{"id":22017,"date":"2026-09-25T10:30:17","date_gmt":"2026-09-25T10:30:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22017"},"modified":"2026-09-25T10:30:17","modified_gmt":"2026-09-25T10:30:17","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 321<\/b><\/h3>\n<p><b>Which security control can prevent unauthorized software from running on a high-value server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application allowlisting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting restricts software execution to applications that have been explicitly approved by the organization. On high-value servers, this can reduce the risk of unauthorized tools, malware, and unapproved executables being launched. Policies may use application hashes, trusted publishers, file paths, or other attributes to determine what is permitted. Allowlisting should be carefully tested because legitimate updates and administrative tools must remain functional. It works best as part of a broader defense-in-depth strategy that includes patching, least privilege, monitoring, and endpoint protection.<\/span><\/p>\n<h3><b>Question 322<\/b><\/h3>\n<p><b>A security administrator wants to grant elevated privileges only for the duration of a maintenance task. Which approach should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent administrator rights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Just-in-time privileged access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privileged access provides elevated permissions only when they are required and for a limited period. After the approved maintenance task or time window ends, the privileges can be automatically removed. This reduces the exposure created by standing administrative permissions and limits the opportunity for attackers to abuse compromised privileged accounts. Organizations can strengthen this approach with approval workflows, multifactor authentication, session recording, and detailed logging. Just-in-time access is especially valuable for administrators and third-party personnel who need occasional access to critical infrastructure.<\/span><\/p>\n<h3><b>Question 323<\/b><\/h3>\n<p><b>Which security process determines whether an organization can continue operating during a major disruption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business continuity planning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate enrollment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business continuity planning identifies how an organization will maintain critical business functions during and after disruptive events. It addresses people, processes, technology, facilities, communications, dependencies, and alternative operating arrangements. Business continuity planning is broader than technical disaster recovery because it considers the continuity of business operations rather than only restoring IT systems. Plans should be based on business impact analysis and tested periodically. Testing can reveal gaps in communication, staffing, dependencies, alternate facilities, and recovery procedures before an actual disruption occurs.<\/span><\/p>\n<h3><b>Question 324<\/b><\/h3>\n<p><b>Which control can identify an attacker attempting to move laterally through an enterprise network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup deduplication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Monitoring traffic between segmented network zones can help identify suspicious lateral movement attempts. Security teams can examine unusual connections, unexpected protocols, authentication activity, and communication between systems that normally have limited interaction. Network segmentation itself restricts movement, while monitoring provides visibility into attempts to cross those boundaries. Combining segmentation with SIEM correlation, endpoint telemetry, and network detection capabilities can provide stronger detection. Organizations should establish expected communication patterns so that unusual internal traffic can be investigated without generating excessive false positives.<\/span><\/p>\n<h3><b>Question 325<\/b><\/h3>\n<p><b>A company needs to determine whether a new application exposes sensitive information through unnecessary API responses. Which activity is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application security testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup restoration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application security testing can evaluate whether an application or API exposes information beyond what is required for legitimate functionality. Testing may examine authentication, authorization, input validation, API responses, error messages, data exposure, and other application behaviors. Security teams can identify excessive data disclosure and recommend changes such as response filtering, stronger authorization checks, or data minimization. Testing should occur throughout the development lifecycle because vulnerabilities discovered before production are generally easier to correct. API security should also be supported by proper authentication, logging, and monitoring.<\/span><\/p>\n<h3><b>Question 326<\/b><\/h3>\n<p><b>Which cryptographic concept allows an organization to replace an older algorithm with a stronger one without redesigning the entire application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cryptographic agility<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic agility is the ability of systems and applications to change cryptographic algorithms, protocols, or key sizes without requiring major architectural redesign. This capability is important because cryptographic standards may become weak, deprecated, or unsuitable as threats and computing capabilities evolve. Applications designed with cryptographic agility can transition more efficiently to stronger algorithms when required. Organizations should avoid hard-coding cryptographic choices throughout application logic and instead use configurable, well-managed cryptographic libraries and services. Planning for algorithm changes also supports long-term security and compliance requirements.<\/span><\/p>\n<h3><b>Question 327<\/b><\/h3>\n<p><b>Which security measure is most appropriate for protecting a private key used by a certificate authority?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network proxy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security module can provide strong protection for sensitive private keys used by certificate authorities. Certificate authority private keys are highly valuable because compromise could allow an attacker to issue fraudulent certificates that appear trustworthy. HSMs can provide secure key storage, cryptographic operations, and tamper-resistant protections. Organizations should also restrict administrative access, maintain appropriate backups where permitted, monitor key usage, and establish procedures for key rotation and recovery. Protecting certificate authority keys is a critical part of maintaining trust in a public key infrastructure.<\/span><\/p>\n<h3><b>Question 328<\/b><\/h3>\n<p><b>An organization wants to ensure that users receive access based on both their job role and the sensitivity of the requested resource. Which model is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contextual access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared-account access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Contextual access control can evaluate multiple characteristics before granting access, including user identity, role, device status, location, resource sensitivity, time, and other environmental conditions. This allows organizations to make more precise authorization decisions than simple role-only models. For example, an employee may normally access a sensitive application from a managed corporate device but receive additional verification when attempting access from an unknown device. Contextual policies support zero trust principles by evaluating the circumstances of each access request rather than relying solely on an assumed trusted network location.<\/span><\/p>\n<h3><b>Question 329<\/b><\/h3>\n<p><b>Which process ensures that security requirements are included in a contract with a third-party service provider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contractual security requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local backup rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint defragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Contractual security requirements formally establish the security obligations of a third-party provider. Contracts can define requirements for data protection, access control, encryption, incident notification, vulnerability management, audit rights, regulatory compliance, retention, subcontractors, and termination procedures. Including these requirements in contracts provides a formal basis for holding vendors accountable. Organizations should align contractual requirements with the sensitivity of the service and information involved. Vendor monitoring and periodic assessments should then verify whether the provider continues to meet the agreed requirements throughout the relationship.<\/span><\/p>\n<h3><b>Question 330<\/b><\/h3>\n<p><b>Which metric measures the average time required to recover from or resolve a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time to Respond or Recover, commonly represented as MTTR depending on organizational usage, measures the average time required to address an incident or restore normal operations after detection. Organizations use this metric to evaluate the effectiveness of incident-response and recovery processes. A lower MTTR can indicate that teams are able to contain, remediate, and recover from incidents efficiently, although the metric should be interpreted alongside incident complexity and severity. MTTD focuses on detection time, while RTO is a business recovery objective rather than an incident-response performance metric.<\/span><\/p>\n<h3><b>Question 331<\/b><\/h3>\n<p><b>Which security mechanism prevents unauthorized changes to a system configuration by automatically restoring an approved state?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Configuration enforcement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration enforcement ensures that systems maintain approved security settings and can automatically remediate unauthorized deviations. For example, an endpoint management platform may detect that a required security setting has been changed and restore the approved configuration. This helps reduce configuration drift and limits the time during which systems operate in an insecure state. Configuration enforcement should be based on documented security baselines and integrated with change management so that authorized modifications are not incorrectly treated as violations. Continuous monitoring provides additional visibility into configuration changes.<\/span><\/p>\n<h3><b>Question 332<\/b><\/h3>\n<p><b>A security team suspects that attackers are using legitimate credentials to access systems. Which capability is most useful for identifying unusual account behavior?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UEBA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics can identify unusual activity associated with otherwise legitimate accounts. Attackers who obtain valid credentials may avoid traditional malware detection, making behavioral analysis particularly valuable. UEBA can identify anomalies such as unusual login locations, abnormal access times, unexpected resource access, or sudden increases in administrative activity. Analysts should correlate these findings with authentication logs, endpoint telemetry, VPN information, and known user behavior. An anomaly does not automatically prove compromise, so investigators should evaluate context before taking disruptive response actions.<\/span><\/p>\n<h3><b>Question 333<\/b><\/h3>\n<p><b>Which recovery architecture maintains two environments capable of processing workloads simultaneously?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-active<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cold site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Offline backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manual recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An active-active architecture maintains two or more environments that can simultaneously process workloads. If one environment becomes unavailable, traffic can be redirected or shifted to the remaining environment with limited interruption. This design can provide strong availability and support rapid failover, but it introduces complexity involving data consistency, synchronization, application state, networking, and operational management. Active-passive architectures are different because one environment normally remains on standby until needed. The appropriate design depends on recovery objectives, application characteristics, geographic requirements, and available resources.<\/span><\/p>\n<h3><b>Question 334<\/b><\/h3>\n<p><b>Which activity should be performed before accepting a significant residual security risk?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk analysis and documented approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deleting the risk record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling security monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing the affected asset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Before accepting significant residual risk, the organization should evaluate the remaining exposure and obtain documented approval from the appropriate risk owner or authority. Risk acceptance should be based on a clear understanding of likelihood, impact, existing controls, compensating measures, and business justification. The decision should include an appropriate review or expiration date when applicable. Simply deleting the risk record does not reduce the underlying exposure. Formal documentation provides accountability and allows leadership to reassess the decision when conditions or threat levels change.<\/span><\/p>\n<h3><b>Question 335<\/b><\/h3>\n<p><b>Which technology helps secure communications between a user and a remote private network over an untrusted connection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RAID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A virtual private network, or VPN, creates a protected communication channel across an untrusted network such as the public internet. Depending on the implementation, a VPN can provide confidentiality, integrity, authentication, and secure routing between authorized endpoints or networks. VPN security depends on strong cryptographic protocols, secure authentication, proper configuration, and current software. Organizations should also apply least privilege and access controls after the VPN connection is established. A VPN protects the communication path but does not automatically make the connected endpoint or internal resources trustworthy.<\/span><\/p>\n<h3><b>Question 336<\/b><\/h3>\n<p><b>Which control helps ensure that employees understand how to identify and report suspicious phishing messages?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security awareness training<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security awareness training teaches employees how to recognize and appropriately respond to common security threats such as phishing, social engineering, malicious attachments, and suspicious links. Effective programs should provide practical guidance and explain how employees can report suspected incidents through approved channels. Organizations may supplement training with simulated phishing exercises and follow-up education. Awareness does not replace technical controls such as email filtering, multifactor authentication, and endpoint protection, but it can reduce the likelihood that users will unintentionally assist attackers.<\/span><\/p>\n<h3><b>Question 337<\/b><\/h3>\n<p><b>A company wants to ensure that a software package was produced by its authorized development organization. Which control provides this assurance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Code signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Code signing uses a digital signature to associate software with an authorized publisher and provide evidence that the signed content has not been altered after signing. The recipient can verify the signature using the publisher&#8217;s trusted public key. This helps users and systems distinguish approved software from unauthorized or modified packages. The security of code signing depends heavily on protecting the private signing key and maintaining a trustworthy certificate lifecycle. Organizations should also secure build pipelines and restrict who can authorize or publish signed software.<\/span><\/p>\n<h3><b>Question 338<\/b><\/h3>\n<p><b>Which process helps determine whether a vulnerability should be remediated immediately or scheduled for later?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based vulnerability prioritization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Random patch selection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based vulnerability prioritization considers factors such as vulnerability severity, exploitability, asset criticality, exposure, business impact, available compensating controls, and threat intelligence. A critical vulnerability on an internet-facing production system may require immediate remediation, while a lower-risk issue on an isolated system may be scheduled later. This approach helps organizations focus limited remediation resources on vulnerabilities that create the greatest practical risk. Vulnerability management should include defined remediation timelines, exception processes, validation of fixes, and continuous reassessment as threat conditions change.<\/span><\/p>\n<h3><b>Question 339<\/b><\/h3>\n<p><b>Which security capability can identify sensitive information stored across multiple repositories before protection policies are applied?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate revocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data discovery identifies where organizational information is stored across systems, applications, databases, endpoints, cloud services, and other repositories. It can help security teams locate sensitive or regulated information that may otherwise be unknown or poorly protected. Discovery is often combined with data classification so that appropriate controls can be applied according to sensitivity. Accurate data discovery supports DLP, encryption, retention management, access reviews, and compliance activities. Organizations should periodically repeat discovery because new data stores and applications can appear as environments change.<\/span><\/p>\n<h3><b>Question 340<\/b><\/h3>\n<p><b>Which security design principle requires systems to remain protected even when a component or control fails?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fail-safe design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single-factor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared administration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fail-safe design considers how a system should behave when a component, security control, or service fails. The objective is to prevent failures from automatically creating unacceptable security exposure. Depending on the system, this may mean denying access when an authorization service becomes unavailable or placing a system into a restricted operating mode. Fail-safe behavior should be selected according to security and availability requirements because denying all access may itself create operational consequences. Architects should explicitly define expected failure behavior and validate it through testing.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 321 Which security control can prevent unauthorized software from running on a high-value server? Application allowlisting Network address translation Data replication Log compression Correct Answer: 1 Explanation Application allowlisting restricts software execution to applications that have been explicitly approved by the organization. On [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22017"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22017"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22017\/revisions"}],"predecessor-version":[{"id":22018,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22017\/revisions\/22018"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}