
CompTIASecurityX (CASP+)
Domain 1Objective 8
Threat Modeling CAS-005 Practice Questions (Page 2)
Part of the Governance, risk, and compliance domain, which accounts for 20% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
5concepts
20%of the exam
Questions 6–10
- 6
Which attack pattern is characterized by an attacker intercepting and potentially altering communications between two parties without their knowledge?
Select an answer first - 7
During a threat modeling exercise, a team identifies that an attacker could exploit a misconfigured firewall to gain unauthorized access to an internal database. Which attack pattern category does this represent?
Select an answer first - 8
During a threat modeling session, a team identifies that an attacker could use a phishing email to trick an employee into downloading a malicious attachment that installs ransomware. Which attack pattern category does this represent?
Select an answer first - 9
A security analyst is reviewing threat intelligence for a regional bank. The intelligence indicates a series of targeted phishing campaigns using legitimate-looking email domains and malware that evades antivirus. The campaigns are well-resourced and appear to be sponsored by a nation-state. Which actor characteristic is MOST relevant when prioritizing defenses?
Select an answer first - 10
What is the primary purpose of the MITRE CAPEC framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.