CompTIA SecurityX CAS-005 Exam Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company troubleshooting a federated single sign-on issue discovers that the identity provider and service provider have mismatched clock settings, causing SAML assertions to be rejected as expired even though they were just issued. Which IAM component's configuration is most directly implicated?

Explanation

SAML assertions include time-bound validity windows, so clock skew between identity provider and service provider commonly causes assertions to be rejected as expired even when freshly issued. OAuth concerns authorization delegation rather than SAML's specific assertion timing, Kerberos uses its own separate ticket timing mechanism, PAM manages privileged credential lifecycle, and EAP is a broader authentication framework rather than the specific SAML assertion timing issue described.

Submit
Please wait...
About This Quiz
CompTIA SecurityX Cas-005 Exam Practice Test 3 - Quiz

This assessment focuses on the CompTIA SecurityX CAS-005 exam, evaluating your knowledge of cybersecurity principles, risk management, and security architecture. It's designed for individuals preparing for the certification, helping to reinforce essential concepts and skills critical for success in the field. Engaging with this material is vital for anyone aiming... see moreto enhance their expertise in security practices. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A financial services company joins an industry-specific organization that facilitates sharing of threat indicators and best practices exclusively among member banks and credit unions, distinct from a broader public threat feed. Which external intelligence source is this?

Explanation

An ISAC is a sector-specific organization facilitating threat indicator and best-practice sharing exclusively among member organizations within an industry, such as financial services. OSINT refers to publicly available information broadly, dark web monitoring watches underground forums, a threat intelligence platform is a tool for managing intelligence data rather than the sharing community itself, and reliability factors assess a source's trustworthiness rather than describing this sector-specific sharing body.

Submit

3. A malware analyst disassembles a suspicious binary into its underlying assembly instructions to understand exactly what it does without ever executing it, since the sample is believed to check for and evade sandbox environments. Which analysis technique is this?

Explanation

Disassembling a binary into assembly instructions to understand its behavior without executing it is reverse engineering. Sandboxing executes the sample in an isolated environment, which this scenario specifically avoids due to suspected sandbox evasion, metadata analysis examines embedded file metadata, volatile storage analysis examines memory, and network analysis examines traffic patterns rather than static code disassembly.

Submit

4. A threat intelligence analyst evaluates a third-party feed, specifically weighing how timely, accurate, and independently corroborated its reported indicators have historically been before deciding how much to trust its data. Separately, the analyst actively works to detect and prevent adversaries from gathering intelligence about the organization's own defensive capabilities and security posture. Which two concepts are described, respectively?

Explanation

Weighing a feed's historical timeliness, accuracy, and corroboration is assessing reliability factors, while actively detecting and preventing adversary intelligence-gathering against the organization is counterintelligence and operational security. OSINT refers to publicly available information broadly, dark web monitoring watches underground forums, and threat intelligence platforms manage intelligence data rather than describing either of these two specific practices.

Submit

5. A code reviewer finds that a web application directly embeds untrusted user input into a database query string without any sanitization, allowing an attacker to alter the query's logic entirely. Which vulnerability is this?

Explanation

Directly embedding untrusted input into a query string without sanitization, allowing an attacker to alter query logic, is an injection vulnerability. Cross-site scripting injects malicious scripts into content viewed by other users rather than database queries, a race condition is a timing-dependent bug, insecure configuration concerns misconfigured settings generally, and weak ciphers concern cryptographic algorithm strength rather than unsanitized query construction.

Submit

6. A SOC ingests bounty program submissions, third-party vulnerability reports, and cloud security posture management data alongside its own internal logs to build a more complete picture of the organization's risk. Which monitoring concept does this represent?

Explanation

Ingesting bounty submissions, third-party reports, and CSPM data alongside internal logs is incorporating diverse data sources. Behavior baselines and analytics establish normal patterns to flag deviations, aggregate data analysis correlates and prioritizes already-collected data, alerting prioritization factors rank which alerts matter most, and reporting and metrics visualize results rather than describing the act of pulling in varied external and internal data sources.

Submit

7. A company wants to permanently destroy an encrypted hard drive's data without physically destroying the drive itself, by simply and irrecoverably discarding the encryption key that protects it, rendering the encrypted data permanently unreadable. Which technique is this?

Explanation

Cryptographic erase destroys data by irrecoverably discarding the encryption key, rendering the encrypted data permanently unreadable without physically destroying the drive. Data sanitization generically covers a broader range of destruction methods, data anonymization removes identifying characteristics rather than destroying data entirely, serialization converts data structures into a storable format, and obfuscation makes data harder to interpret rather than cryptographically rendering it permanently unreadable.

Submit

8. Match each advanced cryptographic concept to its correct description.

Explanation

Homomorphic encryption computes on still-encrypted data, key splitting divides a key among multiple holders, secure multiparty computation lets parties jointly compute without revealing inputs, forward secrecy protects past sessions from a future key compromise, and envelope encryption wraps a data key with a separate key-encrypting key, each addressing a distinct cryptographic goal.

Submit

9. A security team writes an Ansible playbook that automatically applies a standard security baseline configuration to every newly provisioned server, ensuring consistency without manual intervention on each new host. Which automation concept does this represent?

Explanation

Using a tool like Ansible to automatically apply a standard configuration baseline to new infrastructure is infrastructure as code. Cron/scheduled tasks run at fixed time intervals rather than on provisioning events, generative AI code assist helps write code interactively, SCAP standardizes vulnerability and configuration checking rather than provisioning configuration itself, and workflow automation generically describes the broader capability rather than this specific configuration-as-code approach.

Submit

10. A manufacturing plant's operational technology network must remain isolated from the corporate IT network specifically to prevent an IT-side compromise from ever reaching safety-critical production equipment. Which security and privacy consideration for specialized systems does this represent?

Explanation

Isolating OT networks from corporate IT specifically to prevent cross-contamination is segmentation. Aggregation concerns combining data from multiple sources, hardening reduces a system's attack surface directly, data analytics concerns analyzing collected data, and environmental considerations concern physical conditions like temperature rather than network isolation specifically.

Submit

11. A security engineer wants a hardware-backed mechanism, embedded directly in a laptop's motherboard, capable of securely generating and storing a device's disk encryption keys and verifying the integrity of the boot process on that specific device. Complete the sentence: this technology is called a ______.

Explanation

A TPM is embedded directly in a device's motherboard and securely generates and stores disk encryption keys while supporting boot integrity verification for that specific device. An HSM, by contrast, is a separate dedicated device typically serving multiple servers.

Submit

12. A network team investigating a mail delivery problem discovers that legitimate outbound emails are being rejected by recipient mail servers because the sending domain's DNS record listing which mail servers are authorized to send on its behalf does not include the actual sending server's IP address. Which email security mechanism is misconfigured?

Explanation

SPF publishes a DNS record listing which mail servers are authorized to send email on a domain's behalf, and a missing or incorrect entry causes legitimate mail to fail authentication. DKIM cryptographically signs message content rather than listing authorized servers, DMARC builds policy on top of SPF and DKIM results, S/MIME encrypts and signs individual email content, and DNSSEC secures DNS record integrity generally rather than authorized-sender lists specifically.

Submit

13. A security team analyzing a compromised endpoint finds evidence that the attacker modified system logs and cleared specific event entries after completing their objectives, specifically to hinder later forensic investigation. Which threat-actor TTP does this represent?

Explanation

Modifying or clearing logs specifically to hinder forensic investigation is defensive evasion. Lateral movement concerns spreading to other systems, privilege escalation gains higher-level access, unauthorized execution runs code without authorization, and credential dumping extracts stored credentials, none of which describe tampering with logs to cover tracks.

Submit

14. A company runs a phishing simulation campaign, sends quarterly reminders about safe social media use, and tracks completion rates for mandatory security training modules across all departments. Which security program management activity does this represent?

Explanation

Running phishing simulations, social media safety reminders, and tracking training completion is specifically the awareness and training component of security program management. Management commitment concerns leadership's visible support, communication and reporting are broader program elements, and a RACI matrix clarifies roles rather than describing the training and awareness activities themselves.

Submit

15. A zero trust architecture team decides that even internal application-to-application API calls must be authenticated, authorized, and validated on every single call, with no implicit trust granted based solely on being on the internal network. Which zero trust principle does this reflect?

Explanation

Requiring every API call, including internal ones, to be authenticated, authorized, and validated without implicit network-based trust is API integration and validation. Deperimeterization, continuous authorization, and microsegmentation are related but distinct zero trust concepts addressing perimeter reliance, session re-verification, and network-level workload isolation respectively, and security boundaries define zones rather than describing this specific call-by-call API validation requirement.

Submit

16. A company deploying containerized workloads wants to continuously monitor running containers and their host infrastructure for exploits, malware, and misconfigurations specifically within a cloud environment. Which technology fits this need?

Explanation

A CWPP continuously monitors running cloud workloads, including containers, for exploits, malware, and misconfigurations. A CASB provides visibility and policy enforcement over cloud application usage rather than workload-level runtime protection, an API gateway manages API traffic, SD-WAN optimizes wide area network connectivity, and Terraform provisions infrastructure as code rather than continuously monitoring runtime workload security.

Submit

17. A company implements a system where a user's identity, established once by an identity provider, is trusted by multiple separate external service providers without the user needing to log in again to each one. Separately, within its own internal network, the company lets a user log into one internal application and automatically gain access to several other internal applications without a second login. Which two concepts are described, respectively?

Explanation

Trusting an identity across separate external organizations is federation, while granting access across multiple internal applications after one login is single sign-on. Attestation verifies device or system state, conditional access applies contextual policies, and provisioning concerns account creation rather than describing either of these two trust-extension mechanisms.

Submit

18. A security architect labels datasets across the organization as public, internal, confidential, or restricted, and then applies automated tagging so that downstream systems can apply appropriate handling rules based on that label. Which two information and data security design elements does this combination represent?

Explanation

Defining sensitivity categories like public, internal, confidential, and restricted is a classification model, while applying automated tags reflecting those categories is data labeling. DLP concerns preventing data loss at various states, vulnerability management and hardening concern reducing weaknesses, assessments and scanning concern control effectiveness testing, and legacy components and defense-in-depth concern architecture design rather than sensitivity classification and tagging specifically.

Submit

19. A development team documents that their new application must process at least 10,000 transactions per second, a specific measurable target distinct from the broader statement that the application must simply 'perform well.' Which type of requirement is the 10,000 transactions per second target?

Explanation

A specific measurable performance target like transactions per second is a non-functional requirement, describing how well the system performs rather than what it does. A functional requirement describes specific features or behaviors the system must have, a security vs. usability trade-off weighs competing priorities, a formal method mathematically verifies correctness, and a coding standard governs code style rather than describing a performance target.

Submit

20. An architecture team designing a globally distributed application wants users in Asia to be served by servers physically located in Asia, and users in Europe served by servers in Europe, to reduce latency and address data residency requirements. Which design consideration does this represent?

Explanation

Serving users from geographically proximate infrastructure to reduce latency and address data residency is geographical considerations. Vertical scaling concerns single-server resource upgrades, persistence concerns state retention across sessions, interoperability concerns compatibility between systems, and recoverability concerns restoring service after failure rather than geographic placement of infrastructure.

Submit

21. A network architect places a device at key points in the network specifically to passively duplicate traffic for monitoring tools, without being inline and without any risk of disrupting the traffic flow itself if the device fails. Which component is this?

Explanation

A network tap passively duplicates traffic for monitoring without sitting inline in the traffic path, so its failure does not disrupt flow. A reverse proxy and IPS both sit inline and can disrupt traffic if they fail, NAC controls device network admission, and a collector aggregates already-captured data rather than passively duplicating live traffic at the wire level.

Submit

22. A company deploying an AI coding assistant discovers that a plug-in integrated with the assistant contains a flaw allowing it to execute arbitrary shell commands whenever it processes a specially crafted code comment. Complete the sentence: this AI-enabled attack category is called ______.

Explanation

A structural flaw in a plug-in's own construction allowing arbitrary command execution is insecure plug-in design. Prompt injection manipulates the model's instructions through crafted input rather than exploiting a plug-in's code flaw directly.

Submit

23. A threat modeling team reviews architecture diagrams, data flow diagrams, and conducts code reviews specifically to identify every point where an attacker could potentially interact with the system. Which threat modeling activity does this represent?

Explanation

Reviewing architecture, data flows, and code specifically to identify every potential attacker interaction point is attack surface determination. Actor characteristics profiling assesses adversary motivation and capability, enumeration/discovery is one specific technique within attack surface determination rather than the whole activity, modeling applicability applies threats to a specific environment, and abuse case development is a threat modeling method distinct from surface determination itself.

Submit

24. A multinational company must retain certain business records beyond their normal retention schedule because ongoing litigation makes those records potentially relevant as evidence. Which cross-jurisdictional compliance concept requires this extended retention?

Explanation

A legal hold suspends normal data destruction schedules for records that may be relevant to ongoing or anticipated litigation. Due diligence concerns reasonable investigation before a decision, due care concerns reasonable ongoing protective action, export controls restrict cross-border transfer of controlled technology, and contractual obligations concern agreement-based requirements rather than litigation-driven retention specifically.

Submit

25. A company evaluating a new cloud storage vendor specifically assesses the risk that the vendor's own downstream subcontractor, who actually hosts the physical infrastructure, could introduce a security gap the primary vendor doesn't fully control. Which third-party risk category is this?

Explanation

Risk introduced by a vendor's own downstream subcontractor is specifically subprocessor risk. Supply chain risk is the broader category covering the full chain of suppliers, vendor risk concerns the primary vendor relationship directly, and availability and confidentiality risk concern different risk dimensions rather than this specific subcontractor relationship.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company troubleshooting a federated single sign-on issue discovers...
A financial services company joins an industry-specific organization...
A malware analyst disassembles a suspicious binary into its underlying...
A threat intelligence analyst evaluates a third-party feed,...
A code reviewer finds that a web application directly embeds untrusted...
A SOC ingests bounty program submissions, third-party vulnerability...
A company wants to permanently destroy an encrypted hard drive's data...
Match each advanced cryptographic concept to its correct description.
A security team writes an Ansible playbook that automatically applies...
A manufacturing plant's operational technology network must remain...
A security engineer wants a hardware-backed mechanism, embedded...
A network team investigating a mail delivery problem discovers that...
A security team analyzing a compromised endpoint finds evidence that...
A company runs a phishing simulation campaign, sends quarterly...
A zero trust architecture team decides that even internal...
A company deploying containerized workloads wants to continuously...
A company implements a system where a user's identity, established...
A security architect labels datasets across the organization as...
A development team documents that their new application must process...
An architecture team designing a globally distributed application...
A network architect places a device at key points in the network...
A company deploying an AI coding assistant discovers that a plug-in...
A threat modeling team reviews architecture diagrams, data flow...
A multinational company must retain certain business records beyond...
A company evaluating a new cloud storage vendor specifically assesses...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!