{"id":24661,"date":"2026-09-29T11:56:18","date_gmt":"2026-09-29T11:56:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24661"},"modified":"2026-09-29T11:56:18","modified_gmt":"2026-09-29T11:56:18","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 61.<\/b><\/p>\n<p><b>A security architect wants to ensure that administrative access to critical servers originates only from hardened systems with verified security posture. Which solution is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Privileged access workstations combined with conditional access controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared administrator passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Unrestricted remote desktop access from any endpoint<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permanent local administrator rights for all IT staff<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privileged access workstations provide a hardened environment dedicated to sensitive administrative tasks. When combined with conditional access, the organization can require strong authentication, compliant device posture, approved network location, and other contextual conditions before privileged access is granted. Shared passwords and unrestricted remote access weaken accountability and expand the attack surface. Permanent administrative rights also create unnecessary standing privilege. A strong privileged-access architecture uses separate identities, hardened endpoints, MFA, session monitoring, least privilege, and just-in-time authorization where possible.<\/span><\/p>\n<p><b>Question 62.<\/b><\/p>\n<p><b>Which security technology best protects data while it is actively being processed in memory by a cloud workload?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full-disk encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Tokenization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network segmentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Confidential computing using a trusted execution environment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidential computing uses hardware-backed trusted execution environments to protect data while it is being processed. Traditional encryption at rest protects stored information, and TLS protects data in transit, but sensitive information normally must be decrypted for computation. A trusted execution environment helps isolate that processing from the host operating system, hypervisor, or other workloads. Tokenization and segmentation address different security concerns. Confidential computing is especially useful where sensitive data must be processed in infrastructure that is not fully trusted.<\/span><\/p>\n<p><b>Question 63.<\/b><\/p>\n<p><b>An attacker is suspected of stealing browser session cookies to bypass MFA. Which control most directly reduces the usefulness of stolen session tokens?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Longer password expiration periods<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static IP allowlisting only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Short-lived sessions with token revocation and device-bound validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling session logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Short-lived sessions reduce the amount of time a stolen token remains valid, while revocation enables defenders to invalidate active sessions when compromise is suspected. Device binding or other contextual validation can further restrict replay from an unauthorized environment. Password changes alone may not invalidate existing sessions. Static IP controls are often insufficient, especially for mobile or cloud users. Effective session security combines limited token lifetime, continuous validation, strong reauthentication for sensitive actions, and monitoring for anomalous session usage.<\/span><\/p>\n<p><b>Question 64.<\/b><\/p>\n<p><b>Which approach best protects an enterprise API against abuse by an authenticated but compromised client application?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow unlimited API requests after authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Apply fine-grained authorization, rate limiting, behavioral monitoring, and scoped tokens.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable API logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give every client a permanent administrator token.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication alone does not prevent an authenticated application from abusing an API. Fine-grained authorization limits what each client can do, while scoped tokens restrict accessible resources and actions. Rate limiting can reduce automated abuse, and behavioral monitoring can identify unusual request patterns. Permanent administrator tokens create excessive privilege, and disabling logging removes useful detection and forensic evidence. A mature API-security design also includes input validation, schema enforcement, secure secret management, and strong token lifecycle controls.<\/span><\/p>\n<p><b>Question 65.<\/b><\/p>\n<p><b>Which security control most directly reduces risk from a compromised CI\/CD pipeline attempting to deploy unauthorized infrastructure changes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require signed changes, protected branches, approval gates, and policy validation before deployment.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give the pipeline unrestricted administrator access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable audit logging for build systems.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow direct deployment from developer laptops.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Protected branches, approval gates, digital signing, policy validation, and controlled deployment identities reduce the chance that compromised pipeline components can make unauthorized production changes. Direct deployments and unrestricted administrator permissions dramatically increase supply-chain risk. Audit logging should be preserved so suspicious build or release activity can be investigated. Strong CI\/CD security also includes isolated runners, short-lived credentials, dependency scanning, protected signing keys, and separation between build and production administrative privileges.<\/span><\/p>\n<p><b>Question 66.<\/b><\/p>\n<p><b>Which mechanism provides the strongest assurance that a remote system booted using approved firmware and operating-system components?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNSSEC<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data masking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> RAID<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Measured boot with remote attestation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Measured boot records cryptographic measurements of firmware, bootloaders, and other components into trusted hardware such as a TPM. Remote attestation allows another system to verify those measurements against an expected state before granting sensitive access. DNSSEC protects DNS integrity, RAID provides storage resilience, and data masking protects sensitive values. Measured boot and attestation are particularly valuable in zero-trust device validation because they provide evidence about system integrity rather than relying only on credentials.<\/span><\/p>\n<p><b>Question 67.<\/b><\/p>\n<p><b>Which security practice best reduces the risk that an attacker can replace a legitimate software package with a malicious version in an internal repository?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable package verification.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit anonymous uploads.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Verify package signatures, restrict repository write access, and maintain provenance records.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow developers to install packages directly from unknown internet sources.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Signature verification helps detect unauthorized modification, while strict repository permissions prevent untrusted users from publishing or replacing packages. Provenance records provide traceability about where artifacts originated and how they were built. Anonymous uploads and arbitrary external package use increase supply-chain risk. Internal package repositories should also be monitored, patched, backed up, and integrated with dependency scanning and approval processes for higher-risk components.<\/span><\/p>\n<p><b>Question 68.<\/b><\/p>\n<p><b>Which security architecture is most appropriate for an enterprise that wants users to access internal applications without placing those applications directly on the public internet?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Expose every application through unrestricted inbound firewall rules.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use a zero-trust access broker or application proxy that authenticates users before providing application-level access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication for internal applications.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Require users to know the private IP address.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zero-trust application access solution can authenticate and authorize users before connecting them to private applications without exposing those applications directly to the internet. Access can be based on identity, device posture, risk, and application context. Knowing a private address does not provide security, and disabling authentication creates obvious risk. This model reduces reliance on broad network access and helps limit users to specific applications rather than granting access to entire internal subnets.<\/span><\/p>\n<p><b>Question 69.<\/b><\/p>\n<p><b>A threat hunter wants to identify possible credential dumping activity on Windows endpoints. Which data source is most valuable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint process and memory-access telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNS TTL settings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Backup schedules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential dumping often involves suspicious access to authentication-related processes, memory, registry data, or credential stores. Endpoint telemetry showing process creation, parent-child relationships, memory access, privilege use, and command execution can provide strong evidence. Printer inventory and backup schedules are unrelated. Threat hunters should correlate suspicious endpoint behavior with authentication events, privilege escalation, unusual account activity, and network connections to build a stronger picture of potential credential theft.<\/span><\/p>\n<p><b>Question 70.<\/b><\/p>\n<p><b>Which capability best detects unauthorized transfer of sensitive information through approved collaboration applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Static NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Cloud access security and DLP controls integrated with sanctioned SaaS applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud access security and DLP controls can inspect activity in approved SaaS applications and apply policies based on data sensitivity, user identity, destination, and sharing behavior. This is important because legitimate collaboration tools can still be used to exfiltrate data. RAID, DNS caching, and NAT do not provide content-aware data protection. Effective SaaS governance also includes data classification, access controls, audit logging, sharing restrictions, and monitoring of risky user or application behavior.<\/span><\/p>\n<p><b>Question 71.<\/b><\/p>\n<p><b>A company wants to ensure that highly privileged cloud roles are not assigned permanently. Which access model is best?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent administrator access for all engineers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared root credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Just-in-time privilege elevation with approval and automatic expiration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Anonymous administrative access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time privilege elevation provides administrative permissions only when required and automatically removes them after the approved period. This reduces standing privilege and limits the impact of stolen credentials. Shared root accounts and permanent administrative access increase blast radius and reduce accountability. JIT privilege should be combined with strong MFA, approval workflows, logging, session monitoring, and emergency access procedures so privileged operations remain controlled and auditable.<\/span><\/p>\n<p><b>Question 72.<\/b><\/p>\n<p><b>Which statement best describes data tokenization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It encrypts an entire disk using one symmetric key.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It substitutes sensitive values with non-sensitive tokens while maintaining the original values in a protected system.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It provides network segmentation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It verifies firmware integrity.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tokenization replaces sensitive values with surrogate tokens that have little or no exploitable meaning outside the tokenization system. The original values remain protected in a secure vault or service. This can reduce exposure of payment or personal data in applications that do not need the original value. Tokenization differs from ordinary encryption because the token itself may not be mathematically reversible without the token service. It does not provide network segmentation or device integrity validation.<\/span><\/p>\n<p><b>Question 73.<\/b><\/p>\n<p><b>Which incident response action is most appropriate immediately after confirming that a cloud access key has been exposed publicly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke or rotate the key and investigate its recent use.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Wait until the key expires naturally.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete audit logs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase the key&#8217;s permissions to simplify troubleshooting.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Once a cloud access key is exposed, it should be treated as compromised. Revoking or rotating the credential limits further misuse, while audit logs should be reviewed to determine whether the key was already abused. Waiting for natural expiration leaves a window for attackers, and increasing permissions would worsen the potential impact. Responders should also identify where the secret was exposed, remove it from repositories or systems, and improve controls to prevent similar leaks.<\/span><\/p>\n<p><b>Question 74.<\/b><\/p>\n<p><b>Which design best protects a critical application from denial of service caused by traffic spikes from many distributed internet sources?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a single unprotected origin server.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable rate limiting.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Publish the origin IP directly.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use distributed DDoS protection, rate controls, resilient scaling, and protected origins.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Distributed DDoS protection can absorb or filter malicious traffic before it reaches the application, while rate controls and scalable architecture reduce the impact of traffic spikes. Protecting the origin prevents attackers from bypassing the mitigation service and targeting the backend directly. A single exposed server is a major availability risk. DDoS resilience should also include capacity planning, monitoring, upstream provider coordination, and tested incident procedures.<\/span><\/p>\n<p><b>Question 75.<\/b><\/p>\n<p><b>Which security control most directly prevents developers from deploying infrastructure that violates mandatory cloud-security requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Manual review after production deployment only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Rely exclusively on developer memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Policy-as-code checks integrated into the deployment pipeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable infrastructure version control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy-as-code allows security requirements to be automatically evaluated before infrastructure is deployed. Controls can check for prohibited public exposure, missing encryption, overly broad IAM permissions, insecure network rules, and other configuration risks. Automated enforcement is more consistent than relying solely on memory or post-deployment review. Infrastructure-as-code should also use version control, peer review, testing, and controlled deployment identities to improve security and traceability.<\/span><\/p>\n<p><b>Question 76.<\/b><\/p>\n<p><b>Which statement best describes the purpose of canary tokens in security monitoring?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They provide disk encryption.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> They are decoy resources or credentials designed to generate alerts when accessed unexpectedly.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> They replace MFA.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> They increase network bandwidth.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Canary tokens are deceptive resources, documents, URLs, credentials, or other artifacts that legitimate users should not normally access. Unexpected interaction can provide a high-value signal of unauthorized activity. They can support early detection of lateral movement, data theft, or reconnaissance. Canary tokens do not replace authentication, encryption, or other controls. They are most effective when alerts are monitored and linked to a well-defined investigation or response process.<\/span><\/p>\n<p><b>Question 77.<\/b><\/p>\n<p><b>Which approach best protects sensitive production credentials from exposure in application configuration files?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a secrets manager and retrieve credentials dynamically at runtime.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store credentials in plaintext files.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Commit secrets to version control.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use the same credential in every environment.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secrets manager centralizes credential storage, access control, rotation, auditing, and controlled retrieval. Applications can request credentials at runtime rather than embedding them in files or source code. Reusing the same secret across environments increases blast radius, while committing credentials to repositories can expose them broadly and persistently. Dynamic secrets and workload identities are even stronger where available because they reduce reliance on long-lived static credentials.<\/span><\/p>\n<p><b>Question 78.<\/b><\/p>\n<p><b>Which behavior is most suspicious for a potential cloud account takeover?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A scheduled compliance report runs at its normal time.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A user views a routine dashboard.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> An approved application renews a certificate.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A user authenticates from a new device and immediately creates privileged credentials and disables logging.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A new-device login followed immediately by creation of privileged credentials and attempts to disable logging is highly suspicious. Attackers often try to establish persistence, elevate privilege, and reduce visibility soon after compromising an account. Routine reports, dashboard access, and expected certificate renewal are generally benign. Incident responders should verify the identity, revoke suspicious sessions, review changes, restore logging, and investigate other activity performed by the account.<\/span><\/p>\n<p><b>Question 79.<\/b><\/p>\n<p><b>Which security design best reduces risk when multiple applications need access to the same sensitive data set but require different operations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every application full read-write access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use one shared administrator account.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Create separate service identities and grant each only the specific operations it requires.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable authorization checks.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate service identities support least privilege because each application can receive only the operations required for its function. If one workload is compromised, the attacker&#8217;s permissions remain limited to that application&#8217;s role. Shared administrator accounts and unrestricted permissions create excessive blast radius and poor accountability. Strong service authorization should also include credential rotation, workload identity, logging, and segmentation so application access can be monitored and controlled effectively.<\/span><\/p>\n<p><b>Question 80.<\/b><\/p>\n<p><b>Which approach best supports secure use of autonomous AI agents that can perform actions in enterprise systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give the agent permanent global administrator permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Restrict available tools and permissions, validate actions against policy, log decisions, and require approval for high-impact operations.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable authentication for any system accessed by the agent.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow every model-generated command to execute automatically.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Autonomous agents should operate under tightly constrained permissions because model errors, prompt injection, malicious inputs, or unexpected reasoning can lead to harmful actions. Tool access should be limited to required functions, authorization enforced independently of the model, and high-impact operations gated by approval. Detailed logging supports accountability and investigation. Treating an AI agent as a fully trusted administrator creates an unnecessarily large blast radius if the model is manipulated or behaves incorrectly.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 61. A security architect wants to ensure that administrative access to critical servers originates only from hardened systems with verified security posture. Which solution is most appropriate? Privileged access workstations combined with conditional access controls 2. Shared administrator passwords 3. Unrestricted remote [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24661"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24661"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24661\/revisions"}],"predecessor-version":[{"id":24662,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24661\/revisions\/24662"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}