CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst is investigating a potential phishing incident. The analyst has a suspicious email and wants to safely analyze any URLs without directly visiting them from a corporate workstation. Which of the following techniques should the analyst use to examine the URL's reputation and content?
⚠ Common exam trap
The trap here is assuming that passive inspection or using local tools like curl is sufficient for safe analysis, when in fact dynamic sandboxing is required to observe behavior without risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a URL sandboxing service that detonates the URL in an isolated environment and provides a screenshot and network traffic analysis.
URL sandboxing services are designed to safely analyze URLs by rendering them in an isolated environment. They provide valuable information such as screenshots, final URL, and network requests, which help determine if the URL is malicious. This approach protects the analyst's workstation and the corporate network while gathering actionable intelligence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Copy the URL into a text editor and inspect the domain for typosquatting, then use a WHOIS lookup to determine the registrar.
Why it's wrong here
While domain inspection and WHOIS can provide useful context, they do not reveal the actual content or behavior of the URL. Attackers can use legitimate domains or compromised sites. This method is passive and does not detonate the URL, so it may miss malicious payloads or redirects. It is insufficient for safe dynamic analysis.
- ✗
Forward the email to a personal email account and open the URL on a personal device to see if it is malicious.
Why it's wrong here
Forwarding to a personal account and opening on a personal device violates corporate policy and may still expose the personal device to malware. It also does not provide a controlled analysis environment. This method is unsafe and unprofessional, and it could lead to compromise of personal assets and potential data leakage.
- ✓
Use a URL sandboxing service that detonates the URL in an isolated environment and provides a screenshot and network traffic analysis.
Why this is correct
URL sandboxing services, such as VirusTotal or URLScan.io, allow analysts to submit a URL and have it rendered in a controlled, isolated environment. This reveals the final destination, any drive-by downloads, and network connections without risking the corporate workstation. It is a safe and efficient method for initial triage of suspicious URLs.
- ✗
Use a command-line tool like curl to fetch the URL headers and HTML content, then analyze the response for malicious scripts.
Why it's wrong here
Using curl from a corporate workstation can still expose the system to malicious content if the URL serves an exploit or malware. While it fetches headers and content, it does not provide an isolated environment. An attacker could craft a response that exploits the curl client or the analyst's system. This approach is not as safe as sandboxing.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.