{"id":21995,"date":"2026-09-25T10:24:48","date_gmt":"2026-09-25T10:24:48","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21995"},"modified":"2026-09-25T10:24:48","modified_gmt":"2026-09-25T10:24:48","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 101<\/b><\/h3>\n<p><b>Which security principle limits access to only the resources necessary for a specific task?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundancy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege ensures that users, applications, and systems receive only the permissions required to perform authorized tasks. Limiting permissions reduces the potential impact of compromised accounts, malicious activity, and accidental misuse. Privileges should be reviewed regularly and removed when no longer necessary. Role-based access control, privileged access management, and just-in-time access can help implement this principle. Least privilege should be applied to administrative accounts as well as application and service accounts because excessive permissions can provide attackers with additional opportunities for lateral movement.<\/span><\/p>\n<h3><b>Question 102<\/b><\/h3>\n<p><b>Which technology can detect suspicious activity by analyzing endpoint processes, files, and connections?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UPS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response (EDR) continuously collects security telemetry from endpoints and analyzes activities such as processes, file changes, network connections, and user behavior. EDR can generate alerts when suspicious patterns are detected and may provide response capabilities such as endpoint isolation. This visibility is valuable during both detection and investigation because analysts can examine what occurred on an individual system. RAID provides storage redundancy, DHCP supplies network configuration, and UPS provides power protection. EDR should be integrated with centralized monitoring and incident-response processes.<\/span><\/p>\n<h3><b>Question 103<\/b><\/h3>\n<p><b>What is the primary purpose of a compensating control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all security policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Provide an alternative safeguard when the preferred control cannot be implemented<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eliminate the need for risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all system monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides an alternative security measure when a required or preferred control cannot be implemented as originally intended. For example, if a legacy system cannot support a required security feature, network isolation, enhanced monitoring, or additional access restrictions may reduce the associated risk. The compensating control should provide an appropriate level of protection and be documented along with the reason it is required. Organizations should continue pursuing the preferred remediation where possible rather than treating the compensating control as a permanent replacement automatically.<\/span><\/p>\n<h3><b>Question 104<\/b><\/h3>\n<p><b>Which security technology is commonly used to protect web applications from malicious HTTP requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A web application firewall (WAF) filters HTTP and HTTPS traffic to protect web applications from attacks such as SQL injection, cross-site scripting, malicious requests, and certain application-layer abuse. WAF rules can be customized according to application requirements and threat conditions. A WAF should complement secure coding, vulnerability management, authentication controls, and application testing rather than replace them. RAID provides storage redundancy, NTP synchronizes system clocks, and DHCP provides network configuration. Proper tuning is important because overly restrictive WAF rules can block legitimate application traffic.<\/span><\/p>\n<h3><b>Question 105<\/b><\/h3>\n<p><b>A security architect needs to ensure that two critical administrative tasks are performed by different individuals. Which principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elasticity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among multiple individuals so that one person cannot complete a high-risk process without oversight. This reduces the opportunity for fraud, unauthorized changes, and abuse of privileged access. For example, one administrator may request a sensitive configuration change while another reviews and approves it. Separation of duties is particularly valuable for financial transactions, security administration, and other high-impact activities. It should be implemented carefully so that controls remain practical and do not create unnecessary operational delays or conflicts with legitimate emergency procedures.<\/span><\/p>\n<h3><b>Question 106<\/b><\/h3>\n<p><b>Which control helps identify whether an application contains known vulnerable third-party components?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Software composition analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk defragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software composition analysis (SCA) examines application dependencies and third-party components to identify known vulnerabilities, outdated packages, licensing concerns, and other risks. Modern applications frequently rely on open-source libraries, making dependency visibility important for software supply-chain security. SCA tools can compare component versions against vulnerability databases and help development teams prioritize updates. SCA does not replace source-code analysis or penetration testing because different security issues require different techniques. Organizations should maintain an inventory of software components and establish processes for responding to newly discovered dependency vulnerabilities.<\/span><\/p>\n<h3><b>Question 107<\/b><\/h3>\n<p><b>Which security measure protects a backup from being altered or deleted by ransomware affecting production systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immutable backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public file share<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted write access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable backups are designed so that stored backup data cannot be altered or deleted during a defined protection period. This can help protect recovery data from ransomware and other attacks that attempt to destroy backups before encrypting production systems. Immutability should be combined with access controls, separate credentials, monitoring, and regular restoration testing. Simply storing a backup on another server does not necessarily protect it if attackers can access that server using compromised administrative credentials. Organizations should also consider geographic separation and appropriate backup retention requirements.<\/span><\/p>\n<h3><b>Question 108<\/b><\/h3>\n<p><b>Which metric identifies the maximum acceptable period of data loss?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery point objective (RPO) identifies the amount of data loss an organization can tolerate, normally expressed as a period of time. For example, a 30-minute RPO indicates that recovery should ideally restore data to a point no more than 30 minutes before the disruption. RTO instead measures the targeted restoration time for a service. MTTR measures repair or recovery performance, while an SLA defines agreed service expectations. RPO requirements influence backup frequency, replication methods, and other data-protection strategies.<\/span><\/p>\n<h3><b>Question 109<\/b><\/h3>\n<p><b>An organization wants to prevent sensitive information from leaving endpoints through unauthorized USB devices. Which control is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint data loss prevention (DLP) can monitor and control sensitive information leaving endpoints through channels such as removable media, applications, email, or network connections. Policies can identify specific data types and block, alert, or require authorization for prohibited transfers. Organizations can also restrict USB storage through endpoint management policies, but DLP provides additional visibility into the information being transferred. DNS, load balancing, and NTP serve different infrastructure purposes. Endpoint controls should be designed carefully to protect sensitive information without unnecessarily disrupting legitimate business workflows.<\/span><\/p>\n<h3><b>Question 110<\/b><\/h3>\n<p><b>Which security practice BEST reduces the risk of unauthorized changes to production systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change management provides a controlled process for requesting, reviewing, approving, testing, implementing, and documenting changes to production systems. It helps organizations evaluate security and operational risks before modifications are introduced. Proper change management can require approvals, maintenance windows, rollback plans, testing evidence, and post-implementation verification. Emergency changes may follow an accelerated process but should still be documented and reviewed afterward. Shared passwords and unrestricted deployment weaken accountability and increase the possibility that unauthorized or poorly tested changes will affect production environments.<\/span><\/p>\n<h3><b>Question 111<\/b><\/h3>\n<p><b>Which capability allows an organization to verify that a user is authorized to perform a specific action after authentication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accounting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authorization determines what an authenticated user, application, or service is permitted to access or perform. Authentication establishes identity, while authorization evaluates permissions associated with that identity. For example, a user may successfully authenticate to an application but still be prohibited from viewing administrative settings. Effective authorization should follow least privilege and may use role-based, attribute-based, or policy-based access controls. Organizations should also log important authorization decisions so that inappropriate access can be detected and investigated.<\/span><\/p>\n<h3><b>Question 112<\/b><\/h3>\n<p><b>A security team wants to identify weaknesses caused by incorrect operating system settings across thousands of servers. Which solution would help most?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration compliance assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Video conferencing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration compliance assessments compare systems against approved security baselines or configuration standards. They can identify settings that violate organizational requirements, such as unnecessary services, weak authentication configurations, excessive permissions, or insufficient logging. Automated compliance tools can make this process practical across large server environments. Findings can then be prioritized and remediated through controlled configuration management. Configuration compliance is different from vulnerability scanning because a system can have a secure baseline issue even when no specific software vulnerability is detected.<\/span><\/p>\n<h3><b>Question 113<\/b><\/h3>\n<p><b>Which security concept assumes that access should be continuously verified rather than automatically trusted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero trust requires organizations to avoid automatically trusting users or devices based solely on network location or previous authentication. Access decisions should consider identity, device condition, resource sensitivity, and other relevant context. Continuous verification and least privilege can reduce the impact of compromised credentials and limit lateral movement. Zero trust does not mean that every request is denied; legitimate requests are evaluated against policy and granted only the required level of access. Organizations generally implement zero trust through multiple technologies and governance practices rather than a single product.<\/span><\/p>\n<h3><b>Question 114<\/b><\/h3>\n<p><b>Which control is MOST useful for protecting an encryption key from unauthorized administrative access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Plaintext storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware security module<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared spreadsheet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public repository<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security module (HSM) provides specialized protection for cryptographic keys and can perform cryptographic operations within a controlled hardware environment. HSMs can support secure key generation, storage, use, and management while providing strong access controls and auditing. Depending on the model, tamper-resistant features can provide additional protection. Storing keys in plaintext files, spreadsheets, or public repositories creates significant exposure. Organizations using HSMs should still establish appropriate key-management policies, administrative separation, backup procedures, and recovery processes to ensure keys remain protected and available when required.<\/span><\/p>\n<h3><b>Question 115<\/b><\/h3>\n<p><b>Which activity is MOST appropriate for determining whether a cloud provider meets organizational security requirements before onboarding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor security assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reuse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vendor security assessment evaluates the provider&#8217;s security controls, processes, compliance posture, data handling, incident response, availability, access management, and other relevant requirements. For a cloud provider, the organization should also examine the shared responsibility model and determine which controls remain the customer&#8217;s responsibility. Contracts should address important security obligations, notification requirements, audit rights, and data handling expectations where appropriate. The depth of assessment should reflect the sensitivity of the data and criticality of the service rather than applying exactly the same process to every vendor.<\/span><\/p>\n<h3><b>Question 116<\/b><\/h3>\n<p><b>Which attack specifically attempts to overwhelm a service with excessive traffic or requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DDoS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phishing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privilege escalation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A distributed denial-of-service (DDoS) attack attempts to make a service unavailable by overwhelming it with traffic, requests, or resource consumption. Distributed attacks commonly use many compromised systems, making simple blocking more difficult. Organizations can reduce exposure through DDoS protection services, rate limiting, traffic filtering, scalable architectures, redundant infrastructure, and appropriate incident-response procedures. DDoS attacks primarily target availability rather than directly seeking data theft. However, attackers may use a service disruption as a distraction while conducting other malicious activity, so monitoring should continue during the event.<\/span><\/p>\n<h3><b>Question 117<\/b><\/h3>\n<p><b>Which method provides evidence that a downloaded file has not changed since its expected version?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hash comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cryptographic hash produces a fixed-length value derived from data. Comparing the calculated hash of a downloaded file with a trusted reference value can help determine whether the file has changed. A mismatch indicates that the contents differ, although the hash alone does not establish who produced the file or whether the original file was trustworthy. Digital signatures can provide stronger authenticity and integrity assurances when a trusted signer is involved. Hash verification is commonly used for software downloads, forensic evidence, and file-integrity monitoring.<\/span><\/p>\n<h3><b>Question 118<\/b><\/h3>\n<p><b>A company wants to make security monitoring available even if its primary SIEM server fails. Which architecture is MOST appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-server deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundant SIEM infrastructure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual log deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-only logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Redundant SIEM infrastructure reduces dependence on a single monitoring component and helps maintain security visibility during failures. Organizations may use clustered systems, redundant collectors, replicated storage, geographically separated components, or cloud-based failover capabilities depending on their requirements. The design should also address log buffering so events are not lost during temporary outages. A single SIEM server creates a potential single point of failure, while local-only logging can make centralized investigation difficult. High availability should be tested periodically to verify that failover mechanisms operate as expected.<\/span><\/p>\n<h3><b>Question 119<\/b><\/h3>\n<p><b>Which security activity attempts to determine how an attacker could move from one compromised system to another?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack path analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage formatting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack path analysis examines how an attacker could progress through an environment after gaining an initial foothold. It can identify trust relationships, excessive permissions, exposed services, network connectivity, and other conditions that enable lateral movement or privilege escalation. Security architects can use this information to prioritize segmentation, identity controls, least privilege, monitoring, and other mitigations. Attack path analysis is particularly useful in complex enterprise and cloud environments where many systems are interconnected. It complements vulnerability management by considering how multiple weaknesses may combine into a practical attack route.<\/span><\/p>\n<h3><b>Question 120<\/b><\/h3>\n<p><b>A company discovers that an employee has excessive permissions that are no longer required. What should the organization do?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase the permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove unnecessary privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share the account with another employee<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unnecessary permissions should be removed to maintain least privilege and reduce the potential impact of account compromise or misuse. Access reviews should identify privileges that are no longer required because of role changes, project completion, organizational changes, or outdated access assignments. Organizations can automate parts of this process through identity governance and privileged access management solutions. Removing unnecessary access should be documented and performed through appropriate change procedures. Regular access recertification is important because excessive privileges can accumulate over time if organizations do not review them systematically.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 101 Which security principle limits access to only the resources necessary for a specific task? Availability Least privilege Nonrepudiation Redundancy Correct Answer: 2 Explanation Least privilege ensures that users, applications, and systems receive only the permissions required to perform authorized tasks. Limiting permissions [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21995"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21995"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21995\/revisions"}],"predecessor-version":[{"id":21996,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21995\/revisions\/21996"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}