CompTIA CA1-005 - CompTIA SecurityX Exam

Question #11 (Topic: Exam A)
SIMULATION
You are tasked with integrating a new B2B client application with an existing OAuth workflow that must meet the following requirements:
• The application does not need to know the users' credentials.
• An approval interaction between the users and the HTTP service must be orchestrated.
• The application must have limited access to users' data.
INSTRUCTIONS
Use the drop-down menus to select the action items for the appropriate locations. All placeholders must be filled.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Answer:
Question #12 (Topic: Exam A)
A security analyst wants to use lessons learned from a prior incident response to reduce dwell time in the future. The analyst is using the following data points:

Which of the following would the analyst most likely recommend?
A. Adjusting the SIEM to alert on attempts to visit phishing sites B. Allowing TRACE method traffic to enable better log correlation C. Enabling alerting on all suspicious administrator behavior D. Utilizing allow lists on the WAF for all users using GET methods
Answer: A
Question #13 (Topic: Exam A)
An organization recently implemented a policy that requires all passwords to be rotated every 90 days. An administrator sees a large volume of failed sign-on logs from multiple servers that are often accessed by users. The administrator determines users are disconnecting from the RDP session but not logging off. Which of the following should the administrator do to prevent account lockouts?
A. Increase the account lockout threshold. B. Enforce password complexity. C. Force daily reboots. D. Extend the allowed session length.
Answer: C
Question #14 (Topic: Exam A)
A security analyst is reviewing the following code in the public repository for potential risk concerns:

Which of the following should the security analyst recommend first to remediate the vulnerability?
A. Developing role-based security awareness training B. Revoking the secret used in the solution C. Purging code from public view D. Scanning the application with SAST
Answer: B
Question #15 (Topic: Exam A)
During a recent assessment, a security analyst observed the following:

Which of the following should the analyst use to address the vulnerabilities in the future?
A. System image hardening B. Least privilege C. Defense in depth D. OS update
Answer: C
Download Exam
Page: 3 / 23
Total 115 questions