View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 261.
A security architect wants to reduce the risk that a compromised privileged account can immediately alter critical identity policies. Which control provides the strongest protection?
- Require just-in-time elevation, independent approval, and strong MFA for identity-policy changes
2. Give all administrators permanent global privileges
3. Use a shared identity-administrator account
4. Disable logging for sensitive policy changes
Correct Answer: 1
Explanation:
Just-in-time elevation reduces standing privilege, while independent approval adds separation of duties for high-impact identity changes. Strong MFA further reduces the chance that stolen credentials alone can authorize sensitive actions. Shared or permanent administrator access increases blast radius and weakens accountability. Identity-policy changes should also be logged centrally and monitored because modifications to authentication, federation, or privilege rules can affect access across the enterprise.
Question 262.
Which control best protects an organization from unauthorized changes to container orchestration security policies?
- Allow all cluster administrators to make direct unreviewed changes.
2. Disable configuration versioning.
3. Store cluster policies only on local administrator workstations.
4. Manage policies through version-controlled infrastructure as code with approval and automated validation.
Correct Answer: 4
Explanation:
Version-controlled infrastructure as code provides traceability, peer review, rollback, and automated policy validation. This makes it harder for unauthorized or accidental changes to reach production unnoticed. Direct unreviewed edits and local-only policy files weaken governance and create configuration drift. Sensitive orchestration policies should also use protected repositories, separate deployment identities, audit logging, and alerts for out-of-band changes.
Question 263.
Which security capability is most useful for identifying risky access paths created by nested roles and inherited cloud permissions?
- Data deduplication
2. RAID monitoring
3. Identity permission graphing and entitlement analysis
4. Static routing
Correct Answer: 3
Explanation:
Permission graphing can reveal indirect privilege relationships that are not obvious when reviewing policies individually. Nested roles, group membership, delegated permissions, trust relationships, and inherited access may create unexpected paths to sensitive resources. Entitlement analysis helps identify excessive or unnecessary access and supports least-privilege remediation. RAID, routing, and deduplication do not provide this type of identity visibility.
Question 264.
Which control most directly reduces the risk of sensitive application data being exposed through overly verbose error messages?
- Disable TLS.
2. Use generic user-facing errors while securely logging detailed diagnostic information.
3. Return full stack traces to all clients.
4. Include database credentials in error output for troubleshooting.
Correct Answer: 2
Explanation:
Applications should avoid exposing stack traces, internal paths, queries, credentials, or architecture details to users. Generic external messages reduce information disclosure, while detailed diagnostics can still be recorded in protected logs for authorized troubleshooting. Full stack traces may reveal implementation details useful to attackers. Secure error handling should be combined with centralized logging, input validation, and monitoring.
Question 265.
A company wants to reduce the impact of stolen credentials used against externally accessible applications. Which control is most effective?
- Phishing-resistant MFA combined with risk-based access policies
2. Longer password expiration periods alone
3. Trusting known usernames automatically
4. Disabling failed-login monitoring
Correct Answer: 1
Explanation:
Phishing-resistant MFA makes stolen passwords far less useful because the attacker still needs possession of a cryptographic authenticator bound to the legitimate service. Risk-based policies can also evaluate device posture, location, session behavior, and application sensitivity. Password lifetime alone does not solve credential theft. Monitoring should remain enabled so suspicious authentication attempts and account-takeover activity can be detected.
Question 266.
Which architecture best protects production signing keys from compromise of the build environment?
- Store signing keys directly on CI/CD runners.
2. Embed the key in build scripts.
3. Share the key with all developers.
4. Keep the key in an HSM and allow only controlled signing requests from approved pipelines.
Correct Answer: 4
Explanation:
Keeping private signing keys inside an HSM isolates them from general-purpose build systems and reduces the chance of extraction if a runner is compromised. Approved pipelines can request signing operations without receiving the private key itself. Embedded or shared keys create major supply-chain risk. Signing systems should also enforce strong authorization, provenance checks, separation of duties, and detailed audit logging.
Question 267.
Which security practice is most effective for identifying whether a cloud service account is using permissions it does not normally need?
- Network address translation
2. File compression
3. Behavioral analytics combined with entitlement usage analysis
4. Disk defragmentation
Correct Answer: 3
Explanation:
Behavioral analytics can identify unusual service-account actions, while entitlement usage analysis compares actual behavior with assigned permissions. This combination helps reveal dormant privileges, unexpected API usage, or possible credential compromise. Service accounts often perform predictable tasks, so deviations can be especially meaningful. NAT and storage utilities do not provide identity behavior visibility.
Question 268.
Which statement best describes the purpose of envelope encryption?
- It encrypts all traffic using one permanent key.
2. It encrypts data with a data-encryption key and then protects that key with a separate key-encryption key.
3. It eliminates the need for key rotation.
4. It replaces access control.
Correct Answer: 2
Explanation:
Envelope encryption uses a data-encryption key to protect the actual data and a separate key-encryption key to protect the data key. This makes large-scale key management more practical because data does not need to be re-encrypted whenever the higher-level key changes. It also works well with centralized KMS or HSM services. Envelope encryption does not remove the need for authorization, rotation, or secure key lifecycle management.
Question 269.
A security team sees a sudden spike in outbound HTTPS traffic from a database server that normally has no internet access. What should be investigated first?
- The destination, initiating process, user context, and volume of transferred data
2. Printer configuration
3. Screen resolution
4. Backup label formatting
Correct Answer: 1
Explanation:
Unexpected outbound traffic from a database server may indicate command-and-control communication or data exfiltration. Analysts should identify the process generating the traffic, destination reputation, account context, transferred volume, and any recent configuration changes. The activity should be correlated with endpoint, firewall, and identity telemetry. Routine peripheral settings provide little value for this investigation.
Question 270.
Which control provides the strongest protection against unauthorized deletion of security logs during an incident?
- Keep logs only on the compromised host.
2. Allow administrators to delete logs freely.
3. Disable centralized logging.
4. Forward logs to a separate immutable or write-protected logging system.
Correct Answer: 4
Explanation:
A separate immutable logging platform reduces the chance that attackers with local or administrative access can erase evidence. Forwarding logs quickly also preserves records even if the original system is later destroyed or encrypted. Local-only storage is vulnerable after compromise. Logging infrastructure should use restricted administrative access, integrity protections, retention policies, and alerts for unexpected collection gaps.
Question 271.
Which control best reduces the risk of a vulnerable public-facing application being used as a pivot into internal management systems?
- Place all systems on one flat subnet.
2. Give the application domain administrator privileges.
3. Segment the application and restrict its access to only required internal services.
4. Disable east-west monitoring.
Correct Answer: 3
Explanation:
Segmentation limits what a compromised application can reach after exploitation. Explicit allow rules should permit only required application dependencies rather than broad access to management, identity, or administrative systems. Excessive privileges and flat networks increase lateral-movement opportunities. Network segmentation should be reinforced with least-privilege service identities and application-level authorization.
Question 272.
Which statement best describes the purpose of threat modeling during system design?
- It guarantees the application will have no vulnerabilities.
2. It identifies assets, trust boundaries, attack paths, and mitigations before implementation is complete.
3. It replaces all security testing.
4. It is performed only after a confirmed breach.
Correct Answer: 2
Explanation:
Threat modeling helps teams reason about how a system may be attacked before design decisions become difficult to change. It identifies valuable assets, trust boundaries, entry points, abuse cases, and possible mitigations. This can influence architecture, authentication, segmentation, logging, and data protection choices. Threat modeling complements code review, penetration testing, and runtime monitoring rather than replacing them.
Question 273.
Which action is most appropriate after discovering that a private API credential was committed to a public repository?
- Revoke and replace the credential immediately, then investigate repository history and usage logs.
2. Delete only the most recent commit and continue using the credential.
3. Wait until the credential expires naturally.
4. Increase its permissions to simplify incident response.
Correct Answer: 1
Explanation:
A credential exposed in a public repository should be considered compromised because it may already have been copied or indexed. Removing it from the current version does not eliminate historical copies. The credential should be revoked or rotated, usage logs reviewed, and repository history assessed for other secrets. Secret scanning and pre-commit controls can help prevent recurrence.
Question 274.
Which architecture best protects recovery data against destructive malware operating with production administrator privileges?
- Keep all backup copies directly writable from production.
2. Reuse production administrator credentials for recovery.
3. Allow production systems to delete backup retention policies.
4. Use immutable or offline recovery copies with separate administrative identities.
Correct Answer: 4
Explanation:
Immutable or offline recovery copies reduce the chance that attackers can destroy backups even after obtaining production administrator access. Separate recovery identities prevent compromise of the production control plane from automatically extending into backup administration. Recovery copies should also be tested regularly to verify integrity and restoration procedures. Shared credentials and writable backups create a single security failure domain.
Question 275.
Which control most directly protects sensitive data from exposure when developers need realistic information for software testing?
- Copy unrestricted production data into every test environment.
2. Disable nonproduction access controls.
3. Use masked or synthetic data that preserves required test characteristics.
4. Provide all developers direct production database access.
Correct Answer: 3
Explanation:
Masked or synthetic data can preserve realistic structure and behavior without exposing unnecessary customer or regulated information. This reduces privacy risk in test environments, which often have weaker controls than production. Real production data should be used only when justified and appropriately protected. Nonproduction systems should still enforce access control, encryption, monitoring, and retention policies.
Question 276.
Which statement best describes the purpose of detection engineering?
- It only installs antivirus products.
2. It systematically designs, tests, tunes, and maintains detections for relevant attacker behavior.
3. It eliminates the need for threat intelligence.
4. It guarantees zero false positives.
Correct Answer: 2
Explanation:
Detection engineering translates threat knowledge into measurable analytics, rules, queries, and alerts that identify suspicious behavior. Effective detections are tested against realistic scenarios, tuned to reduce noise, mapped to required telemetry, and maintained as environments and threats change. No detection is guaranteed to have zero false positives. Threat intelligence, incident lessons, and purple-team testing can all improve detection quality.
Question 277.
Which security practice best reduces the risk of unauthorized SaaS applications gaining access to enterprise data?
- Restrict application consent, review requested scopes, and monitor third-party application access.
2. Permit all users to approve any application.
3. Disable consent auditing.
4. Grant every third-party application tenant-wide access.
Correct Answer: 1
Explanation:
Restricting consent prevents users from granting excessive permissions to unverified applications. High-risk scopes should require review, and existing third-party applications should be periodically reassessed. Monitoring OAuth grants and application behavior can reveal malicious or compromised integrations. Unrestricted consent can allow attackers to obtain durable access without stealing passwords directly.
Question 278.
Which activity most strongly suggests a malicious attempt to establish persistence after cloud account compromise?
- A normal scheduled report executes.
2. A user views a routine dashboard.
3. A standard health check succeeds.
4. A suspicious session creates a new service principal and long-lived access credential.
Correct Answer: 4
Explanation:
Creating a new service principal or long-lived credential can allow an attacker to retain access after the original user password or session is revoked. Such activity immediately following suspicious authentication is a strong persistence indicator. Responders should revoke unauthorized credentials, investigate role assignments, preserve logs, and determine whether other persistence mechanisms were created.
Question 279.
Which architecture best protects sensitive partner-facing APIs?
- Use one global administrator token for all partners.
2. Trust partner IP addresses without authentication.
3. Use separate partner identities, scoped authorization, mTLS where appropriate, and API gateway enforcement.
4. Disable rate limiting for authenticated partners.
Correct Answer: 3
Explanation:
Separate partner identities provide accountability and allow permissions to be scoped to each business relationship. API gateways can enforce authentication, authorization, schema validation, quotas, and monitoring, while mTLS can add strong client authentication where appropriate. Shared tokens and IP-only trust create broad exposure. Partner APIs should also use credential rotation and detailed access logging.
Question 280.
Which approach best supports effective enterprise security governance as business and technology environments change?
- Treat approved controls as permanent and never reassess them.
2. Continuously review risks, control effectiveness, exceptions, ownership, and compliance obligations.
3. Revisit security only after major incidents.
4. Avoid measuring whether controls remain effective.
Correct Answer: 2
Explanation:
Security governance must evolve alongside business processes, technologies, regulatory obligations, and threats. Regular risk reviews, control testing, exception management, ownership validation, and compliance assessments help ensure safeguards remain appropriate. Controls that were effective at deployment may degrade because of configuration drift, organizational changes, or new attack methods. Continuous governance supports timely remediation and informed risk decisions.