CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps.

 

Question 241

Which control provides a dedicated secure system for administrators to access isolated network devices?

  1. Load balancer
  2. Proxy server
  3. Jump server
  4. Wireless controller

Correct Answer: 3

Explanation

A jump server provides a controlled access point for administrators who need to manage systems within restricted network segments. Instead of allowing direct administrative connections from user workstations, organizations can require administrators to connect through a hardened jump server. This approach reduces the number of systems that can directly reach sensitive infrastructure and makes administrative activity easier to monitor and log. Jump servers are particularly useful for protecting management networks, critical servers, and infrastructure devices from unauthorized or uncontrolled administrative access.

Question 242

An organization discovers that a former employee’s account remained active for several weeks after termination. Which process should be improved to prevent this issue?

  1. Identity lifecycle management
  2. Vulnerability scanning
  3. Network segmentation
  4. Data classification

Correct Answer: 1

Explanation

Identity lifecycle management controls the creation, modification, suspension, and removal of user identities throughout their employment. When an employee leaves, the associated account should be disabled or removed promptly according to organizational policy. Delays can allow unauthorized access to applications, data, and internal resources. Effective identity lifecycle processes normally integrate human resources events with identity and access management systems so that termination information triggers timely deprovisioning. Regular access reviews can also help identify accounts that should no longer exist or retain access.

Question 243

Which metric measures how long it takes an organization to detect a security incident?

  1. MTTR
  2. RPO
  3. RTO
  4. MTTD

Correct Answer: 4

Explanation

Mean Time to Detect, or MTTD, measures the average time required to identify a security incident after it begins or becomes observable. A lower MTTD generally indicates that monitoring, alerting, and detection processes are identifying suspicious activity more quickly. Organizations can improve MTTD through centralized logging, SIEM correlation, endpoint monitoring, threat intelligence, and properly tuned detection rules. MTTD differs from MTTR, which focuses on the time required to respond to or recover from an identified incident.

Question 244

A security architect wants administrative traffic to remain separate from normal production traffic. Which design provides the strongest architectural separation?

  1. Dedicated management network
  2. Shared user VLAN
  3. Public wireless network
  4. Internet-facing proxy

Correct Answer: 1

Explanation

A dedicated management network separates administrative communications from ordinary production and user traffic. Critical devices such as switches, routers, hypervisors, and security appliances can expose management interfaces only through this restricted network. Access can then be limited to authorized administrators using strong authentication and controlled management workstations or jump servers. This design reduces exposure to threats originating from user networks and makes administrative activity easier to monitor. It also helps prevent compromised user systems from directly reaching sensitive management interfaces.

Question 245

Which activity is most appropriate when an organization needs to determine whether a proposed system collects more personal information than necessary?

  1. Penetration testing
  2. Privacy impact assessment
  3. Vulnerability scanning
  4. Disaster recovery testing

Correct Answer: 2

Explanation

A privacy impact assessment evaluates how a system, process, or project collects, uses, stores, and shares personal information. It can identify unnecessary data collection, excessive retention, inappropriate access, and privacy-related risks before deployment. The assessment supports principles such as data minimization and purpose limitation. Penetration testing and vulnerability scanning primarily evaluate technical security weaknesses rather than whether personal information is being collected appropriately. Conducting a privacy impact assessment early in a project allows privacy concerns to be addressed during design instead of after implementation.

Question 246

A company wants to ensure that only approved devices can connect to internal network ports. Which technology is most appropriate?

  1. WPA3
  2. DNSSEC
  3. 802.1X
  4. TLS

Correct Answer: 3

Explanation

802.1X provides port-based network access control by requiring a device or user to authenticate before gaining access to a protected network connection. It commonly works with an authentication server such as RADIUS and can be used with wired or wireless environments. Organizations can use 802.1X to prevent unauthorized devices from obtaining normal network connectivity. This approach is particularly useful when combined with certificates, identity-based policies, or network access control systems. WPA3 protects wireless communications, while TLS and DNSSEC address different security requirements.

Question 247

Which document identifies the individual accountable for accepting a specific organizational risk?

  1. Risk register
  2. Control matrix
  3. Business impact analysis
  4. Risk ownership assignment

Correct Answer: 4

Explanation

A risk owner is the individual or organizational role accountable for managing a particular risk and making decisions regarding its treatment. Assigning risk ownership establishes clear accountability for accepting, mitigating, transferring, or avoiding the risk. A risk register can document the risk and its owner, but the register itself does not create accountability. A control matrix maps controls to requirements or risks, while a business impact analysis evaluates consequences of disruptions. Clearly defined risk ownership helps prevent important security decisions from being left without an accountable decision maker.

Question 248

A company requires administrators to authenticate without entering passwords whenever possible. Which approach best supports this requirement?

  1. Passwordless authentication
  2. Shared administrator accounts
  3. Static passwords
  4. Anonymous authentication

Correct Answer: 1

Explanation

Passwordless authentication allows users to authenticate without relying on traditional passwords. Examples include hardware security keys, platform authenticators, biometrics combined with secure authentication mechanisms, and other phishing-resistant methods. This can reduce risks associated with password reuse, credential stuffing, phishing, and password theft. Passwordless authentication should still use strong identity verification and appropriate recovery processes. Shared accounts and static passwords weaken accountability and increase credential exposure. For privileged users, organizations should combine passwordless authentication with least privilege, privileged access management, and detailed audit logging.

Question 249

Which security measure helps ensure that a software package has not been modified after publication?

  1. Network segmentation
  2. Digital signature verification
  3. Data masking
  4. Load balancing

Correct Answer: 2

Explanation

Digital signature verification can confirm that software was signed by a trusted publisher and that the signed content has not been altered since signing. The verification process uses the publisher’s public key to validate the signature against the software’s cryptographic content. If the package changes after signing, verification should fail. This provides integrity and can also support authenticity and nonrepudiation when the signing infrastructure is properly managed. Organizations should protect signing keys carefully because compromise of a trusted software-signing key could allow attackers to distribute maliciously modified software.

Question 250

An organization wants to reduce the security impact of a compromised application server. Which architectural approach is most effective?

  1. Disabling all logging
  2. Using one shared administrator account
  3. Removing network boundaries
  4. Segmenting critical services

Correct Answer: 4

Explanation

Segmenting critical services limits the ability of an attacker to move from a compromised application server into other sensitive systems. Security zones, firewalls, access control lists, and microsegmentation can restrict which systems are allowed to communicate. This reduces the potential blast radius of a compromise and provides additional opportunities to detect unauthorized activity. Removing network boundaries would increase exposure, while shared administrator accounts reduce accountability. Segmentation should be based on business and security requirements so that required application dependencies continue to function without unnecessarily broad connectivity.

Question 251

Which security control provides an independent copy of data that can be used after ransomware encrypts production files?

  1. Immutable backup
  2. Network address translation
  3. Web application firewall
  4. Certificate authority

Correct Answer: 1

Explanation

An immutable backup is designed so that stored backup data cannot be modified or deleted during a defined retention period. This makes immutable backups valuable against ransomware and destructive attacks that attempt to encrypt or erase both production data and recovery copies. Backups should also be protected with appropriate access controls and tested regularly through restoration exercises. Simply having a backup does not guarantee successful recovery. Organizations should verify that backup copies are complete, accessible, and capable of meeting recovery objectives such as the required RPO and RTO.

Question 252

A security team needs to determine whether a third-party vendor continues to meet contractual security requirements after onboarding. What should the team perform?

  1. One-time vulnerability scan
  2. Continuous vendor monitoring
  3. Password reset
  4. Data deletion

Correct Answer: 2

Explanation

Continuous vendor monitoring evaluates whether third parties continue to meet security requirements throughout the relationship rather than relying only on an initial assessment. Monitoring can include security questionnaires, compliance reports, breach notifications, vulnerability information, external security ratings, audit evidence, and contractual attestations. Vendor risk can change because of new technologies, ownership changes, vulnerabilities, incidents, or changes in business processes. Ongoing monitoring helps organizations identify these changes and determine whether additional controls, remediation, or risk treatment decisions are necessary.

Question 253

Which technique replaces sensitive payment information with a non-sensitive substitute value?

  1. Hashing
  2. Encryption
  3. Tokenization
  4. Compression

Correct Answer: 3

Explanation

Tokenization replaces sensitive data with a token that has little or no exploitable value outside the authorized tokenization system. For example, a payment card number can be replaced with a token used by an application for transaction processing. The sensitive original value is maintained separately within a protected environment. Tokenization can reduce the exposure of sensitive information across applications and systems. Hashing and encryption serve different purposes: hashing is generally used for integrity or one-way transformations, while encryption is designed to protect data through reversible cryptographic transformation.

Question 254

A company wants to prevent a developer from approving their own production deployment. Which security principle should be applied?

  1. Data minimization
  2. Separation of duties
  3. Defense in depth
  4. Failover

Correct Answer: 2

Explanation

Separation of duties requires sensitive responsibilities to be divided among different individuals or roles so that one person cannot independently complete an entire high-risk process. In a software environment, a developer might create code while another authorized person reviews or approves the production deployment. This reduces the opportunity for unauthorized changes and provides an independent control point. Separation of duties can be supported through workflow approvals, role-based access control, branch protections, and deployment permissions. It is particularly important for activities involving financial, production, or security-sensitive systems.

Question 255

Which cloud security capability is primarily focused on identifying configuration weaknesses across cloud environments?

  1. CSPM
  2. DLP
  3. EDR
  4. HSM

Correct Answer: 1

Explanation

Cloud Security Posture Management, or CSPM, focuses on identifying and helping remediate security configuration problems across cloud environments. Examples include publicly exposed storage, overly permissive identity policies, missing encryption settings, insecure network configurations, and deviations from approved security baselines. CSPM can continuously evaluate cloud resources against organizational policies and compliance requirements. DLP focuses on preventing inappropriate data disclosure, EDR monitors endpoints, and HSMs protect cryptographic keys. CSPM is therefore particularly useful for maintaining consistent security posture across complex and changing cloud deployments.

Question 256

Which recovery site is generally equipped and ready to begin operations with minimal delay?

  1. Cold site
  2. Warm site
  3. Hot site
  4. Archive site

Correct Answer: 3

Explanation

A hot site is a recovery facility that is maintained with systems, infrastructure, and resources needed to support rapid continuation of critical operations. Because it is already prepared, a hot site can significantly reduce recovery time compared with a cold site, which generally requires substantial setup before operations can resume. A warm site falls between the two and may require additional configuration or data restoration. The choice of recovery site depends on business requirements, budget, recovery objectives, and the consequences of prolonged service disruption.

Question 257

A security analyst receives an alert showing that a privileged account logged in from two geographically distant locations within minutes. What should the analyst investigate first?

  1. Possible impossible-travel authentication activity
  2. Backup retention
  3. Certificate expiration
  4. Database normalization

Correct Answer: 1

Explanation

Logins from geographically distant locations within an unusually short period can indicate impossible-travel activity, credential theft, session hijacking, or another authentication anomaly. The analyst should correlate authentication logs with device information, timestamps, VPN activity, identity-provider events, and known user behavior. The activity may have legitimate explanations, such as corporate VPN gateways or remote access infrastructure, so context is important before concluding that an account was compromised. If malicious access is suspected, the organization may need to revoke sessions, reset credentials, investigate related activity, and preserve evidence.

Question 258

Which control helps verify that critical security configurations remain unchanged from an approved baseline?

  1. Data classification
  2. Configuration compliance monitoring
  3. Network address translation
  4. Email filtering

Correct Answer: 2

Explanation

Configuration compliance monitoring compares current system settings against an approved security baseline and identifies deviations. Baselines can define requirements for operating systems, network devices, applications, cloud resources, and other infrastructure. Continuous or periodic monitoring helps identify unauthorized changes, configuration drift, and settings that no longer meet organizational standards. When deviations are discovered, administrators can investigate whether the change was authorized and remediate it when necessary. This control supports secure configuration management and provides evidence that systems continue to meet defined security requirements.

Question 259

Which cryptographic practice reduces the risk associated with a compromised encryption key by limiting how long the key remains usable?

  1. Key rotation
  2. Data compression
  3. Network segmentation
  4. Log aggregation

Correct Answer: 1

Explanation

Key rotation replaces cryptographic keys according to defined schedules or security events. Limiting the lifetime of a key reduces the amount of data that could potentially be exposed if that key is compromised. Effective key management should include secure generation, storage, distribution, rotation, revocation, and destruction procedures. Rotation schedules should reflect the sensitivity of the information, cryptographic algorithm, organizational requirements, and potential threat exposure. Automated key-management services can help organizations consistently enforce these practices across applications and infrastructure.

Question 260

During incident response, which activity is most directly associated with identifying why an incident occurred?

  1. Account provisioning
  2. Root-cause analysis
  3. Data classification
  4. Certificate enrollment

Correct Answer: 2

Explanation

Root-cause analysis seeks to determine the underlying conditions that allowed an incident to occur or continue. Analysts may review logs, configurations, vulnerabilities, authentication events, system changes, attack techniques, and user activity to identify the original weakness or failure. Understanding the root cause helps organizations implement corrective actions instead of addressing only the visible symptoms. For example, removing malware may resolve the immediate problem, while identifying the vulnerable service that enabled the compromise can help prevent recurrence. Root-cause analysis should be supported by reliable evidence collected during the investigation.