CAS-004 • Practice Test 42
Free CAS-004 practice test — 15 questions with explanations. Set 42. No signup required.
A security analyst is investigating a possible insider threat. The analyst has access to endpoint detection and response (EDR) telemetry, network flow logs, and authentication logs. The analyst suspects that a user is exfiltrating data by encoding it into DNS queries to a domain controlled by the attacker. Which data source and analysis technique would best confirm this activity?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.