{"id":21991,"date":"2026-09-25T10:23:58","date_gmt":"2026-09-25T10:23:58","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21991"},"modified":"2026-09-25T10:23:58","modified_gmt":"2026-09-25T10:23:58","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 61<\/b><\/h3>\n<p><b>Which security control is designed to detect unauthorized changes to important system configurations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring detects changes to files, configurations, and other protected resources. It can compare current values against approved baselines and alert security personnel when unexpected modifications occur. This is useful for detecting unauthorized changes caused by malware, attackers, or accidental administrative activity. Monitoring should be configured for critical files and directories while allowing legitimate changes to be documented. Load balancing, NAT, and compression perform different technical functions and do not directly provide the same capability for identifying unauthorized configuration modifications.<\/span><\/p>\n<h3><b>Question 62<\/b><\/h3>\n<p><b>Which security architecture places security controls as close as possible to individual workloads rather than relying only on a network perimeter?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsegmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter bypass<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation applies security policies at a granular level around individual workloads, applications, or services. Instead of trusting systems simply because they exist inside a corporate network, microsegmentation restricts communication according to defined requirements. This can limit lateral movement if an attacker compromises one workload. Policies may be enforced through host-based controls, software-defined networking, cloud security groups, or other mechanisms. Microsegmentation is especially useful in dynamic environments where workloads frequently move or scale and traditional perimeter-based controls cannot provide sufficient internal isolation.<\/span><\/p>\n<h3><b>Question 63<\/b><\/h3>\n<p><b>A security team needs to detect malicious activity across endpoints and provide investigators with detailed process information. Which solution is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response (EDR) solutions collect telemetry from endpoints and provide visibility into processes, files, network connections, user activity, and other security-relevant events. Analysts can use this information to investigate suspicious behavior and determine how an attack progressed. Many EDR platforms also support containment actions such as isolating a compromised endpoint. UPS systems provide power protection, RAID provides storage redundancy, and DNS resolves names. EDR is particularly valuable when endpoint-level investigation is required because it provides information that network-only monitoring may not capture.<\/span><\/p>\n<h3><b>Question 64<\/b><\/h3>\n<p><b>Which activity should occur before implementing a major security architecture change?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk assessment helps organizations identify potential threats, vulnerabilities, impacts, and security requirements before implementing significant architectural changes. The assessment can reveal new attack paths, dependencies, compliance concerns, and operational risks. Security teams can then select appropriate controls and determine whether the proposed design meets organizational risk tolerance. Major changes made without assessment may unintentionally weaken existing protections. Credential sharing and log deletion introduce additional risks, while unrestricted deployment provides no structured validation. Risk assessment should be integrated with change management and architecture review processes.<\/span><\/p>\n<h3><b>Question 65<\/b><\/h3>\n<p><b>A company uses a public cloud provider for sensitive workloads. Which responsibility generally remains with the customer in an IaaS environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical data center security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hypervisor maintenance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guest operating system security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Building access control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In an Infrastructure as a Service environment, the cloud provider generally manages the physical infrastructure, facilities, and virtualization layer, while the customer remains responsible for many controls within the guest environment. These commonly include operating system configuration, application security, identity management, data protection, and network security settings, depending on the provider and service. The exact shared responsibility model varies by provider and service. Organizations should review provider documentation carefully instead of assuming that cloud deployment transfers all security responsibilities to the provider.<\/span><\/p>\n<h3><b>Question 66<\/b><\/h3>\n<p><b>Which authentication method provides the strongest protection against many forms of phishing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password-only authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security questions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware security key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared secret<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hardware security keys that support modern phishing-resistant authentication methods can provide strong protection against credential phishing because authentication is cryptographically tied to the legitimate service. Unlike passwords, a properly implemented security key does not simply provide a reusable secret that an attacker can capture and replay. Password-only authentication and security questions are more susceptible to phishing, credential theft, and reuse. Organizations should combine phishing-resistant authentication with strong identity governance, appropriate recovery procedures, and monitoring to reduce account compromise risks across critical services.<\/span><\/p>\n<h3><b>Question 67<\/b><\/h3>\n<p><b>Which process helps determine the potential consequences if a critical business service becomes unavailable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Code signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business impact analysis determines how disruptions affect critical business functions and identifies the consequences of downtime. It can establish recovery priorities, dependencies, acceptable downtime, financial impacts, regulatory concerns, and requirements for restoring services. These findings help organizations establish recovery time and recovery point objectives and select suitable continuity strategies. Vulnerability scanning identifies technical weaknesses, code signing supports software integrity and authenticity, and certificate renewal maintains valid certificates. A BIA should involve business stakeholders because operational consequences may not be fully understood by technical teams.<\/span><\/p>\n<h3><b>Question 68<\/b><\/h3>\n<p><b>A security analyst notices repeated failed login attempts followed by a successful login from an unusual geographic location. What should the analyst do FIRST?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the event<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Investigate the authentication activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all organizational accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated failed authentication attempts followed by a successful login from an unusual location can indicate credential attacks or account compromise. The analyst should investigate the activity using authentication logs, identity-provider records, endpoint telemetry, VPN information, and other relevant evidence. If compromise is confirmed or strongly suspected, incident response procedures may require actions such as session revocation, credential reset, or account containment. Deleting logs would destroy evidence, while disabling every account is unnecessarily disruptive. Investigation should be guided by documented incident-response procedures and risk.<\/span><\/p>\n<h3><b>Question 69<\/b><\/h3>\n<p><b>Which technology can inspect network traffic and automatically block detected malicious activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An intrusion prevention system (IPS) monitors network traffic and can take preventive action when activity matches defined malicious or suspicious patterns. Depending on its configuration, an IPS can block packets, terminate connections, or apply other response mechanisms. An intrusion detection system primarily detects and alerts without directly preventing the traffic. Syslog provides a mechanism for transmitting log messages, while SNMP is commonly used for network management and monitoring. IPS effectiveness depends on appropriate rule configuration, current detection content, proper placement, and regular tuning to minimize false positives.<\/span><\/p>\n<h3><b>Question 70<\/b><\/h3>\n<p><b>An organization wants to prevent administrators from accessing systems unless they have an approved business need. Which approach BEST supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privileged access management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared root credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent unrestricted privileges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged access management (PAM) controls and monitors access to high-risk administrative accounts. PAM can require approvals, enforce just-in-time access, rotate credentials, record privileged sessions, and limit access based on business requirements. These controls reduce the risk associated with permanent administrative privileges and provide stronger accountability for sensitive actions. Shared credentials make individual accountability difficult, while unrestricted or permanent access increases exposure. PAM should be integrated with identity management, multifactor authentication, logging, and periodic access reviews for effective privileged-account governance.<\/span><\/p>\n<h3><b>Question 71<\/b><\/h3>\n<p><b>Which control is MOST useful for protecting data if a company laptop is stolen?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full-disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen brightness<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Full-disk encryption protects information stored on a device by encrypting the contents of the storage media. If a laptop is lost or stolen and the attacker cannot obtain the necessary authentication or cryptographic keys, accessing the stored information becomes significantly more difficult. Encryption should be supported by secure key management, strong authentication, and appropriate device-management controls. Screen locking can provide additional protection when a device is unattended, but it is not equivalent to protecting the underlying storage. Network load balancing and DNS caching do not protect locally stored data.<\/span><\/p>\n<h3><b>Question 72<\/b><\/h3>\n<p><b>Which security activity identifies the systems, applications, and data that an organization owns or manages?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hashing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An asset inventory identifies and tracks organizational hardware, software, services, data repositories, and other resources. Accurate inventories are fundamental to security because organizations cannot effectively protect systems they do not know exist. Inventory information can include ownership, location, business purpose, classification, software versions, and lifecycle status. Security teams can use this information for vulnerability management, patching, risk assessment, incident response, and compliance activities. Inventories should be maintained continuously because cloud resources, applications, endpoints, and other assets can change frequently.<\/span><\/p>\n<h3><b>Question 73<\/b><\/h3>\n<p><b>A company needs to securely exchange sensitive information with an external business partner. Which control should be prioritized?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared public passwords<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption protects sensitive information from unauthorized disclosure while it is being transmitted or stored. When exchanging data with an external partner, organizations should select secure protocols and establish appropriate authentication, key management, and trust relationships. Depending on the use case, secure file-transfer services, encrypted email, VPN connections, or application-level encryption may be appropriate. Plaintext transmission and shared passwords can expose information to interception and credential compromise. Security requirements should also address data classification, retention, logging, and responsibilities between the participating organizations.<\/span><\/p>\n<h3><b>Question 74<\/b><\/h3>\n<p><b>Which security testing method attempts to discover weaknesses by analyzing application source code without executing it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DAST<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SAST<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stress testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Static application security testing (SAST) analyzes source code, bytecode, or other application representations without requiring the application to execute. It can identify coding weaknesses such as insecure functions, injection risks, hardcoded secrets, and certain authentication or authorization problems. Dynamic application security testing (DAST) evaluates a running application from an external perspective. Load and stress testing primarily evaluate performance and capacity. SAST is most effective when integrated early into the development lifecycle, allowing developers to identify and remediate issues before applications reach production.<\/span><\/p>\n<h3><b>Question 75<\/b><\/h3>\n<p><b>A security team wants to ensure that an application cannot directly access sensitive resources unless explicitly authorized. Which principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits applications, services, users, and processes to the minimum permissions required for their legitimate functions. Applying this principle to applications can reduce the impact of compromised software or exploited vulnerabilities. For example, an application that only needs read access to a database should not receive unrestricted administrative permissions. Least privilege should be combined with strong identity controls, segmentation, logging, and regular permission reviews. Excessive privileges can allow attackers to move from a compromised application to additional resources and significantly increase the consequences of an intrusion.<\/span><\/p>\n<h3><b>Question 76<\/b><\/h3>\n<p><b>Which document defines the specific actions personnel should follow during a cybersecurity incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset purchase order<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network topology diagram<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software license<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incident response plan defines how an organization prepares for, detects, analyzes, contains, eradicates, and recovers from security incidents. It can identify roles, responsibilities, escalation paths, communication requirements, evidence-handling procedures, and decision criteria. Supporting playbooks can provide more detailed instructions for specific scenarios such as ransomware, credential compromise, or data breaches. A network diagram can support investigations but does not define the overall response process. Incident response plans should be tested periodically through exercises and updated when systems, threats, regulations, or organizational responsibilities change.<\/span><\/p>\n<h3><b>Question 77<\/b><\/h3>\n<p><b>A company wants to detect whether employees are sending confidential files to unauthorized external recipients. Which technology is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data loss prevention (DLP) solutions can identify sensitive information and enforce policies governing how that information is transmitted or shared. A DLP system may inspect email content, attachments, endpoint activity, cloud uploads, or other data channels and generate alerts or block prohibited transfers. Policies can be based on classifications, patterns, keywords, or other detection mechanisms. DHCP, RAID, and NAT do not directly inspect organizational information for unauthorized disclosure. DLP should be carefully configured because overly broad policies can interrupt legitimate business communication and create excessive alerts.<\/span><\/p>\n<h3><b>Question 78<\/b><\/h3>\n<p><b>Which technique can reduce the impact of a compromised account by requiring additional approval before privileged access is granted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privileged access provides elevated permissions only when they are needed and, in many implementations, for a limited period. Access may require approval, a documented request, or other validation before privileges are activated. Once the approved period ends, elevated permissions are removed. This reduces the exposure created by permanently active administrative privileges and makes unauthorized use more difficult. Just-in-time access works particularly well with privileged access management, multifactor authentication, logging, and strong approval processes.<\/span><\/p>\n<h3><b>Question 79<\/b><\/h3>\n<p><b>An organization wants to verify that backups can actually restore critical applications. What should it perform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup restoration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log suppression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall removal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Backup restoration testing verifies that stored backups are usable and that critical applications and data can be recovered within established requirements. A backup that has never been tested may be incomplete, corrupted, improperly configured, or dependent on unavailable systems or credentials. Testing should cover different recovery scenarios and validate data integrity, application dependencies, access to encryption keys, and recovery objectives. Results should be documented and used to improve backup procedures. Restoration testing is especially important for ransomware resilience because attackers may target both production systems and backup infrastructure.<\/span><\/p>\n<h3><b>Question 80<\/b><\/h3>\n<p><b>A security architect wants to reduce the number of systems that directly handle sensitive payment information. Which approach would BEST support this objective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization and tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized plaintext storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization reduces the amount of sensitive information collected, stored, and processed, which can reduce the overall attack surface. Tokenization can further reduce exposure by replacing sensitive values with tokens that have limited usefulness outside the approved processing environment. Together, these approaches can reduce the number of systems that directly handle payment information and may simplify security and compliance requirements. Unrestricted replication and plaintext storage increase exposure, while shared administrator accounts weaken accountability. Organizations should design data flows so sensitive information reaches only systems with a legitimate business requirement.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 61 Which security control is designed to detect unauthorized changes to important system configurations? File integrity monitoring Load balancing Network address translation Data compression Correct Answer: 1 Explanation File integrity monitoring detects changes to files, configurations, and other protected resources. It can compare [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21991"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21991"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21991\/revisions"}],"predecessor-version":[{"id":21992,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21991\/revisions\/21992"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21991"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21991"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}