Comptia

CAS-005 Free Practice Questions — Page 6

Question 51

An application security engineer is examining the IAM configuration for a workload. The following is a sample of the decoded payload and header: Which of the following is the most concerning risk?

A. Lateral movement
B. Privilege escalation
C. Credential stuffing
D. RCE from deserialization
Show Answer
Correct Answer: B
Explanation:
Privilege escalation is the most concerning risk when a workload’s service-account IAM role has excessive permissions that could be used to gain broader access. Credential stuffing and deserialization-based RCE are not indicated by an IAM configuration. The sample header and payload are not included here, so this assumes they show an overprivileged role.

Question 52

A company’s engineers must ensure that it is difficult for competitors to determine how the company’s software works. Which of the following techniques can help achieve this objective?

A. Removing dead code
B. Using code signing
C. Diversifying binaries
D. Stripping debug symbols
Show Answer
Correct Answer: D
Explanation:
Stripping debug symbols removes metadata such as function names and source-line mappings, making a binary harder to analyze and understand. Code signing verifies authenticity and integrity, while removing dead code or diversifying binaries does not directly conceal how the software works.

Question 53

An organization has a hybrid architecture that requires disparate systems to communicate with one another without a common chain of trust. Which of the following is the best solution?

A. Deploying a hierarchical access control model
B. Enabling context-based authentication
C. Using microsegmentation between servers
D. Implementing remote attestation services
Show Answer
Correct Answer: D
Explanation:
Remote attestation lets a system cryptographically demonstrate its hardware and software integrity to another system, establishing a basis for trust even when the systems do not share a common trust chain.

Question 54

An IT team receives reports from an employee who is experiencing account lockouts. The analyst sees brute-force attempts from countries where the company does not have offices. Which of the following solutions would best address this issue?

A. Using conditional access for user accounts
B. Removing the maximum number of failed login attempts
C. Implementing SSO for all applications
D. Enforcing password rotations every 60 days
Show Answer
Correct Answer: A
Explanation:
Conditional access can restrict sign-ins based on geographic location, blocking or challenging login attempts from countries where the company has no offices. The other options do not directly address the suspicious login locations; removing failed-attempt limits could make brute-force attacks easier.

Question 55

A security architect is designing Zero Trust enforcement policies for all end users. The majority of users work remotely and travel frequently for work. Which of the following controls should the security architect do first?

A. Switch user MFA from software-based tokens to hardware time-based OTPs.
B. Implement TLS decryption and inspect inbound and outbound network traffic.
C. Enforce daily posture compliance checks against the endpoint security controls.
D. Deploy context-aware reauthentication with UBA baseline deviations.
Show Answer
Correct Answer: D
Explanation:
Context-aware reauthentication can respond to deviations from a user’s normal behavior without treating routine remote work or travel as inherently suspicious. It supports adaptive Zero Trust enforcement better than relying on fixed network locations or periodic checks.

Question 56

A reverse engineer is analyzing a malware sample from a recent security incident. When debugging and disassembling the code, the engineer finds the following section of the code: Which of the following does this malware try to evade?

A. IOC extraction
B. Code similarity
C. Dynamic analysis
D. Malware attribution
Show Answer
Correct Answer: B
Explanation:
The code section itself is missing from the prompt, so the answer cannot be confirmed from the evidence shown. If it demonstrates code mutation or obfuscation, that is used to evade code-similarity detection.

Question 57

A multinational enterprise is planning to implement a centralized authentication solution across its global offices. The risk team identifies that some regional offices operate in areas with high latency and some data centers experience intermittent connectivity issues. The Chief Information Officer requests a solution that minimizes authentication disruptions without compromising security. Which of the following is the best risk treatment strategy?

A. Implement a hybrid identity solution with local failover authentication
B. Require that all users authenticate only during on-site visits to headquarters
C. Accept the risk due to the low probability of simultaneous authentication failures
D. Outsource authentication to a third-party cloud provider
Show Answer
Correct Answer: A
Explanation:
A hybrid identity solution with local failover authentication preserves centralized security controls while allowing regional offices to authenticate during high latency or intermittent connectivity. This minimizes disruption without accepting the risk or imposing impractical restrictions.

Question 58

A company receives several complaints from customers regarding its website. An engineer implements a parser for the web server logs that generates the following output: Which of the following should the company implement to best resolve the issue?

A. IDS
B. CDN
C. WAF
D. NAC
Show Answer
Correct Answer: B
Explanation:
A CDN can improve website performance and availability by serving content from edge locations closer to customers and reducing load on the origin server. The referenced parser output is not included, so this assumes the complaints concern slow or unreliable access rather than malicious web traffic.

Question 59

A security engineer wants to improve the security of an application as part of the development pipeline. The engineer reviews the following component of an internally developed web application that allows employees to manipulate documents from a number of internal servers. response = requests.get(url) Users can specify the document to be parsed by passing the document URL to the application as a parameter. Which of the following is the best solution to verify the quality and security of this component?

A. Indexing
B. Output encoding
C. Code scanner
D. Penetration testing
Show Answer
Correct Answer: C
Explanation:
A code scanner can be integrated into the development pipeline to flag unsafe use of a user-supplied URL in requests.get(url), which could allow server-side request forgery (SSRF).

Question 60

An analyst is using the Diamond Model of Intrusion Analysis to identify the likely chain of activities associated with an attacker's activities. The threat hunter has completed the core components of the model but needs to consider meta factors to more deeply understand the situation. Which of the following should the threat hunter seek to understand within the model?

A. Direction
B. Velocity
C. Capabilities
D. Infrastructure
Show Answer
Correct Answer: A
Explanation:
Direction is a Diamond Model meta-feature that adds context to an intrusion event. Capabilities and infrastructure are core components, not meta-features. Sources: https://www.vectra.ai/topics/diamond-model-of-intrusion-analysis https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/diamond-model-intrusion-analysis

$19

Get all 400 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.