{"id":22005,"date":"2026-09-25T10:28:51","date_gmt":"2026-09-25T10:28:51","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22005"},"modified":"2026-09-25T10:28:51","modified_gmt":"2026-09-25T10:28:51","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>Which security control provides evidence about who accessed a sensitive system and what actions were performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit logging records security-relevant activities such as user authentication, administrative actions, resource access, configuration changes, and other events. Proper audit logs can help establish accountability and support incident investigations, compliance reviews, and forensic analysis. Data compression reduces the size of information, network translation changes addressing information, and load balancing distributes traffic across systems. Audit logs should be protected from unauthorized modification, retained according to organizational requirements, and monitored for suspicious activity. Centralized collection can also improve visibility when multiple systems contribute evidence to an investigation.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>Which security principle limits a user to only the permissions necessary to perform assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege ensures that users, applications, and processes receive only the permissions required to perform their authorized tasks. Limiting privileges reduces the potential impact of compromised accounts, accidental actions, and insider misuse. Separation of duties distributes sensitive responsibilities among multiple individuals, while high availability focuses on maintaining service access. Defense in depth uses multiple layers of security controls. Least privilege should be applied throughout the identity lifecycle and reviewed periodically because permissions that were appropriate in the past may become excessive when responsibilities, projects, or organizational roles change.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>A company wants to identify systems that contain sensitive customer information before selecting additional security controls. What should be performed first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data discovery and classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate revocation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data discovery and classification help an organization identify where sensitive information exists and categorize it according to factors such as sensitivity, regulatory requirements, business value, or confidentiality. This information allows security teams to select appropriate controls based on the actual data being protected. Password synchronization manages authentication information, traffic shaping controls network bandwidth, and certificate revocation removes trust from compromised or invalid certificates. Data discovery can involve databases, file systems, cloud storage, applications, and other repositories. Accurate classification is important because security requirements should be aligned with the sensitivity of the information.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which security control is designed to block malicious web requests targeting application-layer vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN concentrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A web application firewall, or WAF, monitors and filters HTTP and HTTPS requests to help protect web applications from attacks such as SQL injection, cross-site scripting, malicious request patterns, and other application-layer threats. A VPN concentrator manages remote VPN connections, DHCP provides network configuration information, and RAID controllers support storage redundancy. A WAF should complement secure application development rather than replace it. Effective deployment requires appropriate rules, tuning, logging, and monitoring so legitimate application traffic remains available while suspicious requests are detected or blocked.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>Which process verifies that a security control meets its intended requirements before it is accepted for operational use?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control validation determines whether a security control has been implemented correctly and operates as intended. Validation may involve testing, inspection, documentation review, interviews, technical measurements, or other assessment techniques. The objective is to provide evidence that the control satisfies defined requirements before or during operational use. Data archiving focuses on retaining information, account synchronization manages identity information, and network translation modifies network addressing. Control validation is important because the existence of a security mechanism does not automatically demonstrate that it provides the expected level of protection.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>An organization wants to ensure that security requirements are considered during application design rather than after deployment. Which approach is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DevSecOps<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Post-incident analysis only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Emergency recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DevSecOps integrates security practices throughout software development and delivery rather than treating security as a final-stage activity. Security requirements can be incorporated into planning, coding, testing, dependency management, infrastructure provisioning, deployment, and monitoring. Automated security checks can help identify vulnerabilities earlier in the development lifecycle. Post-incident analysis is useful after an event but does not replace preventive development practices. Manual archiving and emergency recovery address different operational needs. DevSecOps promotes shared responsibility for security and helps organizations identify and remediate weaknesses before applications reach production.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>Which control can restrict access to a network based on the security state or identity of a connecting device?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network access control, or NAC, can evaluate devices and users before granting network access. Depending on the implementation, NAC may consider identity, device type, security posture, authentication status, or compliance with organizational requirements. A noncompliant device may be denied access, placed into a restricted network, or redirected for remediation. RAID provides storage redundancy, HSMs protect cryptographic keys, and DLP protects sensitive information from unauthorized disclosure. NAC is particularly useful for environments where unmanaged or noncompliant devices could introduce security risks to internal network resources.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>What is the primary security purpose of a certificate authority?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Issue and validate digital certificates<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compress network packets<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allocate IP addresses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Store backup images<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A certificate authority, or CA, issues and manages digital certificates that bind identities to public keys. Depending on the PKI architecture, the CA validates certificate requests, signs certificates, maintains certificate status information, and supports certificate revocation processes. Network packet compression reduces traffic size, IP address allocation is generally handled by services such as DHCP, and backup systems store recovery information. A trustworthy CA infrastructure is important because systems rely on certificates to establish authenticated relationships for activities such as secure web connections, device authentication, and encrypted communications.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>A company needs to determine whether its recovery procedures meet established recovery objectives. What should it conduct?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery testing verifies whether systems, data, procedures, personnel, and supporting infrastructure can restore operations according to established recovery requirements. Testing can reveal problems such as missing dependencies, incomplete backups, incorrect procedures, or unrealistic recovery time and data-loss expectations. Data classification identifies information sensitivity, password auditing evaluates authentication practices, and asset tagging helps identify resources. Recovery tests can range from tabletop exercises to technical restoration tests and full simulations. Results should be documented and used to improve continuity and disaster recovery plans.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>Which security control helps protect confidential data stored on a lost or stolen laptop?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full-disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port forwarding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Full-disk encryption protects data stored on a device by encrypting the contents of the storage medium. If a laptop is lost or stolen and an unauthorized person cannot obtain the required encryption credentials or keys, the stored information is significantly harder to access directly. Network load balancing distributes traffic, port forwarding redirects network connections, and log rotation manages stored log files. Full-disk encryption should be combined with strong authentication, secure key management, device management, and appropriate backup procedures because encryption alone does not protect against every endpoint threat.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which approach provides a centralized mechanism for applying authentication policies across multiple applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Federated identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Independent local accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Federated identity allows organizations to use trusted identity providers to authenticate users across multiple applications or services. Instead of maintaining separate authentication systems for every application, participating services can rely on established federation relationships and protocols. This can simplify identity management and allow centralized enforcement of authentication requirements such as multifactor authentication. Independent local accounts increase administrative overhead, shared passwords weaken accountability, and anonymous access removes meaningful identity verification. Federation is particularly useful in environments where users need secure access to applications operated by different organizations or service providers.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>Which security activity identifies potential attack paths between assets, vulnerabilities, and privileges?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attack path analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password history review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack path analysis examines how an adversary could move from an initial point of compromise toward valuable assets by exploiting vulnerabilities, excessive privileges, trust relationships, or network connectivity. It helps security teams understand combinations of weaknesses rather than viewing vulnerabilities independently. Data backup protects recovery information, certificate renewal maintains digital trust, and password history review helps prevent password reuse. Attack path analysis can support risk prioritization by showing which weaknesses could contribute to meaningful compromise. It is especially useful in complex environments containing interconnected systems and multiple privilege levels.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>Which security measure is most appropriate for protecting data while it is being transmitted between two systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption in transit<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deduplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption in transit protects information as it moves across networks by converting readable data into protected ciphertext that requires appropriate cryptographic keys for recovery. Secure protocols such as TLS can provide confidentiality and integrity for network communications. Data deduplication reduces duplicate storage, file compression reduces data size, and storage replication creates additional copies of information. Encryption in transit is important when sensitive data crosses untrusted or shared networks. Organizations should also validate certificates, use appropriate cryptographic configurations, and protect endpoints because secure transmission cannot compensate for compromised systems.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>A security team discovers that a privileged account has more permissions than required. What should be done first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove unnecessary privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create another privileged account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish the credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unnecessary privileges should be removed to restore least-privilege access. Excessive permissions increase the potential impact of compromised credentials, insider misuse, and accidental administrative actions. Creating another privileged account does not address the underlying overprivilege, while disabling monitoring removes visibility into potentially risky activity. Publishing credentials would create a serious security exposure. Organizations should document the required business justification for privileged access, review permissions regularly, and use privileged access management where appropriate. Privilege reduction should be coordinated with system owners so legitimate administrative responsibilities are not disrupted.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>Which metric is most useful for measuring how quickly an organization responds after detecting a confirmed security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTBF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean time to respond or remediate, commonly represented as MTTR depending on the organization&#8217;s defined measurement, evaluates how quickly security teams take effective response or recovery action after an issue is identified. It can help organizations assess incident-handling efficiency and identify process bottlenecks. RPO measures acceptable data loss, RTO measures targeted service recovery time, and MTBF measures average time between failures. Organizations should clearly define what starts and ends the MTTR measurement so results remain consistent and useful for operational improvement.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>Which technique reduces the risk of exposing real production data when developers need information for testing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network bridging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log deletion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data masking replaces or obscures sensitive production information so that developers can use realistic datasets without receiving unnecessary exposure to actual confidential or personal information. Depending on the requirement, masking can modify names, account numbers, addresses, or other sensitive fields while maintaining enough structure for testing. Password sharing increases credential exposure, network bridging connects network segments, and log deletion removes evidence. Data masking should be designed so sensitive values cannot be easily reconstructed and should be combined with access controls and appropriate test-environment security.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>Which control is designed to identify malicious activity occurring directly on an endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response, or EDR, monitors endpoint activity and provides security telemetry and response capabilities. It can detect suspicious processes, unusual file activity, unauthorized persistence mechanisms, malicious network connections, and other indicators of compromise. DNS resolves domain names, NAT translates network addresses, and DHCP provides network configuration information. EDR can support investigation by preserving endpoint telemetry and allowing analysts to examine processes, users, files, and connections associated with an event. It is commonly used as part of a broader security monitoring and incident response strategy.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>A company wants to ensure that encryption keys are replaced according to a defined schedule. Which process should be implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Key rotation replaces cryptographic keys according to defined lifecycle requirements. Regular rotation can limit the amount of information protected by a single key and reduce exposure if a key is compromised. Key rotation procedures should consider key generation, distribution, storage, activation, retirement, revocation, and secure destruction. Data replication creates copies of information, network segmentation separates systems, and file compression reduces data size. Organizations should carefully manage key dependencies because improper rotation can make encrypted data or services inaccessible if old keys are needed for decryption.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>Which security activity determines whether an organization has enough resources and procedures to continue critical operations during a major disruption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business continuity planning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business continuity planning identifies how an organization will maintain or restore critical business functions during disruptions. It considers personnel, facilities, technology, suppliers, communication methods, dependencies, and alternate operating arrangements. Password expiration manages authentication credentials, vulnerability scanning identifies technical weaknesses, and certificate pinning restricts trusted certificates or public keys. Business continuity planning is broader than technical disaster recovery because it considers the continuation of business processes as a whole. Plans should be tested and updated regularly to reflect changes in systems, personnel, suppliers, and organizational priorities.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>Which practice helps prevent unauthorized changes to infrastructure by requiring approval and documentation before implementation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous administration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted deployment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change management provides a structured process for requesting, reviewing, approving, implementing, and documenting changes to systems and infrastructure. Security-focused change management can require impact analysis, testing, approval, maintenance windows, rollback plans, and post-implementation verification. Anonymous administration and credential sharing reduce accountability, while unrestricted deployment can introduce uncontrolled changes and security weaknesses. Effective change management helps organizations maintain configuration consistency and provides an audit trail showing who authorized and implemented modifications. Emergency changes can follow expedited procedures while still requiring appropriate documentation and review.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 201 Which security control provides evidence about who accessed a sensitive system and what actions were performed? Audit logging Data compression Network translation Load balancing Correct Answer: 1 Explanation Audit logging records security-relevant activities such as user authentication, administrative actions, resource access, configuration [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22005"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22005"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22005\/revisions"}],"predecessor-version":[{"id":22006,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22005\/revisions\/22006"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22005"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22005"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}