Courseiva
mediumMultiple Select

CAS-004 Practice Question: A security administrator is evaluating ways to…

A security administrator is evaluating ways to improve endpoint detection and response (EDR) capabilities. Which TWO of the following approaches would most effectively enhance the detection of fileless malware attacks?

⚠ Common exam trap

CAS-005 often tests the misconception that adding more signature-based or network-layer tools (NIDS, ML antivirus, FIM) will catch fileless attacks, when in fact only behavioral endpoint telemetry — script logging and process lineage — provides the necessary visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitor PowerShell script block logging and execution events.

Option A is correct because fileless malware frequently abuses PowerShell to execute malicious code in memory, and enabling PowerShell script block logging (Event ID 4104) plus execution events (Event ID 4103/4104) captures the actual script content and commands, giving EDR the telemetry needed to detect these in-memory attacks. Option C is correct because fileless techniques typically spawn processes from unusual parents (e.g., winword.exe launching powershell.exe or wmic.exe), so monitoring process creation chains and parent-child relationships via tools like Sysmon (Event ID 1) or Windows Security Event ID 4688 exposes these anomalous execution patterns. Option B is not the best fit because a NIDS inspects network traffic and cannot see in-memory or script-based execution on the endpoint, so it misses the core of fileless attacks. Option D is not ideal because FIM only detects changes to files on disk, whereas fileless malware resides in memory and leaves little or no file artifacts. Option E is not the best choice because signature- and ML-based antivirus primarily targets known or file-based malware and often fails against fileless techniques that never write a malicious file to disk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Monitor PowerShell script block logging and execution events.

    Why this is correct

    PowerShell script block logging captures deobfuscated script content and execution events directly within the engine, exposing fileless techniques that never write to disk. This satisfies the stem's requirement to detect fileless malware, which evades traditional file-scanning EDR by residing only in memory and script interpreters.

  • ✗

    Install a network intrusion detection system (NIDS) to inspect traffic.

    Why it's wrong here

    A NIDS inspects network traffic, so fileless code executing locally in memory on the endpoint generates no traffic for it to inspect. It is tempting because it is a detection control, and would be correct for command-and-control beaconing or exploit delivery crossing the wire.

  • ✓

    Monitor process creation chain events to detect anomalous parent-child relationships.

    Why this is correct

    Monitoring process creation chains exposes anomalous parent-child relationships, such as Office spawning PowerShell, which fileless malware relies on since it injects into memory rather than writing files to disk. This satisfies the stem's requirement to detect fileless attacks by catching the execution behaviour itself, rather than relying on file signatures that never appear.

  • ✗

    Enable file integrity monitoring (FIM) on critical system files.

    Why it's wrong here

    Fileless malware executes in memory via PowerShell or WMI, leaving no files on disk for FIM to hash or baseline, so it detects nothing here. FIM is tempting because it catches tampering with critical system files, and would be correct against rootkits or configuration drift.

  • ✗

    Deploy advanced antivirus with machine learning signatures.

    Why it's wrong here

    Signature-based scanning inspects files on disk, so in-memory PowerShell and reflective DLL injection evade it entirely. Machine learning signatures remain signature matching, not behavioural telemetry. It is tempting as a modern-sounding upgrade, and would be correct for known malware families with file artefacts.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.