View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 181.
A security architect wants to reduce the risk that a compromised workstation can access sensitive management interfaces. Which control is most appropriate?
- Restrict management access to hardened administrative workstations and dedicated management networks
2. Allow management access from any corporate endpoint
3. Use shared administrator accounts across all systems
4. Disable monitoring of privileged sessions
Correct Answer: 1
Explanation:
Hardened administrative workstations and dedicated management networks reduce exposure of sensitive interfaces to ordinary user endpoints. If a normal workstation is compromised, the attacker should not automatically gain a path to privileged systems. Shared credentials and unrestricted management access increase blast radius and weaken accountability. Strong administrative architecture also uses phishing-resistant MFA, just-in-time privilege, session monitoring, and separate identities for routine and privileged activities.
Question 182.
Which security mechanism best ensures that only approved infrastructure code can modify production cloud resources?
- Direct console changes by developers
2. Shared deployment credentials
3. Unreviewed scripts stored locally
4. Signed infrastructure-as-code artifacts deployed through a controlled pipeline
Correct Answer: 4
Explanation:
Signed infrastructure-as-code artifacts and a controlled deployment pipeline provide stronger assurance that production changes originate from an approved source and have not been modified. The pipeline can also enforce review, policy checks, and restricted deployment identities. Direct console changes and shared credentials reduce traceability and bypass preventive controls. IaC security should include protected repositories, peer review, immutable logs, and rollback procedures.
Question 183.
Which security capability is most useful for detecting unusual access patterns by privileged administrators?
- Data deduplication
2. Static routing
3. User and entity behavior analytics
4. RAID monitoring
Correct Answer: 3
Explanation:
UEBA can identify deviations from normal privileged-user behavior, including unusual login times, atypical resource access, unexpected geographies, or abnormal data transfers. Privileged identities are high-value targets, so behavioral analysis can reveal misuse even when valid credentials are used. Static routing, RAID, and deduplication do not provide identity behavior detection. UEBA should be correlated with PAM, authentication, endpoint, and cloud-control-plane telemetry for better context.
Question 184.
Which statement best describes the purpose of a secure access service edge architecture?
- It replaces all endpoint controls.
2. It converges network and security services to provide policy-based access for distributed users and applications.
3. It requires all traffic to remain inside one data center.
4. It disables identity-based access decisions.
Correct Answer: 2
Explanation:
SASE combines networking and security functions, often including secure web access, zero-trust access, firewalling, and other cloud-delivered controls. It is designed for distributed users, branches, cloud services, and applications rather than relying solely on a central data center. Identity and context are typically important policy inputs. SASE does not replace endpoint security or eliminate the need for application-level authorization.
Question 185.
A security team wants to prevent a compromised workload from reading secrets belonging to unrelated applications. Which control is strongest?
- Use separate workload identities with narrowly scoped secrets permissions
2. Store all secrets in one shared file
3. Give every workload vault-administrator rights
4. Disable secrets-access logging
Correct Answer: 1
Explanation:
Separate workload identities and narrowly scoped permissions ensure that each application can access only the secrets it requires. If one workload is compromised, the attacker should not automatically gain access to credentials for unrelated services. Shared files and vault-admin privileges dramatically increase blast radius. Secrets platforms should also support auditing, rotation, short-lived credentials, and policy enforcement.
Question 186.
Which approach best protects archived sensitive data against unauthorized decryption many years in the future?
- Use permanently fixed weak algorithms.
2. Disable encryption for older archives.
3. Reuse the same encryption key indefinitely.
4. Use strong cryptography, sound key management, and a migration plan for future algorithm changes.
Correct Answer: 4
Explanation:
Long-lived sensitive data requires both strong current cryptography and the ability to migrate when algorithms or key sizes become insufficient. Cryptographic agility, key rotation, secure archival key storage, and periodic reassessment are important. Using one key indefinitely increases exposure, while weak or disabled encryption provides poor confidentiality. Organizations should also consider future threats such as advances in cryptanalysis and quantum computing when designing long-term protection.
Question 187.
Which control is most appropriate for detecting unauthorized modifications to critical configuration files on a Linux server?
- DNS caching
2. Load balancing
3. File integrity monitoring
4. Network address translation
Correct Answer: 3
Explanation:
File integrity monitoring tracks changes to important files by comparing current values against approved baselines or hashes. It can detect unauthorized modifications to configuration files, binaries, scripts, and system components. DNS caching, load balancing, and NAT serve unrelated purposes. FIM alerts should be correlated with change-management records so legitimate updates can be distinguished from suspicious tampering.
Question 188.
Which security principle is being applied when an organization requires one administrator to request a sensitive change and another to approve it?
- Data minimization
2. Separation of duties
3. Network segmentation
4. Tokenization
Correct Answer: 2
Explanation:
Separation of duties prevents one individual from independently completing all stages of a high-risk activity. Requiring separate request and approval roles reduces the chance of fraud, abuse, or accidental change. This principle is particularly important for privileged access, financial transactions, cryptographic key operations, and production changes. It complements least privilege and improves accountability.
Question 189.
An application suddenly begins querying the cloud instance metadata service after a new feature is released. Which threat should be investigated first?
- Server-side request forgery
2. ARP spoofing
3. Password spraying
4. Bluetooth eavesdropping
Correct Answer: 1
Explanation:
Unexpected application access to a cloud metadata service can indicate server-side request forgery, particularly if user-controlled URLs or request destinations are involved. Metadata endpoints may expose temporary credentials or instance information. Defenses include destination validation, metadata-service protections, outbound filtering, and least-privilege instance roles. ARP spoofing and password spraying do not best match the observed behavior.
Question 190.
Which control best protects emergency administrative accounts from unnoticed misuse?
- Use the account for daily operations.
2. Share the account with the entire IT team.
3. Exempt the account from auditing.
4. Alert immediately on every use and require strong authentication and documented access procedures.
Correct Answer: 4
Explanation:
Emergency accounts should be rarely used and closely monitored. Every login should generate immediate review because unexpected use may indicate compromise or policy violation. Strong authentication, secure credential storage, and documented procedures reduce risk. Routine use or shared access weakens accountability and makes malicious activity harder to distinguish from legitimate administration.
Question 191.
Which security control best reduces the impact of dependency confusion attacks in a software build environment?
- Allow packages from any repository.
2. Disable package verification.
3. Use trusted repositories, namespace controls, version pinning, and integrity validation.
4. Remove all dependency inventories.
Correct Answer: 3
Explanation:
Dependency confusion exploits package-resolution behavior to introduce malicious packages that appear preferable to legitimate internal components. Trusted repositories, controlled namespaces, version pinning, and integrity validation reduce this risk. Software composition analysis and SBOMs further improve visibility. Arbitrary package retrieval and disabled verification increase supply-chain exposure.
Question 192.
Which statement best describes the purpose of data sovereignty requirements?
- They only address network bandwidth.
2. They concern where data is stored, processed, or subject to legal jurisdiction.
3. They eliminate the need for encryption.
4. They apply only to physical backups.
Correct Answer: 2
Explanation:
Data sovereignty concerns the legal and regulatory implications of where information is stored, processed, and accessed. Different jurisdictions may impose requirements on residency, government access, privacy, transfer mechanisms, or retention. Cloud architectures must therefore consider region selection, subprocessors, replication, and cross-border data movement. Sovereignty requirements do not replace encryption or broader security controls.
Question 193.
Which incident response action should occur after confirming that a privileged API token has been exposed publicly?
- Revoke the token, replace it, preserve relevant logs, and investigate its use
2. Leave it active until scheduled expiration
3. Delete audit records associated with it
4. Increase its permissions for easier testing
Correct Answer: 1
Explanation:
A publicly exposed privileged token should be treated as compromised. Revocation or rotation limits further abuse, while preserved audit logs help determine whether the token was already used maliciously. Responders should also identify the exposure source, search for related secrets, and review affected resources. Waiting for expiration prolongs risk, and deleting logs destroys useful evidence.
Question 194.
Which architecture best protects sensitive systems when production identity services are compromised?
- Make recovery fully dependent on production identities.
2. Use the same privileged credentials everywhere.
3. Allow unrestricted backup deletion from production accounts.
4. Maintain isolated recovery access with separate identities and protected backup infrastructure.
Correct Answer: 4
Explanation:
Separate recovery identities and isolated backup administration reduce the chance that compromise of production identity systems also destroys the organization’s ability to recover. Protected or immutable backups add further resilience. Using the same credentials and control plane creates common failure modes. Recovery procedures should be exercised regularly to confirm that independent access and restoration processes work when production systems are unavailable.
Question 195.
Which approach best reduces the risk of malicious use of AI agents connected to internal business systems?
- Give every AI agent global administrator rights.
2. Disable authorization checks for agent actions.
3. Restrict tool access, enforce independent authorization, and require approval for high-impact operations.
4. Let the model modify its own audit trail.
Correct Answer: 3
Explanation:
AI agents should operate under least privilege and should not be trusted to authorize their own actions. Tool access should be narrowly scoped, sensitive operations should be independently validated, and high-impact changes may require human approval. Detailed logging is essential for accountability. This reduces the potential damage from prompt injection, malicious inputs, model errors, or unexpected behavior.
Question 196.
Which statement best describes security orchestration, automation, and response?
- It replaces all analysts.
2. It coordinates tools and automates repeatable security workflows while supporting controlled response.
3. It guarantees that every alert is malicious.
4. It eliminates the need for incident-response planning.
Correct Answer: 2
Explanation:
SOAR platforms integrate security tools and automate repetitive workflows such as enrichment, ticketing, containment, and evidence collection. Human oversight is still important for ambiguous or high-impact actions. Automation can improve speed and consistency but does not guarantee alert accuracy or replace incident-response planning. Mature implementations use confidence thresholds, approvals, and rollback capabilities where appropriate.
Question 197.
Which practice best reduces risk from dormant privileged identities?
- Periodically review and disable unused privileged accounts
2. Exempt dormant accounts from monitoring
3. Increase their privileges
4. Share their credentials among administrators
Correct Answer: 1
Explanation:
Dormant privileged accounts increase attack surface because they may remain exploitable despite no longer serving a business purpose. Regular access reviews should identify and disable unused human, service, and emergency identities where appropriate. Shared credentials or monitoring exemptions reduce accountability and increase risk. Identity governance should cover the full lifecycle from creation through deprovisioning.
Question 198.
Which activity most strongly suggests unauthorized persistence in a cloud environment?
- A normal backup finishes.
2. A user views a standard report.
3. A routine health check succeeds.
4. A suspicious account creates a new service principal with long-lived credentials.
Correct Answer: 4
Explanation:
Attackers often create new identities, service principals, access keys, or application credentials to maintain access even if the original compromised session is revoked. A new long-lived credential created by a suspicious account is therefore a strong persistence indicator. Responders should revoke unauthorized identities, preserve logs, review role assignments, and investigate related resource changes.
Question 199.
Which control best reduces the risk of exposing sensitive customer data in development and testing environments?
- Copy all production records into every test environment.
2. Disable test-environment access logging.
3. Use masked, anonymized, or synthetic data whenever full production data is unnecessary.
4. Give all developers production database access.
Correct Answer: 3
Explanation:
Masked, anonymized, and synthetic data allow developers and testers to work without unnecessarily exposing real customer information. This supports data minimization and reduces privacy and compliance risk. Nonproduction environments should still use strong access control, encryption, monitoring, and segmentation. Full production data should be used only when there is a justified requirement and appropriate protection.
Question 200.
Which approach best supports continuous improvement of enterprise security architecture?
- Treat architecture as final after initial deployment.
2. Continuously validate controls, review threat models, test recovery, measure detection performance, and update designs as risks change.
3. Avoid revisiting architectural assumptions.
4. Perform security reviews only after major incidents.
Correct Answer: 2
Explanation:
Security architecture must evolve because technologies, business processes, identities, dependencies, and attacker techniques continually change. Ongoing threat modeling, control validation, resilience testing, detection measurement, and architecture review help identify weaknesses before they become serious incidents. Security should be treated as a lifecycle discipline rather than a one-time implementation.