Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 66 pages
Exam (elaborations)

CompTIA SecurityX (CASP+) CAS 005 Certification Exam Practice Question Bank Advanced-Level Practice Questions for Security Architects, Senior Security Engineers, and Enterprise Security Practitioners a well detailed one 2025 / 2026 written

Document preview thumbnail
Preview 4 out of 66 pages

CompTIA SecurityX (CASP+) CAS 005 Certification Exam Practice Question Bank Advanced-Level Practice Questions for Security Architects, Senior Security Engineers, and Enterprise Security Practitioners a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




CompTIA SecurityX (CASP+) CAS-
005 Certification Exam Practice
Question Bank Advanced-Level
Practice Questions for Security
Architects, Senior Security
Engineers, and Enterprise
Security Practitioners a well
detailed one written
and graded A+ upgraded




Domain 1: Governance, Risk, and Compliance (GRC) – 20% of Exam

, 2




Question 1

A multinational organization is implementing a new third-party risk management program.
Which of the following represents the MOST effective approach for continuous vendor risk
assessment?

A) Conduct annual on-site audits for all third-party vendors
B) Implement continuous monitoring using automated GRC tools with real-time threat
intelligence feeds
C) Require all vendors to complete a self-assessment questionnaire once per quarter
D) Rely on vendor-provided SOC 2 Type II reports exclusively

-” detailed answer 100 % correct :-”B

Rationale: Continuous monitoring using automated GRC tools with real-time threat intelligence
feeds provides ongoing visibility into vendor security posture rather than point-in-time
assessments. Annual audits (A) are insufficient for detecting emerging risks. Self-assessments (C)
are subjective and lack verification. SOC 2 reports (D) are valuable but represent only a snapshot
and should complement, not replace, continuous monitoring.



Question 2

A security architect is developing a threat model for a new cloud-native application. Which
threat modeling methodology is MOST appropriate for identifying trust boundary violations in a
microservices architecture?

A) PASTA
B) STRIDE
C) OCTAVE
D) TRIKE

-” detailed answer 100 % correct :-”B

Rationale: STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service,
Elevation of Privilege) is specifically designed to identify threats across trust boundaries, making
it ideal for microservices architectures where numerous trust boundaries exist between
services. PASTA (A) is risk-centric and more suited for business-driven threat modeling. OCTAVE
(C) is operational-focused. TRIKE (D) uses a risk-based approach with threat trees.

, 3



Question 3

An organization must comply with both GDPR and CCPA requirements for data subject access
requests (DSARs). Which data governance control BEST enables efficient DSAR fulfillment?

A) Implementing data loss prevention (DLP) at network egress points
B) Maintaining an accurate data inventory with classification and data lineage mapping
C) Encrypting all personal data at rest using AES-256
D) Implementing role-based access control (RBAC) for data stores

-” detailed answer 100 % correct :-”B

Rationale: An accurate data inventory with classification and lineage mapping enables
organizations to locate, retrieve, and provide personal data efficiently in response to DSARs. DLP
(A) focuses on preventing data exfiltration. Encryption (C) protects data confidentiality but
doesn't aid in locating data. RBAC (D) controls access but doesn't provide the discovery
capabilities needed for DSAR compliance.



Question 4

A security program manager is creating a RACI matrix for incident response activities. In a RACI
matrix, what does the "A" represent?

A) Accountable
B) Assigned
C) Approved
D) Assessed

-” detailed answer 100 % correct :-”A

Rationale: In a RACI matrix, "A" represents Accountable—the person ultimately responsible for
ensuring the activity is completed correctly. "R" is Responsible (the doer), "C" is Consulted
(provides input), and "I" is Informed (kept updated).



Question 5

Which security framework is MOST appropriate for an organization seeking to align its IT service
management with business objectives while maintaining strong security governance?

A) NIST CSF
B) COBIT

, 4



C) ISO/IEC 27001
D) ITIL

-” detailed answer 100 % correct :-”B

Rationale: COBIT (Control Objectives for Information and Related Technologies) is specifically
designed to align IT governance with business objectives and includes comprehensive security
governance components. NIST CSF (A) is focused on cybersecurity risk management. ISO/IEC
27001 (C) is an information security management standard. ITIL (D) focuses on IT service
management rather than security governance.



Question 6

A financial institution is required to comply with PCI DSS for its payment processing systems.
Which requirement mandates that cardholder data environments maintain network
segmentation?

A) Requirement 1
B) Requirement 3
C) Requirement 6
D) Requirement 10

-” detailed answer 100 % correct :-”A

Rationale: PCI DSS Requirement 1 specifically addresses installing and maintaining network
security controls, including network segmentation to isolate the cardholder data environment
(CDE) from other networks. Requirement 3 (B) covers protecting stored cardholder data.
Requirement 6 (C) addresses secure development. Requirement 10 (D) covers logging and
monitoring.



Question 7

A security analyst is evaluating the risk of a new vendor relationship. The vendor will have
access to sensitive customer PII. Which risk assessment approach BEST quantifies the potential
financial impact of a data breach involving this vendor?

A) Qualitative risk assessment using a high/medium/low scale
B) Quantitative risk assessment calculating single loss expectancy (SLE) and annualized loss
expectancy (ALE)

Document information

Uploaded on
July 25, 2026
Number of pages
66
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions