{"id":24667,"date":"2026-09-29T11:57:10","date_gmt":"2026-09-29T11:57:10","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24667"},"modified":"2026-09-29T11:57:10","modified_gmt":"2026-09-29T11:57:10","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 121.<\/b><\/p>\n<p><b>A security architect needs to reduce the risk that a compromised endpoint can use existing user credentials to access highly sensitive applications. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require phishing-resistant MFA and device posture validation for sensitive access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trust any session originating from the internal network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable reauthentication for privileged actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Grant permanent access once a user authenticates successfully<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phishing-resistant MFA combined with device posture validation reduces reliance on passwords and network location alone. Even if an endpoint or password is compromised, the attacker may still be unable to satisfy hardware-backed authentication and device compliance requirements. Sensitive applications can also require step-up authentication and continuous risk evaluation. Permanent trust after initial login creates excessive exposure, while internal network location does not prove that the user or device remains trustworthy.<\/span><\/p>\n<p><b>Question 122.<\/b><\/p>\n<p><b>Which security approach best protects an enterprise from malicious changes to production infrastructure templates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow direct editing of production resources.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable repository history.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use unsigned templates with no review.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store infrastructure as code in protected repositories with review, signing, and automated policy checks.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Protected infrastructure-as-code repositories provide traceability, version control, peer review, and controlled deployment. Digital signatures or other integrity mechanisms can help verify approved artifacts, while policy-as-code can identify insecure configuration before deployment. Direct manual modification bypasses these controls and creates configuration drift. Strong IaC governance also uses separate deployment identities, change logging, and rollback capability so unauthorized or unsafe changes can be detected and reversed.<\/span><\/p>\n<p><b>Question 123.<\/b><\/p>\n<p><b>A company wants to detect suspicious administrative commands executed through remote management tools. Which telemetry is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Printer queue statistics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Backup media inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Endpoint process creation and command-line logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS cache size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Process creation and command-line telemetry can reveal which administrative tools were executed, what arguments were supplied, and which user initiated the activity. This is valuable for detecting malicious use of legitimate remote-management utilities. Analysts can correlate the endpoint data with authentication events, network connections, privilege changes, and remote-session logs. Printer queues and DNS cache size provide little relevant evidence for this type of behavior.<\/span><\/p>\n<p><b>Question 124.<\/b><\/p>\n<p><b>Which control best reduces the risk of an application using excessive permissions after its service account is compromised?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Grant the account administrator rights to simplify operations.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Apply least-privilege permissions and narrowly scoped resource access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share the service account across applications.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable service-account logging.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits a service account to the exact operations and resources required by the application. If the credential or workload is compromised, the attacker inherits only a constrained set of permissions. Shared accounts and broad administrator roles significantly increase blast radius. Service-account activity should also be logged, monitored, and periodically reviewed, while long-lived credentials should be rotated or replaced by workload identity where possible.<\/span><\/p>\n<p><b>Question 125.<\/b><\/p>\n<p><b>An organization suspects that a cloud administrator is exfiltrating sensitive data using legitimate APIs. Which approach provides the strongest detection capability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Correlate cloud audit logs, data-access events, identity behavior, and outbound transfer patterns<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable cloud logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Rely only on malware signatures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor only failed login attempts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Legitimate API calls can still be used maliciously by an insider or compromised privileged account. Cloud control-plane logs, data-access logs, identity context, and transfer volume provide a stronger behavioral view than malware detection alone. Security teams should look for unusual resource enumeration, bulk downloads, atypical destinations, privilege changes, and deviations from the administrator&#8217;s normal activity. Correlation across multiple data sources improves confidence and helps distinguish legitimate work from misuse.<\/span><\/p>\n<p><b>Question 126.<\/b><\/p>\n<p><b>Which design best protects secrets used by serverless workloads?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Embed credentials in function source code.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Put secrets in public environment variables.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store one shared password in every function package.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Retrieve secrets dynamically from a managed secrets service using workload identity.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A managed secrets service combined with workload identity avoids embedding static credentials in code or deployment packages. The function authenticates using its own identity and retrieves only the secrets it is authorized to use. This supports centralized rotation, logging, and least privilege. Shared or hard-coded secrets are difficult to rotate and may be exposed through source repositories, build artifacts, logs, or configuration snapshots.<\/span><\/p>\n<p><b>Question 127.<\/b><\/p>\n<p><b>Which control is most appropriate for detecting unauthorized changes to critical application binaries?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RAID<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> File integrity monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">File integrity monitoring detects changes to critical files by comparing their current state with a known-good baseline or expected cryptographic hash. This can reveal unauthorized modification of application binaries, libraries, configuration files, or scripts. NAT, RAID, and DNS caching do not provide file-level integrity validation. FIM alerts should be correlated with approved change records so legitimate maintenance can be distinguished from suspicious tampering.<\/span><\/p>\n<p><b>Question 128.<\/b><\/p>\n<p><b>Which statement best describes the security benefit of workload identity federation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It requires every application to store a permanent cloud access key.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It allows workloads to obtain short-lived credentials based on trusted identity relationships instead of static secrets.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for authorization.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It makes all workloads administrators.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload identity federation allows applications or external workloads to exchange a trusted identity assertion for short-lived cloud credentials. This reduces reliance on long-lived static access keys that can be leaked or forgotten. The resulting credentials should still be narrowly scoped through authorization policies. Federation does not eliminate authorization or justify administrator-level permissions. It is particularly useful in CI\/CD, multicloud, and external workload scenarios.<\/span><\/p>\n<p><b>Question 129.<\/b><\/p>\n<p><b>Which response is most appropriate when an organization confirms that a code-signing certificate private key has been stolen?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke the certificate, rotate the key, investigate signed artifacts, and notify affected stakeholders as required.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Continue using the key until its normal expiration.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete audit logs associated with signing.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Publish the private key so users can verify it.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A stolen code-signing private key can allow attackers to create malicious software that appears legitimate. The organization should revoke the affected certificate, generate a new protected key, investigate whether unauthorized artifacts were signed, and communicate with downstream consumers where necessary. Continuing to use the key extends the risk. Signing logs and build records should be preserved because they may be essential for determining the scope of compromise.<\/span><\/p>\n<p><b>Question 130.<\/b><\/p>\n<p><b>Which architecture best limits an attacker&#8217;s ability to move from a compromised user subnet into a production server environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one flat network.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow any authenticated user to reach all servers.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable internal firewalling.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use segmentation with explicit access controls between user, server, and management zones.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segmentation creates controlled boundaries between user networks, production servers, management systems, and other security zones. Explicit allow rules ensure only required communication paths are permitted. This reduces lateral movement after endpoint compromise. Flat networks and broad access policies make it easier for attackers to reach valuable systems. Segmentation should be combined with identity-aware access, endpoint controls, logging, and restricted administrative pathways for stronger protection.<\/span><\/p>\n<p><b>Question 131.<\/b><\/p>\n<p><b>Which control best protects an enterprise from developers accidentally introducing vulnerable third-party packages into production?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable dependency tracking.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow arbitrary packages from unknown repositories.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use software composition analysis and trusted dependency repositories in the CI\/CD pipeline.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all automated build checks.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software composition analysis identifies known vulnerable or risky third-party dependencies before release. Trusted repositories and allowlists further reduce the chance that malicious or unapproved packages enter the build process. Dependency scanning should be combined with SBOM generation, version pinning, integrity verification, and timely remediation. Disabling dependency visibility or automated checks increases software supply-chain risk.<\/span><\/p>\n<p><b>Question 132.<\/b><\/p>\n<p><b>Which statement best describes the purpose of differential privacy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It encrypts all network traffic.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It adds controlled statistical noise to help protect individual privacy in aggregate analysis.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It provides disk redundancy.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Differential privacy introduces carefully calibrated noise into statistical outputs so useful aggregate analysis can be performed while reducing the ability to infer information about specific individuals. It is particularly relevant in large data sets and privacy-preserving analytics. It does not provide transport encryption, authentication, or storage redundancy. Effective use requires careful selection of privacy parameters and an understanding of how repeated queries can affect the privacy budget.<\/span><\/p>\n<p><b>Question 133.<\/b><\/p>\n<p><b>Which action should an incident responder take after identifying a malicious persistence mechanism that creates new privileged cloud credentials?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove the persistence, revoke unauthorized credentials, preserve evidence, and investigate related activity.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Leave the credentials active for convenience.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all audit logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase the malicious credentials&#8217; permissions.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Once malicious persistence is confirmed, responders should revoke unauthorized credentials and remove the persistence mechanism while preserving evidence needed to determine scope and root cause. They should also examine related identities, sessions, role assignments, API calls, and resource changes. Disabling logging or leaving malicious credentials active would increase risk. Containment should be coordinated with forensic and business requirements so critical evidence is not unnecessarily destroyed.<\/span><\/p>\n<p><b>Question 134.<\/b><\/p>\n<p><b>Which control provides the strongest protection for a root cryptographic key used to issue subordinate certificates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store it in a developer workstation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Put it in a shared cloud folder.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Email it to backup administrators.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Keep it offline or inside a highly controlled hardware security module.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root certificate authority keys are extremely sensitive because compromise can undermine trust throughout the PKI. Offline storage or an HSM reduces exposure to normal network and endpoint attacks. Access should be tightly controlled, audited, and often require multiple authorized individuals for sensitive operations. Ordinary workstations, shared folders, and email provide inadequate protection for such a critical cryptographic asset.<\/span><\/p>\n<p><b>Question 135.<\/b><\/p>\n<p><b>Which security technique best reduces the risk of sensitive customer information appearing in lower-security test environments?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Copy the full production database to every test server.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give testers administrator access to production data.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use masked, anonymized, or synthetic test data.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable encryption in nonproduction environments.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Masked, anonymized, or synthetic data reduces the exposure of real customer information while still allowing developers and testers to exercise application functionality. Copying production data into lower-security environments expands privacy and compliance risk. Nonproduction systems should still use strong access controls, encryption, and monitoring because they are often attractive targets. Data minimization is a key principle when production identifiers are not necessary for testing.<\/span><\/p>\n<p><b>Question 136.<\/b><\/p>\n<p><b>Which statement best describes the purpose of security chaos engineering?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It intentionally disables all security controls in production.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It safely tests how systems and teams respond when security controls or assumptions fail.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces penetration testing entirely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It guarantees that incidents cannot occur.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security chaos engineering introduces controlled, planned failure scenarios to test whether security assumptions, controls, monitoring, and response processes work as expected. Examples might include simulating credential loss, service isolation, or security-control degradation in a safe environment. It does not mean indiscriminately disabling protections or replacing other testing methods. The goal is to discover hidden dependencies and improve resilience before real incidents expose them.<\/span><\/p>\n<p><b>Question 137.<\/b><\/p>\n<p><b>Which practice best supports secure management of privileged cloud roles?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use just-in-time elevation, strong MFA, approval workflows, and session logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assign permanent global administrator access to all engineers.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share one root account.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable privileged-access auditing.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time elevation reduces standing privilege by granting sensitive roles only when needed. Strong MFA protects authentication, approval workflows support oversight, and session or activity logging provides accountability. Permanent broad administrator access and shared root credentials greatly increase risk. Privileged access should be regularly reviewed, and unused roles or accounts should be removed promptly.<\/span><\/p>\n<p><b>Question 138.<\/b><\/p>\n<p><b>Which activity most strongly suggests a supply-chain compromise in a CI\/CD environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A scheduled build completes normally.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A developer reads build documentation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A routine unit test passes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> An unapproved build runner begins signing production artifacts using a newly added credential.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An unapproved build runner using a newly introduced signing credential is highly suspicious because it could allow malicious artifacts to be produced and presented as legitimate. Security teams should immediately validate the runner, credential creation, signing history, pipeline changes, and artifact provenance. Signing keys should be tightly protected, and build systems should use controlled identities, approved runners, immutable logs, and separation of duties.<\/span><\/p>\n<p><b>Question 139.<\/b><\/p>\n<p><b>Which security approach best protects internet-facing APIs from automated credential-stuffing attacks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication logs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow unlimited login attempts.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use rate limiting, bot detection, strong MFA, and breached-credential monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust all requests from residential IP addresses.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credential stuffing uses large numbers of stolen username and password combinations against authentication endpoints. Rate limiting and bot controls reduce automated attempts, while MFA makes stolen passwords less useful. Breached-credential monitoring can identify known exposed passwords. Authentication logs should remain enabled so attack patterns can be detected and investigated. Residential IP addresses are not inherently trustworthy because botnets frequently use compromised consumer devices.<\/span><\/p>\n<p><b>Question 140.<\/b><\/p>\n<p><b>Which approach best supports secure adoption of autonomous remediation in a security operations environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically execute every alert response without validation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use confidence thresholds, asset criticality, approval gates for disruptive actions, rollback capability, and full audit logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable human oversight for all high-impact actions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow automation to modify its own logs.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Autonomous remediation can accelerate incident response, but incorrect actions can disrupt critical systems. Confidence thresholds and asset context help determine when automation is appropriate, while approval gates protect high-impact operations. Rollback provides recovery when an action produces unintended effects, and immutable audit logging supports accountability. Automation should be designed to reduce repetitive work without removing necessary safeguards around actions that could materially affect business operations.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 121. A security architect needs to reduce the risk that a compromised endpoint can use existing user credentials to access highly sensitive applications. Which control is most appropriate? Require phishing-resistant MFA and device posture validation for sensitive access 2. Trust any session [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24667"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24667"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24667\/revisions"}],"predecessor-version":[{"id":24668,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24667\/revisions\/24668"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}