{"id":24671,"date":"2026-09-29T11:57:42","date_gmt":"2026-09-29T11:57:42","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24671"},"modified":"2026-09-29T11:57:42","modified_gmt":"2026-09-29T11:57:42","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 161.<\/b><\/p>\n<p><b>A security architect wants to ensure that administrative access to a critical cloud environment is allowed only from trusted devices using strong authentication. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conditional access requiring phishing-resistant MFA and compliant device posture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Password-only authentication from any device<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared administrator accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permanent access from any internal IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Conditional access can evaluate authentication strength, device posture, location, user risk, and requested resources before allowing privileged access. Requiring phishing-resistant MFA and a compliant managed device significantly reduces the risk of stolen passwords or unmanaged endpoints being used for administration. Shared accounts weaken accountability, while source IP alone is an unreliable trust signal. Privileged cloud access should also use just-in-time elevation, least privilege, session logging, and continuous monitoring for anomalous administrative activity.<\/span><\/p>\n<p><b>Question 162.<\/b><\/p>\n<p><b>Which security architecture best protects sensitive workloads from unauthorized east-west communication inside a data center?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Flat Layer 2 networking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Unrestricted internal routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared service accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Microsegmentation with explicit application-aware access policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microsegmentation limits communication between workloads according to approved application requirements rather than assuming internal traffic is trusted. This can significantly reduce lateral movement after compromise. Flat networks and unrestricted internal routing increase the number of reachable systems, while shared service identities weaken isolation and accountability. Effective microsegmentation can use workload identity, tags, application context, and least-privilege rules to permit only necessary communication between services and security zones.<\/span><\/p>\n<p><b>Question 163.<\/b><\/p>\n<p><b>A security team wants to determine whether a newly disclosed vulnerability affects any software currently deployed in the enterprise. Which resource is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer inventories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Software inventory and software bills of materials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network address translation tables<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A current software inventory and SBOM provide visibility into installed applications, libraries, and dependencies. When a new vulnerability is disclosed, security teams can determine which systems or applications contain the affected component and prioritize remediation accordingly. DNS caches and NAT tables do not provide dependency information. Accurate software inventories support vulnerability management, incident response, licensing, and supply-chain risk analysis, especially when third-party components are embedded deeply within enterprise applications.<\/span><\/p>\n<p><b>Question 164.<\/b><\/p>\n<p><b>Which control best reduces the risk of session hijacking when a web application uses bearer tokens?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase token lifetime.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use short-lived tokens, secure cookie attributes, revocation, and contextual session validation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow tokens to be transmitted over HTTP.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store tokens in publicly accessible application logs.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Short-lived tokens reduce the period during which a stolen bearer token can be abused. Secure cookie settings, revocation mechanisms, TLS, and contextual validation such as device or risk checks further limit session hijacking. Increasing token lifetime creates more exposure, while transmitting or logging tokens insecurely can directly leak credentials. Sensitive operations may also require reauthentication or step-up verification rather than relying solely on an existing session.<\/span><\/p>\n<p><b>Question 165.<\/b><\/p>\n<p><b>An enterprise wants to reduce the risk of malicious insiders accessing encryption keys used for customer data. Which design is strongest?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store keys in an HSM with separation of duties and tightly controlled administrative access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store keys in plaintext next to the encrypted data.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share one key-management administrator account.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Email backup copies of keys to system administrators.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An HSM can protect key material from direct extraction while enforcing controlled cryptographic operations. Separation of duties prevents a single administrator from having unrestricted control over high-value keys, while individual identities and audit logging improve accountability. Storing keys beside encrypted data or distributing them through email defeats much of the protection encryption is intended to provide. Key management should also include lifecycle controls, rotation, backup, revocation, and recovery procedures.<\/span><\/p>\n<p><b>Question 166.<\/b><\/p>\n<p><b>Which approach best protects production workloads from vulnerable or malicious container images?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow images from any registry.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable signature verification.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give every container privileged host access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Enforce trusted registries, image scanning, signature validation, and admission policies.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A strong container supply-chain control validates where an image originated, whether it contains known vulnerabilities, and whether its signature and provenance meet policy before deployment. Admission policies can block noncompliant workloads automatically. Arbitrary registries and privileged containers increase risk, while disabling signature checks removes an important integrity safeguard. Runtime monitoring, minimal images, restricted capabilities, and regular dependency updates further strengthen container security.<\/span><\/p>\n<p><b>Question 167.<\/b><\/p>\n<p><b>Which security capability is most useful for detecting unusual activity by machine identities and service accounts?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User and entity behavior analytics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service accounts often perform highly predictable actions, making behavioral deviations especially useful for detection. UEBA can identify anomalies such as new login locations, unusual APIs, unexpected privilege use, or abnormal access times. Static routing, RAID, and compression do not provide identity behavior analysis. Machine identities should also be inventoried, monitored, rotated, and granted narrowly scoped permissions because compromised service credentials can provide attackers with persistent access.<\/span><\/p>\n<p><b>Question 168.<\/b><\/p>\n<p><b>Which statement best describes the security benefit of immutable infrastructure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrators modify production servers manually whenever possible.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Systems are replaced with approved images rather than changed extensively in place.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Logging is disabled to reduce configuration changes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Every server keeps a unique undocumented configuration.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable infrastructure reduces configuration drift by replacing systems with approved, version-controlled images rather than relying on repeated manual changes. This supports consistency, reproducibility, and stronger change control. If a system is compromised or misconfigured, it can be rebuilt from a trusted image instead of repaired manually. The model works best with automated deployment, signed artifacts, infrastructure as code, centralized logs, and secure image pipelines.<\/span><\/p>\n<p><b>Question 169.<\/b><\/p>\n<p><b>A company detects repeated access attempts to a cloud metadata endpoint from a public-facing application. Which threat should be investigated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server-side request forgery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Password spraying<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> DNS poisoning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ARP spoofing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud metadata endpoints often expose temporary credentials or instance information to workloads. If a public-facing application can be manipulated into requesting metadata URLs, this may indicate server-side request forgery. Successful SSRF could allow an attacker to obtain credentials or access internal resources. Defenses include strict URL validation, metadata protections, outbound filtering, and least-privilege workload roles. Password spraying, DNS poisoning, and ARP spoofing do not best explain this behavior.<\/span><\/p>\n<p><b>Question 170.<\/b><\/p>\n<p><b>Which security control provides the strongest protection for privileged emergency accounts?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use them for routine administration.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Share them across teams.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Exempt them from monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store them securely, require strong MFA, restrict use, and alert on every authentication.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Emergency or break-glass accounts should be highly protected because they often have extensive privileges and may bypass normal access paths. Credentials should be secured, use strong authentication where possible, and be accessed only under documented emergency procedures. Every use should generate immediate monitoring and review. Routine use, shared access, or monitoring exemptions undermine accountability and increase the chance that a compromise will go unnoticed.<\/span><\/p>\n<p><b>Question 171.<\/b><\/p>\n<p><b>Which control best reduces the risk that a malicious developer can secretly insert unauthorized code into a production release?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable peer review.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow direct production deployments from laptops.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require protected branches, independent review, signed artifacts, and controlled release pipelines.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share deployment credentials among all developers.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Protected branches and independent review reduce the chance that one developer can make unapproved changes without oversight. Signed artifacts and controlled release pipelines provide integrity and traceability from source to production. Direct deployment and shared credentials weaken separation of duties and accountability. Strong software-release security also includes CI\/CD isolation, short-lived deployment credentials, dependency scanning, and audit logs that cannot be easily altered by developers.<\/span><\/p>\n<p><b>Question 172.<\/b><\/p>\n<p><b>Which statement best describes a compensating control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It removes all risk permanently.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It provides an alternative safeguard when the preferred control cannot be implemented.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It always replaces the need for remediation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It is used only for physical security.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides alternative risk reduction when the preferred or required safeguard cannot be implemented immediately or technically. For example, additional segmentation and monitoring might temporarily reduce risk when a legacy system cannot be patched. The control should provide meaningful protection appropriate to the identified risk. Compensating controls do not automatically eliminate the need for eventual remediation, and their effectiveness should be reviewed and documented.<\/span><\/p>\n<p><b>Question 173.<\/b><\/p>\n<p><b>A security team suspects malicious use of PowerShell on several endpoints. Which evidence should be correlated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PowerShell logs, process creation events, parent-child relationships, and network connections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer queue data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Backup media labels<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Monitor resolution settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">PowerShell can be used legitimately or maliciously, so context is essential. Script-block logging, command-line data, process ancestry, user identity, and network connections can help determine whether execution is suspicious. Analysts should look for encoded commands, unusual parent processes, downloads, credential access, and connections to unexpected destinations. Printer and display information provide little value for this investigation. Behavioral correlation is more effective than blocking PowerShell indiscriminately.<\/span><\/p>\n<p><b>Question 174.<\/b><\/p>\n<p><b>Which architecture best protects backup systems from ransomware that has compromised production identity services?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use the same identities and passwords everywhere.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep backups continuously writable from production.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow production administrators unrestricted deletion rights.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use separate recovery identities, immutable storage, and isolated backup administration.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate recovery identities reduce dependence on compromised production authentication systems, while immutable backups prevent unauthorized modification or deletion during protected retention periods. Isolated administration further limits attacker reach. Shared credentials and continuously writable backups create common failure paths that ransomware can exploit. Recovery environments should also be regularly tested so isolation and security controls do not prevent the organization from meeting restoration objectives.<\/span><\/p>\n<p><b>Question 175.<\/b><\/p>\n<p><b>Which control most directly reduces the impact of credential theft from a CI\/CD system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use permanent cloud administrator keys.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store credentials in source repositories.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use short-lived workload credentials with narrowly scoped permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable pipeline logging.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Short-lived credentials reduce the useful lifetime of stolen secrets, while narrowly scoped permissions limit what a compromised build or deployment system can do. Workload identity federation can further eliminate the need for static access keys. Permanent administrator keys and source-controlled credentials create substantial supply-chain risk. Logging should remain enabled to provide evidence of unusual builds, access, or deployments.<\/span><\/p>\n<p><b>Question 176.<\/b><\/p>\n<p><b>Which statement best describes the purpose of attack surface management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It focuses only on internal antivirus signatures.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It identifies and evaluates exposed assets, services, and attack paths that may be reachable by adversaries.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces vulnerability remediation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for asset inventory.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack surface management helps organizations discover and evaluate exposed systems, domains, cloud services, applications, and other assets that attackers may target. It can identify unknown or unmanaged resources, misconfigurations, and internet-facing services that increase risk. It complements vulnerability management rather than replacing it. Accurate asset inventory remains essential because security teams cannot effectively protect resources they do not know exist.<\/span><\/p>\n<p><b>Question 177.<\/b><\/p>\n<p><b>Which practice best supports secure decommissioning of a cloud application?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke credentials, remove data as required, disable integrations, and verify residual resources are deleted or retained appropriately.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Leave access keys active in case the application returns.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep abandoned public storage buckets indefinitely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore third-party integrations.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure decommissioning requires more than shutting down the primary application. Credentials, service accounts, API integrations, data stores, DNS records, backups, secrets, and cloud resources should be reviewed and handled according to retention and business requirements. Leaving active keys or abandoned public resources creates unnecessary attack surface. Decommissioning should be documented so teams can confirm that residual access paths and sensitive data have been addressed.<\/span><\/p>\n<p><b>Question 178.<\/b><\/p>\n<p><b>Which behavior most strongly suggests possible privilege escalation in a cloud environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A scheduled report runs normally.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A user views a standard dashboard.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A service completes its usual health check.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A low-privilege identity suddenly modifies role-assignment policies and assumes an administrative role.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A low-privilege identity modifying authorization policy and then assuming an administrative role is a strong indicator of privilege escalation or account abuse. Security teams should review how the identity gained permission to change roles, inspect related API calls, revoke suspicious sessions, and validate subsequent administrative activity. Routine reporting or health checks do not present the same risk. Cloud authorization changes should be closely monitored because they can rapidly expand attacker access.<\/span><\/p>\n<p><b>Question 179.<\/b><\/p>\n<p><b>Which security design best reduces the risk of sensitive information leaking through generative AI prompts?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Permit all employees to submit unrestricted regulated data to any model.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable all AI usage logs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Enforce approved AI services, data classification rules, DLP controls, and restrictions on sensitive inputs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give AI tools direct administrator access to all corporate data.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Approved AI services should be governed according to the sensitivity of information they process. Data classification and DLP can help prevent users from submitting regulated, confidential, or proprietary information to inappropriate models. Logging supports investigation and policy enforcement, while access should follow least privilege. Organizations should also evaluate retention, model-training terms, third-party data handling, prompt injection, and output leakage risks before integrating AI into sensitive workflows.<\/span><\/p>\n<p><b>Question 180.<\/b><\/p>\n<p><b>Which approach best supports long-term security resilience in a complex hybrid enterprise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume controls remain effective after initial deployment.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Continuously validate controls, review architecture, exercise incident recovery, monitor identity and workload risk, and remediate discovered gaps.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Test security only after a major incident.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable telemetry to reduce operational complexity.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise environments continuously change as applications, identities, cloud resources, dependencies, and threats evolve. Security controls therefore require repeated validation rather than one-time deployment. Architecture reviews, purple-team exercises, recovery tests, telemetry analysis, vulnerability remediation, and control validation provide evidence that safeguards still work. Continuous improvement helps organizations detect drift, hidden dependencies, and failed assumptions before attackers exploit them.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 161. A security architect wants to ensure that administrative access to a critical cloud environment is allowed only from trusted devices using strong authentication. Which control is most appropriate? Conditional access requiring phishing-resistant MFA and compliant device posture 2. Password-only authentication from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24671"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24671"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24671\/revisions"}],"predecessor-version":[{"id":24672,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24671\/revisions\/24672"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}