CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part7 Q121-140

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 121.

A security architect needs to reduce the risk that a compromised endpoint can use existing user credentials to access highly sensitive applications. Which control is most appropriate?

  1. Require phishing-resistant MFA and device posture validation for sensitive access
    2. Trust any session originating from the internal network
    3. Disable reauthentication for privileged actions
    4. Grant permanent access once a user authenticates successfully

Correct Answer: 1

Explanation:

Phishing-resistant MFA combined with device posture validation reduces reliance on passwords and network location alone. Even if an endpoint or password is compromised, the attacker may still be unable to satisfy hardware-backed authentication and device compliance requirements. Sensitive applications can also require step-up authentication and continuous risk evaluation. Permanent trust after initial login creates excessive exposure, while internal network location does not prove that the user or device remains trustworthy.

Question 122.

Which security approach best protects an enterprise from malicious changes to production infrastructure templates?

  1. Allow direct editing of production resources.
    2. Disable repository history.
    3. Use unsigned templates with no review.
    4. Store infrastructure as code in protected repositories with review, signing, and automated policy checks.

Correct Answer: 4

Explanation:

Protected infrastructure-as-code repositories provide traceability, version control, peer review, and controlled deployment. Digital signatures or other integrity mechanisms can help verify approved artifacts, while policy-as-code can identify insecure configuration before deployment. Direct manual modification bypasses these controls and creates configuration drift. Strong IaC governance also uses separate deployment identities, change logging, and rollback capability so unauthorized or unsafe changes can be detected and reversed.

Question 123.

A company wants to detect suspicious administrative commands executed through remote management tools. Which telemetry is most useful?

  1. Printer queue statistics
    2. Backup media inventory
    3. Endpoint process creation and command-line logging
    4. DNS cache size

Correct Answer: 3

Explanation:

Process creation and command-line telemetry can reveal which administrative tools were executed, what arguments were supplied, and which user initiated the activity. This is valuable for detecting malicious use of legitimate remote-management utilities. Analysts can correlate the endpoint data with authentication events, network connections, privilege changes, and remote-session logs. Printer queues and DNS cache size provide little relevant evidence for this type of behavior.

Question 124.

Which control best reduces the risk of an application using excessive permissions after its service account is compromised?

  1. Grant the account administrator rights to simplify operations.
    2. Apply least-privilege permissions and narrowly scoped resource access.
    3. Share the service account across applications.
    4. Disable service-account logging.

Correct Answer: 2

Explanation:

Least privilege limits a service account to the exact operations and resources required by the application. If the credential or workload is compromised, the attacker inherits only a constrained set of permissions. Shared accounts and broad administrator roles significantly increase blast radius. Service-account activity should also be logged, monitored, and periodically reviewed, while long-lived credentials should be rotated or replaced by workload identity where possible.

Question 125.

An organization suspects that a cloud administrator is exfiltrating sensitive data using legitimate APIs. Which approach provides the strongest detection capability?

  1. Correlate cloud audit logs, data-access events, identity behavior, and outbound transfer patterns
    2. Disable cloud logging
    3. Rely only on malware signatures
    4. Monitor only failed login attempts

Correct Answer: 1

Explanation:

Legitimate API calls can still be used maliciously by an insider or compromised privileged account. Cloud control-plane logs, data-access logs, identity context, and transfer volume provide a stronger behavioral view than malware detection alone. Security teams should look for unusual resource enumeration, bulk downloads, atypical destinations, privilege changes, and deviations from the administrator’s normal activity. Correlation across multiple data sources improves confidence and helps distinguish legitimate work from misuse.

Question 126.

Which design best protects secrets used by serverless workloads?

  1. Embed credentials in function source code.
    2. Put secrets in public environment variables.
    3. Store one shared password in every function package.
    4. Retrieve secrets dynamically from a managed secrets service using workload identity.

Correct Answer: 4

Explanation:

A managed secrets service combined with workload identity avoids embedding static credentials in code or deployment packages. The function authenticates using its own identity and retrieves only the secrets it is authorized to use. This supports centralized rotation, logging, and least privilege. Shared or hard-coded secrets are difficult to rotate and may be exposed through source repositories, build artifacts, logs, or configuration snapshots.

Question 127.

Which control is most appropriate for detecting unauthorized changes to critical application binaries?

  1. Network address translation
    2. RAID
    3. File integrity monitoring
    4. DNS caching

Correct Answer: 3

Explanation:

File integrity monitoring detects changes to critical files by comparing their current state with a known-good baseline or expected cryptographic hash. This can reveal unauthorized modification of application binaries, libraries, configuration files, or scripts. NAT, RAID, and DNS caching do not provide file-level integrity validation. FIM alerts should be correlated with approved change records so legitimate maintenance can be distinguished from suspicious tampering.

Question 128.

Which statement best describes the security benefit of workload identity federation?

  1. It requires every application to store a permanent cloud access key.
    2. It allows workloads to obtain short-lived credentials based on trusted identity relationships instead of static secrets.
    3. It eliminates the need for authorization.
    4. It makes all workloads administrators.

Correct Answer: 2

Explanation:

Workload identity federation allows applications or external workloads to exchange a trusted identity assertion for short-lived cloud credentials. This reduces reliance on long-lived static access keys that can be leaked or forgotten. The resulting credentials should still be narrowly scoped through authorization policies. Federation does not eliminate authorization or justify administrator-level permissions. It is particularly useful in CI/CD, multicloud, and external workload scenarios.

Question 129.

Which response is most appropriate when an organization confirms that a code-signing certificate private key has been stolen?

  1. Revoke the certificate, rotate the key, investigate signed artifacts, and notify affected stakeholders as required.
    2. Continue using the key until its normal expiration.
    3. Delete audit logs associated with signing.
    4. Publish the private key so users can verify it.

Correct Answer: 1

Explanation:

A stolen code-signing private key can allow attackers to create malicious software that appears legitimate. The organization should revoke the affected certificate, generate a new protected key, investigate whether unauthorized artifacts were signed, and communicate with downstream consumers where necessary. Continuing to use the key extends the risk. Signing logs and build records should be preserved because they may be essential for determining the scope of compromise.

Question 130.

Which architecture best limits an attacker’s ability to move from a compromised user subnet into a production server environment?

  1. Use one flat network.
    2. Allow any authenticated user to reach all servers.
    3. Disable internal firewalling.
    4. Use segmentation with explicit access controls between user, server, and management zones.

Correct Answer: 4

Explanation:

Segmentation creates controlled boundaries between user networks, production servers, management systems, and other security zones. Explicit allow rules ensure only required communication paths are permitted. This reduces lateral movement after endpoint compromise. Flat networks and broad access policies make it easier for attackers to reach valuable systems. Segmentation should be combined with identity-aware access, endpoint controls, logging, and restricted administrative pathways for stronger protection.

Question 131.

Which control best protects an enterprise from developers accidentally introducing vulnerable third-party packages into production?

  1. Disable dependency tracking.
    2. Allow arbitrary packages from unknown repositories.
    3. Use software composition analysis and trusted dependency repositories in the CI/CD pipeline.
    4. Remove all automated build checks.

Correct Answer: 3

Explanation:

Software composition analysis identifies known vulnerable or risky third-party dependencies before release. Trusted repositories and allowlists further reduce the chance that malicious or unapproved packages enter the build process. Dependency scanning should be combined with SBOM generation, version pinning, integrity verification, and timely remediation. Disabling dependency visibility or automated checks increases software supply-chain risk.

Question 132.

Which statement best describes the purpose of differential privacy?

  1. It encrypts all network traffic.
    2. It adds controlled statistical noise to help protect individual privacy in aggregate analysis.
    3. It replaces authentication.
    4. It provides disk redundancy.

Correct Answer: 2

Explanation:

Differential privacy introduces carefully calibrated noise into statistical outputs so useful aggregate analysis can be performed while reducing the ability to infer information about specific individuals. It is particularly relevant in large data sets and privacy-preserving analytics. It does not provide transport encryption, authentication, or storage redundancy. Effective use requires careful selection of privacy parameters and an understanding of how repeated queries can affect the privacy budget.

Question 133.

Which action should an incident responder take after identifying a malicious persistence mechanism that creates new privileged cloud credentials?

  1. Remove the persistence, revoke unauthorized credentials, preserve evidence, and investigate related activity.
    2. Leave the credentials active for convenience.
    3. Disable all audit logging.
    4. Increase the malicious credentials’ permissions.

Correct Answer: 1

Explanation:

Once malicious persistence is confirmed, responders should revoke unauthorized credentials and remove the persistence mechanism while preserving evidence needed to determine scope and root cause. They should also examine related identities, sessions, role assignments, API calls, and resource changes. Disabling logging or leaving malicious credentials active would increase risk. Containment should be coordinated with forensic and business requirements so critical evidence is not unnecessarily destroyed.

Question 134.

Which control provides the strongest protection for a root cryptographic key used to issue subordinate certificates?

  1. Store it in a developer workstation.
    2. Put it in a shared cloud folder.
    3. Email it to backup administrators.
    4. Keep it offline or inside a highly controlled hardware security module.

Correct Answer: 4

Explanation:

Root certificate authority keys are extremely sensitive because compromise can undermine trust throughout the PKI. Offline storage or an HSM reduces exposure to normal network and endpoint attacks. Access should be tightly controlled, audited, and often require multiple authorized individuals for sensitive operations. Ordinary workstations, shared folders, and email provide inadequate protection for such a critical cryptographic asset.

Question 135.

Which security technique best reduces the risk of sensitive customer information appearing in lower-security test environments?

  1. Copy the full production database to every test server.
    2. Give testers administrator access to production data.
    3. Use masked, anonymized, or synthetic test data.
    4. Disable encryption in nonproduction environments.

Correct Answer: 3

Explanation:

Masked, anonymized, or synthetic data reduces the exposure of real customer information while still allowing developers and testers to exercise application functionality. Copying production data into lower-security environments expands privacy and compliance risk. Nonproduction systems should still use strong access controls, encryption, and monitoring because they are often attractive targets. Data minimization is a key principle when production identifiers are not necessary for testing.

Question 136.

Which statement best describes the purpose of security chaos engineering?

  1. It intentionally disables all security controls in production.
    2. It safely tests how systems and teams respond when security controls or assumptions fail.
    3. It replaces penetration testing entirely.
    4. It guarantees that incidents cannot occur.

Correct Answer: 2

Explanation:

Security chaos engineering introduces controlled, planned failure scenarios to test whether security assumptions, controls, monitoring, and response processes work as expected. Examples might include simulating credential loss, service isolation, or security-control degradation in a safe environment. It does not mean indiscriminately disabling protections or replacing other testing methods. The goal is to discover hidden dependencies and improve resilience before real incidents expose them.

Question 137.

Which practice best supports secure management of privileged cloud roles?

  1. Use just-in-time elevation, strong MFA, approval workflows, and session logging.
    2. Assign permanent global administrator access to all engineers.
    3. Share one root account.
    4. Disable privileged-access auditing.

Correct Answer: 1

Explanation:

Just-in-time elevation reduces standing privilege by granting sensitive roles only when needed. Strong MFA protects authentication, approval workflows support oversight, and session or activity logging provides accountability. Permanent broad administrator access and shared root credentials greatly increase risk. Privileged access should be regularly reviewed, and unused roles or accounts should be removed promptly.

Question 138.

Which activity most strongly suggests a supply-chain compromise in a CI/CD environment?

  1. A scheduled build completes normally.
    2. A developer reads build documentation.
    3. A routine unit test passes.
    4. An unapproved build runner begins signing production artifacts using a newly added credential.

Correct Answer: 4

Explanation:

An unapproved build runner using a newly introduced signing credential is highly suspicious because it could allow malicious artifacts to be produced and presented as legitimate. Security teams should immediately validate the runner, credential creation, signing history, pipeline changes, and artifact provenance. Signing keys should be tightly protected, and build systems should use controlled identities, approved runners, immutable logs, and separation of duties.

Question 139.

Which security approach best protects internet-facing APIs from automated credential-stuffing attacks?

  1. Disable authentication logs.
    2. Allow unlimited login attempts.
    3. Use rate limiting, bot detection, strong MFA, and breached-credential monitoring.
    4. Trust all requests from residential IP addresses.

Correct Answer: 3

Explanation:

Credential stuffing uses large numbers of stolen username and password combinations against authentication endpoints. Rate limiting and bot controls reduce automated attempts, while MFA makes stolen passwords less useful. Breached-credential monitoring can identify known exposed passwords. Authentication logs should remain enabled so attack patterns can be detected and investigated. Residential IP addresses are not inherently trustworthy because botnets frequently use compromised consumer devices.

Question 140.

Which approach best supports secure adoption of autonomous remediation in a security operations environment?

  1. Automatically execute every alert response without validation.
    2. Use confidence thresholds, asset criticality, approval gates for disruptive actions, rollback capability, and full audit logging.
    3. Disable human oversight for all high-impact actions.
    4. Allow automation to modify its own logs.

Correct Answer: 2

Explanation:

Autonomous remediation can accelerate incident response, but incorrect actions can disrupt critical systems. Confidence thresholds and asset context help determine when automation is appropriate, while approval gates protect high-impact operations. Rollback provides recovery when an action produces unintended effects, and immutable audit logging supports accountability. Automation should be designed to reduce repetitive work without removing necessary safeguards around actions that could materially affect business operations.