CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst is investigating a potential security incident. The analyst needs to determine the order of events on a compromised Windows host. The analyst has access to the following artifacts: a memory dump, the Windows Event Log, and the file system metadata. Which of the following provides the most reliable timeline of user and system activity?
⚠ Common exam trap
The trap here is assuming any single artifact provides a complete and tamper-proof timeline, when in fact each has gaps and can be manipulated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A combination of all three artifacts correlated together.
The most reliable timeline is obtained by correlating the Windows Event Log, file system metadata, and memory dump. Each source has unique data and limitations; combining them allows the analyst to cross-validate timestamps and activities. For example, a process execution in the event log can be linked to a file creation in metadata and a network connection in memory. This multi-source correlation is essential for accurate incident reconstruction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A combination of all three artifacts correlated together.
Why this is correct
Correlating multiple artifacts provides the most reliable timeline. The Windows Event Log gives system and security events, file system metadata shows file operations, and memory dump reveals running processes and network state. Together, they compensate for individual limitations and provide a more complete picture. This approach is standard in digital forensics to establish an accurate sequence of events.
- ✗
The memory dump, because it contains running processes and network connections at the time of capture.
Why it's wrong here
A memory dump provides a snapshot of the system state at the time of acquisition, including running processes and network connections. However, it does not provide historical data or a timeline of past events. It is useful for live analysis but cannot reconstruct the sequence of activities over time. Thus, it is not the best source for a timeline.
- ✗
The Windows Event Log, because it records all system and application events with timestamps.
Why it's wrong here
The Windows Event Log does record many events with timestamps, but it is not comprehensive. Attackers can clear or modify logs, and some activities may not be logged depending on audit policies. It also lacks file system activity details. Therefore, it is not the most reliable sole source for a timeline, especially in a compromised system where logs may be tampered with.
- ✗
The file system metadata, because it includes timestamps for file creation, modification, and access.
Why it's wrong here
File system metadata provides timestamps like MACB (Modified, Accessed, Changed, Birth) times, but these can be manipulated by attackers using timestomping. They also only cover file-related events, not process execution or network activity. While useful, they are not sufficient for a complete timeline and can be unreliable if anti-forensics techniques were used.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.