CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part18 Q341-360

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 341.

A security architect wants to prevent developers from granting excessive permissions to new cloud workloads. Which control is most effective?

  1. Enforce least-privilege role templates and policy-as-code checks during deployment
    2. Give every workload administrator privileges initially
    3. Allow teams to create unrestricted roles manually
    4. Disable permission reviews after deployment

Correct Answer: 1

Explanation:

Least-privilege role templates establish secure defaults, while policy-as-code can automatically detect overly broad permissions before infrastructure is deployed. This reduces inconsistency and prevents excessive privilege from becoming embedded in production. Broad administrator roles increase blast radius and often remain in place longer than intended. Organizations should also review actual permission usage over time and remove privileges that are no longer required.

Question 342.

Which control best protects an enterprise from unauthorized changes to security monitoring rules?

  1. Allow all analysts to modify production detections directly.
    2. Disable change logging.
    3. Use shared administrator credentials for the SIEM.
    4. Manage detection logic through version control, peer review, and controlled deployment.

Correct Answer: 4

Explanation:

Detection rules are part of the security control plane and should be protected like production code. Version control provides traceability and rollback, peer review reduces unauthorized or accidental changes, and controlled deployment creates separation between development and production. Shared credentials and unlogged changes weaken accountability. High-impact rule changes should also be monitored because attackers may try to disable or weaken detections after gaining privileged access.

Question 343.

Which security capability is most appropriate for finding cloud resources that are publicly exposed due to configuration errors?

  1. RAID monitoring
    2. File compression
    3. Cloud security posture management
    4. Local printer auditing

Correct Answer: 3

Explanation:

Cloud security posture management continuously evaluates cloud configurations for risky settings such as public storage, overly permissive network rules, missing encryption, and compliance drift. It can help detect misconfigurations that traditional endpoint tools may not see. RAID, compression, and printer auditing do not provide cloud configuration visibility. CSPM findings should be prioritized based on asset sensitivity, exposure, and exploitability.

Question 344.

Which approach best protects an internal API from misuse by a compromised service account?

  1. Trust the service account completely after authentication.
    2. Enforce fine-grained authorization, scoped tokens, and behavioral monitoring.
    3. Disable API logging.
    4. Give the service account permanent administrator access.

Correct Answer: 2

Explanation:

Authentication proves the identity presented by the caller, but a compromised service account may still behave maliciously. Fine-grained authorization limits what the identity can do, while scoped tokens reduce the accessible resources and behavioral monitoring can detect unusual patterns. Permanent administrator access creates excessive risk. Internal APIs should be protected with the same least-privilege principles as internet-facing services.

Question 345.

A security team wants to reduce the risk of privileged credential theft through phishing. Which solution provides the strongest protection?

  1. Hardware-backed phishing-resistant authentication for privileged users
    2. Security questions
    3. Password reuse across administrative systems
    4. SMS-only authentication

Correct Answer: 1

Explanation:

Hardware-backed phishing-resistant authentication, such as FIDO2-based authenticators, uses public-key cryptography and origin binding to make credential phishing substantially harder. Security questions and SMS codes are more susceptible to social engineering or interception. Privileged identities should also use separate accounts, hardened administrative endpoints, just-in-time access, and strong monitoring to reduce the impact of compromise.

Question 346.

Which architecture best protects signing keys used by an automated release pipeline?

  1. Store keys in the pipeline’s local filesystem.
    2. Commit keys to the private source repository.
    3. Share the key with release engineers.
    4. Use an HSM or protected signing service that performs signing without exposing the private key.

Correct Answer: 4

Explanation:

A protected signing service or HSM keeps the private key isolated from the build environment and can enforce tightly controlled signing requests. This reduces the chance that compromise of a runner or developer account results in key theft. Storing the private key in source control or on build systems creates major software-supply-chain risk. Signing operations should also be logged and tied to verified build provenance.

Question 347.

Which security practice best detects privilege creep among employees who change roles over time?

  1. Disable periodic access reviews.
    2. Allow all historic permissions to remain permanently.
    3. Perform regular entitlement reviews and remove access no longer required.
    4. Share privileged roles across departments.

Correct Answer: 3

Explanation:

Privilege creep occurs when users accumulate access as they change roles without losing permissions from previous responsibilities. Regular entitlement reviews compare current access with business need and help remove unnecessary privileges. Strong identity governance should include joiner, mover, and leaver processes so access changes follow the user’s lifecycle. Permanent accumulation of permissions increases the impact of account compromise.

Question 348.

Which statement best describes the security purpose of certificate revocation checking?

  1. It verifies that every certificate uses the same encryption algorithm.
    2. It determines whether a previously issued certificate should no longer be trusted.
    3. It replaces certificate expiration.
    4. It encrypts private keys.

Correct Answer: 2

Explanation:

Certificate revocation checking determines whether a certificate that has not yet expired has been invalidated because of key compromise, incorrect issuance, or another security event. Mechanisms such as CRLs and OCSP can communicate revocation status. Expiration alone may leave a compromised certificate trusted for too long. Reliable PKI architecture therefore includes issuance, renewal, revocation, monitoring, and key-protection processes.

Question 349.

A security analyst identifies a server making outbound connections to a rare domain shortly after a new administrative login. What should be investigated first?

  1. The process initiating the connection, user context, domain reputation, and related activity
    2. Printer toner levels
    3. Local screen brightness
    4. Office network cabling

Correct Answer: 1

Explanation:

The timing between unusual administrative access and outbound communication may indicate post-compromise command-and-control activity. Analysts should identify which process initiated the connection, what account launched it, the domain’s reputation and age, and whether related files or commands were executed. Correlating endpoint, DNS, firewall, and identity telemetry provides stronger evidence than evaluating the network destination alone.

Question 350.

Which control best protects critical cloud logs from deletion by a compromised tenant administrator?

  1. Store logs only inside the tenant being monitored.
    2. Allow privileged administrators to disable log collection without alerting.
    3. Keep only short-lived local copies.
    4. Export logs to a separate protected account or immutable logging platform.

Correct Answer: 4

Explanation:

Exporting logs to a separate security boundary reduces the chance that a compromised tenant administrator can erase evidence. Immutability or write-protection provides additional safeguards against tampering. Local-only logs remain exposed to the same credentials and administrative plane as the monitored systems. Logging gaps and collection changes should generate alerts because attackers often target telemetry early in an intrusion.

Question 351.

Which security design best limits the consequences of compromise in one application tier?

  1. Put all tiers on one unrestricted network.
    2. Use shared administrator credentials between tiers.
    3. Segment tiers and permit only required application flows between them.
    4. Disable east-west monitoring.

Correct Answer: 3

Explanation:

Tier-based segmentation limits communication between web, application, database, and management systems to required flows. If one tier is compromised, the attacker has fewer opportunities to move laterally. Shared credentials and unrestricted networking increase blast radius. Segmentation should be supported by service identity, least-privilege database access, and monitoring of unexpected internal connections.

Question 352.

Which statement best describes the purpose of risk acceptance?

  1. It means the risk no longer exists.
    2. It is a documented decision by an authorized risk owner to tolerate residual risk.
    3. It automatically eliminates the need for monitoring.
    4. It can be performed informally by any employee.

Correct Answer: 2

Explanation:

Risk acceptance is a deliberate governance decision to tolerate residual risk when further mitigation is not justified or feasible. It should be documented, approved by the appropriate risk owner, and reviewed periodically because business conditions and threat levels may change. Acceptance does not eliminate the risk itself or remove the need for monitoring. Significant accepted risks should have clear ownership and rationale.

Question 353.

Which action is most appropriate when a security team discovers a long-lived cloud access key belonging to an account that no longer exists?

  1. Revoke the key and investigate whether it was used after the account should have been decommissioned.
    2. Leave it active for compatibility.
    3. Increase its permissions.
    4. Exempt the key from logging.

Correct Answer: 1

Explanation:

Credentials associated with decommissioned identities should not remain active. The key should be revoked promptly, and audit logs should be reviewed to determine whether it was used unexpectedly. This scenario indicates a lifecycle management gap because identity removal should include associated keys, tokens, certificates, and sessions. Automated deprovisioning can reduce the likelihood of orphaned credentials.

Question 354.

Which architecture best supports recovery when both production systems and primary identity infrastructure are unavailable?

  1. Require normal production SSO for every recovery operation.
    2. Reuse production administrator accounts for all recovery systems.
    3. Keep recovery infrastructure dependent on the same production network.
    4. Maintain independent recovery authentication, protected backups, and isolated recovery procedures.

Correct Answer: 4

Explanation:

Recovery architecture should avoid relying entirely on the same systems that may be compromised or unavailable during a major incident. Independent authentication, protected backups, and isolated procedures create an alternate path to restoration. Recovery access must still be secured and audited, but it should not depend on failed production identity services. Regular exercises are necessary to validate the independence of these recovery mechanisms.

Question 355.

Which control most directly reduces the risk that confidential information is unintentionally shared through collaboration platforms?

  1. Disable all collaboration logging.
    2. Make every document publicly shareable.
    3. Apply DLP, sharing restrictions, classification labels, and access governance.
    4. Trust users to manually identify every sensitive document.

Correct Answer: 3

Explanation:

DLP and classification labels can identify sensitive content and apply restrictions based on organizational policy. Sharing controls can prevent public or external access, while access governance helps ensure permissions remain appropriate over time. Manual judgment alone is inconsistent and does not scale. Collaboration platforms should also provide audit logs so unusual sharing activity can be investigated.

Question 356.

Which statement best describes the purpose of control validation through attack simulation?

  1. It proves that security products can never fail.
    2. It tests whether preventive and detective controls respond as expected to realistic adversary techniques.
    3. It eliminates the need for incident response.
    4. It should only occur after a breach.

Correct Answer: 2

Explanation:

Attack simulation exercises security controls against realistic techniques to determine whether expected prevention, detection, and response outcomes actually occur. This can reveal telemetry gaps, weak rules, misconfigurations, or failed assumptions. Simulation does not guarantee perfect security, but it provides measurable evidence about control effectiveness. Results should feed detection engineering, architecture improvements, and response procedures.

Question 357.

Which practice best reduces the risk that forgotten third-party integrations retain access after a business relationship ends?

  1. Include application credentials, OAuth grants, API keys, and service accounts in offboarding procedures.
    2. Leave all integration credentials active indefinitely.
    3. Exempt third-party applications from access reviews.
    4. Increase their permissions before contract termination.

Correct Answer: 1

Explanation:

Third-party offboarding should revoke every access mechanism associated with the relationship, including OAuth grants, service accounts, API keys, certificates, and network trust. Forgotten integrations can become long-lived unauthorized access paths. Periodic reviews help identify abandoned applications even before formal contract termination. Access lifecycle governance should cover external identities as well as employees.

Question 358.

Which activity most strongly indicates possible persistence following compromise of an identity administrator?

  1. A user opens a standard application.
    2. A scheduled report is generated.
    3. A routine directory synchronization completes.
    4. A suspicious session registers a new authentication method and creates a privileged application identity.

Correct Answer: 4

Explanation:

Creating alternate authentication methods and privileged application identities can give an attacker durable access even after the original password is changed. These actions are particularly suspicious when they follow abnormal identity-administrator activity. Responders should remove unauthorized methods, revoke sessions, review role assignments, preserve logs, and investigate whether other persistence mechanisms were established.

Question 359.

Which security design best limits misuse of internal APIs by automated workloads?

  1. Use one permanent administrator token for all workloads.
    2. Trust any traffic originating from the internal network.
    3. Use distinct workload identities, scoped authorization, short-lived credentials, and request monitoring.
    4. Disable API audit logs.

Correct Answer: 3

Explanation:

Distinct workload identities provide accountability, while scoped authorization and short-lived credentials limit the effect of credential compromise. Request monitoring can identify unusual behavior such as new endpoints, excessive volume, or atypical operations. Internal location alone should not be treated as sufficient trust. Workload-to-workload APIs should follow the same zero-trust principles as user-facing applications.

Question 360.

Which approach best supports a mature enterprise security program over time?

  1. Treat compliance completion as the end of security work.
    2. Continuously reassess risk, validate controls, measure detection and recovery, and improve architecture based on evidence.
    3. Review security only when regulations change.
    4. Avoid testing systems that are currently operating normally.

Correct Answer: 2

Explanation:

A mature security program continuously measures whether controls reduce real risk rather than relying solely on compliance status. Threats, systems, identities, dependencies, and business requirements change over time, so architecture and operations must evolve as well. Control testing, recovery exercises, detection metrics, threat modeling, and incident lessons provide evidence that can guide ongoing improvement.