Courseiva
mediumMultiple ChoiceObjective-mapped

CAS-004 Practice Question: A threat hunter wants to identify potential…

A threat hunter wants to identify potential lateral movement within the network. Which data source is LEAST useful for this purpose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

DNS query logs

Windows Event ID 4624 (Logon) from domain controllers records successful authentication events, which can indicate lateral movement when an account logs into multiple systems. Event ID 4648 (Logon with explicit credentials) shows when credentials are used explicitly to connect to another system, a common lateral movement technique. Event ID 5140 (File share accessed) logs access to file shares, often used for data staging or tool transfer during lateral movement. DNS query logs primarily show domain name resolution requests. While unusual DNS queries might indicate command-and-control or data exfiltration, they are less directly indicative of lateral movement between hosts because lateral movement typically involves authentication or resource access events rather than DNS lookups. Therefore, DNS query logs are the least useful data source for identifying lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Windows Event ID 4624 (Logon) from domain controllers

    Why it's wrong here

    Successful logins from different systems can indicate lateral movement.

  • Windows Event ID 4648 (Logon with explicit credentials)

    Why it's wrong here

    This event shows when a user runs a process using different credentials, common in lateral movement.

  • Windows Event ID 5140 (File share accessed)

    Why it's wrong here

    File share access from different systems can indicate lateral movement.

  • DNS query logs

    Why this is correct

    DNS logs show name resolution but not lateral movement itself.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.