nerdexam
CompTIA

CAS-005 · Question #276

An organization hires a security consultant to establish a SOC that includes a threat-modeling function. During initial activities, the consultant works with system engineers to identify…

The correct answer is C. Network and data flow diagrams covering the production environment. In the context of establishing a Security Operations Center (SOC) with a threat-modeling function, it's crucial to understand how data flows within the organization's systems. Network and data flow diagrams provide a visual representation of the system's architecture…

Submitted by hans_de· Mar 6, 2026Security Architecture

Question

An organization hires a security consultant to establish a SOC that includes a threat-modeling function. During initial activities, the consultant works with system engineers to identify antipatterns within the environment. Which of the following is most critical for the engineers to disclose to the consultant during this phase?

Options

  • AResults from the most recent infrastructure access review
  • BA listing of unpatchable IoT devices in use in the data center
  • CNetwork and data flow diagrams covering the production environment
  • DResults from the most recent software composition analysis
  • EA current inventory of cloud resources and SaaS products in use

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    4% (2)
  • C
    85% (39)
  • E
    2% (1)

Explanation

In the context of establishing a Security Operations Center (SOC) with a threat-modeling function, it's crucial to understand how data flows within the organization's systems. Network and data flow diagrams provide a visual representation of the system's architecture, illustrating how data moves between components, which is essential for identifying potential security weaknesses and antipatterns. Antipatterns are common responses to recurring problems that are ineffective and risk- inducing. By analyzing these diagrams, the consultant can pinpoint areas where security controls may be lacking or misconfigured, thereby facilitating the development of effective threat

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice