Courseiva
mediumMultiple ChoiceObjective-mapped

CAS-004 Practice Question: After a security incident, the IR team identifies…

After a security incident, the IR team identifies that the attacker used a spear-phishing email with an attached malicious macro. Which log source would be MOST crucial to determine the scope of the compromise?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Proxy server logs

Proxy logs capture all outbound HTTP/HTTPS traffic, which is critical for identifying command-and-control (C2) communications and data exfiltration by the malware. Option A (EDR telemetry) provides endpoint-level details like process execution and network connections, but not all outbound traffic if endpoints are not forwarding logs. Option B (Windows Event Logs 4688) shows process creation events, which can help identify malicious process execution but may not reveal network connections. Option D (email server logs) is useful for tracing the initial phishing email but does not show subsequent system activity or network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Endpoint detection and response (EDR) telemetry

    Why it's wrong here

    EDR telemetry provides endpoint activity including process execution and network connections, but may not capture all external communications such as C2 traffic if not forwarded.

  • Windows Event Logs (Event ID 4688)

    Why it's wrong here

    Windows Event Logs (Event ID 4688) show local process execution, which can indicate macro execution, but do not show outbound network connections.

  • Proxy server logs

    Why this is correct

    Proxy server logs capture outbound HTTP/HTTPS connections, which malware commonly uses for command and control (C2) and data exfiltration, making them most crucial for scope determination.

  • Email server logs

    Why it's wrong here

    Email server logs show the initial spear-phishing email and recipients, but do not reveal subsequent system activity or network connections after the macro runs.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.