
CompTIASecurityX (CASP+)
Domain 1Objective 8
Threat Modeling CAS-005 Practice Questions (Page 3)
Part of the Governance, risk, and compliance domain, which accounts for 20% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 1–2 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
5concepts
20%of the exam
Questions 11–15
- 11
In the STRIDE threat model, which threat category is concerned with an attacker being able to modify data or code?
Select an answer first - 12
Which threat actor characteristic is most commonly associated with organized crime groups?
Select an answer first - 13
A security team is using CAPEC to understand how an attacker might exploit a buffer overflow vulnerability. Which CAPEC category would they most likely consult?
Select an answer first - 14
A security analyst is mapping an adversary's actions to MITRE ATT&CK. The adversary is observed using a legitimate remote desktop application to access a workstation and then transferring data to an external server. Which ATT&CK technique is the analyst MOST likely documenting for the data transfer?
Select an answer first - 15
An attacker sends a specially crafted email to an employee, impersonating the CEO and requesting an urgent wire transfer. Which attack pattern does this describe?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.