CompTIA SecurityX (CAS-005) practice questions

316 free questions with answers and explanations.

Practice test
  1. 151.A security architect is integrating a legacy on-premises application with a new cloud-native microservices platform. The legacy application uses its own user store, while the microservices platform relies on a modern identity provider. To enable single sign-on (SSO) and consistent user experience across both environments without migrating the legacy user store, which architectural component should be implemented?Security Architecture
  2. 152.A global technology company is expanding its operations into new markets. The legal team is concerned about varying data residency and privacy regulations across different jurisdictions, specifically regarding the storage and processing of customer data. They want to implement a strategy that allows them to meet local compliance requirements without having to redesign their entire data architecture for each country. Which compliance strategy is most appropriate for this scenario?Governance, Risk and Compliance
  3. 153.A security architect is designing an automated incident response playbook for a cloud environment. The goal is to quickly isolate compromised resources, collect forensic data, and apply temporary remediation steps without human intervention during initial detection. Which of the following automation technologies would be MOST suitable for orchestrating these complex, multi-step security actions across various cloud services?Security Engineering
  4. 154.A Chief Information Security Officer (CISO) is presenting the organization's cybersecurity posture to the board of directors. The board is primarily interested in the financial risks associated with cyber threats and the potential return on investment (ROI) for new security initiatives. Which risk assessment approach should the CISO use to best communicate these financial implications?Governance, Risk and Compliance
  5. 155.An organization is evaluating its risk management program. The CISO wants to understand the financial impact of a potential data breach. They estimate that a breach would cost approximately $2,000,000 per incident and has a 25% chance of occurring in a given year. The organization has comprehensive cyber insurance that covers 75% of the financial loss for any single incident. What is the Single Loss Expectancy (SLE) for this data breach WITHOUT considering the insurance coverage?Governance, Risk and Compliance
  6. 156.A security architect is evaluating a new cloud-native application for deployment. The application uses serverless functions and containers, and processes sensitive customer data. The architect must ensure that the application's runtime environment is hardened against supply chain attacks and unauthorized code execution, specifically by ensuring that only approved, signed container images can be deployed and executed. Which security control would BEST enforce this policy?Security Engineering
  7. 157.A large enterprise is adopting a 'shift-left' security approach and wants to integrate security testing early into their CI/CD pipeline for custom-developed applications. The primary goal is to identify common coding vulnerabilities, such as SQL injection, cross-site scripting (XSS), and buffer overflows, before the code is even deployed. Which type of security testing tool is best suited for this objective?Security Architecture
  8. 158.A security architect is designing a new microservices platform that will host highly sensitive customer data. To ensure data confidentiality and integrity, all data at rest must be encrypted. Furthermore, the encryption keys themselves must be protected and managed securely, with the ability to rotate them regularly without re-encrypting all data. Which advanced cryptographic technique would BEST address these requirements?Security Engineering
  9. 159.A security architect is designing a new microservices platform that will host sensitive customer data. The platform requires that all data at rest be encrypted, and the encryption keys must be rotated regularly (e.g., annually) and managed centrally. Furthermore, the system must ensure that if a key is compromised, the impact is limited to the data encrypted by that specific key generation. Which key management practice would BEST achieve these goals?Security Engineering
  10. 160.A large manufacturing company is integrating its operational technology (OT) network with its enterprise IT network for centralized monitoring and data analytics. The security team needs to ensure that data can flow unidirectionally from the OT network to the IT network, preventing any potential inbound threats from the IT network impacting critical production systems. Which of the following specialized systems should be implemented?Security Engineering
  11. 161.During a routine vulnerability assessment, a security analyst discovers an outdated web server running on an internal network segment. The server is configured with default credentials for its management interface, which is accessible from other internal segments. The analyst identifies several known vulnerabilities associated with this server version, including remote code execution (RCE) flaws. Which of the following represents the MOST critical immediate risk presented by this discovery?Security Operations
  12. 162.A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs as a service, and its service account requires minimal privileges to perform its functions, specifically to access a network share on another server. The engineer wants to ensure that the service account's password is automatically managed by the domain and rotated regularly without manual intervention. Which type of account should be used?Security Engineering
  13. 163.A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements (e.g., PCI DSS) and the need to protect sensitive transaction data, the organization needs to ensure that cryptographic operations, particularly key generation and digital signing, are performed in a highly secure, tamper-proof environment that can be audited for compliance. Which type of specialized system is purpose-built to meet these requirements?Security Engineering
  14. 164.A security architect is designing a data security solution for a B2B SaaS platform that handles sensitive customer financial data. The platform uses multiple microservices, and data is stored in various databases (relational, NoSQL). To comply with stringent regulatory requirements (e.g., GDPR, PCI DSS), the architect needs to ensure that data is encrypted at rest and in transit, and that access policies are consistently applied across all data stores. Which architectural pattern provides the most integrated and scalable approach for managing encryption keys and access controls across this diverse environment?Security Architecture
  15. 165.A security team is developing a threat hunting program. They want to move beyond simply reacting to alerts and proactively search for advanced persistent threats (APTs) that may have bypassed automated defenses. Which of the following methodologies emphasizes establishing hypotheses about attacker behavior and systematically searching for evidence to prove or disprove them?Security Operations
  16. 166.A company is developing a secure communication platform. The architecture requires that messages between users are encrypted end-to-end, and the system must be able to verify the identity of both the sender and receiver without a central authority acting as an intermediary for key exchange. Which cryptographic primitive is MOST suitable for establishing secure, authenticated communication channels in this scenario?Security Architecture
  17. 167.A cybersecurity team is conducting a periodic review of the organization's enterprise risk management strategy. They note that the current strategy focuses heavily on identifying and mitigating technical vulnerabilities but lacks clear guidance on how to assess and manage risks associated with human error, supply chain dependencies, and geopolitical events. Which aspect of risk management is primarily deficient?Governance, Risk and Compliance
  18. 168.A large e-commerce company is developing a new AI-powered recommendation engine. During the design phase, the data science team raises concerns that the training data, primarily based on historical purchasing patterns, might inadvertently perpetuate existing biases against certain demographic groups. Which AI governance principle is most directly being challenged?Governance, Risk and Compliance
  19. 169.A security architect is designing a secure private cloud environment for a government agency. The agency requires strict network isolation between different departments and projects, ensuring that traffic from one department cannot inadvertently or maliciously reach resources belonging to another, even within the same physical infrastructure. Which cloud networking construct is most appropriate for achieving this granular network segmentation and isolation?Security Architecture
  20. 170.An organization is preparing for a simulated cyberattack exercise to test their incident response capabilities. The exercise plan includes a scenario where an advanced attacker gains a foothold and attempts to escalate privileges. To accurately assess the blue team's detection and response to privilege escalation techniques, which framework would provide a comprehensive and structured catalog of known tactics, techniques, and procedures (TTPs) that can be used to simulate such attacks?Security Operations
  21. 171.An organization is developing a new medical device that processes highly sensitive patient health information. Due to the critical nature of the data and the potential impact on patient safety, the organization wants to ensure the highest level of data privacy and security throughout the device's lifecycle. Which of the following regulatory frameworks is MOST relevant and impactful for guiding the development and deployment of this medical device in the United States?Governance, Risk and Compliance
  22. 172.A security architect is designing a secure communication channel between two geographically dispersed data centers over a public internet connection. The primary requirements are confidentiality, integrity, and authenticity of the data in transit, as well as secure key exchange and management for the communication tunnel. Which networking protocol suite is BEST suited for establishing such a secure tunnel?Security Architecture
  23. 173.A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs as a service and requires access to network resources and specific file shares. To minimize the attack surface and adhere to the principle of least privilege, the engineer wants to assign a service account that automatically manages its password, can be associated with a Service Principal Name (SPN), and supports delegation across multiple hosts. Which type of account should the engineer configure?Security Engineering
  24. 174.A security architect is implementing a Privileged Access Management (PAM) solution. As part of this, administrative users should only have elevated permissions for a limited, predefined duration when performing specific tasks, and these permissions should automatically revoke once the task is completed or the duration expires. Which access control principle is being implemented?Security Engineering
  25. 175.A software development team is adopting a DevOps methodology and needs to integrate security practices throughout their continuous integration/continuous deployment (CI/CD) pipeline. They want to automate security checks as much as possible to ensure rapid feedback and maintain development velocity. Which security automation tool is MOST appropriate for identifying potential vulnerabilities in the source code BEFORE deployment?Security Engineering
  26. 176.A CISO is reviewing the organization's overall risk posture. They have identified several high-impact, low-probability risks, such as a major natural disaster affecting the primary data center. The CISO decides to purchase specialized insurance to cover potential financial losses from such an event. Which of the following risk management strategies is the CISO employing?Governance, Risk and Compliance
  27. 177.A multinational corporation is implementing a new global data governance policy. The policy mandates that all data classifications, retention periods, and access controls must be consistently applied across all subsidiaries, regardless of local regulations, unless local laws explicitly require a more stringent control. This approach aims to minimize legal and compliance risks globally. Which regulatory compliance strategy is this scenario best exemplifying?Governance, Risk and Compliance
  28. 178.A security auditor is reviewing the hardening configuration of a Linux server that hosts a critical web application. The auditor needs to verify that the server is configured to drop network packets that do not match any established connection and to block traffic from specific malicious IP addresses identified in threat intelligence feeds. Which command-line utility should the auditor focus on examining to confirm these firewall rules?Security Engineering
  29. 179.A security engineer is configuring a new Kubernetes cluster for a highly sensitive application. The organization's policy dictates that containers must run with the minimum necessary privileges, and specifically, they should not be able to gain root access, escalate privileges, or access sensitive host paths. Which Kubernetes security primitive should be primarily leveraged to enforce these runtime security constraints on pods?Security Engineering
  30. 180.A security team is implementing a new threat hunting program. They want to proactively search for advanced persistent threats (APTs) that may be evading existing security controls. Which of the following approaches would be MOST effective for identifying novel attack techniques and previously unknown indicators of compromise (IOCs) within their environment?Security Operations
  31. 181.A security architect is tasked with securing a critical government application that processes highly sensitive classified information. The design requires a multi-layered security approach, where data can only be accessed by users with the appropriate security clearance and 'need-to-know' for specific projects. The system must restrict access based on classification levels (e.g., Top Secret, Secret, Confidential) and compartments (e.g., Project A, Project B). Which access control model is best suited for implementing these stringent requirements?Security Architecture
  32. 182.A security analyst is investigating a potential data exfiltration incident. They have identified suspicious outbound network connections from an internal server to an unknown external IP address on TCP port 53. The DNS query logs for the internal server show legitimate-looking DNS queries, but the size of the responses is unusually large and consistent. What type of data exfiltration technique is this scenario most indicative of?Security Operations
  33. 183.A security architect is designing a system for a large e-commerce platform that must handle millions of transactions daily. The system needs to be highly resilient and able to tolerate failures of individual components or even entire data centers without significant impact on service availability or data loss. Which general design principle is MOST important to achieve this goal?Security Architecture
  34. 184.A security auditor is reviewing the hardening configuration of a Linux server that hosts a critical web application. The auditor discovers that the server's SSH service is configured to allow direct root login and uses password-based authentication. Which of the following recommendations would SIGNIFICANTLY improve the server's security posture against brute-force attacks and unauthorized access?Security Engineering
  35. 185.A financial services organization is adopting a Zero Trust architecture. The security team wants to ensure that every access request, regardless of origin (internal or external), is continuously evaluated against granular policies before granting access to resources. This evaluation must consider user identity, device posture, location, and the sensitivity of the requested resource. Which Zero Trust component is primarily responsible for making the real-time access decision?Security Architecture
  36. 186.A security auditor is reviewing the hardening configuration of a Kubernetes cluster used for sensitive production workloads. The auditor identifies that the cluster's default admission controller policies are too permissive, allowing containers to run with root privileges and mount host paths. To enforce a more secure baseline, the auditor recommends implementing a mechanism that intercepts and validates requests to the Kubernetes API server before objects are persisted, ensuring they comply with security best practices. Which Kubernetes security mechanism should be configured to achieve this enforcement?Security Engineering
  37. 187.A large enterprise is adopting a Zero Trust architecture. The security team is implementing a system that continuously evaluates the security posture of every device and user attempting to access corporate resources, regardless of their location. Which component of Zero Trust is primarily responsible for making real-time access decisions based on these evaluations?Security Architecture
  38. 188.A security architect is designing a data security strategy for a new cloud application that processes highly sensitive personal identifiable information (PII). The requirement is to ensure that even if the application's database is compromised, the PII remains unreadable and unusable to an attacker, while still allowing the application to perform searches and analytics on the data without full decryption. Which data security technique is BEST suited for this specific requirement?Security Architecture
  39. 189.A security architect is tasked with ensuring that a new e-commerce application complies with PCI DSS requirements. The application will handle credit card data directly. The architect wants to implement a control that minimizes the scope of PCI DSS applicability while still securely processing transactions. Which of the following controls would BEST achieve this objective?Governance, Risk and Compliance
  40. 190.A cryptographer is designing a long-term data archival system that must remain secure against future advances in quantum computing. The data has a retention period of 50 years. Which cryptographic primitive should be prioritized for key exchange to ensure post-quantum security?Security Engineering
  41. 191.A security architect is designing a data security solution for a B2B SaaS platform that handles highly sensitive customer data across multiple tenants. The platform must ensure that each tenant's data is cryptographically isolated from other tenants, even if the underlying storage infrastructure is shared. Which combination of key management and data encryption strategy would best achieve this tenant-level cryptographic isolation?Security Architecture
  42. 192.A security operations center (SOC) analyst observes a significant increase in network traffic originating from an internal server to various external IP addresses on non-standard ports. Further investigation reveals that the server is communicating with multiple seemingly unrelated domains and IP addresses in short, bursty intervals. The server's primary function is an internal database, and it should not be initiating external connections. Which of the following attack indicators is MOST likely being observed?Security Operations
  43. 193.A security operations center (SOC) analyst is investigating a suspected intrusion. They have identified a malicious executable file on a compromised workstation. To understand its full capabilities and indicators of compromise (IOCs) without risking further compromise to the production network, the analyst decides to execute the file in an isolated environment. Which of the following techniques is the analyst employing?Security Operations
  44. 194.A security operations center (SOC) receives an alert indicating 'High volume of outbound traffic to unusual ports from an internal web server.' Further investigation reveals that the server is attempting to connect to multiple external IP addresses on a wide range of non-standard ports. The web server should only be communicating on ports 80, 443, and 22 (for management). What is the MOST likely cause of this activity?Security Operations
  45. 195.A security architect is designing a new cloud-native application that will handle sensitive customer data. The application needs to ensure that data in transit between microservices within the same Virtual Private Cloud (VPC) is always encrypted and authenticated to prevent eavesdropping and tampering, even if the VPC's underlying network fabric is compromised. Which security mechanism is BEST suited to address this requirement?Security Architecture
  46. 196.A security architect is performing a risk assessment for a new critical system. The architect identifies a vulnerability that, if exploited, could lead to a complete system outage. The cost of a single outage is estimated at $1,000,000. However, the probability of this specific vulnerability being exploited is very low, estimated at once every 10 years. What is the Annualized Loss Expectancy (ALE) for this specific risk?Governance, Risk and Compliance
  47. 197.A security architect is designing a new payment gateway system that requires extremely high assurance of transaction integrity and non-repudiation. Each transaction must be cryptographically proven to have originated from a specific sender and not been altered in transit. Which cryptographic primitive is essential for meeting these requirements?Security Engineering
  48. 198.A security architect is evaluating a new cloud-native application that processes sensitive customer data across multiple regions. The application utilizes managed databases and storage services. The architect needs to ensure that all data at rest within these cloud services is encrypted using customer-managed encryption keys (CMEK) and that the key management infrastructure provides strong hardware-backed security. Which solution BEST addresses these requirements?Security Architecture
  49. 199.A security architect is designing a new cloud-native application that will process sensitive customer data. The application will be deployed across multiple regions globally. The architect needs to ensure that data in transit between microservices within the same cloud region is encrypted and authenticated without significant performance overhead. Which of the following architectural patterns would BEST address this requirement?Security Architecture
  50. 200.A security architect is designing a system for a highly sensitive research facility that processes classified information. The facility requires an access control model where subjects are assigned a security clearance, and objects (data, resources) are assigned a security classification. Access decisions are strictly based on comparing these labels, ensuring a 'need-to-know' and 'no write-down, no read-up' policy. Which access control model is MOST appropriate for this scenario?Security Architecture