CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part20 Q381-400

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 381.

A security architect wants to reduce the risk that a compromised privileged account can immediately alter enterprise-wide authentication policies. Which control is most appropriate?

  1. Require just-in-time privilege elevation, independent approval, and strong MFA for authentication-policy changes
    2. Give all identity administrators permanent unrestricted access
    3. Use one shared privileged account for all identity operations
    4. Disable audit logging for authentication changes

Correct Answer: 1

Explanation:

Just-in-time privilege reduces standing administrative access, while independent approval adds separation of duties for high-impact identity changes. Strong MFA provides additional assurance that a stolen password alone cannot authorize sensitive actions. Permanent broad privileges and shared accounts increase blast radius and weaken accountability. Authentication-policy changes should also be centrally logged and monitored because attackers who gain access to identity controls may attempt to weaken MFA, federation, or recovery settings.

Question 382.

Which architecture best protects enterprise applications from direct internet exposure while still allowing approved external users to access them securely?

  1. Publish every application directly to the internet
    2. Disable authentication for remote users
    3. Allow access based solely on source IP addresses
    4. Use identity-aware application access through a zero-trust broker or secure proxy

Correct Answer: 4

Explanation:

An identity-aware access broker can authenticate and authorize users before establishing access to private applications. Access decisions can consider user identity, device posture, risk, authentication strength, and application sensitivity. This avoids exposing backend systems directly to the internet and reduces broad network access. IP address alone is not a sufficient trust signal, and authentication should never be removed merely because access is remote or proxied.

Question 383.

Which security capability is most useful for identifying unexpected or excessive permissions assigned to machine identities in a cloud environment?

  1. RAID monitoring
    2. DNS caching
    3. Cloud entitlement and permission usage analysis
    4. Disk compression

Correct Answer: 3

Explanation:

Cloud entitlement analysis can reveal excessive, inherited, unused, or risky permissions assigned to service accounts, workload identities, and other machine identities. Comparing granted permissions with observed usage helps identify privileges that can safely be removed. Machine identities often accumulate access over time and may be overlooked during ordinary user access reviews. Least privilege should apply equally to both human and nonhuman identities.

Question 384.

Which control best reduces the risk of a compromised API client abusing a sensitive transaction endpoint?

  1. Trust the client completely after authentication.
    2. Enforce scoped authorization, transaction limits, rate controls, and contextual validation.
    3. Disable API logging.
    4. Give every client administrator-level access.

Correct Answer: 2

Explanation:

Authentication alone does not prevent a compromised client from abusing an API. Scoped authorization limits the actions and resources available to the client, while transaction limits and rate controls constrain abuse. Contextual validation can identify anomalous patterns such as unusual device, location, or transaction behavior. Detailed auditing is also important for detection and investigation. Broad administrator access significantly increases potential impact.

Question 385.

A security operations team wants to detect malicious use of legitimate remote administration tools. Which approach provides the strongest visibility?

  1. Correlate endpoint process activity, command lines, identity context, and network connections
    2. Rely only on malware file hashes
    3. Disable endpoint telemetry
    4. Block all administrative tools permanently

Correct Answer: 1

Explanation:

Legitimate administration tools are frequently abused by attackers, so behavioral context is critical. Process execution, command-line arguments, parent-child relationships, remote-session data, identity events, and network connections can reveal suspicious activity even when the executable itself is trusted. File hashes alone are insufficient. Blanket blocking of all administrative tools is usually impractical and may interfere with legitimate operations.

Question 386.

Which design best protects critical cryptographic keys if the general-purpose operating system hosting an application is compromised?

  1. Store keys in plaintext configuration files.
    2. Keep keys in application source code.
    3. Store keys in user home directories.
    4. Use an HSM or hardware-backed secure key service.

Correct Answer: 4

Explanation:

An HSM or hardware-backed key service isolates key material from the general-purpose operating system and can perform cryptographic operations without exposing private keys directly. Plaintext files, source code, and user directories remain vulnerable if the host is compromised. High-value key systems should also enforce least privilege, separation of duties, key rotation, secure backup, and detailed auditing.

Question 387.

Which security practice best reduces the risk that outdated third-party dependencies remain unnoticed in production software?

  1. Disable dependency inventories.
    2. Allow arbitrary package versions.
    3. Maintain SBOMs and continuously scan dependencies for vulnerabilities and outdated components.
    4. Remove automated build checks.

Correct Answer: 3

Explanation:

SBOMs provide visibility into the components and dependencies included in applications. Continuous dependency scanning can identify vulnerable or obsolete versions and support timely remediation. Without inventory, organizations may not know which applications are affected when a vulnerability is disclosed. Strong dependency management also includes trusted repositories, version pinning, integrity verification, and controlled update processes.

Question 388.

Which statement best describes the purpose of data classification in enterprise security?

  1. It automatically encrypts all information.
    2. It categorizes data based on sensitivity and handling requirements so appropriate controls can be applied.
    3. It removes the need for access control.
    4. It applies only to printed documents.

Correct Answer: 2

Explanation:

Data classification helps organizations distinguish between public, internal, confidential, regulated, and highly sensitive information. Different classifications can drive different requirements for encryption, access, retention, monitoring, sharing, and disposal. Classification does not automatically implement controls, but it provides the basis for consistent handling decisions. It should apply across structured data, documents, cloud storage, collaboration platforms, and other information repositories.

Question 389.

A security team detects that a normally dormant service account has begun making repeated privilege-management API calls. What should be done first?

  1. Investigate the identity, revoke suspicious sessions or credentials if needed, and review recent activity.
    2. Ignore the behavior because the account exists legitimately.
    3. Increase the service account’s privileges.
    4. Disable audit logging for the account.

Correct Answer: 1

Explanation:

A dormant service account suddenly performing privilege-management operations is a significant anomaly and may indicate credential compromise. The security team should validate whether the activity is expected, inspect the source workload or host, review related API calls, and contain suspicious sessions or credentials. Dormant identities should generally have been disabled if no longer required. Successful authentication does not guarantee that the behavior is legitimate.

Question 390.

Which control provides the strongest protection against unauthorized modification of enterprise audit records?

  1. Store logs only on local production systems.
    2. Allow privileged users to delete logs freely.
    3. Disable centralized collection.
    4. Send logs to a separate immutable or tamper-resistant platform.

Correct Answer: 4

Explanation:

A separate immutable logging platform provides stronger integrity because attackers or administrators with access to production systems cannot easily alter historical records. Local-only storage creates a common failure domain. Security teams should also monitor for gaps in log collection, unexpected retention changes, and attempts to disable telemetry. Protected audit records are essential for investigation, compliance, and accountability.

Question 391.

Which architecture best limits lateral movement if an internet-facing application is compromised?

  1. Place all internal systems on one flat network.
    2. Give the application broad administrative rights.
    3. Segment the application and allow only required connections to downstream services.
    4. Disable east-west monitoring.

Correct Answer: 3

Explanation:

Segmentation limits the systems a compromised application can reach after exploitation. Explicit allow rules should permit only necessary communication to required services and deny access to unrelated management, identity, and data systems. Broad privileges and flat networking significantly increase blast radius. Segmentation is most effective when paired with service identity, application authorization, and monitoring of unexpected internal traffic.

Question 392.

Which statement best describes the purpose of a business impact analysis?

  1. It identifies every software vulnerability in the enterprise.
    2. It determines how disruption of business processes affects the organization and helps establish recovery priorities.
    3. It replaces incident response planning.
    4. It is used only to measure network performance.

Correct Answer: 2

Explanation:

A business impact analysis identifies critical processes, dependencies, acceptable downtime, data-loss tolerance, and consequences of disruption. These findings help determine recovery priorities and support RTO and RPO decisions. A BIA is focused on business consequences rather than technical vulnerability discovery. It informs continuity and disaster-recovery planning but does not replace incident response or technical resilience testing.

Question 393.

Which action is most appropriate after discovering that a privileged API key was exposed in a public repository?

  1. Revoke or rotate the key immediately, review its usage, and investigate the exposure.
    2. Delete only the current file and keep the key active.
    3. Wait until the key expires naturally.
    4. Increase the key’s permissions.

Correct Answer: 1

Explanation:

A credential exposed publicly should be considered compromised because it may already have been copied or indexed. Revocation or rotation limits further misuse, while usage logs help determine whether the key was abused. Repository history should also be reviewed because deleting the latest version may not remove older copies. Preventive controls such as secret scanning and managed credential retrieval should be implemented to reduce recurrence.

Question 394.

Which architecture best protects recovery capability when ransomware compromises production systems and normal administrator credentials?

  1. Use the same credentials for production and backups.
    2. Keep every backup permanently writable.
    3. Allow production administrators unrestricted backup deletion.
    4. Maintain isolated recovery identities, immutable backups, and independent administrative access.

Correct Answer: 4

Explanation:

Recovery systems should not depend entirely on the same identities and administrative paths used in production. Separate recovery identities and isolated administration reduce the chance that compromised production credentials can destroy backups. Immutable copies further prevent unauthorized modification or deletion. Recovery procedures should be exercised regularly so the organization knows that protected data can actually be restored under adverse conditions.

Question 395.

Which control most directly reduces exposure of sensitive data used for application testing?

  1. Copy full production databases into every test environment.
    2. Disable nonproduction access controls.
    3. Use masked, anonymized, or synthetic data where real identifiers are unnecessary.
    4. Give developers unrestricted access to production systems.

Correct Answer: 3

Explanation:

Masked, anonymized, or synthetic data enables realistic testing while reducing exposure of customer, regulated, or confidential information. Development and testing environments often have broader access and different operational controls than production, making unnecessary production data particularly risky. Data minimization should be applied wherever possible. Test systems should still use strong authentication, encryption, monitoring, and appropriate retention controls.

Question 396.

Which statement best describes the purpose of security metrics and key performance indicators?

  1. They guarantee that controls cannot fail.
    2. They provide measurable evidence about security performance, trends, and control effectiveness.
    3. They eliminate the need for qualitative risk analysis.
    4. They are useful only for compliance reporting.

Correct Answer: 2

Explanation:

Security metrics help organizations measure whether controls and processes are improving outcomes over time. Examples can include remediation time, detection coverage, incident response speed, privileged-access reduction, or recovery performance. Metrics do not eliminate the need for judgment and risk analysis, but they provide evidence that can support better decisions. Effective metrics should be tied to meaningful security objectives rather than collected solely for reporting.

Question 397.

Which practice best reduces risk from unmanaged machine identities in a large cloud environment?

  1. Inventory machine identities, assign owners, review permissions, and rotate or eliminate unnecessary credentials.
    2. Exempt service identities from governance.
    3. Give every machine identity administrator privileges.
    4. Disable machine-identity logging.

Correct Answer: 1

Explanation:

Machine identities can greatly outnumber human users and often hold significant permissions. Inventory, ownership, access review, and credential lifecycle management are therefore essential. Unused credentials should be revoked, and active identities should use narrow permissions and short-lived credentials where possible. Exempting service identities from governance creates hidden attack paths and increases the chance of unmanaged privilege accumulation.

Question 398.

Which activity most strongly suggests an attacker is attempting to weaken cloud defenses before performing additional actions?

  1. A scheduled application health check succeeds.
    2. A routine report is generated.
    3. A standard backup completes.
    4. A privileged identity disables threat detection and reduces audit-log retention immediately after an unusual login.

Correct Answer: 4

Explanation:

Attackers often attempt to reduce visibility after gaining privileged access. Unexpectedly disabling detection services and shortening audit retention after suspicious authentication is a high-priority indicator. Security teams should validate the session, preserve available logs, restore monitoring, revoke suspicious access if warranted, and review other administrative changes made during the same period.

Question 399.

Which security design best protects internal service-to-service communication in a zero-trust architecture?

  1. Trust all traffic originating from internal IP addresses.
    2. Use a single shared API key for every service.
    3. Use workload identities, mutual authentication, scoped authorization, and short-lived credentials.
    4. Disable service communication logging.

Correct Answer: 3

Explanation:

Zero-trust service communication requires explicit identity and authorization for every connection rather than implicit trust based on network location. Workload identities provide accountability, mutual authentication establishes both endpoints, scoped authorization limits permitted operations, and short-lived credentials reduce the impact of theft. Shared keys and IP-based trust create broad security boundaries and make compromise more damaging.

Question 400.

Which approach best supports continuous improvement of an enterprise SecurityX-level security architecture?

  1. Treat compliance approval as proof that the architecture will remain secure indefinitely.
    2. Continuously reassess threats, test controls, review identities and dependencies, exercise recovery, and update architecture based on measured gaps.
    3. Review security design only after major incidents.
    4. Avoid changing controls once they have passed an audit.

Correct Answer: 2

Explanation:

Enterprise security architecture must evolve as technologies, identities, dependencies, threats, and business requirements change. Threat-model reviews, control testing, access analysis, detection validation, resilience exercises, and incident lessons provide evidence of where improvements are needed. Continuous reassessment helps prevent outdated assumptions and configuration drift from becoming persistent weaknesses. A mature program treats architecture as an ongoing risk-management discipline rather than a one-time compliance exercise.