CompTIA SecurityX CAS-005 Exam Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company wants to ensure that administrators must check out temporary, time-limited elevated credentials through a broker system before accessing critical infrastructure, rather than holding standing administrative rights indefinitely. Which IAM component is this?

Explanation

PAM specifically brokers and manages temporary, time-limited elevated credential checkout rather than standing privileges. SSO consolidates authentication across applications, federation extends identity across organizational boundaries, MFA adds a second authentication factor, and conditional access applies contextual policies rather than managing privileged credential lifecycle specifically.

Submit
Please wait...
About This Quiz
CompTIA SecurityX Cas-005 Exam Practice Test 1 - Quiz

This practice assessment focuses on the CompTIA SecurityX CAS-005 exam, evaluating your understanding of essential security concepts and skills. It covers key areas such as risk management, incident response, and network security. This resource is vital for anyone preparing for the certification, helping you gauge your readiness and identify areas... see morefor improvement. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A forensic examiner needs to extract data directly from a device's memory chip at the hardware level, using a standardized hardware debugging interface, because the device's software is too damaged or locked to allow normal data extraction. Which technique is this?

Explanation

JTAG is a standardized hardware debugging interface allowing direct extraction of data from a device's memory chip at the hardware level, used when normal software-based extraction is not possible. Code stylometry analyzes coding style for malware attribution, byte code analysis examines compiled intermediate code, sandboxing safely executes suspicious code in isolation, and timeline reconstruction sequences events chronologically rather than describing hardware-level extraction.

Submit

3. A threat intelligence team wants to structure indicator of compromise data in a standardized format and then automatically transmit that structured data to partner organizations' threat intelligence platforms. Which two standards do these two steps represent, respectively?

Explanation

STIX is the standardized format for structuring threat intelligence data, while TAXII is the protocol used to transmit that structured data between platforms. YARA and Snort are rule-based languages for identifying malware and network patterns respectively, and Sigma is a rule-based language for SIEM detection rules, none of which describe the data format or transmission protocol itself.

Submit

4. An application checks whether a file exists and is safe to process, but between that check and the moment it actually opens the file, an attacker replaces the file with a malicious one, and the application processes the malicious file without re-verifying it. Which vulnerability is this?

Explanation

TOCTOU is the specific vulnerability where a gap between checking a condition and acting on it allows an attacker to change state in between, exactly as described. A race condition is the broader category TOCTOU is a specific instance of, a confused deputy tricks a privileged program into misusing its authority, deserialization exploits unsafe object reconstruction, and directory service misconfiguration concerns misconfigured directory services rather than this timing gap.

Submit

5. A SOC is deciding which of two simultaneous alerts to investigate first. One involves a low-severity vulnerability on a non-critical test server, while the other involves the same vulnerability on the organization's primary customer database server. Which alert prioritization factor most directly explains why the second alert should be investigated first?

Explanation

The asset type and criticality factor accounts for the same vulnerability carrying far more organizational risk on a primary customer database than a non-critical test server. Data classification concerns data sensitivity specifically, residual risk concerns risk remaining after controls, impact alone doesn't fully explain prioritization without factoring in which asset is affected, and alert failure rate concerns whether alerts fire correctly rather than which asset matters more.

Submit

6. A SOC analyst reviewing SIEM alerts finds that a specific correlation rule has been flagging benign nightly backup jobs as potential data exfiltration for the past month, requiring analysts to manually dismiss the same alert every night. Which SIEM issue does this represent?

Explanation

A rule consistently flagging benign, legitimate activity as malicious is a false positive. Event duplication refers to the same event being logged multiple times, a non-reporting device has stopped sending logs, retention gap concerns log storage duration, and audit log reduction filters low-value log noise rather than describing an inaccurate correlation rule.

Submit

7. A payment processor replaces a customer's actual credit card number with a randomly generated, format-preserving substitute value in its database, keeping the real number stored only in a separate, highly secured vault, so that a breach of the main database would not expose real card numbers. Which technique is this?

Explanation

Tokenization replaces sensitive data with a non-sensitive substitute while keeping the real value in a separate secured vault. Hashing produces a one-way irreversible digest rather than a reversible vault-linked substitute, obfuscation makes data harder to interpret without this vault structure, data anonymization removes identifying characteristics permanently, and cryptographic erase destroys data by discarding its encryption key.

Submit

8. A security architect wants to ensure that even if a server's long-term private key is compromised in the future, past recorded and intercepted TLS sessions cannot be retroactively decrypted using that key. Which cryptographic property provides this protection?

Explanation

Forward secrecy ensures session keys are derived so a future compromise of the long-term private key cannot retroactively decrypt previously captured sessions. Key stretching strengthens weak passwords, envelope encryption wraps a data key with a key-encrypting key, homomorphic encryption allows computation on encrypted data, and secure multiparty computation lets parties jointly compute without revealing inputs, none of which protect past sessions from a future key compromise.

Submit

9. A SOC configures its SOAR platform so that when a phishing alert fires, the platform automatically executes a fully scripted, no-human-intervention sequence of enrichment and remediation steps for low-severity cases, while high-severity cases instead trigger a documented set of recommended steps that a human analyst manually works through. Which two SOAR concepts do these represent, respectively?

Explanation

A runbook is a fully automated, scripted sequence executed without human intervention, while a playbook documents recommended steps for a human analyst to follow manually. Workflow automation is the broader enabling capability, event-based triggers initiate either type of response, and infrastructure as code concerns provisioning infrastructure rather than incident handling procedures.

Submit

10. A utility company operates a centralized system that collects real-time telemetry from field sensors across a power grid and allows operators to remotely monitor and adjust equipment from a central control room. Which specific term describes this centralized supervisory system, as distinct from the broader category of industrial control systems it belongs to?

Explanation

SCADA specifically describes the centralized supervisory system collecting real-time telemetry and enabling centralized remote monitoring and control, a specific type of ICS. ICS is the broader umbrella category, OT is an even broader category covering all operational technology, HVAC refers specifically to climate control systems, and IoT refers to broadly networked smart devices rather than this specific centralized grid supervisory system.

Submit

11. A company wants a dedicated, tamper-resistant hardware device, separate from any single endpoint, capable of generating and storing cryptographic keys and performing cryptographic operations for multiple servers at high volume, such as for a certificate authority. Which technology fits this specific enterprise-scale need, as distinct from a chip embedded in a single laptop?

Explanation

An HSM is a dedicated, tamper-resistant hardware device separate from individual endpoints, built for high-volume enterprise cryptographic operations like a certificate authority. A TPM is embedded in a single endpoint, a vTPM is a virtualized software emulation, a secure enclave is an isolated execution environment within a single processor, and CPU security extensions provide processor-level features rather than standalone high-volume hardware.

Submit

12. A network team implements a mechanism that cryptographically signs DNS records so that resolvers can verify a response has not been tampered with in transit, specifically to prevent an attacker from injecting a forged DNS response. Which technology is this?

Explanation

DNSSEC cryptographically signs DNS records so resolvers can verify authenticity and detect tampering, directly preventing forged response injection. DNS sinkholing redirects malicious traffic, zone transfers replicate DNS data between servers, DNS poisoning is the attack this defends against, and DMARC concerns email authentication rather than DNS record integrity.

Submit

13. A security team wants a tool deployed on every endpoint that continuously monitors for suspicious behavior, retains detailed telemetry for investigation, and can isolate a compromised host from the network in response to a detected threat. Which technology is this?

Explanation

EDR continuously monitors endpoint behavior, retains detailed telemetry, and can actively respond, such as isolating a compromised host. HIDS primarily detects rather than actively responds, a host-based firewall filters traffic to and from the host, anti-malware focuses on known malicious signatures, and SELinux enforces mandatory access control policies on Linux rather than providing this broader detection-and-response capability.

Submit

14. A CISO is documenting a new vulnerability remediation process and wants to clearly define which team owns the decision to accept risk on an unpatched finding, which teams must be consulted before that decision, and which teams simply need to be kept informed afterward. Which governance tool is designed for exactly this kind of role clarification?

Explanation

A RACI matrix specifically documents who is Responsible, Accountable, Consulted, and Informed for a given process or decision, exactly matching the need to clarify decision ownership and consultation. COBIT and ITIL are broader governance frameworks, a CMDB inventories configuration items, and a GRC tool is a platform category rather than the specific role-clarification technique itself.

Submit

15. A zero trust architecture team wants to restrict lateral movement within a single flat data center network by creating fine-grained, workload-level security policies between individual servers, rather than just segmenting at the traditional subnet or VLAN level. Which concept is this?

Explanation

Microsegmentation creates fine-grained, workload-level policies restricting lateral movement between individual servers, well beyond traditional subnet or VLAN-level segmentation. Macrosegmentation is not the standard term here, always-on VPN concerns persistent encrypted remote connectivity, SASE is a broader converged framework, and deperimeterization concerns removing reliance on a fixed perimeter rather than fine-grained internal policy.

Submit

16. A company wants visibility and control over which cloud applications employees are using, including detecting unsanctioned SaaS tools, and wants to enforce data security policies as traffic flows to and from these cloud services. Which technology fits this need?

Explanation

A CASB sits between users and cloud services to provide visibility into cloud usage, including shadow IT detection, and enforces data security policies on that traffic. SASE is a broader converged framework, SD-WAN optimizes WAN connectivity, a container orchestration platform manages containerized workloads, and an API gateway manages API traffic rather than broad cloud application visibility.

Submit

17. A company wants an access control model where a user's ability to open a specific file depends dynamically on a combination of factors, including the user's department, the file's sensitivity label, the time of day, and the user's current device compliance status, evaluated together at the moment of access. Which access control model fits this need?

Explanation

Attribute-based access control evaluates a combination of dynamic attributes together at the moment of access. Role-based access control assigns permissions strictly by role, mandatory access control enforces fixed centralized labels without this dynamic multi-attribute evaluation, discretionary access control lets owners assign permissions directly, and rule-based access control applies static predefined rules rather than combining multiple contextual attributes dynamically.

Submit

18. A security architect designs a system so that even if an attacker bypasses the perimeter firewall, they would still need to defeat host-based intrusion detection, endpoint anti-malware, and strict internal segmentation before reaching sensitive data. Which security concept does this layered design represent?

Explanation

Defense-in-depth layers multiple independent controls so defeating any single one does not grant full access. Attack surface reduction minimizes exposed entry points rather than layering controls, hardening secures individual systems, legacy component isolation addresses outdated systems specifically, and control effectiveness measures existing control performance rather than describing the layered design.

Submit

19. A software vendor provides customers with a formal, itemized inventory of every open-source and third-party component included in their application, along with version numbers, so customers can independently assess supply chain risk. Complete the sentence: this artifact is called a ______.

Explanation

An SBoM is the formal, itemized inventory of every component in a piece of software, provided for independent supply chain risk assessment. SAST/DAST identify vulnerabilities through testing rather than inventorying components, and formal methods documentation concerns mathematical verification of correctness rather than component inventory.

Submit

20. An architecture team designing for growth decides to handle increased load by adding more server instances behind a load balancer rather than upgrading the CPU and memory of a single existing server. Which availability design consideration does this decision represent?

Explanation

Horizontal scaling adds more instances to distribute load, exactly as described. Vertical scaling instead increases resources of a single existing server, persistence concerns whether state is retained across sessions, geographical considerations concern physical resource location, and interoperability concerns compatibility between systems.

Submit

21. A company wants to place a component in front of its public-facing web applications specifically to inspect and filter HTTP/HTTPS traffic for attacks like SQL injection and cross-site scripting, distinct from a general network firewall. Which component is this?

Explanation

A web application firewall specifically inspects and filters HTTP/HTTPS traffic for application-layer attacks like SQL injection and XSS. An IPS operates more broadly across network traffic, NAC controls device network admission, a VPN provides encrypted tunneling, and a reverse proxy forwards requests without itself specializing in application-layer attack filtering.

Submit

22. A security architect reviewing an AI deployment identifies two distinct risks: one where an attacker could subtly corrupt the data used to train a future model version, and a separate one where an attacker could query the deployed model repeatedly to reconstruct approximations of the data it was originally trained on. Which two threats to the model are these, respectively?

Explanation

Corrupting data used for future training is training data poisoning, while reconstructing approximations of original training data through repeated queries is model inversion. Model theft copies the model itself, model denial of service exhausts availability, and insecure output handling fails to validate output before downstream use rather than describing either threat here.

Submit

23. An analyst wants one framework that maps the relationships between an adversary, their capability, their infrastructure, and the victim in a single intrusion, and a separate framework that instead categorizes design-time software threats into six named categories including spoofing and tampering. Which two frameworks are being described, respectively?

Explanation

The Diamond Model explicitly maps relationships between adversary, capability, infrastructure, and victim, while STRIDE categorizes software threats into six named categories including spoofing and tampering. The Cyber Kill Chain models sequential attack stages, MITRE ATT&CK catalogs real-world adversary techniques, and CAPEC catalogs common attack patterns rather than describing either the four-element intrusion model or the six-category threat taxonomy.

Submit

24. Match each privacy regulation to the jurisdiction or population it primarily protects.

Explanation

GDPR protects EU residents' data, CCPA protects California residents specifically, LGPD is Brazil's counterpart data protection law, and COPPA specifically protects children's online privacy in the US, each operating within a distinct jurisdictional or demographic scope.

Submit

25. A risk team calculates that a specific data breach scenario has an annualized loss expectancy of $340,000 based on historical incident frequency and average cost per incident, and uses this dollar figure to compare against other risks. Which risk assessment approach does this represent?

Explanation

Quantitative analysis expresses risk in concrete numerical terms, such as an annualized loss expectancy in dollars, allowing direct comparison across risks. Qualitative analysis instead uses relative categories like high/medium/low, risk appetite setting defines tolerable risk levels rather than calculating cost, and severity impact scoring and third-party risk management are different, narrower risk activities.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company wants to ensure that administrators must check out...
A forensic examiner needs to extract data directly from a device's...
A threat intelligence team wants to structure indicator of compromise...
An application checks whether a file exists and is safe to process,...
A SOC is deciding which of two simultaneous alerts to investigate...
A SOC analyst reviewing SIEM alerts finds that a specific correlation...
A payment processor replaces a customer's actual credit card number...
A security architect wants to ensure that even if a server's long-term...
A SOC configures its SOAR platform so that when a phishing alert...
A utility company operates a centralized system that collects...
A company wants a dedicated, tamper-resistant hardware device,...
A network team implements a mechanism that cryptographically signs DNS...
A security team wants a tool deployed on every endpoint that...
A CISO is documenting a new vulnerability remediation process and...
A zero trust architecture team wants to restrict lateral movement...
A company wants visibility and control over which cloud applications...
A company wants an access control model where a user's ability to open...
A security architect designs a system so that even if an attacker...
A software vendor provides customers with a formal, itemized inventory...
An architecture team designing for growth decides to handle increased...
A company wants to place a component in front of its public-facing web...
A security architect reviewing an AI deployment identifies two...
An analyst wants one framework that maps the relationships between an...
Match each privacy regulation to the jurisdiction or population it...
A risk team calculates that a specific data breach scenario has an...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!