{"id":24669,"date":"2026-09-29T11:57:25","date_gmt":"2026-09-29T11:57:25","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24669"},"modified":"2026-09-29T11:57:25","modified_gmt":"2026-09-29T11:57:25","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 141.<\/b><\/p>\n<p><b>A security architect wants to ensure that only healthy, company-managed devices can access a highly sensitive internal application. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conditional access that evaluates device compliance, identity, MFA strength, and session risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static password authentication only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Unrestricted access from any device on the internet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust based only on source IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional access can evaluate identity, authentication strength, device compliance, location, risk signals, and application sensitivity before granting access. This is stronger than relying on passwords or source IP addresses alone because compromised credentials may be used from unmanaged or infected systems. Sensitive applications can also require step-up authentication or restricted sessions. A zero-trust approach treats device posture as one of several important signals rather than assuming that successful authentication automatically means the device is safe.<\/span><\/p>\n<p><b>Question 142.<\/b><\/p>\n<p><b>Which architecture best protects secrets used by containerized workloads from exposure in source code or deployment manifests?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store credentials in container images.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Put passwords in plaintext YAML files.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share one secret across all namespaces.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use a secrets-management platform with workload identity and dynamic retrieval.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A secrets-management platform allows workloads to retrieve only the credentials they need at runtime, avoiding hard-coded secrets in source code, images, and manifests. Workload identity further reduces dependence on long-lived static credentials. Shared or embedded secrets increase blast radius and may persist in repositories or build artifacts even after deletion. Centralized secret management also supports access control, rotation, auditing, expiration, and automated credential issuance.<\/span><\/p>\n<p><b>Question 143.<\/b><\/p>\n<p><b>Which security capability is most useful for identifying abnormal behavior by service accounts that normally run predictable automated tasks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User and entity behavior analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and entity behavior analytics can establish a baseline for service-account behavior and identify deviations such as unusual login locations, unexpected resource access, abnormal API use, or new execution patterns. Service accounts often behave predictably, making anomalies particularly useful for detection. RAID, DNS caching, and compression do not provide behavioral security analysis. UEBA works best when correlated with identity logs, cloud audit events, endpoint telemetry, and application activity.<\/span><\/p>\n<p><b>Question 144.<\/b><\/p>\n<p><b>Which statement best describes the purpose of network egress filtering?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It controls only inbound internet traffic.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It restricts outbound communication to approved destinations and services.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces endpoint protection.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It disables routing between all internal systems.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Egress filtering controls outbound network communication and can prevent compromised systems from reaching command-and-control servers, unauthorized cloud services, or other prohibited destinations. It can also reduce data exfiltration risk. Egress controls do not replace endpoint protection or segmentation; they complement those safeguards. Policies should be based on legitimate business requirements and monitored so unexpected outbound connections can be investigated.<\/span><\/p>\n<p><b>Question 145.<\/b><\/p>\n<p><b>A security team wants to reduce the chance that a compromised CI\/CD runner can alter production infrastructure. Which control is strongest?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use isolated runners with short-lived credentials, least privilege, and approval gates for production changes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give every runner permanent administrator access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable pipeline audit logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow direct production changes from developer laptops.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Isolated build runners reduce cross-job contamination, while short-lived credentials limit the period during which stolen access can be abused. Least-privilege deployment roles and approval gates further restrict what the pipeline can change. Permanent administrator credentials create a large blast radius, and direct production access bypasses important review controls. Strong CI\/CD security also includes protected repositories, provenance verification, signed artifacts, dependency scanning, and tamper-resistant logging.<\/span><\/p>\n<p><b>Question 146.<\/b><\/p>\n<p><b>Which security technology is most appropriate when an organization wants to protect data during processing from a potentially compromised hypervisor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> File compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNSSEC<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Confidential computing with a trusted execution environment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidential computing uses hardware-backed trusted execution environments to isolate sensitive workloads and data from the surrounding host infrastructure, including potentially compromised hypervisors or privileged software. Encryption at rest and in transit does not fully protect data while it is actively being processed. NAT and DNSSEC address unrelated network concerns. Confidential computing can be useful for high-value workloads in shared or third-party cloud environments.<\/span><\/p>\n<p><b>Question 147.<\/b><\/p>\n<p><b>Which control most directly reduces the risk of a compromised privileged account being used indefinitely?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permanent administrator membership<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared privileged passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Just-in-time privilege elevation with automatic expiration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling privileged session logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Just-in-time elevation minimizes standing privilege by granting powerful permissions only when needed and removing them automatically afterward. This reduces the time window in which a compromised account can be abused. Permanent administrator membership and shared passwords increase risk and weaken accountability. JIT access is strongest when combined with phishing-resistant MFA, approval workflows, session monitoring, and regular review of privileged roles.<\/span><\/p>\n<p><b>Question 148.<\/b><\/p>\n<p><b>Which control best protects a web application from injection attacks caused by malicious input?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust all input from authenticated users.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use parameterized queries, input validation, and contextual output handling.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable application logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase DNS cache lifetime.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Parameterized queries separate data from executable query structure, making many injection attacks significantly harder. Input validation ensures that submitted data matches expected formats, while contextual output handling helps reduce related issues such as script injection. Authentication alone does not make user input safe. Secure coding should also include least-privilege database permissions, dependency management, testing, and application-layer monitoring.<\/span><\/p>\n<p><b>Question 149.<\/b><\/p>\n<p><b>A company discovers that a cloud administrator account was used to create a new privileged identity shortly after an unusual login. What is the most appropriate response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke suspicious sessions, disable unauthorized identities, preserve logs, and investigate related activity.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the activity because a privileged account performed it.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete audit logs to protect privacy.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase the new identity&#8217;s permissions.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creation of new privileged identities after suspicious authentication may indicate persistence following account compromise. The organization should contain the incident by revoking suspicious sessions and disabling unauthorized credentials while preserving evidence for investigation. Audit logs are essential for determining what changes were made and whether additional accounts or resources were affected. Increasing privileges or ignoring the activity would expand risk.<\/span><\/p>\n<p><b>Question 150.<\/b><\/p>\n<p><b>Which control provides the strongest protection for private keys used to sign firmware updates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store the keys in a shared developer folder.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Embed them in the build script.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep them in source control.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use an HSM with tightly controlled signing operations.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firmware-signing keys are high-value assets because compromise could allow attackers to produce malicious updates that appear authentic. An HSM can protect private key material from extraction and perform signing operations under tightly controlled access policies. Keys stored in scripts, repositories, or shared folders are much more exposed. Strong signing processes also use approval workflows, separation of duties, audit logs, and secure artifact verification.<\/span><\/p>\n<p><b>Question 151.<\/b><\/p>\n<p><b>Which security strategy best limits lateral movement inside a cloud environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Put every workload on one flat network.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Share administrative credentials across services.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use microsegmentation with explicit workload-to-workload access policies.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable east-west traffic monitoring.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation limits communication between workloads to explicitly approved paths. This reduces the attacker&#8217;s ability to move laterally after compromising one service or virtual machine. Flat networks and shared credentials increase the number of reachable systems and make compromise more damaging. East-west visibility should be maintained so abnormal internal communication can be detected. Identity-aware segmentation can provide even stronger control than IP-based filtering alone.<\/span><\/p>\n<p><b>Question 152.<\/b><\/p>\n<p><b>Which statement best describes the purpose of data minimization?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collect as much information as possible for future use.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Collect, process, and retain only the data necessary for the intended purpose.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable encryption to simplify access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store all data permanently.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization reduces privacy and security risk by limiting collection, processing, and retention to information that is genuinely required. If unnecessary data is never collected or retained, it cannot be exposed in a future breach. This principle is especially important for personal, regulated, and sensitive information. Organizations should regularly review whether data sets, fields, and retention periods remain justified by legitimate business requirements.<\/span><\/p>\n<p><b>Question 153.<\/b><\/p>\n<p><b>Which security practice best supports reliable investigation of administrator activity across multiple cloud platforms?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Centralize audit logs in a protected logging platform and normalize identity context.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep logs only on each local system.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable audit trails for privileged users.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use shared administrator accounts.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logging allows security teams to investigate administrator activity across multiple platforms using a common timeline and identity context. Logs should be stored in a protected location that administrators cannot easily alter. Shared accounts weaken attribution, while disabled or local-only logging makes investigation more difficult. Normalizing identities across platforms can help analysts determine when the same user performs related actions in different environments.<\/span><\/p>\n<p><b>Question 154.<\/b><\/p>\n<p><b>Which architecture best protects recovery systems from compromise when production administrator credentials are stolen?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use identical credentials in production and recovery environments.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanently connect recovery infrastructure to production networks.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow production administrators unrestricted backup deletion rights.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain isolated recovery infrastructure with separate identities and immutable backups.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate identities and isolated recovery infrastructure reduce the chance that credentials stolen from production can also compromise backups and recovery systems. Immutable backups further prevent attackers from deleting or modifying protected recovery copies. Using the same credentials and network paths across production and recovery creates common failure modes. Recovery procedures should also be tested regularly so isolation does not prevent timely restoration when needed.<\/span><\/p>\n<p><b>Question 155.<\/b><\/p>\n<p><b>Which control is most effective for reducing risk from malicious container images obtained from public registries?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow any image to run if its name looks legitimate.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable image scanning.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use trusted registries, vulnerability scanning, signature verification, and admission controls.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give containers privileged host access by default.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trusted registries and image scanning reduce the risk of vulnerable or malicious containers, while signature verification helps confirm artifact integrity and provenance. Admission controls can enforce these requirements before workloads are allowed to run. Image names alone provide no security assurance, and privileged containers substantially increase host risk. Organizations should also maintain minimal images, patch dependencies, and monitor runtime behavior.<\/span><\/p>\n<p><b>Question 156.<\/b><\/p>\n<p><b>Which statement best describes the purpose of red teaming?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It only verifies whether backups exist.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It simulates realistic adversary behavior to evaluate detection, prevention, and response capabilities.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces all vulnerability scanning.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It guarantees that the organization cannot be breached.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Red teaming emulates realistic adversary objectives and techniques to test how effectively an organization prevents, detects, and responds to attack activity. The exercise can reveal weaknesses across technology, processes, and people. Red teaming complements rather than replaces vulnerability assessment, penetration testing, and other security validation methods. Results should be used to improve detections, architecture, incident response, and defensive controls.<\/span><\/p>\n<p><b>Question 157.<\/b><\/p>\n<p><b>Which practice best reduces the risk of API keys being accidentally exposed in source repositories?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use secret scanning, pre-commit controls, and runtime secret retrieval from a managed vault.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Put API keys directly into code comments.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use the same key for every environment.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable repository auditing.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secret scanning can identify credentials before or shortly after they enter a repository, while pre-commit controls can block unsafe changes. Runtime retrieval from a secrets manager avoids embedding long-lived credentials in source code. Using one key across environments increases the impact of exposure. If a secret is committed, it should generally be rotated because removing the visible file does not eliminate copies from history or downstream clones.<\/span><\/p>\n<p><b>Question 158.<\/b><\/p>\n<p><b>Which event should be considered the strongest indicator of potential identity compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens a normal application at the usual time.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A scheduled password rotation completes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> An approved system runs a backup.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A dormant account authenticates from an unusual location and immediately requests privileged access.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dormant identity suddenly authenticating from an unusual location and requesting privilege represents a strong anomaly. Attackers often target forgotten or lightly monitored accounts because their activity may attract less attention. Analysts should verify the authentication method, device, location, requested privileges, and subsequent resource access. The account may need to be disabled or its sessions revoked while the activity is investigated.<\/span><\/p>\n<p><b>Question 159.<\/b><\/p>\n<p><b>Which security design best protects sensitive application data when multiple teams need access for different purposes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every team full database administrator rights.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use one shared account for all teams.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply role-based or attribute-based access controls with least-privilege permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable auditing to improve performance.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Role-based and attribute-based access controls allow permissions to be aligned with job function, resource sensitivity, context, and business purpose. This enables teams to access only the data and operations required for their responsibilities. Shared administrator accounts create excessive privilege and weak accountability. Auditing should remain enabled so access to sensitive information can be reviewed and investigated.<\/span><\/p>\n<p><b>Question 160.<\/b><\/p>\n<p><b>Which approach best supports continuous security validation in a complex enterprise environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume deployed controls continue to work indefinitely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Regularly test controls using automated validation, purple-team exercises, attack simulations, and measurable detection outcomes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Avoid testing production defenses.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Evaluate controls only after a major breach.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous validation helps determine whether security controls work against realistic attack techniques as infrastructure and configurations change. Automated control testing, purple-team exercises, breach-and-attack simulations, and detection metrics can reveal gaps before real attackers exploit them. Security effectiveness should be measured through outcomes rather than assumed from product deployment alone. Findings should feed back into architecture, detection engineering, response procedures, and remediation planning.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 141. A security architect wants to ensure that only healthy, company-managed devices can access a highly sensitive internal application. Which control is most appropriate? Conditional access that evaluates device compliance, identity, MFA strength, and session risk 2. Static password authentication only 3. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24669"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24669"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24669\/revisions"}],"predecessor-version":[{"id":24670,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24669\/revisions\/24670"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}