{"id":21999,"date":"2026-09-25T10:28:02","date_gmt":"2026-09-25T10:28:02","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21999"},"modified":"2026-09-25T10:28:02","modified_gmt":"2026-09-25T10:28:02","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>Which security architecture principle requires access decisions to be continuously verified rather than automatically trusted?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero trust requires organizations to verify access requests rather than automatically trusting users or devices based on their network location. Access decisions can consider identity, device security, application context, resource sensitivity, and other conditions. This approach reduces the assumption that internal network traffic is inherently trustworthy. Open access and implicit trust weaken authorization controls, while shared credentials reduce accountability and make individual activity difficult to attribute. A zero-trust architecture typically combines strong authentication, least privilege, segmentation, continuous monitoring, and policy-based authorization to reduce unauthorized access opportunities.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>What is the primary purpose of a security governance committee?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configure individual workstations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Align security decisions with organizational objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace all technical administrators<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perform daily vulnerability scans<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security governance committee provides organizational oversight for security strategy, priorities, policies, and risk decisions. It helps align cybersecurity activities with business objectives, regulatory obligations, risk tolerance, and available resources. Such a committee does not normally replace technical administrators or perform routine operational tasks such as workstation configuration or daily vulnerability scanning. Governance establishes direction and accountability, while security operations implement and monitor controls. Effective governance can also help resolve conflicts between business requirements and security needs by ensuring that significant security decisions receive appropriate management attention.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>A company defines the maximum level of risk it is willing to accept while pursuing its objectives. What does this describe?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk appetite<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery point objective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security baseline<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk appetite describes the broad amount and type of risk an organization is willing to accept while achieving its strategic and operational objectives. It provides direction for risk decisions and helps determine whether proposed activities fall within acceptable boundaries. An RPO defines the maximum acceptable amount of data loss measured in time. A security baseline establishes expected configurations, while asset classification categorizes resources according to factors such as sensitivity or business importance. Risk appetite is generally established at an organizational level and can guide more specific risk tolerance and treatment decisions.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>Which technology is designed to provide centralized security policy enforcement and visibility for cloud application usage?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BIOS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A cloud access security broker, or CASB, provides security controls and visibility between an organization and cloud services. Depending on the implementation, CASB capabilities can include access control, data loss prevention, threat detection, activity monitoring, and compliance support. RAID provides storage redundancy, BIOS initializes hardware during system startup, and DHCP assigns network configuration information. CASB technology can be particularly useful when organizations use numerous cloud applications and need centralized security policies for controlling access to cloud-based resources and protecting sensitive information.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>Which activity is most appropriate for determining whether a third-party supplier introduces unacceptable security risk before contract approval?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor risk assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reset<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port scanning only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vendor risk assessment evaluates a supplier&#8217;s security practices, controls, compliance posture, data handling, incident response capabilities, and other factors before or during a business relationship. Organizations can use questionnaires, documentation reviews, audit reports, technical assessments, and contractual requirements to evaluate supplier risk. A password reset addresses individual account security, while log rotation manages stored logs. Port scanning may identify certain technical exposures but is not sufficient for evaluating an entire supplier relationship. Vendor risk assessments help organizations identify supply-chain risks before granting access to sensitive systems or data.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>An organization wants infrastructure configurations to be reviewed for security weaknesses before deployment. Which approach is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Infrastructure as Code scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Physical destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling configuration management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Infrastructure as Code, or IaC, scanning analyzes configuration files used to provision infrastructure and identifies insecure settings before deployment. It can detect issues such as excessive permissions, publicly exposed resources, weak encryption settings, and insecure network configurations. Finding these problems during development allows teams to correct them before production deployment. Physical destruction does not evaluate configuration security, manual password sharing creates additional security risk, and disabling configuration management removes important visibility and consistency. Integrating IaC security checks into CI\/CD pipelines can help make secure configuration validation a repeatable development practice.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>Which approach provides a documented mapping between security controls and regulatory or compliance requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deduplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control mapping establishes relationships between security controls and applicable regulatory, contractual, or organizational requirements. A single security control may satisfy requirements from multiple frameworks, allowing organizations to identify overlaps and reduce unnecessary duplication. Network translation changes addressing information, data deduplication removes duplicate data, and credential rotation replaces authentication secrets periodically. Control mapping can support audits, compliance assessments, and governance by showing how implemented safeguards address specific requirements. It also helps identify gaps where a regulatory or contractual requirement does not have an appropriate supporting control.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>A security team wants to automate repetitive incident-response actions after detecting a confirmed threat. Which technology is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SOAR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PKI<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security orchestration, automation, and response, or SOAR, helps security teams automate and coordinate repetitive response activities. For example, a SOAR platform may receive an alert, enrich it with threat intelligence, create an incident record, disable a compromised account, or request endpoint isolation according to approved workflows. RAID provides storage redundancy, VLANs provide network segmentation, and PKI manages digital certificates and public key infrastructure. SOAR can reduce manual workload and improve response consistency, but automated actions should be carefully controlled to prevent incorrect responses to false positives.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>Which cloud security capability continuously evaluates cloud resources against security configuration policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSPM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Security Posture Management, or CSPM, evaluates cloud environments for configuration weaknesses, policy violations, and compliance issues. It can identify problems such as publicly exposed storage, overly permissive access policies, missing encryption settings, or insecure configurations across supported cloud resources. SMTP is used for email transmission, NAT translates network addresses, and NTP synchronizes system clocks. CSPM is valuable because cloud environments can change rapidly and manual reviews may not provide continuous visibility. Automated posture monitoring allows security teams to identify and prioritize configuration issues before they result in security incidents.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which recovery site is generally equipped with systems and infrastructure that can support rapid business restoration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hot site is a recovery facility that is prepared with significant infrastructure and operational capabilities so critical business services can be restored relatively quickly after a major disruption. A cold site generally provides basic facilities but requires substantial preparation before operations can resume. A warm site provides an intermediate level of readiness and may require additional configuration or data restoration. Recovery-site selection depends on business requirements, budget, RTO, and operational priorities. Organizations should periodically test recovery arrangements to confirm that the selected site can support expected restoration objectives.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>What is the primary purpose of certificate pinning?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Restrict an application to trusted certificates or public keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase database storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign IP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compress network traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate pinning allows an application to associate a service with a specific trusted certificate or public key rather than relying only on the broader system trust store. This can help reduce certain man-in-the-middle risks when a fraudulent or unexpectedly issued certificate might otherwise be accepted. Certificate pinning must be carefully managed because improperly maintained pins can cause legitimate connections to fail after certificate changes. Database storage, IP addressing, and network compression are unrelated functions. Organizations should consider operational requirements and certificate lifecycle management when implementing this security mechanism.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>Which process helps ensure that former employees no longer retain access to organizational resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity deprovisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity deprovisioning removes or disables accounts and associated access when employees leave an organization or no longer require specific resources. Effective offboarding should address corporate applications, cloud services, VPN access, privileged accounts, physical access, and other relevant permissions. Data classification determines information sensitivity, log aggregation centralizes event records, and vulnerability scanning identifies technical weaknesses. Automated identity lifecycle processes can improve the speed and consistency of deprovisioning. Timely removal of unnecessary accounts is particularly important because abandoned credentials can provide attackers with legitimate-looking access to organizational resources.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>A security architect places a filtering component between two networks with different trust levels. What is this boundary commonly called?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trust boundary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broadcast domain<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A trust boundary is a point where the level of trust changes between systems, networks, applications, or components. Security controls can be placed at these boundaries to inspect, authenticate, filter, or restrict traffic crossing from one trust level to another. For example, a firewall may separate an internal network from a less trusted external network. A storage pool concerns data storage resources, a broadcast domain describes a network communication scope, and a recovery zone is not the general term for a change in trust. Identifying trust boundaries is an important part of secure architecture design.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>Which document provides a structured description of how information moves between systems and processing components?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data flow diagram<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident ticket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A data flow diagram, or DFD, illustrates how information moves between users, applications, processes, data stores, and external systems. Security architects can use DFDs to identify trust boundaries, sensitive information paths, external dependencies, and locations where security controls may be required. A password policy defines authentication requirements, an asset disposal record documents equipment disposal, and an incident ticket tracks a security event. Data flow analysis is particularly useful during architecture and threat-modeling activities because it helps teams understand where information enters, leaves, and changes within an environment.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which security control helps ensure that only authorized software packages are installed on managed endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Screen brightness policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network time synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting permits only approved applications or software components to execute or be installed according to defined organizational policies. This can reduce the risk of unauthorized software, malicious programs, and potentially unwanted applications being introduced onto managed endpoints. Screen brightness policies do not provide application security, data archiving concerns information retention, and time synchronization supports accurate timestamps. Allowlisting should be carefully maintained because legitimate software changes require policy updates. When combined with application control and endpoint monitoring, it can provide an additional layer of protection against unauthorized executable content.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>A company wants to verify that its employees can respond effectively to a simulated cyberattack without actually disrupting production. Which exercise is most suitable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tabletop exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Destructive penetration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Production shutdown<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware replacement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A tabletop exercise uses a simulated scenario to allow participants to discuss responsibilities, decisions, communication, escalation, and response procedures without directly disrupting production systems. It can reveal gaps in incident response plans, contact information, decision authority, and coordination between departments. A destructive penetration test could create operational risk if improperly controlled, while shutting down production is not a normal exercise requirement. Hardware replacement does not test incident response capabilities. Tabletop exercises are often used as a practical and relatively low-risk way to validate organizational preparedness.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>Which cryptographic approach is generally most appropriate for efficiently encrypting large volumes of stored data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Symmetric encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asymmetric encryption only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signatures only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Symmetric encryption uses the same secret key for encryption and decryption and is generally efficient for protecting large amounts of data. Algorithms based on symmetric cryptography can process substantial volumes of information with relatively low computational overhead compared with asymmetric operations. Asymmetric cryptography is commonly used for key exchange, authentication, and digital signatures rather than bulk encryption. Hashing provides integrity-related functions but is not reversible encryption, while digital signatures provide authenticity and integrity rather than confidentially encrypting large datasets. Many secure systems combine symmetric and asymmetric cryptography to benefit from the strengths of both approaches.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>A security team receives thousands of alerts from multiple monitoring systems. Which capability can help correlate and prioritize related events?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SIEM correlation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk defragmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security information and event management, or SIEM, platforms collect security-related events from multiple sources and can correlate them to identify patterns that may indicate malicious activity. Correlation rules can connect events such as repeated authentication failures, unusual administrative actions, and suspicious network connections into a more meaningful security alert. This helps analysts prioritize potentially significant incidents instead of reviewing every event independently. Disk defragmentation, file compression, and printer management do not provide centralized security event correlation. SIEM effectiveness depends on appropriate data sources, detection rules, tuning, and analyst workflows.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>Which privacy technique replaces identifying information with realistic but non-identifying values while retaining a relationship to the original data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pseudonymization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Token routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pseudonymization replaces direct identifiers with substitute values so that the data no longer directly identifies an individual without additional information. The original relationship can often be restored when the separately protected mapping information is available. This differs from irreversible anonymization, where the goal is to prevent re-identification. Network segmentation separates communication environments, token routing is not a general privacy technique, and data replication creates additional copies of information. Pseudonymization can reduce privacy exposure while allowing organizations to retain useful relationships within datasets for approved business or analytical purposes.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>A critical application must remain available when one server fails. Which architecture provides this capability by distributing service across multiple active servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-active clustering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-server deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual backup storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Offline archiving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An active-active architecture uses multiple operational servers that can simultaneously provide a service. If one server becomes unavailable, other active nodes can continue serving users, improving availability and reducing dependence on a single system. A single-server deployment creates a single point of failure, while manual backup storage and offline archiving primarily support data recovery rather than continuous service availability. Active-active designs require appropriate synchronization, load distribution, monitoring, and failure-handling mechanisms. They are commonly considered for applications where downtime would have significant operational or business consequences.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 141 Which security architecture principle requires access decisions to be continuously verified rather than automatically trusted? Zero trust Open access Implicit trust Shared credentials Correct Answer: 1 Explanation Zero trust requires organizations to verify access requests rather than automatically trusting users or devices [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21999"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21999"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21999\/revisions"}],"predecessor-version":[{"id":22000,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21999\/revisions\/22000"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}