CAS-004 Security Operations Practice Question
A security analyst is reviewing a suspicious email reported by a user. The email contains a link to a domain that was registered three days ago and hosts a JavaScript file. The analyst wants to safely analyze the JavaScript file to understand its behavior without risking infection. Which of the following approaches is MOST appropriate?
⚠ Common exam trap
The trap here is assuming that any execution, even in a sandbox, is safe, when in fact static analysis avoids execution entirely and is often sufficient for JavaScript.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Download the JavaScript file and analyze its code using a text editor and a deobfuscation tool.
Static analysis of the JavaScript file by downloading it and examining its code with deobfuscation tools is the safest and most informative approach. It allows the analyst to understand the script's functionality, extract indicators, and determine its malicious intent without any risk of executing the code. This method is preferred when the goal is to understand behavior without infection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open the link in a sandboxed virtual machine with no network access and execute the JavaScript in a browser.
Why it's wrong here
While sandboxing is good, executing the JavaScript in a browser within a VM without network access may still allow the script to run and potentially exploit the browser or VM. However, the lack of network access prevents command-and-control, but the script could still perform local actions. This method is not the most controlled for static analysis of the script's code.
- ✓
Download the JavaScript file and analyze its code using a text editor and a deobfuscation tool.
Why this is correct
Downloading the file and performing static analysis with a text editor and deobfuscation tools allows the analyst to understand the script's logic, identify obfuscation techniques, and extract indicators without executing it. This avoids any risk of infection and is a standard safe practice for analyzing potentially malicious scripts.
- ✗
Submit the URL to a public online JavaScript sandbox and review the execution trace.
Why it's wrong here
Public online sandboxes may not provide sufficient isolation or detailed tracing, and submitting sensitive URLs could leak information. Moreover, the sandbox might not capture all behaviors, especially if the script uses evasion techniques. This method is less controlled than local static analysis.
- ✗
Use a command-line tool to fetch the JavaScript file and pipe it directly to a JavaScript engine for execution.
Why it's wrong here
Executing the JavaScript directly, even in a command-line engine, could trigger malicious behavior if the engine has vulnerabilities or if the script is designed to exploit the environment. This approach lacks isolation and could compromise the analyst's system. It is not safe for analyzing unknown scripts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.