{"id":21993,"date":"2026-09-25T10:24:20","date_gmt":"2026-09-25T10:24:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21993"},"modified":"2026-09-25T10:24:20","modified_gmt":"2026-09-25T10:24:20","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which security control is used to verify that software has not been modified after it was published?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature can help verify software integrity and authenticity. Software publishers can sign packages or executables using a private key, allowing recipients to validate the signature with the corresponding public key. If the software is modified after signing, signature verification should detect the change. Digital signatures can also help establish the identity associated with the signing certificate. Organizations should still obtain software from trusted sources and maintain secure certificate and key-management practices because a valid signature alone does not guarantee that software is completely safe.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>What is the PRIMARY purpose of network segmentation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase monitor resolution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce storage requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Limit unnecessary communication between systems<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation divides an environment into separate logical or physical security zones and controls communication between them. This limits unnecessary connectivity and can reduce lateral movement if an attacker compromises one system. Segmentation can be implemented using firewalls, VLANs, access control lists, software-defined networking, or microsegmentation technologies. It should reflect business requirements and documented communication flows. Segmentation does not replace authentication or endpoint security; instead, it provides another defensive layer that limits which systems can communicate with one another.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which capability allows security teams to collect logs from many systems into one location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Centralized logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk partitioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logging collects security and operational events from multiple systems into a common location. This improves visibility and makes it easier to correlate events across servers, endpoints, network devices, applications, and identity systems. Centralized logs can support incident detection, investigations, compliance reporting, and forensic analysis. They should be protected against unauthorized modification and retained according to organizational requirements. Technologies such as SIEM platforms commonly build upon centralized logging by adding correlation, analytics, alerting, and investigation capabilities.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>An organization wants to make stolen passwords less useful to attackers. Which control should be implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires additional verification beyond a password, such as a hardware token, authenticator application, or biometric factor. If an attacker obtains a user&#8217;s password, the additional factor can prevent access when the attacker cannot provide the required second factor. MFA is especially important for privileged accounts, remote access, cloud applications, and systems containing sensitive information. Organizations should use strong authentication methods and protect account-recovery processes because attackers may attempt to bypass MFA through social engineering or weak recovery mechanisms.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which process determines whether a security control is operating as intended?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software compilation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A control assessment evaluates whether a security control is properly designed, implemented, and operating effectively. Assessors may review configurations, documentation, logs, procedures, interviews, and technical test results. The purpose is to determine whether the control provides the intended protection and meets applicable requirements. Assessments can identify gaps that require remediation or additional safeguards. They are different from simply documenting that a control exists. Regular assessments are especially important after major infrastructure changes, security incidents, or changes to regulatory and business requirements.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>A company needs to ensure that only approved devices can access its internal network. Which technology is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control (NAC) can evaluate devices and users before or during network access and enforce policies based on organizational requirements. NAC can check device identity, security posture, authentication status, or other attributes before granting appropriate access. Noncompliant devices can be restricted or placed into remediation networks. RAID provides storage redundancy, SMTP handles email transmission, and a CDN distributes content. NAC is particularly useful in environments where organizations need to control access from managed endpoints, guest systems, or personally owned devices.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>Which principle requires an organization to collect only the data necessary for a specific business purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data duplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting, processing, and retaining only the information necessary for a legitimate and defined purpose. Reducing unnecessary data can lower privacy exposure, storage requirements, breach impact, and regulatory obligations. Organizations should identify why information is needed and avoid retaining it indefinitely when there is no business or legal requirement. Data minimization works alongside data classification, retention policies, access controls, and secure disposal. Collecting excessive information can create unnecessary risk because attackers may target information that an organization did not actually need to retain.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>A security engineer wants to prevent a web application from accepting malicious SQL commands through user input. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection prevention through parameterized queries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Time synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Parameterized queries separate SQL commands from user-supplied data and are an effective defense against SQL injection. Instead of allowing input to become part of an executable SQL statement, the application treats supplied values as data. Additional protections can include input validation, least-privileged database accounts, secure coding practices, and web application firewalls. Load balancing, compression, and time synchronization do not directly prevent SQL injection. Security testing should verify that input-handling controls remain effective across expected and unexpected application inputs.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>Which security mechanism can replace sensitive payment information with a non-sensitive substitute value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash cracking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive information with a token that can be used within approved systems without exposing the original value. The sensitive information is typically stored in a protected tokenization system, while other applications use the token instead. This can reduce the number of systems that directly handle sensitive payment information and may reduce the impact of a compromise. Tokenization is different from encryption because tokens do not necessarily contain the original value in a mathematically reversible form. Strong access controls and protection of the tokenization system remain essential.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which metric specifies how quickly a critical service should be restored after an outage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTBF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash value<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective (RTO) specifies the targeted maximum time within which a service or system should be restored after a disruption. Organizations use RTO values to design recovery strategies and determine whether technologies such as clustering, redundant infrastructure, or alternate processing locations are necessary. Recovery point objective (RPO) instead describes acceptable data loss measured in time. MTBF measures the expected time between failures, while a hash value supports integrity verification. Recovery requirements should be established according to business impact and operational priorities.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which control provides a record of actions performed by individual users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Auditing records user and system activities so organizations can determine who performed an action, when it occurred, and what resources were involved. Audit logs support accountability, incident investigation, compliance, and detection of suspicious behavior. Logging should capture appropriate events without unnecessarily collecting sensitive information, and logs should be protected from unauthorized modification. Shared accounts can weaken accountability because multiple individuals may appear as the same identity. Strong identity management combined with centralized and protected audit logging provides better attribution of security-relevant actions.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>A company wants to identify weaknesses before deploying a new application. Which activity should be performed during development?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted production access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security testing during development helps identify vulnerabilities before an application reaches production. Depending on the application and risk level, testing can include static analysis, dynamic testing, dependency analysis, authentication testing, authorization testing, and penetration testing. Finding weaknesses earlier generally provides more opportunity to correct design or implementation problems before deployment. Security testing should be integrated into the development lifecycle rather than treated as an activity performed only after release. Results should be documented, prioritized, remediated, and validated before production acceptance.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which technology is designed to analyze security events and correlate information from multiple sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security information and event management (SIEM) platform collects and correlates security events from multiple sources. It can combine logs from endpoints, servers, network devices, cloud services, identity systems, and applications to identify patterns that may indicate an attack. SIEM platforms commonly provide alerting, dashboards, investigation capabilities, and long-term event retention. RAID provides storage redundancy, DHCP assigns network configuration, and UPS provides power protection. Effective SIEM deployment requires appropriate log sources, useful detection rules, accurate timestamps, and regular tuning to reduce unnecessary alerts.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>A security team wants to reduce the damage caused if an attacker compromises one employee workstation. Which strategy is MOST effective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network architecture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted administrator access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation limits communication between systems and security zones, reducing the opportunities available to an attacker after compromising a workstation. Sensitive servers, administrative systems, and critical applications can be placed into separate zones with narrowly defined communication paths. This can restrict lateral movement and reduce the potential scope of an intrusion. A flat network provides broader connectivity, while shared credentials and unrestricted administrative access can increase the consequences of compromise. Segmentation should be combined with endpoint protection, identity controls, monitoring, and least privilege.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>Which activity helps an organization determine what information would be affected by a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Processor overclocking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen calibration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cable testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data classification categorizes information according to sensitivity, business value, regulatory requirements, or other defined criteria. Classification helps organizations determine which security controls should protect different types of information. During an incident, knowing whether affected data is public, internal, confidential, regulated, or highly sensitive can help determine response priorities, notification requirements, and potential impact. Classification should be supported by handling procedures, access controls, retention requirements, and secure disposal practices. Without appropriate classification, organizations may struggle to determine the significance of exposed information.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which approach provides temporary administrative privileges only when they are required?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time access provides elevated privileges for a limited period rather than keeping administrative permissions permanently active. This reduces the time during which privileged credentials can be abused and supports stronger control over high-risk activities. Organizations may require approval, authentication, justification, or ticket references before granting access. Once the authorized period ends, privileges are automatically removed or expire. Just-in-time access is commonly implemented with privileged access management and should be supported by logging and monitoring so administrative actions can be reviewed.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>An organization wants to identify whether a cloud provider&#8217;s security practices meet its requirements before using the service. What should be performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log removal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vendor risk assessment evaluates whether a provider&#8217;s security practices, controls, policies, and operational processes meet organizational requirements. For cloud services, the assessment may examine identity management, encryption, data location, incident response, vulnerability management, compliance, business continuity, subcontractors, and breach notification. Organizations should also review contractual responsibilities and independent assurance reports when appropriate. Vendor risk assessments help identify risks before sensitive information or critical workloads are transferred to a provider. The depth of assessment should reflect the service&#8217;s criticality and the sensitivity of the information involved.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which security control can isolate a compromised endpoint from the rest of the network while allowing security personnel to investigate it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR network isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID mirroring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Many endpoint detection and response (EDR) platforms provide network-isolation capabilities that can restrict a compromised endpoint&#8217;s communication while preserving security-team access for investigation. This can help contain malware, prevent lateral movement, and limit communication with command-and-control infrastructure. Isolation should be performed according to incident-response procedures because disconnecting a system may affect business operations or remove useful network evidence. Load balancing, RAID, and DNS caching do not provide endpoint containment. EDR isolation is one component of a broader incident-response and containment strategy.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>Which security requirement is MOST directly addressed by encrypting data stored on a database server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confidentiality<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scalability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption of stored database information primarily protects confidentiality by making the data unreadable without the appropriate cryptographic key. This can reduce exposure if storage media, database files, or backups are accessed by unauthorized parties. Encryption does not automatically provide availability or prove who performed an action. Effective database security should also include access controls, auditing, secure key management, backup protection, and vulnerability management. Encryption should be applied according to data sensitivity and risk because protecting the data without protecting the keys would provide limited security value.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>A company discovers that its incident response procedures have not been tested for several years. What should the security team do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the existing procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Conduct an incident response exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove escalation contacts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incident response exercise validates whether personnel, procedures, communication channels, technical controls, and decision-making processes work as expected during a security event. A tabletop exercise can begin with realistic scenarios and identify gaps without affecting production systems, while more advanced exercises can test technical response capabilities. Findings should be documented and used to update procedures, contact information, escalation paths, and response playbooks. Regular testing is important because environments and threats change over time, and an untested plan may fail when an actual incident occurs.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which security control is used to verify that software has not been modified after it was published? Load balancing Digital signature Network segmentation Data masking Correct Answer: 2 Explanation A digital signature can help verify software integrity and authenticity. Software publishers can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21993"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21993"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21993\/revisions"}],"predecessor-version":[{"id":21994,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21993\/revisions\/21994"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}