TechNuggets Academy
CAS-005

Free CompTIA SecurityX Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$5094 exam domainsLevel Expert2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Governance, Risk, and Compliance
A company wants continuous compliance evidence for PCI DSS across hundreds of cloud accounts, reducing manual audit prep effort. Which approach BEST meets this requirement?
Policy-as-code enforced in the CI/CD pipeline provides continuous, automated validation of controls at deployment time and generates machine-readable audit evidence, which is the core intent of compliance-as-code programs at enterprise scale.
Question 2 of 12 · Security Architecture
A global enterprise is retiring its site-to-site VPN concentrators for remote employees who need direct, low-latency access to internal SaaS and on-premises applications. The security team requires continuous identity and device posture verification before and during every session, regardless of network location, as part of a SASE rollout. Which component should be the core access control mechanism in this architecture?
ZTNA brokers per-session, per-application access based on continuous identity, device posture, and contextual risk evaluation instead of granting broad network-level trust like a VPN. It is the defining access component of a SASE architecture and directly satisfies the requirement for continuous verification regardless of location.
Question 3 of 12 · Security Engineering
A financial services firm is redesigning its TLS infrastructure to protect data-in-transit against 'harvest-now-decrypt-later' attacks, where adversaries capture encrypted traffic today to decrypt once cryptographically relevant quantum computers exist. The firm still needs to maintain compatibility with legacy clients during a multi-year transition. Which approach BEST addresses this requirement?
Hybrid key exchange combines a classical algorithm with a NIST-standardized post-quantum KEM (ML-KEM), providing quantum resistance for the key establishment step while remaining backward compatible with classical security guarantees during the transition period — the recommended approach for mitigating harvest-now-decrypt-later risk.
Question 4 of 12 · Security Operations
A financial services SOC receives over 10,000 alerts daily from firewalls, EDR, IDS, and cloud security tools. Analysts spend most of their shift pivoting between consoles to manually correlate related alerts, causing critical incidents to be missed during triage. The SOC lead wants a platform that ingests alerts from all tools, automatically correlates related events, and triggers predefined automated response playbooks (e.g., isolate host, disable account) based on configurable criteria — without requiring analysts to manually execute each response step. Which solution BEST meets this requirement?
SOAR (Security Orchestration, Automation, and Response) integrated with the SIEM is purpose-built to ingest correlated alert data and execute automated, criteria-based playbooks (isolation, account disable, ticket creation) without manual tool-switching, directly reducing analyst fatigue and response time.
Question 5 of 12 · Governance, Risk, and Compliance
A critical database server has an asset value (AV) of $500,000. The exposure factor (EF) for a ransomware attack is 40%. The annualized rate of occurrence (ARO) is 0.5 (once every two years). What is the Annualized Loss Expectancy (ALE)?
SLE = AV x EF = $500,000 x 0.4 = $200,000. ALE = SLE x ARO = $200,000 x 0.5 = $100,000.
Question 6 of 12 · Security Architecture
A payment processor must allow its data science team to run aggregate spending-pattern analytics on card transaction records while ensuring the primary account number (PAN) is never exposed in the analytics environment, and referential integrity across records for the same card must be preserved. Which data protection technique BEST meets these requirements?
Tokenization replaces the PAN with a non-sensitive surrogate token that maps consistently back to the same card, preserving referential integrity for analytics (e.g., grouping transactions by the same card) while the actual PAN never leaves the secure token vault, removing it from the analytics environment's compliance scope.
Question 7 of 12 · Security Engineering
A company deployed an LLM-powered customer support application using retrieval-augmented generation (RAG) against an internal knowledge base. The security team discovers that users can craft inputs causing the model to ignore its system instructions and return confidential internal documents verbatim, bypassing intended restrictions. Which control BEST mitigates this risk?
Prompt injection attacks manipulate model behavior at the input/output boundary; an independent guardrail layer that validates and filters both inputs (detecting injection patterns) and outputs (blocking confidential data leakage) directly addresses the attack vector regardless of what the underlying model does.
Question 8 of 12 · Security Operations
A SOC's UEBA (User and Entity Behavior Analytics) tool is generating a high rate of false positives by flagging routine after-hours administrative activity performed by IT staff as anomalous, causing analysts to ignore its alerts. Which action BEST reduces false positives while preserving the tool's ability to detect true behavioral anomalies?
UEBA effectiveness depends on comparing behavior against an appropriate peer group. Building role-based baselines (e.g., comparing admins to other admins) accounts for legitimate variance in privileged workflows while still flagging genuine deviations within that peer group.
Question 9 of 12 · Governance, Risk, and Compliance
A CISO discovers that a critical SaaS vendor processing customer PII has no SOC 2 Type II report and has subcontracted data processing to a fourth-party cloud provider without notification. Which action should the CISO prioritize FIRST?
Standard third-party risk management practice is to obtain independent attestation of controls and formalize subprocessor governance (right-to-audit, notification, approval clauses) in the contract before deciding on further action.
Question 10 of 12 · Security Architecture
An enterprise data center runs dozens of application workloads on virtual machines within the same flat VLAN. Security architects need to enforce granular, workload-specific policies that block lateral (east-west) movement between VMs even though they share the same subnet, without redesigning the physical network. Which control should be implemented?
Host-based micro-segmentation enforces granular, workload-level policies directly at the hypervisor or host firewall layer, independent of the underlying VLAN or physical topology, and effectively blocks east-west lateral movement between VMs on the same subnet without any physical network redesign.
Question 11 of 12 · Security Engineering
A web application team wants to reduce TLS handshake latency caused by certificate revocation checks while also eliminating the privacy concern of clients revealing their browsing destinations directly to the Certificate Authority during each check. Which solution BEST meets both requirements?
OCSP stapling has the web server periodically query the CA and cache (staple) a signed revocation response to present during the TLS handshake, eliminating client-to-CA round trips (reducing latency) and preventing the CA from learning which clients are visiting which sites (preserving privacy).
Question 12 of 12 · Security Operations
During an enterprise attack surface assessment, a security analyst identifies that SMBv1 is enabled and exposed on 200 servers supporting a decommissioned application, though some undocumented internal tools may still reference it. What is the BEST remediation approach?
SMBv1 is a legacy protocol with well-documented critical vulnerabilities (e.g., EternalBlue) and no reliable patch path; the correct enterprise approach is to segment/isolate the affected assets, validate actual dependencies through traffic monitoring, and then disable the protocol once confirmed safe — balancing risk reduction with operational continuity.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →

CAS-005 exam — quick answers

How much does the CAS-005 exam cost?

The exam fee is approximately $509 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 4 domains: Governance, Risk, and Compliance (20%), Security Architecture (27%), Security Engineering (31%), Security Operations (22%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

How do I get the discount?

Use code FREETEST33 at checkout for $34.99 (list undefined) through Oct 6 — the enroll button applies it automatically.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Governance, Risk, and Compliance →Security Architecture →Security Engineering →Security Operations →