Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is investigating a potential compromise of a Windows server. The analyst suspects that an attacker used a technique to dump credentials from memory. Which TWO of the following artifacts or events would MOST likely indicate that a credential dumping tool such as Mimikatz was executed? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any process creation or service installation involving lsass or Mimikatz is a clear indicator, when in fact credential dumping is best detected by monitoring access to lsass memory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event ID 10 from Sysmon showing lsass.exe accessed by an unsigned process

The correct indicators are a handle request to lsass.exe with PROCESS_VM_READ (Event ID 4656) and Sysmon Event ID 10 showing lsass.exe accessed by an unsigned process. Both directly relate to unauthorized memory reading of the Local Security Authority Subsystem Service, which stores credentials. The other events are either normal system activities or too generic to specifically indicate credential dumping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event ID 4624 with logon type 3 (network) for a service account

    Why it's wrong here

    Event ID 4624 with logon type 3 indicates a network logon, which is common for service accounts accessing resources. While it could be part of lateral movement, it does not directly indicate credential dumping from memory. Attackers may use such logons after dumping credentials, but the event itself is not specific to the technique.

  • ✓

    Event ID 10 from Sysmon showing lsass.exe accessed by an unsigned process

    Why this is correct

    Sysmon Event ID 10 logs process access, including when a process opens a handle to another process. If an unsigned process accesses lsass.exe, it is highly suspicious because legitimate processes accessing lsass are typically signed by Microsoft. This event is a strong indicator of credential dumping attempts, as tools like Mimikatz often run as unsigned binaries or injected code.

  • ✗

    Event ID 4688 with process creation for lsass.exe

    Why it's wrong here

    Event ID 4688 logs process creation, but lsass.exe is a legitimate system process that runs normally. Its creation does not indicate credential dumping; an attacker would not typically create a new lsass.exe. Instead, they would access the existing lsass process memory, so this event is not a reliable indicator.

  • ✗

    Event ID 7045 with a new service named 'MimikatzSvc'

    Why it's wrong here

    Event ID 7045 logs the installation of a new service. While an attacker might install a malicious service, credential dumping tools like Mimikatz typically run as standalone executables or injected code, not as services. The service name 'MimikatzSvc' is a blatant indicator, but real attackers would likely use less obvious names, and this event alone does not confirm credential dumping.

  • ✓

    Event ID 4656 with handle to lsass.exe requesting PROCESS_VM_READ

    Why this is correct

    Event ID 4656 logs handle requests to objects. When a process requests PROCESS_VM_READ access to lsass.exe, it indicates an attempt to read its memory, which is a hallmark of credential dumping tools like Mimikatz. This event, especially when combined with other indicators, strongly suggests malicious activity targeting credential storage.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.