CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part13 Q241-260

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 241.

A security architect wants to reduce the risk that sensitive workloads can communicate with unauthorized internal services after one application is compromised. Which control is most appropriate?

  1. Identity-aware microsegmentation with explicit east-west allow policies
    2. A flat internal network with broad trust
    3. Shared credentials between application tiers
    4. Unrestricted internal routing

Correct Answer: 1

Explanation:

Identity-aware microsegmentation limits workload-to-workload communication to approved paths and can make decisions based on service identity rather than network location alone. This reduces lateral movement if one application is compromised. Flat networks and shared credentials increase blast radius because an attacker may reach unrelated systems. Strong east-west controls should be combined with workload identity, application authorization, monitoring, and least-privilege service permissions.

Question 242.

Which approach best protects an organization from malicious changes to production cloud configurations that bypass the normal deployment pipeline?

  1. Allow unrestricted manual console changes.
    2. Disable configuration monitoring.
    3. Trust administrators to document changes later.
    4. Use configuration drift detection and alert on changes that differ from approved infrastructure-as-code state.

Correct Answer: 4

Explanation:

Configuration drift detection compares actual deployed resources against the approved infrastructure-as-code baseline. Unexpected differences can indicate manual changes, compromised credentials, or configuration errors. Alerting on drift helps teams identify changes that bypass normal review and deployment controls. Manual console changes should be tightly restricted, and approved emergency changes should eventually be reconciled into the authoritative infrastructure definition.

Question 243.

A company wants to identify cloud resources that have excessive permissions compared with what their identities actually use. Which capability is most appropriate?

  1. Network address translation
    2. RAID monitoring
    3. Cloud infrastructure entitlement management
    4. File compression

Correct Answer: 3

Explanation:

Cloud infrastructure entitlement management evaluates permissions assigned to human and machine identities and can compare granted access with actual usage. This helps identify excessive, unused, inherited, or risky entitlements. Such analysis supports least privilege and reduces the chance that a compromised account can access unnecessary resources. NAT, RAID, and compression do not provide identity entitlement visibility.

Question 244.

Which security control best reduces risk when an enterprise must continue operating an unpatchable legacy system?

  1. Connect it directly to the internet.
    2. Apply compensating controls such as segmentation, allowlisting, monitoring, and tightly restricted access.
    3. Give all users local administrator rights.
    4. Disable logging to reduce system load.

Correct Answer: 2

Explanation:

When a vulnerable legacy system cannot be patched immediately, compensating controls can reduce exposure while the organization plans replacement or remediation. Segmentation limits reachable systems, allowlisting restricts permitted communication or applications, and enhanced monitoring can detect suspicious behavior. Access should be tightly controlled. These measures do not remove the underlying vulnerability, so the residual risk should be documented and reviewed.

Question 245.

Which action provides the strongest protection when a private key used by an internal certificate authority is suspected of compromise?

  1. Revoke affected certificates as appropriate, replace the compromised key, and investigate issued certificates.
    2. Continue using the key until its scheduled expiration.
    3. Publish the private key for transparency.
    4. Disable PKI logging.

Correct Answer: 1

Explanation:

A compromised certificate authority key can undermine trust in certificates issued under that authority. The organization should replace the affected key and determine which certificates may need revocation or reissuance. Logs should be preserved to identify potentially fraudulent certificate issuance. Continuing to trust a compromised private key extends the risk and may allow attackers to impersonate systems or users.

Question 246.

Which architecture best protects highly sensitive encryption keys used by multiple enterprise applications?

  1. Store keys in application configuration files.
    2. Distribute copies of keys to development teams.
    3. Keep keys in source repositories.
    4. Use centralized hardware-backed key management with controlled cryptographic operations.

Correct Answer: 4

Explanation:

Centralized hardware-backed key management can protect key material from extraction while enforcing access controls, rotation, auditing, and cryptographic operations. Application configuration files and source repositories expose high-value keys to unnecessary users and systems. Centralization also makes lifecycle management more consistent. Access should still be separated by application and role so one compromised workload cannot use every enterprise key.

Question 247.

Which security practice is most effective for finding hidden attack paths created by nested groups, delegated roles, and indirect trust relationships?

  1. Disk encryption
    2. DNS filtering
    3. Identity attack-path analysis and permission graphing
    4. Network load balancing

Correct Answer: 3

Explanation:

Permission graphing can reveal indirect privilege paths that are difficult to see from individual access-control entries. Nested group membership, delegated roles, service principals, trust relationships, and privilege inheritance may allow a seemingly low-privilege identity to reach sensitive resources. Identity attack-path analysis helps security teams identify and remove these unintended escalation opportunities before attackers exploit them.

Question 248.

Which statement best describes the purpose of step-up authentication?

  1. It permanently grants elevated privileges after login.
    2. It requires stronger authentication when a user performs a higher-risk action or accesses a sensitive resource.
    3. It disables MFA for trusted users.
    4. It replaces authorization decisions.

Correct Answer: 2

Explanation:

Step-up authentication requires additional or stronger verification when risk increases, such as when accessing sensitive data, changing security settings, or approving a financial transaction. A user may have already authenticated normally, but the higher-risk operation triggers stronger assurance. Step-up authentication complements authorization and least privilege; it does not replace them or create permanent elevated access.

Question 249.

A security team wants to detect whether an attacker is using stolen credentials from geographically distant locations within a time period that would be physically impossible for the legitimate user. Which detection is most appropriate?

  1. Impossible-travel analysis combined with device and session context
    2. RAID health monitoring
    3. Disk deduplication
    4. Printer auditing

Correct Answer: 1

Explanation:

Impossible-travel analysis identifies authentication events that occur from distant geographic locations within an implausibly short period. Device, VPN, proxy, and session context should also be considered because legitimate services can produce apparent geographic anomalies. When correlated with unfamiliar devices, token use, or risky authentication events, impossible travel can provide a useful account-compromise signal.

Question 250.

Which control best reduces the likelihood that a compromised API client can consume excessive backend resources?

  1. Disable authentication.
    2. Allow unlimited request rates.
    3. Trust authenticated clients completely.
    4. Enforce rate limits, quotas, and resource-consumption controls.

Correct Answer: 4

Explanation:

Authentication confirms identity but does not prevent an authenticated or compromised client from abusing backend resources. Rate limits and quotas restrict request volume and can prevent one consumer from exhausting shared capacity. Resource-consumption controls may also limit expensive queries, payload sizes, or concurrency. These safeguards should be combined with monitoring, authorization, and anomaly detection.

Question 251.

Which security control best helps an organization detect whether attackers are using trusted administrative tools for lateral movement?

  1. File compression
    2. Static routing
    3. Endpoint detection correlated with identity and remote-access telemetry
    4. RAID mirroring

Correct Answer: 3

Explanation:

Attackers frequently use legitimate administrative tools to blend into normal activity. Endpoint detection can record process execution, command-line arguments, parent-child relationships, remote sessions, and network activity. Correlating these events with authentication and identity telemetry helps distinguish authorized administration from suspicious lateral movement. File compression and RAID monitoring do not provide this behavioral context.

Question 252.

Which statement best describes the purpose of an SBOM?

  1. It provides network segmentation rules.
    2. It documents software components and dependencies contained in an application or product.
    3. It stores user passwords.
    4. It replaces vulnerability scanning.

Correct Answer: 2

Explanation:

A software bill of materials provides visibility into libraries, frameworks, packages, and other components included in software. When a dependency vulnerability is discovered, organizations can use an SBOM to determine which applications may be affected. An SBOM does not replace scanning, testing, or remediation. It supports supply-chain transparency and faster impact analysis.

Question 253.

A company discovers that a privileged administrator account is being used from a previously unseen device. What is the most appropriate first security response?

  1. Validate the session, assess risk, and require additional authentication or containment as warranted.
    2. Assume the activity is legitimate because the credentials are valid.
    3. Disable all privileged logging.
    4. Permanently allow the new device without verification.

Correct Answer: 1

Explanation:

A new device accessing a privileged account should be treated as a meaningful risk signal. The organization should validate the user and device, review the authentication method, inspect recent activity, and apply step-up authentication or containment if the context is suspicious. Valid credentials alone are not sufficient proof that access is legitimate. Privileged sessions require heightened monitoring because compromise can have broad consequences.

Question 254.

Which design best protects sensitive business data if ransomware compromises production administrator accounts?

  1. Keep all backups mounted and writable from production.
    2. Use identical credentials for production and backup administration.
    3. Allow unrestricted backup deletion from production accounts.
    4. Use immutable backups with separate recovery identities and isolated administration.

Correct Answer: 4

Explanation:

Immutable backups prevent protected recovery data from being modified or deleted during the retention period. Separate recovery identities and isolated administration reduce the chance that stolen production credentials can destroy backup systems as well. Using shared credentials and continuously writable backups creates common failure paths. Recovery procedures should also be tested regularly to verify that protected backups can be restored successfully.

Question 255.

Which security technique best reduces exposure of sensitive fields in analytics data sets when exact identifiers are unnecessary?

  1. Disable encryption.
    2. Provide analysts unrestricted raw production access.
    3. Use masking, pseudonymization, or aggregation.
    4. Copy the data to unmanaged endpoints.

Correct Answer: 3

Explanation:

Masking, pseudonymization, and aggregation reduce the amount of directly identifying or sensitive information exposed during analysis. This supports data minimization while preserving analytical usefulness. Giving broad access to raw production data increases privacy and security risk. The chosen technique should reflect whether re-identification is necessary, the sensitivity of the data, and applicable legal or regulatory requirements.

Question 256.

Which statement best describes the purpose of continuous control monitoring?

  1. It replaces all human review.
    2. It repeatedly evaluates whether required security controls remain implemented and effective over time.
    3. It guarantees that systems cannot be breached.
    4. It is used only during initial system deployment.

Correct Answer: 2

Explanation:

Continuous control monitoring evaluates whether required safeguards remain in place as environments change. It can identify configuration drift, disabled logging, excessive privileges, missing encryption, or other deviations from policy. Automated checks improve speed and consistency, but human review is still needed for interpretation, exceptions, and risk decisions. The objective is to detect control degradation before it creates serious exposure.

Question 257.

Which practice best reduces the security risk associated with third-party SaaS integrations that request broad access to enterprise data?

  1. Review requested permissions, restrict scopes, validate the vendor, and monitor ongoing access.
    2. Approve every integration automatically.
    3. Give all integrations administrator-level permissions.
    4. Disable audit logs for third-party applications.

Correct Answer: 1

Explanation:

Third-party integrations should receive only the permissions required for their intended function. Vendor security posture, requested scopes, data handling, contractual obligations, and ongoing activity should be assessed before approval. Broad permissions can allow a compromised or malicious integration to access large amounts of enterprise data. Periodic reviews should remove integrations and permissions that are no longer needed.

Question 258.

Which activity most strongly suggests possible tampering with enterprise security monitoring?

  1. An application completes a normal health check.
    2. A scheduled report is generated.
    3. A backup completes successfully.
    4. A privileged identity unexpectedly disables multiple security data collectors shortly after logging in from a new location.

Correct Answer: 4

Explanation:

Disabling multiple security data collectors after anomalous privileged authentication is a strong indicator that an attacker may be attempting to reduce visibility before further activity. Responders should validate the account, restore telemetry, revoke suspicious sessions if appropriate, and examine actions performed before and after monitoring was disrupted. Security telemetry itself should be protected as a high-value asset.

Question 259.

Which architecture best protects APIs that are accessed by external partners with different business permissions?

  1. Use a single shared administrator token for all partners.
    2. Disable authorization after authentication.
    3. Use separate partner identities, scoped tokens, fine-grained authorization, and API gateway controls.
    4. Trust all partner traffic based only on source IP.

Correct Answer: 3

Explanation:

Separate identities and scoped tokens allow each partner to receive only the API permissions required for its business relationship. Fine-grained authorization can restrict resources and operations, while API gateways can enforce rate limits, validation, and monitoring. Shared administrator tokens create excessive risk and poor accountability. Network location alone should not determine authorization.

Question 260.

Which approach best supports secure long-term adoption of new technologies across an enterprise?

  1. Deploy new technology broadly before assessing risk.
    2. Perform threat modeling, define security requirements, test controls, monitor outcomes, and update governance as the technology evolves.
    3. Assume vendor defaults are always sufficient.
    4. Avoid reviewing new technology after initial approval.

Correct Answer: 2

Explanation:

New technologies can introduce unfamiliar trust boundaries, dependencies, failure modes, and data risks. Threat modeling and explicit security requirements help identify these issues before broad deployment. Testing and monitoring provide evidence that controls work, while governance must evolve as usage patterns and threats change. Security should therefore be integrated throughout the technology lifecycle rather than added only after deployment.