{"id":24691,"date":"2026-09-29T12:00:30","date_gmt":"2026-09-29T12:00:30","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=24691"},"modified":"2026-09-29T12:00:30","modified_gmt":"2026-09-29T12:00:30","slug":"comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-securityx-ca1-005-test-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"CompTIA SecurityX CA1-005 Test Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/ca1-005-exam-dumps\"><b>CompTIA SecurityX CA1-005 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 361.<\/b><\/p>\n<p><b>A security architect wants to prevent a compromised application from accessing cloud resources outside its normal business function. Which control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use a dedicated workload identity with least-privilege permissions and resource-level restrictions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assign the application a global administrator role<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share one access key across all applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable authorization checks for trusted workloads<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A dedicated workload identity allows permissions to be restricted to only the resources and actions required by that application. If the workload is compromised, the attacker&#8217;s access remains constrained. Shared keys and broad administrator privileges increase blast radius and make accountability difficult. Resource-level authorization should be combined with short-lived credentials, secret management, monitoring, and periodic entitlement reviews so unused permissions can be removed.<\/span><\/p>\n<p><b>Question 362.<\/b><\/p>\n<p><b>Which architecture best protects security telemetry from attackers who gain administrator access to production systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep all logs only on production hosts.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow local administrators to delete audit records without review.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable security log forwarding.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Export logs to a separate protected security account or immutable logging platform.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A separate logging security boundary makes it more difficult for attackers with production privileges to erase evidence. Immutable or write-protected storage further protects historical records from alteration. Local-only logging creates a common failure domain because the same administrator who compromises the system may also delete its logs. Security teams should also monitor for logging interruptions and unexpected retention-policy changes.<\/span><\/p>\n<p><b>Question 363.<\/b><\/p>\n<p><b>Which capability is most useful for identifying whether a cloud user can indirectly gain administrative rights through nested permissions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> RAID monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Identity attack-path analysis and permission graphing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity attack-path analysis maps relationships among users, groups, roles, trusts, service principals, and resources. It can reveal indirect privilege paths that are not obvious from a single access-control policy. These paths may allow a low-privilege identity to reach highly privileged resources through inheritance or delegation. Graph analysis helps security teams identify and remove unintended privilege-escalation opportunities.<\/span><\/p>\n<p><b>Question 364.<\/b><\/p>\n<p><b>Which control best reduces the risk of a stolen API token being used from an unauthorized environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the token lifetime.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use short-lived, sender-constrained or context-bound tokens with revocation support.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Store the token in application logs.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable token validation after initial authentication.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Short-lived tokens reduce the attack window, while sender-constrained or context-bound tokens make simple replay from another client more difficult. Revocation allows defenders to invalidate compromised sessions or credentials quickly. Increasing token lifetime or disabling validation increases exposure. High-value APIs should also validate issuer, audience, scopes, expiration, and requested operations for every sensitive request.<\/span><\/p>\n<p><b>Question 365.<\/b><\/p>\n<p><b>A security team wants to prevent a compromised developer account from independently approving and releasing production code. Which control is strongest?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enforce separation of duties with independent review and release approval<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give developers direct production administrator access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use shared deployment credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable release auditing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separation of duties prevents one compromised or malicious account from controlling the entire release process. Independent review and approval add another decision point before production deployment. Shared credentials and direct production access weaken accountability and bypass important controls. Secure release processes should also use protected branches, signed artifacts, short-lived deployment identities, and tamper-resistant logs.<\/span><\/p>\n<p><b>Question 366.<\/b><\/p>\n<p><b>Which architecture best protects sensitive data being processed by workloads in an untrusted hosting environment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use plaintext shared memory.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable workload isolation.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Rely only on disk encryption.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use confidential computing with trusted execution environments and attestation.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Confidential computing protects data during active processing inside hardware-backed trusted execution environments. Remote attestation can verify the workload state before secrets or sensitive data are released. Disk encryption protects data at rest but does not protect plaintext while it is processed. Confidential computing complements TLS, storage encryption, workload identity, and access control in high-assurance environments.<\/span><\/p>\n<p><b>Question 367.<\/b><\/p>\n<p><b>Which security practice best identifies service accounts that have more privilege than they actually use?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable entitlement reviews.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give every service account administrator access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compare assigned permissions with actual permission usage.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share service identities across applications.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Comparing assigned permissions with observed use can reveal unnecessary privileges that should be removed. Service accounts frequently accumulate access over time as applications evolve. Unused privileges increase the impact of credential compromise even though legitimate workloads do not need them. Permission usage analysis supports least privilege and should be combined with periodic access reviews and credential lifecycle management.<\/span><\/p>\n<p><b>Question 368.<\/b><\/p>\n<p><b>Which statement best describes the purpose of mutual TLS between services?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need for authorization.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It encrypts traffic and allows both services to authenticate each other.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees that application code is secure.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It replaces segmentation.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mutual TLS protects traffic in transit and requires both endpoints to present trusted certificates, providing bidirectional authentication. This is useful for service-to-service communication in zero-trust and service-mesh environments. However, mTLS does not replace authorization, segmentation, secure coding, or workload policy. Certificate issuance, rotation, revocation, and trust management are also important to maintain security.<\/span><\/p>\n<p><b>Question 369.<\/b><\/p>\n<p><b>A security analyst detects repeated attempts by a workload to access a cloud metadata endpoint immediately after receiving user-controlled URLs. Which attack should be investigated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server-side request forgery<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Password spraying<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ARP poisoning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Bluetooth spoofing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A workload accessing cloud metadata after processing user-controlled URLs strongly suggests server-side request forgery. An attacker may attempt to force the application to retrieve internal metadata, temporary credentials, or other protected resources. Defenses include strict URL validation, outbound filtering, metadata-service protections, and least-privilege workload roles. Password spraying and local network attacks do not best fit this scenario.<\/span><\/p>\n<p><b>Question 370.<\/b><\/p>\n<p><b>Which control provides the strongest protection for cryptographic keys used to sign enterprise software releases?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store them in developer home directories.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Commit them to a private code repository.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Keep them in pipeline environment variables indefinitely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use an HSM with controlled signing operations and strict authorization.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An HSM protects private key material from direct extraction and can restrict signing operations to approved users or automated workflows. Developer directories, repositories, and environment variables expose high-value signing keys to unnecessary risk. Strong signing systems should also use separation of duties, release approval, provenance verification, key rotation, and detailed audit logging.<\/span><\/p>\n<p><b>Question 371.<\/b><\/p>\n<p><b>Which architecture best limits lateral movement from a compromised application server to database and identity infrastructure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place all systems on one flat subnet.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Give the application broad administrative access.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use segmentation with explicit network and service-level allow policies.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable east-west traffic monitoring.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segmentation limits which systems a compromised application can reach. Explicit allow policies should permit only required dependencies and deny unnecessary communication with identity, management, or unrelated database systems. Flat networks and broad privileges increase lateral-movement opportunities. Strong containment also uses workload identity, least privilege, application-level authorization, and monitoring of internal traffic.<\/span><\/p>\n<p><b>Question 372.<\/b><\/p>\n<p><b>Which statement best describes the purpose of an access review?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It permanently grants users their current permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It verifies that existing permissions remain appropriate for current business responsibilities.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for deprovisioning.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It applies only to guest accounts.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Access reviews validate whether users, service accounts, groups, and applications still require their assigned permissions. Role changes and project transitions can cause privilege creep if unnecessary access is never removed. Regular reviews support least privilege and help identify dormant or excessive access. They should include privileged identities, third-party accounts, machine identities, and sensitive applications where appropriate.<\/span><\/p>\n<p><b>Question 373.<\/b><\/p>\n<p><b>Which action is most appropriate after discovering that a privileged service account credential has been exposed in a public artifact repository?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revoke or rotate the credential immediately and investigate whether it was used.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete only the visible file and continue using the credential.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Wait until the credential expires naturally.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase the account&#8217;s privileges for troubleshooting.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A publicly exposed credential should be treated as compromised because it may already have been copied, indexed, or cached. Rotation or revocation limits further misuse, while audit logs should be reviewed for suspicious activity. Simply deleting the artifact does not remove historical copies. The organization should also identify why the secret was exposed and implement secret scanning or managed credential retrieval to prevent recurrence.<\/span><\/p>\n<p><b>Question 374.<\/b><\/p>\n<p><b>Which architecture best preserves recovery capability if ransomware compromises production identities and management systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use production credentials for all backup administration.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep every recovery copy directly writable from production.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Join backup infrastructure to the same administrative domain.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use isolated recovery administration, separate identities, and immutable or offline backups.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Isolated recovery infrastructure and separate identities reduce the chance that compromise of production administration also destroys the organization&#8217;s recovery capability. Immutable or offline copies make backup destruction significantly harder. Shared credentials and writable repositories create a single failure domain. Recovery procedures should be exercised regularly to confirm that teams can restore critical systems even when normal identity services are unavailable.<\/span><\/p>\n<p><b>Question 375.<\/b><\/p>\n<p><b>Which control most directly reduces the risk that sensitive production information appears in lower-security development systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Copy complete production databases to developer laptops.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable nonproduction encryption.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use masking, anonymization, or synthetic data when real identifiers are unnecessary.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Give developers unrestricted production access.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Masked, anonymized, and synthetic data reduce exposure of real customer or regulated information while preserving useful testing characteristics. Development environments often have broader access and different operational controls, making unnecessary production data risky. Data minimization should therefore be applied wherever possible. Nonproduction systems should still use strong authentication, logging, encryption, and segmentation.<\/span><\/p>\n<p><b>Question 376.<\/b><\/p>\n<p><b>Which statement best describes the purpose of security control testing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It proves that a control will never fail.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It determines whether a control is implemented correctly and produces the intended security outcome.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It removes the need for monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It is required only after an incident.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control testing provides evidence that a safeguard is actually configured and operating as intended. A product being deployed does not guarantee that it prevents or detects relevant attacks. Testing can involve technical validation, simulations, audits, or review of measurable outcomes. Findings should lead to remediation, tuning, or architectural changes when controls do not meet expectations.<\/span><\/p>\n<p><b>Question 377.<\/b><\/p>\n<p><b>Which practice best reduces the risk from third-party applications that retain access after their business purpose ends?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Periodically review and revoke unused OAuth grants, service accounts, API keys, and application permissions.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Leave all integrations active indefinitely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Exempt third-party applications from monitoring.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase permissions on unused integrations.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unused integrations can retain access long after users and administrators forget they exist. Periodic reviews should verify ownership, business justification, requested scopes, and recent activity. Credentials and grants that are no longer required should be revoked. Third-party application lifecycle management is an important part of attack-surface reduction because abandoned integrations can become hidden persistence paths.<\/span><\/p>\n<p><b>Question 378.<\/b><\/p>\n<p><b>Which activity most strongly suggests a malicious attempt to weaken endpoint defenses?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A normal application launches.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A scheduled system backup completes.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> An approved patch is installed.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A privileged account disables endpoint protection across multiple systems immediately after suspicious authentication.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling endpoint protection across multiple systems after anomalous privileged authentication is a strong sign of malicious activity. Attackers often weaken defensive controls before deploying ransomware, credential theft tools, or persistence mechanisms. Security teams should validate the account, restore protection, revoke suspicious sessions, preserve logs, and investigate any actions performed while defenses were disabled.<\/span><\/p>\n<p><b>Question 379.<\/b><\/p>\n<p><b>Which security design best protects machine-to-machine API communication in a zero-trust architecture?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Trust all internal IP addresses automatically.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use one shared API key for every workload.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use workload identities, mutual authentication, scoped authorization, and short-lived credentials.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable API logging to reduce overhead.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero-trust service communication requires explicit identity and authorization rather than trust based on network location. Workload identities provide accountability, mutual authentication establishes both endpoints, scoped permissions enforce least privilege, and short-lived credentials reduce credential-theft impact. Shared keys and IP-based trust provide weaker security boundaries and larger blast radius.<\/span><\/p>\n<p><b>Question 380.<\/b><\/p>\n<p><b>Which approach best supports a continuously improving enterprise security architecture?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume approved designs remain secure indefinitely.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Regularly reassess threat models, test controls, review identity and configuration drift, and incorporate incident lessons into architecture.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Change architecture only after major breaches.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoid measuring control effectiveness.<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise security architecture must evolve as workloads, identities, dependencies, attacker techniques, and business requirements change. Threat-model reviews, control validation, entitlement reviews, drift monitoring, resilience exercises, and incident lessons provide evidence about where protections need improvement. Continuous reassessment helps prevent outdated assumptions from becoming persistent security weaknesses.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA SecurityX CA1-005 Exam Dumps and Practice Test Dumps &nbsp; Question 361. A security architect wants to prevent a compromised application from accessing cloud resources outside its normal business function. Which control is most appropriate? Use a dedicated workload identity with least-privilege permissions and resource-level restrictions 2. Assign the application a global administrator [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24691"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=24691"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24691\/revisions"}],"predecessor-version":[{"id":24692,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/24691\/revisions\/24692"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=24691"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=24691"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=24691"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}