View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 141.
A security architect wants to ensure that only healthy, company-managed devices can access a highly sensitive internal application. Which control is most appropriate?
- Conditional access that evaluates device compliance, identity, MFA strength, and session risk
2. Static password authentication only
3. Unrestricted access from any device on the internet
4. Trust based only on source IP address
Correct Answer: 1
Explanation:
Conditional access can evaluate identity, authentication strength, device compliance, location, risk signals, and application sensitivity before granting access. This is stronger than relying on passwords or source IP addresses alone because compromised credentials may be used from unmanaged or infected systems. Sensitive applications can also require step-up authentication or restricted sessions. A zero-trust approach treats device posture as one of several important signals rather than assuming that successful authentication automatically means the device is safe.
Question 142.
Which architecture best protects secrets used by containerized workloads from exposure in source code or deployment manifests?
- Store credentials in container images.
2. Put passwords in plaintext YAML files.
3. Share one secret across all namespaces.
4. Use a secrets-management platform with workload identity and dynamic retrieval.
Correct Answer: 4
Explanation:
A secrets-management platform allows workloads to retrieve only the credentials they need at runtime, avoiding hard-coded secrets in source code, images, and manifests. Workload identity further reduces dependence on long-lived static credentials. Shared or embedded secrets increase blast radius and may persist in repositories or build artifacts even after deletion. Centralized secret management also supports access control, rotation, auditing, expiration, and automated credential issuance.
Question 143.
Which security capability is most useful for identifying abnormal behavior by service accounts that normally run predictable automated tasks?
- RAID monitoring
2. DNS caching
3. User and entity behavior analytics
4. Disk compression
Correct Answer: 3
Explanation:
User and entity behavior analytics can establish a baseline for service-account behavior and identify deviations such as unusual login locations, unexpected resource access, abnormal API use, or new execution patterns. Service accounts often behave predictably, making anomalies particularly useful for detection. RAID, DNS caching, and compression do not provide behavioral security analysis. UEBA works best when correlated with identity logs, cloud audit events, endpoint telemetry, and application activity.
Question 144.
Which statement best describes the purpose of network egress filtering?
- It controls only inbound internet traffic.
2. It restricts outbound communication to approved destinations and services.
3. It replaces endpoint protection.
4. It disables routing between all internal systems.
Correct Answer: 2
Explanation:
Egress filtering controls outbound network communication and can prevent compromised systems from reaching command-and-control servers, unauthorized cloud services, or other prohibited destinations. It can also reduce data exfiltration risk. Egress controls do not replace endpoint protection or segmentation; they complement those safeguards. Policies should be based on legitimate business requirements and monitored so unexpected outbound connections can be investigated.
Question 145.
A security team wants to reduce the chance that a compromised CI/CD runner can alter production infrastructure. Which control is strongest?
- Use isolated runners with short-lived credentials, least privilege, and approval gates for production changes.
2. Give every runner permanent administrator access.
3. Disable pipeline audit logging.
4. Allow direct production changes from developer laptops.
Correct Answer: 1
Explanation:
Isolated build runners reduce cross-job contamination, while short-lived credentials limit the period during which stolen access can be abused. Least-privilege deployment roles and approval gates further restrict what the pipeline can change. Permanent administrator credentials create a large blast radius, and direct production access bypasses important review controls. Strong CI/CD security also includes protected repositories, provenance verification, signed artifacts, dependency scanning, and tamper-resistant logging.
Question 146.
Which security technology is most appropriate when an organization wants to protect data during processing from a potentially compromised hypervisor?
- File compression
2. Network address translation
3. DNSSEC
4. Confidential computing with a trusted execution environment
Correct Answer: 4
Explanation:
Confidential computing uses hardware-backed trusted execution environments to isolate sensitive workloads and data from the surrounding host infrastructure, including potentially compromised hypervisors or privileged software. Encryption at rest and in transit does not fully protect data while it is actively being processed. NAT and DNSSEC address unrelated network concerns. Confidential computing can be useful for high-value workloads in shared or third-party cloud environments.
Question 147.
Which control most directly reduces the risk of a compromised privileged account being used indefinitely?
- Permanent administrator membership
2. Shared privileged passwords
3. Just-in-time privilege elevation with automatic expiration
4. Disabling privileged session logging
Correct Answer: 3
Explanation:
Just-in-time elevation minimizes standing privilege by granting powerful permissions only when needed and removing them automatically afterward. This reduces the time window in which a compromised account can be abused. Permanent administrator membership and shared passwords increase risk and weaken accountability. JIT access is strongest when combined with phishing-resistant MFA, approval workflows, session monitoring, and regular review of privileged roles.
Question 148.
Which control best protects a web application from injection attacks caused by malicious input?
- Trust all input from authenticated users.
2. Use parameterized queries, input validation, and contextual output handling.
3. Disable application logging.
4. Increase DNS cache lifetime.
Correct Answer: 2
Explanation:
Parameterized queries separate data from executable query structure, making many injection attacks significantly harder. Input validation ensures that submitted data matches expected formats, while contextual output handling helps reduce related issues such as script injection. Authentication alone does not make user input safe. Secure coding should also include least-privilege database permissions, dependency management, testing, and application-layer monitoring.
Question 149.
A company discovers that a cloud administrator account was used to create a new privileged identity shortly after an unusual login. What is the most appropriate response?
- Revoke suspicious sessions, disable unauthorized identities, preserve logs, and investigate related activity.
2. Ignore the activity because a privileged account performed it.
3. Delete audit logs to protect privacy.
4. Increase the new identity’s permissions.
Correct Answer: 1
Explanation:
Creation of new privileged identities after suspicious authentication may indicate persistence following account compromise. The organization should contain the incident by revoking suspicious sessions and disabling unauthorized credentials while preserving evidence for investigation. Audit logs are essential for determining what changes were made and whether additional accounts or resources were affected. Increasing privileges or ignoring the activity would expand risk.
Question 150.
Which control provides the strongest protection for private keys used to sign firmware updates?
- Store the keys in a shared developer folder.
2. Embed them in the build script.
3. Keep them in source control.
4. Use an HSM with tightly controlled signing operations.
Correct Answer: 4
Explanation:
Firmware-signing keys are high-value assets because compromise could allow attackers to produce malicious updates that appear authentic. An HSM can protect private key material from extraction and perform signing operations under tightly controlled access policies. Keys stored in scripts, repositories, or shared folders are much more exposed. Strong signing processes also use approval workflows, separation of duties, audit logs, and secure artifact verification.
Question 151.
Which security strategy best limits lateral movement inside a cloud environment?
- Put every workload on one flat network.
2. Share administrative credentials across services.
3. Use microsegmentation with explicit workload-to-workload access policies.
4. Disable east-west traffic monitoring.
Correct Answer: 3
Explanation:
Microsegmentation limits communication between workloads to explicitly approved paths. This reduces the attacker’s ability to move laterally after compromising one service or virtual machine. Flat networks and shared credentials increase the number of reachable systems and make compromise more damaging. East-west visibility should be maintained so abnormal internal communication can be detected. Identity-aware segmentation can provide even stronger control than IP-based filtering alone.
Question 152.
Which statement best describes the purpose of data minimization?
- Collect as much information as possible for future use.
2. Collect, process, and retain only the data necessary for the intended purpose.
3. Disable encryption to simplify access.
4. Store all data permanently.
Correct Answer: 2
Explanation:
Data minimization reduces privacy and security risk by limiting collection, processing, and retention to information that is genuinely required. If unnecessary data is never collected or retained, it cannot be exposed in a future breach. This principle is especially important for personal, regulated, and sensitive information. Organizations should regularly review whether data sets, fields, and retention periods remain justified by legitimate business requirements.
Question 153.
Which security practice best supports reliable investigation of administrator activity across multiple cloud platforms?
- Centralize audit logs in a protected logging platform and normalize identity context.
2. Keep logs only on each local system.
3. Disable audit trails for privileged users.
4. Use shared administrator accounts.
Correct Answer: 1
Explanation:
Centralized logging allows security teams to investigate administrator activity across multiple platforms using a common timeline and identity context. Logs should be stored in a protected location that administrators cannot easily alter. Shared accounts weaken attribution, while disabled or local-only logging makes investigation more difficult. Normalizing identities across platforms can help analysts determine when the same user performs related actions in different environments.
Question 154.
Which architecture best protects recovery systems from compromise when production administrator credentials are stolen?
- Use identical credentials in production and recovery environments.
2. Permanently connect recovery infrastructure to production networks.
3. Allow production administrators unrestricted backup deletion rights.
4. Maintain isolated recovery infrastructure with separate identities and immutable backups.
Correct Answer: 4
Explanation:
Separate identities and isolated recovery infrastructure reduce the chance that credentials stolen from production can also compromise backups and recovery systems. Immutable backups further prevent attackers from deleting or modifying protected recovery copies. Using the same credentials and network paths across production and recovery creates common failure modes. Recovery procedures should also be tested regularly so isolation does not prevent timely restoration when needed.
Question 155.
Which control is most effective for reducing risk from malicious container images obtained from public registries?
- Allow any image to run if its name looks legitimate.
2. Disable image scanning.
3. Use trusted registries, vulnerability scanning, signature verification, and admission controls.
4. Give containers privileged host access by default.
Correct Answer: 3
Explanation:
Trusted registries and image scanning reduce the risk of vulnerable or malicious containers, while signature verification helps confirm artifact integrity and provenance. Admission controls can enforce these requirements before workloads are allowed to run. Image names alone provide no security assurance, and privileged containers substantially increase host risk. Organizations should also maintain minimal images, patch dependencies, and monitor runtime behavior.
Question 156.
Which statement best describes the purpose of red teaming?
- It only verifies whether backups exist.
2. It simulates realistic adversary behavior to evaluate detection, prevention, and response capabilities.
3. It replaces all vulnerability scanning.
4. It guarantees that the organization cannot be breached.
Correct Answer: 2
Explanation:
Red teaming emulates realistic adversary objectives and techniques to test how effectively an organization prevents, detects, and responds to attack activity. The exercise can reveal weaknesses across technology, processes, and people. Red teaming complements rather than replaces vulnerability assessment, penetration testing, and other security validation methods. Results should be used to improve detections, architecture, incident response, and defensive controls.
Question 157.
Which practice best reduces the risk of API keys being accidentally exposed in source repositories?
- Use secret scanning, pre-commit controls, and runtime secret retrieval from a managed vault.
2. Put API keys directly into code comments.
3. Use the same key for every environment.
4. Disable repository auditing.
Correct Answer: 1
Explanation:
Secret scanning can identify credentials before or shortly after they enter a repository, while pre-commit controls can block unsafe changes. Runtime retrieval from a secrets manager avoids embedding long-lived credentials in source code. Using one key across environments increases the impact of exposure. If a secret is committed, it should generally be rotated because removing the visible file does not eliminate copies from history or downstream clones.
Question 158.
Which event should be considered the strongest indicator of potential identity compromise?
- A user opens a normal application at the usual time.
2. A scheduled password rotation completes.
3. An approved system runs a backup.
4. A dormant account authenticates from an unusual location and immediately requests privileged access.
Correct Answer: 4
Explanation:
A dormant identity suddenly authenticating from an unusual location and requesting privilege represents a strong anomaly. Attackers often target forgotten or lightly monitored accounts because their activity may attract less attention. Analysts should verify the authentication method, device, location, requested privileges, and subsequent resource access. The account may need to be disabled or its sessions revoked while the activity is investigated.
Question 159.
Which security design best protects sensitive application data when multiple teams need access for different purposes?
- Give every team full database administrator rights.
2. Use one shared account for all teams.
3. Apply role-based or attribute-based access controls with least-privilege permissions.
4. Disable auditing to improve performance.
Correct Answer: 3
Explanation:
Role-based and attribute-based access controls allow permissions to be aligned with job function, resource sensitivity, context, and business purpose. This enables teams to access only the data and operations required for their responsibilities. Shared administrator accounts create excessive privilege and weak accountability. Auditing should remain enabled so access to sensitive information can be reviewed and investigated.
Question 160.
Which approach best supports continuous security validation in a complex enterprise environment?
- Assume deployed controls continue to work indefinitely.
2. Regularly test controls using automated validation, purple-team exercises, attack simulations, and measurable detection outcomes.
3. Avoid testing production defenses.
4. Evaluate controls only after a major breach.
Correct Answer: 2
Explanation:
Continuous validation helps determine whether security controls work against realistic attack techniques as infrastructure and configurations change. Automated control testing, purple-team exercises, breach-and-attack simulations, and detection metrics can reveal gaps before real attackers exploit them. Security effectiveness should be measured through outcomes rather than assumed from product deployment alone. Findings should feed back into architecture, detection engineering, response procedures, and remediation planning.