CAS-004 Security Operations Practice Question
A security analyst is reviewing a potentially malicious PowerShell script that was executed on a workstation. The script contains obfuscated code and makes network connections. The analyst wants to perform dynamic analysis to understand its behavior. Which TWO of the following methods would BEST allow the analyst to observe the script's runtime actions in a controlled environment? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse static analysis or restrictive controls with dynamic analysis, which requires executing the code in a safe environment to observe behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up a debugger and step through the script line by line
Dynamic analysis involves executing the script in a controlled environment to observe its behavior. An isolated sandbox with network simulation allows safe execution and monitoring of API calls, network traffic, and system changes. Stepping through the script with a debugger provides line-by-line visibility into its execution, revealing obfuscated logic and runtime actions. Both methods are essential for understanding malicious scripts without risking production systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use PowerShell's Constrained Language Mode to restrict script execution
Why it's wrong here
Constrained Language Mode restricts PowerShell capabilities to prevent malicious scripts from running, but it does not help analyze the script's behavior. It is a mitigation, not an analysis method. The analyst wants to observe what the script does, not block it. Thus, this is not a dynamic analysis technique for understanding behavior.
- ✓
Set up a debugger and step through the script line by line
Why this is correct
Using a debugger to step through the script line by line allows the analyst to observe variable values, function calls, and execution flow in real time. This is a powerful dynamic analysis method for understanding obfuscated scripts. It can reveal decryption routines and network calls as they happen, without needing to fully deobfuscate statically.
- ✓
Execute the script in an isolated sandbox with network simulation and monitor API calls
Why this is correct
Running the script in an isolated sandbox with network simulation allows safe observation of its behavior, including API calls, file system changes, and network traffic. This is a core dynamic analysis technique. The sandbox prevents the malware from affecting production systems while providing detailed telemetry on its actions.
- ✗
Perform static analysis by extracting strings and examining the abstract syntax tree
Why it's wrong here
Static analysis involves examining the script without executing it, such as extracting strings or building an AST. While valuable, it is not dynamic analysis. The question asks for dynamic analysis methods to observe runtime actions. Static analysis may be hindered by obfuscation and does not show actual behavior.
- ✗
Run the script on a production workstation with logging enabled
Why it's wrong here
Running a potentially malicious script on a production workstation is dangerous and unethical, as it could cause damage or spread malware. Dynamic analysis should always be conducted in an isolated environment. Production systems are not appropriate for analyzing unknown malware due to risk of compromise and data loss.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.