Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is investigating a potential malware infection on a Windows workstation. The analyst wants to perform live response to collect volatile data. Which of the following commands or tools should the analyst use to capture volatile data? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse non-volatile registry or file system data with volatile data, or assuming Linux commands work on Windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use `netstat -anob` to capture active network connections and associated process IDs.

Volatile data includes information that is lost when the system is powered off, such as active network connections and running processes. The `netstat -anob` command captures network connections with associated process IDs, and `wmic process get name,processid,commandline` captures running processes with command lines. Both are essential for live response on Windows and help identify malicious activity quickly. The other options involve non-volatile data or are not applicable to Windows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use `netstat -anob` to capture active network connections and associated process IDs.

    Why this is correct

    `netstat -anob` displays active connections, listening ports, and the executable name and PID for each connection. This is volatile data that can be lost on reboot and is crucial for identifying command-and-control connections. It is a standard live response command for capturing network state on Windows systems.

  • ✗

    Use `fsutil usn readjournal C:` to read the USN journal for file system changes.

    Why it's wrong here

    `fsutil usn readjournal` reads the change journal, which records modifications to files on an NTFS volume. While it can provide historical data about file changes, it is not considered volatile data in the same sense as running processes or network connections. The USN journal persists across reboots, so it is less time-sensitive and not typically part of initial volatile data collection.

  • ✓

    Use `wmic process get name,processid,commandline` to list running processes and their command lines.

    Why this is correct

    `wmic process get name,processid,commandline` retrieves detailed information about running processes, including command-line arguments that might reveal malicious scripts or parameters. This is volatile data that helps identify suspicious processes. It is a reliable method for capturing process information during live response.

  • ✗

    Use `reg export HKLM\Software\Microsoft\Windows\CurrentVersion\Run run.reg` to export autostart entries.

    Why it's wrong here

    Exporting registry keys for autostart entries is useful for persistence analysis, but registry data is stored on disk and is not volatile. It can be collected after a reboot. Live response prioritizes volatile data that would be lost, such as network connections and process memory, so this is not one of the first two choices for volatile data capture.

  • ✗

    Use `dd if=/dev/mem of=memory.dmp` to capture physical memory.

    Why it's wrong here

    `dd` is a Linux/Unix command and `/dev/mem` is not a standard Windows path. On Windows, memory capture requires specialized tools like WinPmem or DumpIt. Using `dd` in this manner would not work on a Windows workstation and is not a valid live response technique for Windows.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.