Courseiva
Security Operations →hardMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is investigating a security incident where an attacker gained unauthorized access to a server. The analyst reviews the server logs and finds the following entries: 'Accepted password for root from 192.168.1.100 port 22 ssh2' followed by 'session opened for user root by (uid=0)'. The analyst suspects the attacker used stolen credentials. Which of the following log sources would provide the MOST direct evidence of the attacker's activities after the initial access?

⚠ Common exam trap

The trap here is assuming that bash history or authentication logs provide sufficient detail about post-exploitation activities, when in fact system call auditing offers more comprehensive and reliable evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System call auditing logs (e.g., auditd).

System call auditing logs, such as those from auditd, capture detailed system-level activities including process execution, file access, and network connections. They are tamper-resistant and provide a comprehensive record of the attacker's actions after initial access. Authentication logs only show login events, bash history can be altered, and NetFlow lacks host-based detail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    System call auditing logs (e.g., auditd).

    Why this is correct

    System call auditing logs, such as those generated by auditd on Linux, record detailed information about system calls, including process execution, file access, and network activity. They provide a comprehensive and tamper-resistant record of the attacker's actions after initial access. This is the most direct evidence for forensic analysis.

  • ✗

    Network flow data (NetFlow) from the server's switch.

    Why it's wrong here

    NetFlow data provides information about network connections, such as source/destination IP, ports, and bytes transferred, but it does not reveal what the attacker did on the server itself. It can show lateral movement or data exfiltration but lacks the granularity of system-level auditing. Thus, it is not the most direct evidence of post-access activities.

  • ✗

    Bash history file for the root user.

    Why it's wrong here

    The bash history file can show commands executed by the root user, but it is not a reliable source because it can be easily modified or deleted by the attacker. Additionally, it only captures interactive shell commands, not actions performed by scripts or other processes. Thus, it is not the most direct or trustworthy evidence.

  • ✗

    Authentication logs from the SSH service.

    Why it's wrong here

    Authentication logs show the successful login but do not provide details about what commands were executed or files accessed after the session opened. They are useful for identifying the initial access vector but not for post-exploitation activities. The analyst needs logs that record command execution or system calls to understand the attacker's actions.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.