CompTIA SecurityX CAS-005 (V5) Practice Question

A cloud-hosted generative-AI platform allows users to install community plug-ins that extend core functionality. During a security review, engineers notice that several third-party plug-ins request administrator-level API scopes and perform no authorization checks before invoking privileged back-end services.

Which of the following controls would MOST effectively prevent a malicious or compromised plug-in from executing unintended high-privilege actions in the production environment?

  • Increase the default OAuth token lifetime so plug-ins do not need to re-authenticate frequently

  • Enable verbose audit logging of all plug-in activity and review the logs weekly

  • Enforce role-based access control and least-privilege scopes for each plug-in, combined with sandbox isolation

  • Store plug-in service credentials in environment variables instead of source code

CompTIA SecurityX CAS-005 (V5)
Governance, Risk, and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $64
$529.00 $465.00
SAVE $70
CompTIA SecurityX Voucher with Retake
v5 / CAS-005
Includes Retake
$578.00 $508.00
Bash, the Crucial Exams Chat Bot
AI Bot