{"id":24663,"date":"2026-09-29T11:56:39","date_gmt":"2026-09-29T11:56:39","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24663"},"modified":"2026-09-29T11:56:39","modified_gmt":"2026-09-29T11:56:39","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 81.<\/b><\/p>\n<p><b>A security architect needs to reduce the risk that a compromised SaaS account can be used to access sensitive enterprise data from an unmanaged device. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conditional access that evaluates identity, MFA strength, device compliance, and risk before granting access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanent allowlisting of all user IP addresses<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disabling MFA for trusted users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allowing access solely based on possession of a valid password<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional access evaluates multiple contextual factors before granting access, such as user identity, authentication strength, device compliance, location, application sensitivity, and current risk. This is stronger than relying on passwords or network location alone. An unmanaged device may lack required endpoint protections, encryption, or monitoring. A well-designed policy can block, restrict, or require stronger verification for risky sessions while still allowing legitimate access from compliant devices.<\/span><\/p>\n<p><b>Question 82.<\/b><\/p>\n<p><b>Which security architecture best protects a highly sensitive database from direct access by end-user workstations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Expose the database to the entire internal network.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable database authentication for trusted subnets.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow all users to connect with shared credentials.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Place the database in a restricted segment and require access through approved application tiers.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A restricted database segment combined with application-tier access reduces direct attack paths and limits the systems that can communicate with the database. Users interact with approved applications rather than connecting directly to the data tier. Shared credentials and unrestricted network access increase blast radius and weaken accountability. This design should be reinforced with service identities, least-privilege database permissions, encryption, monitoring, and explicit network allow rules.<\/span><\/p>\n<p><b>Question 83.<\/b><\/p>\n<p><b>An organization wants to detect unauthorized changes to infrastructure-as-code templates before they are deployed. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable version control.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Rely only on manual inspection after deployment.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require code review, protected branches, integrity checks, and policy-as-code validation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow direct changes to production from developer workstations.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Protected repositories, mandatory code review, integrity validation, and policy-as-code checks help identify unauthorized or insecure changes before infrastructure reaches production. Version control provides traceability, while branch protections and approval workflows reduce the risk of unreviewed modifications. Direct production changes from user workstations bypass important security controls. Automated policy checks can also detect insecure configurations such as public storage, overly permissive IAM roles, or missing encryption settings.<\/span><\/p>\n<p><b>Question 84.<\/b><\/p>\n<p><b>Which statement best describes the purpose of key rotation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need for access control.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It limits the period during which a compromised cryptographic key can remain useful.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees that encrypted data can never be exposed.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces certificate validation.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Key rotation replaces existing cryptographic keys with new ones according to policy or when compromise is suspected. This limits the useful lifetime of a stolen key and supports sound cryptographic hygiene. Rotation does not eliminate the need for access control, secure storage, auditing, or certificate validation. High-value keys should also be protected using appropriate hardware-backed controls, restricted administrative access, and documented lifecycle procedures.<\/span><\/p>\n<p><b>Question 85.<\/b><\/p>\n<p><b>A security operations team observes a sudden increase in outbound traffic from a server that normally communicates only with internal systems. What should the team do first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Validate the traffic, identify the destination, and investigate the associated process or account activity.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Immediately delete all server logs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable centralized monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Assume the behavior is legitimate because the server is internal.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unexpected outbound communication from a normally internal-only system may indicate malware, command-and-control traffic, data exfiltration, or an unauthorized configuration change. Analysts should identify the destination, process, user, timing, and data volume before deciding on containment. Deleting logs or disabling monitoring destroys useful evidence. Internal systems should not be considered trustworthy solely because of their network location, especially in a zero-trust architecture.<\/span><\/p>\n<p><b>Question 86.<\/b><\/p>\n<p><b>Which control best protects an organization&#8217;s root certificate authority private key?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store it in a shared network folder.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Place it in an administrator&#8217;s email account.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep it on a standard application server.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use offline or hardware-backed key protection with strict access controls.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A root certificate authority key is one of the most sensitive cryptographic assets in an enterprise. Offline or hardware-backed protection significantly reduces the risk of unauthorized extraction or use. Access should be tightly restricted, audited, and governed by strong procedures, often including separation of duties. Storing the key in ordinary user, application, or network locations exposes it to malware, credential theft, and administrative compromise.<\/span><\/p>\n<p><b>Question 87.<\/b><\/p>\n<p><b>Which practice most effectively reduces the attack surface of a production server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Install every available service in case it is needed later.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Enable all inbound ports.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove unnecessary services, software, accounts, and network exposure.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share local administrator accounts across systems.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack-surface reduction involves removing functions and access paths that are not required. Unnecessary services, packages, accounts, open ports, and administrative interfaces can all create exploitable opportunities. Hardening should be based on the server&#8217;s intended role and supported by patching, secure configuration, monitoring, and least privilege. Installing additional software or opening unnecessary ports increases rather than decreases exposure.<\/span><\/p>\n<p><b>Question 88.<\/b><\/p>\n<p><b>A company wants to reduce the risk of users approving malicious OAuth applications. Which control is best?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow any user to approve any application.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Restrict consent to approved applications and require administrative review for high-risk scopes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable logging of OAuth grants.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow applications to request unrestricted permissions.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OAuth consent phishing relies on users granting legitimate authorization tokens to malicious applications. Restricting user consent and requiring review for sensitive permissions reduces this risk. Organizations should also monitor newly registered applications, unusual consent events, and high-risk permission grants. Disabling logs or allowing unrestricted scopes reduces visibility and control. Approval workflows should balance usability with the sensitivity of requested access.<\/span><\/p>\n<p><b>Question 89.<\/b><\/p>\n<p><b>Which enterprise security capability is most useful for determining whether a newly discovered vulnerability is actually present in production applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Software inventory and SBOM correlation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A software inventory or software bill of materials allows security teams to identify which systems and applications contain a vulnerable component. When a new vulnerability is disclosed, the organization can quickly determine affected versions, prioritize critical assets, and begin remediation. DNS caching, NAT, and printer management do not provide software dependency visibility. Accurate inventory data is essential for effective vulnerability and supply-chain risk management.<\/span><\/p>\n<p><b>Question 90.<\/b><\/p>\n<p><b>Which control provides the strongest protection against unauthorized modification of audit logs by a compromised administrator?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store all logs locally on the administered system.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow administrators to delete logs without review.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable audit logging during maintenance.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Send logs to a separate tamper-resistant or immutable logging platform.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logs stored in a separate security boundary are harder for a compromised administrator to alter or delete. Immutability or write-once controls can provide even stronger protection against tampering. Local-only logs are vulnerable if the host or administrator account is compromised. Critical administrative, identity, security, and configuration events should be forwarded promptly and monitored for gaps or unusual changes.<\/span><\/p>\n<p><b>Question 91.<\/b><\/p>\n<p><b>Which cloud-security design best supports least privilege for serverless functions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every function the same administrator role.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use one shared access key for all functions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assign each function a narrowly scoped execution identity with only required permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable authentication for internal APIs.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Each serverless function should receive a distinct execution identity with only the permissions required for its intended task. This minimizes blast radius if the function or its dependencies are compromised. Shared administrator roles or common access keys create excessive privilege and make activity difficult to attribute. Fine-grained permissions should be combined with logging, secret management, network restrictions, dependency scanning, and short-lived credentials where available.<\/span><\/p>\n<p><b>Question 92.<\/b><\/p>\n<p><b>Which statement best describes the security purpose of microsegmentation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need for identity controls.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It limits communication between workloads to reduce lateral movement.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically patches every system.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces encryption.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation creates fine-grained boundaries between workloads, applications, or security zones. By permitting only required communication paths, it reduces the attacker&#8217;s ability to move laterally after compromising one system. Microsegmentation does not replace identity, encryption, patching, or endpoint controls. It is most effective when policies are based on workload identity, application requirements, and continuous monitoring rather than broad network trust.<\/span><\/p>\n<p><b>Question 93.<\/b><\/p>\n<p><b>A security team suspects a malicious insider is using approved cloud collaboration tools to move sensitive documents externally. Which data should be correlated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DLP events, cloud-sharing logs, file access records, and identity activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer toner levels<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNS TTL configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Backup media labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Insider data theft often involves legitimate tools, so correlating multiple contextual sources is essential. DLP events can identify sensitive content, cloud-sharing logs show external transfers, file access records reveal unusual collection behavior, and identity telemetry provides user context. None of these signals alone always proves malicious activity. Investigations should be performed according to organizational policy, legal requirements, and privacy obligations.<\/span><\/p>\n<p><b>Question 94.<\/b><\/p>\n<p><b>Which control best protects an API from clients attempting to submit malicious or malformed input?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all input validation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted request sizes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Trust requests from internal IP addresses automatically.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Enforce schema validation, input sanitization, and request-size limits.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Schema validation and input controls ensure that API requests conform to expected formats and size limits before application logic processes them. This reduces exposure to injection, malformed payloads, parser abuse, and resource-exhaustion attacks. Internal location does not make input trustworthy. API gateways, web application firewalls, authentication, authorization, rate limiting, and monitoring can provide additional layers of protection.<\/span><\/p>\n<p><b>Question 95.<\/b><\/p>\n<p><b>Which security approach is most appropriate when an enterprise must protect sensitive data used for machine-learning training?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Copy all production data into an unrestricted shared folder.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable access logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply data minimization, masking where possible, controlled access, and protected training environments.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give every data scientist unrestricted production access.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Machine-learning training can involve large volumes of sensitive information, so organizations should minimize the data used and remove or mask unnecessary identifiers where possible. Access should be restricted to authorized personnel and workloads, and training environments should be monitored and appropriately segmented. Logging should remain enabled to support accountability. Broad production access creates unnecessary risk and can expose regulated or confidential information.<\/span><\/p>\n<p><b>Question 96.<\/b><\/p>\n<p><b>Which statement best describes cryptographic agility?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It means using one algorithm forever.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It is the ability to replace cryptographic algorithms, protocols, or keys without redesigning the entire system.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for key management.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It requires disabling encryption during migration.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic agility allows an organization to adapt when algorithms become weak, standards change, or new cryptographic requirements emerge. Systems should avoid hard-coded assumptions that make algorithm or key replacement difficult. Agility supports migration planning for future cryptographic changes, including post-quantum transitions. It does not remove the need for secure key management, testing, compatibility planning, or controlled rollout procedures.<\/span><\/p>\n<p><b>Question 97.<\/b><\/p>\n<p><b>Which practice best reduces the risk that compromised developer credentials can modify production code directly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require protected branches, peer review, signed commits or artifacts, and controlled deployment pipelines.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give all developers direct write access to production systems.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable source-control audit logs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share deployment credentials across the development team.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Protected branches and review requirements prevent a single compromised account from modifying production-bound code without additional controls. Signed artifacts or commits strengthen integrity, while controlled deployment pipelines separate development access from production deployment privileges. Shared credentials and direct production access increase risk and weaken traceability. CI\/CD systems should also use short-lived credentials, isolated runners, approval gates, and extensive auditing.<\/span><\/p>\n<p><b>Question 98.<\/b><\/p>\n<p><b>Which behavior most strongly suggests persistence after a cloud account compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user runs a normal monthly report.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> An administrator updates a documented firewall rule.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A scheduled backup completes successfully.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A newly created access key or application credential appears immediately after suspicious login activity.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers often create new credentials, service principals, access keys, or application tokens to maintain access even if the original compromised session is revoked. Creation of new credentials immediately after suspicious authentication should therefore be investigated urgently. Responders should identify who created the credential, revoke unauthorized access, review permissions, inspect related activity, and determine whether additional persistence mechanisms were established.<\/span><\/p>\n<p><b>Question 99.<\/b><\/p>\n<p><b>Which security architecture most effectively protects sensitive internal services from lateral movement originating from compromised endpoints?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A flat internal network with broad trust<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared service credentials across all applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Zero-trust segmentation with explicit identity-aware access policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling east-west traffic monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero-trust segmentation requires explicit authorization for communication between users, devices, and workloads rather than assuming internal traffic is trustworthy. Identity-aware policies, device posture, service identity, and microsegmentation can significantly limit lateral movement. Flat networks and shared credentials expand attacker reach, while disabling monitoring reduces visibility. Strong east-west controls are especially important after an initial endpoint compromise.<\/span><\/p>\n<p><b>Question 100.<\/b><\/p>\n<p><b>Which approach best supports secure enterprise adoption of autonomous systems that can make high-impact operational changes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Grant permanent unrestricted administrator access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Constrain permissions, enforce independent authorization, log actions, test behavior, and require human approval for critical changes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable policy enforcement whenever automation is used.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow the autonomous system to modify its own audit records.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Autonomous systems should operate within tightly constrained security boundaries. Permissions should be narrowly scoped, policy enforcement should remain independent of the autonomous decision engine, and high-impact actions should require additional authorization or human approval. Detailed logs provide accountability and support investigations. Testing and monitoring are also necessary because unexpected behavior, malicious input, or model manipulation can otherwise cause significant operational or security impact.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 81. A security architect needs to reduce the risk that a compromised SaaS account can be used to access sensitive enterprise data from an unmanaged device. Which control is most appropriate? Conditional access that evaluates identity, MFA strength, device compliance, and risk [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24663"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24663"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24663\/revisions"}],"predecessor-version":[{"id":24664,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24663\/revisions\/24664"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}