View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 361.
A security architect wants to prevent a compromised application from accessing cloud resources outside its normal business function. Which control is most appropriate?
- Use a dedicated workload identity with least-privilege permissions and resource-level restrictions
2. Assign the application a global administrator role
3. Share one access key across all applications
4. Disable authorization checks for trusted workloads
Correct Answer: 1
Explanation:
A dedicated workload identity allows permissions to be restricted to only the resources and actions required by that application. If the workload is compromised, the attacker’s access remains constrained. Shared keys and broad administrator privileges increase blast radius and make accountability difficult. Resource-level authorization should be combined with short-lived credentials, secret management, monitoring, and periodic entitlement reviews so unused permissions can be removed.
Question 362.
Which architecture best protects security telemetry from attackers who gain administrator access to production systems?
- Keep all logs only on production hosts.
2. Allow local administrators to delete audit records without review.
3. Disable security log forwarding.
4. Export logs to a separate protected security account or immutable logging platform.
Correct Answer: 4
Explanation:
A separate logging security boundary makes it more difficult for attackers with production privileges to erase evidence. Immutable or write-protected storage further protects historical records from alteration. Local-only logging creates a common failure domain because the same administrator who compromises the system may also delete its logs. Security teams should also monitor for logging interruptions and unexpected retention-policy changes.
Question 363.
Which capability is most useful for identifying whether a cloud user can indirectly gain administrative rights through nested permissions?
- DNS caching
2. RAID monitoring
3. Identity attack-path analysis and permission graphing
4. Disk compression
Correct Answer: 3
Explanation:
Identity attack-path analysis maps relationships among users, groups, roles, trusts, service principals, and resources. It can reveal indirect privilege paths that are not obvious from a single access-control policy. These paths may allow a low-privilege identity to reach highly privileged resources through inheritance or delegation. Graph analysis helps security teams identify and remove unintended privilege-escalation opportunities.
Question 364.
Which control best reduces the risk of a stolen API token being used from an unauthorized environment?
- Increase the token lifetime.
2. Use short-lived, sender-constrained or context-bound tokens with revocation support.
3. Store the token in application logs.
4. Disable token validation after initial authentication.
Correct Answer: 2
Explanation:
Short-lived tokens reduce the attack window, while sender-constrained or context-bound tokens make simple replay from another client more difficult. Revocation allows defenders to invalidate compromised sessions or credentials quickly. Increasing token lifetime or disabling validation increases exposure. High-value APIs should also validate issuer, audience, scopes, expiration, and requested operations for every sensitive request.
Question 365.
A security team wants to prevent a compromised developer account from independently approving and releasing production code. Which control is strongest?
- Enforce separation of duties with independent review and release approval
2. Give developers direct production administrator access
3. Use shared deployment credentials
4. Disable release auditing
Correct Answer: 1
Explanation:
Separation of duties prevents one compromised or malicious account from controlling the entire release process. Independent review and approval add another decision point before production deployment. Shared credentials and direct production access weaken accountability and bypass important controls. Secure release processes should also use protected branches, signed artifacts, short-lived deployment identities, and tamper-resistant logs.
Question 366.
Which architecture best protects sensitive data being processed by workloads in an untrusted hosting environment?
- Use plaintext shared memory.
2. Disable workload isolation.
3. Rely only on disk encryption.
4. Use confidential computing with trusted execution environments and attestation.
Correct Answer: 4
Explanation:
Confidential computing protects data during active processing inside hardware-backed trusted execution environments. Remote attestation can verify the workload state before secrets or sensitive data are released. Disk encryption protects data at rest but does not protect plaintext while it is processed. Confidential computing complements TLS, storage encryption, workload identity, and access control in high-assurance environments.
Question 367.
Which security practice best identifies service accounts that have more privilege than they actually use?
- Disable entitlement reviews.
2. Give every service account administrator access.
3. Compare assigned permissions with actual permission usage.
4. Share service identities across applications.
Correct Answer: 3
Explanation:
Comparing assigned permissions with observed use can reveal unnecessary privileges that should be removed. Service accounts frequently accumulate access over time as applications evolve. Unused privileges increase the impact of credential compromise even though legitimate workloads do not need them. Permission usage analysis supports least privilege and should be combined with periodic access reviews and credential lifecycle management.
Question 368.
Which statement best describes the purpose of mutual TLS between services?
- It eliminates the need for authorization.
2. It encrypts traffic and allows both services to authenticate each other.
3. It guarantees that application code is secure.
4. It replaces segmentation.
Correct Answer: 2
Explanation:
Mutual TLS protects traffic in transit and requires both endpoints to present trusted certificates, providing bidirectional authentication. This is useful for service-to-service communication in zero-trust and service-mesh environments. However, mTLS does not replace authorization, segmentation, secure coding, or workload policy. Certificate issuance, rotation, revocation, and trust management are also important to maintain security.
Question 369.
A security analyst detects repeated attempts by a workload to access a cloud metadata endpoint immediately after receiving user-controlled URLs. Which attack should be investigated first?
- Server-side request forgery
2. Password spraying
3. ARP poisoning
4. Bluetooth spoofing
Correct Answer: 1
Explanation:
A workload accessing cloud metadata after processing user-controlled URLs strongly suggests server-side request forgery. An attacker may attempt to force the application to retrieve internal metadata, temporary credentials, or other protected resources. Defenses include strict URL validation, outbound filtering, metadata-service protections, and least-privilege workload roles. Password spraying and local network attacks do not best fit this scenario.
Question 370.
Which control provides the strongest protection for cryptographic keys used to sign enterprise software releases?
- Store them in developer home directories.
2. Commit them to a private code repository.
3. Keep them in pipeline environment variables indefinitely.
4. Use an HSM with controlled signing operations and strict authorization.
Correct Answer: 4
Explanation:
An HSM protects private key material from direct extraction and can restrict signing operations to approved users or automated workflows. Developer directories, repositories, and environment variables expose high-value signing keys to unnecessary risk. Strong signing systems should also use separation of duties, release approval, provenance verification, key rotation, and detailed audit logging.
Question 371.
Which architecture best limits lateral movement from a compromised application server to database and identity infrastructure?
- Place all systems on one flat subnet.
2. Give the application broad administrative access.
3. Use segmentation with explicit network and service-level allow policies.
4. Disable east-west traffic monitoring.
Correct Answer: 3
Explanation:
Segmentation limits which systems a compromised application can reach. Explicit allow policies should permit only required dependencies and deny unnecessary communication with identity, management, or unrelated database systems. Flat networks and broad privileges increase lateral-movement opportunities. Strong containment also uses workload identity, least privilege, application-level authorization, and monitoring of internal traffic.
Question 372.
Which statement best describes the purpose of an access review?
- It permanently grants users their current permissions.
2. It verifies that existing permissions remain appropriate for current business responsibilities.
3. It eliminates the need for deprovisioning.
4. It applies only to guest accounts.
Correct Answer: 2
Explanation:
Access reviews validate whether users, service accounts, groups, and applications still require their assigned permissions. Role changes and project transitions can cause privilege creep if unnecessary access is never removed. Regular reviews support least privilege and help identify dormant or excessive access. They should include privileged identities, third-party accounts, machine identities, and sensitive applications where appropriate.
Question 373.
Which action is most appropriate after discovering that a privileged service account credential has been exposed in a public artifact repository?
- Revoke or rotate the credential immediately and investigate whether it was used.
2. Delete only the visible file and continue using the credential.
3. Wait until the credential expires naturally.
4. Increase the account’s privileges for troubleshooting.
Correct Answer: 1
Explanation:
A publicly exposed credential should be treated as compromised because it may already have been copied, indexed, or cached. Rotation or revocation limits further misuse, while audit logs should be reviewed for suspicious activity. Simply deleting the artifact does not remove historical copies. The organization should also identify why the secret was exposed and implement secret scanning or managed credential retrieval to prevent recurrence.
Question 374.
Which architecture best preserves recovery capability if ransomware compromises production identities and management systems?
- Use production credentials for all backup administration.
2. Keep every recovery copy directly writable from production.
3. Join backup infrastructure to the same administrative domain.
4. Use isolated recovery administration, separate identities, and immutable or offline backups.
Correct Answer: 4
Explanation:
Isolated recovery infrastructure and separate identities reduce the chance that compromise of production administration also destroys the organization’s recovery capability. Immutable or offline copies make backup destruction significantly harder. Shared credentials and writable repositories create a single failure domain. Recovery procedures should be exercised regularly to confirm that teams can restore critical systems even when normal identity services are unavailable.
Question 375.
Which control most directly reduces the risk that sensitive production information appears in lower-security development systems?
- Copy complete production databases to developer laptops.
2. Disable nonproduction encryption.
3. Use masking, anonymization, or synthetic data when real identifiers are unnecessary.
4. Give developers unrestricted production access.
Correct Answer: 3
Explanation:
Masked, anonymized, and synthetic data reduce exposure of real customer or regulated information while preserving useful testing characteristics. Development environments often have broader access and different operational controls, making unnecessary production data risky. Data minimization should therefore be applied wherever possible. Nonproduction systems should still use strong authentication, logging, encryption, and segmentation.
Question 376.
Which statement best describes the purpose of security control testing?
- It proves that a control will never fail.
2. It determines whether a control is implemented correctly and produces the intended security outcome.
3. It removes the need for monitoring.
4. It is required only after an incident.
Correct Answer: 2
Explanation:
Control testing provides evidence that a safeguard is actually configured and operating as intended. A product being deployed does not guarantee that it prevents or detects relevant attacks. Testing can involve technical validation, simulations, audits, or review of measurable outcomes. Findings should lead to remediation, tuning, or architectural changes when controls do not meet expectations.
Question 377.
Which practice best reduces the risk from third-party applications that retain access after their business purpose ends?
- Periodically review and revoke unused OAuth grants, service accounts, API keys, and application permissions.
2. Leave all integrations active indefinitely.
3. Exempt third-party applications from monitoring.
4. Increase permissions on unused integrations.
Correct Answer: 1
Explanation:
Unused integrations can retain access long after users and administrators forget they exist. Periodic reviews should verify ownership, business justification, requested scopes, and recent activity. Credentials and grants that are no longer required should be revoked. Third-party application lifecycle management is an important part of attack-surface reduction because abandoned integrations can become hidden persistence paths.
Question 378.
Which activity most strongly suggests a malicious attempt to weaken endpoint defenses?
- A normal application launches.
2. A scheduled system backup completes.
3. An approved patch is installed.
4. A privileged account disables endpoint protection across multiple systems immediately after suspicious authentication.
Correct Answer: 4
Explanation:
Disabling endpoint protection across multiple systems after anomalous privileged authentication is a strong sign of malicious activity. Attackers often weaken defensive controls before deploying ransomware, credential theft tools, or persistence mechanisms. Security teams should validate the account, restore protection, revoke suspicious sessions, preserve logs, and investigate any actions performed while defenses were disabled.
Question 379.
Which security design best protects machine-to-machine API communication in a zero-trust architecture?
- Trust all internal IP addresses automatically.
2. Use one shared API key for every workload.
3. Use workload identities, mutual authentication, scoped authorization, and short-lived credentials.
4. Disable API logging to reduce overhead.
Correct Answer: 3
Explanation:
Zero-trust service communication requires explicit identity and authorization rather than trust based on network location. Workload identities provide accountability, mutual authentication establishes both endpoints, scoped permissions enforce least privilege, and short-lived credentials reduce credential-theft impact. Shared keys and IP-based trust provide weaker security boundaries and larger blast radius.
Question 380.
Which approach best supports a continuously improving enterprise security architecture?
- Assume approved designs remain secure indefinitely.
2. Regularly reassess threat models, test controls, review identity and configuration drift, and incorporate incident lessons into architecture.
3. Change architecture only after major breaches.
4. Avoid measuring control effectiveness.
Correct Answer: 2
Explanation:
Enterprise security architecture must evolve as workloads, identities, dependencies, attacker techniques, and business requirements change. Threat-model reviews, control validation, entitlement reviews, drift monitoring, resilience exercises, and incident lessons provide evidence about where protections need improvement. Continuous reassessment helps prevent outdated assumptions from becoming persistent security weaknesses.