CompTIA SecurityX (Extended) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 215 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions CAS-005 210 Questions CAS-003 361 Questions CAS-004 149 Questions.

Try Simulator

CA1-005 Sample Questions

  1. Question 1

    Q1

    A company plans to implement a research facility with intellectual property data that should be protected. The following is the security diagram proposed by the security architect:Which of the following security architect models is illustrated by the diagram?

    Question 1 image
    Show answer & explanation

    Correct answer: D

  2. Question 2

    Q2Multiple answers

    A financial technology firm works collaboratively with business partners in the industry to share threat intelligence within a central platform. This collaboration gives partner organizations the ability to obtain and share data associated with emerging threats from a variety of adversaries. Which of the following should the organization most likely leverage to facilitate this activity? (Choose two.) A.CWPPB.YARAC.ATT&CKD.STIXE.TAXIIF.JTAG

    Show answer & explanation

    Correct answers: D, E

  3. Question 3

    Q3Multiple answers

    During a gap assessment, an organization notes that BYOD usage is a significant risk. The organization implemented administrative policies prohibiting BYOD usage. However, the organization has not implemented technical controls to prevent the unauthorized use of BYOD assets when accessing the organization's resources. Which of the following solutions should the organization implement to best reduce the risk of BYOD devices? (Choose two.) A.Cloud IAM, to enforce the use of token-based MFAB.Conditional access, to enforce user-to-device bindingC.NAC, to enforce device configuration requirementsD.PAM, to enforce local password policiesE.SD-WAN, to enforce web content filtering through external proxiesF.DLP, to enforce data protection capabilities

    Show answer & explanation

    Correct answers: B, C

  4. Question 4

    Q4Multiple answers

    A security administrator is performing a gap assessment against a specific OS benchmark. The benchmark requires the following configurations be applied to endpoints:• Full disk encryption• Host-based firewall• Time synchronization• Password policies• Application allow listing• Zero Trust application accessWhich of the following solutions best addresses the requirements? (Choose two.)

    Show answer & explanation

    Correct answers: A, D

  5. Question 5

    Q5

    A global organization is reviewing potential vendors to outsource a critical payroll function. Each vendor's plan includes using local resources in multiple regions to ensure compliance with all regulations. The organization's Chief Information Security Officer is conducting a risk assessment on the potential outsourcing vendors' subprocessors. Which of the following best explains the need for this risk assessment? A.Risk mitigations must be more comprehensive than the existing payroll provider.B.Due care must be exercised during all procurement activities.C.The responsibility of protecting PII remains with the organization.D.Specific regulatory requirements must be met in each jurisdiction.

    Show answer & explanation

    Correct answer: C

  6. Question 6

    Q6

    A manufacturing plant is updating its IT services. During discussions, the senior management team created the following list of considerations:• Staff turnover is high and seasonal.• Extreme conditions often damage endpoints.• Losses from downtime must be minimized.• Regulatory data retention requirements exist.Which of the following best addresses the considerations? A.Establishing further environmental controls to limit equipment damageB.Using a non-persistent virtual desktop interface with thin clientsC.Deploying redundant file servers and configuring database journalingD.Maintaining an inventory of spare endpoints for rapid deployment

    Show answer & explanation

    Correct answer: B

  7. Question 7

    Q7

    A company runs a DAST scan on a web application. The tool outputs the following recommendations:• Use Cookie prefixes.• Content Security Policy - SameSite=strict is not set.Which of the following vulnerabilities has the tool identified? A.RCEB.XSSC.CSRFD.TOCTOU

    Show answer & explanation

    Correct answer: C

  8. Question 8

    Q8Multiple answers

    A company hired an email service provider called my-email.com to deliver company emails. The company started having several issues during the migration. A security engineer is troubleshooting and observes the following configuration snippet:Which of the following should the security engineer modify to fix the issue? (Choose two.) A.The email CNAME record must be changed to a type A record pointing to 192.168.1.11B.The TXT record must be changed to "v=dmarc ip4:192.168.1.10 include:my-email.com ~all"C.The srv01 A record must be changed to a type CNAME record pointing to the email serverD.The email CNAME record must be changed to a type A record pointing to 192.168.1.10E.The TXT record must be changed to "v=dkim ip4:192.168.1.11 include :my-email.com ~all"F.The TXT record must be changed to "v=spf ip4:192.168.1.10 include :my-email.com ~all"G.The srv01 A record must be changed to a type CNAME record pointing to the web01 server

    Question 8 image
    Show answer & explanation

    Correct answers: D, F

  9. Question 9

    Q9

    A government contractor is preparing for a Cybersecurity Maturity Model Certification (CMMC) Level 2 assessment. The security architect needs to design a solution that enforces data residency for Controlled Unclassified Information (CUI) within a multi-tenant cloud environment, ensuring that data is processed and stored exclusively within U.S. sovereign boundaries. Which cloud architecture and service model would be the MOST appropriate choice to meet this stringent compliance requirement?

    Show answer & explanation

    Correct answer: B

    Government community clouds like AWS GovCloud and Azure Government are specifically designed to meet the stringent compliance and data sovereignty requirements of U.S. government agencies and contractors. These environments are physically and logically isolated from the public cloud, are managed exclusively by vetted U.S. persons, and provide the necessary controls to handle regulated data like CUI, making them the most appropriate choice for CMMC Level 2 and higher.

  10. Question 10

    Q10

    A SOC manager is developing a threat hunting program. The initial hunts will be based on Tactics, Techniques, and Procedures (TTPs) from the MITRE ATT&CK framework. The manager wants to create a structured, repeatable process for the hunt team. Which of the following represents the most logical and effective sequence of steps for a hypothesis-driven threat hunt?

    Show answer & explanation

    Correct answer: C

    This is the correct sequence for a structured, hypothesis-driven threat hunt. The process begins by forming a specific hypothesis (e.g., 'An adversary is using PowerShell for lateral movement'). Next, the team gathers relevant intelligence and collects data from sources like EDR, SIEM, and network logs. They then investigate this data to find patterns confirming or denying the hypothesis. Finally, if the hunt is successful, the findings are used to create automated detection rules (enrichment) to catch this activity in the future.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the CA1-005 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 935 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon