CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part16 Q301-320

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 301.

A security architect wants to reduce the risk that a compromised SaaS application can access more enterprise data than necessary. Which control is most appropriate?

  1. Grant the application only narrowly scoped permissions and review them periodically
    2. Give the application tenant-wide administrator access
    3. Use one shared integration account for all SaaS applications
    4. Disable third-party application auditing

Correct Answer: 1

Explanation:

Narrowly scoped permissions limit a SaaS application’s access to only the data and actions required for its business purpose. This reduces the blast radius if the application or its credentials are compromised. Periodic reviews help identify permissions that are no longer needed. Shared accounts and broad administrator roles weaken accountability and unnecessarily expand access. Third-party applications should also be monitored, validated, and removed when no longer required.

Question 302.

Which architecture best protects a critical internal application from direct exposure to the public internet while still allowing remote users to access it?

  1. Publish the application directly with unrestricted inbound rules
    2. Disable authentication for remote users
    3. Expose the backend server’s private management interface
    4. Use a zero-trust application access broker or secure reverse proxy with identity-aware access controls

Correct Answer: 4

Explanation:

A zero-trust access broker or secure reverse proxy can authenticate and authorize users before establishing access to a private application. This avoids exposing the application’s backend directly to the internet. Access decisions can consider user identity, device posture, risk, and application sensitivity. Direct exposure and disabled authentication greatly increase risk. This model also helps reduce broad network access by granting access to specific applications rather than entire subnets.

Question 303.

Which security capability is most useful for identifying whether an attacker has obtained access to a cloud environment through an unexpected trust relationship?

  1. RAID monitoring
    2. File compression
    3. Identity trust-path and entitlement analysis
    4. DNS caching

Correct Answer: 3

Explanation:

Identity trust-path analysis can reveal indirect access routes created by federated relationships, delegated roles, nested groups, service principals, and inherited permissions. Attackers may exploit these relationships to move from a low-privilege identity to a more powerful role. Graphing and entitlement analysis help security teams identify hidden privilege paths and reduce excessive or unintended trust.

Question 304.

Which control best reduces the risk of an attacker abusing a stolen refresh token?

  1. Increase refresh-token lifetime
    2. Use token rotation, revocation, device or session binding, and anomaly detection
    3. Store refresh tokens in application logs
    4. Disable token-expiration checks

Correct Answer: 2

Explanation:

Refresh tokens can provide durable access if stolen, so they should be rotated, revocable, and protected against replay. Device or session binding can make reuse from an unauthorized environment more difficult, while anomaly detection can identify suspicious token activity. Increasing token lifetime or disabling expiration increases risk. Sensitive applications should also monitor unusual locations, devices, and token refresh patterns.

Question 305.

A security team wants to reduce the risk that a compromised build server can sign malicious software releases. Which control is strongest?

  1. Keep signing keys in an HSM and require approved pipeline identity plus release authorization before signing
    2. Store signing keys directly on build servers
    3. Share signing keys with all developers
    4. Disable release audit logs

Correct Answer: 1

Explanation:

An HSM can prevent direct extraction of the signing key even if the build server is compromised. Requiring approved pipeline identity and release authorization adds additional safeguards before a signing operation occurs. Storing keys on build servers or distributing them broadly creates severe supply-chain risk. Release systems should also maintain immutable logs, verify provenance, and separate build privileges from signing authority.

Question 306.

Which architecture best protects highly sensitive workloads from unauthorized communication with other tenants in a shared cloud environment?

  1. Use a flat shared network
    2. Disable workload authentication
    3. Use one security group for every workload
    4. Enforce tenant isolation, segmentation, and workload-specific network policies

Correct Answer: 4

Explanation:

Tenant isolation and workload-specific network policies reduce the possibility that one compromised workload can reach unrelated services or tenants. Flat networking and broad shared policies increase lateral-movement opportunities. Strong isolation should include explicit network rules, separate identities, least-privilege permissions, and monitoring of east-west traffic. In higher-assurance environments, organizations may also use dedicated hosts or confidential computing where appropriate.

Question 307.

Which security practice best detects unexpected changes to cloud IAM policies?

  1. Disable IAM logging
    2. Store IAM configuration only in local administrator notes
    3. Continuously monitor control-plane logs and compare permissions against approved baselines
    4. Use shared administrator accounts

Correct Answer: 3

Explanation:

Cloud control-plane logs record IAM policy changes, role assignments, trust modifications, and other administrative activity. Comparing those events with approved baselines can reveal unexpected or unauthorized changes. Shared accounts make attribution difficult, and disabling logs removes visibility. IAM monitoring should generate alerts for high-risk changes such as creation of new administrators, trust expansion, or logging disablement.

Question 308.

Which statement best describes the purpose of a compensating control in risk management?

  1. It permanently removes the underlying vulnerability.
    2. It provides alternative risk reduction when the preferred control cannot be implemented.
    3. It eliminates the need to document residual risk.
    4. It applies only to compliance audits.

Correct Answer: 2

Explanation:

A compensating control provides alternative protection when the preferred control is temporarily or technically infeasible. Examples include stronger segmentation and monitoring around an unpatchable system. The underlying weakness may still remain, so residual risk should be documented and reviewed. Compensating controls should be assessed for effectiveness and replaced by the preferred control when feasible.

Question 309.

A security analyst sees a sudden sequence of failed administrative actions followed by a successful privilege escalation from the same account. Which response is most appropriate?

  1. Investigate the session, validate the identity, contain suspicious access, and preserve relevant logs
    2. Ignore the event because the final request succeeded
    3. Disable all security monitoring
    4. Delete authentication logs

Correct Answer: 1

Explanation:

A sequence of failed privilege attempts followed by successful escalation can indicate credential abuse or exploitation. The session should be validated immediately, and suspicious access may need to be revoked or contained. Relevant logs should be preserved to determine what resources were affected. Ignoring the activity because one action succeeded would overlook a potentially serious privilege-escalation event.

Question 310.

Which control provides the strongest protection for an enterprise root certificate authority?

  1. Keep it online for convenience
    2. Store the private key on a standard file server
    3. Allow all PKI administrators unrestricted access
    4. Keep the root CA offline with HSM-protected keys and tightly controlled ceremonies

Correct Answer: 4

Explanation:

An offline root CA significantly reduces exposure to network attacks, while HSM protection makes extraction of the private key much more difficult. Controlled key ceremonies and separation of duties improve governance around high-risk operations. Keeping the root continuously online increases attack surface. Root CA compromise can undermine the entire PKI, so it requires stronger protection than ordinary certificate services.

Question 311.

Which security capability best identifies suspicious behavior involving unexpected access to cloud secrets?

  1. RAID health monitoring
    2. Static routing
    3. Secret-access analytics correlated with workload and identity behavior
    4. Data compression

Correct Answer: 3

Explanation:

Secret-access logs can reveal which identities requested which credentials, while behavioral context helps identify abnormal patterns such as bulk retrieval, access from a new workload, or unusual timing. Because machine identities often behave predictably, deviations can indicate compromise. Storage and routing technologies do not provide this security visibility. Secrets platforms should generate high-quality audit records and alerts for suspicious access.

Question 312.

Which statement best describes the purpose of an RTO?

  1. It defines acceptable data loss measured in time.
    2. It defines the maximum acceptable time a service can remain unavailable after disruption.
    3. It defines the number of encryption keys required.
    4. It determines log retention duration.

Correct Answer: 2

Explanation:

The recovery time objective defines how quickly a service or business process must be restored after an outage or disaster. It influences architecture, redundancy, staffing, failover design, and recovery procedures. The recovery point objective instead concerns acceptable data loss measured in time. Both values should be based on business impact and validated through actual recovery exercises.

Question 313.

Which security practice best reduces the risk that abandoned cloud resources remain exposed after a project ends?

  1. Use formal decommissioning that removes identities, network rules, storage, secrets, DNS records, and integrations
    2. Stop only the primary virtual machine
    3. Leave access keys active in case they are needed later
    4. Ignore old public storage buckets

Correct Answer: 1

Explanation:

Cloud applications often leave behind more than compute instances. Credentials, DNS entries, storage, firewall rules, APIs, service accounts, and third-party integrations can remain active after a project ends. Formal decommissioning reduces this residual attack surface. Resources that must be retained should have an identified owner and documented retention requirement rather than being left unmanaged.

Question 314.

Which architecture best reduces the impact of ransomware that has compromised both endpoints and domain administrator credentials?

  1. Keep backups joined to the same administrative domain
    2. Use the same passwords for backup and production systems
    3. Allow domain administrators to delete all backups
    4. Use isolated backup administration, separate identities, and immutable recovery copies

Correct Answer: 4

Explanation:

If ransomware compromises domain administrators, backups managed through the same identity infrastructure may also be destroyed. Separate recovery identities and isolated administration reduce this common dependency. Immutable recovery copies further prevent deletion or modification. Organizations should also test restoration regularly to ensure that backup isolation does not prevent recovery when production identity services are unavailable.

Question 315.

Which control most directly reduces the impact of a compromised API credential used by an external partner?

  1. Give every partner one shared administrator key
    2. Disable API access logging
    3. Use unique partner identities with scoped permissions, quotas, and credential rotation
    4. Trust partner IP addresses without authentication

Correct Answer: 3

Explanation:

Unique partner identities support accountability and allow permissions to be tailored to each relationship. Scoped access limits what a stolen credential can do, while quotas can restrict automated abuse. Credential rotation reduces long-term exposure. Shared administrator keys and IP-only trust create excessive risk. Partner API activity should also be monitored for anomalies and unusual access patterns.

Question 316.

Which statement best describes the purpose of a security control owner?

  1. To guarantee that the control can never fail
    2. To remain accountable for maintaining, reviewing, and addressing issues with the assigned control
    3. To eliminate the need for testing
    4. To approve every business transaction

Correct Answer: 2

Explanation:

A security control owner is accountable for ensuring that an assigned control remains implemented, maintained, and appropriately reviewed. Ownership helps avoid situations where security gaps persist because no team is responsible for remediation. Control owners may coordinate testing, evidence collection, exceptions, updates, and corrective actions. Ownership does not guarantee perfect effectiveness, so controls still require measurement and validation.

Question 317.

Which practice best reduces the risk of sensitive data being exposed through nonproduction AI experimentation?

  1. Use synthetic or masked data and restrict model access to approved environments
    2. Copy full regulated production data into public AI services
    3. Disable AI access logging
    4. Give experimentation environments unrestricted access to production repositories

Correct Answer: 1

Explanation:

Synthetic or masked data allows teams to test AI workflows without unnecessarily exposing regulated or confidential information. Approved environments can enforce access controls, logging, retention requirements, and restrictions on external model use. Experimentation should follow data-minimization principles just like production. Sending raw sensitive data to unapproved services can create privacy, contractual, and security risks.

Question 318.

Which behavior most strongly indicates a possible attempt to weaken identity security controls?

  1. A routine report executes
    2. A user logs into a normal application
    3. A scheduled backup completes
    4. A privileged account disables MFA requirements and adds a new authentication method after an unusual login

Correct Answer: 4

Explanation:

Disabling MFA requirements and adding a new authentication method can allow an attacker to maintain access and bypass normal protections. When these actions occur after suspicious authentication, they should be treated as high-priority indicators. Responders should validate the account, restore secure authentication policy, revoke suspicious sessions, and review other identity changes made during the same period.

Question 319.

Which security design best reduces the risk of unauthorized lateral movement between serverless functions and backend services?

  1. Use one shared administrator identity for all functions
    2. Allow all functions unrestricted network access
    3. Use separate workload identities, least-privilege permissions, and explicit service-to-service policies
    4. Disable logging for function activity

Correct Answer: 3

Explanation:

Separate workload identities and explicit service-to-service policies restrict each function to the backend services and operations it actually requires. This reduces lateral movement if one function or dependency is compromised. Shared administrator identities and unrestricted connectivity create excessive blast radius. Serverless environments should also use secure secret management, logging, dependency scanning, and short-lived credentials.

Question 320.

Which approach best supports resilient security operations when enterprise environments and attacker techniques change frequently?

  1. Freeze detection logic permanently after deployment
    2. Continuously test detections, review telemetry coverage, exercise response, and update controls based on observed gaps
    3. Evaluate security only during annual audits
    4. Disable noisy telemetry rather than tuning detections

Correct Answer: 2

Explanation:

Security operations must evolve as infrastructure, applications, identity systems, and attacker techniques change. Detection testing, telemetry review, incident exercises, and purple-team activity help identify blind spots and weak controls. Findings should drive tuning and remediation. Continuous validation provides stronger assurance than assuming that controls and detections remain effective indefinitely.