CompTIA SecurityX (CAS-005) practice questions
316 free questions with answers and explanations.
- 51.A global software company is implementing a new federated identity management system to allow employees and external partners to securely access various cloud applications. The company wants to minimize the number of times users need to authenticate while ensuring that access policies are consistently enforced across all integrated services, regardless of their underlying identity stores. Which architectural component is crucial for achieving this seamless single sign-on (SSO) experience and consistent policy enforcement in a federated environment?Security Engineering
- 52.A security architect is reviewing the organization's disaster recovery plan (DRP) and business continuity plan (BCP). They note that while the DRP outlines detailed steps for restoring IT systems, the BCP lacks comprehensive strategies for maintaining critical business functions during a prolonged outage. Which governance framework element is primarily being overlooked?Governance, Risk and Compliance
- 53.A security architect is performing a threat modeling exercise for a new cloud-native application that processes sensitive customer data. The architect wants to systematically identify potential threats and vulnerabilities throughout the application's lifecycle. Which of the following threat modeling methodologies is best suited for this purpose, providing a structured approach from design to deployment?Governance, Risk and Compliance
- 54.A security architect is performing a business impact analysis (BIA) for a critical e-commerce platform. During this process, they identify that a prolonged outage of the platform would result in significant reputational damage, customer churn, and potential regulatory fines, in addition to direct revenue loss. Which component of the BIA does this identification of indirect and non-financial losses primarily fall under?Governance, Risk and Compliance
- 55.An organization is evaluating a new Security Orchestration, Automation, and Response (SOAR) platform. One of the key requirements is to automatically enrich incident data by querying various threat intelligence feeds and internal asset management databases. Which component of a SOAR platform is primarily responsible for performing these automated data gathering and enrichment tasks?Security Operations
- 56.During a threat modeling exercise for a new mobile application, the development team identifies a potential vulnerability where an attacker could intercept API calls between the app and the backend server. The team determines that implementing mutual TLS authentication and API gateway rate limiting would effectively address this risk. Which phase of the STRIDE threat modeling methodology does this activity align with?Governance, Risk and Compliance
- 57.A security architect is designing a new blockchain-based settlement system for inter-bank transactions. The system requires high fault tolerance and consistency, even if some nodes in the distributed network act maliciously or fail. The solution must ensure that all legitimate nodes agree on the order and validity of transactions with high throughput. Which consensus algorithm would be MOST suitable for this requirement?Security Engineering
- 58.A financial institution is migrating its legacy mainframe applications to a modern cloud-native architecture. The security team needs to ensure that the new applications comply with stringent regulatory requirements for data integrity and non-repudiation. Which cryptographic primitive, when used for transaction signing, MOST effectively addresses these requirements?Security Engineering
- 59.A software development team is adopting a GitOps methodology for deploying and managing microservices in a Kubernetes cluster. As part of their continuous integration/continuous deployment (CI/CD) pipeline, they need to ensure that all changes to infrastructure and application configurations are automatically scanned for security vulnerabilities and policy compliance BEFORE being applied to the production environment. Which type of security testing is BEST suited for integrating into the GitOps workflow at the pre-deployment stage?Security Engineering
- 60.A security architect is designing a system that processes highly sensitive personal health information (PHI) and must comply with stringent regulatory requirements for data protection. The architect needs a solution to ensure that cryptographic keys used for encrypting PHI are securely generated, stored, and managed throughout their lifecycle, with strong tamper-resistance and auditability. Which technology combination is purpose-built for this requirement?Security Architecture
- 61.A security analyst is investigating a suspected compromise on a Linux server. They find a running process that has no associated executable file on disk, and its memory regions show unusual permissions and content. Which of the following forensic techniques would be most appropriate to further analyze this anomaly?Security Operations
- 62.A financial institution is evaluating its risk exposure to cyberattacks. They estimate that a successful data breach would result in a direct loss of $500,000 in recovery costs and regulatory fines. They also estimate an indirect loss of $1,500,000 due to reputational damage and customer churn. Historical data suggests there is a 20% chance of such a breach occurring in any given year. What is the Annualized Loss Expectancy (ALE) for this specific risk?Governance, Risk and Compliance
- 63.A financial services organization is migrating its sensitive data storage to a multi-cloud environment. To meet stringent regulatory compliance requirements (e.g., GDPR, PCI DSS), they must ensure that cryptographic keys used for data encryption are managed with the highest level of security, including strict access controls, auditing, and protection against exfiltration. Which key management solution offers the BEST combination of security, control, and compliance for this scenario?Security Engineering
- 64.A global enterprise is migrating its legacy on-premises applications to a hybrid cloud environment. The security team needs to ensure consistent security policies, threat protection, and secure access for users to applications regardless of their location or the application's hosting environment. Which architectural approach is best suited to meet these requirements?Security Architecture
- 65.A security architect is designing a new cloud-native application that will handle sensitive financial transactions. To ensure secure, authenticated, and authorized communication between microservices within the application's service mesh, without relying on traditional network perimeter controls, which mechanism should be implemented?Security Architecture
- 66.A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to integrate security testing as early as possible in the development lifecycle to identify and remediate vulnerabilities before deployment. Which security tool or practice is MOST aligned with this 'shift-left' strategy at the code development stage?Security Architecture
- 67.A security architect is designing a system that processes highly sensitive personal health information (PHI). To comply with stringent privacy regulations, the system must ensure that data is encrypted both in transit and at rest, and that the encryption keys are managed securely and separately from the data. Which of the following integrated security solutions BEST addresses the secure management and separation of encryption keys?Security Architecture
- 68.A hospital is deploying a new AI-powered diagnostic tool that uses patient medical images to detect early signs of disease. The Chief Medical Officer (CMO) is concerned about the potential for algorithmic bias, particularly if the training data disproportionately represents certain demographics, leading to inaccurate diagnoses for underrepresented groups. Which aspect of AI governance is the CMO primarily concerned about?Governance, Risk and Compliance
- 69.An organization is considering implementing a new AI-powered anomaly detection system for its network. Before full deployment, the CISO wants to ensure that the system's decision-making process is transparent, explainable, and free from unfair biases, especially since it will be used to flag potential insider threats. Which aspect of AI governance is the CISO primarily focused on addressing?Governance, Risk and Compliance
- 70.A security architect is designing a system for a highly distributed global manufacturing company that uses numerous IoT devices, operational technology (OT) systems, and cloud-based applications. The challenge is to establish a consistent security policy and enforce it across all these diverse endpoints, regardless of their location or underlying technology, without relying on traditional network perimeters. Which architectural paradigm is best suited to address this challenge?Security Architecture
- 71.A security engineer is tasked with hardening a critical Linux server that processes sensitive financial transactions. The organization requires that all sensitive data residing on the server's storage be encrypted at rest, and that the encryption keys themselves must be protected against compromise even if the server's operating system is breached. Which of the following technologies would BEST meet these requirements for key protection?Security Engineering
- 72.A forensic investigator is analyzing a compromised Linux server. They find evidence of an attacker modifying the `/etc/passwd` file and creating a new user with root privileges. To determine the exact command used by the attacker to modify the file and create the user, which Linux audit subsystem would provide the most precise and detailed information?Security Operations
- 73.A security team is performing a post-incident analysis after a targeted attack. They suspect the attacker used a zero-day vulnerability to gain initial access. To understand the full scope of the compromise and prevent future similar attacks, they need to identify the specific vulnerability and the exploit used. Which type of analysis would be most effective in determining the exact nature of the zero-day exploit?Security Operations
- 74.A security analyst is reviewing a server's scheduled tasks and finds an entry configured to execute a PowerShell script every 30 minutes. The script attempts to connect to an external IP address and download a file if the connection is successful. The script uses obfuscated code and is not digitally signed. There is no legitimate business reason for this server to perform such a task. What MITRE ATT&CK technique does this most closely align with?Security Operations
- 75.A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, even against the threat of future quantum computers. The data includes highly sensitive intellectual property. Which advanced cryptographic approach should be prioritized to ensure the enduring security of this archived data?Security Engineering
- 76.A security architect is reviewing the organization's current state of compliance. A key challenge is that various departments interpret regulatory requirements differently, leading to inconsistent control implementation and difficulty in demonstrating overall compliance to auditors. The architect needs a mechanism to ensure that compliance is consistently achieved and measured across the organization, focusing on the desired secure state rather than just checking off boxes. Which compliance metric approach is MOST effective for this situation?Governance, Risk and Compliance
- 77.An organization is preparing for an advanced persistent threat (APT) campaign targeting their intellectual property. The security team wants to proactively identify potential command and control (C2) channels that might be established by the attackers. Which of the following threat hunting techniques would be most effective for this specific goal?Security Operations
- 78.A security analyst is reviewing network traffic logs and observes a high volume of DNS queries for non-existent domains (NXDOMAIN) originating from an internal server to various external DNS resolvers. This activity is persistent and occurs at unusual times. Which type of attack is most likely indicated by these observations?Security Operations
- 79.A security analyst is investigating a critical alert from a web application firewall (WAF) indicating a potential SQL injection attempt against a public-facing web application. The alert shows a suspicious string (' UNION SELECT null, null, @@version -- ') in a URL parameter. Which of the following is the MOST appropriate next step for the analyst to take to contain the immediate threat?Security Operations
- 80.A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements, all encryption keys used for customer transaction data must be protected against both logical and physical compromise, and their lifecycle must be managed according to FIPS 140-2 Level 3 standards. The solution must also support high transaction volumes. Which specialized hardware device is BEST suited to meet these requirements?Security Engineering
- 81.A security architect is designing a secure communication channel for two geographically dispersed data centers. The goal is to ensure confidentiality, integrity, and authenticity of data in transit over an untrusted public network. Which protocol is best suited for establishing a secure tunnel between these two data centers?Security Architecture
- 82.A company is implementing a new security monitoring solution. They want to ensure that all critical security events are captured and analyzed in real-time, but they are concerned about the volume of data and the potential for alert fatigue. Which of the following approaches best balances comprehensive monitoring with efficient alert management?Security Operations
- 83.A security architect is designing an authentication system for a highly sensitive government application. The system requires multiple independent factors for user authentication and must be resistant to credential theft and replay attacks. Which of the following authentication methods, when combined, BEST meets these requirements for a robust, multi-factor authentication (MFA) system?Security Architecture
- 84.A company is conducting a risk assessment for its new customer relationship management (CRM) system. The system processes sensitive customer data, and a data breach could result in significant regulatory fines and reputational damage. The likelihood of a successful attack is estimated at 0.05 per year, and the potential financial loss from such an event is estimated to be $2,000,000. What is the Annualized Loss Expectancy (ALE) for this risk?Governance, Risk and Compliance
- 85.A security architect is designing a system for a highly distributed global manufacturing company that has thousands of devices, users, and applications spread across multiple continents. The company wants to enforce a security model where no user, device, or application is inherently trusted, and access is granted only after continuous verification based on context. Which architectural model best describes this approach?Security Architecture
- 86.A security architect is designing a system for a critical infrastructure organization. Due to the high impact of any disruption, they are evaluating a framework that provides detailed guidance on identifying, protecting, detecting, responding to, and recovering from cyber incidents. The organization also needs to demonstrate compliance with various government regulations. Which of the following frameworks is best suited for this purpose?Governance, Risk and Compliance
- 87.A security engineer is hardening a critical Linux server that hosts a proprietary application. As part of the hardening process, the engineer needs to restrict network access to only essential services, specifically SSH (port 22) and the application's unique port (TCP 8443) from a limited set of administrative IP addresses. All other inbound and outbound traffic should be blocked by default. Which command-line utility is BEST suited for implementing these granular packet filtering rules directly on the Linux server?Security Engineering
- 88.A security architect is designing a new cloud-based data analytics platform that will process sensitive customer financial information. The architect needs to ensure that the platform adheres to strict data privacy regulations, including GDPR and CCPA, while also maintaining high availability and performance. Which of the following governance frameworks would be MOST appropriate to guide the design and implementation of security controls for this platform?Governance, Risk and Compliance
- 89.A security architect is implementing a Privileged Access Management (PAM) solution. As part of the least privilege principle, users should only be granted elevated permissions for a specific duration or task. Which PAM feature BEST supports this requirement?Security Engineering
- 90.A large healthcare provider is considering deploying an AI system for predictive diagnostics. The legal team is concerned about potential liability if the AI makes an incorrect diagnosis leading to patient harm, especially given the 'black box' nature of some advanced AI models. They want to ensure there is a clear mechanism to identify who is responsible for AI system failures and how decisions are made. Which AI governance principle is most relevant to address this concern?Governance, Risk and Compliance
- 91.A CISO is reviewing the organization's approach to cybersecurity and is considering adopting a framework that provides a common language for both technical and business stakeholders, enables risk prioritization based on business needs, and helps integrate cybersecurity into overall enterprise risk management. Which framework is designed with these capabilities?Governance, Risk and Compliance
- 92.An organization is conducting a post-incident review following a data breach. The incident response team determined that the initial compromise occurred through a phishing email that led to credential theft. A key finding is that the organization lacked a robust mechanism to detect unusual login activity from compromised accounts. Which of the following would be the MOST effective control to implement to prevent similar future incidents?Security Operations
- 93.A security engineer is tasked with implementing server hardening best practices across a fleet of Linux servers. The organization requires a method to quickly identify all open ports and established connections on a given server to detect unauthorized services or suspicious communication. Which command-line utility is MOST appropriate for this task?Security Engineering
- 94.A software development team is adopting a microservices architecture and needs to secure inter-service communication. Each microservice should only be able to access the specific resources it needs, and this access should be dynamically managed based on its identity and context rather than static IP addresses or pre-shared keys. Which IAM concept would BEST facilitate this fine-grained, dynamic authorization for microservices?Security Engineering
- 95.A security engineer is tasked with implementing server hardening best practices across a fleet of Linux servers. The organization's policy mandates that all unnecessary services must be disabled, and the attack surface minimized. Which of the following commands would be MOST effective in identifying all open network ports and the services listening on them to inform the hardening process?Security Engineering
- 96.A security team is implementing a Zero Trust architecture across a highly distributed cloud environment. They need to ensure that every request between services, regardless of its origin or destination within the environment, is explicitly authenticated and authorized. This includes requests within the same cloud region, across regions, and even across different cloud providers. Which of the following concepts is central to achieving this level of granular, per-request security?Security Engineering
- 97.A company is migrating its on-premises data center to a hybrid cloud environment. The security architect needs to ensure consistent security policies and visibility across both on-premises and cloud resources. Which of the following approaches BEST addresses this requirement?Security Architecture
- 98.A cloud architect is designing a new microservices-based application in a public cloud environment. Each microservice needs to securely access sensitive credentials (e.g., API keys, database passwords) without embedding them directly in code or configuration files. The solution should also ensure that these credentials are automatically rotated and audited. Which security engineering practice is MOST appropriate for managing these sensitive credentials?Security Engineering
- 99.A security architect is designing a system for managing highly sensitive intellectual property (IP) within a research and development firm. The system requires that access to specific IP documents is not only restricted by user role but also by the sensitivity level of the document and the project the user is currently assigned to. Additionally, access decisions must dynamically adapt based on the user's location and the device's posture (e.g., managed vs. unmanaged device). Which access control model provides the most flexibility and granularity to implement these dynamic, context-aware policies?Security Architecture
- 100.A security architect is evaluating different architectural patterns for a new highly available web application that processes financial transactions. The application must remain operational even if an entire data center region experiences an outage. Which architectural principle is MOST critical to ensure this level of resilience?Security Architecture