CompTIA SecurityX CAS-005 Exam Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A company troubleshooting authentication issues discovers that a legacy application still relies on an older, less secure authentication protocol that does not support modern multifactor authentication integration, creating friction with the organization's IAM strategy. Which authentication and authorization technology gap does this most directly involve?

Explanation

The scenario describes a legacy authentication protocol generally lacking modern MFA integration capability, a common IAM troubleshooting friction point when modernizing authentication. Kerberos, EAP, IEEE 802.1X, and OAuth are all specific named protocols listed in this objective, but the scenario as described is intentionally generic about which legacy protocol is involved, making the general gap itself the best answer rather than any one specific named protocol.

Submit
Please wait...
About This Quiz
CompTIA SecurityX Cas-005 Exam Practice Test 5 - Quiz

This practice assessment focuses on the CompTIA SecurityX CAS-005 Exam, evaluating your understanding of key cybersecurity concepts, risk management, and security architecture. It is designed to help learners prepare effectively for certification and enhance their skills in protecting information systems. Engaging with this material is crucial for anyone aiming to... see moreexcel in the cybersecurity field. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A SOC ingesting terabytes of daily log data configures automated filtering that discards routine, low-value entries like successful health checks before they ever reach analyst dashboards, keeping only what's likely to matter for investigation. Which aggregate data analysis activity is this?

Explanation

Automatically filtering out routine, low-value log entries before they reach analysts is audit log reduction. Correlation links related events together, trends track directional change over time, prioritization ranks which findings matter most, and event parsing breaks raw logs into structured fields rather than filtering out low-value noise specifically.

Submit

3. An incident response team investigating an insider threat case reviews an employee's file access patterns over several months, correlating them against their job role and normal working hours to determine whether their behavior was anomalous. Separately, after the investigation concludes, the team determines that the actual underlying reason the incident was possible was an overly permissive file share configuration that was never corrected after a prior audit had flagged it. Which two concepts are described, respectively?

Explanation

Reviewing an employee's own access patterns against normal behavior to assess anomalous internal activity is an insider threat investigation, while determining the actual underlying reason an incident was possible is root cause analysis. Timeline reconstruction sequences events chronologically, threat response concerns active containment actions, and preparedness exercises test response capability proactively rather than describing either of these two specific investigative activities.

Submit

4. A threat hunting team specifically monitors underground forums and marketplaces for mentions of the organization's name, leaked credentials, or planned attacks against it. Which external intelligence source is this?

Explanation

Specifically monitoring underground forums and marketplaces for organization-relevant mentions is dark web monitoring. OSINT generically covers publicly available information more broadly, information sharing and analysis centers are industry collaboration bodies, reliability factors assess a source's trustworthiness, and counterintelligence concerns detecting adversary intelligence-gathering against the organization rather than proactively scanning underground marketplaces.

Submit

5. A penetration tester finds that a web application accepts a URL parameter and makes the server itself fetch and return the contents of whatever URL is specified, allowing access to internal-only resources not otherwise reachable from outside. Which vulnerability is this?

Explanation

Making the server itself fetch content from an attacker-specified URL, potentially reaching internal-only resources, is server-side request forgery. Cross-site request forgery tricks a victim's browser into making unwanted requests using their own session, cross-site scripting injects malicious scripts, insecure configuration concerns misconfigured settings generally, and directory service misconfiguration concerns misconfigured directory services rather than a server making attacker-directed outbound requests.

Submit

6. A SOC analyst reviewing historical network traffic notices a host that normally transfers a few megabytes of data per day suddenly transferred several gigabytes overnight to an external IP address it had never contacted before. Which monitoring concept most directly flagged this as unusual?

Explanation

Comparing current activity against an established normal pattern for that host, and flagging a significant deviation, is behavior baselines and analytics. Aggregate data analysis generically correlates and prioritizes data broadly, reporting and metrics visualize results, incorporating diverse data sources concerns pulling in varied log types, and alert failures concern alerts not firing correctly rather than describing the baseline-deviation detection itself.

Submit

7. Match each cryptographic use case or technique to its correct description.

Explanation

Tokenization substitutes a non-sensitive value for sensitive data, code signing verifies software hasn't been tampered with, cryptographic erase destroys data by discarding its key, digital signatures prove authenticity and integrity using a private key, and hashing produces a one-way digest for integrity verification, each serving a distinct cryptographic purpose.

Submit

8. A cryptography team evaluates whether their current RSA-based key exchange will remain secure against a sufficiently powerful quantum computer, and begins piloting newer algorithms specifically designed to resist that future threat. Complete the sentence: this field of cryptography is called ______.

Explanation

Evaluating resistance to quantum computing attacks and piloting newer resistant algorithms is post-quantum cryptography. Forward secrecy protects past sessions from future key compromise through an unrelated mechanism.

Submit

9. A security team configures a system so that whenever a new critical CVE affecting software in their environment is published, an automated workflow immediately cross-references affected assets and opens remediation tickets without waiting for a scheduled scan cycle. Which automation concept does this represent?

Explanation

Automatically initiating a workflow the moment a new CVE is published, rather than waiting for a scheduled cycle, is an event-based trigger. Cron/scheduled tasks run at fixed time intervals regardless of new publications, auto-containment isolates an active threat, SCAP generically standardizes vulnerability and configuration checking, and container security concerns securing containerized workloads rather than this specific publication-triggered automation.

Submit

10. A transportation company's traffic signal control systems must remain operational and safe even during a cyberattack, since a failure could directly endanger public safety rather than just causing a business disruption. Which industry-specific challenge category does this represent?

Explanation

Public safety implications of a cyberattack against traffic control systems is specifically a transportation industry-specific challenge. Financial, healthcare, manufacturing, and government/defense sectors each face their own distinct specialized and legacy system challenges rather than this specific traffic-signal public safety concern.

Submit

11. A hardware security team implements a boot process that records cryptographic measurements of each boot stage into a protected hardware component, allowing a remote system to later verify the device booted into a known-good state, even though the boot itself was not halted if a measurement didn't match expectations. Complete the sentence: this technology is called ______.

Explanation

Measured boot records cryptographic measurements of each boot stage for later remote verification, without necessarily halting the boot process itself. Secure Boot, by contrast, actively halts the boot process on a signature mismatch.

Submit

12. A network team investigating a service disruption discovers that an access control list on a router was too restrictive, accidentally blocking legitimate traffic between two business-critical systems that had recently been added to the network. Which network issue category is this?

Explanation

An overly restrictive access control list blocking legitimate traffic is an ACL issue. Routing errors concern incorrect path selection, switching errors concern Layer 2 forwarding issues, VPN/tunnel errors concern encrypted tunnel connectivity, and resource exhaustion concerns capacity being overwhelmed rather than a misconfigured permission list blocking legitimate traffic.

Submit

13. A security team notices that an attacker who gained initial low-privileged access to a server later successfully exploited a local vulnerability to gain full administrative control of that same machine. Which threat-actor TTP does this represent?

Explanation

Gaining full administrative control from initial low-privileged access on the same machine is privilege escalation. Lateral movement concerns spreading to other systems rather than escalating on the same host, credential dumping extracts stored credentials, defensive evasion avoids detection, and unauthorized execution runs code without authorization, none of which specifically describe escalating from low to full privilege on one machine.

Submit

14. A company maintains a database tracking every server, its owner, its configuration baseline, and its relationships to other systems, updated automatically as changes occur, to support accurate change management decisions. Complete the sentence: this governance component is called a ______.

Explanation

A database tracking systems, ownership, configuration, and relationships to support change management is a CMDB. Asset management life cycle is the broader process CMDB data supports, and inventory alone lists what exists without this relationship and configuration detail.

Submit

15. A zero trust architecture team defines a highly restricted network zone where only specifically authorized traffic is permitted, used to house the organization's most sensitive systems, distinct from the general internal network. Which zero trust concept is this?

Explanation

A highly restricted network zone housing the most sensitive systems, with only specifically authorized traffic permitted, is a secure zone. Data perimeters define boundaries around specific sensitive data rather than a network zone broadly, microsegmentation generically restricts lateral movement between workloads, system components refers to the assets within a boundary rather than the boundary itself, and always-on VPN provides persistent encrypted remote connectivity rather than defining a restricted internal zone.

Submit

16. A security team wants continuous, automated assurance that their cloud environment's configuration remains compliant with security best practices, automatically flagging any drift such as a newly created publicly accessible storage bucket. Which technology fits this need?

Explanation

CSPM continuously and automatically assesses cloud configuration against best practices, flagging drift like a newly created public storage bucket. A CASB focuses on cloud application usage visibility and policy enforcement rather than infrastructure configuration posture, container orchestration manages containerized workloads, an API gateway manages API traffic, and Terraform provisions infrastructure as code rather than continuously auditing existing configuration for drift.

Submit

17. A company implementing PKI splits responsibility so that one entity verifies the identity of certificate requestors while a separate entity actually issues the signed certificates, providing a separation of duties in the certificate lifecycle. Which PKI concept is this?

Explanation

Splitting identity verification from certificate issuance between separate entities is CA/RA separation, providing separation of duties. OCSP stapling optimizes real-time revocation checking, certificate templates standardize issuance profiles, certificate extensions add metadata fields, and deployment/integration approach concerns broader PKI rollout strategy rather than this specific division of verification and issuance responsibility.

Submit

18. A security team wants to measure how effective their deployed controls actually are in practice, running periodic tests and tracking specific metrics over time rather than just assuming controls work as designed. Which control effectiveness activity combination does this represent?

Explanation

Running periodic tests and tracking specific metrics over time to measure real-world control performance is assessments combined with metrics tracking. Classification models and labeling concern data sensitivity tagging, vulnerability management and hardening concern reducing weaknesses directly, sensor placement and alerting concern detection infrastructure, and DLP concerns preventing data loss rather than measuring how well existing controls are performing.

Submit

19. A development team wants a runtime protection layer embedded within their application itself that can detect and block attacks like SQL injection as they happen in production, using the application's own internal context rather than relying solely on an external network device. Which technology is this?

Explanation

Runtime application self-protection is embedded within the application itself, using internal context to detect and block attacks in production. A WAF and IPS are external network-layer or perimeter defenses rather than embedded within the application, DAST tests a running application from the outside before production, and SAST analyzes source code statically rather than protecting the application at runtime from within.

Submit

20. An architecture team ensures that a critical application can run correctly whether deployed in the primary cloud provider's environment or migrated to a secondary provider during a failover, without requiring proprietary features unique to only one provider. Which design consideration does this represent?

Explanation

Ensuring an application runs correctly across different provider environments without relying on proprietary features unique to one is interoperability. Persistence vs. non-persistence concerns state retention across sessions, vertical vs. horizontal scaling concerns capacity growth approach, geographical considerations concern physical resource placement, and recoverability only concerns restoring service after failure rather than cross-platform compatibility itself.

Submit

21. A network architect places one component in front of a cluster of web servers specifically to receive all inbound client requests and forward them to the appropriate backend server, shielding the actual servers' identities from direct external exposure. Separately, another component is placed at a key network chokepoint purely to passively duplicate traffic for monitoring tools, without sitting inline in the traffic path at all. Which two components are described, respectively?

Explanation

Shielding backend servers from direct exposure while forwarding inbound requests is a reverse proxy, while passively duplicating traffic without sitting inline is a tap. A forward proxy instead sits in front of clients rather than servers, a collector aggregates already-captured data, and an IPS sits inline and can actively block traffic rather than passively duplicating it.

Submit

22. A company deploying a generative AI chatbot discovers that a carefully crafted user input can bypass the model's content policy entirely, causing it to produce output it was explicitly designed never to generate. Which category of risk does this represent?

Explanation

Crafted input that bypasses a model's content policy entirely to produce explicitly prohibited output is a threat to the model, specifically circumventing its guardrails, closely related to jailbreaking. Overreliance describes human trust in AI output, legal and privacy implications generically covers broader ethical and policy concerns, excessive agency concerns an AI system acting beyond its intended scope, and model theft copies the model itself rather than bypassing its content restrictions.

Submit

23. A threat modeling team documents a specific way an attacker could combine several individually low-severity misconfigurations into a complete compromise path, showing each step from initial foothold to final objective. Which threat modeling method is this?

Explanation

Documenting a chained sequence of steps from initial foothold to final objective is an attack tree or graph. Abuse cases describe how a system could be misused from a user-interaction perspective, antipatterns document known bad design practices to avoid, enumeration/discovery identifies assets and accounts, and actor characteristics profile adversary motivation and capability rather than mapping a specific multi-step compromise path.

Submit

24. A company operating in multiple countries must specifically account for legal restrictions on transferring certain encryption technology across national borders when deploying its security tools internationally. Which cross-jurisdictional compliance concept is this?

Explanation

Legal restrictions on transferring encryption technology across borders are export controls. Due care concerns reasonable ongoing protective action, legal holds suspend data destruction for litigation purposes, contractual obligations concern agreement-based requirements, and e-discovery concerns identifying and producing electronic evidence for litigation rather than cross-border technology transfer restrictions.

Submit

25. A company discovers that sensitive customer records were accessed by an unauthorized party and must now determine appropriate notification timelines, forensic scope, and remediation steps as part of a coordinated organizational response. Which risk management activity is this?

Explanation

Coordinating notification timelines, forensic scope, and remediation after unauthorized access to sensitive records is breach response specifically. Crisis management addresses broader organizational disruption beyond just a data breach, impact analysis models potential scenarios before they occur, third-party risk management addresses vendor and supply chain risk, and confidentiality risk considerations generically is the broader category breach response is a specific activity within.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A company troubleshooting authentication issues discovers that a...
A SOC ingesting terabytes of daily log data configures automated...
An incident response team investigating an insider threat case reviews...
A threat hunting team specifically monitors underground forums and...
A penetration tester finds that a web application accepts a URL...
A SOC analyst reviewing historical network traffic notices a host that...
Match each cryptographic use case or technique to its correct...
A cryptography team evaluates whether their current RSA-based key...
A security team configures a system so that whenever a new critical...
A transportation company's traffic signal control systems must remain...
A hardware security team implements a boot process that records...
A network team investigating a service disruption discovers that an...
A security team notices that an attacker who gained initial...
A company maintains a database tracking every server, its owner, its...
A zero trust architecture team defines a highly restricted network...
A security team wants continuous, automated assurance that their cloud...
A company implementing PKI splits responsibility so that one entity...
A security team wants to measure how effective their deployed controls...
A development team wants a runtime protection layer embedded within...
An architecture team ensures that a critical application can run...
A network architect places one component in front of a cluster of web...
A company deploying a generative AI chatbot discovers that a carefully...
A threat modeling team documents a specific way an attacker could...
A company operating in multiple countries must specifically account...
A company discovers that sensitive customer records were accessed by...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!