nerdexam
CompTIA

CAS-005 · Question #275

During a recent security event, access from the non-production environment to the production environment enabled unauthorized users to: - Install unapproved software - Make unplanned configuration cha

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #275. The question stem and answer options stay visible for context.

Submitted by kevin_r· Mar 6, 2026Security Operations

Question

During a recent security event, access from the non-production environment to the production environment enabled unauthorized users to:

  • Install unapproved software
  • Make unplanned configuration changes

During the investigation, the following findings were identified:

  • Several new users were added in bulk by the IAM team
  • Additional firewalls and routers were recently added
  • Vulnerability assessments have been disabled for more than 30 days
  • The application allow list has not been modified in two weeks
  • Logs were unavailable for various types of traffic
  • Endpoints have not been patched in over ten days

Which of the following actions would most likely need to be taken to ensure proper monitoring? (Choose two.)

Options

  • ADisable bulk user creations by the IAM team
  • BExtend log retention for all security and network devices to 180 days for all traffic
  • CReview the application allow list daily
  • DRoutinely update all endpoints and network devices as soon as new patches/hot fixes are
  • EEnsure all network and security devices are sending relevant data to the SIEM
  • FConfigure firewall rules to only allow production-to-non-production traffic

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice