{"id":22023,"date":"2026-09-25T10:31:00","date_gmt":"2026-09-25T10:31:00","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22023"},"modified":"2026-09-25T10:31:00","modified_gmt":"2026-09-25T10:31:00","slug":"comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-cas-005-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"CompTIA SecurityX CAS-005 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cas-005-exam-dumps\"><b>CompTIA CAS-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which control is most effective for preventing administrators from making unauthorized changes to production systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Change approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup deduplication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Change approval requires proposed modifications to production systems to be reviewed and authorized before implementation. The process should identify the requested change, business justification, affected systems, potential risks, testing requirements, implementation plan, and rollback procedure. For high-risk changes, additional approval or security review may be required. Change management reduces accidental outages and unauthorized modifications while providing an audit trail of decisions. Emergency changes should follow a defined expedited process and receive retrospective review to ensure that bypassing normal procedures does not become routine.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which technology provides a protected execution environment for sensitive code and data even while a system is running?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure enclave<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Proxy server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup appliance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secure enclave provides an isolated execution environment designed to protect sensitive code and data from unauthorized access, including certain threats originating from the host operating system. Trusted execution environments can use hardware-supported protections to help preserve confidentiality and integrity while applications execute. They are useful for workloads handling cryptographic keys, confidential computations, or other sensitive information. Organizations should still evaluate the specific implementation, threat model, and trust assumptions because an enclave does not eliminate every application, hardware, or supply-chain security risk.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>A company wants to prevent a single administrator from both approving and implementing a high-risk security configuration change. Which principle applies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data minimization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of duties<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties divides sensitive responsibilities among different individuals or roles so that one person cannot independently complete an entire high-risk process. For example, one administrator may submit a configuration change while another authorized person reviews and approves it. This reduces the opportunity for fraud, abuse, and accidental mistakes. Separation of duties is particularly valuable for privileged access, financial systems, security policy changes, and production deployments. Organizations should design the process carefully so that segregation does not create unnecessary operational delays or unmanageable administrative overhead.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which metric measures the average time required to detect a security incident?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTD<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mean Time to Detect, or MTTD, measures how long it typically takes an organization to identify a security event or incident after it begins. A lower MTTD generally indicates that monitoring and detection capabilities are identifying suspicious activity more quickly. Organizations can improve detection time through centralized logging, SIEM correlation, endpoint telemetry, threat intelligence, automated alerting, and effective security operations procedures. MTTD differs from MTTR, which focuses on the time required to respond to and recover from an incident after detection.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which cloud security practice helps identify publicly exposed storage resources that should not be accessible from the internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSPM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Code signing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk imaging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Security Posture Management tools continuously evaluate cloud configurations for security weaknesses and policy violations. CSPM can identify issues such as publicly accessible storage, overly permissive identity policies, exposed management interfaces, missing encryption, and insecure network configurations. Automated findings allow security teams to prioritize remediation based on risk and organizational policy. CSPM is particularly useful because cloud environments can change rapidly through automated deployments. However, organizations should combine automated posture checks with governance, secure configuration standards, continuous monitoring, and appropriate ownership of remediation activities.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which approach provides an alternate processing capability at another geographic location to reduce the effect of a regional disaster?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Geographic redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate pinning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographic redundancy distributes systems, services, or data across separate geographic locations so that a regional outage does not necessarily make all resources unavailable. The alternate location may be designed as an active or standby environment depending on recovery requirements. Geographic redundancy can address risks such as natural disasters, regional infrastructure failures, and certain large-scale service disruptions. Its effectiveness depends on factors including data replication, network connectivity, application dependencies, recovery procedures, and the organization&#8217;s RTO and RPO requirements. Regular recovery testing is necessary to validate readiness.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>A security team discovers that an application has excessive permissions to cloud resources it does not use. What should the team do first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant additional permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove unnecessary permissions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable all cloud logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Share the credentials with administrators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Removing unnecessary permissions applies the principle of least privilege and reduces the potential impact if the application&#8217;s credentials or execution environment are compromised. Security teams should identify which resources and actions the application actually requires and eliminate unrelated permissions. Where possible, permissions should be narrowly scoped by resource, action, and environment. Organizations should also review service accounts regularly because application requirements can change over time. Excessive permissions should not be retained simply for convenience, particularly when they provide access to sensitive production resources.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which security mechanism allows a certificate&#8217;s validity to be checked without requiring the client to download the entire certificate revocation list?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OCSP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SAML<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Online Certificate Status Protocol, or OCSP, allows a client to query the status of a digital certificate and determine whether it is valid, revoked, or otherwise unavailable for trusted use. This can avoid downloading a potentially large certificate revocation list. OCSP responses can support more timely certificate-status checking, although availability, privacy, responder reliability, and implementation considerations must be addressed. Organizations may also use OCSP stapling in appropriate environments to reduce direct client communication with certificate-status responders and improve efficiency.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which control helps ensure that sensitive administrative sessions are performed through a monitored intermediary system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bastion host<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data warehouse<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Load balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A bastion host is a hardened intermediary system designed to provide controlled access to sensitive infrastructure. Administrative users can connect to the bastion and then access protected systems from there, allowing organizations to centralize authentication, logging, monitoring, and access restrictions. Bastion hosts should be hardened, regularly patched, and tightly limited to their intended functions. They can be combined with privileged access management, multifactor authentication, session recording, and network segmentation. The design should minimize services and permissions on the bastion to reduce its own attack surface.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which document identifies how different business services depend on applications, systems, personnel, and external providers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dependency map<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dependency map identifies relationships between business services and the resources required to operate them. These dependencies can include applications, databases, infrastructure, employees, network services, cloud providers, suppliers, and communication systems. Dependency mapping is important for business continuity and disaster recovery because an organization may restore one system successfully while an unresolved dependency still prevents the business service from operating. Maintaining accurate dependency information helps teams prioritize recovery activities, identify single points of failure, and understand the potential effects of outages or changes.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which security measure helps protect a private cryptographic key used to sign software releases?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network load balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Hardware Security Module, or HSM, provides specialized hardware protection for cryptographic keys and operations. When used for software signing, an HSM can help prevent private signing keys from being directly exposed to ordinary systems or users. The module can perform cryptographic operations while keeping sensitive key material protected within the controlled device. Organizations should also enforce strong administrative controls, authentication, auditing, backup procedures, and key lifecycle management. Protecting signing keys is critical because compromise could allow unauthorized software or updates to appear legitimately signed.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which activity is most appropriate for determining whether an organization&#8217;s risk remains within its approved tolerance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">File compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk monitoring tracks identified risks and changes in their likelihood, impact, control effectiveness, and overall exposure. Organizations can compare current risk conditions against established risk tolerance or appetite to determine whether additional treatment is required. Monitoring may use key risk indicators, control assessments, vulnerability information, incident trends, and changes in business operations. Risk monitoring should be continuous for significant risks rather than performed only during annual assessments. When risk exceeds approved thresholds, management may need to reduce, transfer, avoid, or formally accept the exposure.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which secure development practice prevents unauthorized developers from directly modifying protected production branches?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Branch protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disk encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data retention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Branch protection rules restrict how code can be changed in important source-control branches. Organizations can require pull requests, peer review, automated testing, security checks, and authorized approvals before changes are merged into protected branches. This reduces the possibility that a developer or compromised account can directly introduce unauthorized or untested code into production-bound software. Branch protection is particularly useful when combined with strong identity controls, commit signing, CI\/CD security checks, dependency scanning, and audit logging. Administrative exceptions should be controlled and reviewed.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which incident response action is primarily intended to stop an attacker from continuing to access compromised systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Containment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lessons learned<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset procurement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Containment limits the attacker&#8217;s ability to continue operating within the environment and reduces further damage while investigation proceeds. Actions can include isolating compromised endpoints, blocking malicious network connections, disabling compromised accounts, restricting access to affected resources, or separating impacted network segments. Containment should be carefully planned because aggressive actions may destroy evidence or disrupt critical business services. Security teams should balance the need to stop malicious activity with operational and forensic requirements. After containment, eradication and recovery activities can address the underlying compromise.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which control provides evidence that a software package came from an approved publisher and was not modified after signing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Digital signature<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tokenization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data masking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A digital signature can provide assurance about software integrity and the identity associated with the signing key. When users or systems verify a valid signature against a trusted public key, they can determine whether the signed artifact was altered after signing and whether it was signed by the expected publisher or authority. Organizations should protect private signing keys carefully and establish procedures for key rotation and revocation. Signature verification should occur before deployment, particularly for software, firmware, packages, and updates obtained from external or distributed sources.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which recovery site typically requires more preparation than a hot site before critical services can be restored?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Warm site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active-active site<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Production cluster<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fully operational primary site<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A warm site provides some infrastructure and resources for recovery but generally requires additional configuration, data restoration, or application preparation before becoming fully operational. It therefore usually takes longer to activate than a hot site, which is maintained in a more ready state. Warm sites can provide a balance between recovery capability and cost. Organizations should select a recovery-site strategy based on business requirements, including RTO, RPO, criticality, budget, geographic risk, and application dependencies. Recovery procedures should be tested regularly.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which security capability can automatically execute predefined response actions after detecting a confirmed threat?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SOAR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SAST<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SBOM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Orchestration, Automation, and Response platforms can automate repetitive security operations by connecting multiple security tools and executing predefined playbooks. For example, a SOAR workflow may receive an alert, enrich it with threat intelligence, isolate an endpoint, disable a compromised account, and create an investigation ticket. Automation can reduce response time and improve consistency, but poorly designed playbooks may cause unnecessary disruption. Organizations should carefully define approval requirements, test automation, monitor outcomes, and restrict automated actions according to their potential business impact.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which requirement is most important when preserving digital evidence for possible legal proceedings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Chain of custody<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network balancing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password expiration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Chain of custody documents how digital evidence was collected, handled, transferred, stored, and accessed from the time it was obtained. Accurate records help demonstrate that evidence was protected from unauthorized alteration and that its handling can be accounted for throughout an investigation. Investigators should document relevant timestamps, individuals, systems, acquisition methods, storage locations, and transfers. Evidence should be preserved using appropriate forensic procedures and access controls. Maintaining integrity and traceability is especially important when evidence may later be presented to legal, regulatory, or disciplinary authorities.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which approach allows an organization to continue operating when one critical infrastructure component fails?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fault tolerance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity federation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Threat intelligence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fault tolerance allows a system or service to continue operating despite the failure of a component. It can be achieved through redundant hardware, clustered systems, multiple network paths, replicated services, or other architectures designed to eliminate single points of failure. Fault-tolerant designs are particularly important for critical services where downtime could cause significant operational, financial, or safety consequences. Organizations should distinguish fault tolerance from backup and disaster recovery because redundancy can maintain service availability, while backups primarily support restoration after data loss or system failure.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which governance practice ensures that significant security risks have an accountable individual responsible for managing them?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk ownership assignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network address translation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password synchronization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk ownership assignment designates an accountable individual or role responsible for managing a particular risk. The risk owner typically evaluates the exposure, coordinates treatment decisions, monitors changes, and ensures that appropriate actions are taken or formally accepted. Assigning ownership prevents important risks from becoming everyone&#8217;s responsibility and therefore effectively belonging to no one. Risk owners should have sufficient authority and business knowledge to make or escalate decisions. Ownership should be documented in the risk register and reviewed when organizational responsibilities or risk conditions change.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA CAS-005 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Which control is most effective for preventing administrators from making unauthorized changes to production systems? Data masking Change approval Network compression Backup deduplication Correct Answer: 2 Explanation Change approval requires proposed modifications to production systems to be reviewed and authorized before implementation. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22023"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22023"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22023\/revisions"}],"predecessor-version":[{"id":22024,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22023\/revisions\/22024"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22023"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}