Official Bank 0/326

CompTIA SecurityX Certification (CAS-005) - CompTIA Actual Exam Questions

Last updated on April 15, 2026

97% Exam Compliance
326 Total Questions
1
Question

A security engineer reviews an after action report from a previous security breach and notes a long lag time between detection and containment of a compromised account. The engineer suggests using SOAR to address this concern. Which of the following best explains the engineer's goal?

Options
A

To prevent accounts from being compromised

B

To enable log correlation using machine learning

C

To orchestrate additional reporting for the security operations center

D

To prepare runbooks to automate future incident response

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

An administrator brings the company's fleet of mobile devices into its PKI in order to align device WLAN NAC configurations with existing workstations and laptops. Thousands of devices need to be reconfigured in a cost-effective, time-efficient, and secure manner. Which of the following actions best achieve this goal? (Select two)

Select 2
Options
A

Using the existing MDM solution to integrate with directory services for authentication and enrollment

B

Deploying netAuth extended key usage certificate templates

C

Deploying serverAuth extended key usage certificate templates

D

Deploying clientAuth extended key usage certificate templates

E

Configuring SCEP on the CA with an OTP for bulk device enrollment

F

Submitting a CSR to the CA to obtain a single certificate that can be used across all devices

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

A security analyst wants to use lessons learned from a poor incident response to reduce dwell lime in the future The analyst is using the following data points Which of the following would the analyst most likely recommend?

Question image
Options
A

Adjusting the SIEM to alert on attempts to visit phishing sites

B

Allowing TRACE method traffic to enable better log correlation

C

Enabling alerting on all suspicious administrator behavior

D

utilizing allow lists on the WAF for all users using GFT methods

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

A developer makes a small change to a resource allocation module on a popular social media website and causes a memory leak. During a peak utilization period, several web servers crash, causing the website to go offline. Which of the following testing techniques is the most efficient way to prevent this from reoccurring?

Options
A

Load

B

Smoke

C

Regression

D

Canary

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

An engineering team determines the cost to mitigate certain risks is higher than the asset values The team must ensure the risks are prioritized appropriately. Which of the following is the best way to address the issue?

Options
A

Data labeling

B

Branch protection

C

Vulnerability assessments

D

Purchasing insurance

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.