Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst receives an alert from the SIEM indicating a possible DNS tunneling attempt. The analyst needs to investigate the incident. Which of the following actions should the analyst take FIRST to validate the alert?

⚠ Common exam trap

The trap here is jumping to containment or advanced analysis before performing a simple log review, which can quickly confirm or dismiss the alert.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review DNS logs for unusually long or high-entropy subdomain queries from the same host.

The first step should be to review DNS logs for anomalies such as long or high-entropy subdomain queries from the same host. This leverages existing data to validate the alert without disrupting services. Blocking DNS traffic is a containment action, packet capture is more resource-intensive, and vulnerability scanning does not address active tunneling behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a vulnerability scan on the suspected host to check for DNS-related exploits.

    Why it's wrong here

    A vulnerability scan checks for known software flaws and does not detect active DNS tunneling, which is a communication technique rather than a vulnerability. Scanning would not validate the alert and could generate noise. The analyst needs to examine network traffic patterns, not system vulnerabilities, to confirm tunneling.

  • ✓

    Review DNS logs for unusually long or high-entropy subdomain queries from the same host.

    Why this is correct

    DNS tunneling often encodes data in subdomains, resulting in long, random-looking strings. Reviewing DNS logs for such patterns from a single host can quickly validate the alert. This is a direct and efficient first step because it uses existing log data without disrupting operations, and it can confirm whether the traffic is anomalous.

  • ✗

    Capture full packet data for all DNS queries and analyze the payloads for executable content.

    Why it's wrong here

    Capturing full packet data can be resource-intensive and may not be immediately available. While analyzing payloads can confirm tunneling, it is not the first step; it is more time-consuming and requires specialized tools. The analyst should first check existing logs for anomalies before escalating to packet capture, which might be overkill and slow the investigation.

  • ✗

    Immediately block all outbound DNS traffic from the suspected host.

    Why it's wrong here

    Blocking all outbound DNS traffic from the host would disrupt legitimate name resolution and could break business functions. It is a containment action, not a validation step, and should be taken only after confirming malicious activity. Taking this action first may cause unnecessary outages and does not help determine if the alert is a true positive.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.