CAS-004 Security Operations Practice Question
A security analyst is investigating a potential breach and needs to determine the timeline of events on a compromised Windows workstation. The analyst has access to the disk image and memory dump. Which artifact should the analyst examine FIRST to establish a timeline of file system activity?
⚠ Common exam trap
The trap here is assuming that Prefetch files provide a complete file system timeline, when they only record program execution and limited file references.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$MFT (Master File Table)
The $MFT is the central repository for file metadata on NTFS, including timestamps for file creation, modification, and access. It provides a comprehensive record of file system activity, making it the primary artifact for timeline analysis. Other artifacts like Prefetch or Event Logs are useful for specific activities but do not cover the full scope of file system changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Registry hives
Why it's wrong here
Registry hives store configuration data, user settings, and some historical information like USB device connections or installed software. They are not designed to track file system activity and lack comprehensive timestamps for file operations. Therefore, they are not the best source for a file system timeline.
- ✓
$MFT (Master File Table)
Why this is correct
$MFT contains metadata for every file on an NTFS volume, including timestamps for creation, modification, and access. It is a primary source for file system timeline analysis. Other artifacts like prefetch or registry hives provide program execution or configuration data but are not as comprehensive for file system activity timelines.
- ✗
Prefetch files
Why it's wrong here
Prefetch files contain information about program execution, including when an application was last run and which files it accessed. While useful for execution timeline, they do not cover all file system activity. They are limited to executed programs and do not provide a full file system timeline like $MFT does.
- ✗
Windows Event Logs
Why it's wrong here
Windows Event Logs record system, security, and application events, which can help establish a timeline of user logons, service starts, and other activities. However, they do not directly record file creation or modification events unless auditing is enabled. They are not the first choice for file system activity timeline compared to $MFT.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.