CAS-004 Security Operations Practice Question
A security operations center (SOC) analyst is reviewing logs from a Linux web server and notices a high volume of requests containing encoded characters such as %2e%2e%2f and %00 in the URI. The analyst suspects an attempt to exploit a path traversal vulnerability. Which of the following log sources would BEST confirm whether the attack was successful?
⚠ Common exam trap
The trap here is assuming that an IDS alert or firewall log confirms a successful attack, when they only show attempts or unrelated traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web server access logs showing HTTP 200 responses for requests containing encoded traversal sequences.
To confirm a path traversal attack's success, the analyst needs evidence that the server actually processed the malicious requests and potentially returned sensitive files. Web server access logs with HTTP 200 responses to traversal attempts provide that evidence. Other log sources may indicate attempts or unrelated activity but do not directly confirm file access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall logs showing allowed outbound connections from the web server to a database server.
Why it's wrong here
Firewall logs show network connections but do not reveal whether a path traversal attack succeeded. A connection to a database server could be normal application behavior. This source does not provide evidence of file system access or traversal exploitation, making it irrelevant for confirming the attack's success.
- ✗
Intrusion detection system (IDS) alerts indicating a path traversal signature match.
Why it's wrong here
IDS alerts indicate that a signature matched traffic, suggesting an attempt, but they do not confirm whether the attack succeeded. IDS may generate false positives and cannot verify if files were actually accessed. Therefore, this source alone does not confirm success; it only indicates detection of potential malicious activity.
- ✓
Web server access logs showing HTTP 200 responses for requests containing encoded traversal sequences.
Why this is correct
HTTP 200 responses to traversal attempts indicate the server processed the requests successfully, which may mean files outside the web root were accessed. This directly confirms potential success, unlike error codes. Correlating with file access logs can further validate, but the access logs are the primary source for web-based attacks.
- ✗
Authentication logs showing multiple failed login attempts from the same IP address.
Why it's wrong here
Authentication logs track login attempts, not file access or web requests. Failed logins are unrelated to path traversal exploitation, which typically does not involve authentication. This source would be useful for brute-force attacks but not for confirming a path traversal attack's success.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.