Step2Study
IT & TechnologyCAS-005100% Free

CompTIA SecurityX (CAS-005)

Practice bank
316 Qs
Real exam
90 Qs
Time limit
165 min
Passing
Pass/fail only (no scaled score)

Exam blueprint

Governance, Risk and Compliance
20%
Security Architecture
27%
Security Engineering
31%
Security Operations
22%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 165 min · pass 80% · 316 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

CompTIA SecurityX (CAS-005) practice test questions

Sample questions from the 316-question bank, with answers and explanations.

All questions
  1. 1. A security architect is evaluating different architectural patterns for a new highly available and resilient system. The system must maintain continuous operation even if a single component fails. Which principle is most directly addressed by implementing redundant components and failover mechanisms?

    Security Architecture

    • A. Single Point of Failure (SPOF) Elimination
    • B. Defense in Depth
    • C. Separation of Duties
    • D. Least Privilege
    Show answer

    A. Single Point of Failure (SPOF) Elimination

    Implementing redundant components and failover mechanisms directly targets the elimination of Single Points of Failure (SPOFs) by ensuring that no single component's failure can bring down the entire system.

  2. 2. A security team is developing a threat hunting hypothesis: 'Adversaries are using legitimate administrative tools (LOLBins) to move laterally within our network, specifically targeting RDP sessions.' Which of the following data sources would be most critical to analyze to validate this hypothesis?

    Security Operations

    • A. Web application firewall (WAF) logs for SQL injection attempts.
    • B. Endpoint Detection and Response (EDR) telemetry for process execution and network connections.
    • C. DNS server logs for unusual domain lookups.
    • D. Cloud access security broker (CASB) logs for unauthorized cloud resource access.
    Show answer

    B. Endpoint Detection and Response (EDR) telemetry for process execution and network connections.

    The hypothesis focuses on 'legitimate administrative tools (LOLBins)' and 'lateral movement... targeting RDP sessions'. EDR telemetry provides granular visibility into process execution (to identify LOLBins), network connections (to see RDP traffic), and parent-child process relationships, making it ideal for detecting and analyzing lateral movement and LOLBin usage on endpoints.

  3. 3. An organization is designing a new critical infrastructure system that must operate continuously, even if major components fail or are compromised. The security architect is considering principles to ensure the system can withstand such events. Which design principle focuses on the system's ability to maintain operations despite failures or attacks, often through redundancy and isolation?

    Security Architecture

    • A. Resilience
    • B. Separation of Duties
    • C. Defense in Depth
    • D. Least Privilege
    Show answer

    A. Resilience

    Resilience in security design refers to a system's ability to continue operating, possibly in a degraded but functional state, when faced with failures, attacks, or unexpected conditions. This is often achieved through redundancy, fault tolerance, and isolation.

  4. 4. A large enterprise is migrating its on-premises data warehouse to a cloud-native platform. The data warehouse contains petabytes of sensitive customer transaction data, and the migration requires a phased approach. The security architect needs to design a solution that ensures data privacy and compliance with various regulations during the migration process, especially when data is transferred between the on-premises and cloud environments, and while it resides in temporary cloud storage before final integration. Which data security control is paramount for protecting this sensitive data during its journey and temporary residency in the cloud?

    Security Architecture

    • A. Configuring network segmentation within the cloud environment.
    • B. Utilizing Data Loss Prevention (DLP) solutions on egress points.
    • C. Implementing strong firewall rules at the cloud perimeter.
    • D. Applying end-to-end encryption for data in transit and at rest.
    Show answer

    D. Applying end-to-end encryption for data in transit and at rest.

    End-to-end encryption for data in transit and at rest is paramount for protecting sensitive data during migration to the cloud. This ensures that even if data is intercepted during transfer or accessed from temporary storage, it remains unreadable and protected, directly addressing privacy and compliance requirements.

  5. 5. A security analyst is investigating a suspected ransomware infection. They observe encrypted files with a new extension, a ransom note, and a high CPU usage on several endpoints. Further analysis indicates that the ransomware used a complex obfuscation technique to evade signature-based detection. To gain a deeper understanding of the ransomware's decryption mechanism and potentially develop a countermeasure, which advanced forensic technique would be most appropriate?

    Security Operations

    • A. Memory forensics to dump and analyze process memory
    • B. Reverse engineering the ransomware binary
    • C. Network packet capture and protocol analysis
    • D. Static malware analysis using string extraction
    Show answer

    B. Reverse engineering the ransomware binary

    To understand a ransomware's decryption mechanism, especially when obfuscation is used, reverse engineering the ransomware binary (D) is the most appropriate and often necessary technique. This involves dissecting the code to understand its logic, cryptographic routines, and key management, which can lead to developing decryption tools. While other options provide useful information, they won't reveal the decryption logic itself.

  6. 6. A large software company is adopting a 'shift-left' security approach and wants to integrate security testing into its Continuous Integration/Continuous Deployment (CI/CD) pipeline. The primary goal is to identify common security vulnerabilities and coding errors early in the development lifecycle, specifically within the source code itself, before compilation or deployment. Which security testing methodology is BEST suited for this purpose?

    Security Architecture

    • A. Software Composition Analysis (SCA).
    • B. Static Application Security Testing (SAST).
    • C. Dynamic Application Security Testing (DAST).
    • D. Interactive Application Security Testing (IAST).
    Show answer

    B. Static Application Security Testing (SAST).

    Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shifting left' by identifying vulnerabilities and coding errors early in the development process, directly from the code base before compilation or deployment.

  7. 7. A forensic investigator is analyzing a compromised Linux server. They have created a memory dump and identified several suspicious processes. To determine if any of these processes are attempting to hide their activities by unlinking their executable files, which of the following techniques should the investigator use?

    Security Operations

    • A. Analyze network connections associated with the processes using `netstat` output from the memory dump.
    • B. Extract the process environment variables to identify suspicious configurations.
    • C. Look for specific entries in `/var/log/auth.log` that indicate privilege escalation.
    • D. Examine the process's `cwd` (current working directory) and `exe` (executable path) symbolic links in `/proc/<PID>/` within the memory dump.
    Show answer

    D. Examine the process's `cwd` (current working directory) and `exe` (executable path) symbolic links in `/proc/<PID>/` within the memory dump.

    On Linux, when an executable is deleted (unlinked) while a process is still running, the `/proc/<PID>/exe` symbolic link will typically point to a 'deleted' file, and the original file path might not exist on disk. Examining these specific symbolic links and the `cwd` within a memory dump (using tools like Volatility) is the most direct way to detect unlinked executables.

  8. 8. A security architect is designing a highly available and resilient system for a critical financial application that processes millions of transactions daily. The system must tolerate the complete failure of an entire geographic region without data loss or significant service interruption. Which architectural pattern is most effective for achieving this objective?

    Security Architecture

    • A. Load balancing across multiple availability zones in a single region
    • B. Database sharding with eventual consistency
    • C. Active/Passive clustering within a single data center
    • D. Multi-region active/active deployment with synchronous data replication
    Show answer

    D. Multi-region active/active deployment with synchronous data replication

    A multi-region active/active deployment with synchronous data replication ensures that if one entire geographic region fails, another region can immediately take over with no data loss, meeting the requirements for high availability and resilience.

  9. 9. A security analyst is performing threat hunting activities within the organization's SIEM. They are specifically looking for signs of a 'living off the land' attack, where attackers use legitimate system tools and processes for malicious purposes. Which of the following log analysis techniques would be most effective for detecting such an attack?

    Security Operations

    • A. Monitoring for unusual process execution patterns and deviations from baselines.
    • B. Detecting new user account creation and privilege escalation events.
    • C. Searching for known malicious file hashes in endpoint logs.
    • D. Analyzing network flow data for connections to known malicious IP addresses.
    Show answer

    A. Monitoring for unusual process execution patterns and deviations from baselines.

    Living off the land attacks leverage legitimate tools, meaning traditional signature-based detection (like malicious file hashes or known bad IPs) is less effective. Monitoring for unusual process execution patterns and deviations from established baselines is crucial for identifying when legitimate tools are being used in an illegitimate manner.

  10. 10. A large enterprise is migrating its legacy monolithic applications to a microservices architecture running on Kubernetes. The security team needs to implement a solution that ensures all inter-service communication within the cluster is mutually authenticated and encrypted, without requiring developers to embed cryptographic logic into each microservice. This solution should also provide fine-grained authorization policies based on service identity. Which component of a service mesh would BEST address these requirements?

    Security Engineering

    • A. API Gateway
    • B. Ingress Controller
    • C. Sidecar Proxy
    • D. Container Network Interface (CNI)
    Show answer

    C. Sidecar Proxy

    A sidecar proxy, a core component of a service mesh, intercepts all inbound and outbound network traffic for a microservice. It can transparently handle mutual TLS (mTLS) for encryption and authentication, and enforce fine-grained authorization policies based on service identity, without developers needing to modify application code.

  11. 11. A critical infrastructure organization is integrating a new Industrial Control System (ICS) into its operational technology (OT) network. To ensure the highest level of security and prevent unauthorized access or modification, all communications between the ICS components and the supervisory control systems must be integrity-protected and cryptographically authenticated. Given the real-time constraints and resource limitations of some ICS devices, which advanced cryptographic primitive would be MOST suitable for ensuring data integrity and authenticity without full encryption?

    Security Engineering

    • A. Hash-based Message Authentication Code (HMAC)
    • B. RSA Digital Signature Algorithm
    • C. Elliptic Curve Digital Signature Algorithm (ECDSA)
    • D. Advanced Encryption Standard (AES)
    Show answer

    A. Hash-based Message Authentication Code (HMAC)

    The requirement is for data integrity and authenticity without full encryption, especially considering real-time constraints and resource limitations. HMAC (Hash-based Message Authentication Code) provides both data integrity (detects accidental or intentional modification) and authenticity (verifies the sender's identity using a shared secret key) efficiently. AES is for encryption, and ECDSA/RSA are digital signature algorithms that provide non-repudiation in addition to integrity and authenticity but are computationally more expensive than HMAC and might be overkill for resource-constrained ICS devices if non-repudiation is not a strict requirement.

  12. 12. A security architect is tasked with implementing data security for a new application that processes credit card information. To achieve PCI DSS compliance, the architect needs to ensure that sensitive authentication data (SAD) is never stored after authorization, even if encrypted. Which data security control BEST addresses this specific requirement?

    Security Architecture

    • A. Tokenization
    • B. Data Minimization
    • C. Format-Preserving Encryption (FPE)
    • D. Data Masking
    Show answer

    A. Tokenization

    Tokenization replaces sensitive data (like primary account numbers or SAD) with a non-sensitive equivalent (a token) that has no exploitable meaning or value. For PCI DSS, specifically, SAD must not be stored after authorization, even if encrypted. Tokenization achieves this by ensuring the original SAD is never stored by the merchant system, only a non-sensitive token, and the actual SAD is held in a secure, compliant token vault.

  13. 13. A security analyst is investigating a suspected data breach involving sensitive customer information. The forensic investigation reveals that an attacker gained access through a vulnerable web application, escalated privileges, and then maintained persistence by injecting malicious code into a legitimate system process that restarts automatically. Which of the following MITRE ATT&CK tactics does this persistence method MOST directly align with?

    Security Operations

    • A. Initial Access
    • B. Persistence
    • C. Defense Evasion
    • D. Execution
    Show answer

    B. Persistence

    Injecting malicious code into a legitimate system process that restarts automatically is a classic method for maintaining persistence on a compromised system. This ensures the attacker retains access even after reboots or system resets, directly aligning with the 'Persistence' tactic in MITRE ATT&CK.

  14. 14. A financial institution is evaluating its enterprise-wide risk management program. The Chief Risk Officer (CRO) wants to move beyond simply identifying risks to understanding the potential financial impact of various cyber events and prioritizing mitigation efforts based on this impact. Which of the following approaches should the CRO implement to achieve this objective?

    Governance, Risk and Compliance

    • A. Quantitative Risk Assessment
    • B. Qualitative Risk Assessment
    • C. Compliance Checklist Review
    • D. Risk Register Maintenance
    Show answer

    A. Quantitative Risk Assessment

    A quantitative risk assessment focuses on assigning monetary values to assets, threats, and vulnerabilities to calculate the potential financial loss from a cyber event. This allows the CRO to prioritize mitigation based on actual financial impact, moving beyond subjective qualitative ratings.

  15. 15. A security architect is designing an information security program for a critical infrastructure organization. The organization needs a framework that provides a flexible, risk-based approach to cybersecurity, allowing for adaptation to evolving threats and technologies, while also enabling communication of cybersecurity risk to a wide range of stakeholders. Which framework is BEST suited for this requirement?

    Governance, Risk and Compliance

    • A. COBIT
    • B. NIST Cybersecurity Framework (CSF)
    • C. HIPAA
    • D. ISO/IEC 27001
    Show answer

    B. NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) is designed to be flexible, adaptable, and risk-based, making it suitable for critical infrastructure. It provides a common language for communicating cybersecurity risk among stakeholders at all levels, from technical teams to senior management, and is not prescriptive, allowing organizations to tailor it to their specific needs and evolving threat landscape.

  16. 16. A global healthcare provider is deploying a new patient management system across multiple countries. Due to varied and strict data privacy regulations (e.g., GDPR in Europe, HIPAA in the US, local laws in Asia), the architecture must ensure that patient data collected in a specific region remains stored and processed exclusively within that region's geographical boundaries. Which architectural principle directly addresses this requirement?

    Security Architecture

    • A. Data Redundancy
    • B. Data Minimization
    • C. Data Localization (Data Residency)
    • D. Data Obfuscation
    Show answer

    C. Data Localization (Data Residency)

    Data Localization, also known as Data Residency, is the architectural principle that mandates sensitive data to be stored and processed within specific geographical boundaries to comply with local laws and regulations. This directly addresses the requirement for patient data to remain within its region of origin.

  17. 17. A financial institution is designing a new payment processing system that must comply with strict regulatory requirements for data integrity and non-repudiation of transactions. Each transaction must be verifiably linked to the originating party and prove that it has not been altered since it was created. Which cryptographic technique is essential for meeting these requirements?

    Security Architecture

    • A. Symmetric encryption
    • B. Hashing with a salt
    • C. Digital Signatures
    • D. Homomorphic encryption
    Show answer

    C. Digital Signatures

    Digital signatures provide data integrity (proof of no alteration) and non-repudiation (verifiable link to the originator) by using asymmetric cryptography to sign a hash of the data with the sender's private key.

  18. 18. A software development team is adopting a 'shift-left' security approach for their CI/CD pipeline. They want to identify and remediate security vulnerabilities in their custom-developed code as early as possible, ideally before the code is even compiled or deployed. Which security testing tool is best suited for this objective?

    Security Architecture

    • A. Static Application Security Testing (SAST)
    • B. Interactive Application Security Testing (IAST)
    • C. Dynamic Application Security Testing (DAST)
    • D. Penetration Testing
    Show answer

    A. Static Application Security Testing (SAST)

    Static Application Security Testing (SAST) analyzes source code, bytecode, or binary code without executing the application. It is ideal for 'shift-left' as it can identify vulnerabilities early in the development lifecycle, even before the application is compiled or deployed, aligning with the goal of early detection.

  19. 19. A security engineer is hardening a Windows Server that hosts a critical enterprise application. The organization's security policy requires that all system-level processes and services run with the minimum necessary privileges to perform their functions. Which of the following Windows features or concepts is MOST relevant to implementing this principle of least privilege for services?

    Security Engineering

    • A. User Account Control (UAC)
    • B. Service Accounts and Managed Service Accounts (MSAs/gMSAs)
    • C. Windows Firewall with Advanced Security
    • D. Data Execution Prevention (DEP)
    Show answer

    B. Service Accounts and Managed Service Accounts (MSAs/gMSAs)

    Service Accounts and especially Managed Service Accounts (MSAs) or group Managed Service Accounts (gMSAs) in Windows are specifically designed to allow services to run under dedicated, low-privilege identities. MSAs/gMSAs automate password management and simplify service principal name (SPN) management, ensuring that services operate with only the permissions required, thereby adhering to the principle of least privilege. This directly addresses the requirement for system-level processes and services to run with minimum necessary privileges.

  20. 20. A large e-commerce company is implementing a new AI-powered recommendation engine. During the development and testing phases, the data science team discovers that the engine consistently recommends higher-priced items to users in certain postal codes, regardless of their stated preferences or browsing history, potentially leading to unfair pricing for specific demographic groups. Which ethical concern related to AI is MOST directly highlighted by this discovery?

    Governance, Risk and Compliance

    • A. AI Accountability
    • B. AI Transparency
    • C. AI Privacy
    • D. AI Fairness
    Show answer

    D. AI Fairness

    The scenario describes an AI system exhibiting algorithmic bias, where certain demographic groups (inferred by postal codes) receive different, potentially disadvantageous, treatment (higher-priced recommendations). This directly relates to AI Fairness, which aims to ensure AI systems provide equitable outcomes and do not discriminate or perpetuate bias.

  21. 21. A security architect is designing a system for a highly sensitive research facility that processes classified data. The system must enforce strict isolation between different security domains, even at the hardware level, to prevent any data leakage or unauthorized access. Which specialized system architecture is MOST appropriate for achieving this level of isolation?

    Security Engineering

    • A. Hardware-enforced separation (e.g., Multiple Independent Levels of Security/MILS)
    • B. Virtualization with a Type 2 hypervisor
    • C. Cloud-based multi-tenancy with strong access controls
    • D. Containerization (e.g., Docker, Kubernetes)
    Show answer

    A. Hardware-enforced separation (e.g., Multiple Independent Levels of Security/MILS)

    Hardware-enforced separation, such as MILS (Multiple Independent Levels of Security), provides the highest degree of isolation by physically or logically segregating components at the silicon level, ensuring distinct security domains cannot interfere with each other. This is crucial for classified environments where even hypervisor-level vulnerabilities are unacceptable.

  22. 22. A global organization is implementing a new customer relationship management (CRM) system that will store personally identifiable information (PII) for customers across various jurisdictions, each with different data residency and privacy regulations. The security architect needs to design a data architecture that ensures compliance while optimizing performance. Which approach is MOST suitable for addressing these complex requirements?

    Security Architecture

    • A. Centralizing all PII data in a single, highly secured data center in a neutral country.
    • B. Utilizing a globally distributed database with strong encryption, irrespective of data origin.
    • C. Anonymizing all PII data before storage and only de-anonymizing for specific authorized processes.
    • D. Implementing data localization by storing PII within the geographical boundaries of its origin.
    Show answer

    D. Implementing data localization by storing PII within the geographical boundaries of its origin.

    Data localization, or data residency, is the practice of storing data within the geographical borders of its origin. This directly addresses legal and regulatory requirements for data residency and privacy, which vary significantly across jurisdictions, ensuring compliance for PII in a global organization, even if it might add complexity to performance optimization.

  23. 23. A global enterprise is implementing a Zero Trust architecture across its highly distributed network, which includes on-premises data centers, multiple cloud providers, and remote worker endpoints. A key challenge is establishing and verifying the identity of users and devices, and continuously evaluating their trustworthiness before granting access to resources. Which IAM protocol or framework is BEST suited to facilitate this continuous verification and dynamic policy enforcement across such a diverse and distributed environment?

    Security Engineering

    • A. Lightweight Directory Access Protocol (LDAP)
    • B. OAuth 2.0 / OpenID Connect (OIDC)
    • C. Security Assertion Markup Language (SAML)
    • D. Kerberos
    Show answer

    B. OAuth 2.0 / OpenID Connect (OIDC)

    OAuth 2.0, primarily for authorization, combined with OpenID Connect (OIDC), for authentication, provides a flexible and extensible framework for identity and access management across diverse environments. Its token-based approach and ability to integrate with various identity providers make it ideal for continuous verification and dynamic policy enforcement in a Zero Trust model, especially with distributed cloud and remote access.

  24. 24. A global e-commerce company is migrating its entire infrastructure to a multi-cloud environment. The security team needs to establish a unified security posture, enforce consistent policies, and gain centralized visibility across AWS, Azure, and Google Cloud Platform while maintaining compliance with regional data residency laws. Which integrated security approach is best suited for this complex scenario?

    Security Architecture

    • A. Implementing native security services independently on each cloud platform.
    • B. Utilizing a Security Information and Event Management (SIEM) system with cloud connectors.
    • C. Deploying a Cloud Security Posture Management (CSPM) solution with multi-cloud support.
    • D. Establishing a site-to-site VPN between each cloud provider and an on-premises security appliance.
    Show answer

    C. Deploying a Cloud Security Posture Management (CSPM) solution with multi-cloud support.

    A CSPM solution with multi-cloud support is specifically designed to address the challenges of consistent policy enforcement, compliance, and visibility across multiple cloud providers. It automates the identification of misconfigurations and security risks, ensuring a unified security posture, which native services or SIEMs alone cannot fully achieve for policy enforcement across heterogeneous environments.

  25. 25. A security architect is designing a new cloud-based application and needs to ensure that sensitive data handled by the application is protected both in transit and at rest. The application will interact with several microservices and store data in a NoSQL database. Which combination of cryptographic controls should the architect prioritize to meet these requirements?

    Security Operations

    • A. HTTPS for data in transit and hardware security modules (HSMs) for key management.
    • B. TLS for data in transit and client-side encryption with strong access controls for data at rest.
    • C. VPN for data in transit and full disk encryption for data at rest.
    • D. SSH for data in transit and symmetric encryption for data at rest.
    Show answer

    B. TLS for data in transit and client-side encryption with strong access controls for data at rest.

    TLS (Transport Layer Security) is the standard for securing data in transit over networks, commonly used by microservices. Client-side encryption ensures that data is encrypted before it leaves the application and is stored in the NoSQL database, offering stronger protection than database-managed encryption, especially when combined with strong access controls.

CompTIA SecurityX (CAS-005) flashcards

Tap a card to flip it. 156 flashcards in the full deck.

  • Single Point of Failure (SPOF) Elimination

    Flip card

    An architectural principle focused on identifying and mitigating any single component or logical path whose failure would cause the entire system or service to become unavailable.

    • Achieved through redundancy, clustering, and failover.
    • Crucial for high availability and business continuity.
    • Applies to hardware, software, network paths, and data.
    Study this card →
  • EDR for Lateral Movement

    Flip card

    Endpoint Detection and Response (EDR) solutions collect and analyze endpoint data (process execution, network connections, file system changes) to detect, investigate, and respond to threats like lateral movement and LOLBin abuse.

    • Provides granular endpoint visibility.
    • Detects anomalous process behavior.
    • Tracks network connections originating from endpoints.
    Study this card →
  • Resilient Architecture

    Flip card

    A resilient architecture is designed to withstand and recover from various failures, attacks, or unexpected conditions, maintaining its core functionality and operations even when components are compromised or unavailable.

    • Focuses on continuous operation despite disruptions.
    • Achieved through redundancy, fault tolerance, isolation, graceful degradation.
    • Adapts to changing conditions and recovers quickly.
    Study this card →
  • End-to-End Data Encryption

    Flip card

    The practice of encrypting data at its origin and decrypting it only at its final destination, ensuring it remains protected throughout its entire lifecycle, including in transit and at rest.

    • Protects data confidentiality from source to destination.
    • Crucial for sensitive data, especially during cloud migrations.
    • Combines encryption for data in transit (e.g., TLS) and at rest (e.g., disk encryption).
    Study this card →
  • Binary Reverse Engineering (Malware)

    Flip card

    The process of deconstructing executable software (binaries) to understand its inner workings, algorithms, and logic, without access to the source code. It's essential for analyzing complex malware, especially when obfuscation is present, to develop countermeasures or identify vulnerabilities.

    • Analyzes compiled code (binary).
    • Reveals algorithms and logic (e.g., decryption).
    • Bypasses obfuscation techniques.
    Study this card →
  • Static Application Security Testing (SAST)

    Flip card

    Static Application Security Testing (SAST) is a white-box testing method that analyzes an application's source code, bytecode, or binary code without actually executing the application, to identify security vulnerabilities and coding errors.

    • Performed early in the SDLC ('shift-left').
    • Identifies vulnerabilities in custom code.
    • Does not require a running application.
    Study this card →
  • Linux Process Forensics (/proc)

    Flip card

    The `/proc` filesystem in Linux is a virtual filesystem that provides an interface to kernel data structures, allowing forensic investigators to examine running processes, their memory maps, open files, and other runtime information.

    • Each process has a directory `/proc/<PID>/`.
    • Contains `exe` (executable path), `cwd` (current working directory), `maps` (memory maps).
    • Crucial for analyzing live system state and memory dumps.
    Study this card →
  • Geographic Redundancy

    Flip card

    The practice of having duplicate critical systems and data in geographically separate locations to ensure continuous operation and data availability in the event of a regional disaster.

    • Protects against large-scale outages (e.g., natural disasters).
    • Often involves active/active or active/passive deployments across regions.
    • Requires robust data replication strategies (synchronous for zero data loss).
    Study this card →
  • Living Off The Land (LotL)

    Flip card

    An attack technique where adversaries use legitimate, pre-installed tools and features already present on a compromised system (e.g., PowerShell, WMI, PsExec) to carry out malicious activities, making detection difficult.

    • Uses legitimate system binaries and scripts.
    • Avoids introducing new malware.
    • Difficult to detect with signature-based methods.
    Study this card →
  • Sidecar Proxy (Service Mesh)

    Flip card

    A lightweight proxy deployed alongside each application container (microservice) in a Kubernetes pod. It intercepts all network traffic to and from the microservice, offloading network and security functions from the application logic.

    • Enables transparent mutual TLS (mTLS) between services.
    • Enforces traffic policies and authorization.
    • Removes security and network concerns from application code.
    Study this card →
  • HMAC

    Flip card

    HMAC (Hash-based Message Authentication Code) is a specific type of Message Authentication Code (MAC) involving a cryptographic hash function and a secret cryptographic key. It is used to simultaneously verify both the data integrity and the authenticity of a message.

    • Provides both data integrity and authenticity.
    • Uses a shared secret key.
    • More efficient than digital signatures for integrity/authenticity.
    Study this card →
  • Tokenization for PCI DSS SAD

    Flip card

    Tokenization is a data security technique where sensitive data (like credit card numbers or Sensitive Authentication Data - SAD) is replaced with a unique, non-sensitive identifier called a token. For PCI DSS, this ensures SAD is never stored by the merchant after authorization, as only the token is retained.

    • Replaces sensitive data with a non-sensitive token.
    • Original data stored in a secure token vault (or discarded for SAD).
    • Crucial for PCI DSS compliance, especially for SAD.
    Study this card →
  • MITRE ATT&CK Persistence

    Flip card

    The MITRE ATT&CK 'Persistence' tactic describes techniques adversaries use to maintain their foothold in a system across reboots, changes in credentials, or other interruptions.

    • Ensures continued access to a compromised system.
    • Often involves modifying system startup mechanisms, creating new user accounts, or injecting code.
    • Crucial for long-term operations by an attacker.
    Study this card →
  • Quantitative Risk Assessment

    Flip card

    An objective, data-driven approach to risk assessment that assigns monetary values to assets, threats, vulnerabilities, and the potential losses from security incidents.

    • Uses formulas like ALE = SLE x ARO to calculate financial risk.
    • Provides a clear financial justification for security investments.
    • Requires detailed data on asset values, incident frequency, and recovery costs.
    Study this card →
  • NIST Cybersecurity Framework (CSF)

    Flip card

    A voluntary framework for organizations to manage and reduce cybersecurity risk.

    • Composed of five core functions: Identify, Protect, Detect, Respond, Recover.
    • Designed to be flexible and adaptable to various sectors and organizational types.
    • Enables communication of cybersecurity risk across an organization.
    Study this card →
  • Data Localization (Data Residency)

    Flip card

    The requirement that certain data must be stored and processed within the geographical borders of a specific country or region, often due to legal or regulatory mandates.

    • Ensures compliance with national data protection laws.
    • Impacts cloud deployment strategies and data transfer mechanisms.
    • Requires careful planning for global applications and services.
    Study this card →
  • Digital Signatures

    Flip card

    A cryptographic technique used to verify the authenticity and integrity of digital messages or documents, providing assurance of the sender's identity (non-repudiation) and proof that the data has not been altered in transit.

    • Uses asymmetric cryptography (private key to sign, public key to verify).
    • Provides data integrity and non-repudiation.
    • Often involves hashing the message before signing.
    Study this card →
  • Managed Service Accounts (MSAs/gMSAs)

    Flip card

    Managed Service Accounts (MSAs) and group Managed Service Accounts (gMSAs) are special types of domain accounts in Active Directory designed to provide automatic password management, simplified SPN management, and delegation of management to other administrators, for services and scheduled tasks.

    • Automate password rotation for service accounts.
    • Provide principle of least privilege for services.
    • Eliminate need for manual password updates for services.
    Study this card →
  • AI Fairness

    Flip card

    The principle that AI systems should produce equitable outcomes and not discriminate against specific groups or perpetuate societal biases.

    • Involves identifying and mitigating algorithmic bias.
    • Crucial for ethical and trustworthy AI systems.
    • Ensures AI benefits all users equally.
    Study this card →
  • Hardware-Enforced Separation (MILS)

    Flip card

    A system architecture that uses hardware mechanisms to create provably isolated partitions, ensuring distinct security domains cannot interfere with each other.

    • Highest level of isolation.
    • Used for classified or safety-critical systems.
    • Prevents side-channel attacks and hypervisor escapes.
    Study this card →
  • OAuth 2.0 / OpenID Connect (OIDC)

    Flip card

    OAuth 2.0 is an authorization framework allowing third-party applications to obtain limited access to an HTTP service. OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, enabling clients to verify the identity of the end-user.

    • OAuth provides authorization, OIDC provides authentication.
    • Token-based (access tokens, ID tokens).
    • Widely used for federated identity and SSO in cloud/mobile.
    Study this card →
  • Cloud Security Posture Management (CSPM)

    Flip card

    A security solution that continuously monitors cloud environments for misconfigurations, compliance violations, and security risks, providing remediation guidance and enforcing security policies.

    • Automates identification of security misconfigurations across cloud resources.
    • Ensures continuous compliance with industry standards and regulations.
    • Provides centralized visibility and reporting for multi-cloud environments.
    Study this card →
  • Client-Side Encryption

    Flip card

    The process of encrypting data on the user's or application's device before it is transmitted to a cloud service or stored in a database, ensuring that the cloud provider never has access to unencrypted sensitive data.

    • User/application controls the encryption keys.
    • Protects data even if the cloud provider is compromised.
    • Can make search and indexing more complex.
    Study this card →
  • Security Service Edge (SSE)

    Flip card

    Security Service Edge (SSE) is a cloud-centric security model that converges security services including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Firewall-as-a-Service (FWaaS) into a unified, cloud-delivered platform.

    • Delivers security as a cloud service.
    • Provides consistent policy enforcement for users, devices, and applications.
    • Component of SASE (Secure Access Service Edge).
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.