Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 61 pages
Exam (elaborations)

CompTIA SecurityX (CAS-005) Bridge Certification Exam – Advanced Practice Question Bank 150 Multiple-Choice Questions | Advanced/Hard Difficulty | For Experienced Security Professionals a well detailed one 2025 / 2026 written and graded A+

Document preview thumbnail
Preview 4 out of 61 pages

CompTIA SecurityX (CAS-005) Bridge Certification Exam – Advanced Practice Question Bank 150 Multiple-Choice Questions | Advanced/Hard Difficulty | For Experienced Security Professionals a well detailed one 2025 / 2026 written and graded A+ upgraded

Content preview

1




CompTIA SecurityX (CAS-005)
Bridge Certification Exam –
Advanced Practice Question Bank
150 Multiple-Choice Questions |
Advanced/Hard Difficulty | For
Experienced Security
Professionals a well detailed one
written and graded
A+ upgraded


Domain 1: Governance, Risk, and Compliance (GRC)

Question 1
A multinational financial services organization operates in the EU, US, and Asia-Pacific regions.
The security architect is designing a unified risk management program that must comply with

, 2



GDPR, CCPA, SOX, and local banking regulations. Which of the following approaches best
addresses this requirement while minimizing operational friction?

A) Implement the most stringent regulation globally and apply it uniformly across all regions
B) Deploy separate, region-specific compliance programs managed independently by each
regional office
C) Establish a federated GRC framework with centralized policy governance and regional control
implementation
D) Outsource all compliance activities to a third-party managed security service provider

-” detailed answer 100 % correct :-”C
Rationale: A federated GRC framework provides centralized governance for consistency while
allowing regional teams to implement controls that address local regulatory nuances. This
balances compliance requirements with operational efficiency. Option A creates unnecessary
overhead in less stringent regions; Option B lacks centralized oversight; Option D transfers risk
without addressing the underlying governance requirement.



Question 2
A security architect is evaluating the organization's cybersecurity resiliency metrics for an
upcoming board presentation. Which metric best quantifies the organization's ability to
maintain operations during an active ransomware attack?

A) Mean Time to Detect (MTTD)
B) Recovery Time Objective (RTO) and Recovery Point Objective (RPO) alignment
C) Number of security incidents detected per quarter
D) Percentage of endpoints with antivirus software installed

-” detailed answer 100 % correct :-”B
Rationale: RTO and RPO directly measure an organization's ability to recover operations and
data after a disruption. MTTD measures detection speed but not recovery capability. Incident
counts and antivirus coverage are operational metrics that do not measure resiliency during an
active attack.



Question 3
Which of the following regulatory frameworks specifically requires organizations to report data
breaches within 72 hours of discovery?

, 3



A) HIPAA
B) GLBA
C) GDPR
D) SOX

-” detailed answer 100 % correct :-”C
Rationale: GDPR Article 33 requires notification to the supervisory authority within 72 hours of
becoming aware of a personal data breach. HIPAA requires notification within 60 days; GLBA
and SOX do not have specific 72-hour breach notification requirements.



Question 4
A security architect is implementing controls to meet CMMC Level 2 requirements for a defense
contractor. Which of the following is a foundational requirement at this level?

A) Implementation of a complete zero trust architecture
B) Establishment of a formal incident response plan with documented procedures
C) Deployment of post-quantum cryptographic algorithms
D) Implementation of AI-based threat detection across all network segments

-” detailed answer 100 % correct :-”B
Rationale: CMMC Level 2 requires the establishment of formal incident response plans and
procedures as part of basic cyber hygiene. Zero trust architecture and post-quantum
cryptography exceed Level 2 requirements; AI-based threat detection is not a specific CMMC
Level 2 requirement.



Question 5
An organization is adopting NIST CSF 2.0 as its primary security framework. During the "Identify"
function, which activity should the security team prioritize?

A) Deploying endpoint detection and response tools
B) Conducting asset inventory and risk assessment
C) Implementing security awareness training
D) Establishing incident response playbooks

-” detailed answer 100 % correct :-”B
Rationale: The NIST CSF Identify function focuses on understanding the organizational context,
assets, and risks. Asset inventory and risk assessment are foundational Identify activities. EDR

, 4



deployment relates to Protect/Detect functions; training relates to Protect; playbooks relate to
Respond.



Question 6
A security architect is developing a risk management strategy that must address both
quantitative and qualitative risk assessments. Which of the following best describes the
relationship between these two approaches?

A) Quantitative assessment replaces qualitative assessment for all enterprise risks
B) Qualitative assessment is used for regulatory compliance; quantitative is used for operational
risks
C) Both approaches should be used complementarily, with quantitative providing financial
impact data and qualitative providing contextual risk insights
D) Qualitative assessment is more accurate and should be used exclusively

-” detailed answer 100 % correct :-”C
Rationale: Quantitative risk assessment provides monetary values and probabilistic data (e.g.,
ALE, SLE), while qualitative assessment provides contextual, subjective risk rankings. Used
together, they provide a comprehensive risk picture. Neither approach should be used
exclusively.



Question 7
An organization must comply with PCI DSS Requirement 11, which addresses vulnerability
management. Which activity is explicitly required under this requirement?

A) Annual external vulnerability scans and quarterly internal scans
B) Daily automated penetration testing
C) Monthly social engineering assessments
D) Continuous red team exercises

-” detailed answer 100 % correct :-”A
Rationale: PCI DSS Requirement 11.2 requires quarterly internal and external vulnerability scans
and annual penetration testing. Daily testing, monthly social engineering, and continuous red
team exercises are not explicitly required by PCI DSS.



Question 8
A security architect is designing a compliance monitoring program for a hybrid cloud

Document information

Uploaded on
July 25, 2026
Number of pages
61
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$24.69

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions