Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is investigating a possible insider threat. The analyst has access to endpoint detection and response (EDR) telemetry, network flow logs, and authentication logs. The analyst suspects that a user is exfiltrating data by encoding it into DNS queries to a domain controlled by the attacker. Which data source and analysis technique would best confirm this activity?

⚠ Common exam trap

The trap here is assuming that network flow logs will show large data transfers, but DNS exfiltration uses many small queries that may not exceed volume thresholds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inspect DNS query logs for unusually long or high-entropy subdomain strings and repeated queries to the same domain.

DNS exfiltration hides data in DNS queries, typically as encoded subdomains. The most direct way to confirm is to examine DNS query logs for indicators like long, high-entropy labels and repetitive queries to the same domain. Other data sources may show related activity but do not directly reveal the DNS-based channel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Inspect DNS query logs for unusually long or high-entropy subdomain strings and repeated queries to the same domain.

    Why this is correct

    DNS exfiltration often encodes data in subdomains, resulting in long, random-looking strings. Analyzing DNS query logs for such patterns, especially repeated queries to a single domain, can reveal tunneling. This directly addresses the scenario and uses the appropriate data source.

  • ✗

    Review authentication logs for anomalous login times or locations from the user's account.

    Why it's wrong here

    Authentication logs can indicate compromised credentials or insider access, but they do not show data exfiltration via DNS. The scenario already assumes the user is the insider; the focus is on the exfiltration method, not login anomalies.

  • ✗

    Correlate EDR process creation events with network connections to known malicious IP addresses.

    Why it's wrong here

    EDR process events and IP connections are useful for detecting malware, but DNS exfiltration may not involve direct IP connections to malicious addresses; the attacker uses DNS. This approach might miss the DNS-based channel and is not the best fit for confirming DNS exfiltration.

  • ✗

    Analyze network flow logs for large outbound data transfers to external IP addresses.

    Why it's wrong here

    Network flow logs capture volume and endpoints, but DNS exfiltration often uses small, frequent queries that may not trigger large transfer thresholds. Flow logs might show traffic to the DNS server, but not the encoded data. This method is less effective for detecting DNS tunneling.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.