easyMultiple Select
CAS-004 Practice Question: Which TWO of the following are best practices for…
Which TWO of the following are best practices for securing a database server?
⚠ Common exam trap
CompTIA CASP+ often tests the misconception that sample databases are harmless for testing, but in a production security context, any unnecessary software or data increases risk and should be removed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable default accounts
Option C is correct because default accounts (such as Oracle's SCOTT/TIGER, MySQL's anonymous users, or SQL Server's sa) are widely known to attackers and should be disabled, renamed, or have their passwords changed to eliminate an easy entry point. Option D is correct because using encrypted connections (e.g., TLS/SSL for MySQL, PostgreSQL, and SQL Server, or Oracle Native Network Encryption) protects credentials and data in transit from eavesdropping and man-in-the-middle attacks. Option A is not a best practice because sample databases often contain known schemas, default credentials, and unnecessary attack surface that should be removed from production servers. Option B is wrong because enabling remote access from any IP (0.0.0.0/0) exposes the database to the entire internet; access should be restricted to specific trusted hosts or subnets via firewall rules and bind-address settings. Option E is incorrect because simple passwords are trivially brute-forced or guessed; strong password policies, account lockout, and multi-factor authentication are the recommended controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install sample databases for testing
Why it's wrong here
Sample databases ship with default credentials, known schemas and demonstration data that attackers enumerate, expanding the exploitable surface of a production server. Installing them is tempting for developer testing convenience, and would be acceptable only on an isolated, non-production instance that is never exposed to untrusted networks.
- ✗
Enable remote access from any IP
Why it's wrong here
Allowing remote connections from any IP exposes the database listener to the entire internet, enabling brute-force and exploitation attempts from arbitrary sources. It is tempting because it removes connectivity troubleshooting during administration, and would be acceptable only when restricted to specific, firewalled management addresses or a private subnet.
- ✓
Disable default accounts
Why this is correct
Default and sample accounts often ship with well-known credentials or excessive privileges, giving attackers an easy entry point. Disabling or removing them eliminates that unnecessary attack surface before any other database hardening measure is applied.
- ✓
Use encrypted connections
Why this is correct
Encrypted connections such as TLS protect credentials and query results while they traverse the network, preventing eavesdropping and man-in-the-middle interception. This satisfies the requirement to secure data in transit between clients and the database server.
- ✗
Use simple passwords for ease of administration
Why it's wrong here
Simple passwords are trivially guessed or brute-forced, and administrators often reuse them across systems, undermining authentication on the database server. Convenience during administration makes this tempting, but strong, unique credentials combined with rotation and multi-factor authentication would be the correct approach instead.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.