CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part15 Q281-300

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 281.

A security architect wants to reduce the risk that a compromised cloud administrator account can modify sensitive network controls without oversight. Which control is most appropriate?

  1. Require just-in-time privilege elevation with independent approval for high-impact network changes
    2. Give all administrators permanent network administrator privileges
    3. Use one shared cloud administrator account
    4. Disable audit logging for infrastructure changes

Correct Answer: 1

Explanation:

Just-in-time privilege limits how long elevated access exists, while independent approval adds separation of duties for sensitive network modifications. This reduces the chance that one compromised account can silently change security controls. Shared accounts and permanent administrative access increase blast radius and weaken accountability. High-impact changes should also be centrally logged, monitored, and ideally deployed through controlled infrastructure-as-code pipelines with rollback capability.

Question 282.

Which control best ensures that a workload can access only the specific cloud API permissions it requires?

  1. Grant the workload a global administrator role.
    2. Use one shared role for every application.
    3. Disable workload authentication.
    4. Assign a dedicated workload identity with narrowly scoped permissions.

Correct Answer: 4

Explanation:

A dedicated workload identity with narrowly scoped permissions supports least privilege and limits the blast radius if the workload is compromised. Shared broad roles make it difficult to distinguish legitimate activity and can expose unrelated resources. Disabling authentication creates even greater risk. Machine identities should also use short-lived credentials where possible and have their permissions reviewed periodically.

Question 283.

Which security capability is most useful for detecting risky cloud configuration changes that occur outside approved deployment workflows?

  1. RAID monitoring
    2. File compression
    3. Configuration drift detection
    4. Static routing

Correct Answer: 3

Explanation:

Configuration drift detection compares the actual deployed environment against an approved baseline or infrastructure-as-code definition. Unexpected differences may indicate unauthorized console changes, compromised credentials, or configuration errors. RAID, compression, and routing do not provide governance over configuration state. Drift alerts should be investigated and reconciled so the approved code remains the authoritative source of infrastructure configuration.

Question 284.

Which approach best protects an enterprise API from authorization bypass when multiple user roles access the same endpoint?

  1. Trust all authenticated users equally.
    2. Enforce server-side authorization for every requested resource and operation.
    3. Rely only on client-side interface restrictions.
    4. Disable authorization checks for internal users.

Correct Answer: 2

Explanation:

Authentication establishes identity, but authorization must still be enforced on the server for every sensitive action and resource. Client-side restrictions can be bypassed, and internal users should not be automatically trusted. Fine-grained authorization should consider role, resource ownership, requested action, and other policy attributes. Strong API design also uses scoped tokens, input validation, logging, and consistent access-control testing.

Question 285.

A security team suspects attackers are using valid service-account credentials for reconnaissance. Which telemetry provides the strongest evidence?

  1. Cloud API audit logs correlated with normal service-account behavior
    2. Printer activity records
    3. Monitor resolution settings
    4. Disk fragmentation statistics

Correct Answer: 1

Explanation:

Cloud API audit logs can show enumeration of resources, privilege queries, unusual role assumptions, and other reconnaissance activity. Because service accounts often behave predictably, comparing current behavior with a normal baseline can reveal suspicious deviations. Printer and display information provide no relevant context. Analysts should also review source systems, authentication methods, session timing, and follow-on privilege changes.

Question 286.

Which architecture best protects sensitive application secrets from compromise of the host operating system?

  1. Store secrets in plaintext local files.
    2. Embed secrets in application source code.
    3. Place credentials in shell history.
    4. Use hardware-backed or isolated secrets services with tightly controlled retrieval.

Correct Answer: 4

Explanation:

Hardware-backed or isolated secret-management services reduce exposure of sensitive credentials to the general-purpose host. Applications can retrieve secrets dynamically under tightly scoped identity policies rather than storing them in source code or files. Plaintext local storage and shell history are easily exposed after host compromise. Strong secret management also includes rotation, auditing, expiration, and separation between application and administrative identities.

Question 287.

Which security practice best reduces the chance that a malicious dependency is introduced during software development?

  1. Allow any package from any public repository.
    2. Disable dependency version tracking.
    3. Use approved repositories, dependency scanning, integrity verification, and version pinning.
    4. Remove all build-system logging.

Correct Answer: 3

Explanation:

Approved repositories and version pinning reduce reliance on unknown packages, while dependency scanning identifies known vulnerable or risky components. Integrity verification helps ensure packages have not been modified unexpectedly. Disabling version tracking or allowing unrestricted repositories increases software-supply-chain risk. SBOM generation and controlled package publishing provide additional visibility and governance.

Question 288.

Which statement best describes the purpose of continuous authentication?

  1. It means authenticating only once when an account is created.
    2. It reevaluates trust during a session using changing risk and contextual signals.
    3. It eliminates the need for authorization.
    4. It permanently trusts a device after initial enrollment.

Correct Answer: 2

Explanation:

Continuous authentication or continuous access evaluation reassesses session trust based on factors such as device posture, location, behavior, identity risk, and security events. If risk increases, access can be restricted, revoked, or subjected to additional verification. This supports zero-trust principles by avoiding permanent trust after initial login. Authorization remains necessary because authenticated users still need appropriate permissions.

Question 289.

A security operations team detects an unusual spike in DNS queries containing long encoded subdomains. Which threat should be investigated first?

  1. DNS tunneling or data exfiltration
    2. ARP spoofing
    3. Disk corruption
    4. Printer malfunction

Correct Answer: 1

Explanation:

Long, high-entropy, or encoded subdomains generated at unusual volume can indicate DNS tunneling, where attackers encode data or command-and-control traffic into DNS queries. Analysts should correlate DNS logs with endpoint processes, destination domains, data volume, and host behavior. Not every unusual DNS pattern is malicious, so contextual validation is important. ARP spoofing and hardware issues do not best match the observed behavior.

Question 290.

Which control provides the strongest assurance that production firmware has not been replaced with an unauthorized version?

  1. DNSSEC
    2. Data masking
    3. File compression
    4. Secure boot with signed firmware verification

Correct Answer: 4

Explanation:

Secure boot verifies cryptographic signatures on firmware and boot components before allowing them to execute. This helps prevent unauthorized or tampered firmware from becoming part of the trusted boot chain. DNSSEC, data masking, and compression address different security goals. Measured boot and remote attestation can provide additional evidence about the state of the system after startup.

Question 291.

Which control best reduces the risk that a compromised endpoint can use valid user credentials to access a high-value SaaS application?

  1. Allow access from any device after password authentication.
    2. Trust all internal IP addresses.
    3. Require compliant device posture and phishing-resistant MFA.
    4. Disable session monitoring.

Correct Answer: 3

Explanation:

Requiring a compliant device and phishing-resistant MFA adds assurance beyond the password itself. A stolen password may still be insufficient if the attacker lacks an approved device and cryptographic authenticator. Internal IP addresses alone do not establish trust. Sensitive SaaS applications may also use risk-based session controls, step-up authentication, and continuous evaluation to reduce account-takeover risk.

Question 292.

Which statement best describes a security exception process?

  1. It permanently bypasses security policy without review.
    2. It documents a justified deviation, associated risk, compensating controls, approval, and expiration or review date.
    3. It eliminates the need for governance.
    4. It should never identify an owner.

Correct Answer: 2

Explanation:

A security exception process allows a documented and time-bounded deviation when a standard control cannot be met. It should identify the business justification, risk owner, compensating safeguards, approval authority, and review or expiration date. Exceptions should not become permanent unmanaged gaps. Periodic reassessment ensures the organization either restores compliance or consciously accepts residual risk.

Question 293.

Which response is most appropriate after discovering that a production database credential was exposed in a CI/CD log?

  1. Revoke or rotate the credential, restrict the log, and investigate any use of the exposed secret.
    2. Leave the credential unchanged because the log is internal.
    3. Delete all incident records.
    4. Increase the credential’s privileges for easier troubleshooting.

Correct Answer: 1

Explanation:

An exposed production credential should be treated as compromised even if disclosure occurred in an internal system. The secret should be rotated promptly, access to the log restricted, and audit records reviewed for suspicious use. The pipeline should also be corrected so secrets are masked or never written to logs. Internal environments can still be accessed by compromised users, systems, or third parties.

Question 294.

Which architecture best protects high-value recovery data from attackers who compromise normal production administration?

  1. Use the same identities for backup and production administration.
    2. Keep all backup repositories continuously writable.
    3. Give production administrators unrestricted deletion rights.
    4. Use isolated backup administration, separate identities, and immutable recovery copies.

Correct Answer: 4

Explanation:

Separate administrative identities and isolated backup infrastructure reduce the chance that attackers can use compromised production privileges to destroy recovery capabilities. Immutable copies further protect data from modification or deletion during the retention period. Using the same identities creates a common failure domain. Backup security should be validated through routine restoration exercises and monitoring for suspicious deletion or policy changes.

Question 295.

Which technique best helps an organization identify exploitable privilege-escalation paths across enterprise identity systems?

  1. Network load balancing
    2. Data deduplication
    3. Identity attack-path analysis
    4. Disk compression

Correct Answer: 3

Explanation:

Identity attack-path analysis examines relationships among users, groups, service accounts, roles, trusts, permissions, and resources to reveal indirect privilege-escalation opportunities. Attackers often exploit combinations of seemingly minor permissions to reach high-value identities or systems. Graph-based analysis can make these paths visible and help security teams prioritize remediation. Storage and network-performance technologies do not provide this identity insight.

Question 296.

Which statement best describes the purpose of purple teaming?

  1. It replaces all defensive operations.
    2. It brings offensive and defensive teams together to test and improve detections and controls.
    3. It guarantees that all attacks will be prevented.
    4. It is only a compliance documentation exercise.

Correct Answer: 2

Explanation:

Purple teaming combines attacker-style testing with defensive observation and improvement. Offensive participants emulate realistic techniques while defenders verify whether controls detect, prevent, and respond effectively. The exercise produces actionable improvements to telemetry, rules, procedures, and architecture. Purple teaming complements red teaming, threat hunting, and vulnerability management rather than replacing them.

Question 297.

Which practice best reduces the risk of secret sprawl across an enterprise?

  1. Centralize secret management, inventory credentials, rotate them, and eliminate unnecessary static secrets.
    2. Allow every team to store passwords wherever convenient.
    3. Reuse one password across applications.
    4. Disable secret-access auditing.

Correct Answer: 1

Explanation:

Secret sprawl occurs when credentials are copied across source code, scripts, documents, configuration files, and user systems. Centralized secret management improves visibility, rotation, access control, and auditing. Inventorying existing secrets helps identify unnecessary or abandoned credentials. Reusing secrets increases blast radius, while decentralized storage makes exposure and remediation much harder.

Question 298.

Which activity most strongly indicates possible malicious modification of cloud security controls?

  1. A scheduled report executes normally.
    2. A user reads a dashboard.
    3. A standard application health check succeeds.
    4. A privileged account unexpectedly disables multiple security policies after an anomalous login.

Correct Answer: 4

Explanation:

Unexpected disabling of multiple security controls following anomalous privileged authentication is a strong sign of potential compromise. Attackers often weaken defenses before establishing persistence, escalating privilege, or accessing data. Responders should validate the session, preserve evidence, restore protections, revoke suspicious access where appropriate, and examine other changes made during the same period.

Question 299.

Which security design best reduces the risk that one compromised third-party integration can access unrelated enterprise data?

  1. Give every integration tenant-wide administrator privileges.
    2. Use one shared integration account.
    3. Assign each integration its own identity with narrowly scoped permissions and monitored access.
    4. Disable consent and access logging.

Correct Answer: 3

Explanation:

Separate integration identities and narrowly scoped permissions reduce the blast radius of compromise and provide clearer accountability. Each integration should access only the data and APIs required for its business purpose. Broad shared access can expose unrelated information. Third-party applications should also undergo periodic permission reviews, vendor risk assessment, credential rotation, and monitoring for abnormal behavior.

Question 300.

Which approach best supports resilient security architecture in an environment that changes frequently?

  1. Freeze all security designs permanently after approval.
    2. Continuously reassess architecture, validate controls, monitor drift, exercise recovery, and update protections as risks evolve.
    3. Review architecture only after successful attacks.
    4. Disable telemetry to reduce complexity.

Correct Answer: 2

Explanation:

Fast-changing environments create new identities, workloads, dependencies, and attack paths. Continuous architecture review, control validation, configuration monitoring, recovery testing, and threat reassessment help security teams identify gaps before attackers exploit them. Security design should therefore evolve alongside technology and business change rather than remaining fixed after initial deployment.