CAS-004 Security Operations Practice Question
A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution. The team wants to ensure that the EDR can detect advanced threats that use fileless techniques and living-off-the-land binaries (LOLBins). Which two data sources should the SOC prioritize collecting from the EDR to effectively detect such threats? (Choose two.)
⚠ Common exam trap
The trap here is assuming that traditional antivirus logs or network packet captures are sufficient for detecting fileless threats, when in fact endpoint process and script-level telemetry is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Event Logs, specifically Sysmon events for process creation and network connections
Detecting fileless threats and LOLBins requires visibility into process execution and script activity. Sysmon events provide detailed process creation and network connection data, while PowerShell script block logging and API tracing capture the actual code and function calls used by attackers. These sources together give the SOC the behavioral context needed to identify advanced techniques that evade traditional file-based detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User login and logout events from the domain controller
Why it's wrong here
User login events are important for auditing access but do not provide insight into process execution or script behavior on endpoints. They cannot detect fileless techniques or LOLBin abuse because those occur after authentication and do not necessarily generate login events. Thus, they are not a priority for this specific detection goal.
- ✓
Windows Event Logs, specifically Sysmon events for process creation and network connections
Why this is correct
Sysmon provides detailed process creation events including command-line arguments, parent process, and hashes, which are critical for detecting suspicious LOLBin execution and fileless techniques. Network connection events from Sysmon also help identify command-and-control traffic. This data source is essential for advanced threat detection because it captures rich context that native Windows event logs may lack.
- ✓
API call tracing and script block logging from PowerShell
Why this is correct
PowerShell script block logging captures the actual code executed, including obfuscated scripts, which is crucial for detecting fileless malware that uses PowerShell. API call tracing can reveal suspicious function calls. Together, they provide deep visibility into script-based attacks that do not write to disk, making them a high-priority data source.
- ✗
Full packet capture (PCAP) of all network traffic
Why it's wrong here
While PCAP can be useful for network forensics, it is not a primary EDR data source and does not directly show endpoint process behavior. Fileless attacks often use encrypted channels, making PCAP less effective for detection. Storing full PCAP is also resource-intensive and not typically prioritized for endpoint detection.
- ✗
Antivirus scan logs showing signature-based detection results
Why it's wrong here
Antivirus scan logs only indicate when a known signature matches a file. Fileless threats and LOLBins often do not have signatures and may not be flagged by traditional AV. Relying on these logs alone would miss the subtle behaviors of advanced attacks, making them insufficient for detecting fileless techniques.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.