CompTIA SecurityX Practice Questions: Access Control

6 free, exam-style CompTIA SecurityX (CAS-005) practice questions covering Access Control, each with the correct answer and an explanation. Start a timed exam below, or scroll on to read through the questions.

🧠

Mini Exam

25 Questions · 50 minutes

Start Quiz 🚀
🏆

Mock SecurityX Exam

85 Questions · 165 minutes

Start Quiz 🚀
📅

Daily Quiz

10 Questions · 20 minutes

Start Quiz 🚀
🎯

Standard Practice

50 Questions · 100 minutes

Start Quiz 🚀

Access Control practice questions

Answers and explanations are shown. Take the timed exam above to test yourself first.

Q1. What is the PRIMARY security benefit of using hardware security keys for MFA?

  • A.Phishable authentication
  • B.Resistance to phishing and MITM attacks✓ Correct
  • C.Shared credentials
  • D.No encryption
Explanation: Hardware keys use cryptographic proofs that can't be phished. Learn more.

Q2. Which of the following is MOST important when implementing passwordless authentication?

  • A.Fallback to SMS OTP
  • B.FIDO2 WebAuthn standards compliance✓ Correct
  • C.Disabled MFA
  • D.No device attestation
Explanation: FIDO2 provides phishing-resistant passwordless auth. Learn more.

Q3. A company wants employees to access multiple SaaS apps using the corporate identity provider. Which standard is commonly used for federation?

  • A.SAML✓ Correct
  • B.TFTP
  • C.ARP
  • D.SNMPv1
Explanation: SAML is commonly used for federated single sign-on between an identity provider and service providers. Learn more.

Q4. Which access control model evaluates attributes such as user role, device health, and location?

  • A.ABAC✓ Correct
  • B.DAC only
  • C.MAC address filtering only
  • D.Break-glass only
Explanation: Attribute-based access control makes authorization decisions from multiple subject, object, action, and environment attributes. Learn more.

Q5. Which privileged access approach grants administrator rights only when needed and for a limited time?

  • A.Just-in-time PAM✓ Correct
  • B.Shared root password
  • C.Permanent local admin for all users
  • D.Anonymous elevation
Explanation: Just-in-time privileged access reduces standing privileges by granting elevated rights only for approved sessions. Learn more.

Q6. Which control reduces blast radius when a production service account is compromised?

  • A.Least privilege and scoped permissions✓ Correct
  • B.Domain administrator rights
  • C.Shared passwords
  • D.Wildcard cloud permissions
Explanation: Scoped permissions limit what a compromised identity can access or change. Learn more.

More CompTIA SecurityX practice topics

Keep studying CompTIA SecurityX

Full CompTIA SecurityX practice exam · CompTIA SecurityX study guide · All CompTIA practice questions

Last updated