exam questions

Exam CAS-005 All Questions

View all questions & answers for the CAS-005 exam

Exam CAS-005 topic 1 question 2 discussion

Actual exam question from CompTIA's CAS-005
Question #: 2
Topic #: 1
[All CAS-005 Questions]

An organization is working to secure its development process to ensure developers cannot deploy artifacts directly into the production environment. Which of the following security practice recommendations would be the best to accomplish this objective?

  • A. Implement least privilege access to all systems.
  • B. Roll out security awareness training for all users.
  • C. Set up policies and systems with separation of duties.
  • D. Enforce job rotations for all developers and administrators.
  • E. Utilize mandatory vacations for all developers.
  • F. Review all access to production systems on a quarterly basis.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HopHopHipHip
3 weeks, 3 days ago
Selected Answer: C
Separation of duties (SoD) is a foundational security principle that prevents a single individual from having control over all aspects of a critical process. In this case, it ensures that the people who write the code (developers) are not the same ones who deploy or approve it for production. Job rotations: Useful for avoiding fraud and reducing knowledge silos, but not relevant to deployment control.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...