Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is reviewing an incident where an attacker used a compromised service account to perform lateral movement within an Active Directory environment. The analyst wants to identify other systems that the attacker may have accessed using this account. Which two data sources would be most effective for this investigation? (Choose two.)

⚠ Common exam trap

The trap here is focusing on network or endpoint logs that do not tie activity to the specific service account, missing the domain-wide authentication trail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Domain controller security logs for Kerberos service ticket requests (Event ID 4769) involving the service account.

To track lateral movement of a service account, the analyst needs authentication records across the domain. Windows Security event logs (4624) show successful logons per system, and domain controller Kerberos service ticket requests (4769) show which services the account requested tickets for. Together, these reveal the systems the attacker accessed. Other sources lack account-specific authentication details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Domain controller security logs for Kerberos service ticket requests (Event ID 4769) involving the service account.

    Why this is correct

    Event ID 4769 logs Kerberos service ticket requests, showing which services the account accessed. Since service accounts often use Kerberos, this can reveal lateral movement to servers. Correlating with logon events provides a comprehensive view of accessed systems.

  • ✓

    Windows Security event logs for logon events (e.g., Event ID 4624) filtered by the service account.

    Why this is correct

    Event ID 4624 records successful logons, including the account name and logon type. Filtering for the compromised service account reveals which systems it authenticated to, directly showing lateral movement targets. This is a primary source for tracking account usage across the domain.

  • ✗

    SIEM alerts for unusual process execution on the service account's original workstation.

    Why it's wrong here

    SIEM alerts on the original workstation might show initial compromise, but the goal is to find other systems accessed. Lateral movement implies the account was used elsewhere, so logs from the source workstation alone are insufficient. The analyst needs domain-wide authentication data.

  • ✗

    Antivirus logs on the domain controller.

    Why it's wrong here

    Antivirus logs on the domain controller would show malware detections, not account authentication events. They are not relevant for tracking lateral movement via a service account unless malware was involved, which is not specified. The focus is on account activity, not endpoint malware.

  • ✗

    Firewall logs showing outbound connections from the service account's workstation.

    Why it's wrong here

    Firewall logs typically do not associate traffic with user accounts; they show IP addresses. The service account may be used from various workstations, so firewall logs alone cannot reliably link activity to the account. They might help identify network paths but not account-specific access.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.