Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is investigating a potential breach and needs to determine the timeline of events on a compromised Windows workstation. The analyst has access to the disk image and memory dump. Which artifact should the analyst examine FIRST to establish a timeline of file system activity?

⚠ Common exam trap

The trap here is assuming that Prefetch files provide a complete file system timeline, when they only record program execution and limited file references.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

$MFT (Master File Table)

The $MFT is the central repository for file metadata on NTFS, including timestamps for file creation, modification, and access. It provides a comprehensive record of file system activity, making it the primary artifact for timeline analysis. Other artifacts like Prefetch or Event Logs are useful for specific activities but do not cover the full scope of file system changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Registry hives

    Why it's wrong here

    Registry hives store configuration data, user settings, and some historical information like USB device connections or installed software. They are not designed to track file system activity and lack comprehensive timestamps for file operations. Therefore, they are not the best source for a file system timeline.

  • ✓

    $MFT (Master File Table)

    Why this is correct

    $MFT contains metadata for every file on an NTFS volume, including timestamps for creation, modification, and access. It is a primary source for file system timeline analysis. Other artifacts like prefetch or registry hives provide program execution or configuration data but are not as comprehensive for file system activity timelines.

  • ✗

    Prefetch files

    Why it's wrong here

    Prefetch files contain information about program execution, including when an application was last run and which files it accessed. While useful for execution timeline, they do not cover all file system activity. They are limited to executed programs and do not provide a full file system timeline like $MFT does.

  • ✗

    Windows Event Logs

    Why it's wrong here

    Windows Event Logs record system, security, and application events, which can help establish a timeline of user logons, service starts, and other activities. However, they do not directly record file creation or modification events unless auditing is enabled. They are not the first choice for file system activity timeline compared to $MFT.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.