CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part4 Q61-80

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 61.

A security architect wants to ensure that administrative access to critical servers originates only from hardened systems with verified security posture. Which solution is most appropriate?

  1. Privileged access workstations combined with conditional access controls
    2. Shared administrator passwords
    3. Unrestricted remote desktop access from any endpoint
    4. Permanent local administrator rights for all IT staff

Correct Answer: 1

Explanation:

Privileged access workstations provide a hardened environment dedicated to sensitive administrative tasks. When combined with conditional access, the organization can require strong authentication, compliant device posture, approved network location, and other contextual conditions before privileged access is granted. Shared passwords and unrestricted remote access weaken accountability and expand the attack surface. Permanent administrative rights also create unnecessary standing privilege. A strong privileged-access architecture uses separate identities, hardened endpoints, MFA, session monitoring, least privilege, and just-in-time authorization where possible.

Question 62.

Which security technology best protects data while it is actively being processed in memory by a cloud workload?

  1. Full-disk encryption
    2. Tokenization
    3. Network segmentation
    4. Confidential computing using a trusted execution environment

Correct Answer: 4

Explanation:

Confidential computing uses hardware-backed trusted execution environments to protect data while it is being processed. Traditional encryption at rest protects stored information, and TLS protects data in transit, but sensitive information normally must be decrypted for computation. A trusted execution environment helps isolate that processing from the host operating system, hypervisor, or other workloads. Tokenization and segmentation address different security concerns. Confidential computing is especially useful where sensitive data must be processed in infrastructure that is not fully trusted.

Question 63.

An attacker is suspected of stealing browser session cookies to bypass MFA. Which control most directly reduces the usefulness of stolen session tokens?

  1. Longer password expiration periods
    2. Static IP allowlisting only
    3. Short-lived sessions with token revocation and device-bound validation
    4. Disabling session logging

Correct Answer: 3

Explanation:

Short-lived sessions reduce the amount of time a stolen token remains valid, while revocation enables defenders to invalidate active sessions when compromise is suspected. Device binding or other contextual validation can further restrict replay from an unauthorized environment. Password changes alone may not invalidate existing sessions. Static IP controls are often insufficient, especially for mobile or cloud users. Effective session security combines limited token lifetime, continuous validation, strong reauthentication for sensitive actions, and monitoring for anomalous session usage.

Question 64.

Which approach best protects an enterprise API against abuse by an authenticated but compromised client application?

  1. Allow unlimited API requests after authentication.
    2. Apply fine-grained authorization, rate limiting, behavioral monitoring, and scoped tokens.
    3. Disable API logging.
    4. Give every client a permanent administrator token.

Correct Answer: 2

Explanation:

Authentication alone does not prevent an authenticated application from abusing an API. Fine-grained authorization limits what each client can do, while scoped tokens restrict accessible resources and actions. Rate limiting can reduce automated abuse, and behavioral monitoring can identify unusual request patterns. Permanent administrator tokens create excessive privilege, and disabling logging removes useful detection and forensic evidence. A mature API-security design also includes input validation, schema enforcement, secure secret management, and strong token lifecycle controls.

Question 65.

Which security control most directly reduces risk from a compromised CI/CD pipeline attempting to deploy unauthorized infrastructure changes?

  1. Require signed changes, protected branches, approval gates, and policy validation before deployment.
    2. Give the pipeline unrestricted administrator access.
    3. Disable audit logging for build systems.
    4. Allow direct deployment from developer laptops.

Correct Answer: 1

Explanation:

Protected branches, approval gates, digital signing, policy validation, and controlled deployment identities reduce the chance that compromised pipeline components can make unauthorized production changes. Direct deployments and unrestricted administrator permissions dramatically increase supply-chain risk. Audit logging should be preserved so suspicious build or release activity can be investigated. Strong CI/CD security also includes isolated runners, short-lived credentials, dependency scanning, protected signing keys, and separation between build and production administrative privileges.

Question 66.

Which mechanism provides the strongest assurance that a remote system booted using approved firmware and operating-system components?

  1. DNSSEC
    2. Data masking
    3. RAID
    4. Measured boot with remote attestation

Correct Answer: 4

Explanation:

Measured boot records cryptographic measurements of firmware, bootloaders, and other components into trusted hardware such as a TPM. Remote attestation allows another system to verify those measurements against an expected state before granting sensitive access. DNSSEC protects DNS integrity, RAID provides storage resilience, and data masking protects sensitive values. Measured boot and attestation are particularly valuable in zero-trust device validation because they provide evidence about system integrity rather than relying only on credentials.

Question 67.

Which security practice best reduces the risk that an attacker can replace a legitimate software package with a malicious version in an internal repository?

  1. Disable package verification.
    2. Permit anonymous uploads.
    3. Verify package signatures, restrict repository write access, and maintain provenance records.
    4. Allow developers to install packages directly from unknown internet sources.

Correct Answer: 3

Explanation:

Signature verification helps detect unauthorized modification, while strict repository permissions prevent untrusted users from publishing or replacing packages. Provenance records provide traceability about where artifacts originated and how they were built. Anonymous uploads and arbitrary external package use increase supply-chain risk. Internal package repositories should also be monitored, patched, backed up, and integrated with dependency scanning and approval processes for higher-risk components.

Question 68.

Which security architecture is most appropriate for an enterprise that wants users to access internal applications without placing those applications directly on the public internet?

  1. Expose every application through unrestricted inbound firewall rules.
    2. Use a zero-trust access broker or application proxy that authenticates users before providing application-level access.
    3. Disable authentication for internal applications.
    4. Require users to know the private IP address.

Correct Answer: 2

Explanation:

A zero-trust application access solution can authenticate and authorize users before connecting them to private applications without exposing those applications directly to the internet. Access can be based on identity, device posture, risk, and application context. Knowing a private address does not provide security, and disabling authentication creates obvious risk. This model reduces reliance on broad network access and helps limit users to specific applications rather than granting access to entire internal subnets.

Question 69.

A threat hunter wants to identify possible credential dumping activity on Windows endpoints. Which data source is most valuable?

  1. Endpoint process and memory-access telemetry
    2. Printer inventory
    3. DNS TTL settings
    4. Backup schedules

Correct Answer: 1

Explanation:

Credential dumping often involves suspicious access to authentication-related processes, memory, registry data, or credential stores. Endpoint telemetry showing process creation, parent-child relationships, memory access, privilege use, and command execution can provide strong evidence. Printer inventory and backup schedules are unrelated. Threat hunters should correlate suspicious endpoint behavior with authentication events, privilege escalation, unusual account activity, and network connections to build a stronger picture of potential credential theft.

Question 70.

Which capability best detects unauthorized transfer of sensitive information through approved collaboration applications?

  1. RAID monitoring
    2. DNS caching
    3. Static NAT
    4. Cloud access security and DLP controls integrated with sanctioned SaaS applications

Correct Answer: 4

Explanation:

Cloud access security and DLP controls can inspect activity in approved SaaS applications and apply policies based on data sensitivity, user identity, destination, and sharing behavior. This is important because legitimate collaboration tools can still be used to exfiltrate data. RAID, DNS caching, and NAT do not provide content-aware data protection. Effective SaaS governance also includes data classification, access controls, audit logging, sharing restrictions, and monitoring of risky user or application behavior.

Question 71.

A company wants to ensure that highly privileged cloud roles are not assigned permanently. Which access model is best?

  1. Permanent administrator access for all engineers
    2. Shared root credentials
    3. Just-in-time privilege elevation with approval and automatic expiration
    4. Anonymous administrative access

Correct Answer: 3

Explanation:

Just-in-time privilege elevation provides administrative permissions only when required and automatically removes them after the approved period. This reduces standing privilege and limits the impact of stolen credentials. Shared root accounts and permanent administrative access increase blast radius and reduce accountability. JIT privilege should be combined with strong MFA, approval workflows, logging, session monitoring, and emergency access procedures so privileged operations remain controlled and auditable.

Question 72.

Which statement best describes data tokenization?

  1. It encrypts an entire disk using one symmetric key.
    2. It substitutes sensitive values with non-sensitive tokens while maintaining the original values in a protected system.
    3. It provides network segmentation.
    4. It verifies firmware integrity.

Correct Answer: 2

Explanation:

Tokenization replaces sensitive values with surrogate tokens that have little or no exploitable meaning outside the tokenization system. The original values remain protected in a secure vault or service. This can reduce exposure of payment or personal data in applications that do not need the original value. Tokenization differs from ordinary encryption because the token itself may not be mathematically reversible without the token service. It does not provide network segmentation or device integrity validation.

Question 73.

Which incident response action is most appropriate immediately after confirming that a cloud access key has been exposed publicly?

  1. Revoke or rotate the key and investigate its recent use.
    2. Wait until the key expires naturally.
    3. Delete audit logs.
    4. Increase the key’s permissions to simplify troubleshooting.

Correct Answer: 1

Explanation:

Once a cloud access key is exposed, it should be treated as compromised. Revoking or rotating the credential limits further misuse, while audit logs should be reviewed to determine whether the key was already abused. Waiting for natural expiration leaves a window for attackers, and increasing permissions would worsen the potential impact. Responders should also identify where the secret was exposed, remove it from repositories or systems, and improve controls to prevent similar leaks.

Question 74.

Which design best protects a critical application from denial of service caused by traffic spikes from many distributed internet sources?

  1. Use a single unprotected origin server.
    2. Disable rate limiting.
    3. Publish the origin IP directly.
    4. Use distributed DDoS protection, rate controls, resilient scaling, and protected origins.

Correct Answer: 4

Explanation:

Distributed DDoS protection can absorb or filter malicious traffic before it reaches the application, while rate controls and scalable architecture reduce the impact of traffic spikes. Protecting the origin prevents attackers from bypassing the mitigation service and targeting the backend directly. A single exposed server is a major availability risk. DDoS resilience should also include capacity planning, monitoring, upstream provider coordination, and tested incident procedures.

Question 75.

Which security control most directly prevents developers from deploying infrastructure that violates mandatory cloud-security requirements?

  1. Manual review after production deployment only
    2. Rely exclusively on developer memory
    3. Policy-as-code checks integrated into the deployment pipeline
    4. Disable infrastructure version control

Correct Answer: 3

Explanation:

Policy-as-code allows security requirements to be automatically evaluated before infrastructure is deployed. Controls can check for prohibited public exposure, missing encryption, overly broad IAM permissions, insecure network rules, and other configuration risks. Automated enforcement is more consistent than relying solely on memory or post-deployment review. Infrastructure-as-code should also use version control, peer review, testing, and controlled deployment identities to improve security and traceability.

Question 76.

Which statement best describes the purpose of canary tokens in security monitoring?

  1. They provide disk encryption.
    2. They are decoy resources or credentials designed to generate alerts when accessed unexpectedly.
    3. They replace MFA.
    4. They increase network bandwidth.

Correct Answer: 2

Explanation:

Canary tokens are deceptive resources, documents, URLs, credentials, or other artifacts that legitimate users should not normally access. Unexpected interaction can provide a high-value signal of unauthorized activity. They can support early detection of lateral movement, data theft, or reconnaissance. Canary tokens do not replace authentication, encryption, or other controls. They are most effective when alerts are monitored and linked to a well-defined investigation or response process.

Question 77.

Which approach best protects sensitive production credentials from exposure in application configuration files?

  1. Use a secrets manager and retrieve credentials dynamically at runtime.
    2. Store credentials in plaintext files.
    3. Commit secrets to version control.
    4. Use the same credential in every environment.

Correct Answer: 1

Explanation:

A secrets manager centralizes credential storage, access control, rotation, auditing, and controlled retrieval. Applications can request credentials at runtime rather than embedding them in files or source code. Reusing the same secret across environments increases blast radius, while committing credentials to repositories can expose them broadly and persistently. Dynamic secrets and workload identities are even stronger where available because they reduce reliance on long-lived static credentials.

Question 78.

Which behavior is most suspicious for a potential cloud account takeover?

  1. A scheduled compliance report runs at its normal time.
    2. A user views a routine dashboard.
    3. An approved application renews a certificate.
    4. A user authenticates from a new device and immediately creates privileged credentials and disables logging.

Correct Answer: 4

Explanation:

A new-device login followed immediately by creation of privileged credentials and attempts to disable logging is highly suspicious. Attackers often try to establish persistence, elevate privilege, and reduce visibility soon after compromising an account. Routine reports, dashboard access, and expected certificate renewal are generally benign. Incident responders should verify the identity, revoke suspicious sessions, review changes, restore logging, and investigate other activity performed by the account.

Question 79.

Which security design best reduces risk when multiple applications need access to the same sensitive data set but require different operations?

  1. Give every application full read-write access.
    2. Use one shared administrator account.
    3. Create separate service identities and grant each only the specific operations it requires.
    4. Disable authorization checks.

Correct Answer: 3

Explanation:

Separate service identities support least privilege because each application can receive only the operations required for its function. If one workload is compromised, the attacker’s permissions remain limited to that application’s role. Shared administrator accounts and unrestricted permissions create excessive blast radius and poor accountability. Strong service authorization should also include credential rotation, workload identity, logging, and segmentation so application access can be monitored and controlled effectively.

Question 80.

Which approach best supports secure use of autonomous AI agents that can perform actions in enterprise systems?

  1. Give the agent permanent global administrator permissions.
    2. Restrict available tools and permissions, validate actions against policy, log decisions, and require approval for high-impact operations.
    3. Disable authentication for any system accessed by the agent.
    4. Allow every model-generated command to execute automatically.

Correct Answer: 2

Explanation:

Autonomous agents should operate under tightly constrained permissions because model errors, prompt injection, malicious inputs, or unexpected reasoning can lead to harmful actions. Tool access should be limited to required functions, authorization enforced independently of the model, and high-impact operations gated by approval. Detailed logging supports accountability and investigation. Treating an AI agent as a fully trusted administrator creates an unnecessarily large blast radius if the model is manipulated or behaves incorrectly.