Comptia

CAS-005 Free Practice Questions — Page 3

Question 21

An engineer sees the following segment while manually integrating legacy code into a modern application: Which of the following functions or expressions should the engineer modify?

A. Line [03]; String destination[len];
B. Line [03]; char source[20];
C. Line [04]; if (sizeof(source) > 8)
D. Line [04]; Remove if-else clause
E. Line [05]; snprintf (...);
F. Line [05]; memcpy(...);
Show Answer
Correct Answer: D
Explanation:
Because `source` is declared as `char source[20]`, `sizeof(source)` is always 20, so `sizeof(source) > 8` is always true. The `else` branch is unreachable, making the if-else clause redundant.

Question 22

A security engineer is reviewing a security incident in which an employee account was compromised. The engineer notes the following activity after reviewing the logs: Which of the following is the best way to reduce the probability of a future compromise?

A. Using a different third-party MFA vendor
B. Configuring password complexity to include special characters
C. Implementing conditional access across the organization
D. Increasing the rotation rate of account credentials
Show Answer
Correct Answer: C
Explanation:
Implementing conditional access is the best broad measure: it can require stronger verification or restrict access based on factors such as device compliance, location, and sign-in risk. Password complexity and more frequent rotation are less effective general protections, and switching MFA vendors alone does not address the underlying access risk.

Question 23

A pharmaceutical company employs automated control systems to fabricate chemicals. During a recent experiment to attempt to secure these systems, a security engineer finds that the controllers do not appear to be sensitive to additional network latency. Which of the following is the best recommendation for this issue?

A. Performing integrity checks on control system command journals
B. Performing baseline reviews on the system configurations
C. Integrating a proxy to drop improperly formatted commands
D. Implementing in-line encryption between the control systems
E. Deploying and configuring a protocol accelerator
Show Answer
Correct Answer: C
Explanation:
Because the controllers tolerate additional latency, an inline protocol-aware proxy is practical. It can inspect control-system commands and drop improperly formatted ones before they reach the controllers. Encryption would protect communications but would not validate whether commands are properly formed.

Question 24

A SOC analyst is investigating an event in which a penetration tester was able to successfully create and execute a payload. The analyst pulls the following command history from the affected server: $ uname -a && env $ vim foo.c $ gcc foo.c /tmp/lockfile $ chmod +x /tmp/lockfile $ ./tmp/lockfile Which of the following should the analyst implement to improve the security of the server?

A. Kernel-supported ASLR controls
B. Application controls with allow lists
C. OS restrictions of globally writable folders
D. EDR signatures that terminate specific processes
Show Answer
Correct Answer: B
Explanation:
Application allowlisting can prevent the newly compiled, unauthorized payload from executing. ASLR does not block execution of arbitrary binaries, and process-specific EDR signatures are less general. Restricting writable directories can help, but allowlisting most directly addresses this create-and-execute behavior.

Question 25

A cyber security architect seeks to improve vulnerability management and orchestrate a large number of vulnerability checks. Key constraints include: • There are 512 containerized microservices • Vulnerability data is sourced from multiple scanners • CIS baselines must be enforced • Scan activity must be scheduled. Which of the following automation workflows best meets this objective?

A. Employing an endpoint data collection system
B. Deploying an XCCDF scanner
C. Utilizing CVSS reports for SOC analysts
D. Using a repository scanner to enforce IaC security
Show Answer
Correct Answer: B
Explanation:
An XCCDF scanner can run standardized configuration checks against CIS baselines. Its scans can be scheduled across the environment; the other options do not directly provide baseline compliance checks. Sources: https://tech-insider.org/cis-benchmarks-server-hardening-2026

Question 26

Which of the following cryptographic techniques is the most resistant to quantum computing decryption attacks?

A. Elliptic curve
B. Zero-knowledge proofs
C. Lattice-based
D. AEAD
Show Answer
Correct Answer: C
Explanation:
Lattice-based cryptography is a leading family of post-quantum cryptographic techniques, relying on problems for which no efficient quantum-solving algorithm is known. Elliptic-curve cryptography is vulnerable to Shor’s algorithm; zero-knowledge proofs are a proof technique rather than a particular quantum-resistant primitive; and AEAD is an encryption mode whose quantum resistance depends on the underlying cipher and key size.

Question 27

The Chief Information Security Officer must ensure that an organization's baseline workload is standardized prior to deployment and any modifications are immediately returned to the approved configuration. Which of the following are the best ways to assist with meeting these goals? (Choose two.)

A. CNAPP
B. SIEM
C. IaC
D. PowerShell scripts
E. Automated patching
F. Code assist
Show Answer
Correct Answer: A, C
Explanation:
IaC defines a repeatable, approved workload configuration before deployment. A CNAPP can continuously monitor deployed cloud workloads for configuration drift and help remediate deviations from that baseline.

Question 28

A security architect wants to integrate a new data source for its SOC team that meets the following requirements • Incident escalation should include specific data points • Clear remediation actions should be included for the incident response team • Timeliness and accuracy are the most important factors Which of the following is the best way to meet the architect's objective?

A. Known-exploit vulnerability database
B. Review incident escalation playbook
C. Validation of incident scoring
D. Industry threat feeds from the ISAC
Show Answer
Correct Answer: D
Explanation:
Industry threat feeds from an ISAC provide timely, sector-specific threat intelligence—such as indicators, context, and recommended mitigations—that can enrich incident escalations with relevant details and actionable response guidance. The other options are a vulnerability resource or process reviews, rather than an ongoing threat-intelligence data source.

Question 29

A security engineer discovers that some workstations are trying to establish communication with an unknown domain. The engineer compiles the following information: Which of the following best describes this attack?

A. Fast flux
B. Sinkholing
C. On-path attack
D. DNS poisoning
Show Answer
Correct Answer: A
Explanation:
The question appears to omit the compiled information needed to distinguish the options. Based on the available wording, fast flux is the likely intended answer: it uses rapidly changing IP addresses for a domain to conceal resilient malicious infrastructure. A domain alone attempting communication is not enough to confirm fast flux.

Question 30

A security officer is receiving alerts from a cloud service provider about a new wave of phishing campaigns. To prepare employees, the cloud service provider advises the company to make announcements and develop basic security competence. Which of the following solutions best aligns with the cloud service provider’s advice?

A. Enhancing crisis management
B. Developing tabletop exercises
C. Establishing a security awareness program
D. Creating simulated attacks
Show Answer
Correct Answer: C
Explanation:
A security awareness program communicates emerging threats to employees and builds their basic security knowledge and skills. Tabletop exercises and simulated attacks are practice or testing methods, while crisis management focuses on responding to incidents.

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.