CompTIA
CAS-005 · Question #275
During a recent security event, access from the non-production environment to the production environment enabled unauthorized users to: - Install unapproved software - Make unplanned configuration cha
Sign in or unlock CAS-005 to reveal the answer and full explanation for question #275. The question stem and answer options stay visible for context.
Submitted by kevin_r· Mar 6, 2026Security Operations
Question
During a recent security event, access from the non-production environment to the production environment enabled unauthorized users to:
- Install unapproved software
- Make unplanned configuration changes
During the investigation, the following findings were identified:
- Several new users were added in bulk by the IAM team
- Additional firewalls and routers were recently added
- Vulnerability assessments have been disabled for more than 30 days
- The application allow list has not been modified in two weeks
- Logs were unavailable for various types of traffic
- Endpoints have not been patched in over ten days
Which of the following actions would most likely need to be taken to ensure proper monitoring? (Choose two.)
Options
- ADisable bulk user creations by the IAM team
- BExtend log retention for all security and network devices to 180 days for all traffic
- CReview the application allow list daily
- DRoutinely update all endpoints and network devices as soon as new patches/hot fixes are
- EEnsure all network and security devices are sending relevant data to the SIEM
- FConfigure firewall rules to only allow production-to-non-production traffic
Unlock CAS-005 to see the answer
You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.