View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 41.
A security architect is designing a cloud-native application that must protect secrets used by workloads. Which approach provides the strongest security?
- Store secrets in a centralized secrets-management platform and issue short-lived credentials to authorized workloads
2. Embed credentials directly in container images
3. Store passwords in plaintext environment files committed to source control
4. Use one permanent shared secret for all services
Correct Answer: 1
Explanation:
A centralized secrets-management platform can securely store credentials, enforce access policies, rotate secrets, maintain audit records, and issue short-lived credentials to authorized workloads. Embedding credentials in images or source-controlled files greatly increases the risk of accidental disclosure. A single long-lived shared credential also creates excessive blast radius and weakens accountability. Mature cloud-native designs increasingly use workload identity, dynamic secrets, automated rotation, and tightly scoped permissions to reduce exposure of static credentials.
Question 42.
An enterprise wants to ensure that only approved and verified container images can run in its production Kubernetes clusters. Which control best meets this requirement?
- Disable all image scanning
2. Allow developers to deploy images from any public repository
3. Rely only on container names
4. Use admission policies that verify image signatures and approved provenance
Correct Answer: 4
Explanation:
Admission controls can prevent unapproved workloads from running by verifying image signatures, provenance, repository source, and other deployment requirements before a container is admitted to the cluster. Allowing arbitrary public images increases software-supply-chain risk, while container names provide no meaningful integrity assurance. Image scanning remains useful but should be combined with signature verification and trusted provenance. This approach helps prevent tampered, unapproved, or incorrectly built artifacts from entering production.
Question 43.
A company needs to prevent confidential information from being copied to unauthorized cloud storage services from managed endpoints. Which control is most appropriate?
- DNS caching
2. Network address translation
3. Data loss prevention with endpoint and cloud controls
4. RAID mirroring
Correct Answer: 3
Explanation:
Data loss prevention can identify sensitive information and enforce policies that prevent or monitor unauthorized transfer through endpoints, browsers, email, cloud applications, removable media, and other channels. DNS caching, NAT, and RAID serve unrelated purposes. Effective DLP depends on accurate data classification, contextual policy, user education, and carefully tuned enforcement. Organizations should also monitor sanctioned and unsanctioned cloud services so sensitive information is not moved outside approved environments.
Question 44.
A security architect wants to reduce dependency on passwords for privileged access while making authentication highly resistant to phishing. Which solution is best?
- SMS one-time codes
2. Hardware-backed passkeys or FIDO2 authenticators
3. Knowledge-based security questions
4. Longer password expiration intervals
Correct Answer: 2
Explanation:
FIDO2 and hardware-backed passkeys use public-key cryptography and bind authentication to the legitimate service origin, making them highly resistant to credential phishing and replay. SMS codes can still be captured through phishing or SIM-based attacks, while security questions are often predictable or exposed. Extending password lifetimes does not address phishing risk. Privileged access benefits especially from phishing-resistant MFA combined with device trust, least privilege, and just-in-time administrative authorization.
Question 45.
Which security architecture best reduces risk when a remote workforce accesses SaaS applications directly from the internet rather than through a corporate data center?
- Identity-aware access controls with device posture evaluation and conditional access
2. Trust any device that knows the application URL
3. Disable MFA for remote workers
4. Allow access based only on the user’s public IP address
Correct Answer: 1
Explanation:
Identity-aware conditional access evaluates factors such as user identity, authentication strength, device compliance, location, risk signals, and requested application before allowing access. This is better suited to modern SaaS usage than relying only on a corporate perimeter. Public IP addresses can change and do not establish trustworthy identity or device state. MFA should generally be strengthened for remote access rather than disabled. Conditional access supports zero-trust principles in distributed environments.
Question 46.
An organization wants to protect sensitive analytics performed on encrypted data without exposing the plaintext to the processing environment. Which technology is specifically designed for computation over encrypted information?
- Tokenization
2. Network segmentation
3. Secure boot
4. Homomorphic encryption
Correct Answer: 4
Explanation:
Homomorphic encryption enables certain computations to be performed on encrypted data without first decrypting it into plaintext. This can be valuable in specialized privacy-preserving analytics scenarios where the processing party should not directly access the underlying data. Tokenization substitutes sensitive values with tokens, while segmentation and secure boot address different security concerns. Homomorphic encryption can have substantial computational overhead, so organizations should evaluate performance and supported operations before selecting it.
Question 47.
A security engineer discovers that administrators can approve their own privileged access requests. Which governance principle is being violated?
- Defense in depth
2. Availability
3. Separation of duties
4. Data minimization
Correct Answer: 3
Explanation:
Separation of duties divides sensitive responsibilities among multiple individuals or roles so one person cannot independently initiate and approve a high-risk action. Allowing administrators to approve their own privileged access weakens oversight and increases fraud or misuse risk. Approval workflows should involve independent authorization where appropriate. Separation of duties is particularly important for privileged access, financial transactions, key management, production changes, and other activities where insider misuse could have significant consequences.
Question 48.
Which control best reduces the risk that a compromised application server can directly communicate with a sensitive database it does not need to access?
- Increase DNS TTL values
2. Enforce network segmentation and explicit allow rules between application tiers
3. Enable public access to the database
4. Use identical firewall rules for every server
Correct Answer: 2
Explanation:
Network segmentation with explicit allow rules limits communication to approved application paths. A server that does not require database access should be unable to establish such connections. This reduces lateral movement and constrains the blast radius of a compromised workload. Increasing DNS TTL values does not enforce access control, while public database exposure significantly increases risk. Segmentation should be combined with strong authentication, service identity, and least-privilege database permissions.
Question 49.
Which security practice provides the strongest assurance that an infrastructure-as-code template has not been modified after approval?
- Digitally sign approved templates and verify signatures before deployment
2. Store templates only as email attachments
3. Rename approved files
4. Disable version control history
Correct Answer: 1
Explanation:
Digital signatures can provide cryptographic integrity and authenticity for approved infrastructure-as-code artifacts. Deployment tooling can verify signatures before applying changes, helping prevent unauthorized modification. Email storage or file naming does not provide meaningful integrity protection, and disabling version control removes important traceability. IaC security should also include code review, policy validation, protected repositories, automated testing, and controlled deployment pipelines.
Question 50.
A company wants to detect data exfiltration through unusual DNS query patterns. Which security capability is most appropriate?
- Full-disk encryption
2. Printer auditing
3. RAID monitoring
4. DNS analytics and anomaly detection
Correct Answer: 4
Explanation:
DNS analytics can identify unusual query volumes, long encoded subdomains, rare domains, abnormal request patterns, and other behavior consistent with DNS tunneling or exfiltration. Full-disk encryption protects stored information but does not detect network misuse. Printer and RAID monitoring serve unrelated purposes. DNS telemetry should be correlated with endpoint, network, and identity data to distinguish malicious tunneling from legitimate applications that generate unusual DNS traffic.
Question 51.
An organization needs to ensure that cloud administrators cannot silently change security policies without detection. Which control best supports this requirement?
- Disable logging of administrative activity
2. Use shared privileged accounts
3. Centralize immutable audit logging with alerting for security-policy changes
4. Allow unrestricted administrative changes outside change-management processes
Correct Answer: 3
Explanation:
Centralized and tamper-resistant audit logs provide accountability for administrative actions and can generate alerts when critical security policies change. Logs should ideally be protected in a separate security boundary so privileged users cannot easily erase evidence. Shared accounts weaken attribution, while disabling logging removes visibility. Strong cloud governance also uses change approval, infrastructure-as-code, least privilege, separation of duties, and continuous configuration monitoring.
Question 52.
Which statement best describes the purpose of certificate pinning in an application?
- It replaces encryption with hashing.
2. It restricts trust to an expected certificate or public key rather than accepting any generally trusted certificate.
3. It disables server authentication.
4. It automatically prevents all application vulnerabilities.
Correct Answer: 2
Explanation:
Certificate pinning restricts an application to a specific certificate, public key, or approved trust relationship, reducing the risk that an unexpected certificate issued by another trusted authority is accepted. This can make certain man-in-the-middle attacks more difficult. However, pinning introduces operational challenges because certificate rotation must be carefully managed. It does not replace encryption, eliminate server authentication, or prevent unrelated application vulnerabilities.
Question 53.
A company is concerned that a trusted employee may intentionally copy sensitive files shortly before resigning. Which detection strategy is most appropriate?
- Correlate DLP alerts, unusual file access, removable-media activity, and identity-risk indicators
2. Disable all employee monitoring
3. Rely only on antivirus signatures
4. Remove audit logging from file servers
Correct Answer: 1
Explanation:
Potential insider-risk activity is best identified by correlating multiple contextual signals rather than relying on one event. Useful indicators can include unusual access to sensitive repositories, large data transfers, removable-media use, cloud uploads, and identity-risk changes. Antivirus signatures are unlikely to detect legitimate tools used for unauthorized copying. Monitoring should be implemented consistently with legal, privacy, and organizational requirements and should focus on behavior relevant to protecting sensitive information.
Question 54.
Which architecture provides the strongest protection for a signing key used to approve production software releases?
- Store the key in a public repository.
2. Save the key in a developer’s home directory.
3. Email the key to release managers.
4. Use hardware-backed key storage with tightly controlled signing operations.
Correct Answer: 4
Explanation:
A production signing key is a high-value asset because compromise could allow an attacker to make malicious software appear legitimate. Hardware-backed key storage, such as an HSM, helps prevent direct extraction while providing controlled cryptographic operations, auditing, and access enforcement. Storing the key in user directories, email, or repositories exposes it to unnecessary risk. Strong signing processes also use separation of duties, approval workflows, and restricted build environments.
Question 55.
Which approach is most effective for identifying unknown malicious activity across a large enterprise when no specific indicator of compromise is available?
- Disable telemetry that does not match known signatures.
2. Search only for known file hashes.
3. Use threat hunting based on behavioral hypotheses and cross-source telemetry.
4. Investigate only systems already confirmed compromised.
Correct Answer: 3
Explanation:
Threat hunting is useful when defenders do not have a specific known indicator. Hunters develop hypotheses about attacker behavior and examine endpoint, identity, network, cloud, and application telemetry for patterns that could indicate hidden compromise. Known hashes remain useful but cannot detect many new or modified techniques. Effective threat hunting often produces new detections and identifies telemetry gaps that can improve future monitoring.
Question 56.
Which security concept is being applied when an organization deploys endpoint protection, network segmentation, strong identity controls, and centralized monitoring rather than relying on a single safeguard?
- Single sign-on
2. Defense in depth
3. Data localization
4. Obfuscation
Correct Answer: 2
Explanation:
Defense in depth uses multiple complementary security controls so that failure or bypass of one layer does not immediately result in complete compromise. Endpoint security, segmentation, strong identity, application controls, encryption, logging, and incident response can work together to constrain attackers. The goal is not simply to deploy more products but to create independent preventive, detective, and responsive layers across likely attack paths.
Question 57.
A business-critical application must survive the failure of an entire cloud region. Which design best supports this requirement?
- Deploy independent application and data capacity in multiple regions with tested failover
2. Place all instances in one availability zone
3. Store backups only on the active application server
4. Rely exclusively on manual rebuilding after an outage
Correct Answer: 1
Explanation:
Multi-region architecture reduces dependence on a single regional failure domain. Critical components, data replication, network paths, identity dependencies, and operational procedures should all be considered. Failover must also be tested because configuration errors or hidden dependencies can prevent recovery when needed. A single availability zone or region cannot protect against region-wide failure. Resilience planning should be aligned with documented RTO and RPO requirements.
Question 58.
Which scenario most strongly indicates a possible OAuth consent phishing attack?
- A scheduled database backup completes.
2. A user changes a password after expiration.
3. A workstation receives a normal operating-system patch.
4. A user grants a newly registered third-party application broad access to email and files after clicking an unsolicited link.
Correct Answer: 4
Explanation:
OAuth consent phishing attempts to convince users to grant a malicious application legitimate authorization tokens rather than stealing the user’s password directly. Broad permissions to email, files, or other cloud resources granted to an unfamiliar application after an unsolicited request are highly suspicious. Security teams should review the application registration, publisher, requested scopes, consent logs, and subsequent activity. If malicious, authorization should be revoked and related accounts and applications investigated.
Question 59.
Which security control most directly reduces the risk that sensitive production data is exposed when copied into development environments?
- Increase developer administrator privileges.
2. Disable encryption in development.
3. Use data masking or synthetic data instead of unnecessary production records.
4. Place development systems directly on the public internet.
Correct Answer: 3
Explanation:
Data masking and synthetic data reduce exposure by allowing developers to test applications without using unnecessary real customer or regulated information. Production data copied into lower-security environments can create serious privacy and compliance risk. Data minimization should be applied so only the information required for a legitimate purpose is processed. Development environments should also use appropriate access controls, logging, encryption, and segmentation rather than being treated as inherently low risk.
Question 60.
Which approach best supports secure use of artificial intelligence models integrated with internal enterprise applications?
- Give the model unrestricted access to all corporate systems.
2. Apply least-privilege tool access, input and output controls, logging, and defenses against prompt-based manipulation.
3. Disable authorization checks whenever an AI agent requests a resource.
4. Allow model-generated actions to execute with global administrator privileges.
Correct Answer: 2
Explanation:
AI-integrated applications should be treated as potentially untrusted decision-making components rather than automatically privileged actors. Access to tools and internal systems should be narrowly scoped, sensitive inputs and outputs controlled, actions logged, and high-impact operations subjected to authorization or human approval. Prompt injection and indirect manipulation can cause models to misuse connected tools. Applying least privilege and explicit policy enforcement reduces the blast radius if the model behaves unexpectedly or processes malicious instructions.