CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part1 Q1-20

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 1.

An enterprise is implementing zero trust across several cloud environments and on-premises networks. Which design principle should receive the highest priority?

  1. Continuously evaluate identity, device posture, context, and authorization before granting access
    2. Trust all traffic originating from internal network segments
    3. Allow persistent administrative sessions after the first successful authentication
    4. Base authorization exclusively on source IP addresses

Correct Answer: 1

Explanation:

Zero trust assumes that neither internal nor external requests should be trusted automatically. Access decisions should continuously consider identity, device posture, workload context, authentication strength, requested resource, and applicable policy. Traditional network location alone is insufficient because compromised internal systems can be used for lateral movement. Persistent administrative sessions also increase risk when contextual conditions change. A mature zero-trust implementation combines strong identity, least privilege, segmentation, continuous verification, telemetry, and policy enforcement to reduce implicit trust throughout hybrid and multicloud environments.

Question 2.

A security architect needs to protect a highly sensitive application while allowing administrators to perform privileged tasks without exposing reusable administrator credentials. Which solution best meets the requirement?

  1. Shared local administrator passwords
    2. Permanent domain administrator membership
    3. Passwords stored in an encrypted spreadsheet
    4. Privileged access management with just-in-time credential issuance

Correct Answer: 4

Explanation:

Privileged access management with just-in-time access reduces the amount of time powerful credentials or permissions remain available. Access can be approved for a specific task, monitored, and automatically revoked when the authorized period ends. Shared passwords weaken accountability, while permanent administrator membership creates unnecessary standing privilege. An encrypted spreadsheet protects credentials at rest but does not provide session control, approval workflows, rotation, or temporary elevation. PAM combined with MFA and session auditing provides stronger governance over privileged operations.

Question 3.

An organization wants to reduce the risk that a compromised workload in one Kubernetes namespace can communicate freely with workloads in other namespaces. Which control is most appropriate?

  1. Increase container image retention
    2. Disable centralized logging
    3. Implement Kubernetes network policies and workload segmentation
    4. Place every pod in the same service account

Correct Answer: 3

Explanation:

Kubernetes network policies can restrict pod-to-pod and namespace-to-namespace communication based on defined rules. This limits lateral movement if a workload becomes compromised and supports microsegmentation within the cluster. Increasing image retention does not control runtime communications, and disabling logging reduces visibility. Sharing the same service account across all pods would weaken isolation and authorization. Strong Kubernetes security typically combines network policies, least-privilege service accounts, admission controls, image security, runtime monitoring, and secrets protection.

Question 4.

A company is evaluating a new SaaS provider that will process regulated customer information. Which activity provides the strongest assurance before onboarding the provider?

  1. Accept the provider’s marketing material as sufficient evidence.
    2. Perform a risk-based third-party assessment that reviews controls, data handling, contracts, and independent assurance evidence.
    3. Require the provider to use the same operating system as the company.
    4. Rely only on the provider’s public privacy statement.

Correct Answer: 2

Explanation:

A risk-based third-party assessment evaluates whether the provider’s security controls and contractual obligations are appropriate for the sensitivity of the data and the organization’s regulatory requirements. Evidence can include independent assurance reports, architecture documentation, encryption practices, incident-notification terms, subprocessors, data residency, resilience, and access controls. Marketing material and privacy statements provide limited assurance. Operating-system similarity is not a meaningful substitute for evaluating whether the provider manages security risk effectively throughout the service lifecycle.

Question 5.

A security team wants to detect previously unknown malicious behavior by identifying deviations from normal user and system activity. Which capability is most appropriate?

  1. User and entity behavior analytics
    2. Static allowlisting only
    3. Full-disk encryption
    4. Network address translation

Correct Answer: 1

Explanation:

User and entity behavior analytics establishes behavioral baselines and looks for deviations that may indicate compromised accounts, insider threats, or other abnormal activity. This can reveal suspicious behavior even when no known signature exists. Static allowlisting can prevent some unauthorized execution but does not provide comprehensive behavioral detection. Full-disk encryption protects data at rest, and NAT modifies addressing. UEBA is especially valuable when correlated with authentication logs, endpoint telemetry, cloud activity, and other contextual information.

Question 6.

An organization needs to protect cryptographic private keys used by a critical certificate authority from extraction. Which technology provides the strongest dedicated protection?

  1. A general-purpose file server
    2. An encrypted text file
    3. A password-protected ZIP archive
    4. A hardware security module

Correct Answer: 4

Explanation:

A hardware security module provides dedicated hardware-backed protection for cryptographic keys and can perform sensitive cryptographic operations without exposing private key material to ordinary system memory or storage. HSMs commonly support tamper resistance, access controls, auditing, and secure key lifecycle management. Encrypted files and archives provide some confidentiality but remain more vulnerable to credential compromise, malware, and extraction. For high-value certificate authority keys or enterprise signing keys, hardware-backed key protection significantly reduces key-theft risk.

Question 7.

A threat hunter observes repeated authentication attempts from several countries followed by a successful login and rapid access to cloud storage. Which hypothesis should be investigated first?

  1. Normal software patching
    2. Scheduled database maintenance
    3. Account compromise followed by unauthorized data access
    4. Hardware inventory collection

Correct Answer: 3

Explanation:

The sequence of geographically distributed authentication attempts, a successful login, and immediate access to cloud storage is consistent with a potentially compromised account. The hunter should examine authentication telemetry, MFA events, impossible-travel indicators, device information, session details, downloaded data, and related identity activity. The behavior does not closely match ordinary patching, database maintenance, or asset inventory. Threat hunting begins with a hypothesis and then uses available evidence to determine whether the observed behavior is malicious or benign.

Question 8.

A critical application uses multiple microservices. The security architect wants each service to authenticate other services without relying on long-lived shared secrets. Which design is best?

  1. Embed a common password in every container image.
    2. Use workload identities with short-lived certificates or tokens.
    3. Store one API key in a public configuration repository.
    4. Disable service authentication on internal networks.

Correct Answer: 2

Explanation:

Workload identities with short-lived certificates or tokens reduce the risk associated with static shared secrets. Each service can receive a distinct identity, and credentials can be rotated automatically and expire quickly. Embedded passwords and shared API keys are difficult to rotate and can compromise many services if exposed. Internal network location should not be treated as sufficient authentication. Modern service-to-service security commonly uses workload identity, mutual TLS, least privilege, and automated credential lifecycle management.

Question 9.

A security architect is designing controls for an industrial control system that cannot tolerate frequent active scanning. Which approach is most appropriate for asset visibility?

  1. Passive network monitoring tailored for OT protocols
    2. Aggressive vulnerability scanning every hour
    3. Frequent unauthenticated port sweeps from the internet
    4. Disabling all network monitoring

Correct Answer: 1

Explanation:

Passive monitoring observes network communications without actively probing sensitive industrial devices, making it well suited to operational technology environments where aggressive scans could disrupt fragile or safety-critical systems. OT-aware monitoring can identify devices, protocols, communication relationships, and anomalous behavior while minimizing operational impact. Active scanning may still be possible in carefully controlled circumstances, but it should be validated with asset owners and vendors. Eliminating monitoring would reduce visibility and make unauthorized or abnormal activity harder to detect.

Question 10.

A company wants to prevent developers from accidentally committing cloud API keys to source-code repositories. Which control provides the most direct preventive capability?

  1. Increase backup frequency.
    2. Extend password expiration periods.
    3. Disable code review.
    4. Implement automated secret scanning in repositories and CI/CD pipelines.

Correct Answer: 4

Explanation:

Automated secret scanning can identify credentials, API keys, tokens, and other sensitive values before or shortly after they are committed to a repository. Integrating scanning with pre-commit hooks and CI/CD pipelines provides early detection and can block unsafe changes. Backups do not prevent secret exposure, longer password lifetimes can increase risk, and disabling code review removes a useful security control. Organizations should also rotate any exposed secrets immediately rather than assuming deletion from the repository eliminates the compromise.

Question 11.

Which security architecture best limits lateral movement after an attacker compromises a user workstation?

  1. A single flat network with broad internal access
    2. Shared administrator credentials across all systems
    3. Microsegmentation with least-privilege access between security zones
    4. Disabling internal firewall rules

Correct Answer: 3

Explanation:

Microsegmentation limits communication between systems and workloads according to explicit business requirements. If a workstation becomes compromised, the attacker’s ability to reach servers, administrative interfaces, databases, and other sensitive assets can be substantially reduced. Flat networks and broad shared credentials make lateral movement easier. Internal firewall controls should reinforce segmentation rather than be disabled. Effective segmentation also benefits from identity-aware policies, monitoring, endpoint controls, and strong administrative separation.

Question 12.

An organization needs to ensure that sensitive data stored in a cloud database remains protected even if storage media or snapshots are accessed without authorization. Which control is most appropriate?

  1. Network load balancing
    2. Encryption at rest with securely managed keys
    3. DNS round-robin
    4. Increased application logging only

Correct Answer: 2

Explanation:

Encryption at rest protects stored information if underlying disks, backups, snapshots, or storage systems are accessed improperly. The effectiveness of the control depends heavily on secure key management, including access restrictions, rotation, backup, and separation of duties. Load balancing and DNS configuration address availability or traffic distribution rather than data confidentiality. Logging is important for detection and accountability but does not prevent an unauthorized party from reading unencrypted stored data.

Question 13.

A red team demonstrates that an attacker can reuse captured session tokens even after a user’s password is changed. Which control would most directly reduce this risk?

  1. Short-lived tokens with revocation and continuous session validation
    2. Increasing DNS cache duration
    3. Using longer usernames
    4. Disabling TLS inspection

Correct Answer: 1

Explanation:

Password changes do not necessarily invalidate existing session tokens. Short-lived tokens, explicit revocation, session binding, risk-based reevaluation, and continuous validation can limit how long stolen tokens remain useful. Sensitive applications may also bind sessions to device or contextual attributes and require reauthentication for high-risk actions. DNS settings and username length do not mitigate token replay. Token lifecycle management is therefore an important component of modern identity and zero-trust architectures.

Question 14.

A business requires rapid restoration of a critical service after ransomware while minimizing the chance that backups are encrypted by the attacker. Which backup strategy is strongest?

  1. Keep all backups permanently mounted to production servers.
    2. Store only one backup copy on the same storage array.
    3. Allow all administrators to delete backup history.
    4. Maintain isolated or immutable backups with regularly tested recovery procedures.

Correct Answer: 4

Explanation:

Isolated or immutable backups make it significantly harder for ransomware operators to encrypt or destroy recovery copies after compromising production systems. Recovery procedures should also be tested regularly because a backup is useful only if it can be restored within business recovery objectives. Permanently mounted backups may be reachable by attackers, while a single backup copy creates a dangerous single point of failure. Access to backup deletion and configuration functions should be tightly controlled and separately monitored.

Question 15.

Which technique best protects a software supply chain from unauthorized modification of build artifacts?

  1. Disable version control.
    2. Allow developers to distribute binaries directly from personal systems.
    3. Digitally sign artifacts and verify provenance throughout the build and deployment process.
    4. Store source code only on removable media.

Correct Answer: 3

Explanation:

Digital signatures and verifiable provenance help consumers and deployment systems confirm that an artifact originated from an authorized build process and was not modified afterward. Strong software supply-chain security also includes controlled build environments, dependency verification, protected repositories, isolated credentials, and auditable CI/CD processes. Disabling version control or distributing software directly from personal devices reduces integrity and traceability. Signing alone is not sufficient, but it is a central mechanism for protecting artifact authenticity and integrity.

Question 16.

A security team needs to automate containment of a confirmed malicious endpoint while preserving analyst oversight for high-impact actions. Which approach is best?

  1. Fully disable all automation.
    2. Use SOAR playbooks with approval gates for disruptive containment steps.
    3. Allow any alert to automatically shut down the entire network.
    4. Require analysts to perform every repetitive enrichment task manually.

Correct Answer: 2

Explanation:

Security orchestration, automation, and response can automate repetitive tasks such as enrichment, reputation checks, evidence collection, and ticket creation while requiring human approval for disruptive actions such as isolating a critical server. Approval gates balance speed with operational safety. Disabling automation sacrifices efficiency, while unrestricted automatic shutdown can create unacceptable business impact from false positives. A mature SOAR design uses confidence levels, asset criticality, escalation paths, logging, and human oversight where appropriate.

Question 17.

Which enterprise security control most directly reduces the risk posed by compromised third-party software dependencies?

  1. Maintain a software bill of materials and continuously assess dependency vulnerabilities.
    2. Disable all application logging.
    3. Allow unrestricted package downloads from unknown repositories.
    4. Avoid tracking software versions.

Correct Answer: 1

Explanation:

A software bill of materials provides visibility into the components and dependencies used within an application. When a third-party vulnerability is disclosed, the organization can quickly determine where the affected component is present and prioritize remediation. Continuous dependency scanning further helps identify vulnerable or malicious packages. Unrestricted external repositories and poor version tracking increase supply-chain risk. SBOMs are most effective when integrated with secure dependency sources, vulnerability management, provenance verification, and patch processes.

Question 18.

A security architect wants administrators to authenticate with cryptographic credentials that are resistant to phishing and replay. Which solution is strongest?

  1. SMS-only authentication
    2. Security questions
    3. Password reuse across systems
    4. Hardware-backed FIDO2 authentication

Correct Answer: 4

Explanation:

Hardware-backed FIDO2 authentication uses public-key cryptography and is designed to resist common phishing and replay attacks. The private credential remains protected by the authenticator and is bound to the legitimate service origin. SMS codes can be exposed through phishing, SIM-swap attacks, or interception, while security questions are often weak. Reusing passwords increases compromise risk. Strong phishing-resistant authentication is especially important for privileged and administrative accounts.

Question 19.

A company discovers a compromised server that may contain volatile evidence useful for determining attacker activity. What should the incident response team consider before powering the system off?

  1. Immediately reinstall the operating system.
    2. Delete temporary files.
    3. Capture volatile evidence when safe and consistent with the incident response plan.
    4. Disable all centralized logging.

Correct Answer: 3

Explanation:

Volatile evidence such as active network connections, running processes, memory-resident malware, encryption keys, and session information may disappear when a system is powered down. When circumstances permit, responders should collect relevant volatile evidence using approved procedures while considering containment, safety, and business impact. Immediate rebuilding may destroy useful evidence, and disabling logging reduces visibility. Incident response actions should follow documented procedures and preserve evidence integrity when forensic analysis or legal review may be required.

Question 20.

An organization is designing resilience for a mission-critical application. Which approach best reduces the risk of a single regional cloud outage causing complete service failure?

  1. Deploy every component into one availability zone.
    2. Design redundant application and data services across independent failure domains with tested failover.
    3. Store the only database backup on the production database server.
    4. Disable disaster-recovery testing to avoid downtime.

Correct Answer: 2

Explanation:

Resilient architectures distribute critical components across independent failure domains so that the loss of one zone or region does not automatically cause complete service failure. The design should include data replication, capacity planning, dependency analysis, controlled failover, and regular recovery testing. Keeping all components in one zone or storing backups only with production systems creates single points of failure. Disaster-recovery testing is necessary to verify that technical controls actually meet the organization’s recovery time and recovery point objectives.