CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part11 Q201-220

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 201.

A security architect wants to reduce the risk that a single compromised SaaS administrator account can make irreversible tenant-wide changes. Which design is most appropriate?

  1. Require just-in-time privilege elevation with independent approval and immutable audit logging
    2. Give every administrator permanent global privileges
    3. Use one shared administrator account for all support staff
    4. Disable change notifications to reduce alert volume

Correct Answer: 1

Explanation:

Just-in-time elevation limits how long powerful permissions exist, while independent approval provides separation of duties for high-risk actions. Immutable logging preserves evidence of who requested, approved, and performed each change. Permanent global access and shared accounts increase blast radius and weaken accountability. Sensitive administrative operations should also use strong MFA, session monitoring, role reviews, and clearly defined emergency-access procedures.

Question 202.

Which control best protects sensitive data when several analytics teams require access to different portions of the same data lake?

  1. Give every team unrestricted administrator access.
    2. Use one shared data-access account.
    3. Disable data classification to simplify permissions.
    4. Apply fine-grained role- or attribute-based access controls based on data classification and business need.

Correct Answer: 4

Explanation:

Fine-grained authorization allows each analytics team to access only the data and operations required for its legitimate purpose. Data classification helps determine which records require stronger restrictions, masking, or monitoring. Shared accounts and broad administrator permissions increase exposure and reduce accountability. Strong data-lake security also includes encryption, audit logging, data minimization, and periodic access reviews.

Question 203.

A cloud workload must prove its identity to another service without storing a long-lived secret. Which approach is best?

  1. Embed a static API key in the application image.
    2. Use one shared credential for all workloads.
    3. Use workload identity federation to obtain short-lived credentials.
    4. Disable authentication for internal service traffic.

Correct Answer: 3

Explanation:

Workload identity federation allows a trusted workload identity to obtain temporary credentials without storing a long-lived secret. Short-lived credentials reduce the period in which stolen access can be abused and are easier to rotate automatically. Shared or embedded credentials create larger blast radius and greater exposure. Authorization should still be narrowly scoped so the workload can access only the resources required for its function.

Question 204.

Which security practice most directly limits damage if a production API signing key is compromised?

  1. Never rotate signing keys.
    2. Use short validity periods, secure key rotation, revocation, and protected key storage.
    3. Store the private key in source control.
    4. Reuse the same key across all environments.

Correct Answer: 2

Explanation:

Short validity periods, secure rotation, revocation capability, and strong key protection reduce the useful lifetime and impact of a compromised signing key. Reusing the same key across development and production unnecessarily expands the blast radius. Private keys should be stored in an HSM or equivalent protected system when their compromise would have serious consequences. Key lifecycle procedures should also include auditing, backup, and emergency replacement.

Question 205.

A threat hunter observes a user account authenticating normally but then accessing systems the user has never previously used. Which approach is most appropriate?

  1. Correlate identity behavior, endpoint activity, privilege use, and resource access patterns
    2. Ignore the behavior because authentication succeeded
    3. Disable centralized logging
    4. Rely only on antivirus signatures

Correct Answer: 1

Explanation:

Successful authentication does not prove that account activity is legitimate. A compromised user may authenticate correctly using stolen credentials or tokens. Correlating identity behavior with endpoint, network, privilege, and resource-access telemetry can reveal account takeover or insider misuse. Behavioral context is especially valuable when the attacker uses legitimate credentials and standard administrative tools rather than malware.

Question 206.

Which architecture best protects high-value cryptographic keys from compromise of the application server using them?

  1. Keep keys in a local plaintext configuration file.
    2. Store keys in the application’s source repository.
    3. Place keys in a shared network folder.
    4. Perform cryptographic operations in an HSM or equivalent hardware-backed key service.

Correct Answer: 4

Explanation:

An HSM or hardware-backed key service isolates sensitive key material from the application server and can perform cryptographic operations without exposing private keys directly. Plaintext files, repositories, and shared folders leave keys vulnerable to malware or privileged attackers. High-value key systems should also enforce least privilege, separation of duties, key rotation, auditing, and documented recovery procedures.

Question 207.

Which security capability is most appropriate for identifying resources that an organization has exposed to the internet without realizing it?

  1. RAID monitoring
    2. Local printer inventory
    3. External attack surface management
    4. File compression

Correct Answer: 3

Explanation:

External attack surface management discovers internet-facing domains, hosts, cloud services, applications, certificates, and other externally reachable assets. It can help identify shadow IT, forgotten systems, and exposed services that are not present in internal inventories. RAID monitoring and local inventory tools do not provide the same external visibility. Findings should feed asset management, vulnerability remediation, and ownership processes.

Question 208.

Which statement best describes a strong zero-trust authorization model?

  1. Internal network location automatically grants trust.
    2. Access decisions continuously consider identity, device, context, resource sensitivity, and policy.
    3. Authentication is required only once for the lifetime of an account.
    4. All authenticated users receive the same permissions.

Correct Answer: 2

Explanation:

Zero trust removes implicit trust based on network location and requires explicit, context-aware authorization. Access decisions may consider identity, device posture, authentication strength, session risk, resource sensitivity, and requested action. Authentication alone is not enough because authorization must still enforce least privilege. Continuous evaluation can also revoke or restrict access when risk changes during an active session.

Question 209.

A company wants to ensure that developers cannot bypass security controls by deploying directly to production. Which control is strongest?

  1. Require production changes to pass through protected CI/CD pipelines with approval gates and restricted deployment identities
    2. Give every developer direct production administrator access
    3. Share deployment credentials across teams
    4. Disable build and deployment logs

Correct Answer: 1

Explanation:

Controlled CI/CD pipelines enforce consistent review, testing, policy validation, and deployment procedures. Restricted deployment identities limit what the pipeline can change, while approval gates provide oversight for sensitive releases. Direct administrator access from developer systems bypasses these controls and creates a larger attack surface. Strong pipelines also protect signing keys, use short-lived credentials, and retain tamper-resistant audit logs.

Question 210.

Which control best reduces the likelihood of a malicious insider secretly deleting audit evidence?

  1. Store logs only on the administrator’s workstation.
    2. Allow administrators to disable logging without alerting.
    3. Keep all audit data on the same system being administered.
    4. Forward logs to a separate immutable or tamper-resistant logging platform.

Correct Answer: 4

Explanation:

Forwarding audit records to a separate protected platform makes it much harder for a compromised or malicious administrator to alter or delete evidence. Immutability or write-once protections further strengthen integrity. Local-only logs can be erased after compromise. Critical administrative activity should also generate alerts for logging gaps, policy changes, and attempts to disable monitoring.

Question 211.

Which security practice best reduces risk from malicious package updates in a software supply chain?

  1. Trust every update automatically.
    2. Disable integrity verification.
    3. Verify package signatures, provenance, dependency changes, and repository source before release.
    4. Allow developers to download dependencies from unknown repositories.

Correct Answer: 3

Explanation:

Software supply-chain security requires validating where packages originated, whether they were modified, and whether dependencies changed unexpectedly. Signature verification and provenance provide integrity and origin assurance, while trusted repositories reduce exposure to malicious packages. Automated dependency scanning, SBOM generation, and controlled package publishing further strengthen the build process.

Question 212.

Which statement best describes the purpose of a security control baseline?

  1. It guarantees that every system is immune to attack.
    2. It defines a minimum consistent set of security requirements for a class of systems or environments.
    3. It removes the need for risk assessment.
    4. It applies only to physical facilities.

Correct Answer: 2

Explanation:

A security baseline establishes minimum required controls such as hardening settings, logging, encryption, authentication, patching, and network restrictions. Baselines improve consistency and reduce configuration drift across similar systems. They do not guarantee security or eliminate the need for risk-based exceptions. Baselines should be reviewed periodically and adapted when threats, technologies, or business requirements change.

Question 213.

An incident responder confirms that a compromised user account created several long-lived API tokens. Which action is most appropriate?

  1. Revoke the tokens, terminate suspicious sessions, preserve evidence, and investigate associated activity
    2. Wait for all tokens to expire naturally
    3. Increase token permissions to make investigation easier
    4. Delete authentication logs

Correct Answer: 1

Explanation:

Long-lived API tokens created by a compromised identity may provide persistence even after the original password is changed. Responders should revoke unauthorized tokens and sessions while preserving logs needed to determine scope and timeline. They should also review privilege changes, accessed resources, related identities, and other persistence mechanisms. Deleting evidence or waiting for expiration unnecessarily prolongs risk.

Question 214.

Which architecture best supports resilient recovery after a destructive attack that compromises production identity services?

  1. Depend entirely on the production identity provider for recovery access.
    2. Reuse production administrator credentials in the recovery environment.
    3. Keep backups permanently writable from production.
    4. Maintain isolated recovery identities, immutable backups, and independently accessible recovery infrastructure.

Correct Answer: 4

Explanation:

A destructive attacker may target identity systems, production workloads, and backups simultaneously. Independent recovery identities prevent restoration from depending on the same compromised control plane. Immutable backups reduce the ability to destroy recovery data, while isolated infrastructure provides an alternate path for restoration. Recovery must also be regularly exercised to confirm that procedures, credentials, dependencies, and backups actually work under crisis conditions.

Question 215.

Which control most directly reduces the chance that an AI agent can perform an unauthorized high-impact action?

  1. Independent authorization checks and human approval for sensitive operations
    2. Give the agent unrestricted administrator privileges
    3. Disable audit logging for agent actions
    4. Allow the model to decide its own permissions

Correct Answer: 1

Explanation:

AI agents should not be allowed to authorize themselves. Independent policy enforcement ensures that actions are validated against enterprise security requirements regardless of what the model requests. High-impact operations may require human approval, especially when they affect privileged accounts, production systems, or sensitive data. Least privilege, tool restrictions, logging, and rollback capability further reduce the consequences of unexpected or manipulated agent behavior.

Question 216.

Which statement best describes a tabletop incident response exercise?

  1. It is a live destructive test against production systems.
    2. It is a discussion-based exercise in which participants walk through roles, decisions, and procedures for a simulated incident.
    3. It replaces technical recovery testing permanently.
    4. It guarantees that the organization will respond perfectly during a real incident.

Correct Answer: 2

Explanation:

A tabletop exercise is a structured discussion that allows participants to practice decision-making, escalation, communication, and coordination during a simulated incident. It can identify unclear responsibilities, outdated procedures, and dependency gaps without disrupting production. Tabletop exercises complement technical simulations, recovery tests, and red-team activities rather than replacing them.

Question 217.

Which practice best reduces the risk from unused service accounts with elevated privileges?

  1. Periodically identify, review, disable, or remove inactive service identities
    2. Exempt service accounts from access reviews
    3. Increase privileges on dormant accounts
    4. Disable monitoring of machine identities

Correct Answer: 1

Explanation:

Dormant service accounts can provide attackers with overlooked access paths, especially when they retain elevated permissions or long-lived credentials. Identity governance should include nonhuman identities, not just employees. Accounts that are no longer needed should be disabled or removed after dependency validation. Active service accounts should have narrowly scoped permissions, credential rotation, and behavioral monitoring.

Question 218.

Which activity most strongly suggests a possible attempt to weaken cloud defenses before further compromise?

  1. A standard health check succeeds.
    2. A routine backup completes.
    3. An approved user views a dashboard.
    4. A privileged identity disables threat-detection services and modifies audit-log retention unexpectedly.

Correct Answer: 4

Explanation:

Attackers frequently attempt to reduce visibility before performing additional malicious actions. Unexpected disabling of threat detection and weakening of audit-log retention are therefore high-priority events. Analysts should validate the identity and session, preserve existing logs, restore monitoring, and investigate any actions performed before and after the change. Routine operational events do not present the same level of risk.

Question 219.

Which architecture most directly reduces the risk of data exfiltration from compromised workloads?

  1. Allow unrestricted outbound internet connectivity.
    2. Disable network monitoring.
    3. Enforce egress filtering, destination controls, DLP where appropriate, and outbound traffic monitoring.
    4. Trust all traffic generated by production systems.

Correct Answer: 3

Explanation:

Egress filtering limits where workloads can communicate, while destination controls and monitoring can identify unusual outbound activity. DLP can add content-aware protection when sensitive information is transferred through supported channels. Compromised production systems should not be assumed trustworthy. Restricting outbound paths can also interfere with command-and-control traffic and make exfiltration more difficult.

Question 220.

Which approach best supports long-term effectiveness of enterprise security controls?

  1. Assume controls remain effective after deployment.
    2. Continuously measure, test, tune, and validate controls against changing threats, systems, and business requirements.
    3. Review controls only after a major breach.
    4. Avoid changing detections once they are implemented.

Correct Answer: 2

Explanation:

Security effectiveness changes as infrastructure, identities, applications, attacker techniques, and business requirements evolve. Continuous validation through control testing, detection measurement, purple-team exercises, architecture reviews, recovery testing, and risk reassessment helps reveal degraded or incomplete controls. Findings should drive tuning and remediation so the security program continues to reduce real risk rather than relying on assumptions.