{"id":24679,"date":"2026-09-29T11:58:58","date_gmt":"2026-09-29T11:58:58","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24679"},"modified":"2026-09-29T11:58:58","modified_gmt":"2026-09-29T11:58:58","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 241.<\/b><\/p>\n<p><b>A security architect wants to reduce the risk that sensitive workloads can communicate with unauthorized internal services after one application is compromised. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identity-aware microsegmentation with explicit east-west allow policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A flat internal network with broad trust<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shared credentials between application tiers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Unrestricted internal routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity-aware microsegmentation limits workload-to-workload communication to approved paths and can make decisions based on service identity rather than network location alone. This reduces lateral movement if one application is compromised. Flat networks and shared credentials increase blast radius because an attacker may reach unrelated systems. Strong east-west controls should be combined with workload identity, application authorization, monitoring, and least-privilege service permissions.<\/span><\/p>\n<p><b>Question 242.<\/b><\/p>\n<p><b>Which approach best protects an organization from malicious changes to production cloud configurations that bypass the normal deployment pipeline?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow unrestricted manual console changes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable configuration monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Trust administrators to document changes later.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use configuration drift detection and alert on changes that differ from approved infrastructure-as-code state.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration drift detection compares actual deployed resources against the approved infrastructure-as-code baseline. Unexpected differences can indicate manual changes, compromised credentials, or configuration errors. Alerting on drift helps teams identify changes that bypass normal review and deployment controls. Manual console changes should be tightly restricted, and approved emergency changes should eventually be reconciled into the authoritative infrastructure definition.<\/span><\/p>\n<p><b>Question 243.<\/b><\/p>\n<p><b>A company wants to identify cloud resources that have excessive permissions compared with what their identities actually use. Which capability is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network address translation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cloud infrastructure entitlement management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> File compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud infrastructure entitlement management evaluates permissions assigned to human and machine identities and can compare granted access with actual usage. This helps identify excessive, unused, inherited, or risky entitlements. Such analysis supports least privilege and reduces the chance that a compromised account can access unnecessary resources. NAT, RAID, and compression do not provide identity entitlement visibility.<\/span><\/p>\n<p><b>Question 244.<\/b><\/p>\n<p><b>Which security control best reduces risk when an enterprise must continue operating an unpatchable legacy system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Connect it directly to the internet.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Apply compensating controls such as segmentation, allowlisting, monitoring, and tightly restricted access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give all users local administrator rights.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable logging to reduce system load.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a vulnerable legacy system cannot be patched immediately, compensating controls can reduce exposure while the organization plans replacement or remediation. Segmentation limits reachable systems, allowlisting restricts permitted communication or applications, and enhanced monitoring can detect suspicious behavior. Access should be tightly controlled. These measures do not remove the underlying vulnerability, so the residual risk should be documented and reviewed.<\/span><\/p>\n<p><b>Question 245.<\/b><\/p>\n<p><b>Which action provides the strongest protection when a private key used by an internal certificate authority is suspected of compromise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke affected certificates as appropriate, replace the compromised key, and investigate issued certificates.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Continue using the key until its scheduled expiration.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Publish the private key for transparency.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable PKI logging.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compromised certificate authority key can undermine trust in certificates issued under that authority. The organization should replace the affected key and determine which certificates may need revocation or reissuance. Logs should be preserved to identify potentially fraudulent certificate issuance. Continuing to trust a compromised private key extends the risk and may allow attackers to impersonate systems or users.<\/span><\/p>\n<p><b>Question 246.<\/b><\/p>\n<p><b>Which architecture best protects highly sensitive encryption keys used by multiple enterprise applications?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store keys in application configuration files.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Distribute copies of keys to development teams.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep keys in source repositories.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use centralized hardware-backed key management with controlled cryptographic operations.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized hardware-backed key management can protect key material from extraction while enforcing access controls, rotation, auditing, and cryptographic operations. Application configuration files and source repositories expose high-value keys to unnecessary users and systems. Centralization also makes lifecycle management more consistent. Access should still be separated by application and role so one compromised workload cannot use every enterprise key.<\/span><\/p>\n<p><b>Question 247.<\/b><\/p>\n<p><b>Which security practice is most effective for finding hidden attack paths created by nested groups, delegated roles, and indirect trust relationships?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disk encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> DNS filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Identity attack-path analysis and permission graphing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Network load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Permission graphing can reveal indirect privilege paths that are difficult to see from individual access-control entries. Nested group membership, delegated roles, service principals, trust relationships, and privilege inheritance may allow a seemingly low-privilege identity to reach sensitive resources. Identity attack-path analysis helps security teams identify and remove these unintended escalation opportunities before attackers exploit them.<\/span><\/p>\n<p><b>Question 248.<\/b><\/p>\n<p><b>Which statement best describes the purpose of step-up authentication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It permanently grants elevated privileges after login.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It requires stronger authentication when a user performs a higher-risk action or accesses a sensitive resource.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It disables MFA for trusted users.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces authorization decisions.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Step-up authentication requires additional or stronger verification when risk increases, such as when accessing sensitive data, changing security settings, or approving a financial transaction. A user may have already authenticated normally, but the higher-risk operation triggers stronger assurance. Step-up authentication complements authorization and least privilege; it does not replace them or create permanent elevated access.<\/span><\/p>\n<p><b>Question 249.<\/b><\/p>\n<p><b>A security team wants to detect whether an attacker is using stolen credentials from geographically distant locations within a time period that would be physically impossible for the legitimate user. Which detection is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Impossible-travel analysis combined with device and session context<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RAID health monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disk deduplication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Impossible-travel analysis identifies authentication events that occur from distant geographic locations within an implausibly short period. Device, VPN, proxy, and session context should also be considered because legitimate services can produce apparent geographic anomalies. When correlated with unfamiliar devices, token use, or risky authentication events, impossible travel can provide a useful account-compromise signal.<\/span><\/p>\n<p><b>Question 250.<\/b><\/p>\n<p><b>Which control best reduces the likelihood that a compromised API client can consume excessive backend resources?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow unlimited request rates.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Trust authenticated clients completely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Enforce rate limits, quotas, and resource-consumption controls.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication confirms identity but does not prevent an authenticated or compromised client from abusing backend resources. Rate limits and quotas restrict request volume and can prevent one consumer from exhausting shared capacity. Resource-consumption controls may also limit expensive queries, payload sizes, or concurrency. These safeguards should be combined with monitoring, authorization, and anomaly detection.<\/span><\/p>\n<p><b>Question 251.<\/b><\/p>\n<p><b>Which security control best helps an organization detect whether attackers are using trusted administrative tools for lateral movement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> File compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Endpoint detection correlated with identity and remote-access telemetry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> RAID mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attackers frequently use legitimate administrative tools to blend into normal activity. Endpoint detection can record process execution, command-line arguments, parent-child relationships, remote sessions, and network activity. Correlating these events with authentication and identity telemetry helps distinguish authorized administration from suspicious lateral movement. File compression and RAID monitoring do not provide this behavioral context.<\/span><\/p>\n<p><b>Question 252.<\/b><\/p>\n<p><b>Which statement best describes the purpose of an SBOM?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It provides network segmentation rules.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It documents software components and dependencies contained in an application or product.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It stores user passwords.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces vulnerability scanning.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A software bill of materials provides visibility into libraries, frameworks, packages, and other components included in software. When a dependency vulnerability is discovered, organizations can use an SBOM to determine which applications may be affected. An SBOM does not replace scanning, testing, or remediation. It supports supply-chain transparency and faster impact analysis.<\/span><\/p>\n<p><b>Question 253.<\/b><\/p>\n<p><b>A company discovers that a privileged administrator account is being used from a previously unseen device. What is the most appropriate first security response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Validate the session, assess risk, and require additional authentication or containment as warranted.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume the activity is legitimate because the credentials are valid.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all privileged logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permanently allow the new device without verification.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A new device accessing a privileged account should be treated as a meaningful risk signal. The organization should validate the user and device, review the authentication method, inspect recent activity, and apply step-up authentication or containment if the context is suspicious. Valid credentials alone are not sufficient proof that access is legitimate. Privileged sessions require heightened monitoring because compromise can have broad consequences.<\/span><\/p>\n<p><b>Question 254.<\/b><\/p>\n<p><b>Which design best protects sensitive business data if ransomware compromises production administrator accounts?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep all backups mounted and writable from production.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use identical credentials for production and backup administration.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow unrestricted backup deletion from production accounts.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use immutable backups with separate recovery identities and isolated administration.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable backups prevent protected recovery data from being modified or deleted during the retention period. Separate recovery identities and isolated administration reduce the chance that stolen production credentials can destroy backup systems as well. Using shared credentials and continuously writable backups creates common failure paths. Recovery procedures should also be tested regularly to verify that protected backups can be restored successfully.<\/span><\/p>\n<p><b>Question 255.<\/b><\/p>\n<p><b>Which security technique best reduces exposure of sensitive fields in analytics data sets when exact identifiers are unnecessary?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable encryption.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Provide analysts unrestricted raw production access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use masking, pseudonymization, or aggregation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Copy the data to unmanaged endpoints.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Masking, pseudonymization, and aggregation reduce the amount of directly identifying or sensitive information exposed during analysis. This supports data minimization while preserving analytical usefulness. Giving broad access to raw production data increases privacy and security risk. The chosen technique should reflect whether re-identification is necessary, the sensitivity of the data, and applicable legal or regulatory requirements.<\/span><\/p>\n<p><b>Question 256.<\/b><\/p>\n<p><b>Which statement best describes the purpose of continuous control monitoring?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It replaces all human review.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It repeatedly evaluates whether required security controls remain implemented and effective over time.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees that systems cannot be breached.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It is used only during initial system deployment.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous control monitoring evaluates whether required safeguards remain in place as environments change. It can identify configuration drift, disabled logging, excessive privileges, missing encryption, or other deviations from policy. Automated checks improve speed and consistency, but human review is still needed for interpretation, exceptions, and risk decisions. The objective is to detect control degradation before it creates serious exposure.<\/span><\/p>\n<p><b>Question 257.<\/b><\/p>\n<p><b>Which practice best reduces the security risk associated with third-party SaaS integrations that request broad access to enterprise data?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review requested permissions, restrict scopes, validate the vendor, and monitor ongoing access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Approve every integration automatically.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give all integrations administrator-level permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable audit logs for third-party applications.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party integrations should receive only the permissions required for their intended function. Vendor security posture, requested scopes, data handling, contractual obligations, and ongoing activity should be assessed before approval. Broad permissions can allow a compromised or malicious integration to access large amounts of enterprise data. Periodic reviews should remove integrations and permissions that are no longer needed.<\/span><\/p>\n<p><b>Question 258.<\/b><\/p>\n<p><b>Which activity most strongly suggests possible tampering with enterprise security monitoring?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An application completes a normal health check.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A scheduled report is generated.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A backup completes successfully.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A privileged identity unexpectedly disables multiple security data collectors shortly after logging in from a new location.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling multiple security data collectors after anomalous privileged authentication is a strong indicator that an attacker may be attempting to reduce visibility before further activity. Responders should validate the account, restore telemetry, revoke suspicious sessions if appropriate, and examine actions performed before and after monitoring was disrupted. Security telemetry itself should be protected as a high-value asset.<\/span><\/p>\n<p><b>Question 259.<\/b><\/p>\n<p><b>Which architecture best protects APIs that are accessed by external partners with different business permissions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a single shared administrator token for all partners.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable authorization after authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use separate partner identities, scoped tokens, fine-grained authorization, and API gateway controls.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust all partner traffic based only on source IP.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate identities and scoped tokens allow each partner to receive only the API permissions required for its business relationship. Fine-grained authorization can restrict resources and operations, while API gateways can enforce rate limits, validation, and monitoring. Shared administrator tokens create excessive risk and poor accountability. Network location alone should not determine authorization.<\/span><\/p>\n<p><b>Question 260.<\/b><\/p>\n<p><b>Which approach best supports secure long-term adoption of new technologies across an enterprise?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy new technology broadly before assessing risk.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Perform threat modeling, define security requirements, test controls, monitor outcomes, and update governance as the technology evolves.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assume vendor defaults are always sufficient.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoid reviewing new technology after initial approval.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">New technologies can introduce unfamiliar trust boundaries, dependencies, failure modes, and data risks. Threat modeling and explicit security requirements help identify these issues before broad deployment. Testing and monitoring provide evidence that controls work, while governance must evolve as usage patterns and threats change. Security should therefore be integrated throughout the technology lifecycle rather than added only after deployment.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 241. A security architect wants to reduce the risk that sensitive workloads can communicate with unauthorized internal services after one application is compromised. Which control is most appropriate? Identity-aware microsegmentation with explicit east-west allow policies 2. A flat internal network with broad [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24679"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24679"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24679\/revisions"}],"predecessor-version":[{"id":24680,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24679\/revisions\/24680"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}