CompTIA SecurityX (CAS-005) practice questions
316 free questions with answers and explanations.
- 1.A security architect is reviewing the security posture of an organization's continuous integration/continuous deployment (CI/CD) pipeline. They observe that sensitive API keys and database credentials are hardcoded directly into application source code within the Git repository. What is the MOST significant security risk introduced by this practice?Security Operations
- 2.An organization is deploying a new cloud-native application that handles sensitive customer data. To ensure continuous compliance and security, they decide to integrate security checks and automated policy enforcement directly into their CI/CD pipeline. This includes automated code analysis, container image scanning, and infrastructure-as-code (IaC) security reviews. Which methodology are they primarily adopting?Governance, Risk and Compliance
- 3.A software development company uses a DevOps methodology and deploys code multiple times a day. To maintain compliance with internal security policies and external regulations, security checks must be integrated into the continuous integration/continuous deployment (CI/CD) pipeline without significantly slowing down development. Which of the following would be the MOST effective approach to achieve this balance?Governance, Risk and Compliance
- 4.A security architect is evaluating a new cloud-native application for potential vulnerabilities. The application uses serverless functions that interact with a managed database and object storage. Traditional network-based vulnerability scanners are struggling to provide comprehensive coverage. Which of the following approaches would be MOST effective for identifying security weaknesses in this environment?Security Operations
- 5.A security architect is designing a Zero Trust architecture for an enterprise. The goal is to ensure that all access requests, regardless of their origin (internal or external), are explicitly verified before granting access to resources. Which component is primarily responsible for making the decision to grant or deny access based on established policies?Security Architecture
- 6.A security architect is tasked with ensuring the confidentiality and integrity of data at rest on user endpoints (laptops, mobile devices) for a highly mobile workforce. The solution must ensure that even if a device is lost or stolen, sensitive data remains unreadable. Which encryption strategy is most effective for this scenario?Security Architecture
- 7.A global enterprise is migrating its legacy on-premises applications to a hybrid cloud environment. The security architect needs to design a solution that provides consistent network security policies and traffic inspection across both on-premises data centers and multiple public cloud providers, without requiring separate security appliances or configurations for each environment. Which architectural pattern is MOST suitable for this requirement?Security Architecture
- 8.A large manufacturing company is integrating its operational technology (OT) network with its enterprise IT network to enable predictive maintenance and real-time analytics. The security architect is concerned about the potential for IT-based cyberattacks to propagate into the sensitive OT environment. Which specialized network component is BEST suited to provide a highly secure, unidirectional data flow from the OT network to the IT network, preventing any direct inbound communication to the OT side?Security Engineering
- 9.A security analyst is performing a forensic investigation on a potentially compromised Windows server. During the analysis of network connections, the analyst observes suspicious outbound UDP traffic on port 53 to external DNS servers, with unusually large DNS query responses containing non-standard data. The server's primary role is an internal file share, and it has no legitimate reason to initiate such external DNS queries. Which type of data exfiltration technique does this MOST strongly suggest?Security Operations
- 10.A security architect is designing a secure communication channel for a critical real-time financial transaction system that spans multiple geographical locations. The primary requirements are strong authentication of communicating parties, data confidentiality, and data integrity over an untrusted network. Which of the following protocols is BEST suited to meet these requirements?Security Architecture
- 11.A security engineer is tasked with implementing a robust access control mechanism for a new cloud-based application that processes highly sensitive customer data. The application will be accessed by internal employees, external partners, and customers, each requiring different levels of access based on their roles and specific tasks. The engineer needs to ensure that access decisions are dynamic, based on multiple attributes of the user, resource, and environment at the time of access. Which access control model would BEST meet these requirements?Security Engineering
- 12.A healthcare organization is designing a new patient management system that handles Electronic Health Records (EHR). Due to regulatory compliance (e.g., HIPAA), the system must ensure that patient data is securely partitioned, and access is strictly controlled based on the user's role and the sensitivity classification of the data, regardless of any discretionary access controls. Which access control model is BEST suited for enforcing such strict, rule-based access?Security Architecture
- 13.A global manufacturing company is implementing a new enterprise resource planning (ERP) system that will store intellectual property, financial records, and employee data across its international subsidiaries. The CISO needs to ensure that data protection policies are consistent yet adaptable to local legal and cultural nuances. Which compliance strategy BEST addresses this requirement?Governance, Risk and Compliance
- 14.A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the high-impact nature of potential cyberattacks, the security architect must ensure the system adheres to the 'defense-in-depth' principle. Which of the following security measures, when applied to the ICS, BEST exemplifies this principle?Security Engineering
- 15.A financial institution is designing a new payment processing system that must comply with strict regulatory requirements for data integrity and non-repudiation of transactions. Each transaction must be verifiably linked to the originating party and prove that it has not been altered since it was created. Which cryptographic technique is essential for meeting these requirements?Security Architecture
- 16.A security architect is designing a new cloud-based application and needs to ensure that sensitive data handled by the application is protected both in transit and at rest. The application will interact with several microservices and store data in a NoSQL database. Which combination of cryptographic controls should the architect prioritize to meet these requirements?Security Operations
- 17.A security engineer is tasked with securing a fleet of IoT devices deployed in remote locations. These devices have limited processing power and memory but must securely communicate with a central cloud platform. Which cryptographic algorithm should be prioritized for data encryption to balance security with resource constraints?Security Engineering
- 18.A security architect is designing an automated incident response (IR) workflow for a cloud environment. The goal is to quickly isolate compromised virtual machines (VMs) and revoke their access credentials upon detection of a high-severity threat. The solution needs to integrate with various cloud provider APIs and internal security tools. Which automation approach would be MOST effective for orchestrating these complex, multi-step actions across different systems?Security Engineering
- 19.A global healthcare provider is deploying a new patient management system across multiple countries. Due to varied and strict data privacy regulations (e.g., GDPR in Europe, HIPAA in the US, local laws in Asia), the architecture must ensure that patient data collected in a specific region remains stored and processed exclusively within that region's geographical boundaries. Which architectural principle directly addresses this requirement?Security Architecture
- 20.A security architect is designing an information security program for a critical infrastructure organization. The organization needs a framework that provides a flexible, risk-based approach to cybersecurity, allowing for adaptation to evolving threats and technologies, while also enabling communication of cybersecurity risk to a wide range of stakeholders. Which framework is BEST suited for this requirement?Governance, Risk and Compliance
- 21.A security analyst is conducting a threat modeling exercise for a new microservices architecture. They are using the PASTA framework. After defining the business and technical objectives and identifying the technical scope, the next logical step is to analyze the identified threats and vulnerabilities. Which phase of PASTA does this correspond to?Governance, Risk and Compliance
- 22.An organization is deploying a new web application and must ensure all server-side components are hardened according to industry best practices. Which of the following is a critical step in hardening a web server to minimize its attack surface?Security Engineering
- 23.A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to identify and remediate security vulnerabilities in their custom-developed code as early as possible, ideally before the code is even compiled or deployed. Which security testing tool is best suited for this objective?Security Architecture
- 24.A global organization is implementing a new customer relationship management (CRM) system that will store personally identifiable information (PII) for customers across various jurisdictions, each with different data residency and privacy regulations. The security architect needs to design a data architecture that ensures compliance while optimizing performance. Which approach is MOST suitable for addressing these complex requirements?Security Architecture
- 25.A security analyst is investigating a suspected data breach involving sensitive customer information. The forensic investigation reveals that an attacker gained access through a vulnerable web application, escalated privileges, and then maintained persistence by injecting malicious code into a legitimate system process that restarts automatically. Which of the following MITRE ATT&CK tactics does this persistence method MOST directly align with?Security Operations
- 26.A financial institution is designing a new blockchain-based settlement system for inter-bank transactions. Due to regulatory requirements and the need for absolute transaction finality and immutability, the system must utilize a consensus mechanism that is highly resistant to collusion among participants and ensures that all legitimate transactions are eventually recorded, even if some participants are malicious. Which consensus mechanism would be MOST appropriate for this enterprise-grade, permissioned blockchain?Security Engineering
- 27.A security engineer is hardening a Windows Server that hosts a critical enterprise application. The organization's security policy requires that all system-level processes and services run with the minimum necessary privileges to perform their functions. Which of the following Windows features or concepts is MOST relevant to implementing this principle of least privilege for services?Security Engineering
- 28.A security architect is designing a system for a highly sensitive research facility that processes classified data. The system must enforce strict isolation between different security domains, even at the hardware level, to prevent any data leakage or unauthorized access. Which specialized system architecture is MOST appropriate for achieving this level of isolation?Security Engineering
- 29.A large e-commerce company is implementing a new AI-powered recommendation engine. During the development and testing phases, the data science team discovers that the engine consistently recommends higher-priced items to users in certain postal codes, regardless of their stated preferences or browsing history, potentially leading to unfair pricing for specific demographic groups. Which ethical concern related to AI is MOST directly highlighted by this discovery?Governance, Risk and Compliance
- 30.A large e-commerce company is experiencing frequent credential stuffing attacks against its customer login portal. The security team has implemented MFA, but attackers are still able to enumerate valid usernames. The company wants to implement a mechanism that cryptographically proves user presence and intent during authentication without relying on traditional passwords or shared secrets, thereby eliminating the ability to enumerate valid usernames through password-guessing attempts. Which of the following technologies would BEST address this specific challenge?Security Engineering
- 31.A critical infrastructure organization is integrating a new Industrial Control System (ICS) into its operational technology (OT) network. To ensure the highest level of security and prevent unauthorized access or modification, all communications between the ICS components and the supervisory control systems must be integrity-protected and cryptographically authenticated. Given the real-time constraints and resource limitations of some ICS devices, which advanced cryptographic primitive would be MOST suitable for ensuring data integrity and authenticity without full encryption?Security Engineering
- 32.A financial institution is evaluating its enterprise-wide risk management program. The Chief Risk Officer (CRO) wants to move beyond simply identifying risks to understanding the potential financial impact of various cyber events and prioritizing mitigation efforts based on this impact. Which of the following approaches should the CRO implement to achieve this objective?Governance, Risk and Compliance
- 33.A global enterprise is implementing a Zero Trust architecture across its highly distributed network, which includes on-premises data centers, multiple cloud providers, and remote worker endpoints. A key challenge is establishing and verifying the identity of users and devices, and continuously evaluating their trustworthiness before granting access to resources. Which IAM protocol or framework is BEST suited to facilitate this continuous verification and dynamic policy enforcement across such a diverse and distributed environment?Security Engineering
- 34.A global e-commerce company is migrating its entire infrastructure to a multi-cloud environment. The security team needs to establish a unified security posture, enforce consistent policies, and gain centralized visibility across AWS, Azure, and Google Cloud Platform while maintaining compliance with regional data residency laws. Which integrated security approach is best suited for this complex scenario?Security Architecture
- 35.A security architect is tasked with implementing data security for a new application that processes credit card information. To achieve PCI DSS compliance, the architect needs to ensure that sensitive authentication data (SAD) is never stored after authorization, even if encrypted. Which data security control BEST addresses this specific requirement?Security Architecture
- 36.A cloud architect is designing a new microservices-based application in a public cloud environment. Each microservice needs to securely access specific secrets (e.g., database credentials, API keys) without embedding them directly in the application code or configuration files. Which solution is BEST suited for managing and distributing these secrets dynamically and securely?Security Engineering
- 37.A security architect is designing a secure software supply chain for a critical aerospace system. The design requires ensuring the integrity and authenticity of all software components, libraries, and binaries throughout the development, build, and deployment pipelines. Any unauthorized modification or tampering at any stage must be detected and prevented. Which security control or process is most effective for achieving this end-to-end integrity and authenticity?Security Architecture
- 38.A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The auditor identifies a requirement to restrict the types of container images that can be deployed to the cluster, ensuring that only images from approved, trusted registries are allowed. Which native Kubernetes admission controller should the auditor recommend to enforce this policy?Security Engineering
- 39.A critical infrastructure organization is integrating a new Industrial Control System (ICS) into its existing network. Due to the high sensitivity of the ICS environment, the security team needs to ensure that any data flowing from the IT network to the OT network is strictly one-way, preventing any potential back-channel communication or data exfiltration from the OT network. Which specialized security device is BEST suited for enforcing this unidirectional data flow?Security Engineering
- 40.A security architect is evaluating different architectural patterns for a new highly available and resilient system. The system must maintain continuous operation even if a single component fails. Which principle is most directly addressed by implementing redundant components and failover mechanisms?Security Architecture
- 41.A security team is developing a threat hunting hypothesis: 'Adversaries are using legitimate administrative tools (LOLBins) to move laterally within our network, specifically targeting RDP sessions.' Which of the following data sources would be most critical to analyze to validate this hypothesis?Security Operations
- 42.An organization is designing a new critical infrastructure system that must operate continuously, even if major components fail or are compromised. The security architect is considering principles to ensure the system can withstand such events. Which design principle focuses on the system's ability to maintain operations despite failures or attacks, often through redundancy and isolation?Security Architecture
- 43.A large enterprise is migrating its on-premises data warehouse to a cloud-native platform. The data warehouse contains petabytes of sensitive customer transaction data, and the migration requires a phased approach. The security architect needs to design a solution that ensures data privacy and compliance with various regulations during the migration process, especially when data is transferred between the on-premises and cloud environments, and while it resides in temporary cloud storage before final integration. Which data security control is paramount for protecting this sensitive data during its journey and temporary residency in the cloud?Security Architecture
- 44.A security analyst is investigating a suspected ransomware infection. They observe encrypted files with a new extension, a ransom note, and a high CPU usage on several endpoints. Further analysis indicates that the ransomware used a complex obfuscation technique to evade signature-based detection. To gain a deeper understanding of the ransomware's decryption mechanism and potentially develop a countermeasure, which advanced forensic technique would be most appropriate?Security Operations
- 45.A large software company is adopting a 'shift-left' security approach and wants to integrate security testing into its Continuous Integration/Continuous Deployment (CI/CD) pipeline. The primary goal is to identify common security vulnerabilities and coding errors early in the development lifecycle, specifically within the source code itself, before compilation or deployment. Which security testing methodology is BEST suited for this purpose?Security Architecture
- 46.A forensic investigator is analyzing a compromised Linux server. They have created a memory dump and identified several suspicious processes. To determine if any of these processes are attempting to hide their activities by unlinking their executable files, which of the following techniques should the investigator use?Security Operations
- 47.A security architect is designing a highly available and resilient system for a critical financial application that processes millions of transactions daily. The system must tolerate the complete failure of an entire geographic region without data loss or significant service interruption. Which architectural pattern is most effective for achieving this objective?Security Architecture
- 48.A security analyst is performing threat hunting activities within the organization's SIEM. They are specifically looking for signs of a 'living off the land' attack, where attackers use legitimate system tools and processes for malicious purposes. Which of the following log analysis techniques would be most effective for detecting such an attack?Security Operations
- 49.A large enterprise is migrating its legacy monolithic applications to a microservices architecture running on Kubernetes. The security team needs to implement a solution that ensures all inter-service communication within the cluster is mutually authenticated and encrypted, without requiring developers to embed cryptographic logic into each microservice. This solution should also provide fine-grained authorization policies based on service identity. Which component of a service mesh would BEST address these requirements?Security Engineering
- 50.A security architect is integrating a legacy on-premises application with a new cloud-native microservices platform. The legacy application relies on Active Directory for authentication, while the cloud platform uses OIDC (OpenID Connect) with an external identity provider. Which component is essential for securely bridging these two distinct identity management systems?Security Architecture