CompTIA SecurityX (CAS-005) practice questions
316 free questions with answers and explanations.
- 101.An incident response team is investigating a critical server compromise. They have obtained a memory dump from the affected system. To determine if a rootkit is actively hiding processes or network connections, which forensic technique would be most effective?Security Operations
- 102.A Chief Compliance Officer (CCO) is implementing a new compliance monitoring program. They want to ensure that the program not only identifies non-compliance but also provides insights into the root causes and trends of compliance failures across the organization. Which type of compliance metric would be most effective for achieving this goal?Governance, Risk and Compliance
- 103.A security architect is performing a threat modeling exercise for a new cloud-native application that processes sensitive customer data. The architect is particularly concerned about vulnerabilities that could lead to unauthorized data disclosure, data alteration, or denial of service. Which threat modeling framework would BEST help the architect systematically identify these types of threats?Governance, Risk and Compliance
- 104.An incident response team is analyzing a compromised Linux server. They discover that a malicious user account was created by an attacker, and this account was subsequently used to modify critical system files. The team needs to determine the exact commands executed by the attacker using this malicious account. Which of the following log files would be MOST crucial to review for this information on a standard Linux system?Security Operations
- 105.During a routine vulnerability scan of an organization's network, a security professional discovers several unpatched systems running end-of-life operating systems. These systems host critical legacy applications that cannot be easily updated or replaced due to compatibility issues and vendor support. What is the most appropriate long-term mitigation strategy for these systems?Security Operations
- 106.A security architect is evaluating a third-party vendor that will manage critical infrastructure for the organization. The vendor has provided their SOC 2 Type II report. Which of the following information should the architect primarily look for in this report to assess the vendor's commitment to security and compliance over time?Governance, Risk and Compliance
- 107.A security analyst is reviewing logs from a web server and notices a sudden, sustained increase in HTTP GET requests to a specific URL, originating from a wide range of disparate IP addresses. The requests are all for a non-existent page and contain random, long strings in the query parameters. The web server's CPU utilization is spiking, and legitimate users are reporting slow response times. Which of the following attack types is most likely occurring?Security Operations
- 108.A recent audit report identified that several critical systems lack adequate logging for security events, making incident investigation difficult and compliance reporting incomplete. The CISO needs to address this finding by implementing a comprehensive logging strategy across the enterprise. Which of the following risk management steps should the CISO prioritize IMMEDIATELY after identifying this gap?Governance, Risk and Compliance
- 109.A security architect is designing a key management system for a global enterprise that processes highly sensitive data. The system must ensure that cryptographic keys are generated, stored, and used in a way that provides the highest level of tamper resistance and protection against disclosure, even from privileged administrators. Which specialized hardware component would be MOST appropriate for safeguarding the master encryption keys?Security Engineering
- 110.A global financial institution is expanding its operations into several new countries. As part of its governance strategy, the institution must ensure compliance with a multitude of international data protection laws, including GDPR, CCPA, and emerging regulations in Asia and South America. To achieve this, the institution decides to adopt a common set of security policies and controls that meet the highest standards across all applicable regulations, rather than tailoring them individually for each region. Which compliance strategy is being employed?Governance, Risk and Compliance
- 111.A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, even against future advances in cryptanalysis, including quantum computing. The archived data will be accessed infrequently but must remain secure. Which cryptographic approach should be prioritized for protecting this data?Security Engineering
- 112.A security architect is evaluating a new cloud-native application for deployment. The application relies heavily on containerized microservices orchestrated by Kubernetes. To ensure the integrity and authenticity of container images used in production, the architect wants to implement a mechanism that verifies the digital signature of each image before it is allowed to run. Which of the following best describes this security control?Security Engineering
- 113.A security architect is tasked with establishing a robust governance framework for a rapidly growing fintech startup. The startup processes sensitive financial data and operates across multiple jurisdictions. The architect needs a framework that provides a comprehensive approach to information security, covering organizational structure, policies, processes, and risk management, while also being internationally recognized for demonstrating due diligence to regulators and partners. Which of the following frameworks is MOST suitable for this requirement?Governance, Risk and Compliance
- 114.A security architect is integrating a new cloud-based analytics platform with an existing on-premises Identity Provider (IdP). The goal is to allow users to authenticate once against the on-premises IdP and then seamlessly access the cloud analytics platform without re-entering credentials. The solution must support modern authentication protocols and avoid direct exposure of the on-premises IdP to the internet. Which component is BEST suited to facilitate this secure and seamless authentication process?Security Architecture
- 115.A cloud architect is designing a secure network for a multi-tenant SaaS application hosted on a public cloud provider. The application processes sensitive customer data, and strict isolation between tenants is paramount. Which network architecture component is MOST effective in providing granular, logical separation of network traffic and resources for each tenant within the shared cloud infrastructure?Security Architecture
- 116.A security architect is designing a key management system for a global enterprise that processes vast amounts of encrypted data. The solution must ensure that encryption keys are generated, stored, and managed in a highly secure, tamper-resistant environment, meeting stringent compliance requirements for cryptographic module validation. Which specialized hardware device is MOST suitable for this purpose?Security Engineering
- 117.A security analyst is investigating a suspected data exfiltration incident. They have identified a compromised internal server that was observed making frequent, small outbound HTTP POST requests to an external IP address that changes periodically. The HTTP user-agent string used in these requests is highly unusual and inconsistent with any legitimate application on the server. What technique is the attacker most likely employing?Security Operations
- 118.A security architect is designing a new microservices-based application for a financial institution. The application will handle sensitive customer data and must maintain high availability and integrity, even in the face of partial system failures or malicious attacks. Which of the following design principles is MOST critical for ensuring the application's resilience and security in this scenario?Security Architecture
- 119.A security analyst is performing a post-incident review after a significant data breach. The root cause analysis indicates that the attackers gained initial access through a vulnerable web application, then escalated privileges, and finally moved laterally to a database server to exfiltrate data. To prevent similar future incidents, which of the following security controls would have been most effective in limiting the impact of the lateral movement phase?Security Operations
- 120.A security architect is implementing a Zero Trust architecture across a highly distributed cloud environment. The goal is to ensure that all service-to-service communication within the microservices ecosystem is mutually authenticated and encrypted, regardless of network location. The architect wants to achieve this without burdening developers with manual certificate management or complex network configurations. Which approach would BEST integrate into a service mesh to achieve this?Security Engineering
- 121.A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster must originate from trusted, scanned repositories and remain immutable. Which Kubernetes security admission controller should the engineer configure to enforce this policy?Security Engineering
- 122.A security architect is designing an identity and access management (IAM) solution for a multinational corporation. The solution must support seamless single sign-on (SSO) across various cloud-based applications from different vendors while maintaining a high level of security and compliance with regional data residency requirements. Which IAM federation standard is BEST suited for this scenario?Security Engineering
- 123.A financial institution is designing a new payment processing system that must comply with strict regulatory requirements for data confidentiality and non-repudiation. The system needs to ensure that all financial transactions are provably authentic and that the sender cannot later deny having sent a specific transaction. Which cryptographic primitive is essential for achieving non-repudiation in this context?Security Architecture
- 124.A security architect is designing an authentication system for a new enterprise application. The application will be deployed across multiple cloud environments and needs to support a diverse set of user identities, including employees, partners, and customers, each managed by different identity providers. The architect wants to enable seamless, single sign-on (SSO) experiences while ensuring strong authentication and authorization across these disparate identity sources. Which of the following identity federation standards would be MOST appropriate for this scenario?Security Engineering
- 125.A security architect is evaluating different key management strategies for an organization's cryptographic operations. The organization requires a solution that offers the highest level of assurance for protecting cryptographic keys, especially master keys, against both logical and physical attacks. Which key management solution offers this level of protection?Security Engineering
- 126.A security architect is designing an authentication system for a new enterprise application that requires high assurance and resistance to credential stuffing attacks. The system must support multi-factor authentication (MFA) and provide cryptographic proof of identity without relying on shared secrets or centralized user databases for primary authentication. Which of the following authentication standards would BEST meet these requirements?Security Engineering
- 127.A security architect is designing a system for a global financial institution that processes high-volume transactions and requires continuous availability. The design must ensure that the system can withstand the failure of an entire regional data center without service interruption. Which architectural principle is most critical for achieving this requirement?Security Architecture
- 128.An incident response team is performing forensics on a compromised Windows server. They suspect that an attacker used a remote access tool (RAT) that injected itself into legitimate processes to evade detection. To identify these hidden processes and their associated network connections, which of the following memory forensic techniques would be most effective?Security Operations
- 129.A security analyst is investigating a suspected insider threat. They need to determine if a specific user account accessed sensitive files outside of business hours and copied them to a removable drive. Which of the following log sources would provide the most relevant forensic evidence for this investigation?Security Operations
- 130.A security architect is tasked with ensuring the confidentiality and integrity of data at rest in a multi-tenant cloud storage service. The solution must prevent the cloud provider from accessing the unencrypted data, even with full administrative privileges. Which data security strategy should the architect recommend?Security Architecture
- 131.A cybersecurity team is evaluating a third-party API gateway solution for their microservices architecture. The solution needs to provide a centralized point for authentication, authorization, rate limiting, and traffic routing to various backend microservices, while also protecting the internal services from direct exposure. Which security pattern does this API gateway primarily implement?Security Architecture
- 132.A security team is implementing a Zero Trust architecture for a highly distributed cloud environment. A key requirement is to ensure that all network communication between workloads (e.g., containers, VMs) is mutually authenticated and authorized based on their identity, regardless of their network location. This should be transparent to developers and automatically enforced. Which technology or approach would BEST achieve this requirement?Security Engineering
- 133.An incident response team is investigating a potential insider threat. They need to analyze user activity on a critical file share to determine if any unauthorized access or data exfiltration occurred. Specifically, they want to see which users accessed which files, when, and what actions (read, write, delete) were performed. Which type of log would provide the most granular and relevant information for this investigation?Security Operations
- 134.A security architect is deploying a new web application into a multi-cloud environment. The application's database contains highly sensitive customer data, and the organization requires a solution that provides granular control over network access to the database, ensuring that only specific application instances from a particular Virtual Private Cloud (VPC) can connect to it, and that all other traffic is implicitly denied. Which network security construct should the architect use to achieve this precise level of access control?Security Architecture
- 135.A global technology company is establishing a new data center in a country with stringent data residency and sovereignty laws. The company's CISO wants to ensure that all data stored and processed within this new facility complies with local regulations while maintaining global security standards. Which of the following governance strategies would best address this requirement?Governance, Risk and Compliance
- 136.A global organization is implementing a Zero Trust architecture. As part of this initiative, all communication between microservices across different cloud providers must be mutually authenticated and encrypted, regardless of network location. Which of the following technologies would be MOST effective in achieving this requirement?Security Engineering
- 137.A security analyst is investigating a suspected data exfiltration incident. They discover that a large volume of data was transferred from an internal server to an external IP address over TCP port 53. Further investigation reveals that the data was encapsulated within DNS queries and responses, using a custom protocol. Which exfiltration technique is being used?Security Operations
- 138.A security architect is designing a new cloud-native application that will process highly sensitive personal identifiable information (PII). The application uses microservices, and each microservice needs to securely communicate with other microservices without relying on a centralized certificate authority or pre-shared keys for every connection. Which of the following advanced cryptographic techniques would BEST address this requirement?Security Engineering
- 139.An organization is deploying a new web application and must ensure all server-side components, including the operating system, web server, and application runtime, are configured to minimize attack surface. Which of the following is a key server hardening practice that focuses on removing unnecessary software and services?Security Engineering
- 140.A security architect is designing a secure private cloud environment for a government agency handling unclassified but sensitive data. The agency requires strict isolation between different departmental workloads and ensuring that network traffic between these workloads cannot be intercepted or modified by other tenants or external entities. Which networking construct is fundamental to achieving this level of isolation and secure communication within the private cloud?Security Architecture
- 141.A new regulation mandates that all data breaches involving personally identifiable information (PII) must be reported to affected individuals and regulatory authorities within 72 hours of discovery. An organization currently has an incident response plan that focuses primarily on containment and eradication, with reporting procedures being an afterthought. To comply with the new regulation, the organization needs to update its plan. Which of the following components of the incident response plan requires the MOST significant immediate revision?Governance, Risk and Compliance
- 142.A security analyst is investigating a compromised endpoint. They suspect that a malicious process is attempting to hide its activity by unlinking itself from the process list and manipulating system calls. Which advanced forensic technique would be most effective in detecting such a rootkit-like behavior?Security Operations
- 143.A security architect is designing a new cloud-native application that will handle highly sensitive customer data. The application will leverage serverless functions (AWS Lambda) and a managed NoSQL database (DynamoDB). To minimize the attack surface and ensure data integrity, which security principle should be most rigorously applied to the serverless functions' permissions?Security Operations
- 144.A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the high-stakes nature of the environment, the security architect must ensure that all communications between field devices (PLCs, RTUs) and the central control system are not only encrypted but also protected against replay attacks and unauthorized modifications. Which cryptographic primitive, when properly implemented, would provide the BEST assurance of both data integrity and authenticity for these communications?Security Engineering
- 145.A security architect is designing a new enterprise application that requires high assurance of data integrity and authenticity for critical transactions. The solution must ensure that any modification to the transaction data, even a single bit, is immediately detectable and attributable to a specific entity. Which cryptographic primitive would be MOST suitable for this requirement?Security Engineering
- 146.A multinational corporation is developing a new cloud-based platform for processing sensitive customer data across various regions. The legal team is concerned about complying with a patchwork of global data privacy regulations, such as GDPR, CCPA, LGPD, and others. To streamline compliance efforts and reduce overhead, which approach should the security architect recommend?Governance, Risk and Compliance
- 147.A security analyst is investigating a compromised workstation. The attacker gained initial access, established persistence, and then attempted to move laterally to other systems. The analyst wants to understand the full scope of the lateral movement attempts and identify all accessed systems. Which of the following forensic artifacts would provide the MOST comprehensive evidence of lateral movement on the compromised workstation?Security Operations
- 148.A Chief Information Security Officer (CISO) is evaluating the organization's adherence to various compliance standards. They discover that while many individual controls are implemented, there is no overarching process to ensure that these controls are consistently applied and regularly reviewed across all systems and departments. Which aspect of a governance framework is most directly lacking?Governance, Risk and Compliance
- 149.A security architect is reviewing an existing application's data flow to identify potential vulnerabilities. The application processes user input, stores it in a database, and then displays it to other users. Which of the following data security principles is MOST relevant to mitigating risks associated with data in transit and at rest in this scenario?Security Architecture
- 150.A development team is implementing a new API gateway for an internal application. The gateway needs to enforce authorization policies, handle rate limiting, and protect against common web vulnerabilities. Which architectural pattern would BEST integrate these security functions into the API gateway?Security Architecture