easyMultiple Choice
CAS-004 Practice Question: A SOC analyst is investigating a potential…
A SOC analyst is investigating a potential lateral movement within the network. Which log source is most critical for detecting lateral movement using pass-the-hash or pass-the-ticket attacks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authentication logs (e.g., Windows Event ID 4624)
Authentication logs, such as Windows Event ID 4624, are the most critical for detecting lateral movement via pass-the-hash or pass-the-ticket attacks because they record logon events across systems, revealing when an attacker uses stolen credentials to access other machines. Option B (antivirus logs) is less relevant as they focus on malware, not authentication patterns. Option C (DNS logs) shows name resolution but not authentication. Option D (firewall logs) indicate network flows but lack authentication context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Authentication logs (e.g., Windows Event ID 4624)
Why this is correct
Pass-the-hash and pass-the-ticket reuse stolen credential material, producing authentication events such as Windows Event ID 4624 with anomalous logon types or source hosts. Authentication logs therefore expose the credential reuse that reveals lateral movement, unlike firewall or DNS data.
- ✗
Antivirus logs
Why it's wrong here
Antivirus logs record file and process detections on individual hosts, not authentication events such as NTLM hashes or Kerberos tickets traversing the network. Domain controller security logs, capturing logon and ticket events, are what reveal pass-the-hash or pass-the-ticket activity.
- ✗
DNS logs
Why it's wrong here
Pass-the-hash and pass-the-ticket abuse NTLM and Kerberos authentication, leaving evidence in Windows Security event logs (4624, 4625, 4768, 4769) and Kerberos TGS requests. DNS logs record name resolution only, revealing nothing about credential reuse. They would be the right source for detecting DNS tunnelling or command-and-control beaconing.
- ✗
Firewall logs
Why it's wrong here
Firewall logs show allowed and denied network flows between hosts, but not the credential material or authentication events used. Pass-the-hash and pass-the-ticket appear in domain controller security logs as anomalous logon and Kerberos ticket requests, which firewalls never record.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.