Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security operations center (SOC) analyst is reviewing a Windows event log after a suspected credential dumping incident. The analyst observes Event ID 4688 (process creation) for a process named 'rundll32.exe' with command-line arguments containing 'comsvcs.dll MiniDump'. Which of the following best describes the attacker's technique?

⚠ Common exam trap

The trap here is assuming that credential dumping always requires custom tools like Mimikatz, overlooking built-in Windows utilities that can achieve the same goal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Credential dumping via LSASS memory using a signed Windows binary

The attacker used rundll32.exe to call the MiniDump export of comsvcs.dll, a built-in Windows DLL, to dump LSASS process memory. This is a living-off-the-land technique for credential dumping (T1003.001) that evades detection by using a signed binary. The other options describe different credential access methods that do not match the observed command line.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Credential dumping via LSASS memory using a signed Windows binary

    Why this is correct

    This is correct because comsvcs.dll MiniDump is a known LOLBin technique to dump LSASS memory using rundll32.exe, a signed Microsoft binary. It avoids dropping custom tools and can bypass some application whitelisting. The command-line arguments are a strong indicator of credential dumping, aligning with MITRE ATT&CK T1003.001.

  • ✗

    Pass-the-hash using NTLM authentication against remote systems

    Why it's wrong here

    Pass-the-hash uses captured NTLM hashes to authenticate without knowing the plaintext password, often via tools like Mimikatz or Impacket. It does not involve running rundll32.exe with comsvcs.dll MiniDump. The observed command is local memory dumping, not remote authentication with stolen hashes.

  • ✗

    Kerberoasting by requesting service tickets for SPNs

    Why it's wrong here

    Kerberoasting involves requesting Kerberos service tickets (TGS) for service accounts with SPNs and cracking them offline. It does not use rundll32.exe with comsvcs.dll MiniDump. This command-line pattern is unrelated to Kerberos ticket manipulation, so this option misidentifies the technique.

  • ✗

    DCSync attack to replicate directory services data

    Why it's wrong here

    DCSync leverages directory replication permissions (DS-Replication-Get-Changes) to impersonate a domain controller and extract password hashes. It typically uses tools like Mimikatz with the dcsync command and does not involve rundll32.exe. The command-line arguments here indicate local LSASS dumping, not directory replication.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.