{"id":24689,"date":"2026-09-29T12:00:16","date_gmt":"2026-09-29T12:00:16","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24689"},"modified":"2026-09-29T12:00:16","modified_gmt":"2026-09-29T12:00:16","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 341.<\/b><\/p>\n<p><b>A security architect wants to prevent developers from granting excessive permissions to new cloud workloads. Which control is most effective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enforce least-privilege role templates and policy-as-code checks during deployment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give every workload administrator privileges initially<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow teams to create unrestricted roles manually<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable permission reviews after deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least-privilege role templates establish secure defaults, while policy-as-code can automatically detect overly broad permissions before infrastructure is deployed. This reduces inconsistency and prevents excessive privilege from becoming embedded in production. Broad administrator roles increase blast radius and often remain in place longer than intended. Organizations should also review actual permission usage over time and remove privileges that are no longer required.<\/span><\/p>\n<p><b>Question 342.<\/b><\/p>\n<p><b>Which control best protects an enterprise from unauthorized changes to security monitoring rules?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow all analysts to modify production detections directly.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable change logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use shared administrator credentials for the SIEM.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Manage detection logic through version control, peer review, and controlled deployment.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection rules are part of the security control plane and should be protected like production code. Version control provides traceability and rollback, peer review reduces unauthorized or accidental changes, and controlled deployment creates separation between development and production. Shared credentials and unlogged changes weaken accountability. High-impact rule changes should also be monitored because attackers may try to disable or weaken detections after gaining privileged access.<\/span><\/p>\n<p><b>Question 343.<\/b><\/p>\n<p><b>Which security capability is most appropriate for finding cloud resources that are publicly exposed due to configuration errors?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Cloud security posture management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Local printer auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud security posture management continuously evaluates cloud configurations for risky settings such as public storage, overly permissive network rules, missing encryption, and compliance drift. It can help detect misconfigurations that traditional endpoint tools may not see. RAID, compression, and printer auditing do not provide cloud configuration visibility. CSPM findings should be prioritized based on asset sensitivity, exposure, and exploitability.<\/span><\/p>\n<p><b>Question 344.<\/b><\/p>\n<p><b>Which approach best protects an internal API from misuse by a compromised service account?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust the service account completely after authentication.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Enforce fine-grained authorization, scoped tokens, and behavioral monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable API logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give the service account permanent administrator access.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication proves the identity presented by the caller, but a compromised service account may still behave maliciously. Fine-grained authorization limits what the identity can do, while scoped tokens reduce the accessible resources and behavioral monitoring can detect unusual patterns. Permanent administrator access creates excessive risk. Internal APIs should be protected with the same least-privilege principles as internet-facing services.<\/span><\/p>\n<p><b>Question 345.<\/b><\/p>\n<p><b>A security team wants to reduce the risk of privileged credential theft through phishing. Which solution provides the strongest protection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hardware-backed phishing-resistant authentication for privileged users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Security questions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Password reuse across administrative systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> SMS-only authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hardware-backed phishing-resistant authentication, such as FIDO2-based authenticators, uses public-key cryptography and origin binding to make credential phishing substantially harder. Security questions and SMS codes are more susceptible to social engineering or interception. Privileged identities should also use separate accounts, hardened administrative endpoints, just-in-time access, and strong monitoring to reduce the impact of compromise.<\/span><\/p>\n<p><b>Question 346.<\/b><\/p>\n<p><b>Which architecture best protects signing keys used by an automated release pipeline?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store keys in the pipeline&#8217;s local filesystem.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Commit keys to the private source repository.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share the key with release engineers.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use an HSM or protected signing service that performs signing without exposing the private key.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A protected signing service or HSM keeps the private key isolated from the build environment and can enforce tightly controlled signing requests. This reduces the chance that compromise of a runner or developer account results in key theft. Storing the private key in source control or on build systems creates major software-supply-chain risk. Signing operations should also be logged and tied to verified build provenance.<\/span><\/p>\n<p><b>Question 347.<\/b><\/p>\n<p><b>Which security practice best detects privilege creep among employees who change roles over time?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable periodic access reviews.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow all historic permissions to remain permanently.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Perform regular entitlement reviews and remove access no longer required.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share privileged roles across departments.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privilege creep occurs when users accumulate access as they change roles without losing permissions from previous responsibilities. Regular entitlement reviews compare current access with business need and help remove unnecessary privileges. Strong identity governance should include joiner, mover, and leaver processes so access changes follow the user&#8217;s lifecycle. Permanent accumulation of permissions increases the impact of account compromise.<\/span><\/p>\n<p><b>Question 348.<\/b><\/p>\n<p><b>Which statement best describes the security purpose of certificate revocation checking?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It verifies that every certificate uses the same encryption algorithm.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It determines whether a previously issued certificate should no longer be trusted.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It replaces certificate expiration.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It encrypts private keys.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate revocation checking determines whether a certificate that has not yet expired has been invalidated because of key compromise, incorrect issuance, or another security event. Mechanisms such as CRLs and OCSP can communicate revocation status. Expiration alone may leave a compromised certificate trusted for too long. Reliable PKI architecture therefore includes issuance, renewal, revocation, monitoring, and key-protection processes.<\/span><\/p>\n<p><b>Question 349.<\/b><\/p>\n<p><b>A security analyst identifies a server making outbound connections to a rare domain shortly after a new administrative login. What should be investigated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The process initiating the connection, user context, domain reputation, and related activity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Printer toner levels<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Local screen brightness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Office network cabling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The timing between unusual administrative access and outbound communication may indicate post-compromise command-and-control activity. Analysts should identify which process initiated the connection, what account launched it, the domain&#8217;s reputation and age, and whether related files or commands were executed. Correlating endpoint, DNS, firewall, and identity telemetry provides stronger evidence than evaluating the network destination alone.<\/span><\/p>\n<p><b>Question 350.<\/b><\/p>\n<p><b>Which control best protects critical cloud logs from deletion by a compromised tenant administrator?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store logs only inside the tenant being monitored.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow privileged administrators to disable log collection without alerting.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep only short-lived local copies.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Export logs to a separate protected account or immutable logging platform.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exporting logs to a separate security boundary reduces the chance that a compromised tenant administrator can erase evidence. Immutability or write-protection provides additional safeguards against tampering. Local-only logs remain exposed to the same credentials and administrative plane as the monitored systems. Logging gaps and collection changes should generate alerts because attackers often target telemetry early in an intrusion.<\/span><\/p>\n<p><b>Question 351.<\/b><\/p>\n<p><b>Which security design best limits the consequences of compromise in one application tier?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Put all tiers on one unrestricted network.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use shared administrator credentials between tiers.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Segment tiers and permit only required application flows between them.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable east-west monitoring.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Tier-based segmentation limits communication between web, application, database, and management systems to required flows. If one tier is compromised, the attacker has fewer opportunities to move laterally. Shared credentials and unrestricted networking increase blast radius. Segmentation should be supported by service identity, least-privilege database access, and monitoring of unexpected internal connections.<\/span><\/p>\n<p><b>Question 352.<\/b><\/p>\n<p><b>Which statement best describes the purpose of risk acceptance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It means the risk no longer exists.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It is a documented decision by an authorized risk owner to tolerate residual risk.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically eliminates the need for monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It can be performed informally by any employee.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance is a deliberate governance decision to tolerate residual risk when further mitigation is not justified or feasible. It should be documented, approved by the appropriate risk owner, and reviewed periodically because business conditions and threat levels may change. Acceptance does not eliminate the risk itself or remove the need for monitoring. Significant accepted risks should have clear ownership and rationale.<\/span><\/p>\n<p><b>Question 353.<\/b><\/p>\n<p><b>Which action is most appropriate when a security team discovers a long-lived cloud access key belonging to an account that no longer exists?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke the key and investigate whether it was used after the account should have been decommissioned.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Leave it active for compatibility.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase its permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Exempt the key from logging.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Credentials associated with decommissioned identities should not remain active. The key should be revoked promptly, and audit logs should be reviewed to determine whether it was used unexpectedly. This scenario indicates a lifecycle management gap because identity removal should include associated keys, tokens, certificates, and sessions. Automated deprovisioning can reduce the likelihood of orphaned credentials.<\/span><\/p>\n<p><b>Question 354.<\/b><\/p>\n<p><b>Which architecture best supports recovery when both production systems and primary identity infrastructure are unavailable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require normal production SSO for every recovery operation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reuse production administrator accounts for all recovery systems.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep recovery infrastructure dependent on the same production network.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain independent recovery authentication, protected backups, and isolated recovery procedures.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery architecture should avoid relying entirely on the same systems that may be compromised or unavailable during a major incident. Independent authentication, protected backups, and isolated procedures create an alternate path to restoration. Recovery access must still be secured and audited, but it should not depend on failed production identity services. Regular exercises are necessary to validate the independence of these recovery mechanisms.<\/span><\/p>\n<p><b>Question 355.<\/b><\/p>\n<p><b>Which control most directly reduces the risk that confidential information is unintentionally shared through collaboration platforms?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all collaboration logging.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Make every document publicly shareable.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply DLP, sharing restrictions, classification labels, and access governance.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Trust users to manually identify every sensitive document.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DLP and classification labels can identify sensitive content and apply restrictions based on organizational policy. Sharing controls can prevent public or external access, while access governance helps ensure permissions remain appropriate over time. Manual judgment alone is inconsistent and does not scale. Collaboration platforms should also provide audit logs so unusual sharing activity can be investigated.<\/span><\/p>\n<p><b>Question 356.<\/b><\/p>\n<p><b>Which statement best describes the purpose of control validation through attack simulation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It proves that security products can never fail.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It tests whether preventive and detective controls respond as expected to realistic adversary techniques.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for incident response.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It should only occur after a breach.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attack simulation exercises security controls against realistic techniques to determine whether expected prevention, detection, and response outcomes actually occur. This can reveal telemetry gaps, weak rules, misconfigurations, or failed assumptions. Simulation does not guarantee perfect security, but it provides measurable evidence about control effectiveness. Results should feed detection engineering, architecture improvements, and response procedures.<\/span><\/p>\n<p><b>Question 357.<\/b><\/p>\n<p><b>Which practice best reduces the risk that forgotten third-party integrations retain access after a business relationship ends?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Include application credentials, OAuth grants, API keys, and service accounts in offboarding procedures.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Leave all integration credentials active indefinitely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Exempt third-party applications from access reviews.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase their permissions before contract termination.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party offboarding should revoke every access mechanism associated with the relationship, including OAuth grants, service accounts, API keys, certificates, and network trust. Forgotten integrations can become long-lived unauthorized access paths. Periodic reviews help identify abandoned applications even before formal contract termination. Access lifecycle governance should cover external identities as well as employees.<\/span><\/p>\n<p><b>Question 358.<\/b><\/p>\n<p><b>Which activity most strongly indicates possible persistence following compromise of an identity administrator?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user opens a standard application.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A scheduled report is generated.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A routine directory synchronization completes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A suspicious session registers a new authentication method and creates a privileged application identity.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creating alternate authentication methods and privileged application identities can give an attacker durable access even after the original password is changed. These actions are particularly suspicious when they follow abnormal identity-administrator activity. Responders should remove unauthorized methods, revoke sessions, review role assignments, preserve logs, and investigate whether other persistence mechanisms were established.<\/span><\/p>\n<p><b>Question 359.<\/b><\/p>\n<p><b>Which security design best limits misuse of internal APIs by automated workloads?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use one permanent administrator token for all workloads.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trust any traffic originating from the internal network.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use distinct workload identities, scoped authorization, short-lived credentials, and request monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable API audit logs.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Distinct workload identities provide accountability, while scoped authorization and short-lived credentials limit the effect of credential compromise. Request monitoring can identify unusual behavior such as new endpoints, excessive volume, or atypical operations. Internal location alone should not be treated as sufficient trust. Workload-to-workload APIs should follow the same zero-trust principles as user-facing applications.<\/span><\/p>\n<p><b>Question 360.<\/b><\/p>\n<p><b>Which approach best supports a mature enterprise security program over time?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treat compliance completion as the end of security work.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Continuously reassess risk, validate controls, measure detection and recovery, and improve architecture based on evidence.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review security only when regulations change.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoid testing systems that are currently operating normally.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mature security program continuously measures whether controls reduce real risk rather than relying solely on compliance status. Threats, systems, identities, dependencies, and business requirements change over time, so architecture and operations must evolve as well. Control testing, recovery exercises, detection metrics, threat modeling, and incident lessons provide evidence that can guide ongoing improvement.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 341. A security architect wants to prevent developers from granting excessive permissions to new cloud workloads. Which control is most effective? Enforce least-privilege role templates and policy-as-code checks during deployment 2. Give every workload administrator privileges initially 3. Allow teams to create [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24689"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24689"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24689\/revisions"}],"predecessor-version":[{"id":24690,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24689\/revisions\/24690"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}