This is the free Comptia CAS-005 practice question bank —
200 of 400 total questions, each with a full explanation, free to
read with no signup required. Updated 2026-10-03.
Every answer is verified against official Comptia documentation —
see our methodology.
Question 1
During a vulnerability assessment, a scan reveals the following finding:
Windows Server 2016 Missing hotfix KB87728 - CVSS 3.1 Score: 8.1 [High] - Affected host 172.16.15.2
Later in the review process, the remediation team marks the finding as a false positive. Which of the following is the best way to avoid this issue on future scans?
A. Getting an up-to-date list of assets from the CMDB
B. Performing an authenticated scan on the servers
C. Configuring the sensor with an advanced policy for fingerprinting servers
D. Coordinating the scan execution with the remediation team early in the process
Show Answer
Correct Answer: B
Explanation: An authenticated scan can inspect the server’s installed updates and patch state directly, making missing-hotfix findings more accurate and helping prevent false positives on future scans.
Question 2
An organization wants to implement a secure cloud architecture across all instances. Given the following requirements:
• Establish a standard network template
• Deployments must be consistent
• Security policies must be able to be changed at scale
Which of the following technologies meets these requirements?
A. Serverless deployment model
B. Container orchestration
C. Infrastructure as code
D. CLI cloud administration
E. API gateway
Show Answer
Correct Answer: C
Explanation: Infrastructure as code defines network and security configurations in reusable, machine-readable templates. Applying those templates consistently automates deployments and lets the organization update policies across many instances at scale.
Question 3
A software analyst is conducting a forensic investigation. The analyst needs to differentiate between approved software components and those used within an application If used as part of the CI/CD pipeline, which of the following would most effectively help the analyst do this?
A. Dynamic analysis
B. Branch protection
C. Desenalization
D. Code signing
Show Answer
Correct Answer: D
Explanation: Code signing applies a verifiable digital signature to software artifacts, allowing the analyst or CI/CD pipeline to confirm their publisher and detect changes. This helps distinguish approved, trusted components from unapproved or altered ones.
Question 4
A company with a large, cloud-native, e-commerce website wants to know more details about an ongoing, sophisticated attack against the web platform. Which of the following is the best technique?
A. User behavior analytics
B. Dark web monitoring
C. Structured Threat Information exchange
D. High-interaction honeypots
Show Answer
Correct Answer: D
Explanation: High-interaction honeypots provide realistic systems that attackers can interact with, allowing defenders to observe and analyze their techniques and behavior in detail. The other options focus on user activity analysis, monitoring underground forums, or exchanging threat information.
Question 5
A security architect wants to configure a mail server so it maintains an updated list of IOCs and blocks known-malicious incoming emails. Which of the following will the security architect most likely need for this task?
A. Log analyzer
B. Threat feed API
C. Scheduled task
D. Webhooks
E. Inbox deletion code
F. Security runbook
Show Answer
Correct Answer: B
Explanation: A threat feed API supplies updated indicators of compromise that the mail server can use to identify and block known-malicious incoming email. A scheduled task could automate checks, but it does not provide the threat intelligence itself.
Question 6
Which of the following mechanisms must a security protocol provide in order for zero-knowledge proofs to work in practical cryptographic applications?
A. Challenge-response series
B. Shared secret key derivation
C. Multiparty value splitting
D. Three-way handshake
Show Answer
Correct Answer: A
Explanation: Zero-knowledge proofs commonly use a challenge-response sequence: the verifier issues a challenge, and the prover responds in a way that demonstrates knowledge of the secret without revealing it. Shared-key derivation, multiparty value splitting, and a three-way handshake are not required mechanisms.
Question 7
A security analyst is attempting to determine which user accessed an internal web server. The analyst obtains the following address assignment logs from the VPN and logs from the domain when authenticating for the VPN from the SIEM:
Which of the following actions should the analyst take?
A. Confirm that the workstation and hostnames are the same in both logs.
B. Use the assigned VPN addresses for failed logins to identify the user.
C. Ensure that all log sources are configured to the same time zone.
D. Reduce the delay in VPN logs being sent to the SIEM.
Show Answer
Correct Answer: C
Explanation: To correlate VPN address assignments with domain authentication events and identify the user, the analyst must ensure timestamps from both log sources use the same time zone. Otherwise, events may appear out of sequence or fail to match.
Question 8
Which of the following best explains an AI model denial-of-service attack?
A. Users posting large, computationally intensive data sets
B. Untrustworthy and unverified model output
C. An adversary attacking the API of an AI service
D. Using the model output to understand its parameters or architecture
Show Answer
Correct Answer: A
Explanation: A model denial-of-service attack overwhelms the model with large or computationally intensive inputs, exhausting resources and making the service slow or unavailable. Inferring a model’s parameters from its output (D) is model extraction, not denial of service.
Sources:
https://troj.ai/blog/model-denial-of-service
https://chainofthought.show/glossary/model-denial-of-service
Question 9
Which of the following preconditions must be met in order for homomorphic encryption to become practical in mainstream data-in-use applications?
A. Availability of updated ECC curves that provide quantum resistance
B. Coprocessors made available with more appropriate security extensions
C. Finalization of a standard PQC suite of lattice- and code-based algorithms
D. Capability to run the most advanced LLMs while disconnected from the internet
Show Answer
Correct Answer: B
Explanation: Homomorphic encryption is computationally expensive. More suitable coprocessors and hardware extensions could accelerate encrypted computation enough for mainstream data-in-use applications. Quantum-resistant ECC curves, a finalized PQC suite, and offline LLM capability are not prerequisites.
Question 10
A systems administrator works for an organization that is merging with another one. The systems administrator needs to produce specific reports for the board of directors. Which of the following actions is the board of directors most likely taking?
A. Exercising due diligence
B. Enforcing a non-disclosure agreement
C. Investigating their right of first refusal
D. Performing third-party attestations
Show Answer
Correct Answer: A
Explanation: The board is most likely exercising due diligence: reviewing reports to assess the other organization’s operations, risks, and obligations before completing the merger.
$19
Get all 400 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.