Comptia

CAS-005 Free Practice Questions — Page 20

Question 191

A company wants to improve and automate the compliance of its cloud environments to meet industry standards. Which of the following resources should the company use to best achieve this goal?

A. Jenkins
B. Python
C. Ansible
D. PowerShell
Show Answer
Correct Answer: C
Explanation:
Ansible can automate configuration management across cloud environments and enforce consistent settings aligned with compliance requirements. Jenkins is primarily for CI/CD, while Python and PowerShell are general-purpose scripting tools that typically require custom implementation for this purpose.

Question 192

A developer receives feedback about code quality and efficiency. The developer needs to identify and resolve the following coding issues before submitting the code changes for peer review: • Indexing beyond arrays • Dereferencing null pointers • Potentially dangerous data type combos • Unreachable code • Non-portable constructs Which of the following would be most appropriate for the developer to use in this situation?

A. Linting
B. SBoM
C. DAST
D. Branch protection
E. Software composition analysis
Show Answer
Correct Answer: A
Explanation:
Linting performs static checks on source code and can flag issues such as out-of-bounds indexing, null-pointer dereferences, unsafe type usage, unreachable code, and non-portable constructs before peer review. The other options address dependency inventories, runtime testing, workflow controls, or third-party component risks.

Question 193

During DAST scanning, applications are consistently reporting code defects in open-source libraries that were used to build web applications. Most of the code defects are from using libraries with known vulnerabilities. The code defects are causing product deployment delays. Which of the following is the best way to uncover these issues earlier in the life cycle?

A. Directing application logs to the SIEM for continuous monitoring
B. Modifying the WAF polices to block against known vulnerabilities
C. Completing an IAST scan against the web application
D. Using a software dependency management solution
Show Answer
Correct Answer: D
Explanation:
A software dependency management solution can identify open-source components and flag known vulnerabilities in them during development, before deployment. SIEM and WAF controls operate mainly at runtime, while IAST focuses on testing the running application rather than managing vulnerable dependencies.

Question 194

A company has a requirement in customer contracts that states applications must undergo external audits to identify vulnerabilities. Which of the following is the best action for the company to complete before hiring an external auditor?

A. Gather evidence for the audit.
B. Conduct an internal audit assessment.
C. Identify lessons learned from the audit.
D. Select samples for audit testing.
Show Answer
Correct Answer: B
Explanation:
Conduct an internal audit assessment first to identify and address gaps before engaging an external auditor. Gathering audit evidence and selecting samples are part of audit execution, while lessons learned are identified afterward.

Question 195

A Chief Information Security Officer requests an action plan to remediate vulnerabilities. A security analyst reviews the output from a recent vulnerability scan and notices hundreds of unique vulnerabilities. The output includes the CVSS score, IP address, hostname, and the list of vulnerabilities. The analyst determines more information is needed in order to decide which vulnerabilities should be fixed immediately. Which of the following is the best source for this information?

A. Third-party risk review
B. Business impact analysis
C. Incident response playbook
D. Crisis management plan
Show Answer
Correct Answer: B
Explanation:
A business impact analysis identifies which systems and business processes are most critical and the consequences of their disruption. This context helps prioritize vulnerabilities beyond their CVSS scores, based on business impact.

Question 196

An organization wants to create a threat model to identify vulnerabilities in its infrastructure. Which of the following should be prioritized first?

A. External-facing infrastructure with known exploited vulnerabilities
B. Internal infrastructure with high-severity and known exploited vulnerabilities
C. External-facing infrastructure with a low risk score and no known exploited vulnerabilities
D. External-facing infrastructure with a high risk score that can only be exploited with local access to the resource
Show Answer
Correct Answer: A
Explanation:
Prioritize externally facing infrastructure with known exploited vulnerabilities. It is directly reachable by attackers and has evidence of active exploitation, creating an immediate risk of compromise and a potential foothold for lateral movement. The internal asset in B is also important, but lacks the same direct external exposure.

Question 197

A company acquires a location with a large infrastructure of legacy devices. Because of the hardware's age and the legacy software's limitations, the OS cannot be upgraded, and the machines cannot be virtualized. These machines are not publicly facing, but they do have internet access. The following controls are currently in place: • EDR • Anti-malware • Logging and monitoring • Host-based firewall • Proxied internet access A security architect needs to supplement the existing control strategy with one that restricts unauthorized software. Which of the following controls should the architect recommend to best supplement the existing environment?

A. SIEM
B. Isolation
C. Conditional access
D. Application control
Show Answer
Correct Answer: D
Explanation:
Application control can restrict execution to approved software, directly addressing unauthorized programs on systems that cannot be upgraded or virtualized. SIEM provides monitoring, isolation limits connectivity, and conditional access governs access rather than software execution.

Question 198

Recent reports indicate that a software tool is being exploited. Attackers were able to bypass user access controls and load a database. A security analyst needs to find the vulnerability and recommend a mitigation. The analyst generates the following output: Which of the following would the analyst most likely recommend?

A. Installing appropriate EDR tools to block pass-the-hash attempts
B. Adding additional time to software development to perform fuzz testing
C. Removing hard-coded credentials from the source code
D. Not allowing users to change their local passwords
Show Answer
Correct Answer: C
Explanation:
Hard-coded credentials can let attackers bypass normal user access controls and access the database. Removing them from the source code and using secure credential management is the most appropriate mitigation.

Question 199

After a company discovered a zero-day vulnerability in its VPN solution, the company plans to deploy cloud-hosted resources to replace its current on-premises systems. An engineer must find an appropriate solution to facilitate trusted connectivity. Which of the following capabilities is the most relevant?

A. Container orchestration
B. Microsegmentation
C. Conditional access
D. Secure access service edge
Show Answer
Correct Answer: D
Explanation:
Secure access service edge (SASE) delivers cloud-hosted networking and security capabilities that provide trusted access to cloud resources, reducing reliance on the vulnerable on-premises VPN.

Question 200

Which of the following best explains the importance of determining organizational risk appetite when operating with a constrained budget?

A. Risk appetite directly impacts acceptance of high-impact, low-likelihood events.
B. Organizational risk appetite varies from organization to organization.
C. Budgetary pressure drives risk mitigation planning in all companies.
D. Risk appetite directly influences which breaches are disclosed publicly.
Show Answer
Correct Answer: A
Explanation:
With a constrained budget, an organization must prioritize which risks to mitigate and which to accept. Its risk appetite helps determine whether it will tolerate high-impact, low-likelihood events or allocate limited resources to address them.

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.