CompTIA SecurityX CAS-005 Exam Practice Test 2

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company troubleshooting IAM issues discovers that a service account used by an automated backup job has authentication tied to a specific approved geographic region, and login attempts from any other region are automatically blocked regardless of valid credentials. Which conditional access factor does this represent?

Explanation

Restricting authentication based on the geographic region the request originates from is the geographic location conditional access factor. User-to-device binding ties an identity to a specific approved device, time-based access restricts login to certain hours, configuration-based access considers device or system settings, and biometrics use physical characteristics for authentication rather than geographic origin.

Submit
Please wait...
About This Quiz
CompTIA SecurityX Cas-005 Exam Practice Test 2 - Quiz

This practice assessment focuses on the CompTIA SecurityX CAS-005 exam, evaluating essential cybersecurity concepts and skills. It covers topics like risk management, network security, and incident response, making it a valuable resource for those preparing for the certification. By engaging with this material, learners can enhance their understanding and readiness... see morefor the exam. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A security team configures an endpoint so that only a pre-approved, explicitly defined list of applications is permitted to execute, and anything not on that list is blocked by default, even if it appears benign. Which mitigation technique is this?

Explanation

Allow listing permits only pre-approved applications to execute and blocks everything else by default. Defense-in-depth layers multiple independent controls rather than a single execution-control list, least privilege limits granted permissions to the minimum needed, input validation checks incoming data for correctness, and output encoding prevents injection by encoding outgoing data rather than controlling which applications may run.

Submit

3. During incident response, an analyst examines the embedded metadata within a suspicious image file, including GPS coordinates and the device model used to capture it, to help establish where and how the image originated. Which analysis category is this?

Explanation

Examining embedded metadata within a file, such as GPS coordinates and device model in an image, is metadata analysis. Malware analysis examines malicious code behavior, hardware analysis examines physical device components, network analysis examines traffic patterns, and volatile storage analysis examines data in memory rather than embedded file metadata.

Submit

4. A threat hunting team deploys a decoy network segment populated with fake credentials and fabricated file shares specifically to detect and study attacker behavior if an intruder interacts with it, without any legitimate business traffic ever touching it. Which internal intelligence source is this?

Explanation

A honeynet is a decoy network segment populated with fabricated assets specifically to detect and study attacker behavior. Adversary emulation engagements actively simulate real attacker techniques against production systems, hypothesis-based searches proactively test specific theories about compromise, user behavior analytics baseline normal behavior to flag anomalies, and internal reconnaissance gathers information about the organization's own environment rather than deploying a decoy segment.

Submit

5. A code review identifies a function that trusts a filename provided entirely by user input to determine which internal privileged operation to perform, allowing an attacker to manipulate that input to trick the function into performing an operation it should never have authority to do. Complete the sentence: this vulnerability is called a ______.

Explanation

A confused deputy vulnerability occurs when a privileged program is tricked by untrusted input into misusing its own legitimate authority on the attacker's behalf. TOCTOU concerns a timing gap between checking and using a resource, and deserialization exploits unsafe object reconstruction, both distinct mechanisms.

Submit

6. A security team building a SIEM dashboard wants to visually correlate the number of failed login attempts across the organization with the number of successful logins from new geographic locations over the same time period, to spot potential credential compromise trends at a glance. Which reporting concept does this represent?

Explanation

Visually correlating multiple data trends together for quick at-a-glance insight is visualization, a reporting and metrics concept. Audit log reduction filters out low-value log noise, retention concerns how long data is stored, event parsing concerns how raw logs are broken down into structured fields, and non-reporting devices refers to sources that have stopped sending logs rather than describing this visual correlation dashboard.

Submit

7. A software vendor cryptographically signs each release of their application so that customers can verify the code has not been tampered with since it left the vendor's build pipeline before installing it. Which technique is this?

Explanation

Code signing cryptographically signs software releases so recipients can verify integrity and authenticity before installation. Tokenization substitutes sensitive data values, serialization converts data structures into a storable or transmittable format, a one-time pad is a theoretically unbreakable symmetric cipher using a single-use key, and lightweight cryptography is designed for resource-constrained devices rather than describing software release integrity verification specifically.

Submit

8. A cloud provider offers a cryptographic technique where a data encryption key is itself encrypted by a separate, higher-level key-encrypting key, allowing the data key to be safely stored alongside the encrypted data while the key-encrypting key remains protected separately, often in an HSM. Which technique is this?

Explanation

Envelope encryption wraps a data encryption key with a separate key-encrypting key, allowing the data key to be safely stored with the encrypted data while the key-encrypting key stays protected separately. Key stretching strengthens weak passwords, homomorphic encryption allows computation on encrypted data, forward secrecy protects past sessions from future key compromise, and secure multiparty computation allows joint computation without revealing individual inputs, none of which describe this layered key-wrapping structure.

Submit

9. A security team wants to write a Python script that automatically pulls the latest threat intelligence feed, checks it against internal firewall rules, and updates blocklists without manual intervention, triggered specifically whenever the feed publishes new data rather than running on a fixed schedule. Which automation concept does the triggering mechanism represent?

Explanation

Triggering automatically whenever new data is published, rather than on a fixed schedule, is an event-based trigger. Cron/scheduled tasks run at fixed time intervals regardless of new data, infrastructure as code provisions infrastructure through code, configuration files store settings in formats like YAML or JSON, and workflow automation generically describes the broader automated process rather than this specific event-driven activation mechanism.

Submit

10. A manufacturing company operating legacy industrial equipment finds that a specific control system cannot be patched at all because the vendor no longer exists and the system predates any formal security update mechanism. Which characteristic of specialized/legacy systems does this describe?

Explanation

A system that cannot be patched because the vendor no longer exists is specifically unsupported. Highly constrained refers to limited processing or memory resources, obsolete refers to outdated technology generally, unable to secure is a broader characteristic that unsupported status is one specific cause of, and regulatory refers to compliance-driven challenges rather than vendor discontinuation specifically.

Submit

11. A hardware security team implements a boot process that cryptographically verifies each stage of the boot sequence, from firmware through the bootloader to the operating system, halting the boot if any stage's signature does not match what is expected. Which technology is this?

Explanation

Secure Boot cryptographically verifies each boot stage and halts the process if a signature does not match, preventing unauthorized code from executing during startup. Measured boot instead records boot stage measurements for later attestation without necessarily halting the boot itself, self-healing hardware automatically recovers from faults, tamper detection identifies physical interference, and virtual hardware describes emulated hardware components rather than this signature-verification boot process.

Submit

12. A network team troubleshooting intermittent connectivity discovers that a router's routing table has drifted significantly from its documented baseline configuration over time due to undocumented manual changes by different engineers. Which network misconfiguration category does this represent?

Explanation

A configuration gradually diverging from its documented baseline due to undocumented manual changes over time is configuration drift. Routing errors refer to specific incorrect routing decisions, switching errors concern Layer 2 switching issues, insecure routing concerns routing protocols lacking proper security, and VPN/tunnel errors concern encrypted tunnel connectivity issues rather than this gradual baseline divergence.

Submit

13. Match each threat-actor TTP to its correct description.

Explanation

These five TTPs represent distinct techniques threat actors use across a compromised endpoint: injections insert malicious input, credential dumping extracts stored secrets, unauthorized execution runs code without permission, lateral movement spreads across the network, and defensive evasion specifically avoids detection.

Submit

14. A company documents formal, written expectations for password complexity requirements and network segmentation rules, going beyond high-level policy statements into specific, measurable requirements that must be met. Complete the sentence: this security program documentation type is called a ______.

Explanation

Standards define specific, measurable requirements, such as exact password complexity rules, distinct from high-level policy statements. Policies set broad intent, procedures document step-by-step execution, and guidelines offer recommended but non-mandatory practices.

Submit

15. A zero trust architecture requires that a user who was authenticated an hour ago be automatically re-verified before accessing a highly sensitive financial system, even though their session token is technically still valid, because their access context has changed. Which zero trust concept is this?

Explanation

Continuous authorization re-evaluates whether access should still be granted based on current context, even for an already-authenticated session, exactly as described. Deperimeterization concerns removing reliance on a fixed network boundary, microsegmentation restricts lateral movement between workloads, asset attestation verifies device identity and state, and API integration and validation concerns securing API-level interactions rather than this ongoing re-verification of an active session.

Submit

16. A company running short-lived, event-driven functions in the cloud that automatically scale to zero when not in use, without the company managing any underlying servers, is using which cloud capability?

Explanation

Serverless computing runs short-lived, event-driven functions that automatically scale to zero without the customer managing underlying servers. Containerization still involves managing container images and often underlying orchestration, infrastructure as code provisions infrastructure through code rather than describing the execution model itself, a CASB provides cloud visibility and policy enforcement, and package monitoring tracks software dependencies rather than describing this specific compute execution model.

Submit

17. A company implementing PKI wants a mechanism for clients to quickly check whether a specific certificate has been revoked without downloading an entire, potentially large revocation list. Separately, the company wants its certificates to carry additional metadata fields specifying permitted key usages and extended validation details. Which two PKI concepts do these represent, respectively?

Explanation

OCSP stapling allows a server to attach proof of current certificate validity to the TLS handshake, avoiding separate revocation list downloads, while certificate extensions add metadata fields specifying permitted key usages and validation details. CA/RA separation divides issuance and registration duties, certificate templates standardize issuance profiles, and deployment/integration approach concerns broader rollout strategy rather than these two specific certificate mechanics.

Submit

18. A security team wants to ensure that log entries flowing into their SIEM from firewalls, servers, and applications are all sent to a single centralized location, and that unusual spikes or gaps in that logging are automatically flagged. Which two detection and threat-hunting enablers does this combination represent?

Explanation

Sending all logs to a single location is centralized logging, while automatically flagging unusual spikes or gaps is continuous monitoring, together forming a core detection and threat-hunting enabler pairing. Sensor placement and alerting concern where monitoring points are physically or logically placed and how detected issues are surfaced, classification models and labeling concern data sensitivity tagging, vulnerability management and hardening concern reducing weaknesses, and DLP concerns preventing data loss rather than describing centralized log aggregation and anomaly flagging.

Submit

19. A CI/CD pipeline is configured so that any attempt to merge code directly into the main branch without going through a required peer review and passing automated tests is automatically blocked. Which practice is this?

Explanation

Blocking direct merges to a protected branch without required review and passing tests is branch protection. Canary testing gradually rolls out changes to a small subset of users, regression testing checks that changes don't break existing functionality, coding standards and linting enforce style consistency, and continuous improvement is a broader ongoing practice rather than this specific merge-gating mechanism.

Submit

20. A development team integrates a testing approach into their pipeline that analyzes a running web application by actually sending it crafted requests and observing its responses, identifying vulnerabilities like SQL injection without access to the underlying source code. Which software assurance technique is this?

Explanation

DAST tests a running application from the outside by sending crafted requests and observing responses, without needing source code access. SAST analyzes source code directly without running the application, IAST combines static and dynamic analysis during runtime with instrumentation, RASP protects an application at runtime rather than testing it during development, and formal methods use mathematical proofs to verify correctness rather than sending test requests.

Submit

21. A network architect places a device inline between users and the internet specifically to forward client requests to external destinations on their behalf, hiding the internal client's identity and allowing centralized content filtering and caching. Which component is this?

Explanation

A forward proxy sits between internal clients and external destinations, forwarding requests on the client's behalf while hiding their identity and enabling centralized filtering and caching. A reverse proxy instead sits in front of servers to protect them from external clients, an API gateway manages API traffic specifically, a CDN caches and distributes content geographically, and a tap passively captures traffic for monitoring rather than actively forwarding client requests.

Submit

22. A company deploying an AI-powered digital assistant discovers that the assistant, when given access to internal email and calendar systems, was able to autonomously forward a confidential document to an external party based on a poorly worded internal request, far beyond what the assistant's intended function required. Which AI usage risk does this represent?

Explanation

An AI system taking autonomous action far beyond its intended function, such as forwarding a confidential document, is excessive agency. Overreliance describes humans trusting AI output too much rather than the AI acting beyond its scope, sensitive information disclosure to the model concerns data being fed into the model rather than autonomous action taken by it, model denial of service targets availability, and insecure plug-in design concerns architectural flaws in an integrated plug-in rather than over-permissioned autonomous capability.

Submit

23. A threat modeling team profiles a specific adversary group and determines that their primary motivation is stealing intellectual property to benefit a foreign government's economic interests, rather than for direct financial gain or public notoriety. Which actor characteristic does this motivation represent?

Explanation

Stealing intellectual property to benefit a foreign government's interests is espionage, a distinct motivation from direct financial gain. Financial motivation seeks direct monetary benefit, geopolitical motivation concerns broader state-level political objectives, activism concerns ideological causes, and notoriety concerns seeking recognition or fame rather than covert intelligence gathering for a foreign government.

Submit

24. A hospital system implementing a new patient portal must specifically account for regulatory requirements unique to the healthcare sector, distinct from the requirements a retail company or a utility company would face. Which compliance awareness category does this represent?

Explanation

Accounting for requirements unique to a specific sector like healthcare is awareness of industry-specific compliance. Industry standards and security/reporting frameworks apply more broadly across sectors, privacy regulations generically cover personal data protection rather than sector-specific rules, and cross-jurisdictional compliance concerns operating across multiple legal jurisdictions rather than sector-specific requirements.

Submit

25. A risk team determines that a critical vulnerability requires a specific technical fix to be applied, and separately schedules a follow-up scan afterward specifically to confirm the fix actually closed the gap before closing the ticket. Which two risk management activities do these two steps represent, respectively?

Explanation

Applying the technical fix is remediation, while the follow-up scan confirming the fix actually worked is validation. Risk prioritization ranks which risks to address first, severity impact rates a finding's consequences, and risk assessment frameworks provide structured evaluation methodologies, none of which describe these two sequential closing-out steps.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company troubleshooting IAM issues discovers that a service account...
A security team configures an endpoint so that only a pre-approved,...
During incident response, an analyst examines the embedded metadata...
A threat hunting team deploys a decoy network segment populated with...
A code review identifies a function that trusts a filename provided...
A security team building a SIEM dashboard wants to visually correlate...
A software vendor cryptographically signs each release of their...
A cloud provider offers a cryptographic technique where a data...
A security team wants to write a Python script that automatically...
A manufacturing company operating legacy industrial equipment finds...
A hardware security team implements a boot process that...
A network team troubleshooting intermittent connectivity discovers...
Match each threat-actor TTP to its correct description.
A company documents formal, written expectations for password...
A zero trust architecture requires that a user who was authenticated...
A company running short-lived, event-driven functions in the cloud...
A company implementing PKI wants a mechanism for clients to quickly...
A security team wants to ensure that log entries flowing into their...
A CI/CD pipeline is configured so that any attempt to merge code...
A development team integrates a testing approach into their pipeline...
A network architect places a device inline between users and the...
A company deploying an AI-powered digital assistant discovers that the...
A threat modeling team profiles a specific adversary group and...
A hospital system implementing a new patient portal must specifically...
A risk team determines that a critical vulnerability requires a...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!