Free CA1-005 Comptia CA1-005 Practice Test Question

Loading demo links...

Showing 1–2 of 2 questions

Question 1 (Topic 1)

A global organization is reviewing potential vendors to outsource a critical payroll function. Each vendor's plan includes using local resources in multiple regions to ensure compliance with all regulations. The organization's Chief Information Security Officer is conducting a risk assessment on the potential outsourcing vendors' subprocessors. Which of the following best explains the need for this risk assessment?

Select an option, then click Submit answer.

  • Risk mitigations must be more comprehensive than the existing payroll provider.
  • Due care must be exercised during all procurement activities.
  • The responsibility of protecting PII remains with the organization.
  • Specific regulatory requirements must be met in each jurisdiction.
Question 2 (Topic 1)

A company that uses containers to run its applications is required to identify vulnerabilities on every container image in a private repository. The security team needs to be able to quickly evaluate whether to respond to a given vulnerability. Which of the following will allow the security team to achieve the objective with the least effort?

Select an option, then click Submit answer.

  • SAST scan reports
  • Centralized SBoM
  • CIS benchmark compliance reports
  • Credentialed vulnerability scan