{"id":22021,"date":"2026-09-25T10:30:46","date_gmt":"2026-09-25T10:30:46","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22021"},"modified":"2026-09-25T10:30:46","modified_gmt":"2026-09-25T10:30:46","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which security control is most appropriate for restricting administrative access to only authorized management workstations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Management access control restricts administrative interfaces so that only approved users, systems, or network locations can reach them. Organizations can require administrators to use dedicated management workstations or hardened jump servers rather than ordinary employee endpoints. This reduces the opportunity for a compromised workstation to reach sensitive infrastructure. Additional safeguards can include multifactor authentication, privileged access management, network segmentation, and session logging. Restricting management access is especially important for routers, switches, hypervisors, security appliances, and other infrastructure where unauthorized administrative changes could have significant consequences.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which security activity identifies whether an organization&#8217;s security controls align with specific regulatory or contractual requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control mapping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk imaging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control mapping links organizational security controls to specific regulatory, contractual, or framework requirements. This allows security teams to determine which controls satisfy particular obligations and where gaps may exist. A single security control may address multiple requirements, while some requirements may need several controls. Control mapping can simplify audits, compliance reporting, and security program management. Organizations should maintain mappings as requirements change and verify that mapped controls remain effective. Documentation alone is not sufficient; the organization should also retain evidence showing that applicable controls are implemented and operating.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>A company wants to detect unauthorized modifications to critical configuration files immediately after they occur. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File integrity monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring continuously or periodically checks important files for unauthorized changes. It can compare current file characteristics against a trusted baseline using cryptographic hashes, metadata, or other indicators. When unexpected modifications occur, alerts can be generated for investigation. FIM is useful for critical operating system files, application configurations, security policies, and other sensitive resources. Organizations should identify which files require monitoring and tune alerting to distinguish legitimate administrative changes from suspicious activity. Centralized logging can preserve FIM alerts for later investigation.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which security architecture provides the strongest isolation between highly sensitive workloads and ordinary user systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Flat networking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsegmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared VLAN access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation applies granular security policies to individual workloads, applications, or groups of systems rather than relying only on broad network boundaries. This allows organizations to restrict communication based on application identity, workload, port, protocol, or other attributes. If an ordinary user system becomes compromised, microsegmentation can prevent unnecessary connections to sensitive workloads. It supports zero trust and defense-in-depth strategies by reducing implicit trust between systems. Proper implementation requires understanding application dependencies and continuously maintaining policies as workloads and business requirements change.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which process determines whether a security policy exception should be renewed, modified, or closed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Exception review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate issuance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exception review evaluates whether an approved deviation from a security policy remains necessary and acceptable. Reviewers should consider the original business justification, current risk, compensating controls, remediation progress, expiration date, and changes in the technical environment. If the underlying reason for the exception no longer exists, the organization can close it and restore normal compliance. If the risk remains, the exception may require renewal with updated approval. Formal reviews prevent temporary exceptions from becoming permanent unmanaged weaknesses.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>A security team needs to identify the attack techniques used during a confirmed intrusion. Which framework-based activity is most useful?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TTP analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate enrollment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TTP analysis examines an attacker&#8217;s tactics, techniques, and procedures to understand how an intrusion was conducted. Analysts can compare observed behavior with known adversary techniques and use the findings to improve detection and response capabilities. TTP information can help identify related activity across systems and determine whether other parts of the environment may have been affected. Security teams can use frameworks such as MITRE ATT&amp;CK as references for categorizing adversary behavior. TTP analysis should be based on collected evidence rather than assumptions about attacker activity.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which authentication approach is generally strongest against phishing when properly implemented?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security questions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMS-only verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FIDO2-based authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password hints<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FIDO2-based authentication can provide phishing-resistant authentication by using public-key cryptography tied to the legitimate relying party. The authenticator does not simply provide a reusable secret that an attacker can capture and replay on a fraudulent website. Depending on implementation, FIDO2 can use hardware security keys or platform authenticators. Strong account recovery procedures remain important because attackers may attempt to bypass authentication through weaker recovery mechanisms. Organizations should deploy phishing-resistant authentication especially for privileged accounts and other high-value identities.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which control helps prevent an attacker from using stolen credentials after the legitimate user&#8217;s employment has ended?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Account deprovisioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Account deprovisioning removes or disables access when a user no longer requires organizational resources. Termination and role-change processes should trigger timely updates to identity systems, application accounts, privileged credentials, tokens, and other access mechanisms. Delayed deprovisioning can leave former employees or attackers with valid credentials. Organizations should integrate human resources processes with identity lifecycle management where appropriate and perform periodic account reviews to identify dormant or orphaned accounts. Strong deprovisioning controls reduce the risk of unauthorized access after employment or responsibilities change.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which security measure provides a way to verify that a message was not altered during transmission?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Integrity protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Availability monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integrity protection ensures that data has not been modified without authorization. Cryptographic mechanisms such as hashes, message authentication codes, and digital signatures can provide evidence of data integrity. The appropriate mechanism depends on the communication and trust model. For example, a message authentication code can verify integrity when communicating parties share a secret key, while a digital signature can provide integrity and support authenticity and nonrepudiation. Integrity protection is distinct from confidentiality, which prevents unauthorized parties from reading the protected information.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>A security team wants to detect suspicious changes to privileged accounts and permissions. Which data source should be monitored closely?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity and access logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Printer status reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temperature readings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression statistics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity and access logs provide valuable information about account creation, authentication, privilege changes, access requests, and administrative actions. Monitoring these events can reveal suspicious activities such as unexpected privilege escalation, creation of unauthorized accounts, or changes to authentication settings. Security teams can correlate identity events with endpoint, network, and application telemetry to improve detection accuracy. Logs should be protected against unauthorized modification and retained according to security and compliance requirements. Privileged identity events deserve particular attention because misuse of administrative access can have broad consequences.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which practice reduces the likelihood that a compromised service account can access unrelated cloud resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Narrow permission scoping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Broad administrator rights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent root access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Narrow permission scoping applies least privilege to service accounts by granting only the resources and actions required by the application. A service account with broad permissions creates a significant risk if its credentials or execution environment are compromised. Cloud administrators should identify the application&#8217;s actual requirements and remove unnecessary permissions. Separate service accounts can also be used for different applications or functions to limit the potential blast radius. Permissions should be reviewed regularly because application requirements and cloud environments can change over time.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which security process helps determine how long specific categories of information should be retained?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention management<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat hunting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data retention management establishes appropriate retention periods for different categories of information based on business, legal, regulatory, and contractual requirements. Retaining data indefinitely can increase privacy, security, and storage risks, while deleting it too early can create compliance or operational problems. Retention schedules should identify responsible owners, applicable data categories, retention periods, and secure disposal requirements. Organizations should periodically review retention rules because legal obligations and business needs can change. Effective retention management works alongside data classification, minimization, and secure destruction practices.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which activity provides a realistic evaluation of how security personnel would respond to a simulated major incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tabletop exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vulnerability patching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A tabletop exercise uses a simulated incident scenario to evaluate how personnel, procedures, communication channels, and decision-making processes would function during a real event. Participants discuss actions they would take without necessarily making production changes. Tabletop exercises can expose gaps in incident response plans, escalation procedures, responsibilities, communications, and resource availability. They can be conducted for scenarios such as ransomware, data breaches, cloud outages, or insider incidents. Findings should be documented and used to update response plans and improve organizational preparedness.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which control can limit an application&#8217;s ability to communicate only with approved external services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Egress filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate archiving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Egress filtering controls outbound network traffic leaving an environment or system. By allowing connections only to approved destinations, ports, or protocols, organizations can reduce the ability of compromised systems to communicate with attacker-controlled infrastructure. Egress filtering can help limit command-and-control communications, unauthorized data transfers, and other malicious outbound activity. Rules should be designed carefully because applications may require legitimate external services. Combining egress controls with DNS security, endpoint monitoring, proxy inspection, and DLP can provide stronger protection against unauthorized outbound communications.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which security control is specifically intended to protect the integrity of software build artifacts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Artifact signing applies a digital signature to software packages, binaries, containers, or other build outputs. Consumers can verify the signature to determine whether an artifact originated from an approved source and whether it changed after signing. This protects the software supply chain from certain forms of tampering and unauthorized replacement. Signing keys must be strongly protected because compromise could allow attackers to produce apparently trusted artifacts. Organizations should combine signing with secure build environments, access controls, provenance tracking, dependency management, and verification before deployment.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>A company wants to identify whether a cloud administrator has granted excessive permissions to a user. Which activity should be performed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk imaging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An access review evaluates existing permissions to determine whether they remain appropriate for a user&#8217;s responsibilities and current risk level. In cloud environments, excessive permissions can expose large numbers of resources if an account is compromised. Reviewers should examine roles, policies, direct permissions, inherited access, and privileged assignments. Unnecessary permissions should be removed or reduced according to least-privilege requirements. Automated identity governance and cloud security tools can assist with identifying excessive permissions, but human review may still be required for business context and authorization decisions.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which security capability helps identify vulnerable dependencies included in an application&#8217;s software supply chain?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SCA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MDM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software composition analysis identifies third-party and open-source components used within an application and evaluates them for known vulnerabilities and other risks. SCA can identify outdated libraries, vulnerable package versions, and dependency relationships that may not be obvious from reviewing application source code alone. Integrating SCA into CI\/CD pipelines allows developers to detect problems before deployment. Organizations can strengthen supply chain security by combining SCA with dependency pinning, software bills of materials, trusted repositories, vulnerability monitoring, and controlled update processes.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which incident response phase focuses on removing malware and attacker persistence from affected systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Eradication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Preparation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Eradication focuses on eliminating the underlying causes and malicious components of an incident. Activities can include removing malware, deleting persistence mechanisms, disabling compromised accounts, closing exploited vulnerabilities, and addressing malicious configuration changes. Eradication should occur after sufficient investigation and containment so that important evidence is not destroyed prematurely. Once eradication is complete, systems can proceed toward recovery and normal operation. Organizations should verify that the underlying weakness has been addressed to reduce the likelihood that attackers can regain access using the same method.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which approach provides a controlled alternative when a required security control cannot be implemented immediately?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compensating control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control removal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Unrestricted access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk concealment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides an alternative security measure when the preferred control cannot be implemented because of technical, operational, or business constraints. For example, if an older system cannot support a required authentication mechanism, network isolation and enhanced monitoring may temporarily reduce the associated risk. Compensating controls should be documented, approved, and evaluated to determine whether they provide adequate protection. They should not automatically become permanent substitutes without periodic review. Organizations should continue pursuing the intended control when practical.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which activity verifies that an organization&#8217;s incident response procedures work effectively before a real emergency occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Incident response exercise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An incident response exercise evaluates whether personnel, procedures, technologies, and communication processes can operate effectively during a simulated security event. Exercises can range from discussion-based tabletop scenarios to more technical simulations involving security tools and response teams. They can reveal unclear responsibilities, missing contact information, ineffective escalation paths, insufficient logging, or gaps in containment procedures. Results should be documented and converted into corrective actions. Regular exercises improve preparedness and help organizations validate that written response plans are practical rather than merely documented.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 361 Which security control is most appropriate for restricting administrative access to only authorized management workstations? Data masking Management access control Backup replication Email filtering Correct Answer: 2 Explanation Management access control restricts administrative interfaces so that only approved users, systems, or network [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22021"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22021"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22021\/revisions"}],"predecessor-version":[{"id":22022,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22021\/revisions\/22022"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}