Exam Details

  • Exam Code
    :CAS-005
  • Exam Name
    :CompTIA SecurityX
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :261 Q&As
  • Last Updated
    :Mar 31, 2025

CompTIA CompTIA Certifications CAS-005 Questions & Answers

  • Question 21:

    An organization has deployed a cloud-based application that provides virtual event services globally to clients. During a typical event, thousands of users access various entry pages within a short period of time. The entry pages include sponsor-related content that is relatively static and is pulled from a database. When the first major event occurs, users report poor response time on the entry pages. Which of the following features is the most appropriate for the company to implement?

    A. Horizontal scalability

    B. Vertical scalability

    C. Containerization

    D. Static code analysis

    E. Caching

  • Question 22:

    company management elects to cancel production. Which of the following risk strategies is the company using in this scenario?

    A. Avoidance

    B. Mitigation

    C. Rejection

    D. Acceptance

  • Question 23:

    Which of the following security features do email signatures provide?

    A. Non-repudiation

    B. Body encryption

    C. Code signing

    D. Sender authentication

    E. Chain of custody

  • Question 24:

    A company has data it would like to aggregate from its PLCs for data visualization and predictive maintenance purposes. Which of the following is the most likely destination for the tag data from the PLCs?

    A. External drive

    B. Cloud storage

    C. System aggregator

    D. Local historian

  • Question 25:

    A security engineer has learned that terminated employees' accounts are not being disabled. The termination dates are updated automatically in the human resources information system software by the appropriate human resources staff. Which of the following would best reduce risks to the organization?

    A. Exporting reports from the system on a weekly basis to disable terminated employees' accounts

    B. Granting permission to human resources staff to mark terminated employees' accounts as disabled

    C. Configuring allowed login times for all staff to only work during business hours

    D. Automating a process to disable the accounts by integrating Active Directory and human resources information systems

  • Question 26:

    An organization needs to classify its systems and data in accordance with external requirements. Which of the following roles is best qualified to perform this task?

    A. Systems administrator

    B. Data owner

    C. Data processor

    D. Data custodian

    E. Data steward

  • Question 27:

    A senior cybersecurity engineer is solving a digital certificate issue in which the CA denied certificate issuance due to failed subject identity validation. At which of the following steps within the PKI enrollment process would the denial have occurred?

    A. RA

    B. OCSP

    C. CA

    D. IdP

  • Question 28:

    A security analyst identified a vulnerable and deprecated runtime engine that is supporting a public-facing banking application. The developers anticipate the transition to modern development environments will take at least a month. Which of the following controls would best mitigate the risk without interrupting the service during the transition?

    A. Shutting down the systems until the code is ready

    B. Uninstalling the impacted runtime engine

    C. Selectively blocking traffic on the affected port

    D. Configuring IPS and WAF with signatures

  • Question 29:

    An organization's load balancers have reached end of life and have a vulnerability that will require them to be replaced. The load balancers are scheduled to be decommissioned within the next month. The management team has decided not to resolve this risk and instead allow the load balancers to remain in place until their decommission date. Which of the following risk handling techniques is the management team using?

    A. Avoid

    B. Mitigate

    C. Accept

    D. Transfer

  • Question 30:

    A help desk analyst suddenly begins receiving numerous calls from remote employees who state they are unable to connect to the VPN. The employees indicate the VPN client software is warning about an expired certificate. The help desk analyst determines the VPN certificate is valid. Which of the following is the most likely cause of the issue?

    A. The certificate has been compromised and needs to be replaced.

    B. The VPN concentrator is running an old version of code and needs to be upgraded.

    C. The NTP settings on the VPN concentrator are incorrectly configured.

    D. The end users are using outdated VPN client software.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CAS-005 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.