CompTIA SecurityX (CAS-005) practice questions
316 free questions with answers and explanations.
- 251.A security architect is designing a new cloud-native application that exposes several APIs for external partners. The application needs to validate incoming API requests for proper formatting, enforce rate limiting to prevent abuse, and block known malicious payloads and SQL injection attempts before requests reach the backend services. Which type of security control should be implemented in front of the API endpoints?Security Architecture
- 252.A security architect is designing a new cloud-native application that will handle sensitive customer data. To ensure the confidentiality and integrity of this data, the architect wants to enforce strict controls that grant access based on a combination of user attributes (e.g., department, role, security clearance), resource attributes (e.g., data sensitivity, classification), and environmental conditions (e.g., time of day, device posture). Which access control model best supports this dynamic and fine-grained approach?Security Architecture
- 253.A security architect is designing a secure communication channel between two geographically distant data centers that host critical business applications. The channel must provide strong encryption, data integrity, and authentication for all IP traffic exchanged between these networks. Which protocol suite is specifically designed to meet these requirements at the network layer?Security Architecture
- 254.A security engineer is hardening a Windows Server that hosts a critical enterprise application. The application runs as a service and requires specific permissions to access network resources and file shares on other machines within the domain, but without requiring a user password for the service account itself. The organization wants to centralize management of these service accounts and their associated Service Principal Names (SPNs) in Active Directory, reducing the risk of password sprawl and simplifying credential rotation. Which type of service account is BEST suited for this scenario?Security Engineering
- 255.A security architect is designing a system for a highly distributed global manufacturing company that has numerous remote sites, mobile users, and a mix of on-premises and cloud applications. The company wants to shift from a perimeter-based security model to one that assumes no implicit trust, regardless of location. Which security architecture best fits this description?Security Architecture
- 256.A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The organization mandates strict security policies for all pods, including restricting privileged containers, preventing hostPath volume mounts, and ensuring immutable file systems. These policies must be enforced at the cluster level before any pod is allowed to run. Which Kubernetes admission controller is BEST suited to enforce these types of pod-level security best practices?Security Engineering
- 257.A security architect is designing an identity and access management (IAM) solution for a multi-cloud environment where users need to access applications hosted across different cloud providers and on-premises systems. The solution must provide single sign-on (SSO) capabilities and allow for standardized attribute exchange to facilitate authorization decisions. Which federation standard is BEST suited for this scenario?Security Engineering
- 258.A global enterprise is implementing a Zero Trust architecture across its highly distributed cloud environment. As part of this initiative, the security team needs to ensure that all service-to-service communication within the microservices ecosystem is mutually authenticated and encrypted, regardless of network location. Which technology is BEST suited to achieve this goal efficiently and at scale?Security Engineering
- 259.A security architect is evaluating a new cloud-native application that exposes several APIs to external partners. The architect needs to protect these APIs from common web-based attacks such as SQL injection, cross-site scripting (XSS), and malicious bots, while also providing rate limiting and API security analytics. Which security control would be most effective for this purpose?Security Architecture
- 260.A global enterprise is implementing a Zero Trust architecture across its highly distributed cloud environment. A key component of this strategy is to ensure that all service-to-service communication is mutually authenticated and encrypted, regardless of network location. The security team decides to deploy a solution that injects a transparent proxy alongside each application instance, handling all network traffic and enforcing security policies. This approach is commonly known as a:Security Engineering
- 261.A global organization is implementing a Zero Trust architecture. As part of this initiative, all internal microservices communications must be mutually authenticated and encrypted, regardless of their network location. This requires an enforcement mechanism that operates at the application layer and can manage certificates for thousands of ephemeral service instances. Which technology BEST addresses this requirement?Security Engineering
- 262.A security architect is designing a new microservices-based application that will handle sensitive customer data. The architecture requires that each microservice can independently verify the identity and authorization of requests originating from other microservices, without relying on a central authentication service for every inter-service call. Which architectural pattern best addresses this requirement?Security Architecture
- 263.A critical infrastructure organization is implementing a new Industrial Control System (ICS) in a highly sensitive operational environment. The security architect needs to ensure that data flows from the ICS network to the enterprise network are strictly unidirectional to prevent any potential back-channel attacks or unauthorized commands from reaching the control systems. Which of the following security devices is BEST suited to enforce this requirement?Security Engineering
- 264.A security architect is designing a data processing pipeline for a machine learning platform that handles highly sensitive medical research data. The platform needs to perform analytical computations on this encrypted data in the cloud without ever decrypting it, to maintain maximum confidentiality even from the cloud provider. Which advanced cryptographic technique is required to achieve this specific goal?Security Architecture
- 265.A security architect is designing an authentication system for a new enterprise application. The application will be accessed by both internal employees and external partners, each using different identity providers. The architect wants to enable single sign-on (SSO) across these diverse identity stores while maintaining a high level of security and interoperability. Which of the following identity federation standards is BEST suited for this requirement?Security Engineering
- 266.A global organization is implementing a Zero Trust architecture. As part of this initiative, all communication between internal microservices, regardless of their network location, must be mutually authenticated and encrypted. The security team wants to achieve this without requiring developers to embed complex TLS logic into each microservice's application code. Which solution BEST addresses this requirement?Security Engineering
- 267.A security architect is designing a long-term data archival system that must remain secure against future cryptographic breakthroughs, including the potential advent of practical quantum computers. The data needs to be recoverable and verifiable for several decades. Which advanced cryptographic concept should the architect prioritize to address this specific threat?Security Engineering
- 268.A security architect is designing an authentication system for a new enterprise application that will integrate with multiple third-party services. The primary requirement is to enable single sign-on (SSO) across these services while ensuring strong identity verification. Which federated identity standard is BEST suited for this scenario, offering robust security features and broad interoperability?Security Engineering
- 269.A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The auditor finds that while Pod Security Standards (PSS) are enforced, there is no mechanism to ensure that container images are scanned for vulnerabilities and signed before deployment. Which Kubernetes admission controller, when combined with an external policy engine, would be MOST effective in enforcing these additional security requirements?Security Engineering
- 270.A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster must come from approved, trusted registries and must not contain known vulnerabilities or unapproved software. Which Kubernetes admission controller should be configured to enforce these policies at the point of deployment?Security Engineering
- 271.A security architect is designing a system for a highly distributed global manufacturing company. The company wants to enforce security policies based on user attributes, device posture, and environmental factors, rather than just network location or static roles. The goal is to dynamically grant or deny access to resources, even for internal users. Which concept is being described?Security Architecture
- 272.A security architect is designing an identity and access management (IAM) solution for an enterprise that requires fine-grained authorization decisions based on dynamic attributes of the user, resource, and environment. For example, access to a document might depend on the user's department, the document's classification, and the time of day. Which access control model is BEST suited for this complex requirement?Security Engineering
- 273.A security auditor is reviewing the hardening configuration of a Kubernetes cluster. The organization requires that all container images deployed to the cluster must originate from trusted, scanned repositories and meet specific security baselines. The auditor needs to identify the Kubernetes admission controller that can enforce these policies by intercepting and validating pod creation requests before they are persisted in the cluster's etcd database. Which admission controller is MOST relevant to this requirement?Security Engineering
- 274.A security architect is designing a secure private cloud environment for a government agency. The agency requires strict isolation between different departmental workloads and highly granular control over network traffic within and between these isolated environments. Each department must have its own virtual network space that is logically separated from others, with the ability to define custom routing tables and IP address ranges without affecting other departments. Which cloud networking construct is most appropriate for this level of isolation and control?Security Architecture
- 275.A security architect is designing a new payment gateway system that requires extremely high assurance for transaction integrity and non-repudiation. Each transaction must be cryptographically proven to have originated from a specific participant and not been altered in transit. The solution must also scale to millions of transactions per day. Which cryptographic primitive is BEST suited to achieve both integrity and non-repudiation in this high-volume context?Security Engineering
- 276.An organization is deploying a new web application and must ensure all server-side components (operating system, web server, database) are configured securely according to industry best practices. This involves applying security patches, disabling unnecessary services, removing default accounts, and configuring secure access controls. This comprehensive process is known as:Security Engineering
- 277.A large enterprise is migrating its legacy monolithic applications to a microservices architecture. The security team wants to implement granular access control policies based on user attributes, resource attributes, and environmental conditions (e.g., time of day, location, device posture). This approach should go beyond simple role-based access and provide dynamic authorization decisions at runtime. Which access control model is BEST suited for this advanced requirement?Security Engineering
- 278.A critical infrastructure organization is implementing a new Industrial Control System (ICS) that requires extreme isolation from external networks due to the severe consequences of a breach. Data from the ICS network must be sent to a corporate reporting network for analysis, but no data or commands can ever flow back into the ICS network. Which security device is BEST suited to enforce this unidirectional data flow?Security Engineering
- 279.A security architect is designing a secure communication channel between two geographically distant data centers that host critical business applications. The channel must provide strong encryption, data integrity, and authentication for all IP traffic. Which protocol suite is BEST suited for this purpose?Security Architecture
- 280.A security architect is designing a system for a large enterprise that uses a hybrid cloud environment. The enterprise needs to ensure consistent security policy enforcement, centralized visibility, and automated remediation for misconfigurations across both on-premises infrastructure and multiple public cloud providers. Which solution category is BEST suited to address these challenges?Security Architecture
- 281.A security architect is designing a new cloud-native application that will process highly sensitive customer financial data. The application uses microservices, and each service needs to encrypt its data at rest before storing it in a database. To minimize the risk associated with key compromise and ensure compliance, a multi-layered encryption strategy is required, where data encryption keys (DEKs) are themselves encrypted. Which cryptographic technique BEST describes this approach?Security Engineering
- 282.A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, even against future advances in cryptanalysis. The data is highly sensitive and regulatory requirements mandate protection from quantum computer attacks. Which cryptographic approach should be prioritized?Security Engineering
- 283.A security architect is designing a system that processes highly sensitive personal health information (PHI). The system must be able to perform analytics and machine learning on this data without ever decrypting it, even during processing. This is necessary to comply with stringent privacy regulations. Which advanced cryptographic technique would enable this capability?Security Architecture
- 284.A security architect is developing a strategy for long-term data archival that must maintain confidentiality and integrity for several decades, anticipating advancements in quantum computing. The archived data is highly sensitive and cannot be re-encrypted periodically due to its sheer volume and regulatory constraints. Which advanced cryptographic concept should be integrated into the key management system to mitigate future quantum threats?Security Engineering
- 285.A security architect is designing a data processing pipeline for a machine learning platform handling highly confidential research data. The platform needs to perform computations on encrypted data without decrypting it, to maintain confidentiality throughout the entire processing lifecycle, even when data is 'in use'. Which advanced cryptographic technique is best suited for this requirement?Security Architecture
- 286.A security architect is implementing a Privileged Access Management (PAM) solution. As part of this, they want to ensure that administrative access to critical systems is granted only when explicitly requested and for a strictly limited duration, automatically revoking access once the task is complete or the time limit expires. This minimizes the window of opportunity for attackers to exploit standing privileges. Which PAM concept does this BEST describe?Security Engineering
- 287.A global financial institution is implementing a new payment processing system that requires extremely high assurance of transaction integrity and resistance to tampering, even in the presence of malicious nodes. The system must maintain consensus on transaction order and validity across a distributed network of participants, some of whom may be untrustworthy. Which of the following advanced consensus mechanisms would BEST meet these requirements?Security Engineering
- 288.A security architect is designing an identity and access management (IAM) solution for a multi-cloud environment. The solution needs to provide centralized authentication and authorization services for applications deployed across different cloud providers, allowing users to log in once and access multiple services without re-entering credentials. Which of the following protocols is BEST suited for this requirement?Security Engineering
- 289.A security architect is evaluating a new cloud-native application that exposes several APIs for internal and external consumption. The architect aims to protect these APIs from common web-based attacks such as SQL injection, XSS, and DDoS, while also providing API authentication, authorization, and rate limiting. The solution should be scalable and easily integrated into the CI/CD pipeline. Which security component is best suited for this purpose?Security Architecture
- 290.A security engineer is hardening a critical Linux server that hosts a proprietary application. To prevent unauthorized access and exfiltration, the engineer needs to limit the server's outbound network connections to only specific, approved IP addresses and ports required by the application. Which command-line utility is BEST suited for configuring these packet filtering rules directly on the Linux kernel?Security Engineering
- 291.A security architect is designing a new microservices-based application. The application will consist of numerous independent services communicating over a network. The architect needs to ensure that each service can cryptographically verify the identity of the other services it communicates with, and that all communication between them is encrypted, without relying on a central certificate authority for every service-to-service interaction. Which security mechanism is BEST suited for this requirement?Security Architecture
- 292.A security architect is designing a new system for a utility company that manages critical national infrastructure. The system must maintain continuous operation even if a data center goes completely offline due to a major natural disaster. Data loss tolerance is near zero, and recovery time must be minimal. Which architectural pattern is MOST appropriate for ensuring both high availability and disaster recovery for this scenario?Security Architecture
- 293.A security architect is reviewing a proposed architecture for a new e-commerce platform. The platform will handle millions of transactions daily and must be highly scalable and resilient. The architect is particularly concerned about protecting the database from direct external attacks while ensuring that application servers can access it securely. Which network segmentation strategy would be MOST effective for addressing this concern?Security Architecture
- 294.A security architect is designing a system for a large enterprise that uses a hybrid cloud environment. The enterprise needs to ensure consistent security policies, reduce the attack surface, and gain centralized visibility into the security posture of both their on-premises infrastructure and multiple public cloud accounts. Which integrated security approach would best address these requirements?Security Architecture
- 295.A global healthcare provider is deploying a new patient management system across multiple countries. Due to varying data privacy regulations (e.g., HIPAA, GDPR, local laws), the system must ensure that patient data collected in one country is only stored and processed within that country's borders, and never leaves without explicit, legal consent. Which architectural approach should the security architect prioritize?Security Architecture
- 296.A security architect is designing a new cloud-native application that will handle sensitive customer payment information. The application needs to ensure that all data at rest in the database is encrypted, and that the encryption keys are managed securely and rotated regularly. The organization wants to leverage cloud-native services for key management to reduce operational overhead while maintaining control over key access policies. Which cloud service should the architect integrate?Security Architecture
- 297.A security architect is designing an access control system for a highly sensitive research facility that processes classified government data. The system must enforce a strict 'need-to-know' principle, where access decisions are based on the classification level of the information and the clearance level of the user, regardless of their role or group membership. Which access control model is most appropriate for this scenario?Security Architecture
- 298.A security architect is designing a new cloud-native application that involves multiple microservices. The application needs to ensure that only authorized services can communicate with each other, and access policies should be dynamically enforced based on service identity and context, rather than static IP addresses. Which Zero Trust principle is MOST relevant to this requirement?Security Architecture
- 299.A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to production namespaces must originate from an approved, trusted registry and be cryptographically signed by the internal CI/CD pipeline. Which Kubernetes admission controller should the engineer configure to enforce this policy?Security Engineering
- 300.A critical infrastructure organization is integrating a new Industrial Control System (ICS) into its existing network. Due to the extreme sensitivity of the ICS and the potential for severe physical consequences from cyberattacks, the security team needs to ensure that data can flow ONLY from the ICS network to the enterprise network, with absolutely no possibility of data flowing back into the ICS network. Which specialized security device is BEST suited for this unidirectional data transfer requirement?Security Engineering