Courseiva
Security Operations →easyMultiple Select

CAS-004 Security Operations Practice Question

A security team is evaluating endpoint detection and response (EDR) solutions. They want a solution that can detect fileless malware and malicious PowerShell scripts. Which TWO capabilities should the team prioritize? (Choose TWO.)

⚠ Common exam trap

CAS-005 often tests the distinction between detection capabilities and response actions, so the trap is selecting network analysis or firewall automation when the question specifically asks about detecting fileless and script-based threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Behavioral monitoring of script execution (e.g., PowerShell)

Option C is correct because behavioral monitoring of script execution detects malicious PowerShell activity by analyzing command-line arguments, script block logging (Event ID 4104), and suspicious behaviors like encoded commands or download cradles, which is essential for catching script-based attacks that evade static signatures. Option E is correct because fileless malware resides in memory (e.g., injected into processes like powershell.exe or wmic.exe) rather than on disk, so memory scanning is required to detect these in-memory artifacts, reflective DLL injections, and shellcode that leave no file footprint. Option A is not the priority because signature-based detection relies on known file hashes and patterns, which fileless and obfuscated PowerShell threats typically avoid. Option B, while useful for identifying command-and-control traffic, addresses network-level detection rather than the endpoint fileless/script execution behaviors the team specifically wants. Option D is unrelated to detection, as automated firewall rule creation is a response/containment action, not a detection capability for fileless malware or malicious scripts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Signature-based detection of known malware

    Why it's wrong here

    Signatures match known file hashes and byte patterns, so fileless malware and script-based attacks leave nothing on disk for them to match. It is tempting because signature detection is a familiar, low-noise baseline, and would be correct for identifying known, previously catalogued malware binaries.

  • ✗

    Network traffic analysis for C2 communication

    Why it's wrong here

    Network traffic analysis inspects packets for command-and-control patterns; it cannot see in-memory process behaviour or PowerShell script content executing on the host. It is tempting because C2 detection is valuable EDR telemetry, and would be correct for identifying beaconing to external infrastructure.

  • ✓

    Behavioral monitoring of script execution (e.g., PowerShell)

    Why this is correct

    Fileless malware and malicious PowerShell leave no executable on disk, so behavioural monitoring of script execution detects suspicious command patterns, encoded payloads and anomalous process behaviour in memory. This satisfies the stem's requirement to catch threats that evade signature-based file scanning.

  • ✗

    Automated firewall rule creation

    Why it's wrong here

    Firewall rule creation is a response or containment action, not a detection capability, so it contributes nothing to identifying fileless malware or malicious PowerShell. It is tempting because automated response is a headline EDR feature, and would be correct if the team wanted to block malicious network traffic automatically.

  • ✓

    Memory scanning capabilities

    Why this is correct

    Fileless attacks reside in RAM rather than on disk, so memory scanning inspects running processes, injected code and in-memory payloads that traditional file-based detection misses. This directly addresses the stem's constraint of detecting fileless malware and malicious PowerShell activity.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.