CAS-004 Security Operations Practice Question
A security analyst is investigating a potential compromise of a Windows server. The analyst suspects that an attacker used a technique to dump credentials from memory. Which TWO of the following artifacts or events would MOST likely indicate that a credential dumping tool such as Mimikatz was executed? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any process creation or service installation involving lsass or Mimikatz is a clear indicator, when in fact credential dumping is best detected by monitoring access to lsass memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 10 from Sysmon showing lsass.exe accessed by an unsigned process
The correct indicators are a handle request to lsass.exe with PROCESS_VM_READ (Event ID 4656) and Sysmon Event ID 10 showing lsass.exe accessed by an unsigned process. Both directly relate to unauthorized memory reading of the Local Security Authority Subsystem Service, which stores credentials. The other events are either normal system activities or too generic to specifically indicate credential dumping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event ID 4624 with logon type 3 (network) for a service account
Why it's wrong here
Event ID 4624 with logon type 3 indicates a network logon, which is common for service accounts accessing resources. While it could be part of lateral movement, it does not directly indicate credential dumping from memory. Attackers may use such logons after dumping credentials, but the event itself is not specific to the technique.
- ✓
Event ID 10 from Sysmon showing lsass.exe accessed by an unsigned process
Why this is correct
Sysmon Event ID 10 logs process access, including when a process opens a handle to another process. If an unsigned process accesses lsass.exe, it is highly suspicious because legitimate processes accessing lsass are typically signed by Microsoft. This event is a strong indicator of credential dumping attempts, as tools like Mimikatz often run as unsigned binaries or injected code.
- ✗
Event ID 4688 with process creation for lsass.exe
Why it's wrong here
Event ID 4688 logs process creation, but lsass.exe is a legitimate system process that runs normally. Its creation does not indicate credential dumping; an attacker would not typically create a new lsass.exe. Instead, they would access the existing lsass process memory, so this event is not a reliable indicator.
- ✗
Event ID 7045 with a new service named 'MimikatzSvc'
Why it's wrong here
Event ID 7045 logs the installation of a new service. While an attacker might install a malicious service, credential dumping tools like Mimikatz typically run as standalone executables or injected code, not as services. The service name 'MimikatzSvc' is a blatant indicator, but real attackers would likely use less obvious names, and this event alone does not confirm credential dumping.
- ✓
Event ID 4656 with handle to lsass.exe requesting PROCESS_VM_READ
Why this is correct
Event ID 4656 logs handle requests to objects. When a process requests PROCESS_VM_READ access to lsass.exe, it indicates an attempt to read its memory, which is a hallmark of credential dumping tools like Mimikatz. This event, especially when combined with other indicators, strongly suggests malicious activity targeting credential storage.
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.