{"id":24685,"date":"2026-09-29T11:59:45","date_gmt":"2026-09-29T11:59:45","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24685"},"modified":"2026-09-29T11:59:45","modified_gmt":"2026-09-29T11:59:45","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 301.<\/b><\/p>\n<p><b>A security architect wants to reduce the risk that a compromised SaaS application can access more enterprise data than necessary. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Grant the application only narrowly scoped permissions and review them periodically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give the application tenant-wide administrator access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use one shared integration account for all SaaS applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable third-party application auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Narrowly scoped permissions limit a SaaS application&#8217;s access to only the data and actions required for its business purpose. This reduces the blast radius if the application or its credentials are compromised. Periodic reviews help identify permissions that are no longer needed. Shared accounts and broad administrator roles weaken accountability and unnecessarily expand access. Third-party applications should also be monitored, validated, and removed when no longer required.<\/span><\/p>\n<p><b>Question 302.<\/b><\/p>\n<p><b>Which architecture best protects a critical internal application from direct exposure to the public internet while still allowing remote users to access it?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publish the application directly with unrestricted inbound rules<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable authentication for remote users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Expose the backend server&#8217;s private management interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use a zero-trust application access broker or secure reverse proxy with identity-aware access controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A zero-trust access broker or secure reverse proxy can authenticate and authorize users before establishing access to a private application. This avoids exposing the application&#8217;s backend directly to the internet. Access decisions can consider user identity, device posture, risk, and application sensitivity. Direct exposure and disabled authentication greatly increase risk. This model also helps reduce broad network access by granting access to specific applications rather than entire subnets.<\/span><\/p>\n<p><b>Question 303.<\/b><\/p>\n<p><b>Which security capability is most useful for identifying whether an attacker has obtained access to a cloud environment through an unexpected trust relationship?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Identity trust-path and entitlement analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity trust-path analysis can reveal indirect access routes created by federated relationships, delegated roles, nested groups, service principals, and inherited permissions. Attackers may exploit these relationships to move from a low-privilege identity to a more powerful role. Graphing and entitlement analysis help security teams identify hidden privilege paths and reduce excessive or unintended trust.<\/span><\/p>\n<p><b>Question 304.<\/b><\/p>\n<p><b>Which control best reduces the risk of an attacker abusing a stolen refresh token?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase refresh-token lifetime<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use token rotation, revocation, device or session binding, and anomaly detection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store refresh tokens in application logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable token-expiration checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Refresh tokens can provide durable access if stolen, so they should be rotated, revocable, and protected against replay. Device or session binding can make reuse from an unauthorized environment more difficult, while anomaly detection can identify suspicious token activity. Increasing token lifetime or disabling expiration increases risk. Sensitive applications should also monitor unusual locations, devices, and token refresh patterns.<\/span><\/p>\n<p><b>Question 305.<\/b><\/p>\n<p><b>A security team wants to reduce the risk that a compromised build server can sign malicious software releases. Which control is strongest?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep signing keys in an HSM and require approved pipeline identity plus release authorization before signing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store signing keys directly on build servers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share signing keys with all developers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable release audit logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An HSM can prevent direct extraction of the signing key even if the build server is compromised. Requiring approved pipeline identity and release authorization adds additional safeguards before a signing operation occurs. Storing keys on build servers or distributing them broadly creates severe supply-chain risk. Release systems should also maintain immutable logs, verify provenance, and separate build privileges from signing authority.<\/span><\/p>\n<p><b>Question 306.<\/b><\/p>\n<p><b>Which architecture best protects highly sensitive workloads from unauthorized communication with other tenants in a shared cloud environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a flat shared network<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable workload authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use one security group for every workload<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Enforce tenant isolation, segmentation, and workload-specific network policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tenant isolation and workload-specific network policies reduce the possibility that one compromised workload can reach unrelated services or tenants. Flat networking and broad shared policies increase lateral-movement opportunities. Strong isolation should include explicit network rules, separate identities, least-privilege permissions, and monitoring of east-west traffic. In higher-assurance environments, organizations may also use dedicated hosts or confidential computing where appropriate.<\/span><\/p>\n<p><b>Question 307.<\/b><\/p>\n<p><b>Which security practice best detects unexpected changes to cloud IAM policies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable IAM logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store IAM configuration only in local administrator notes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Continuously monitor control-plane logs and compare permissions against approved baselines<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use shared administrator accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud control-plane logs record IAM policy changes, role assignments, trust modifications, and other administrative activity. Comparing those events with approved baselines can reveal unexpected or unauthorized changes. Shared accounts make attribution difficult, and disabling logs removes visibility. IAM monitoring should generate alerts for high-risk changes such as creation of new administrators, trust expansion, or logging disablement.<\/span><\/p>\n<p><b>Question 308.<\/b><\/p>\n<p><b>Which statement best describes the purpose of a compensating control in risk management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It permanently removes the underlying vulnerability.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It provides alternative risk reduction when the preferred control cannot be implemented.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need to document residual risk.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It applies only to compliance audits.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides alternative protection when the preferred control is temporarily or technically infeasible. Examples include stronger segmentation and monitoring around an unpatchable system. The underlying weakness may still remain, so residual risk should be documented and reviewed. Compensating controls should be assessed for effectiveness and replaced by the preferred control when feasible.<\/span><\/p>\n<p><b>Question 309.<\/b><\/p>\n<p><b>A security analyst sees a sudden sequence of failed administrative actions followed by a successful privilege escalation from the same account. Which response is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigate the session, validate the identity, contain suspicious access, and preserve relevant logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the event because the final request succeeded<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable all security monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete authentication logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sequence of failed privilege attempts followed by successful escalation can indicate credential abuse or exploitation. The session should be validated immediately, and suspicious access may need to be revoked or contained. Relevant logs should be preserved to determine what resources were affected. Ignoring the activity because one action succeeded would overlook a potentially serious privilege-escalation event.<\/span><\/p>\n<p><b>Question 310.<\/b><\/p>\n<p><b>Which control provides the strongest protection for an enterprise root certificate authority?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep it online for convenience<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store the private key on a standard file server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow all PKI administrators unrestricted access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Keep the root CA offline with HSM-protected keys and tightly controlled ceremonies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An offline root CA significantly reduces exposure to network attacks, while HSM protection makes extraction of the private key much more difficult. Controlled key ceremonies and separation of duties improve governance around high-risk operations. Keeping the root continuously online increases attack surface. Root CA compromise can undermine the entire PKI, so it requires stronger protection than ordinary certificate services.<\/span><\/p>\n<p><b>Question 311.<\/b><\/p>\n<p><b>Which security capability best identifies suspicious behavior involving unexpected access to cloud secrets?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID health monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Secret-access analytics correlated with workload and identity behavior<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secret-access logs can reveal which identities requested which credentials, while behavioral context helps identify abnormal patterns such as bulk retrieval, access from a new workload, or unusual timing. Because machine identities often behave predictably, deviations can indicate compromise. Storage and routing technologies do not provide this security visibility. Secrets platforms should generate high-quality audit records and alerts for suspicious access.<\/span><\/p>\n<p><b>Question 312.<\/b><\/p>\n<p><b>Which statement best describes the purpose of an RTO?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It defines acceptable data loss measured in time.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It defines the maximum acceptable time a service can remain unavailable after disruption.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It defines the number of encryption keys required.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It determines log retention duration.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The recovery time objective defines how quickly a service or business process must be restored after an outage or disaster. It influences architecture, redundancy, staffing, failover design, and recovery procedures. The recovery point objective instead concerns acceptable data loss measured in time. Both values should be based on business impact and validated through actual recovery exercises.<\/span><\/p>\n<p><b>Question 313.<\/b><\/p>\n<p><b>Which security practice best reduces the risk that abandoned cloud resources remain exposed after a project ends?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use formal decommissioning that removes identities, network rules, storage, secrets, DNS records, and integrations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Stop only the primary virtual machine<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Leave access keys active in case they are needed later<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Ignore old public storage buckets<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud applications often leave behind more than compute instances. Credentials, DNS entries, storage, firewall rules, APIs, service accounts, and third-party integrations can remain active after a project ends. Formal decommissioning reduces this residual attack surface. Resources that must be retained should have an identified owner and documented retention requirement rather than being left unmanaged.<\/span><\/p>\n<p><b>Question 314.<\/b><\/p>\n<p><b>Which architecture best reduces the impact of ransomware that has compromised both endpoints and domain administrator credentials?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep backups joined to the same administrative domain<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use the same passwords for backup and production systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow domain administrators to delete all backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use isolated backup administration, separate identities, and immutable recovery copies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If ransomware compromises domain administrators, backups managed through the same identity infrastructure may also be destroyed. Separate recovery identities and isolated administration reduce this common dependency. Immutable recovery copies further prevent deletion or modification. Organizations should also test restoration regularly to ensure that backup isolation does not prevent recovery when production identity services are unavailable.<\/span><\/p>\n<p><b>Question 315.<\/b><\/p>\n<p><b>Which control most directly reduces the impact of a compromised API credential used by an external partner?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give every partner one shared administrator key<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable API access logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use unique partner identities with scoped permissions, quotas, and credential rotation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust partner IP addresses without authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unique partner identities support accountability and allow permissions to be tailored to each relationship. Scoped access limits what a stolen credential can do, while quotas can restrict automated abuse. Credential rotation reduces long-term exposure. Shared administrator keys and IP-only trust create excessive risk. Partner API activity should also be monitored for anomalies and unusual access patterns.<\/span><\/p>\n<p><b>Question 316.<\/b><\/p>\n<p><b>Which statement best describes the purpose of a security control owner?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that the control can never fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To remain accountable for maintaining, reviewing, and addressing issues with the assigned control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To approve every business transaction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security control owner is accountable for ensuring that an assigned control remains implemented, maintained, and appropriately reviewed. Ownership helps avoid situations where security gaps persist because no team is responsible for remediation. Control owners may coordinate testing, evidence collection, exceptions, updates, and corrective actions. Ownership does not guarantee perfect effectiveness, so controls still require measurement and validation.<\/span><\/p>\n<p><b>Question 317.<\/b><\/p>\n<p><b>Which practice best reduces the risk of sensitive data being exposed through nonproduction AI experimentation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use synthetic or masked data and restrict model access to approved environments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Copy full regulated production data into public AI services<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable AI access logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give experimentation environments unrestricted access to production repositories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Synthetic or masked data allows teams to test AI workflows without unnecessarily exposing regulated or confidential information. Approved environments can enforce access controls, logging, retention requirements, and restrictions on external model use. Experimentation should follow data-minimization principles just like production. Sending raw sensitive data to unapproved services can create privacy, contractual, and security risks.<\/span><\/p>\n<p><b>Question 318.<\/b><\/p>\n<p><b>Which behavior most strongly indicates a possible attempt to weaken identity security controls?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A routine report executes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A user logs into a normal application<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A scheduled backup completes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A privileged account disables MFA requirements and adds a new authentication method after an unusual login<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling MFA requirements and adding a new authentication method can allow an attacker to maintain access and bypass normal protections. When these actions occur after suspicious authentication, they should be treated as high-priority indicators. Responders should validate the account, restore secure authentication policy, revoke suspicious sessions, and review other identity changes made during the same period.<\/span><\/p>\n<p><b>Question 319.<\/b><\/p>\n<p><b>Which security design best reduces the risk of unauthorized lateral movement between serverless functions and backend services?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one shared administrator identity for all functions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow all functions unrestricted network access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use separate workload identities, least-privilege permissions, and explicit service-to-service policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable logging for function activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separate workload identities and explicit service-to-service policies restrict each function to the backend services and operations it actually requires. This reduces lateral movement if one function or dependency is compromised. Shared administrator identities and unrestricted connectivity create excessive blast radius. Serverless environments should also use secure secret management, logging, dependency scanning, and short-lived credentials.<\/span><\/p>\n<p><b>Question 320.<\/b><\/p>\n<p><b>Which approach best supports resilient security operations when enterprise environments and attacker techniques change frequently?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Freeze detection logic permanently after deployment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Continuously test detections, review telemetry coverage, exercise response, and update controls based on observed gaps<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evaluate security only during annual audits<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable noisy telemetry rather than tuning detections<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security operations must evolve as infrastructure, applications, identity systems, and attacker techniques change. Detection testing, telemetry review, incident exercises, and purple-team activity help identify blind spots and weak controls. Findings should drive tuning and remediation. Continuous validation provides stronger assurance than assuming that controls and detections remain effective indefinitely.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 301. A security architect wants to reduce the risk that a compromised SaaS application can access more enterprise data than necessary. Which control is most appropriate? Grant the application only narrowly scoped permissions and review them periodically 2. Give the application tenant-wide [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24685"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24685"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24685\/revisions"}],"predecessor-version":[{"id":24686,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24685\/revisions\/24686"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24685"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}