View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps
Question 81.
A security architect needs to reduce the risk that a compromised SaaS account can be used to access sensitive enterprise data from an unmanaged device. Which control is most appropriate?
- Conditional access that evaluates identity, MFA strength, device compliance, and risk before granting access
2. Permanent allowlisting of all user IP addresses
3. Disabling MFA for trusted users
4. Allowing access solely based on possession of a valid password
Correct Answer: 1
Explanation:
Conditional access evaluates multiple contextual factors before granting access, such as user identity, authentication strength, device compliance, location, application sensitivity, and current risk. This is stronger than relying on passwords or network location alone. An unmanaged device may lack required endpoint protections, encryption, or monitoring. A well-designed policy can block, restrict, or require stronger verification for risky sessions while still allowing legitimate access from compliant devices.
Question 82.
Which security architecture best protects a highly sensitive database from direct access by end-user workstations?
- Expose the database to the entire internal network.
2. Disable database authentication for trusted subnets.
3. Allow all users to connect with shared credentials.
4. Place the database in a restricted segment and require access through approved application tiers.
Correct Answer: 4
Explanation:
A restricted database segment combined with application-tier access reduces direct attack paths and limits the systems that can communicate with the database. Users interact with approved applications rather than connecting directly to the data tier. Shared credentials and unrestricted network access increase blast radius and weaken accountability. This design should be reinforced with service identities, least-privilege database permissions, encryption, monitoring, and explicit network allow rules.
Question 83.
An organization wants to detect unauthorized changes to infrastructure-as-code templates before they are deployed. Which control is most appropriate?
- Disable version control.
2. Rely only on manual inspection after deployment.
3. Require code review, protected branches, integrity checks, and policy-as-code validation.
4. Allow direct changes to production from developer workstations.
Correct Answer: 3
Explanation:
Protected repositories, mandatory code review, integrity validation, and policy-as-code checks help identify unauthorized or insecure changes before infrastructure reaches production. Version control provides traceability, while branch protections and approval workflows reduce the risk of unreviewed modifications. Direct production changes from user workstations bypass important security controls. Automated policy checks can also detect insecure configurations such as public storage, overly permissive IAM roles, or missing encryption settings.
Question 84.
Which statement best describes the purpose of key rotation?
- It eliminates the need for access control.
2. It limits the period during which a compromised cryptographic key can remain useful.
3. It guarantees that encrypted data can never be exposed.
4. It replaces certificate validation.
Correct Answer: 2
Explanation:
Key rotation replaces existing cryptographic keys with new ones according to policy or when compromise is suspected. This limits the useful lifetime of a stolen key and supports sound cryptographic hygiene. Rotation does not eliminate the need for access control, secure storage, auditing, or certificate validation. High-value keys should also be protected using appropriate hardware-backed controls, restricted administrative access, and documented lifecycle procedures.
Question 85.
A security operations team observes a sudden increase in outbound traffic from a server that normally communicates only with internal systems. What should the team do first?
- Validate the traffic, identify the destination, and investigate the associated process or account activity.
2. Immediately delete all server logs.
3. Disable centralized monitoring.
4. Assume the behavior is legitimate because the server is internal.
Correct Answer: 1
Explanation:
Unexpected outbound communication from a normally internal-only system may indicate malware, command-and-control traffic, data exfiltration, or an unauthorized configuration change. Analysts should identify the destination, process, user, timing, and data volume before deciding on containment. Deleting logs or disabling monitoring destroys useful evidence. Internal systems should not be considered trustworthy solely because of their network location, especially in a zero-trust architecture.
Question 86.
Which control best protects an organization’s root certificate authority private key?
- Store it in a shared network folder.
2. Place it in an administrator’s email account.
3. Keep it on a standard application server.
4. Use offline or hardware-backed key protection with strict access controls.
Correct Answer: 4
Explanation:
A root certificate authority key is one of the most sensitive cryptographic assets in an enterprise. Offline or hardware-backed protection significantly reduces the risk of unauthorized extraction or use. Access should be tightly restricted, audited, and governed by strong procedures, often including separation of duties. Storing the key in ordinary user, application, or network locations exposes it to malware, credential theft, and administrative compromise.
Question 87.
Which practice most effectively reduces the attack surface of a production server?
- Install every available service in case it is needed later.
2. Enable all inbound ports.
3. Remove unnecessary services, software, accounts, and network exposure.
4. Share local administrator accounts across systems.
Correct Answer: 3
Explanation:
Attack-surface reduction involves removing functions and access paths that are not required. Unnecessary services, packages, accounts, open ports, and administrative interfaces can all create exploitable opportunities. Hardening should be based on the server’s intended role and supported by patching, secure configuration, monitoring, and least privilege. Installing additional software or opening unnecessary ports increases rather than decreases exposure.
Question 88.
A company wants to reduce the risk of users approving malicious OAuth applications. Which control is best?
- Allow any user to approve any application.
2. Restrict consent to approved applications and require administrative review for high-risk scopes.
3. Disable logging of OAuth grants.
4. Allow applications to request unrestricted permissions.
Correct Answer: 2
Explanation:
OAuth consent phishing relies on users granting legitimate authorization tokens to malicious applications. Restricting user consent and requiring review for sensitive permissions reduces this risk. Organizations should also monitor newly registered applications, unusual consent events, and high-risk permission grants. Disabling logs or allowing unrestricted scopes reduces visibility and control. Approval workflows should balance usability with the sensitivity of requested access.
Question 89.
Which enterprise security capability is most useful for determining whether a newly discovered vulnerability is actually present in production applications?
- Software inventory and SBOM correlation
2. DNS caching
3. Network address translation
4. Printer management
Correct Answer: 1
Explanation:
A software inventory or software bill of materials allows security teams to identify which systems and applications contain a vulnerable component. When a new vulnerability is disclosed, the organization can quickly determine affected versions, prioritize critical assets, and begin remediation. DNS caching, NAT, and printer management do not provide software dependency visibility. Accurate inventory data is essential for effective vulnerability and supply-chain risk management.
Question 90.
Which control provides the strongest protection against unauthorized modification of audit logs by a compromised administrator?
- Store all logs locally on the administered system.
2. Allow administrators to delete logs without review.
3. Disable audit logging during maintenance.
4. Send logs to a separate tamper-resistant or immutable logging platform.
Correct Answer: 4
Explanation:
Centralized logs stored in a separate security boundary are harder for a compromised administrator to alter or delete. Immutability or write-once controls can provide even stronger protection against tampering. Local-only logs are vulnerable if the host or administrator account is compromised. Critical administrative, identity, security, and configuration events should be forwarded promptly and monitored for gaps or unusual changes.
Question 91.
Which cloud-security design best supports least privilege for serverless functions?
- Give every function the same administrator role.
2. Use one shared access key for all functions.
3. Assign each function a narrowly scoped execution identity with only required permissions.
4. Disable authentication for internal APIs.
Correct Answer: 3
Explanation:
Each serverless function should receive a distinct execution identity with only the permissions required for its intended task. This minimizes blast radius if the function or its dependencies are compromised. Shared administrator roles or common access keys create excessive privilege and make activity difficult to attribute. Fine-grained permissions should be combined with logging, secret management, network restrictions, dependency scanning, and short-lived credentials where available.
Question 92.
Which statement best describes the security purpose of microsegmentation?
- It eliminates the need for identity controls.
2. It limits communication between workloads to reduce lateral movement.
3. It automatically patches every system.
4. It replaces encryption.
Correct Answer: 2
Explanation:
Microsegmentation creates fine-grained boundaries between workloads, applications, or security zones. By permitting only required communication paths, it reduces the attacker’s ability to move laterally after compromising one system. Microsegmentation does not replace identity, encryption, patching, or endpoint controls. It is most effective when policies are based on workload identity, application requirements, and continuous monitoring rather than broad network trust.
Question 93.
A security team suspects a malicious insider is using approved cloud collaboration tools to move sensitive documents externally. Which data should be correlated first?
- DLP events, cloud-sharing logs, file access records, and identity activity
2. Printer toner levels
3. DNS TTL configuration
4. Backup media labels
Correct Answer: 1
Explanation:
Insider data theft often involves legitimate tools, so correlating multiple contextual sources is essential. DLP events can identify sensitive content, cloud-sharing logs show external transfers, file access records reveal unusual collection behavior, and identity telemetry provides user context. None of these signals alone always proves malicious activity. Investigations should be performed according to organizational policy, legal requirements, and privacy obligations.
Question 94.
Which control best protects an API from clients attempting to submit malicious or malformed input?
- Disable all input validation.
2. Allow unrestricted request sizes.
3. Trust requests from internal IP addresses automatically.
4. Enforce schema validation, input sanitization, and request-size limits.
Correct Answer: 4
Explanation:
Schema validation and input controls ensure that API requests conform to expected formats and size limits before application logic processes them. This reduces exposure to injection, malformed payloads, parser abuse, and resource-exhaustion attacks. Internal location does not make input trustworthy. API gateways, web application firewalls, authentication, authorization, rate limiting, and monitoring can provide additional layers of protection.
Question 95.
Which security approach is most appropriate when an enterprise must protect sensitive data used for machine-learning training?
- Copy all production data into an unrestricted shared folder.
2. Disable access logging.
3. Apply data minimization, masking where possible, controlled access, and protected training environments.
4. Give every data scientist unrestricted production access.
Correct Answer: 3
Explanation:
Machine-learning training can involve large volumes of sensitive information, so organizations should minimize the data used and remove or mask unnecessary identifiers where possible. Access should be restricted to authorized personnel and workloads, and training environments should be monitored and appropriately segmented. Logging should remain enabled to support accountability. Broad production access creates unnecessary risk and can expose regulated or confidential information.
Question 96.
Which statement best describes cryptographic agility?
- It means using one algorithm forever.
2. It is the ability to replace cryptographic algorithms, protocols, or keys without redesigning the entire system.
3. It eliminates the need for key management.
4. It requires disabling encryption during migration.
Correct Answer: 2
Explanation:
Cryptographic agility allows an organization to adapt when algorithms become weak, standards change, or new cryptographic requirements emerge. Systems should avoid hard-coded assumptions that make algorithm or key replacement difficult. Agility supports migration planning for future cryptographic changes, including post-quantum transitions. It does not remove the need for secure key management, testing, compatibility planning, or controlled rollout procedures.
Question 97.
Which practice best reduces the risk that compromised developer credentials can modify production code directly?
- Require protected branches, peer review, signed commits or artifacts, and controlled deployment pipelines.
2. Give all developers direct write access to production systems.
3. Disable source-control audit logs.
4. Share deployment credentials across the development team.
Correct Answer: 1
Explanation:
Protected branches and review requirements prevent a single compromised account from modifying production-bound code without additional controls. Signed artifacts or commits strengthen integrity, while controlled deployment pipelines separate development access from production deployment privileges. Shared credentials and direct production access increase risk and weaken traceability. CI/CD systems should also use short-lived credentials, isolated runners, approval gates, and extensive auditing.
Question 98.
Which behavior most strongly suggests persistence after a cloud account compromise?
- A user runs a normal monthly report.
2. An administrator updates a documented firewall rule.
3. A scheduled backup completes successfully.
4. A newly created access key or application credential appears immediately after suspicious login activity.
Correct Answer: 4
Explanation:
Attackers often create new credentials, service principals, access keys, or application tokens to maintain access even if the original compromised session is revoked. Creation of new credentials immediately after suspicious authentication should therefore be investigated urgently. Responders should identify who created the credential, revoke unauthorized access, review permissions, inspect related activity, and determine whether additional persistence mechanisms were established.
Question 99.
Which security architecture most effectively protects sensitive internal services from lateral movement originating from compromised endpoints?
- A flat internal network with broad trust
2. Shared service credentials across all applications
3. Zero-trust segmentation with explicit identity-aware access policies
4. Disabling east-west traffic monitoring
Correct Answer: 3
Explanation:
Zero-trust segmentation requires explicit authorization for communication between users, devices, and workloads rather than assuming internal traffic is trustworthy. Identity-aware policies, device posture, service identity, and microsegmentation can significantly limit lateral movement. Flat networks and shared credentials expand attacker reach, while disabling monitoring reduces visibility. Strong east-west controls are especially important after an initial endpoint compromise.
Question 100.
Which approach best supports secure enterprise adoption of autonomous systems that can make high-impact operational changes?
- Grant permanent unrestricted administrator access.
2. Constrain permissions, enforce independent authorization, log actions, test behavior, and require human approval for critical changes.
3. Disable policy enforcement whenever automation is used.
4. Allow the autonomous system to modify its own audit records.
Correct Answer: 2
Explanation:
Autonomous systems should operate within tightly constrained security boundaries. Permissions should be narrowly scoped, policy enforcement should remain independent of the autonomous decision engine, and high-impact actions should require additional authorization or human approval. Detailed logs provide accountability and support investigations. Testing and monitoring are also necessary because unexpected behavior, malicious input, or model manipulation can otherwise cause significant operational or security impact.