CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part9 Q161-180

View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps

 

Question 161.

A security architect wants to ensure that administrative access to a critical cloud environment is allowed only from trusted devices using strong authentication. Which control is most appropriate?

  1. Conditional access requiring phishing-resistant MFA and compliant device posture
    2. Password-only authentication from any device
    3. Shared administrator accounts
    4. Permanent access from any internal IP address

Correct Answer: 1

Explanation:

Conditional access can evaluate authentication strength, device posture, location, user risk, and requested resources before allowing privileged access. Requiring phishing-resistant MFA and a compliant managed device significantly reduces the risk of stolen passwords or unmanaged endpoints being used for administration. Shared accounts weaken accountability, while source IP alone is an unreliable trust signal. Privileged cloud access should also use just-in-time elevation, least privilege, session logging, and continuous monitoring for anomalous administrative activity.

Question 162.

Which security architecture best protects sensitive workloads from unauthorized east-west communication inside a data center?

  1. Flat Layer 2 networking
    2. Unrestricted internal routing
    3. Shared service accounts
    4. Microsegmentation with explicit application-aware access policies

Correct Answer: 4

Explanation:

Microsegmentation limits communication between workloads according to approved application requirements rather than assuming internal traffic is trusted. This can significantly reduce lateral movement after compromise. Flat networks and unrestricted internal routing increase the number of reachable systems, while shared service identities weaken isolation and accountability. Effective microsegmentation can use workload identity, tags, application context, and least-privilege rules to permit only necessary communication between services and security zones.

Question 163.

A security team wants to determine whether a newly disclosed vulnerability affects any software currently deployed in the enterprise. Which resource is most useful?

  1. DNS cache records
    2. Printer inventories
    3. Software inventory and software bills of materials
    4. Network address translation tables

Correct Answer: 3

Explanation:

A current software inventory and SBOM provide visibility into installed applications, libraries, and dependencies. When a new vulnerability is disclosed, security teams can determine which systems or applications contain the affected component and prioritize remediation accordingly. DNS caches and NAT tables do not provide dependency information. Accurate software inventories support vulnerability management, incident response, licensing, and supply-chain risk analysis, especially when third-party components are embedded deeply within enterprise applications.

Question 164.

Which control best reduces the risk of session hijacking when a web application uses bearer tokens?

  1. Increase token lifetime.
    2. Use short-lived tokens, secure cookie attributes, revocation, and contextual session validation.
    3. Allow tokens to be transmitted over HTTP.
    4. Store tokens in publicly accessible application logs.

Correct Answer: 2

Explanation:

Short-lived tokens reduce the period during which a stolen bearer token can be abused. Secure cookie settings, revocation mechanisms, TLS, and contextual validation such as device or risk checks further limit session hijacking. Increasing token lifetime creates more exposure, while transmitting or logging tokens insecurely can directly leak credentials. Sensitive operations may also require reauthentication or step-up verification rather than relying solely on an existing session.

Question 165.

An enterprise wants to reduce the risk of malicious insiders accessing encryption keys used for customer data. Which design is strongest?

  1. Store keys in an HSM with separation of duties and tightly controlled administrative access.
    2. Store keys in plaintext next to the encrypted data.
    3. Share one key-management administrator account.
    4. Email backup copies of keys to system administrators.

Correct Answer: 1

Explanation:

An HSM can protect key material from direct extraction while enforcing controlled cryptographic operations. Separation of duties prevents a single administrator from having unrestricted control over high-value keys, while individual identities and audit logging improve accountability. Storing keys beside encrypted data or distributing them through email defeats much of the protection encryption is intended to provide. Key management should also include lifecycle controls, rotation, backup, revocation, and recovery procedures.

Question 166.

Which approach best protects production workloads from vulnerable or malicious container images?

  1. Allow images from any registry.
    2. Disable signature verification.
    3. Give every container privileged host access.
    4. Enforce trusted registries, image scanning, signature validation, and admission policies.

Correct Answer: 4

Explanation:

A strong container supply-chain control validates where an image originated, whether it contains known vulnerabilities, and whether its signature and provenance meet policy before deployment. Admission policies can block noncompliant workloads automatically. Arbitrary registries and privileged containers increase risk, while disabling signature checks removes an important integrity safeguard. Runtime monitoring, minimal images, restricted capabilities, and regular dependency updates further strengthen container security.

Question 167.

Which security capability is most useful for detecting unusual activity by machine identities and service accounts?

  1. RAID monitoring
    2. File compression
    3. User and entity behavior analytics
    4. Static routing

Correct Answer: 3

Explanation:

Service accounts often perform highly predictable actions, making behavioral deviations especially useful for detection. UEBA can identify anomalies such as new login locations, unusual APIs, unexpected privilege use, or abnormal access times. Static routing, RAID, and compression do not provide identity behavior analysis. Machine identities should also be inventoried, monitored, rotated, and granted narrowly scoped permissions because compromised service credentials can provide attackers with persistent access.

Question 168.

Which statement best describes the security benefit of immutable infrastructure?

  1. Administrators modify production servers manually whenever possible.
    2. Systems are replaced with approved images rather than changed extensively in place.
    3. Logging is disabled to reduce configuration changes.
    4. Every server keeps a unique undocumented configuration.

Correct Answer: 2

Explanation:

Immutable infrastructure reduces configuration drift by replacing systems with approved, version-controlled images rather than relying on repeated manual changes. This supports consistency, reproducibility, and stronger change control. If a system is compromised or misconfigured, it can be rebuilt from a trusted image instead of repaired manually. The model works best with automated deployment, signed artifacts, infrastructure as code, centralized logs, and secure image pipelines.

Question 169.

A company detects repeated access attempts to a cloud metadata endpoint from a public-facing application. Which threat should be investigated first?

  1. Server-side request forgery
    2. Password spraying
    3. DNS poisoning
    4. ARP spoofing

Correct Answer: 1

Explanation:

Cloud metadata endpoints often expose temporary credentials or instance information to workloads. If a public-facing application can be manipulated into requesting metadata URLs, this may indicate server-side request forgery. Successful SSRF could allow an attacker to obtain credentials or access internal resources. Defenses include strict URL validation, metadata protections, outbound filtering, and least-privilege workload roles. Password spraying, DNS poisoning, and ARP spoofing do not best explain this behavior.

Question 170.

Which security control provides the strongest protection for privileged emergency accounts?

  1. Use them for routine administration.
    2. Share them across teams.
    3. Exempt them from monitoring.
    4. Store them securely, require strong MFA, restrict use, and alert on every authentication.

Correct Answer: 4

Explanation:

Emergency or break-glass accounts should be highly protected because they often have extensive privileges and may bypass normal access paths. Credentials should be secured, use strong authentication where possible, and be accessed only under documented emergency procedures. Every use should generate immediate monitoring and review. Routine use, shared access, or monitoring exemptions undermine accountability and increase the chance that a compromise will go unnoticed.

Question 171.

Which control best reduces the risk that a malicious developer can secretly insert unauthorized code into a production release?

  1. Disable peer review.
    2. Allow direct production deployments from laptops.
    3. Require protected branches, independent review, signed artifacts, and controlled release pipelines.
    4. Share deployment credentials among all developers.

Correct Answer: 3

Explanation:

Protected branches and independent review reduce the chance that one developer can make unapproved changes without oversight. Signed artifacts and controlled release pipelines provide integrity and traceability from source to production. Direct deployment and shared credentials weaken separation of duties and accountability. Strong software-release security also includes CI/CD isolation, short-lived deployment credentials, dependency scanning, and audit logs that cannot be easily altered by developers.

Question 172.

Which statement best describes a compensating control?

  1. It removes all risk permanently.
    2. It provides an alternative safeguard when the preferred control cannot be implemented.
    3. It always replaces the need for remediation.
    4. It is used only for physical security.

Correct Answer: 2

Explanation:

A compensating control provides alternative risk reduction when the preferred or required safeguard cannot be implemented immediately or technically. For example, additional segmentation and monitoring might temporarily reduce risk when a legacy system cannot be patched. The control should provide meaningful protection appropriate to the identified risk. Compensating controls do not automatically eliminate the need for eventual remediation, and their effectiveness should be reviewed and documented.

Question 173.

A security team suspects malicious use of PowerShell on several endpoints. Which evidence should be correlated first?

  1. PowerShell logs, process creation events, parent-child relationships, and network connections
    2. Printer queue data
    3. Backup media labels
    4. Monitor resolution settings

Correct Answer: 1

Explanation:

PowerShell can be used legitimately or maliciously, so context is essential. Script-block logging, command-line data, process ancestry, user identity, and network connections can help determine whether execution is suspicious. Analysts should look for encoded commands, unusual parent processes, downloads, credential access, and connections to unexpected destinations. Printer and display information provide little value for this investigation. Behavioral correlation is more effective than blocking PowerShell indiscriminately.

Question 174.

Which architecture best protects backup systems from ransomware that has compromised production identity services?

  1. Use the same identities and passwords everywhere.
    2. Keep backups continuously writable from production.
    3. Allow production administrators unrestricted deletion rights.
    4. Use separate recovery identities, immutable storage, and isolated backup administration.

Correct Answer: 4

Explanation:

Separate recovery identities reduce dependence on compromised production authentication systems, while immutable backups prevent unauthorized modification or deletion during protected retention periods. Isolated administration further limits attacker reach. Shared credentials and continuously writable backups create common failure paths that ransomware can exploit. Recovery environments should also be regularly tested so isolation and security controls do not prevent the organization from meeting restoration objectives.

Question 175.

Which control most directly reduces the impact of credential theft from a CI/CD system?

  1. Use permanent cloud administrator keys.
    2. Store credentials in source repositories.
    3. Use short-lived workload credentials with narrowly scoped permissions.
    4. Disable pipeline logging.

Correct Answer: 3

Explanation:

Short-lived credentials reduce the useful lifetime of stolen secrets, while narrowly scoped permissions limit what a compromised build or deployment system can do. Workload identity federation can further eliminate the need for static access keys. Permanent administrator keys and source-controlled credentials create substantial supply-chain risk. Logging should remain enabled to provide evidence of unusual builds, access, or deployments.

Question 176.

Which statement best describes the purpose of attack surface management?

  1. It focuses only on internal antivirus signatures.
    2. It identifies and evaluates exposed assets, services, and attack paths that may be reachable by adversaries.
    3. It replaces vulnerability remediation.
    4. It eliminates the need for asset inventory.

Correct Answer: 2

Explanation:

Attack surface management helps organizations discover and evaluate exposed systems, domains, cloud services, applications, and other assets that attackers may target. It can identify unknown or unmanaged resources, misconfigurations, and internet-facing services that increase risk. It complements vulnerability management rather than replacing it. Accurate asset inventory remains essential because security teams cannot effectively protect resources they do not know exist.

Question 177.

Which practice best supports secure decommissioning of a cloud application?

  1. Revoke credentials, remove data as required, disable integrations, and verify residual resources are deleted or retained appropriately.
    2. Leave access keys active in case the application returns.
    3. Keep abandoned public storage buckets indefinitely.
    4. Ignore third-party integrations.

Correct Answer: 1

Explanation:

Secure decommissioning requires more than shutting down the primary application. Credentials, service accounts, API integrations, data stores, DNS records, backups, secrets, and cloud resources should be reviewed and handled according to retention and business requirements. Leaving active keys or abandoned public resources creates unnecessary attack surface. Decommissioning should be documented so teams can confirm that residual access paths and sensitive data have been addressed.

Question 178.

Which behavior most strongly suggests possible privilege escalation in a cloud environment?

  1. A scheduled report runs normally.
    2. A user views a standard dashboard.
    3. A service completes its usual health check.
    4. A low-privilege identity suddenly modifies role-assignment policies and assumes an administrative role.

Correct Answer: 4

Explanation:

A low-privilege identity modifying authorization policy and then assuming an administrative role is a strong indicator of privilege escalation or account abuse. Security teams should review how the identity gained permission to change roles, inspect related API calls, revoke suspicious sessions, and validate subsequent administrative activity. Routine reporting or health checks do not present the same risk. Cloud authorization changes should be closely monitored because they can rapidly expand attacker access.

Question 179.

Which security design best reduces the risk of sensitive information leaking through generative AI prompts?

  1. Permit all employees to submit unrestricted regulated data to any model.
    2. Disable all AI usage logs.
    3. Enforce approved AI services, data classification rules, DLP controls, and restrictions on sensitive inputs.
    4. Give AI tools direct administrator access to all corporate data.

Correct Answer: 3

Explanation:

Approved AI services should be governed according to the sensitivity of information they process. Data classification and DLP can help prevent users from submitting regulated, confidential, or proprietary information to inappropriate models. Logging supports investigation and policy enforcement, while access should follow least privilege. Organizations should also evaluate retention, model-training terms, third-party data handling, prompt injection, and output leakage risks before integrating AI into sensitive workflows.

Question 180.

Which approach best supports long-term security resilience in a complex hybrid enterprise?

  1. Assume controls remain effective after initial deployment.
    2. Continuously validate controls, review architecture, exercise incident recovery, monitor identity and workload risk, and remediate discovered gaps.
    3. Test security only after a major incident.
    4. Disable telemetry to reduce operational complexity.

Correct Answer: 2

Explanation:

Enterprise environments continuously change as applications, identities, cloud resources, dependencies, and threats evolve. Security controls therefore require repeated validation rather than one-time deployment. Architecture reviews, purple-team exercises, recovery tests, telemetry analysis, vulnerability remediation, and control validation provide evidence that safeguards still work. Continuous improvement helps organizations detect drift, hidden dependencies, and failed assumptions before attackers exploit them.