CompTIA SecurityX Practice Questions: More Practice Questions

35 free, exam-style CompTIA SecurityX (CAS-005) practice questions covering More Practice Questions, each with the correct answer and an explanation. Start a timed exam below, or scroll on to read through the questions.

🧠

Mini Exam

25 Questions · 50 minutes

Start Quiz 🚀
🏆

Mock SecurityX Exam

85 Questions · 165 minutes

Start Quiz 🚀
📅

Daily Quiz

10 Questions · 20 minutes

Start Quiz 🚀
🎯

Standard Practice

50 Questions · 100 minutes

Start Quiz 🚀

More Practice Questions practice questions

Answers and explanations are shown. Take the timed exam above to test yourself first.

Q1. What is the PRIMARY benefit of using a SIEM system?

  • A.Reducing hardware costs
  • B.Centralized log analysis✓ Correct
  • C.Automating patch management
  • D.Blocking DDoS attacks
Explanation: SIEM aggregates and analyzes logs for threat detection. Learn more.

Q2. What is the PRIMARY purpose of a Security Operations Center (SOC)?

  • A.Developing software
  • B.Monitoring and responding to security incidents✓ Correct
  • C.Managing hardware inventory
  • D.Conducting employee training
Explanation: SOC teams monitor, detect, and respond to security threats. Learn more.

Q3. Which of the following is a key feature of a Security Information and Event Management (SIEM) system?

  • A.Real-time log analysis✓ Correct
  • B.Basic firewall functionality
  • C.Data backup
  • D.User training
Explanation: SIEM systems provide real-time analysis of security alerts. Learn more.

Q4. Which enterprise security metric shows how quickly incidents are detected after compromise?

  • A.Mean time to detect✓ Correct
  • B.Annual license cost
  • C.Cable attenuation
  • D.Disk IOPS only
Explanation: Mean time to detect tracks the average time between incident start and detection. Learn more.

Q5. What is the PRIMARY security benefit of using process-level telemetry for EDR solutions?

  • A.Reduced visibility
  • B.Detection of in-memory and living-off-the-land attacks✓ Correct
  • C.Disabled logging
  • D.No behavioral analysis
Explanation: Process-level visibility detects advanced evasion techniques. Learn more.

Q6. What is the PRIMARY risk of allowing USB devices in a secure environment?

  • A.Increased power consumption
  • B.Data exfiltration✓ Correct
  • C.Slower network speeds
  • D.Software licensing issues
Explanation: USB devices can introduce malware or facilitate data theft. Learn more.

Q7. Which technology can isolate browser sessions so malicious web content does not execute on the endpoint?

  • A.Remote browser isolation✓ Correct
  • B.Static ARP
  • C.Open guest VLAN
  • D.Shared local admin
Explanation: Remote browser isolation executes browser activity away from the endpoint and streams safe rendering results back to the user. Learn more.

Q8. Which of the following is a critical step in incident response?

  • A.Deleting logs
  • B.Containment✓ Correct
  • C.Ignoring alerts
  • D.Delaying patches
Explanation: Containment limits the impact of a security incident. Learn more.

Q9. Which activity best validates that incident evidence remained trustworthy from collection through analysis?

  • A.Maintaining chain of custody✓ Correct
  • B.Deleting duplicate files
  • C.Reusing administrator tokens
  • D.Compressing logs without hashes
Explanation: Chain of custody documents who handled evidence, when, and why, helping preserve integrity and admissibility. Learn more.

Q10. Which response plan role coordinates public messaging during a major breach?

  • A.Communications or public relations lead✓ Correct
  • B.Database indexer
  • C.Wireless controller
  • D.Patch cable technician
Explanation: Public messaging should be coordinated through assigned communications roles to maintain accuracy and consistency. Learn more.

Q11. Which regulation mandates breach notification within 72 hours for EU organizations?

  • A.HIPAA
  • B.GDPR✓ Correct
  • C.CCPA
  • D.SOX
Explanation: GDPR Article 33 requires breach notifications within 72 hours of discovery. Learn more.

Q12. A company relies on an overseas SaaS provider for regulated records. Which risk should be assessed first?

  • A.Data residency and cross-border transfer requirements✓ Correct
  • B.Monitor color calibration
  • C.Printer duplex settings
  • D.Bluetooth speaker pairing
Explanation: Regulated data stored or processed in another jurisdiction can trigger data residency, sovereignty, and transfer obligations. Learn more.

Q13. Which privacy principle requires collecting only the data needed for a stated purpose?

  • A.Data minimization✓ Correct
  • B.Data hoarding
  • C.Key stretching
  • D.Network peering
Explanation: Data minimization limits collection and retention to what is necessary for the business purpose. Learn more.

Q14. A BIA identifies that a payment system must be restored within four hours. Which metric is being defined?

  • A.RTO✓ Correct
  • B.RPO
  • C.MTBF
  • D.SLE
Explanation: Recovery time objective defines the maximum acceptable time to restore a process or system after disruption. Learn more.

Q15. Which metric estimates the average time a system operates before failing?

  • A.MTBF✓ Correct
  • B.RTO
  • C.RPO
  • D.ARO
Explanation: Mean time between failures is used to estimate reliability and plan maintenance or redundancy. Learn more.

Q16. Which strategy keeps a fully equipped alternate site ready for near-immediate failover?

  • A.Hot site✓ Correct
  • B.Cold site
  • C.Paper backup only
  • D.Offline archive
Explanation: A hot site has equipment, connectivity, and data availability needed for rapid recovery. Learn more.

Q17. Which board-level artifact helps align cybersecurity investments with business priorities?

  • A.Security strategy roadmap✓ Correct
  • B.Packet capture ring buffer
  • C.Default router password list
  • D.Workstation wallpaper standard
Explanation: A security roadmap ties initiatives, milestones, risks, and investments to business objectives and governance priorities. Learn more.

Q18. Which enterprise control records who approved a firewall rule change and why?

  • A.Change management ticket✓ Correct
  • B.Packet TTL
  • C.Printer queue
  • D.Screen saver setting
Explanation: Change management records approvals, business justification, implementation details, and rollback steps. Learn more.

Q19. Which security review is most relevant before acquiring a third-party SaaS product?

  • A.Vendor risk assessment✓ Correct
  • B.Keyboard layout audit
  • C.Monitor inventory only
  • D.DHCP lease review
Explanation: Vendor risk assessments evaluate security, privacy, compliance, and operational risks before procurement. Learn more.

Q20. Which of the following is a key security control for IoT device fleets?

  • A.Default credentials
  • B.Secure over-the-air (OTA) update mechanism✓ Correct
  • C.Disabled patching
  • D.No device authentication
Explanation: OTA updates are critical for maintaining IoT device security. Learn more.

Q21. Which of the following is MOST important when securing voice-controlled systems?

  • A.Disabled voice authentication
  • B.Speaker recognition and voice command authorization✓ Correct
  • C.No encryption
  • D.Unrestricted microphone access
Explanation: Voice systems must verify speaker identity and command legitimacy. Learn more.

Q22. What is the PRIMARY security benefit of using Intel SGX for database operations?

  • A.Unrestricted data access
  • B.Confidential query processing in secure enclaves✓ Correct
  • C.Disabled memory protection
  • D.No process isolation
Explanation: SGX enables processing of sensitive data without exposing it to the OS. Learn more.

Q23. What is the PRIMARY security consideration for synthetic data generation systems?

  • A.Complete data replication
  • B.Privacy preservation through statistical dissimilarity✓ Correct
  • C.Disabled access controls
  • D.No integrity checks
Explanation: Synthetic data must not allow reconstruction of original datasets. Learn more.

Q24. Which of the following is a key security control for mitigating optical TEMPEST attacks?

  • A.Unrestricted visibility of screens
  • B.Faraday shielding and screen filters✓ Correct
  • C.Disabled memory protection
  • D.No process isolation
Explanation: Optical emissions must be controlled to prevent screen eavesdropping. Learn more.

Q25. What is the PRIMARY purpose of a Faraday cage?

  • A.Blocking electromagnetic signals✓ Correct
  • B.Enhancing Wi-Fi range
  • C.Cooling servers
  • D.Preventing physical theft
Explanation: Faraday cages block electromagnetic interference (EMI). Learn more.

Q26. Which security model enforces the principle of least privilege by default?

  • A.Bell-LaPadula
  • B.Biba
  • C.Clark-Wilson
  • D.Zero Trust✓ Correct
Explanation: Zero Trust assumes no implicit trust and enforces least privilege access. Learn more.

Q27. Which of the following is a hardware-based security feature for preventing buffer overflow attacks?

  • A.ASLR
  • B.DEP/NX bit✓ Correct
  • C.MAC filtering
  • D.TLS encryption
Explanation: Data Execution Prevention (DEP) or NX bit prevents code execution in memory regions marked as non-executable. Learn more.

Q28. Which of the following is a key security control for mitigating Bluetooth Low Energy (BLE) vulnerabilities?

  • A.Disabled encryption
  • B.Secure pairing and connection parameters✓ Correct
  • C.Public device addresses
  • D.No authentication
Explanation: BLE requires secure pairing to prevent MITM attacks. Learn more.

Q29. What is the PRIMARY security benefit of using ARM TrustZone for mobile payments?

  • A.Unrestricted app access
  • B.Hardware-isolated secure execution environment✓ Correct
  • C.Disabled memory protection
  • D.No process isolation
Explanation: TrustZone provides hardware-enforced separation of sensitive operations. Learn more.

Q30. What is the PRIMARY purpose of a Certificate Authority (CA)?

  • A.Generating encryption keys
  • B.Issuing digital certificates✓ Correct
  • C.Blocking phishing emails
  • D.Managing firewalls
Explanation: CAs validate and issue digital certificates for secure communications. Learn more.

Q31. What is the PRIMARY purpose of a deception technology (e.g., honeypot)?

  • A.Improving network speed
  • B.Detecting intruders✓ Correct
  • C.Automating backups
  • D.Enhancing encryption
Explanation: Deception technologies lure attackers to detect malicious activity. Learn more.

Q32. Which file system metadata is MOST useful for forensic timeline analysis?

  • A.MAC times✓ Correct
  • B.File size
  • C.Permissions
  • D.Checksum
Explanation: Modified, Accessed, and Created (MAC) timestamps help reconstruct events. Learn more.

Q33. What does a high volume of DNS TXT queries indicate?

  • A.Normal web browsing
  • B.Data exfiltration✓ Correct
  • C.DDoS attack
  • D.VPN usage
Explanation: Attackers may use DNS tunneling (TXT queries) to bypass firewalls. Learn more.

Q34. Which backup strategy follows the 3-2-1 rule?

  • A.3 backups, 2 locations, 1 offline✓ Correct
  • B.3 full backups daily
  • C.2 on-site, 1 cloud
  • D.1 backup, 2 encryption keys
Explanation: The 3-2-1 rule ensures redundancy and resilience. Learn more.

Q35. Which platform capability automates incident response steps such as ticket creation and IP blocking?

  • A.SOAR playbooks✓ Correct
  • B.Manual password vault export
  • C.Static routing only
  • D.Screen recording
Explanation: SOAR playbooks orchestrate repeatable security actions across tools to speed response and reduce manual effort. Learn more.

More CompTIA SecurityX practice topics

Keep studying CompTIA SecurityX

Full CompTIA SecurityX practice exam · CompTIA SecurityX study guide · All CompTIA practice questions

Last updated