{"id":22009,"date":"2026-09-25T10:29:20","date_gmt":"2026-09-25T10:29:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22009"},"modified":"2026-09-25T10:29:20","modified_gmt":"2026-09-25T10:29:20","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which control provides a dedicated secure system for administrators to access isolated network devices?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Jump server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireless controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A jump server provides a controlled access point for administrators who need to manage systems within restricted network segments. Instead of allowing direct administrative connections from user workstations, organizations can require administrators to connect through a hardened jump server. This approach reduces the number of systems that can directly reach sensitive infrastructure and makes administrative activity easier to monitor and log. Jump servers are particularly useful for protecting management networks, critical servers, and infrastructure devices from unauthorized or uncontrolled administrative access.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>An organization discovers that a former employee&#8217;s account remained active for several weeks after termination. Which process should be improved to prevent this issue?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity lifecycle management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity lifecycle management controls the creation, modification, suspension, and removal of user identities throughout their employment. When an employee leaves, the associated account should be disabled or removed promptly according to organizational policy. Delays can allow unauthorized access to applications, data, and internal resources. Effective identity lifecycle processes normally integrate human resources events with identity and access management systems so that termination information triggers timely deprovisioning. Regular access reviews can also help identify accounts that should no longer exist or retain access.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which metric measures how long it takes an organization to detect a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time to Detect, or MTTD, measures the average time required to identify a security incident after it begins or becomes observable. A lower MTTD generally indicates that monitoring, alerting, and detection processes are identifying suspicious activity more quickly. Organizations can improve MTTD through centralized logging, SIEM correlation, endpoint monitoring, threat intelligence, and properly tuned detection rules. MTTD differs from MTTR, which focuses on the time required to respond to or recover from an identified incident.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>A security architect wants administrative traffic to remain separate from normal production traffic. Which design provides the strongest architectural separation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dedicated management network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared user VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public wireless network<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet-facing proxy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dedicated management network separates administrative communications from ordinary production and user traffic. Critical devices such as switches, routers, hypervisors, and security appliances can expose management interfaces only through this restricted network. Access can then be limited to authorized administrators using strong authentication and controlled management workstations or jump servers. This design reduces exposure to threats originating from user networks and makes administrative activity easier to monitor. It also helps prevent compromised user systems from directly reaching sensitive management interfaces.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which activity is most appropriate when an organization needs to determine whether a proposed system collects more personal information than necessary?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Penetration testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Privacy impact assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster recovery testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A privacy impact assessment evaluates how a system, process, or project collects, uses, stores, and shares personal information. It can identify unnecessary data collection, excessive retention, inappropriate access, and privacy-related risks before deployment. The assessment supports principles such as data minimization and purpose limitation. Penetration testing and vulnerability scanning primarily evaluate technical security weaknesses rather than whether personal information is being collected appropriately. Conducting a privacy impact assessment early in a project allows privacy concerns to be addressed during design instead of after implementation.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>A company wants to ensure that only approved devices can connect to internal network ports. Which technology is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WPA3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TLS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">802.1X provides port-based network access control by requiring a device or user to authenticate before gaining access to a protected network connection. It commonly works with an authentication server such as RADIUS and can be used with wired or wireless environments. Organizations can use 802.1X to prevent unauthorized devices from obtaining normal network connectivity. This approach is particularly useful when combined with certificates, identity-based policies, or network access control systems. WPA3 protects wireless communications, while TLS and DNSSEC address different security requirements.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which document identifies the individual accountable for accepting a specific organizational risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk register<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control matrix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business impact analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk ownership assignment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk owner is the individual or organizational role accountable for managing a particular risk and making decisions regarding its treatment. Assigning risk ownership establishes clear accountability for accepting, mitigating, transferring, or avoiding the risk. A risk register can document the risk and its owner, but the register itself does not create accountability. A control matrix maps controls to requirements or risks, while a business impact analysis evaluates consequences of disruptions. Clearly defined risk ownership helps prevent important security decisions from being left without an accountable decision maker.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>A company requires administrators to authenticate without entering passwords whenever possible. Which approach best supports this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Passwordless authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Passwordless authentication allows users to authenticate without relying on traditional passwords. Examples include hardware security keys, platform authenticators, biometrics combined with secure authentication mechanisms, and other phishing-resistant methods. This can reduce risks associated with password reuse, credential stuffing, phishing, and password theft. Passwordless authentication should still use strong identity verification and appropriate recovery processes. Shared accounts and static passwords weaken accountability and increase credential exposure. For privileged users, organizations should combine passwordless authentication with least privilege, privileged access management, and detailed audit logging.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which security measure helps ensure that a software package has not been modified after publication?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Digital signature verification can confirm that software was signed by a trusted publisher and that the signed content has not been altered since signing. The verification process uses the publisher&#8217;s public key to validate the signature against the software&#8217;s cryptographic content. If the package changes after signing, verification should fail. This provides integrity and can also support authenticity and nonrepudiation when the signing infrastructure is properly managed. Organizations should protect signing keys carefully because compromise of a trusted software-signing key could allow attackers to distribute maliciously modified software.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>An organization wants to reduce the security impact of a compromised application server. Which architectural approach is most effective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Using one shared administrator account<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing network boundaries<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segmenting critical services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segmenting critical services limits the ability of an attacker to move from a compromised application server into other sensitive systems. Security zones, firewalls, access control lists, and microsegmentation can restrict which systems are allowed to communicate. This reduces the potential blast radius of a compromise and provides additional opportunities to detect unauthorized activity. Removing network boundaries would increase exposure, while shared administrator accounts reduce accountability. Segmentation should be based on business and security requirements so that required application dependencies continue to function without unnecessarily broad connectivity.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which security control provides an independent copy of data that can be used after ransomware encrypts production files?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Immutable backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web application firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate authority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An immutable backup is designed so that stored backup data cannot be modified or deleted during a defined retention period. This makes immutable backups valuable against ransomware and destructive attacks that attempt to encrypt or erase both production data and recovery copies. Backups should also be protected with appropriate access controls and tested regularly through restoration exercises. Simply having a backup does not guarantee successful recovery. Organizations should verify that backup copies are complete, accessible, and capable of meeting recovery objectives such as the required RPO and RTO.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>A security team needs to determine whether a third-party vendor continues to meet contractual security requirements after onboarding. What should the team perform?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One-time vulnerability scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continuous vendor monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password reset<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deletion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous vendor monitoring evaluates whether third parties continue to meet security requirements throughout the relationship rather than relying only on an initial assessment. Monitoring can include security questionnaires, compliance reports, breach notifications, vulnerability information, external security ratings, audit evidence, and contractual attestations. Vendor risk can change because of new technologies, ownership changes, vulnerabilities, incidents, or changes in business processes. Ongoing monitoring helps organizations identify these changes and determine whether additional controls, remediation, or risk treatment decisions are necessary.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>Which technique replaces sensitive payment information with a non-sensitive substitute value?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive data with a token that has little or no exploitable value outside the authorized tokenization system. For example, a payment card number can be replaced with a token used by an application for transaction processing. The sensitive original value is maintained separately within a protected environment. Tokenization can reduce the exposure of sensitive information across applications and systems. Hashing and encryption serve different purposes: hashing is generally used for integrity or one-way transformations, while encryption is designed to protect data through reversible cryptographic transformation.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>A company wants to prevent a developer from approving their own production deployment. Which security principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Failover<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties requires sensitive responsibilities to be divided among different individuals or roles so that one person cannot independently complete an entire high-risk process. In a software environment, a developer might create code while another authorized person reviews or approves the production deployment. This reduces the opportunity for unauthorized changes and provides an independent control point. Separation of duties can be supported through workflow approvals, role-based access control, branch protections, and deployment permissions. It is particularly important for activities involving financial, production, or security-sensitive systems.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which cloud security capability is primarily focused on identifying configuration weaknesses across cloud environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSPM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Security Posture Management, or CSPM, focuses on identifying and helping remediate security configuration problems across cloud environments. Examples include publicly exposed storage, overly permissive identity policies, missing encryption settings, insecure network configurations, and deviations from approved security baselines. CSPM can continuously evaluate cloud resources against organizational policies and compliance requirements. DLP focuses on preventing inappropriate data disclosure, EDR monitors endpoints, and HSMs protect cryptographic keys. CSPM is therefore particularly useful for maintaining consistent security posture across complex and changing cloud deployments.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which recovery site is generally equipped and ready to begin operations with minimal delay?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hot site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Archive site<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hot site is a recovery facility that is maintained with systems, infrastructure, and resources needed to support rapid continuation of critical operations. Because it is already prepared, a hot site can significantly reduce recovery time compared with a cold site, which generally requires substantial setup before operations can resume. A warm site falls between the two and may require additional configuration or data restoration. The choice of recovery site depends on business requirements, budget, recovery objectives, and the consequences of prolonged service disruption.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>A security analyst receives an alert showing that a privileged account logged in from two geographically distant locations within minutes. What should the analyst investigate first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Possible impossible-travel authentication activity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database normalization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Logins from geographically distant locations within an unusually short period can indicate impossible-travel activity, credential theft, session hijacking, or another authentication anomaly. The analyst should correlate authentication logs with device information, timestamps, VPN activity, identity-provider events, and known user behavior. The activity may have legitimate explanations, such as corporate VPN gateways or remote access infrastructure, so context is important before concluding that an account was compromised. If malicious access is suspected, the organization may need to revoke sessions, reset credentials, investigate related activity, and preserve evidence.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which control helps verify that critical security configurations remain unchanged from an approved baseline?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration compliance monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration compliance monitoring compares current system settings against an approved security baseline and identifies deviations. Baselines can define requirements for operating systems, network devices, applications, cloud resources, and other infrastructure. Continuous or periodic monitoring helps identify unauthorized changes, configuration drift, and settings that no longer meet organizational standards. When deviations are discovered, administrators can investigate whether the change was authorized and remediate it when necessary. This control supports secure configuration management and provides evidence that systems continue to meet defined security requirements.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which cryptographic practice reduces the risk associated with a compromised encryption key by limiting how long the key remains usable?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log aggregation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Key rotation replaces cryptographic keys according to defined schedules or security events. Limiting the lifetime of a key reduces the amount of data that could potentially be exposed if that key is compromised. Effective key management should include secure generation, storage, distribution, rotation, revocation, and destruction procedures. Rotation schedules should reflect the sensitivity of the information, cryptographic algorithm, organizational requirements, and potential threat exposure. Automated key-management services can help organizations consistently enforce these practices across applications and infrastructure.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>During incident response, which activity is most directly associated with identifying why an incident occurred?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root-cause analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root-cause analysis seeks to determine the underlying conditions that allowed an incident to occur or continue. Analysts may review logs, configurations, vulnerabilities, authentication events, system changes, attack techniques, and user activity to identify the original weakness or failure. Understanding the root cause helps organizations implement corrective actions instead of addressing only the visible symptoms. For example, removing malware may resolve the immediate problem, while identifying the vulnerable service that enabled the compromise can help prevent recurrence. Root-cause analysis should be supported by reliable evidence collected during the investigation.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which control provides a dedicated secure system for administrators to access isolated network devices? Load balancer Proxy server Jump server Wireless controller Correct Answer: 3 Explanation A jump server provides a controlled access point for administrators who need to manage systems within [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22009"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22009"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22009\/revisions"}],"predecessor-version":[{"id":22010,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22009\/revisions\/22010"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22009"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22009"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22009"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}