitors, and configuration databases each serve different operational functions and none provides the combined correlation and retention capability required.

Exam trap

The trap here is choosing a tool that produces security-relevant data, such as a vulnerability scanner, when the requirement is a platform that ingests and correlates logs from many sources.

186
MCQmedium

During a secure SDLC, a development team is reviewing code for security flaws early in the development process. Which type of testing is MOST appropriate for identifying vulnerabilities in source code before it is compiled?

A.DAST
B.SAST
C.IAST
D.RASP
AnswerB

SAST analyses source code statically, before compilation or execution, tracing tainted data flows to flag injection flaws, unsafe functions and hardcoded secrets. That directly matches the requirement to identify vulnerabilities in source code early, whereas DAST and IAST need a running or instrumented build.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binaries without executing the program, making it the correct choice for finding vulnerabilities before compilation. It integrates into the IDE or CI pipeline and can flag issues like hardcoded secrets, injection flaws, and insecure API usage at the code level. Because it works on the code itself, it is the only option that fits the 'before it is compiled' requirement.

Exam trap

CAS-005 often tests the confusion between SAST (static, pre-compilation, white-box) and DAST/IAST/RASP (dynamic, runtime, black-box or instrumented), tricking candidates who focus on 'testing' rather than on when the code is analyzed.

How to eliminate wrong answers

Option A is wrong because DAST (Dynamic Application Security Testing) tests a running application from the outside by sending malicious requests, so it requires a deployed, executing application and cannot inspect source code. Option C is wrong because IAST (Interactive Application Security Testing) instruments a running application during execution, typically combining agent-based runtime analysis with test traffic, so it also requires execution. Option D is wrong because RASP (Runtime Application Self-Protection) runs inside a live application to detect and block attacks in real time, which is a runtime protection mechanism, not a pre-compilation code review technique.

187
MCQmedium

A security architect is designing a system that must process sensitive personal data. The organization wants to ensure that even if the database is compromised, the data remains unreadable to the attacker. The architect also needs to support searching on a specific field without decrypting the entire dataset. Which cryptographic approach best meets these requirements?

A.Transparent data encryption (TDE) on the database
B.Hashing the sensitive data with a salt
C.Application-level encryption with deterministic encryption for the searchable field
D.Tokenization of all sensitive fields with a centralized token vault
AnswerC

Application-level encryption ensures data is encrypted before it reaches the database, so a database compromise yields only ciphertext. Using deterministic encryption for the searchable field allows equality searches because the same plaintext always produces the same ciphertext. This meets both the confidentiality and searchability requirements, making it the correct approach.

Why this answer

Application-level encryption with deterministic encryption for the searchable field ensures that data is encrypted before storage and remains unreadable if the database is compromised. Deterministic encryption allows equality searches on that field without decrypting the entire dataset. Other methods either leave data readable in memory, prevent searching, or introduce a separate high-value target.

Exam trap

The trap here is assuming that transparent data encryption protects against database compromise, when it only protects data at rest and does not prevent access once the database is running.

188
MCQmedium

A security architect at a financial services firm must ensure that virtual machine workloads on a private cloud cannot execute unauthorized binaries, even if an attacker gains root access. The solution must enforce policy at the hypervisor layer without relying on agents inside the guest OS. Which of the following should the architect implement?

A.Virtual machine introspection (VMI) with hypervisor-enforced integrity monitoring
B.File integrity monitoring (FIM) of /usr/bin on each virtual machine
C.Security information and event management (SIEM) correlation with guest OS logs
D.Host-based intrusion prevention system (HIPS) installed on each guest OS
AnswerA

VMI allows the hypervisor to inspect guest memory and CPU state from outside the VM, so policy enforcement cannot be bypassed by root-level attackers inside the guest. It monitors integrity and can block execution of unauthorized binaries at the hypervisor layer, satisfying the agentless and root-resistant requirements described in the scenario.

Why this answer

Hypervisor-based introspection enforces policy outside the guest OS, so even root-level malware cannot disable the control. It provides tamper-resistant visibility and can prevent execution of unauthorized binaries, meeting the agentless and root-resistant requirements. Agent-based tools and log correlation are either bypassable or detective only.

Exam trap

The trap here is assuming that any endpoint security tool running inside the guest OS can enforce policy against a root-level attacker.

← PreviousPage 3 of 3 · 188 questions total

Ready to test yourself?

Try a timed practice session using only Casp Security Architecture questions.