CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst is reviewing a Windows event log after a suspected credential dumping incident. The analyst observes Event ID 4688 (process creation) for a process named 'rundll32.exe' with command-line arguments containing 'comsvcs.dll MiniDump'. Which of the following best describes the attacker's technique?
⚠ Common exam trap
The trap here is assuming that credential dumping always requires custom tools like Mimikatz, overlooking built-in Windows utilities that can achieve the same goal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Credential dumping via LSASS memory using a signed Windows binary
The attacker used rundll32.exe to call the MiniDump export of comsvcs.dll, a built-in Windows DLL, to dump LSASS process memory. This is a living-off-the-land technique for credential dumping (T1003.001) that evades detection by using a signed binary. The other options describe different credential access methods that do not match the observed command line.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Credential dumping via LSASS memory using a signed Windows binary
Why this is correct
This is correct because comsvcs.dll MiniDump is a known LOLBin technique to dump LSASS memory using rundll32.exe, a signed Microsoft binary. It avoids dropping custom tools and can bypass some application whitelisting. The command-line arguments are a strong indicator of credential dumping, aligning with MITRE ATT&CK T1003.001.
- ✗
Pass-the-hash using NTLM authentication against remote systems
Why it's wrong here
Pass-the-hash uses captured NTLM hashes to authenticate without knowing the plaintext password, often via tools like Mimikatz or Impacket. It does not involve running rundll32.exe with comsvcs.dll MiniDump. The observed command is local memory dumping, not remote authentication with stolen hashes.
- ✗
Kerberoasting by requesting service tickets for SPNs
Why it's wrong here
Kerberoasting involves requesting Kerberos service tickets (TGS) for service accounts with SPNs and cracking them offline. It does not use rundll32.exe with comsvcs.dll MiniDump. This command-line pattern is unrelated to Kerberos ticket manipulation, so this option misidentifies the technique.
- ✗
DCSync attack to replicate directory services data
Why it's wrong here
DCSync leverages directory replication permissions (DS-Replication-Get-Changes) to impersonate a domain controller and extract password hashes. It typically uses tools like Mimikatz with the dcsync command and does not involve rundll32.exe. The command-line arguments here indicate local LSASS dumping, not directory replication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.