CompTIA SecurityX CAS-005 Exam Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company troubleshooting SSO issues discovers that a user can successfully authenticate to the identity provider but is then denied access to a specific application because the identity provider's trust relationship with that particular service provider was never properly established. Which IAM concept is most directly implicated?

Explanation

A missing or broken trust relationship between an identity provider and a specific service provider is a federation configuration issue. MFA concerns a second authentication factor, PAM manages privileged credential lifecycle, biometrics use physical characteristics for authentication, and conditional access applies contextual policies rather than describing a fundamentally missing trust relationship between the identity provider and a service provider.

Submit
Please wait...
About This Quiz
CompTIA SecurityX Cas-005 Exam Practice Test 4 - Quiz

This assessment focuses on the CompTIA SecurityX CAS-005 exam, evaluating your understanding of cybersecurity concepts, risk management, and security protocols. It's designed for learners preparing for the certification, helping you identify strengths and areas for improvement in your knowledge of security practices. Engaging with this content will enhance your readiness... see morefor the exam and strengthen your cybersecurity skills. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. After containing and eradicating a ransomware infection, the incident response team pieces together the exact sequence of events, from initial phishing email to final encryption, by correlating timestamps across multiple log sources. Which activity is this?

Explanation

Correlating timestamps across multiple sources to piece together the exact sequence of events is timeline reconstruction. Root cause analysis determines why the incident occurred rather than sequencing when events happened, threat response concerns active containment and remediation actions, preparedness exercises test response capability proactively, and data recovery and extraction retrieves lost or damaged data rather than sequencing the incident timeline.

Submit

3. An incident responder needs to understand exactly which registry keys, files, and processes were modified during a compromise, all of which existed only in the computer's memory at the time of the incident and would be lost once the system is powered off. Which analysis category is this?

Explanation

Data that exists only in memory and would be lost on power-off is volatile storage, and analyzing it is volatile storage analysis. Non-volatile storage analysis examines persistent storage like disks, metadata analysis examines embedded file metadata, hardware analysis examines physical device components, and network analysis examines traffic patterns rather than memory-resident artifacts.

Submit

4. A threat hunter formulates a specific theory that an APT group known to target the organization's sector is likely using a particular living-off-the-land technique, and proactively searches the environment for evidence supporting or refuting that specific theory, rather than waiting for an alert to fire. Which internal intelligence source activity is this?

Explanation

Proactively searching for evidence supporting or refuting a specific theory about adversary behavior is a hypothesis-based search. Honeypots are decoy systems for detection, user behavior analytics baselines normal behavior to flag anomalies, internal reconnaissance gathers information about the organization's own environment, and adversary emulation engagements actively simulate attacker techniques rather than proactively testing a specific theory without waiting for an alert.

Submit

5. A code reviewer finds a legacy function still in use throughout an application that has been officially marked by the language maintainers as unsafe and scheduled for removal in a future release. Separately, in a different code path, the reviewer finds a fixed-size buffer being written to without any bounds checking, allowing more data than it can hold to spill into adjacent memory. Which two vulnerability categories are described, respectively?

Explanation

A function officially marked unsafe and scheduled for removal is a deprecated function, while writing beyond a fixed-size buffer's bounds into adjacent memory is an overflow. Race conditions concern timing-dependent bugs, weak ciphers concern cryptographic algorithm strength, and insecure configuration concerns misconfigured settings generally rather than either of these two specific code-level flaws.

Submit

6. A SOC dashboard displays the percentage of critical alerts resolved within the target response time over the past quarter, giving leadership a quick sense of whether the team is meeting its performance goals. Which reporting concept is this?

Explanation

A persistent display summarizing key performance metrics like alert resolution rates over time is a dashboard. Visualization generically covers any graphical representation, audit log reduction filters low-value log noise, event parsing structures raw log data, and correlation links related events together rather than describing this ongoing performance-tracking display.

Submit

7. A company implementing passwordless authentication issues each user a hardware security key that generates a cryptographic proof of identity tied to a private key that never leaves the device, eliminating reliance on a memorized secret entirely. Which use case does this represent?

Explanation

Using a hardware-backed private key to prove identity without a memorized password is certificate-based authentication, a passwordless approach. Software provenance verifies the origin and integrity of software artifacts, non-repudiation only concerns proving an action cannot be denied after the fact, data anonymization removes identifying characteristics, and immutable databases prevent record alteration rather than describing hardware-backed passwordless identity proof.

Submit

8. A cryptographic implementation combines encryption with a built-in integrity check in a single operation, ensuring that any tampering with the ciphertext is detected at decryption time without needing a separate hashing step. Complete the sentence: this technique is called ______.

Explanation

Authenticated encryption with associated data combines encryption and integrity verification in a single operation, detecting tampering at decryption without a separate hashing step. Forward secrecy and homomorphic encryption address different cryptographic goals entirely.

Submit

9. A security team wants a generative AI feature integrated into their development environment specifically to help write secure code snippets and generate accurate technical documentation for internal APIs, without the AI having any autonomous deployment capability. Which automation use case does this represent?

Explanation

Using generative AI to help write code and generate documentation is code assist. Auto-containment automatically isolates a threat, SCAP standardizes vulnerability and configuration checking, workflow automation generically describes broader automated processes, and SOAR runbooks execute fully automated incident response sequences rather than assisting with code writing and documentation generation.

Submit

10. Match each industry sector to the specialized/legacy system challenge it is most associated with.

Explanation

Each sector carries a distinct specialized-systems challenge: utilities must protect grid availability, transportation must prevent safety-critical failures, healthcare must balance patching against certification and patient safety, manufacturing must protect proprietary processes, and government/defense must manage classification and clearance requirements.

Submit

11. A security researcher discovers that a specific model of USB flash drive can be reprogrammed at the firmware level to impersonate a keyboard and automatically type malicious commands the instant it is plugged into a computer. Which threat-actor TTP category does this represent?

Explanation

A USB device reprogrammed to impersonate a keyboard and execute malicious commands upon connection is specifically a USB-based attack. Firmware tampering modifies a device's own firmware more broadly rather than specifically weaponizing USB peripheral behavior, shimming inserts malicious code between a driver and hardware, memory attacks target RAM contents, and EMI concerns electromagnetic interference rather than USB peripheral impersonation.

Submit

12. A network team investigating intermittent TLS handshake failures between two systems discovers that one system only supports newer cipher suites while the other has not been updated and only supports older ones, leaving no common cipher suite for them to agree on. Which issue category is this?

Explanation

Two systems having no cipher suite in common due to mismatched supported cipher lists is a cipher mismatch. PKI issues generically concern certificate and key infrastructure problems broadly, resource exhaustion concerns capacity being overwhelmed, ACL issues concern access control list misconfigurations, and DoS/DDoS concern availability attacks rather than a negotiation failure due to incompatible cipher suite support.

Submit

13. A security team deploys a solution on mobile devices specifically to enforce corporate policies like remote wipe, app whitelisting, and encryption requirements across both company-owned and employee-owned devices accessing corporate resources. Which technology is this?

Explanation

MDM specifically enforces policies like remote wipe, app whitelisting, and encryption on mobile devices, both corporate-owned and personally owned. EDR focuses on threat detection and response rather than policy enforcement specifically, a host-based firewall filters network traffic, browser isolation runs browsing sessions in an isolated environment, and SELinux enforces mandatory access control on Linux systems rather than managing mobile device policy broadly.

Submit

14. A company adopts a GRC platform that automatically links specific technical controls to the regulatory requirements they satisfy, so auditors can quickly see which controls address which compliance obligations. Complete the sentence: this GRC tool capability is called ______.

Explanation

Automatically linking specific controls to the regulatory requirements they satisfy is mapping. Automation reduces manual GRC workflow effort generally, and compliance tracking monitors ongoing adherence status over time, both distinct capabilities.

Submit

15. A zero trust architecture team defines a specific data perimeter around a sensitive customer database, distinct from a broader network segment, so that access policies can be enforced based on the sensitivity of that data regardless of where within the network it physically resides. Which zero trust concept is this?

Explanation

Defining a security boundary around specific sensitive data, independent of physical network location, is a data perimeter. Microsegmentation restricts lateral movement between workloads at the network level, always-on VPN provides persistent encrypted remote connectivity, continuous authorization re-evaluates access based on context, and deperimeterization concerns removing reliance on a fixed network boundary rather than defining a data-specific security zone.

Submit

16. A company using infrastructure as code to provision its cloud environment wants every change to that Terraform configuration reviewed and approved through the same pipeline used for application code changes, rather than being applied manually and inconsistently. Which practice does this represent?

Explanation

Running infrastructure code changes through the same reviewed, automated pipeline as application code is applying CI/CD practices to infrastructure as code. Package monitoring tracks software dependencies for vulnerabilities, shadow IT detection identifies unsanctioned tool use, container orchestration manages containerized workload deployment, and serverless workloads describes a compute execution model rather than a change management pipeline practice.

Submit

17. A company implementing PKI issues different certificate profiles for web servers, code signing, and email encryption, each with pre-configured settings appropriate to its specific use case, rather than manually configuring every certificate from scratch. Which PKI component is this?

Explanation

Pre-configured certificate profiles for different use cases like web servers, code signing, and email encryption are certificate templates. OCSP stapling optimizes real-time revocation status checking, CA/RA separation divides issuance and registration duties, certificate extensions generically add metadata fields, and certificate revocation only concerns invalidating certificates rather than the pre-configured issuance profiles used to create them consistently.

Submit

18. A company deploys sensors at key network chokepoints and configures automated alerts specifically to notify the SOC the moment unusual traffic patterns matching known attack behavior are observed. Which two detection and threat-hunting enablers does this combination represent?

Explanation

Deciding where to deploy sensors at network chokepoints is sensor placement, while configuring automated notifications when patterns are observed is alerting. Centralized logging and continuous monitoring concern log aggregation and ongoing observation rather than sensor location and notification specifically, classification models and tagging strategies concern data sensitivity, DLP concerns preventing data loss, and vulnerability management and hardening concern reducing weaknesses rather than describing sensor placement and alert triggering.

Submit

19. A security team requires that every new software dependency added to a project be automatically checked against a database of known vulnerabilities before the build is allowed to complete. Which software assurance activity is this?

Explanation

Automatically checking dependencies against known vulnerability databases is software composition analysis. SAST analyzes the organization's own source code, IAST combines static and dynamic analysis during runtime, RASP protects a running application at runtime, and formal methods use mathematical proofs to verify correctness rather than checking third-party dependencies for known vulnerabilities.

Submit

20. An architecture team designing a payment system ensures that if the primary data center goes offline, transactions can seamlessly continue processing from a secondary data center without requiring manual intervention or causing service interruption. Which availability and integrity design consideration does this represent?

Explanation

Seamlessly continuing operations from a secondary location without manual intervention after a primary failure is recoverability. Interoperability concerns compatibility between different systems, vertical vs. horizontal scaling concerns how capacity is added, persistence vs. non-persistence concerns whether state is retained across sessions, and load balancing only distributes traffic across already-available resources rather than describing failover to an entirely separate data center.

Submit

21. A network architect places one component specifically to accept and route API requests from external partners to the correct internal microservice, enforcing consistent authentication and rate limiting across all those calls in one place. Separately, another component caches and serves static website content from edge locations geographically close to end users to reduce latency. Which two components are described, respectively?

Explanation

Routing and securing API traffic to backend microservices is an API gateway, while caching and serving static content from geographically distributed edge locations is a CDN. A reverse proxy forwards requests more generally without a CDN's edge-caching focus, a WAF filters web application attacks specifically, and a load balancer distributes traffic across servers rather than describing either of these two specialized components.

Submit

22. A company deploys an AI-enabled digital worker with access to internal financial systems and specifically implements controls to detect if the AI is being used for tasks beyond its officially sanctioned purpose, while also requiring that any employee interacting with it be clearly told they are talking to an AI rather than a human. Which two AI-enabled assistant considerations does this combination represent?

Explanation

Detecting use beyond the AI's sanctioned purpose relates to access/permissions scoping, while requiring clear notification that users are interacting with an AI is disclosure of AI usage. Guardrails constrain output content and DLP prevents data loss, overreliance and excessive agency describe human trust and AI autonomy risks respectively, prompt injection and model theft are attacks against the model itself, and sensitive information disclosure and model inversion concern data exposure and reconstruction rather than describing scope monitoring and usage transparency.

Submit

23. A threat modeling exercise specifically considers how the organization's attack surface will change once a planned acquisition brings a new subsidiary's entire IT environment, including unknown legacy systems, under the parent company's responsibility. Which attack surface determination factor does this represent?

Explanation

Considering how an acquisition changes the attack surface by bringing in a new subsidiary's environment is organizational change. Trust boundaries concern where differing trust levels meet within an architecture, code reviews examine source code for flaws, data flows map how information moves through a system, and user factors concern human behavior rather than describing organizational restructuring events like mergers or acquisitions.

Submit

24. A company undergoes a review conducted by its own internal audit team to check adherence to its documented security policies, distinct from a review conducted by an outside firm hired specifically to provide an independent, unbiased assessment. Which of these two review types is the internal team's review?

Explanation

A review conducted by the organization's own team is an internal audit, distinct from an external audit performed by an outside firm for independent assessment. Certification is a formal attestation of meeting a specific standard, a third-party compliance evaluation specifically assesses vendors, and cross-jurisdictional assessment concerns compliance across multiple legal jurisdictions rather than distinguishing who performs the review.

Submit

25. A risk team determines that while the organization would prefer zero security incidents, leadership has formally agreed the organization can tolerate up to two minor incidents per year without triggering an escalated response. Which risk management concept does this formal agreement represent?

Explanation

Formally agreeing on how much risk, such as a specific number of tolerable minor incidents, the organization will accept is risk appetite and tolerance. Risk prioritization ranks risks by importance, severity impact rates the consequences of a specific finding, risk assessment frameworks provide structured methodologies for evaluating risk, and validation confirms that remediation was effective rather than describing this formally agreed tolerance threshold.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company troubleshooting SSO issues discovers that a user can...
After containing and eradicating a ransomware infection, the incident...
An incident responder needs to understand exactly which registry keys,...
A threat hunter formulates a specific theory that an APT group known...
A code reviewer finds a legacy function still in use throughout an...
A SOC dashboard displays the percentage of critical alerts resolved...
A company implementing passwordless authentication issues each user a...
A cryptographic implementation combines encryption with a built-in...
A security team wants a generative AI feature integrated into their...
Match each industry sector to the specialized/legacy system challenge...
A security researcher discovers that a specific model of USB flash...
A network team investigating intermittent TLS handshake failures...
A security team deploys a solution on mobile devices specifically to...
A company adopts a GRC platform that automatically links specific...
A zero trust architecture team defines a specific data perimeter...
A company using infrastructure as code to provision its cloud...
A company implementing PKI issues different certificate profiles for...
A company deploys sensors at key network chokepoints and configures...
A security team requires that every new software dependency added to a...
An architecture team designing a payment system ensures that if the...
A network architect places one component specifically to accept and...
A company deploys an AI-enabled digital worker with access to internal...
A threat modeling exercise specifically considers how the...
A company undergoes a review conducted by its own internal audit team...
A risk team determines that while the organization would prefer zero...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!