Courseiva
easyMultiple Choice

CAS-004 Practice Question: A SOC analyst is investigating a potential…

A SOC analyst is investigating a potential lateral movement within the network. Which log source is most critical for detecting lateral movement using pass-the-hash or pass-the-ticket attacks?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication logs (e.g., Windows Event ID 4624)

Authentication logs, such as Windows Event ID 4624, are the most critical for detecting lateral movement via pass-the-hash or pass-the-ticket attacks because they record logon events across systems, revealing when an attacker uses stolen credentials to access other machines. Option B (antivirus logs) is less relevant as they focus on malware, not authentication patterns. Option C (DNS logs) shows name resolution but not authentication. Option D (firewall logs) indicate network flows but lack authentication context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authentication logs (e.g., Windows Event ID 4624)

    Why this is correct

    Pass-the-hash and pass-the-ticket reuse stolen credential material, producing authentication events such as Windows Event ID 4624 with anomalous logon types or source hosts. Authentication logs therefore expose the credential reuse that reveals lateral movement, unlike firewall or DNS data.

  • ✗

    Antivirus logs

    Why it's wrong here

    Antivirus logs record file and process detections on individual hosts, not authentication events such as NTLM hashes or Kerberos tickets traversing the network. Domain controller security logs, capturing logon and ticket events, are what reveal pass-the-hash or pass-the-ticket activity.

  • ✗

    DNS logs

    Why it's wrong here

    Pass-the-hash and pass-the-ticket abuse NTLM and Kerberos authentication, leaving evidence in Windows Security event logs (4624, 4625, 4768, 4769) and Kerberos TGS requests. DNS logs record name resolution only, revealing nothing about credential reuse. They would be the right source for detecting DNS tunnelling or command-and-control beaconing.

  • ✗

    Firewall logs

    Why it's wrong here

    Firewall logs show allowed and denied network flows between hosts, but not the credential material or authentication events used. Pass-the-hash and pass-the-ticket appear in domain controller security logs as anomalous logon and Kerberos ticket requests, which firewalls never record.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.