{"id":22015,"date":"2026-09-25T10:30:03","date_gmt":"2026-09-25T10:30:03","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22015"},"modified":"2026-09-25T10:30:03","modified_gmt":"2026-09-25T10:30:03","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301<\/b><\/h3>\n<p><b>Which security mechanism is specifically designed to verify that a digital certificate has not been revoked?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OCSP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Online Certificate Status Protocol, or OCSP, allows systems to query whether a digital certificate is currently valid or has been revoked by the issuing certificate authority. This provides more current certificate status information than relying solely on periodically downloaded certificate revocation lists. Certificate validation is important because a certificate may need to be revoked before its normal expiration date if its private key is compromised or other trust conditions change. Organizations should also consider certificate lifecycle management, trusted certificate authorities, and secure private-key protection.<\/span><\/p>\n<h3><b>Question 302<\/b><\/h3>\n<p><b>A company wants to prevent a compromised workstation from communicating with servers in a high-security zone. Which control should be implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate archiving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network segmentation separates systems into security zones and restricts communication between those zones. A compromised workstation can therefore be prevented from directly reaching highly sensitive servers when appropriate firewall rules or access controls are enforced. Segmentation limits lateral movement and reduces the potential impact of an endpoint compromise. Security architects should identify required communication paths and explicitly permit only necessary connections. For especially sensitive environments, microsegmentation can provide more granular controls by applying policies to individual workloads rather than relying only on broad network boundaries.<\/span><\/p>\n<h3><b>Question 303<\/b><\/h3>\n<p><b>Which activity provides evidence that a backup can actually be used to restore a critical application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup restoration test<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A backup restoration test verifies that stored backup data can be successfully recovered and used to restore the required systems or information. A backup process may appear successful while still producing incomplete, corrupted, or unusable recovery data. Testing can identify problems involving backup integrity, dependencies, credentials, storage access, application configuration, or restoration procedures. Organizations should conduct restoration tests according to business requirements and document the results. Testing also helps determine whether actual recovery performance meets established RTO and RPO objectives.<\/span><\/p>\n<h3><b>Question 304<\/b><\/h3>\n<p><b>Which control is most appropriate for protecting cryptographic keys used by critical applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network tap<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security module, or HSM, is a specialized device designed to securely generate, store, process, and manage cryptographic keys. HSMs can protect private keys from unauthorized extraction and may provide tamper-resistant security features. They are commonly used for certificate authorities, payment systems, digital signing, encryption services, and other applications where key protection is critical. Proper key lifecycle management remains necessary even when HSMs are deployed. Organizations should define procedures for key generation, rotation, backup, recovery, revocation, and destruction.<\/span><\/p>\n<h3><b>Question 305<\/b><\/h3>\n<p><b>An organization wants to determine which systems would be affected if a critical database becomes unavailable. Which activity should be performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate revocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Media sanitization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dependency mapping identifies relationships between systems, applications, services, data stores, and business processes. When a critical database becomes unavailable, dependency information can show which applications rely on it and which downstream services could be disrupted. This information supports business continuity planning, disaster recovery design, risk analysis, and incident response. Accurate dependency maps should be reviewed periodically because infrastructure and application relationships change over time. Understanding dependencies also helps organizations prioritize recovery activities and identify single points of failure within critical services.<\/span><\/p>\n<h3><b>Question 306<\/b><\/h3>\n<p><b>Which approach allows an organization to require additional authentication when a user attempts access from an unusual location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adaptive authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Adaptive authentication evaluates contextual information and can increase authentication requirements when risk indicators change. For example, a user logging in from an unfamiliar country, unmanaged device, or unusual network may be required to complete an additional authentication factor. This approach provides more flexibility than applying identical authentication requirements to every access request. Adaptive policies should use reliable signals and be carefully configured to minimize false positives. They can support zero trust strategies by evaluating access requests continuously rather than assuming that previously authenticated users are always trustworthy.<\/span><\/p>\n<h3><b>Question 307<\/b><\/h3>\n<p><b>Which document is most useful for identifying the sensitivity level assigned to different categories of organizational data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response plan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disaster recovery schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network topology map<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A data classification policy defines categories used to identify the sensitivity and handling requirements of organizational information. Classifications may include public, internal, confidential, or restricted information, depending on the organization&#8217;s requirements. Classification helps determine appropriate controls for access, encryption, storage, transmission, retention, and disposal. Without consistent classification, security teams may apply inadequate or excessive controls. Data owners should participate in classification decisions because they understand the business value, regulatory requirements, and potential impact associated with the information.<\/span><\/p>\n<h3><b>Question 308<\/b><\/h3>\n<p><b>A security team wants to prevent unauthorized users from changing firewall configurations. Which principle should be applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data duplication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege ensures that users receive only the permissions required to perform their assigned responsibilities. Applying least privilege to firewall administration means only authorized network or security administrators should have permission to modify firewall policies. Administrative access can be further protected through multifactor authentication, privileged access management, approval workflows, and centralized logging. Restricting configuration privileges reduces the likelihood of accidental or malicious changes that could weaken network defenses. Organizations should also periodically review administrative permissions to ensure they remain appropriate.<\/span><\/p>\n<h3><b>Question 309<\/b><\/h3>\n<p><b>Which security control provides an additional layer of protection when a primary security mechanism fails?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple complementary security controls so that the failure or bypass of one control does not automatically result in complete compromise. For example, an organization may combine endpoint protection, network segmentation, multifactor authentication, encryption, monitoring, and application security controls. Each layer addresses different attack paths and provides additional opportunities to prevent, detect, or contain malicious activity. Defense in depth is especially important for high-value systems because no individual control is guaranteed to remain effective against every threat or configuration failure.<\/span><\/p>\n<h3><b>Question 310<\/b><\/h3>\n<p><b>Which control can prevent sensitive information from being transmitted outside the organization through unauthorized channels?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data loss prevention, or DLP, identifies and helps prevent unauthorized transmission, storage, or use of sensitive information. DLP policies can inspect content and context across endpoints, email, cloud services, and network channels. For example, a policy might prevent confidential files from being emailed to external recipients or copied to unauthorized removable media. Effective DLP requires accurate data classification and carefully designed policies to reduce false positives. Organizations should balance protection with legitimate business requirements so that necessary data sharing is not unnecessarily disrupted.<\/span><\/p>\n<h3><b>Question 311<\/b><\/h3>\n<p><b>Which control is designed to ensure that a user cannot approve their own high-risk access request?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption at rest<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties prevents a single individual from controlling multiple conflicting stages of a sensitive process. For access management, this can mean that one employee requests elevated permissions while another authorized person approves the request. The separation reduces opportunities for unauthorized privilege escalation and creates an independent review point. Workflow systems can enforce these requirements automatically by preventing requesters from approving their own requests. This control is particularly valuable for privileged access, financial systems, production environments, and other areas where excessive authority could create significant risk.<\/span><\/p>\n<h3><b>Question 312<\/b><\/h3>\n<p><b>Which security activity involves actively searching for threats that may have avoided automated detection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch packaging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting is a proactive security activity in which analysts search systems, networks, and data for indicators or behaviors associated with potential threats. Instead of waiting for automated alerts, hunters may investigate unusual processes, authentication patterns, network connections, persistence mechanisms, or known attacker techniques. Threat hunting can uncover malicious activity that bypassed traditional security controls. Effective hunting uses threat intelligence, telemetry, behavioral analysis, and knowledge of attacker tactics and techniques. Findings should be fed back into detection engineering and security monitoring to improve future automated detection.<\/span><\/p>\n<h3><b>Question 313<\/b><\/h3>\n<p><b>A company wants to make sure a compromised administrator cannot directly manage every critical network device. Which architecture is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management network isolation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat network access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrative accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public management interfaces<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management network isolation separates administrative interfaces from normal user and production traffic. Critical network devices can expose their management interfaces only through a restricted administrative network accessible to authorized personnel. This limits the number of systems capable of reaching sensitive management functions and reduces the risk that a compromised endpoint can directly administer infrastructure. Organizations can strengthen this design with jump servers, multifactor authentication, privileged access management, and centralized logging. Isolating the management plane is particularly important for high-value network and security infrastructure.<\/span><\/p>\n<h3><b>Question 314<\/b><\/h3>\n<p><b>Which process helps ensure that security requirements are considered when acquiring a new third-party service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor security assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network flattening<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vendor security assessment evaluates the security practices, controls, risks, and capabilities of a third-party provider before or during procurement. The assessment can review security policies, incident response, access controls, encryption, compliance evidence, vulnerability management, data handling, and subcontractor relationships. Results can be incorporated into contractual requirements and risk treatment decisions. Vendor assessments should not necessarily end after onboarding because supplier risk can change over time. Organizations should establish appropriate monitoring and reassessment requirements based on the sensitivity of the service and information involved.<\/span><\/p>\n<h3><b>Question 315<\/b><\/h3>\n<p><b>Which security technology can automatically isolate an endpoint when malicious behavior is detected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EDR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS resolver<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate authority<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Endpoint detection and response, or EDR, monitors endpoint activity and can detect suspicious behavior such as malicious processes, persistence attempts, unauthorized changes, and unusual connections. Many EDR platforms provide response capabilities that allow security teams or automated policies to isolate a compromised endpoint from the network while preserving the system for investigation. Isolation helps contain threats and limit lateral movement. EDR should operate alongside other controls such as endpoint hardening, patch management, application control, identity security, and centralized security monitoring.<\/span><\/p>\n<h3><b>Question 316<\/b><\/h3>\n<p><b>Which control provides evidence of who accessed a sensitive database and when the access occurred?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Audit logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit logging records security-relevant activities such as authentication attempts, data access, configuration changes, and administrative actions. For a sensitive database, audit logs can provide evidence of which account accessed specific resources and when the activity occurred. Logs should be protected against unauthorized modification and retained according to organizational, legal, and compliance requirements. Centralizing database audit events in a SIEM can make correlation and investigation easier. Audit logging supports accountability, incident response, compliance assessments, and forensic investigations when properly configured.<\/span><\/p>\n<h3><b>Question 317<\/b><\/h3>\n<p><b>A company needs to reduce the risk that a stolen password can be reused against its cloud applications. Which control provides the strongest additional protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared accounts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Longer session timeouts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires users to provide an additional authentication factor beyond a password. If an attacker obtains the password, the attacker may still be unable to access the account without the additional factor. Strong implementations can use phishing-resistant hardware authenticators or platform-based credentials. MFA should be applied especially to privileged accounts, remote access, and sensitive cloud applications. Organizations should also secure account recovery procedures because weak recovery mechanisms can undermine otherwise strong authentication controls.<\/span><\/p>\n<h3><b>Question 318<\/b><\/h3>\n<p><b>Which activity verifies that a security architecture meets its intended design before deployment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Architecture validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">User provisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup deletion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Architecture validation reviews whether a proposed or implemented architecture satisfies defined security requirements and design objectives. The process may examine trust boundaries, data flows, access controls, network segmentation, encryption, dependencies, logging, resilience, and attack paths. Validation can identify design weaknesses before they become expensive production problems. Organizations may use threat modeling, architecture reviews, security testing, and control mapping as part of the process. Performing validation before deployment provides an opportunity to correct structural weaknesses rather than relying only on operational controls after implementation.<\/span><\/p>\n<h3><b>Question 319<\/b><\/h3>\n<p><b>Which method can help verify that a downloaded file is identical to the version published by a trusted source?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cryptographic hash comparison<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic hash comparison can verify the integrity of a file by comparing its calculated hash with a trusted reference value. If the values match using a suitable cryptographic hash algorithm, the file content is consistent with the reference at the time of comparison. A mismatch indicates that the content differs, although additional verification may be needed to determine why. Hashes should be obtained from a trustworthy source because an attacker who controls both the file and its published hash could potentially replace both.<\/span><\/p>\n<h3><b>Question 320<\/b><\/h3>\n<p><b>An organization wants to ensure that critical services continue operating if one data center becomes unavailable. Which strategy provides geographic resilience?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local file compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-server deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographic redundancy places critical services or their recovery capabilities across separate physical locations so that a major outage at one site does not necessarily eliminate the organization&#8217;s ability to operate. Depending on requirements, organizations may use active-active or active-passive architectures, replicated data, redundant network connectivity, and automated failover. Geographic redundancy can protect against regional disasters, facility failures, and certain infrastructure outages. The design should account for application dependencies, data consistency, recovery objectives, connectivity, operational complexity, and the cost of maintaining multiple locations.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 301 Which security mechanism is specifically designed to verify that a digital certificate has not been revoked? OCSP NAT SFTP DHCP Correct Answer: 1 Explanation The Online Certificate Status Protocol, or OCSP, allows systems to query whether a digital certificate is currently valid [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22015"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22015"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22015\/revisions"}],"predecessor-version":[{"id":22016,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22015\/revisions\/22016"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22015"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22015"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}