CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part12 Q221-240

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 221.

A security architect is designing administrative access to critical infrastructure. Which approach best reduces the risk of credential theft from everyday user activity?

  1. Use separate privileged identities on hardened administrative workstations
    2. Use the same account for email, web browsing, and administration
    3. Allow privileged access from unmanaged personal devices
    4. Share administrator credentials between operations teams

Correct Answer: 1

Explanation:

Separating privileged administration from ordinary user activity reduces exposure of high-value credentials to phishing, malicious websites, browser attacks, and endpoint compromise. Hardened administrative workstations can be restricted to management functions and protected with stronger security policies. Using the same identity for routine work and administration increases credential exposure, while shared accounts reduce accountability. Strong privileged-access architecture should also include phishing-resistant MFA, just-in-time elevation, session logging, and network restrictions around management interfaces.

Question 222.

An organization must ensure that security-sensitive software artifacts can be traced back to an approved build process. Which control best supports this requirement?

  1. Rename artifacts after compilation
    2. Store releases only on developer workstations
    3. Disable build logs after deployment
    4. Maintain signed provenance metadata for build artifacts

Correct Answer: 4

Explanation:

Signed provenance metadata provides verifiable information about how, where, and from what source an artifact was produced. This helps deployment systems and security teams distinguish authorized build outputs from artifacts produced through compromised or unapproved processes. File names alone provide no integrity assurance, and disabling logs reduces traceability. Strong software-supply-chain controls also include protected build systems, signed artifacts, trusted dependencies, restricted release permissions, and auditable CI/CD pipelines.

Question 223.

Which security capability is most appropriate for identifying unexpected privilege relationships across a large cloud environment?

  1. Disk encryption
    2. DNS filtering
    3. Identity entitlement analysis and permission graphing
    4. RAID monitoring

Correct Answer: 3

Explanation:

Identity entitlement analysis can reveal effective permissions, nested roles, inherited access, and indirect privilege paths that are difficult to understand through individual policy reviews. Permission graphing is especially useful in cloud environments where identities may gain privilege through combinations of roles, groups, trust relationships, and service accounts. Disk encryption, DNS filtering, and RAID address different security objectives. Reviewing effective access helps identify excessive privilege and unexpected paths to sensitive resources.

Question 224.

Which control best reduces the risk that a compromised web server can reach arbitrary internet destinations for command-and-control communication?

  1. Increase password complexity only
    2. Apply outbound allowlisting and egress filtering
    3. Disable server logging
    4. Trust all outbound traffic from production servers

Correct Answer: 2

Explanation:

Egress filtering limits outbound communication to approved destinations, ports, protocols, or services. A compromised server therefore has fewer opportunities to contact command-and-control infrastructure or exfiltrate data. Password complexity does not restrict post-compromise network behavior, and disabling logging removes useful evidence. Production systems should not automatically be trusted simply because they are internal. Strong egress controls are most effective when combined with monitoring, segmentation, and application-aware policies.

Question 225.

A company wants to detect when privileged users access sensitive systems outside their normal working patterns. Which control is best suited to this requirement?

  1. Behavioral analytics correlated with privileged-access telemetry
    2. Static NAT
    3. File compression
    4. RAID mirroring

Correct Answer: 1

Explanation:

Behavioral analytics can establish normal patterns for privileged users and detect anomalies such as unusual access times, new systems, atypical administrative actions, or abnormal data transfer. Correlating this with PAM, authentication, endpoint, and cloud telemetry provides stronger context. NAT, compression, and RAID do not detect identity misuse. Privileged accounts deserve heightened monitoring because an attacker using legitimate administrative credentials may otherwise appear authorized.

Question 226.

Which architecture best protects an organization’s secrets platform from a compromise of a single application?

  1. Give all applications vault-administrator permissions.
    2. Use one shared secret-access identity.
    3. Disable access auditing.
    4. Assign each workload a separate identity and narrowly scoped secret permissions.

Correct Answer: 4

Explanation:

Separate workload identities with narrowly scoped permissions limit each application to only the secrets required for its function. If one workload is compromised, the attacker should not automatically gain access to credentials belonging to unrelated systems. Shared vault identities and administrator-level permissions create excessive blast radius. Access auditing should remain enabled so abnormal secret retrieval can be detected. Dynamic or short-lived credentials provide additional protection where supported.

Question 227.

Which security technique is most effective for reducing the chance that malicious infrastructure-as-code reaches production?

  1. Allow developers to bypass repositories for urgent changes.
    2. Perform review only after deployment.
    3. Integrate policy-as-code and security testing into the deployment pipeline.
    4. Disable version control protections.

Correct Answer: 3

Explanation:

Policy-as-code and automated security tests allow organizations to detect insecure infrastructure configurations before deployment. Examples include public storage exposure, missing encryption, excessive IAM permissions, or overly permissive network rules. Version control, peer review, and protected branches strengthen the process further. Post-deployment review alone is reactive and allows insecure resources to exist in production before issues are found.

Question 228.

Which statement best describes the purpose of a recovery point objective?

  1. It defines the maximum acceptable duration of a service outage.
    2. It defines the maximum acceptable amount of data loss measured in time.
    3. It specifies the number of administrators required for recovery.
    4. It determines the encryption algorithm used for backups.

Correct Answer: 2

Explanation:

The recovery point objective defines how much data loss an organization can tolerate, usually expressed as a period of time. For example, an RPO of one hour means recovery should restore data to a point no more than one hour before the disruption. Recovery time objective instead focuses on how long the service may remain unavailable. Backup frequency, replication, and data-protection architecture should be designed to meet the required RPO.

Question 229.

A security team discovers that several internal APIs accept tokens issued for unrelated applications. Which design flaw should be corrected first?

  1. Inadequate token audience and scope validation
    2. Excessive disk encryption
    3. DNSSEC configuration
    4. Load-balancer persistence

Correct Answer: 1

Explanation:

APIs should validate that a token was issued for the intended audience and contains appropriate scopes or permissions. Accepting tokens created for unrelated applications can allow unintended access and weaken authorization boundaries. Token validation should also verify issuer, expiration, signature, and other required claims. Disk encryption, DNSSEC, and load-balancing behavior do not address this authorization defect.

Question 230.

Which control provides the strongest protection for a private key used to sign high-value financial transactions?

  1. Store it in a standard file server.
    2. Keep it in an administrator’s email archive.
    3. Embed it in the application executable.
    4. Use an HSM with controlled signing operations and separation of duties.

Correct Answer: 4

Explanation:

A hardware security module protects cryptographic key material from extraction and can enforce controlled signing operations. Separation of duties further reduces the chance that one administrator can misuse the signing capability without oversight. Ordinary file servers, email, and application binaries provide much weaker protection. High-value signing systems should also have strong auditing, key rotation, recovery procedures, and tightly restricted administrative access.

Question 231.

Which capability is most useful for identifying whether a cloud identity has accumulated excessive permissions over time?

  1. RAID monitoring
    2. Network address translation
    3. Cloud infrastructure entitlement management
    4. File deduplication

Correct Answer: 3

Explanation:

Cloud infrastructure entitlement management helps identify excessive, unused, inherited, or risky permissions across cloud identities and resources. It can compare granted privileges with actual usage and support least-privilege remediation. Over time, users and service accounts often accumulate permissions through role changes or temporary access that was never removed. RAID, NAT, and file deduplication do not address authorization governance.

Question 232.

Which statement best describes the security value of immutable logs?

  1. They allow administrators to edit historical records freely.
    2. They make unauthorized modification or deletion of audit records significantly more difficult.
    3. They eliminate the need for monitoring.
    4. They prevent all security incidents.

Correct Answer: 2

Explanation:

Immutable logs are protected against alteration or deletion after they are written, improving integrity and forensic reliability. This is especially important for privileged administrative events, security alerts, and compliance records. Immutability does not remove the need for alerting, investigation, retention management, or secure access. A separate logging security boundary further reduces the chance that attackers can erase evidence after compromising production systems.

Question 233.

An organization discovers an internet-facing system that is not present in its asset inventory. What should the security team do first?

  1. Identify ownership, validate business purpose, assess exposure, and bring the asset under management.
    2. Ignore the system because it is probably temporary.
    3. Disable all enterprise asset discovery.
    4. Add administrator credentials without investigation.

Correct Answer: 1

Explanation:

Unknown internet-facing assets can represent shadow IT, abandoned infrastructure, or unmanaged attack surface. The organization should determine ownership, business purpose, configuration, vulnerabilities, and whether the exposure is intentional. If the asset is legitimate, it should be incorporated into inventory, monitoring, patching, and governance processes. If it is unauthorized, containment or removal may be appropriate. Ignoring unknown assets allows unmanaged risk to persist.

Question 234.

Which architecture best limits the impact of a compromise in one Kubernetes namespace?

  1. Use a single unrestricted service account for the entire cluster.
    2. Allow unrestricted pod-to-pod traffic.
    3. Give all workloads cluster-administrator privileges.
    4. Use namespace isolation, network policies, and least-privilege service accounts.

Correct Answer: 4

Explanation:

Namespace isolation, network policies, and separate service identities reduce the ability of an attacker to move laterally after compromising one workload. Cluster-wide administrator permissions or shared service accounts create excessive privilege and weaken isolation. Kubernetes security should also include admission controls, image verification, secret management, runtime monitoring, and restricted container capabilities. The objective is to contain compromise rather than assuming every workload remains trustworthy.

Question 235.

Which control best detects unauthorized modification of system binaries on critical servers?

  1. DNS filtering
    2. Data masking
    3. File integrity monitoring
    4. Network load balancing

Correct Answer: 3

Explanation:

File integrity monitoring compares critical files against expected states or cryptographic hashes and alerts when unexpected changes occur. This can reveal malware replacement, unauthorized configuration changes, or tampering with system binaries. DNS filtering, data masking, and load balancing address different security goals. FIM should be integrated with change management so approved patches or updates can be distinguished from suspicious modifications.

Question 236.

Which statement best describes a secure decommissioning process for a cloud workload?

  1. Stop the virtual machine and leave all credentials active indefinitely.
    2. Remove credentials, integrations, data, DNS records, permissions, and residual resources according to policy.
    3. Leave public storage resources in place for convenience.
    4. Ignore backup and retention requirements.

Correct Answer: 2

Explanation:

Secure decommissioning must address more than the primary compute resource. Service accounts, secrets, API keys, storage, DNS, network rules, integrations, logs, and backups should all be reviewed. Data must be deleted or retained according to legal and business requirements. Abandoned cloud resources can become forgotten attack paths, so decommissioning should be documented and verified rather than treated as a simple shutdown operation.

Question 237.

Which security practice most directly reduces the risk of developers unintentionally exposing credentials in source repositories?

  1. Secret scanning combined with pre-commit controls and centralized secret management
    2. Store credentials in source-code comments
    3. Disable repository audit logging
    4. Reuse the same credential across all environments

Correct Answer: 1

Explanation:

Secret scanning can detect passwords, API keys, tokens, and certificates before or shortly after they enter a repository. Pre-commit controls can block unsafe changes, while centralized secret management removes the need to place credentials directly in source code. Reused credentials increase the impact of exposure. Any secret committed to a repository should generally be treated as compromised and rotated.

Question 238.

Which behavior most strongly indicates a possible attempt to disable security visibility before further malicious activity?

  1. A scheduled backup completes normally.
    2. A user reads a standard report.
    3. A service performs its usual health check.
    4. A privileged account disables audit logging and changes retention immediately after an unusual login.

Correct Answer: 4

Explanation:

Attackers often attempt to reduce visibility after obtaining privilege. Disabling audit logging and weakening retention soon after suspicious authentication are high-risk actions because they may be intended to conceal subsequent activity. Responders should validate the identity, preserve existing logs, revoke suspicious sessions, restore monitoring, and examine related changes. Routine backups and health checks do not present the same level of concern.

Question 239.

Which security approach best protects sensitive data used by generative AI applications?

  1. Permit unrestricted submission of regulated data to any model.
    2. Disable AI activity logging.
    3. Use approved models, data classification, DLP, access controls, and restrictions on sensitive prompts.
    4. Give models unrestricted access to enterprise repositories.

Correct Answer: 3

Explanation:

Generative AI applications should follow the same data-governance principles as other enterprise systems. Sensitive information should be classified, access restricted, and use limited to approved services with appropriate contractual and technical controls. DLP can help prevent unauthorized submission of regulated or proprietary data. Organizations should also assess prompt injection, model output leakage, retention practices, third-party handling, and tool-access permissions.

Question 240.

Which approach best supports long-term effectiveness of advanced enterprise security architecture?

  1. Treat the original design as permanently valid.
    2. Continuously reassess threats, validate controls, review access, test recovery, and update architecture as conditions change.
    3. Perform architecture reviews only after a successful attack.
    4. Disable telemetry to simplify operations.

Correct Answer: 2

Explanation:

Security architecture must evolve as threats, technologies, identities, business processes, and dependencies change. Regular threat modeling, control validation, access reviews, resilience exercises, telemetry analysis, and architecture assessments help reveal weaknesses before they become major incidents. Continuous improvement turns security architecture into an active risk-management discipline rather than a one-time design exercise.