CAS-004 Security Operations Practice Question
A security analyst is investigating a security incident where an attacker gained unauthorized access to a server. The analyst reviews the server logs and finds the following entries: 'Accepted password for root from 192.168.1.100 port 22 ssh2' followed by 'session opened for user root by (uid=0)'. The analyst suspects the attacker used stolen credentials. Which of the following log sources would provide the MOST direct evidence of the attacker's activities after the initial access?
⚠ Common exam trap
The trap here is assuming that bash history or authentication logs provide sufficient detail about post-exploitation activities, when in fact system call auditing offers more comprehensive and reliable evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System call auditing logs (e.g., auditd).
System call auditing logs, such as those from auditd, capture detailed system-level activities including process execution, file access, and network connections. They are tamper-resistant and provide a comprehensive record of the attacker's actions after initial access. Authentication logs only show login events, bash history can be altered, and NetFlow lacks host-based detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
System call auditing logs (e.g., auditd).
Why this is correct
System call auditing logs, such as those generated by auditd on Linux, record detailed information about system calls, including process execution, file access, and network activity. They provide a comprehensive and tamper-resistant record of the attacker's actions after initial access. This is the most direct evidence for forensic analysis.
- ✗
Network flow data (NetFlow) from the server's switch.
Why it's wrong here
NetFlow data provides information about network connections, such as source/destination IP, ports, and bytes transferred, but it does not reveal what the attacker did on the server itself. It can show lateral movement or data exfiltration but lacks the granularity of system-level auditing. Thus, it is not the most direct evidence of post-access activities.
- ✗
Bash history file for the root user.
Why it's wrong here
The bash history file can show commands executed by the root user, but it is not a reliable source because it can be easily modified or deleted by the attacker. Additionally, it only captures interactive shell commands, not actions performed by scripts or other processes. Thus, it is not the most direct or trustworthy evidence.
- ✗
Authentication logs from the SSH service.
Why it's wrong here
Authentication logs show the successful login but do not provide details about what commands were executed or files accessed after the session opened. They are useful for identifying the initial access vector but not for post-exploitation activities. The analyst needs logs that record command execution or system calls to understand the attacker's actions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.