CompTIA SecurityX (CAS-005) practice questions
316 free questions with answers and explanations.
- 301.A security architect is designing a long-term data archival system that must remain secure against future advances in cryptanalysis, including the potential advent of quantum computers. The data being archived is highly sensitive and requires confidentiality for several decades. Which of the following cryptographic approaches should the architect prioritize for key exchange and encryption to meet this requirement?Security Engineering
- 302.A security architect is designing a new payment gateway system that requires extremely high assurance of transaction integrity and non-repudiation. Each transaction must be cryptographically bound to the sender in a way that is verifiable by any third party and cannot be later denied by the sender. Which cryptographic primitive is BEST suited to meet these specific requirements?Security Engineering
- 303.A security architect is tasked with ensuring that sensitive customer data stored in a cloud database remains encrypted even when the cloud provider's administrators might have access to the underlying infrastructure. The solution must allow the customer to retain full control over the encryption keys, preventing the cloud provider from decrypting the data without explicit customer action. Which encryption key management approach should the architect recommend?Security Architecture
- 304.A security architect is designing a new cloud-native application that will process highly sensitive customer data. The application uses microservices, and each microservice requires its own unique encryption key for data at rest. To minimize the risk of key compromise and ensure high availability, the architect decides to encrypt each microservice's data key with a unique key encryption key (KEK), which is then encrypted by a master key stored in a Hardware Security Module (HSM). This layered approach to encryption is known as:Security Engineering
- 305.A global healthcare provider is deploying a new patient management system across multiple countries. Due to strict regulatory requirements (e.g., GDPR, HIPAA, local data protection laws), patient data collected in one country must remain physically stored and processed within that country's borders. The security architect needs to design the data architecture to comply with these regulations. Which data security principle is paramount in this scenario?Security Architecture
- 306.A global organization is implementing a Zero Trust architecture across its highly distributed microservices environment. The security team needs to ensure that all service-to-service communication is mutually authenticated and encrypted, regardless of network location, without requiring application code changes for TLS setup. Which technology BEST facilitates this requirement?Security Engineering
- 307.A security architect is designing a key management system for a global enterprise that processes highly sensitive customer data. The system must ensure that cryptographic keys are generated, stored, and managed in a tamper-resistant environment, meeting stringent regulatory compliance requirements (e.g., FIPS 140-3 Level 3). Which specialized hardware component is BEST suited for this purpose?Security Engineering
- 308.A security architect is designing a secure communication channel between two globally distributed data centers. The primary requirements are strong encryption for data in transit, mutual authentication between the endpoints, and protection against replay attacks. The solution must operate at the network layer to encapsulate various higher-layer protocols. Which of the following protocols would be best suited for this scenario?Security Architecture
- 309.A financial institution is modernizing its legacy payment processing system. Due to stringent regulatory compliance requirements (e.g., PCI DSS) and the need for maximum security for cryptographic keys, the organization must ensure that all private keys used for transaction signing and encryption never leave a certified, tamper-resistant hardware environment. Furthermore, key generation and all cryptographic operations must occur within this environment. What specific technology is mandated for such a scenario?Security Engineering
- 310.A security architect is designing a new microservices platform that will host highly sensitive customer data. To protect data at rest, the architect wants to implement a multi-layered encryption strategy where data is encrypted with a unique data encryption key (DEK), and the DEK itself is encrypted with a key encryption key (KEK). The KEKs are then managed by a centralized key management system (KMS). This approach ensures that compromise of a single DEK does not expose large datasets and simplifies key rotation. What is this cryptographic practice called?Security Engineering
- 311.A security engineer is hardening a critical Linux server that hosts a proprietary application. The requirement is to restrict network access to the server based on specific IP addresses and port numbers, and to enforce stateful packet filtering for established connections. Which command-line utility is BEST suited for configuring these firewall rules?Security Engineering
- 312.A security architect is designing a secure communication channel between two geographically distant data centers that exchange critical business data. The solution must provide strong authentication, confidentiality, and integrity for all traffic, and operate at the network layer, transparently securing all applications running over the connection without requiring application-level modifications. Which protocol suite is best suited for this requirement?Security Architecture
- 313.A security architect is performing a threat modeling exercise for a new critical microservices-based application. The application processes highly sensitive financial transactions and interacts with several external third-party APIs. The architect needs to identify potential attack vectors and vulnerabilities specific to the inter-service communication within the microservices architecture, as well as interactions with external services. Which of the following threat modeling frameworks would be MOST suitable for systematically identifying these potential threats?Security Operations
- 314.A security operations center (SOC) analyst is investigating a series of alerts indicating potential brute-force attacks against the organization's web application login page. The alerts show multiple failed login attempts from various IP addresses within a short timeframe, targeting several different user accounts. To efficiently analyze these events and identify the scope and origin of the attack, which of the following log types would be MOST critical for the analyst to review FIRST?Security Operations
- 315.A security architect is designing a new secure communication channel for an organization's remote workforce. The primary requirements include ensuring data confidentiality, integrity, and authenticity, even over untrusted networks. The solution must also support various client operating systems and be relatively straightforward to implement without requiring extensive client-side software installations beyond standard OS capabilities. Which of the following protocols would be the MOST appropriate choice for this scenario?Security Operations
- 316.A security analyst is investigating a suspected insider threat. They discover that a privileged user account was used to access sensitive customer data outside of business hours from an unusual geographic location. The organization's security policy states that all access to sensitive data must be logged, and any anomalous access patterns should trigger an alert for immediate review. Which of the following best describes the primary security control that failed to prevent this incident?Security Operations