CompTIA SecurityX (CAS-005) practice questions

316 free questions with answers and explanations.

Practice test
  1. 201.A security architect is designing a system for a highly sensitive research facility that processes classified information. The facility requires an access control model where subjects are assigned a security clearance, and objects (data, resources) are assigned a security classification. Access decisions are strictly based on comparing these labels, ensuring a 'need-to-know' and 'no write-down, no read-up' policy. Which access control model is MOST appropriate for this scenario?Security Architecture
  2. 202.A security architect is designing an identity and access management (IAM) solution for a large enterprise that uses multiple cloud providers and on-premises applications. The goal is to provide a single, unified identity for users across all services, minimizing administrative overhead and improving security posture. Which of the following IAM frameworks is BEST suited for this requirement?Security Engineering
  3. 203.A global e-commerce company is migrating its entire infrastructure to a multi-cloud environment. The security team is concerned about ensuring consistent security configurations, identifying misconfigurations, and detecting non-compliant resources across all cloud providers. They need a solution that can continuously monitor the cloud environments and provide automated remediation suggestions. Which security solution is best suited for this purpose?Security Architecture
  4. 204.A security engineer is tasked with hardening a critical Linux server that processes sensitive financial data. The organization's policy dictates that the server must only allow outbound connections to a specific set of whitelisted IP addresses and ports, and all other outbound traffic must be denied by default. Additionally, inbound connections should only be allowed for SSH (port 22) from a management subnet. Which Linux tool is the MOST appropriate for configuring these network filtering rules?Security Engineering
  5. 205.A security architect is designing a secure software supply chain for a critical aerospace system. The company needs to ensure that all software components (libraries, modules, binaries) used in the system originate from trusted sources, have not been tampered with, and can be verified at any point in their lifecycle. Which security mechanism is most effective for providing verifiable authenticity and integrity of these software components?Security Architecture
  6. 206.A security architect is designing a new payment processing system that must achieve extreme availability and fault tolerance, capable of withstanding the complete loss of an entire data center or even a geographical region without service interruption. Which architectural pattern is most critical for meeting this requirement?Security Architecture
  7. 207.A security architect is evaluating a new cloud-native application that processes sensitive financial transactions. The application's design heavily relies on serverless functions and managed databases. To meet compliance requirements, all data at rest and in transit must be encrypted, and cryptographic keys must be managed in a highly secure, auditable, and centralized manner. Which cloud service category is most appropriate for managing these cryptographic keys?Security Architecture
  8. 208.A critical infrastructure organization is implementing a new Industrial Control System (ICS) in a highly sensitive environment. Due to the severe consequences of a cyber-physical attack, the security team requires an absolute guarantee that no data can flow from the less trusted business network into the highly trusted ICS network, even in the event of a sophisticated compromise. Which specialized system BEST provides this unidirectional data flow enforcement?Security Engineering
  9. 209.A security architect is designing a data storage solution for a highly regulated financial institution. The data includes sensitive customer financial records that must be protected against unauthorized access, even by cloud administrators, and remain available under extreme circumstances. The institution has a strict compliance requirement to maintain full control over the encryption keys. Which combination of technologies would BEST meet these requirements?Security Architecture
  10. 210.A security architect is integrating a legacy on-premises application with a new cloud-native microservices platform. The legacy application uses its own proprietary user directory, while the microservices platform relies on a modern identity provider (IdP). To provide a seamless single sign-on (SSO) experience for users accessing both environments and to centralize identity management, without migrating the legacy user directory, which identity component should be implemented?Security Architecture
  11. 211.A security architect is designing a microservices-based application where individual services need to communicate securely and be resilient to failures. Each service should enforce fine-grained authorization policies based on runtime attributes, and communication between services must be mutually authenticated and encrypted. The solution should also provide traffic management capabilities like load balancing and circuit breaking. Which architectural pattern best addresses these requirements?Security Architecture
  12. 212.A security architect is designing an access control system for a highly sensitive research laboratory. The system must enforce access decisions based on the clearance level of the researcher, the classification level of the data, and the need-to-know principle, where access is only granted if the researcher's clearance dominates the data's classification and they have a specific, approved reason to access it. This model must be strictly enforced and cannot be overridden by data owners. Which access control model is being described?Security Architecture
  13. 213.A global e-commerce company is migrating its entire infrastructure to a multi-cloud environment. The security architect needs to ensure continuous visibility, threat detection, and automated remediation across all cloud accounts and services from different providers. This includes identifying misconfigurations, compliance violations, and suspicious activities. Which security solution is best suited to address these requirements comprehensively?Security Architecture
  14. 214.A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster originate from an approved, scanned registry and are cryptographically signed. Any attempt to deploy an unsigned or unapproved image must be automatically rejected. Which Kubernetes admission controller or feature is BEST suited to enforce this policy?Security Engineering
  15. 215.A security architect is designing a key management system for a global enterprise that processes vast amounts of cryptographic operations daily. The system must provide FIPS 140-2 Level 3 validated protection for cryptographic keys, ensure high performance for signing and encryption operations, and offer robust tamper-resistance. What type of device is BEST suited to meet these stringent requirements?Security Engineering
  16. 216.A large enterprise is migrating its legacy monolithic applications to a microservices architecture. The security team needs to implement fine-grained authorization policies that are dynamically evaluated at runtime, based on a variety of user, resource, and environmental attributes. These policies must be flexible enough to adapt to changing business logic without requiring code changes in each microservice. Which authorization model is BEST suited for this dynamic and attribute-rich environment?Security Engineering
  17. 217.A security architect is implementing a Privileged Access Management (PAM) solution. As part of this, the organization requires that administrative access to critical systems is granted only for the duration of a specific task and automatically revoked afterward. This approach aims to minimize the attack surface associated with standing privileges. Which access control principle is being implemented here?Security Engineering
  18. 218.A security architect is designing a system for a global enterprise that needs to process and store customer data in various regions, each with unique data residency and privacy regulations. The solution must ensure that data processed in one region strictly adheres to that region's regulations and is not transferred or stored elsewhere without explicit compliance. Which architectural principle is MOST critical to implement?Security Architecture
  19. 219.A security architect is integrating a new cloud-based analytics platform with an existing on-premises Human Resources (HR) system. The HR system uses a proprietary identity store, while the analytics platform requires SAML 2.0 for user authentication. The architect needs a solution that can translate authentication requests and assertions between these disparate identity providers and service providers without requiring direct integration between each system. Which architectural component would fulfill this role?Security Architecture
  20. 220.A critical infrastructure organization is implementing a new Industrial Control System (ICS) for its power grid. Due to the severe consequences of a cyber-attack, the organization requires an absolute guarantee that no data can flow from the less trusted business network into the highly sensitive ICS network. Which security control is MOST effective for enforcing this unidirectional data flow?Security Engineering
  21. 221.A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements and the need for high-assurance protection of cryptographic keys, the organization must ensure that all master encryption keys are generated, stored, and used within a tamper-resistant, FIPS 140-2 Level 3 compliant environment. Which specialized hardware device is MOST appropriate for meeting this requirement?Security Engineering
  22. 222.A security architect is developing a strategy for long-term data archival that must maintain confidentiality for several decades, even against adversaries with significant computational power. The architect is particularly concerned about the future threat of quantum computers compromising currently strong asymmetric encryption algorithms. Which key management strategy is MOST critical to implement to mitigate this specific long-term threat to the archived data?Security Engineering
  23. 223.A security architect is designing a new microservices platform that will host highly sensitive customer data. To minimize the blast radius in case of a compromise, each microservice instance must have its own unique encryption key for its persistent data, and these keys must be protected by a master key. Which cryptographic technique BEST describes this approach?Security Engineering
  24. 224.A security architect is evaluating a new cloud-native application that processes sensitive customer PII. The application is designed with a microservices architecture. The architect needs a solution to centrally manage and distribute cryptographic keys for data encryption at rest and in transit across various microservices and cloud services. Which service is best suited for this requirement?Security Architecture
  25. 225.A global software company is implementing a federated identity management system to allow employees to use their corporate credentials to access various third-party Software-as-a-Service (SaaS) applications. The system needs to support multiple identity providers and service providers, facilitate efficient user provisioning, and handle complex attribute mapping. Which protocol is MOST suitable for this complex enterprise-grade federation scenario?Security Engineering
  26. 226.A security architect is designing a new payment processing system that must achieve extreme fault tolerance and high availability. The system needs to continue operating without any data loss or service interruption, even if an entire regional data center becomes unavailable. Which strategy provides the highest level of resilience for this scenario?Security Architecture
  27. 227.A security architect is designing an identity and access management (IAM) solution for a multi-cloud environment. The solution needs to provide centralized authentication and authorization for applications deployed across different cloud providers and on-premises infrastructure. The primary goal is to ensure consistent identity governance and streamline user provisioning and deprovisioning. Which IAM concept is BEST represented by this design?Security Engineering
  28. 228.A security architect is designing an automated incident response playbook for a cloud environment. The goal is to rapidly detect and respond to security threats by integrating various security tools, orchestrating remediation actions, and automating repetitive tasks. The solution should be able to ingest alerts from SIEM, trigger cloud functions, update firewall rules, and isolate compromised resources without human intervention. Which type of platform is BEST suited to achieve this comprehensive automation?Security Engineering
  29. 229.A security architect is designing a secure software supply chain for a critical aerospace system. The architect needs to ensure that software artifacts (e.g., binaries, libraries) originating from trusted developers are not tampered with during transit or storage before deployment. This requires a mechanism to verify the authenticity and integrity of each artifact. Which cryptographic control is best suited for this purpose?Security Architecture
  30. 230.A security architect is designing a new cloud-native application that will process highly sensitive financial transaction data. The application will be deployed across multiple regions globally. To ensure data confidentiality and integrity during transit between microservices within the application and external APIs, which cryptographic control should the architect prioritize for implementation?Security Architecture
  31. 231.A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory requirements and the need for maximum security for cryptographic keys, the architect must ensure that all master encryption keys are generated, stored, and used within a tamper-resistant and FIPS 140-2 Level 3 compliant hardware device. Which of the following technologies is BEST suited for this purpose?Security Engineering
  32. 232.A security architect is designing a secure software supply chain for an organization developing critical infrastructure software. It is paramount to ensure that all software components, including third-party libraries and internal modules, originate from trusted sources and have not been tampered with during transit or storage. Which cryptographic mechanism is BEST suited to verify the authenticity and integrity of these software components?Security Architecture
  33. 233.A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster must originate from an approved, scanned registry and be cryptographically signed by an authorized party. Which Kubernetes admission controller is BEST suited to enforce this policy?Security Engineering
  34. 234.A security architect is designing a new payment processing system that must achieve extremely high availability and fault tolerance. The system will operate across multiple geographically dispersed data centers. A key requirement is that if an entire data center becomes unavailable, the system must continue processing transactions with minimal interruption and no data loss. Which architectural principle is most critical for achieving this requirement?Security Architecture
  35. 235.A security engineer is tasked with hardening a Windows Server that hosts a critical enterprise application. The application uses several services that require access to network resources (e.g., file shares, databases) on other servers. Historically, these services ran under highly privileged domain accounts, posing a significant security risk. The engineer needs to implement a solution that allows these services to securely authenticate to network resources with their own unique, automatically managed identities, without requiring manual password management or granting excessive privileges. Which Windows Server feature is BEST suited for this scenario?Security Engineering
  36. 236.A security architect is designing a system for a large enterprise that uses a hybrid cloud environment. The enterprise needs a unified solution to continuously monitor and enforce security policies across its cloud infrastructure (IaaS, PaaS) and its on-premises virtualized environments. This solution must identify misconfigurations, compliance deviations, and provide remediation guidance. Which security tool or service is BEST suited for this comprehensive requirement?Security Architecture
  37. 237.A security engineer is tasked with implementing server hardening best practices across a fleet of Linux servers. As part of this process, the engineer needs to disable unnecessary services and close unused ports to minimize the attack surface. Which command-line utility is BEST suited for identifying currently open ports and the services listening on them?Security Engineering
  38. 238.A security architect is designing a new financial transaction processing system that requires near-zero downtime and must be able to withstand the failure of an entire data center. The system needs to ensure that all committed transactions are never lost, even in a disaster scenario. Which replication strategy should be implemented for the database component to meet these stringent requirements?Security Architecture
  39. 239.A security architect is implementing a Privileged Access Management (PAM) solution. As part of this initiative, the architect aims to minimize the window of opportunity for attackers to exploit privileged credentials. The solution should grant elevated permissions to users or services only when they are explicitly needed for a specific task and revoke them immediately after the task is completed or a predefined time limit expires. This security principle is known as:Security Engineering
  40. 240.A security architect is designing a new cloud-native application that will host customer data across multiple regions to ensure global availability and low latency. Due to strict data residency regulations in specific countries, certain customer data must be physically stored and processed only within the geographic boundaries of those countries. Which architectural principle must be applied to meet these regulatory requirements?Security Architecture
  41. 241.A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs under a dedicated service account, and the organization requires that this account's password be automatically managed by Active Directory, rotated regularly, and never directly known by administrators. This minimizes the risk of credential compromise. Which type of Active Directory account BEST satisfies these requirements?Security Engineering
  42. 242.A security architect is designing a new cloud-native application that will process highly sensitive customer data. The application uses microservices, and each microservice needs to encrypt data at rest before storing it in a database. Due to performance requirements and the need for frequent key rotation, the architect wants to avoid directly encrypting large data blocks with a master key. Instead, a unique, ephemeral key should be used for each data block, with the master key only used to protect these ephemeral keys. Which cryptographic technique BEST describes this approach?Security Engineering
  43. 243.A security architect is designing an authentication system for a highly distributed global workforce accessing various cloud and on-premises applications. The goal is to simplify user access, reduce administrative overhead, and enhance security by providing a single, consistent identity for each user across all services without directly exposing internal identity stores. Which security architecture component would BEST achieve this?Security Architecture
  44. 244.A security architect is designing a system for a global enterprise that needs to process and store customer data in various international regions. Due to strict data residency regulations in different countries, the system must ensure that data originating from a specific country remains physically within that country's borders. Which architectural pattern should the architect implement to meet this compliance requirement?Security Architecture
  45. 245.A security architect is designing a hybrid cloud environment for a large enterprise. The enterprise needs to ensure consistent security policy enforcement and visibility across both on-premises data centers and multiple public cloud providers. The solution must provide a unified view of security posture, automate compliance checks, and identify misconfigurations in real-time. Which type of security solution is best suited for this requirement?Security Architecture
  46. 246.A security architect is designing a new payment gateway system that requires extremely high availability and fault tolerance, even in the event of compromised or malicious nodes. The system must ensure that all transactions are processed correctly and consistently, even if a minority of nodes in the distributed network fail or behave maliciously. Which consensus mechanism is BEST suited for achieving this Byzantine fault tolerance?Security Engineering
  47. 247.A security architect is designing a long-term data archival system that must remain secure against future cryptographic breakthroughs, including the potential advent of practical quantum computers. The data needs to be recoverable and verifiable for several decades. Which advanced cryptographic concept should the architect prioritize to address this specific threat?Security Engineering
  48. 248.A critical infrastructure organization is implementing a new Industrial Control System (ICS) that requires extreme isolation from external networks due to the severe consequences of a breach. Data from the ICS network must be sent to a corporate reporting network for analysis, but no data or commands can ever flow back into the ICS network. Which security device is BEST suited to enforce this unidirectional data flow?Security Engineering
  49. 249.A large enterprise is migrating its legacy monolithic applications to a microservices architecture. The security team wants to implement granular access control policies based on user attributes, resource attributes, and environmental conditions (e.g., time of day, location, device posture). This approach should go beyond simple role-based access and provide dynamic authorization decisions at runtime. Which access control model is BEST suited for this advanced requirement?Security Engineering
  50. 250.A security architect is designing a system for a highly distributed global manufacturing company that has numerous remote sites, mobile users, and a mix of on-premises and cloud applications. The company wants to shift from a perimeter-based security model to one that assumes no implicit trust, regardless of location. Which security architecture best fits this description?Security Architecture