View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 101.
An enterprise wants to reduce the risk that a compromised identity provider account could be used to access every connected application. Which architectural control provides the strongest additional protection?
- Require application-level authorization, risk-based access policies, and independent privilege boundaries
2. Automatically trust every identity authenticated by the identity provider
3. Disable application authorization checks after SSO authentication
4. Use one shared privileged role across all applications
Correct Answer: 1
Explanation:
Single sign-on simplifies authentication but can increase blast radius if the identity provider is compromised. Applications should still enforce authorization based on user role, requested action, resource sensitivity, device posture, and other risk signals. Privileged applications may also require step-up authentication or separate administrative identities. Treating successful identity-provider authentication as unlimited authorization creates excessive trust. Strong architecture separates authentication from authorization and limits the permissions available to any one compromised identity.
Question 102.
A company needs to protect cryptographic systems against future advances in quantum computing. Which strategy best demonstrates cryptographic agility?
- Hard-code one current algorithm into every application.
2. Avoid maintaining an inventory of cryptographic dependencies.
3. Delay all planning until existing algorithms are officially prohibited.
4. Inventory cryptographic use and design systems so algorithms and keys can be replaced with minimal disruption.
Correct Answer: 4
Explanation:
Cryptographic agility requires visibility into where algorithms, certificates, keys, and protocols are used and the ability to replace them without redesigning entire systems. This is particularly important for post-quantum migration because different applications and protocols may need staged upgrades. Hard-coded cryptography makes migration difficult, while waiting until algorithms are no longer acceptable can create operational pressure. Organizations should maintain crypto inventories, abstraction layers, rotation procedures, compatibility testing, and migration plans.
Question 103.
A security team wants to identify whether attackers are abusing valid cloud credentials to enumerate resources and privileges. Which telemetry is most valuable?
- Printer activity logs
2. Local disk fragmentation statistics
3. Cloud control-plane audit logs
4. Building access records only
Correct Answer: 3
Explanation:
Cloud control-plane audit logs record administrative API calls, identity activity, resource enumeration, permission changes, and other management actions. This telemetry can reveal suspicious reconnaissance performed with valid credentials. Analysts can correlate unusual API sequences, source locations, role assumptions, and privilege changes with authentication events. Printer and disk metrics provide little value for cloud control-plane investigations. Centralized cloud audit logging is therefore a foundational detection and incident-response capability.
Question 104.
Which security control best protects an enterprise from server-side request forgery when an application accepts user-supplied URLs?
- Disable application logging.
2. Validate destinations, restrict outbound network access, and block access to internal metadata services.
3. Allow the application to reach any internal address.
4. Trust URLs that use HTTPS automatically.
Correct Answer: 2
Explanation:
Server-side request forgery can allow attackers to force an application server to access internal services, cloud metadata endpoints, or restricted resources. Defenses include strict URL validation, destination allowlisting where practical, outbound filtering, DNS protections, and controls that prevent access to metadata services. HTTPS alone does not make a destination safe, and unrestricted outbound access increases risk. Application-layer validation and network-level egress restrictions provide complementary protection.
Question 105.
A company wants to prevent one compromised workload identity from being used to retrieve every secret in its cloud environment. Which control best addresses the risk?
- Assign narrowly scoped secret-access policies to individual workload identities.
2. Give all workloads access to the same secret vault administrator role.
3. Store all secrets in one public configuration file.
4. Disable access logging for the secrets platform.
Correct Answer: 1
Explanation:
Each workload should receive access only to the specific secrets required for its function. Fine-grained authorization limits the blast radius if one workload is compromised. Broad administrator access and shared secrets increase the number of resources an attacker can reach. A secrets-management platform should also provide auditing, rotation, short-lived credentials where supported, and separation of administrative roles. Least privilege applies to machine identities just as strongly as it applies to human users.
Question 106.
Which technique best protects sensitive information from unnecessary exposure when data is used for analytics but exact identifiers are not required?
- Publicly publish the original data set.
2. Disable access controls during analysis.
3. Give every analyst production database administrator rights.
4. Apply pseudonymization, masking, or aggregation before analysis.
Correct Answer: 4
Explanation:
Pseudonymization, masking, and aggregation reduce exposure by removing or transforming identifiers that analysts do not need for the intended purpose. This supports data minimization and can reduce privacy risk. Production administrator rights and public access create unnecessary exposure. Organizations should choose the transformation technique based on whether re-identification is required, the sensitivity of the data, regulatory obligations, and the analytical goal.
Question 107.
Which security control most directly helps identify unauthorized firmware modification on enterprise endpoints?
- DNS sinkholing
2. Data tokenization
3. Secure boot combined with measured boot and attestation
4. RAID mirroring
Correct Answer: 3
Explanation:
Secure boot validates approved boot components before execution, while measured boot records integrity measurements that can be evaluated locally or through attestation. Together, these controls provide stronger assurance that firmware and early boot components have not been tampered with. DNS sinkholing, tokenization, and RAID do not verify firmware integrity. Hardware-backed trust mechanisms are particularly valuable for high-assurance endpoints and privileged-access systems.
Question 108.
Which approach best reduces the risk of a malicious administrator secretly changing production firewall policy?
- Allow direct changes with no audit trail.
2. Require peer approval, centralized logging, and controlled deployment of policy changes.
3. Use shared administrator credentials.
4. Disable configuration backups.
Correct Answer: 2
Explanation:
Peer approval and controlled deployment implement separation of duties, while centralized logging provides accountability for who changed what and when. Shared credentials weaken attribution, and disabling backups makes recovery more difficult. High-impact security-policy changes should ideally follow formal change management, use individual privileged identities, support rollback, and generate alerts for unexpected modifications. These controls reduce both malicious misuse and accidental configuration errors.
Question 109.
A security team wants to detect whether a compromised endpoint is communicating with a newly registered command-and-control domain. Which data sources provide the most useful combination?
- DNS telemetry, domain reputation or age data, and endpoint network activity
2. Printer logs only
3. Backup schedules only
4. File compression statistics
Correct Answer: 1
Explanation:
DNS telemetry can show which domain was queried, while domain age and reputation provide context about whether the destination is newly registered or previously associated with malicious activity. Endpoint network telemetry can identify the process making the connection. Correlating these sources improves confidence because newly registered domains are not inherently malicious. Threat detection benefits from combining destination intelligence with endpoint and identity context rather than relying on one indicator alone.
Question 110.
Which control provides the strongest protection against unauthorized use of a cloud root or break-glass account?
- Use the account for routine administration.
2. Share the credentials among the operations team.
3. Disable logging for emergency access.
4. Strongly protect the account, restrict its use, require phishing-resistant MFA where supported, and monitor every use.
Correct Answer: 4
Explanation:
Root and emergency accounts should be treated as exceptional high-value identities. They should not be used for daily administration and should have strong authentication, restricted access, protected credentials, and immediate monitoring whenever used. Shared routine usage reduces accountability and increases exposure. Organizations should also define documented emergency procedures, verify account availability periodically, and investigate every unexpected use because such accounts often bypass normal privilege boundaries.
Question 111.
Which security technique most directly limits the impact of a vulnerable web application being exploited to access internal services?
- Increase password length only.
2. Disable application logs.
3. Place the application in a restricted segment with tightly controlled east-west and outbound access.
4. Give the application server domain administrator rights.
Correct Answer: 3
Explanation:
Segmentation and restricted outbound access reduce what a compromised application can reach after exploitation. Even if the application is breached, explicit network policies can prevent unnecessary access to internal databases, identity systems, management networks, and internet destinations. Password length alone does not constrain post-exploitation movement, while excessive privileges increase risk. Effective architecture assumes individual components may fail and limits the resulting blast radius.
Question 112.
Which statement best describes the security purpose of a privacy impact assessment?
- It replaces all technical security testing.
2. It evaluates how a system collects, uses, stores, shares, and protects personal information and identifies privacy risks.
3. It guarantees legal compliance automatically.
4. It is used only to measure network latency.
Correct Answer: 2
Explanation:
A privacy impact assessment examines how personal information is handled throughout a system or process and identifies privacy risks before or during implementation. It can address collection, purpose, retention, sharing, access, minimization, and protection. It does not replace penetration testing or guarantee compliance by itself. Privacy assessments support informed design decisions and help organizations identify where technical, contractual, or procedural safeguards are needed.
Question 113.
A security engineer finds that a production service account has not been used for six months but still has administrative permissions. Which action best follows least-privilege principles?
- Disable or remove the unused account after validating that it is no longer required.
2. Increase its permissions in case it is needed later.
3. Share the credentials with additional teams.
4. Exempt the account from future access reviews.
Correct Answer: 1
Explanation:
Unused privileged identities increase attack surface because they may remain exploitable even though they no longer provide business value. After confirming the account is not required, administrators should disable or remove it and document the change. Access reviews should include machine and service identities as well as human accounts. Increasing permissions or exempting dormant accounts from review creates unnecessary risk and conflicts with least privilege.
Question 114.
Which architecture best supports secure processing of payment data while minimizing the number of systems subject to payment-data security requirements?
- Copy card data into every application database.
2. Allow unrestricted access to payment data internally.
3. Disable segmentation around payment systems.
4. Isolate the payment environment and use tokenization to keep card data out of unnecessary systems.
Correct Answer: 4
Explanation:
Segmentation and tokenization reduce the number of systems that directly store, process, or transmit sensitive payment data. Applications that do not require the original account number can operate on tokens instead. This decreases exposure and can simplify the scope of security controls. Broad duplication of payment data expands risk. The isolated payment environment should still use strong authentication, monitoring, encryption, vulnerability management, and restricted administrative access.
Question 115.
Which control best reduces the risk that a malicious dependency enters an application through package-name confusion or dependency confusion?
- Allow unrestricted package retrieval from public repositories.
2. Remove dependency version tracking.
3. Use trusted internal repositories, namespace controls, integrity verification, and dependency allowlists.
4. Disable software composition analysis.
Correct Answer: 3
Explanation:
Dependency-confusion attacks exploit package resolution behavior to introduce malicious packages with names or versions that appear preferable to legitimate internal dependencies. Trusted repositories, controlled namespaces, pinned versions, integrity verification, and allowlists reduce this risk. Software composition analysis provides additional visibility and should not be disabled. Organizations should also protect package-publishing permissions and monitor unexpected dependency changes in build pipelines.
Question 116.
Which statement best describes an effective approach to vulnerability prioritization?
- Remediate vulnerabilities only in numerical identifier order.
2. Consider exploitability, asset criticality, exposure, active exploitation, compensating controls, and business impact.
3. Patch only vulnerabilities with the longest descriptions.
4. Ignore vulnerabilities on externally accessible systems.
Correct Answer: 2
Explanation:
Vulnerability severity scores are useful but should not be the sole prioritization factor. An internet-facing vulnerability with active exploitation on a critical system may require faster action than a higher-scoring issue on an isolated test host. Risk-based prioritization considers technical severity together with exploitability, exposure, asset importance, threat intelligence, compensating controls, and business consequences. This helps security teams focus limited remediation resources where they reduce risk most effectively.
Question 117.
Which practice best preserves the forensic value of collected evidence during an investigation?
- Document collection, maintain chain of custody, and verify evidence integrity with cryptographic hashes.
2. Allow anyone on the team to modify the evidence freely.
3. Store the only copy on the suspected compromised system.
4. Delete collection timestamps.
Correct Answer: 1
Explanation:
Chain-of-custody documentation records who collected, transferred, accessed, and stored evidence. Cryptographic hashing helps demonstrate that evidence has not changed since collection. Evidence should be protected from unauthorized modification and stored in appropriately controlled locations. The exact procedures depend on organizational, legal, and regulatory requirements, but preserving integrity and documenting handling are fundamental to reliable forensic analysis.
Question 118.
Which activity is most suspicious in a cloud environment and should trigger immediate investigation?
- A scheduled backup completes normally.
2. A developer reads documentation.
3. An application performs its expected health check.
4. A newly assumed privileged role disables audit logging and creates additional access credentials.
Correct Answer: 4
Explanation:
Disabling audit logging and creating new credentials immediately after privilege elevation are common attacker objectives because they can reduce visibility and establish persistence. The security team should preserve available logs, revoke unauthorized sessions and credentials, determine how the role was assumed, and review subsequent changes. Routine backups and health checks are expected behavior. Administrative actions that simultaneously reduce monitoring and expand access deserve urgent attention.
Question 119.
Which approach best reduces risk from insecure default configurations in newly deployed cloud resources?
- Configure each resource manually with no standards.
2. Trust vendor defaults in every case.
3. Use hardened infrastructure templates, policy-as-code, and continuous configuration assessment.
4. Disable configuration monitoring after deployment.
Correct Answer: 3
Explanation:
Hardened templates establish secure baseline settings, while policy-as-code can prevent noncompliant infrastructure from being deployed. Continuous configuration monitoring identifies drift after deployment. Relying solely on vendor defaults or manual configuration can lead to inconsistent security settings. This approach also supports repeatability, auditability, and faster remediation across large cloud environments.
Question 120.
Which approach best supports enterprise resilience against destructive cyberattacks that affect production systems, identity services, and administrative tooling simultaneously?
- Depend on one online backup system.
2. Maintain isolated recovery capabilities, protected identities, immutable backups, documented procedures, and regularly exercised restoration plans.
3. Use the same credentials for production and recovery environments.
4. Avoid recovery testing because it may interrupt operations.
Correct Answer: 2
Explanation:
Sophisticated destructive attacks can target production workloads, identity systems, backups, and administrative tools at the same time. Resilience therefore requires independent recovery capabilities, separate privileged identities, immutable or offline backup copies, documented procedures, and regular exercises. Recovery environments should not depend entirely on the same credentials or infrastructure that an attacker may have compromised. Testing verifies that restoration procedures, dependencies, data, and personnel can meet business recovery objectives.