CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part17 Q321-340

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 321.

A security architect wants to reduce the risk that a compromised identity provider can automatically grant unrestricted access to every downstream application. Which control is most appropriate?

  1. Enforce application-level authorization and resource-specific access checks after authentication
    2. Trust every authenticated identity for all applications
    3. Disable downstream authorization checks
    4. Assign all federated users the same privileged role

Correct Answer: 1

Explanation:

Authentication by an identity provider proves who the user is, but downstream applications should still independently enforce authorization. Resource-specific access checks, least privilege, and step-up controls can limit what a compromised account can do even if the identity provider has been abused. Blindly trusting all federated identities creates excessive blast radius. Strong federation design separates authentication from authorization and uses risk-aware controls for sensitive resources.

Question 322.

Which control best protects cloud workloads from unauthorized changes to security groups or network access policies?

  1. Allow manual changes without review.
    2. Disable configuration history.
    3. Use shared administrator accounts.
    4. Manage network policy through version-controlled infrastructure as code with approval and drift detection.

Correct Answer: 4

Explanation:

Version-controlled infrastructure as code provides traceability, peer review, and rollback, while drift detection identifies changes made outside the approved process. This reduces the likelihood that unauthorized or accidental policy changes persist unnoticed. Shared accounts and unreviewed manual edits weaken accountability. High-impact network changes should also generate alerts and be tied to individual privileged identities.

Question 323.

Which security capability is most useful for identifying whether a low-privilege cloud identity can indirectly reach an administrative role through trust relationships?

  1. Disk encryption
    2. RAID monitoring
    3. Identity attack-path and permission graph analysis
    4. DNS caching

Correct Answer: 3

Explanation:

Identity attack-path analysis maps users, groups, roles, service principals, trust relationships, and permissions to reveal indirect routes to privilege. A low-privilege identity may appear harmless in isolation but gain administrative access through nested or delegated relationships. Graph analysis makes these paths easier to identify and prioritize for remediation. Storage and DNS technologies do not provide this identity context.

Question 324.

Which control most directly reduces the impact of stolen OAuth access tokens?

  1. Make tokens valid indefinitely.
    2. Use short lifetimes, scoped permissions, revocation, and contextual validation.
    3. Store tokens in application logs.
    4. Disable expiration checks.

Correct Answer: 2

Explanation:

Short-lived tokens reduce the time an attacker can use stolen credentials, while scoped permissions limit what the token can access. Revocation and contextual validation further reduce replay risk. Long-lived tokens and disabled expiration increase exposure. Sensitive systems may also require reauthentication or stronger validation for high-impact actions even when a token remains technically valid.

Question 325.

A security team wants to reduce the risk that a compromised software build system can introduce malicious code into signed releases. Which design is strongest?

  1. Separate build and signing functions, protect signing keys in an HSM, and require release approval.
    2. Keep signing keys directly on build servers.
    3. Share signing credentials with developers.
    4. Disable build provenance logging.

Correct Answer: 1

Explanation:

Separating build and signing functions prevents compromise of the build environment from automatically granting control over trusted signing keys. An HSM protects private key material, while release approval adds another independent control. Shared keys and local key storage create significant supply-chain risk. Provenance and audit logging should be retained so organizations can verify how each release was produced.

Question 326.

Which architecture best protects sensitive data processing from a malicious or compromised cloud host administrator?

  1. Store plaintext data in shared memory.
    2. Disable workload isolation.
    3. Use only network segmentation.
    4. Use confidential computing with trusted execution environments and attestation.

Correct Answer: 4

Explanation:

Confidential computing protects data while it is being processed by isolating workloads inside hardware-backed trusted execution environments. Remote attestation can provide evidence that the expected code and environment are running before sensitive data is released. Network segmentation alone does not protect against a malicious host administrator. Confidential computing complements encryption at rest and in transit.

Question 327.

Which security practice best reduces risk from overly permissive cloud roles that are rarely used?

  1. Increase their permissions to avoid future access problems.
    2. Exempt them from review.
    3. Analyze actual usage and remove unused privileges.
    4. Share the roles among teams.

Correct Answer: 3

Explanation:

Permission usage analysis helps identify privileges that are granted but never used. Removing these excess permissions reduces attack surface and supports least privilege. Dormant permissions are especially risky because attackers can abuse them even though legitimate users no longer need them. Privileged roles should be reviewed regularly and, where practical, converted to just-in-time access.

Question 328.

Which statement best describes the purpose of token binding or sender-constrained tokens?

  1. They eliminate the need for TLS.
    2. They make a token harder to replay from a different client or context.
    3. They replace authorization.
    4. They allow tokens to be shared safely across users.

Correct Answer: 2

Explanation:

Sender-constrained tokens are tied to a particular client, key, or context, making simple replay from another environment more difficult. This is stronger than ordinary bearer tokens, which may be usable by anyone who obtains them. Such controls do not eliminate the need for TLS or authorization. They are especially useful in higher-assurance API and session designs.

Question 329.

A security analyst observes a workload retrieving a large number of secrets it has never accessed before. Which action is most appropriate?

  1. Investigate the workload identity, secret-access logs, recent changes, and downstream activity.
    2. Ignore the behavior because the requests authenticated successfully.
    3. Disable all secret logging.
    4. Increase the workload’s vault permissions.

Correct Answer: 1

Explanation:

Unexpected bulk secret retrieval may indicate workload compromise, credential abuse, or a configuration error. Analysts should inspect the identity, source workload, recent deployments, secret-access patterns, and any subsequent use of retrieved credentials. Successful authentication does not automatically make the behavior legitimate. High-value secrets platforms should generate alerts for anomalous access and support rapid credential rotation.

Question 330.

Which control best protects an enterprise from unauthorized changes to DNS records used by critical services?

  1. Allow all administrators unrestricted DNS modification.
    2. Use shared DNS credentials.
    3. Disable DNS change logging.
    4. Enforce strong administrative access, change approval, audit logging, and DNSSEC where appropriate.

Correct Answer: 4

Explanation:

Critical DNS changes should be tightly controlled because attackers can redirect users and services by modifying records. Strong administrative authentication, approval workflows, and logging reduce unauthorized changes. DNSSEC can provide integrity validation for signed DNS data where supported. Shared credentials and unlogged changes weaken accountability and make tampering harder to detect.

Question 331.

Which security control best limits damage if a public-facing application is compromised through a zero-day vulnerability?

  1. Give the application broad internal access for convenience.
    2. Disable internal segmentation.
    3. Restrict the application to only required network paths and service permissions.
    4. Use shared administrator credentials.

Correct Answer: 3

Explanation:

A zero-day may bypass preventive application controls, so architecture should assume individual components can fail. Segmentation, egress controls, and least-privilege service identities limit what an attacker can reach after compromise. Broad internal access increases blast radius. Defense in depth focuses on containment as well as prevention.

Question 332.

Which statement best describes the purpose of threat-informed defense?

  1. It relies only on generic compliance checklists.
    2. It uses relevant adversary behaviors and threat intelligence to prioritize controls, detections, and testing.
    3. It eliminates the need for asset knowledge.
    4. It guarantees every attack will be prevented.

Correct Answer: 2

Explanation:

Threat-informed defense aligns security controls and detections with realistic attacker techniques that are relevant to the organization. Threat intelligence, incident history, attack frameworks, and business context can help prioritize investments and validation. Compliance remains important, but it does not always reflect the most likely or damaging attack paths. Threat-informed defense supports focused testing and measurable improvement.

Question 333.

Which practice best protects against unauthorized use of dormant API credentials?

  1. Inventory credentials, disable unused ones, rotate active secrets, and monitor their use.
    2. Keep unused credentials indefinitely.
    3. Exempt old credentials from logging.
    4. Share dormant keys among teams.

Correct Answer: 1

Explanation:

Dormant API credentials create unnecessary attack surface because they may remain valid even though no legitimate process uses them. Regular inventory and cleanup reduce this exposure. Active credentials should be rotated, narrowly scoped, and monitored. Long-lived unused keys are especially dangerous because attackers can exploit them without immediately disrupting normal operations.

Question 334.

Which architecture best protects backup recovery capability from compromise of the primary identity platform?

  1. Require the primary identity provider for all recovery authentication.
    2. Use identical credentials in both environments.
    3. Allow production administrators to delete every backup.
    4. Maintain separate recovery identities and independently accessible backup administration.

Correct Answer: 4

Explanation:

If the primary identity system is compromised or unavailable, recovery should not depend entirely on it. Separate recovery identities and independent administrative access reduce this shared dependency. Immutable or offline backups provide additional protection. Recovery access should be secured, audited, and tested so it remains available during a real crisis without creating an uncontrolled bypass.

Question 335.

Which control most directly reduces the risk of sensitive information being exposed through application logs?

  1. Log full passwords and access tokens for troubleshooting.
    2. Disable all logging.
    3. Apply log redaction and avoid recording secrets or regulated data unless strictly necessary.
    4. Allow logs to be publicly readable.

Correct Answer: 3

Explanation:

Logs are often widely accessible to operations and security teams, so they should not contain passwords, tokens, private keys, or unnecessary regulated data. Redaction and structured logging can preserve useful diagnostic information without exposing secrets. Disabling all logging removes critical visibility, while public access creates severe confidentiality risk. Sensitive logs should also have appropriate access controls and retention policies.

Question 336.

Which statement best describes the purpose of blast-radius reduction in security architecture?

  1. It means preventing every possible compromise.
    2. It limits the systems, data, and privileges an attacker can reach after one component is compromised.
    3. It eliminates the need for monitoring.
    4. It requires flat networks.

Correct Answer: 2

Explanation:

Blast-radius reduction assumes that some controls may eventually fail and focuses on limiting the consequences. Segmentation, least privilege, separate identities, scoped credentials, and isolated recovery systems all help contain compromise. This principle is central to resilient and zero-trust architecture. Preventive controls remain important, but containment ensures one breach does not automatically become an enterprise-wide incident.

Question 337.

Which practice best reduces risk from third-party API integrations that are no longer actively used?

  1. Revoke unused integrations, credentials, and permissions after confirming they are no longer required.
    2. Leave all integrations active indefinitely.
    3. Increase permissions on abandoned integrations.
    4. Disable third-party access auditing.

Correct Answer: 1

Explanation:

Unused integrations often retain credentials and access permissions long after business use has ended. Removing them reduces attack surface and prevents forgotten third parties from becoming hidden access paths. Organizations should review integration ownership, usage, scopes, and vendor status periodically. Credentials should be revoked rather than simply ignored.

Question 338.

Which activity most strongly suggests that an attacker is attempting to establish persistence in an identity environment?

  1. A normal user reads a report.
    2. A scheduled backup completes.
    3. An approved application refreshes a standard token.
    4. A suspicious privileged session adds a new authentication method and creates a long-lived application credential.

Correct Answer: 4

Explanation:

Adding new authentication methods or long-lived application credentials can allow attackers to retain access after the original password or session is revoked. When these actions follow suspicious privileged activity, they are strong persistence indicators. Responders should remove unauthorized methods, revoke sessions and credentials, preserve logs, and review other identity changes made during the same period.

Question 339.

Which security design best protects an enterprise API that processes highly sensitive transactions?

  1. Use one shared bearer token for all clients.
    2. Disable request validation for trusted users.
    3. Combine strong client authentication, scoped authorization, schema validation, rate controls, and detailed auditing.
    4. Trust all requests from internal IP addresses.

Correct Answer: 3

Explanation:

Sensitive APIs need multiple layers of protection. Strong client authentication establishes identity, scoped authorization limits permitted actions, schema validation rejects malformed requests, and rate controls reduce abuse. Detailed audit logs support investigation and accountability. Shared tokens or IP-based trust alone provide weak security boundaries and increase blast radius if a credential or system is compromised.

Question 340.

Which approach best supports continuous assurance that enterprise security controls remain effective?

  1. Assume controls work because they were deployed successfully.
    2. Continuously test controls, review telemetry, measure outcomes, and remediate gaps as environments change.
    3. Review security only after confirmed incidents.
    4. Avoid changing controls once compliance has been achieved.

Correct Answer: 2

Explanation:

Security controls can degrade because of configuration drift, software changes, new identities, evolving threats, or business growth. Continuous assurance uses testing, telemetry review, detection metrics, resilience exercises, and control validation to determine whether safeguards still produce the intended outcomes. Findings should drive remediation and architectural improvement rather than relying on assumptions from initial deployment.