Courseiva
easyMultiple Select

CAS-004 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for securing a database server?

⚠ Common exam trap

CompTIA CASP+ often tests the misconception that sample databases are harmless for testing, but in a production security context, any unnecessary software or data increases risk and should be removed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable default accounts

Option C is correct because default accounts (such as Oracle's SCOTT/TIGER, MySQL's anonymous users, or SQL Server's sa) are widely known to attackers and should be disabled, renamed, or have their passwords changed to eliminate an easy entry point. Option D is correct because using encrypted connections (e.g., TLS/SSL for MySQL, PostgreSQL, and SQL Server, or Oracle Native Network Encryption) protects credentials and data in transit from eavesdropping and man-in-the-middle attacks. Option A is not a best practice because sample databases often contain known schemas, default credentials, and unnecessary attack surface that should be removed from production servers. Option B is wrong because enabling remote access from any IP (0.0.0.0/0) exposes the database to the entire internet; access should be restricted to specific trusted hosts or subnets via firewall rules and bind-address settings. Option E is incorrect because simple passwords are trivially brute-forced or guessed; strong password policies, account lockout, and multi-factor authentication are the recommended controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Install sample databases for testing

    Why it's wrong here

    Sample databases ship with default credentials, known schemas and demonstration data that attackers enumerate, expanding the exploitable surface of a production server. Installing them is tempting for developer testing convenience, and would be acceptable only on an isolated, non-production instance that is never exposed to untrusted networks.

  • ✗

    Enable remote access from any IP

    Why it's wrong here

    Allowing remote connections from any IP exposes the database listener to the entire internet, enabling brute-force and exploitation attempts from arbitrary sources. It is tempting because it removes connectivity troubleshooting during administration, and would be acceptable only when restricted to specific, firewalled management addresses or a private subnet.

  • ✓

    Disable default accounts

    Why this is correct

    Default and sample accounts often ship with well-known credentials or excessive privileges, giving attackers an easy entry point. Disabling or removing them eliminates that unnecessary attack surface before any other database hardening measure is applied.

  • ✓

    Use encrypted connections

    Why this is correct

    Encrypted connections such as TLS protect credentials and query results while they traverse the network, preventing eavesdropping and man-in-the-middle interception. This satisfies the requirement to secure data in transit between clients and the database server.

  • ✗

    Use simple passwords for ease of administration

    Why it's wrong here

    Simple passwords are trivially guessed or brute-forced, and administrators often reuse them across systems, undermining authentication on the database server. Convenience during administration makes this tempting, but strong, unique credentials combined with rotation and multi-factor authentication would be the correct approach instead.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.