CompTIA SecurityX CAS-005 (V5) Practice Question

An enterprise relies on a single perimeter firewall to protect its internal network. During a threat-modeling exercise, the security architect must decide whether this control is sufficient against advanced persistent threats (APTs) that frequently use zero-day exploits, phishing, and lateral movement. Which statement BEST justifies why one firewall alone is inadequate in this scenario?

  • Advanced adversaries can employ application-layer attacks, encrypted tunnels, and insider compromise to bypass or avoid perimeter filtering; layered controls such as IDS/IPS, endpoint protection, and network segmentation reduce this risk.

  • Next-generation firewalls automatically adapt their rules to any new threat, eliminating the need for additional security controls.

  • Modern stateful firewalls add latency that conflicts with IDS sensors, so an additional firewall is required only to improve performance.

  • Perimeter firewalls cannot process any IPv6 traffic, leaving the network wholly exposed to IPv6-borne threats.

CompTIA SecurityX CAS-005 (V5)
Governance, Risk, and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $64
$529.00 $465.00
SAVE $70
CompTIA SecurityX Voucher with Retake
v5 / CAS-005
Includes Retake
$578.00 $508.00
Bash, the Crucial Exams Chat Bot
AI Bot