CAS-005 · domain
Security Operations
Security Operations covers threat hunting, incident response, digital forensics, and malware analysis on the CompTIA SecurityX exam. Questions present realistic scenarios—memory-resident PowerShell, volatile evidence collection order, phishing macro payload delivery, static binary inspection—and ask you to select the correct methodology, phase, or analysis technique rather than recall definitions.
Focused practice
Practice Security Operations questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Operations
A candidate must apply the correct methodology, evidence order, or incident phase to a scenario. The single most important thing: preserve volatile data first and never execute a sample when static analysis is requested.
Threat hunting hypothesis-driven methodology, including MITRE ATT&CK mapping and PowerShell in-memory execution detection
Volatile evidence collection order: memory, network connections, running processes, then disk artifacts
Incident response phases: identification, containment, eradication, recovery, and lessons learned per NIST SP 800-61
Static malware analysis of binaries without execution, including strings, PE headers, and disassembly
Watch out for
Common Security Operations exam traps
- ▸Collecting disk images before memory, which destroys volatile data such as running processes and network connections
- ▸Confusing static analysis with dynamic or sandbox analysis when the question says the sample must not be executed
- ▸Mismatching incident response phases, such as labeling containment as eradication or recovery when the scenario describes isolating a host
Question index
All Security Operations questions (164)
Click any question to see the full explanation, or start a practice session above.
An organization uses an EDR solution and wants to detect ransomware that encrypts files and then deletes volume shadow copies. Which EDR detection technique would be most effective for this behavior?
Hard2A security analyst is reviewing a vulnerability scan report for a web application. The report shows a high-severity finding for a SQL injection vulnerability on a login page. The analyst needs to validate the finding before escalating to the development team. Which of the following actions should the analyst take to safely validate the vulnerability?
Medium3A security team is implementing deception technology to detect attackers inside the network. They plan to deploy fake systems that appear vulnerable and attract attackers. Which of the following is an example of a honeytoken?
Easy4A security analyst is investigating a suspected DNS tunneling attack. The analyst observes a high volume of DNS queries to a single domain, with query names that appear to be Base64-encoded strings. Which of the following is the MOST effective way to confirm and analyze this activity?
Medium5A penetration tester is planning a test against a web application. The rules of engagement specify that the tester must not disrupt production services. Which TWO reconnaissance techniques are considered passive and would be appropriate for initial information gathering without impacting the target? (Select TWO.)
Easy6A security operations center (SOC) analyst receives an alert from the SIEM indicating a user has logged into the corporate VPN from an unusual geographic location at 3 AM, which is outside the user's normal working hours. The user has not previously exhibited this behavior. Which advanced SIEM capability is most likely responsible for generating this alert?
Medium7A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution across 10,000 endpoints. The team wants to ensure that if the EDR agent is disabled or tampered with, the SOC is immediately alerted and the endpoint can be isolated. Which EDR capability should the team prioritize?
Medium8An organization wants to share threat intelligence with industry peers using a standardized format. Which of the following formats is specifically designed for representing structured threat information in a machine-readable way?
Easy9A security analyst is analyzing a memory dump from a compromised host using Volatility. Which Volatility plugin would be most useful to identify a malicious process that is hidden from the standard process listing?
Medium10A security analyst is investigating a potential data exfiltration incident. The analyst has a packet capture (PCAP) file from the network segment where the suspected exfiltration occurred. The analyst wants to extract files that were transferred over HTTP and analyze their contents. Which of the following tools should the analyst use to achieve this?
Hard11A security analyst is using the MITRE ATT&CK framework to categorize adversary behavior observed in recent incidents. The analyst notes that the adversary used spearphishing with a malicious attachment to gain initial access, then executed a PowerShell script to download additional tools. Which ATT&CK tactic is the PowerShell execution associated with?
Medium12A security analyst is conducting a penetration test for a client. The rules of engagement specify that no social engineering is allowed. Which TWO of the following reconnaissance techniques are permitted under these rules?
Medium13An organization needs to ensure that evidence collected during a forensic investigation remains intact and admissible in court. Which process is most critical for maintaining the integrity of digital evidence?
Easy14During a digital forensics investigation of a compromised Linux server, the investigator needs to preserve the evidence in a forensically sound manner. The server is still running. Which of the following should the investigator do first?
Medium15A security team is implementing a threat intelligence program and wants to consume intelligence from various sources. Which TWO of the following are commonly used threat intelligence feeds or sharing mechanisms? (Select TWO.)
Medium16A security analyst is reviewing threat intelligence feeds and notices that a known Advanced Persistent Threat (APT) group has been using a specific technique to move laterally within networks. The analyst wants to map this technique to the MITRE ATT&CK framework. Which resource would the analyst use to find the corresponding ATT&CK technique ID?
Medium17A security analyst is investigating a phishing campaign targeting the organization. The threat intelligence team has provided indicators such as email subject lines, sender domains, and attachment hashes. However, the analyst notices that these IOCs change rapidly and are only effective for a short period. Which type of threat intelligence would provide more durable and actionable information for defending against this campaign?
Medium18A vulnerability scanner reports a critical vulnerability on a critical server with a CVSS v3.1 base score of 9.8. The server cannot be patched immediately due to vendor constraints. Which of the following should the security team implement as a compensating control?
Easy19A security analyst is reviewing a malware sample in a sandbox environment. The analyst notes that the malware attempts to check for the presence of a debugger and modifies its behavior if one is detected. Additionally, the malware uses encrypted strings and resolves API calls dynamically. Which THREE analysis techniques would be most effective for understanding this malware's capabilities? (Select THREE.)
Hard20A security analyst receives an alert from the SIEM indicating a possible DNS tunneling attempt. The analyst needs to investigate the incident. Which of the following actions should the analyst take FIRST to validate the alert?
Medium21A security team is preparing for a penetration test. Which document defines the scope, rules, and restrictions for the test?
Easy22A security team is deploying deception technology to detect lateral movement within the network. They plan to use honeypots configured to mimic critical servers. Which TWO of the following are essential considerations for the honeypot deployment to be effective? (Choose TWO.)
Medium23During a penetration test, the tester has obtained a foothold on an internal server. The tester wants to identify other systems on the network and find potential targets for lateral movement. Which type of reconnaissance is MOST appropriate in this scenario?
Medium24A security engineer is implementing a new endpoint detection and response (EDR) solution. The engineer wants to detect process injection techniques where malware writes to the memory of a remote process and then creates a remote thread to execute its payload. Which of the following Windows API call sequences should the EDR monitor to detect this behavior?
Hard25A security analyst is reviewing firewall logs and notices a large number of outbound connections from an internal server to various external IP addresses on port 443. The connections are occurring at regular intervals and transferring small amounts of data. Which of the following is the MOST likely explanation for this activity?
Easy26A security administrator is configuring a new VPN concentrator to support remote workers. The organization requires that all remote access use strong authentication and that the VPN concentrator validate the health of connecting devices before granting access. Which technology should the administrator implement?
Medium27A security operations center (SOC) has deployed a SOAR platform to automate phishing response. An analyst wants to ensure that when a phishing email is reported, the platform automatically extracts all URLs from the email body and headers, submits them to a threat intelligence service, and then quarantines the email if any URL is malicious. Which SOAR component should the analyst configure to define this sequence of actions?
Medium28A security analyst is reviewing threat intelligence feeds and notices indicators from a known APT group. Which threat intelligence sharing standard is most commonly used to structure and share such cyber threat information in a machine-readable format?
Easy29A security operations team has deployed a deception platform consisting of several Windows and Linux honeypots on a dedicated VLAN. After two weeks, the team notices the honeypots generate a high volume of connection attempts originating from internal vulnerability scanners, asset discovery tools, and backup agents, drowning out any genuine adversary activity. Which of the following is the BEST course of action to preserve the fidelity of the deception environment?
Hard30During an incident response, the team identifies that an attacker gained initial access via a phishing email containing a malicious macro. The macro downloaded a payload from a remote server. Which phase of the incident response lifecycle is currently being executed when the team identifies the phishing email as the attack vector?
Medium31A security analyst is investigating a malware sample found on a workstation. The analyst wants to determine the malware's capabilities without executing it. Which type of malware analysis involves examining the binary's strings, headers, and structure?
Easy32During a malware analysis, an analyst runs a suspicious binary in a sandbox and observes that it attempts to communicate with a known malicious IP address, modifies registry keys, and creates a service. The analyst then extracts strings from the binary and finds references to a specific C2 server. Which analysis phase does the extraction of strings represent?
Hard33An organization is unable to patch a critical vulnerability in a legacy application due to vendor limitations. The risk assessment indicates a high likelihood of exploitation. Which compensating control should the organization implement to reduce the risk?
Medium34A company's incident response team is conducting a post-incident review. They identify that the intrusion was not detected for 72 hours due to insufficient logging on critical servers. Which phase of the incident response lifecycle should be improved to address this gap?
Medium35A security analyst is reviewing an incident where an attacker used a compromised service account to perform lateral movement within an Active Directory environment. The analyst wants to identify other systems that the attacker may have accessed using this account. Which two data sources would be most effective for this investigation? (Choose two.)
Hard36A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an attacker used DNS tunneling to exfiltrate data. Which THREE network traffic indicators would support this hypothesis? (Select THREE.)
Medium37Which of the following best describes the purpose of the STIX and TAXII standards in threat intelligence sharing?
Easy38A security analyst is investigating a security incident where an attacker gained unauthorized access to a server. The analyst reviews the server logs and finds the following entries: 'Accepted password for root from 192.168.1.100 port 22 ssh2' followed by 'session opened for user root by (uid=0)'. The analyst suspects the attacker used stolen credentials. Which of the following log sources would provide the MOST direct evidence of the attacker's activities after the initial access?
Hard39A SOC team is implementing a SOAR platform to automate responses to phishing emails. The team wants to create a playbook that, upon detection of a phishing email, automatically quarantines the email from all mailboxes and blocks the sender's domain. Which type of playbook action is being described?
Medium40A security operations center (SOC) is evaluating a new EDR solution. Which three capabilities are essential for effective endpoint detection and response? (Select THREE).
Hard41During an incident response, a team is prioritizing containment actions. Which THREE of the following actions should be taken to contain the incident effectively?
Hard42A security analyst is reviewing a suspicious PowerShell script found on a compromised host. The script contains a long string of base64-encoded text and uses the `-EncodedCommand` parameter. The analyst wants to understand the script's functionality without executing it. Which of the following actions should the analyst take FIRST?
Medium43A security analyst is investigating a malware sample that uses the Windows API function NtQueryInformationProcess to detect if it is being debugged. The analyst wants to understand how this anti-debugging technique works and how to bypass it. Which of the following statements accurately describes the technique and a potential bypass?
Hard44During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which technique is most commonly used for lateral movement in a Windows environment?
Easy45A security engineer is configuring a web application firewall (WAF) to protect a public-facing application from common attacks. The engineer wants to ensure the WAF can detect and block SQL injection and cross-site scripting (XSS) attempts. Which TWO of the following WAF capabilities should the engineer enable? (Choose two.)
Medium46An organization wants to detect attackers who have already breached the network by deploying decoy credentials and data files. Which type of deception technology should they use?
Medium47An organization wants to collect threat intelligence from multiple Information Sharing and Analysis Centers (ISACs) relevant to their industry. Which of the following is a primary benefit of participating in an ISAC?
Easy48A security operations team is developing a SOAR playbook to automate response to a detected ransomware outbreak. The team wants to ensure the playbook can contain the threat quickly while minimizing business disruption. Which TWO actions should the playbook include as automated responses? (Select TWO.)
Medium49During a threat hunting exercise, a security analyst hypothesizes that an adversary is using PowerShell to execute malicious scripts. Which approach is the analyst employing?
Medium50A security engineer is configuring a Web Application Firewall (WAF) to protect an e-commerce site against SQL injection attacks. The WAF is deployed in reverse proxy mode. The engineer notices that legitimate search queries containing single quotes are being blocked. Which of the following actions should the engineer take to reduce false positives while maintaining protection?
Hard51A security analyst is reviewing a suspicious PowerShell script that was found on a compromised host. The analyst wants to understand the script's functionality without executing it. Which of the following techniques should the analyst use?
Medium52A security team is implementing a new detection for a fileless malware attack that uses PowerShell to execute a malicious script directly in memory. The team wants to detect this activity using Windows Event Logs. Which of the following event IDs should they monitor to capture the script block content?
Hard53An organization has a critical vulnerability in a legacy application that cannot be patched due to vendor end-of-life. The application is required for business operations and is accessible only from the internal network. Which compensating control would best reduce the risk of exploitation while maintaining availability?
Hard54A SOC team receives an alert from a SOAR platform indicating a potential phishing email. The SOAR playbook automatically quarantines the email, blocks the sender, and opens a ticket. This is an example of which SOAR capability?
Medium55A security operations center (SOC) is deploying a new endpoint detection and response (EDR) solution. The team wants to ensure that the EDR can detect advanced threats that use fileless techniques and living-off-the-land binaries (LOLBins). Which two data sources should the SOC prioritize collecting from the EDR to effectively detect such threats? (Choose two.)
Hard56During a penetration test, the tester gains access to a web server and wants to escalate privileges to root. The tester discovers that the web application runs with a service account that has the SeImpersonatePrivilege enabled. Which attack is most likely to succeed for privilege escalation?
Hard57A security architect is designing deception technologies to detect and delay attackers. Which TWO of the following are examples of deception technologies that can be deployed? Select TWO.
Medium58A company uses a SIEM with User Behavior Analytics (UBA). The UBA generates an alert when a user accesses sensitive data at unusual hours. Which type of correlation rule is being applied?
Medium59A security analyst is reviewing a Windows event log from a domain controller and notices Event ID 4769 with the ticket encryption type 0x17. The analyst suspects a Kerberoasting attack. Which of the following best explains why this event is suspicious?
Hard60A security operations center (SOC) analyst is reviewing a Windows event log after a suspected credential dumping incident. The analyst observes Event ID 4688 (process creation) for a process named 'rundll32.exe' with command-line arguments containing 'comsvcs.dll MiniDump'. Which of the following best describes the attacker's technique?
Medium61Which component of the MITRE ATT&CK framework categorizes the 'why' of an adversary's action, such as initial access or credential access?
Easy62An incident responder is analyzing a malware sample obtained from an infected host. The responder wants to perform dynamic analysis to observe the malware's behavior in a safe environment. Which of the following is the best approach?
Hard63During a red team exercise, the team gains access to a workstation and needs to maintain persistence. They modify a registry run key to execute a payload. However, the organization uses EDR that monitors registry changes. Which technique could the red team use to avoid detection?
Hard64A security analyst is reviewing a packet capture of suspicious traffic that uses a custom protocol over TCP. The analyst needs to determine the application-layer payload and session flow to identify potential data exfiltration. Which tool is MOST appropriate for this task?
Medium65A security analyst is reviewing logs from a SIEM and notices that a user account has been successfully authenticated from two different geographic locations within a short time span, which is impossible. The SIEM uses user behavior analytics (UBA). What type of anomaly is this most likely to detect?
Hard66An organization is implementing a threat hunting program. The team decides to use a hypothesis-driven approach. Which of the following best describes this methodology?
Medium67A security administrator is configuring a new web server and wants to ensure that it is protected against cross-site scripting (XSS) attacks. Which of the following controls should the administrator implement to BEST mitigate XSS?
Easy68A security analyst is reviewing a CVSS score for a vulnerability that affects a critical server. The base score is 7.5, but the analyst needs to adjust for the environment. Which TWO of the following are valid CVSS environmental metrics that can modify the score? (Choose two.)
Medium69A security analyst is performing dynamic malware analysis in a sandbox. The analyst observes that the malware sample attempts to connect to a command-and-control (C2) server but fails. The analyst wants to modify the sandbox environment to allow the malware to communicate with the C2 server to observe its behavior. Which TWO of the following changes should the analyst make? (Choose two.)
Hard70A company's incident response team is developing a playbook for ransomware incidents. The playbook should cover the preparation phase. Which THREE of the following are appropriate preparation activities? (Choose THREE.)
Medium71An organization uses a SIEM to collect logs from multiple sources. The security team wants to identify users who are accessing resources outside of normal business hours and exhibiting unusual data transfer patterns. Which advanced SIEM capability would be most effective?
Hard72A security operations center (SOC) is implementing User Behavior Analytics (UBA) to detect insider threats. Which TWO of the following data sources are most critical for establishing a baseline of normal user behavior?
Medium73A security analyst is investigating a potential breach and needs to determine the timeline of events on a compromised Windows workstation. The analyst has access to the disk image and memory dump. Which artifact should the analyst examine FIRST to establish a timeline of file system activity?
Hard74A security operations center (SOC) receives a high-severity alert indicating that a domain administrator account was used to authenticate to a workstation at 03:00. The account is normally used only for interactive logons to domain controllers during business hours. The SOC analyst wants to quickly determine whether this is a malicious activity or a false positive. Which of the following is the MOST appropriate next step?
Medium75A security administrator is configuring a new wireless network for a small office. The administrator wants to ensure that only authorized devices can connect and that traffic is encrypted. Which of the following should the administrator implement?
Easy76Which CVSS metric component is used to reflect the impact of a vulnerability based on the specific environment of an organization?
Medium77A security analyst is investigating a potential security incident and needs to determine the order of events. The analyst has collected logs from various sources, including Windows Event Logs, firewall logs, and IDS alerts. Which of the following should the analyst do FIRST to establish a timeline?
Medium78A security operations center (SOC) analyst is tuning a SIEM correlation rule to detect lateral movement using pass-the-hash attacks. The analyst wants to minimize false positives while ensuring detection of true positives. Which approach is most effective for reducing false positives in this scenario?
Hard79A security analyst is using Volatility to analyze a memory dump from a compromised Windows system. The analyst suspects that a rootkit is hiding processes. Which Volatility plugin should the analyst use to detect hidden processes?
Medium80During an incident response, a forensic analyst captures the memory of a compromised Windows system. Using Volatility, the analyst runs the 'pslist' command and sees a suspicious process 'svchost.exe' with a parent process 'explorer.exe'. Which Volatility plugin should the analyst use next to detect potential process hollowing?
Hard81A security operations team is deploying a new endpoint agent. They want to enforce a policy that only executables signed by trusted publishers and with a valid certificate chain are allowed to run, even if the user has local administrator rights. Which Windows feature should they configure to meet this requirement?
Medium82A security analyst is using the MITRE ATT&CK framework to map adversarial behaviors. Which THREE of the following are tactics defined by ATT&CK? (Select THREE.)
Hard83An organization is implementing a SOAR solution to automate responses to common incidents. They want to create a playbook for phishing email handling. Which of the following actions should be automated in the playbook after a user reports a suspicious email?
Medium84A threat intelligence analyst is profiling a threat actor that has been targeting the energy sector. Which THREE of the following attributes are most important to include in a threat actor profile? Select THREE.
Hard85During a security incident, the incident response team has identified the root cause and removed the threat from all affected systems. Which phase of the incident response lifecycle involves returning systems to normal operation and monitoring for any signs of recurrence?
Easy86A security operations center (SOC) analyst is investigating a potential malware infection on a workstation. The analyst wants to perform static analysis on a suspicious executable. Which tool or technique is most appropriate for examining the executable without executing it?
Medium87A security analyst is investigating a possible insider threat. The analyst has access to endpoint detection and response (EDR) telemetry, network flow logs, and authentication logs. The analyst suspects that a user is exfiltrating data by encoding it into DNS queries to a domain controlled by the attacker. Which data source and analysis technique would best confirm this activity?
Hard88A SOC analyst is investigating a suspicious process that is making outbound connections to an unknown IP address. The analyst wants to examine the process memory for injected code. Which Volatility plugin is most appropriate for detecting code injection by listing all Virtual Address Descriptors (VADs) that are mapped as executable and writable?
Hard89Which of the following is the primary advantage of using STIX and TAXII for threat intelligence sharing?
Easy90A security team is evaluating an EDR solution. Which of the following capabilities is a primary differentiator between EDR and traditional antivirus?
Medium91An organization wants to deploy a technology that lures attackers into a controlled environment to observe their tactics, techniques, and procedures (TTPs). Which deception technology should the organization implement?
Easy92A vulnerability scanner reports a critical vulnerability with a CVSS base score of 9.8 on a public-facing web server. However, the server has a compensating control: a Web Application Firewall (WAF) that blocks exploit attempts. How should the security team prioritize patching this vulnerability?
Medium93A security analyst is reviewing a suspicious email reported by a user. The email contains a link to a domain that was registered three days ago and hosts a JavaScript file. The analyst wants to safely analyze the JavaScript file to understand its behavior without risking infection. Which of the following approaches is MOST appropriate?
Medium94A penetration tester is performing a test against a web application. During active reconnaissance, the tester discovers that the application discloses version numbers in HTTP headers. Which phase of the penetration testing lifecycle does this activity belong to?
Medium95A security analyst is reviewing a suspicious email reported by a user. The email contains an attachment named 'invoice.pdf.exe'. Which type of malware analysis technique should the analyst perform first to determine if the file is malicious?
Medium96A security engineer is reviewing the results of a penetration test. The tester successfully exploited a vulnerability in a web application and escalated privileges to domain admin. Which THREE of the following findings should be included in the technical report to provide actionable remediation steps? (Select THREE.)
Hard97A vulnerability management team is prioritizing patches for a set of critical vulnerabilities. Vulnerability A has a CVSS base score of 9.8, vulnerability B has a CVSS base score of 7.5, and vulnerability C has a CVSS base score of 8.2. However, vulnerability B is actively being exploited in the wild, while the others are not. Which vulnerability should be patched first according to best practices?
Medium98A security analyst is reviewing the following command executed on a Linux server: 'nmap -sS -Pn -p 80,443 192.168.1.0/24'. Which of the following BEST describes the purpose of this command?
Medium99A security analyst is reviewing a packet capture (PCAP) from a suspected command-and-control (C2) channel. The analyst observes periodic outbound connections to an external IP address over TCP port 443. The traffic is encrypted with TLS, but the analyst suspects it may be malicious. Which TWO of the following techniques would be MOST effective to identify the malicious nature of the traffic without decrypting the payload? (Choose two.)
Hard100Which of the following is a key benefit of using an Extended Detection and Response (XDR) solution over traditional Endpoint Detection and Response (EDR)?
Easy101A security analyst is investigating a potential data exfiltration incident. Network logs show a large volume of outbound traffic from an internal database server to an unfamiliar external IP address over port 443. The traffic occurs daily at 02:00 and lasts for exactly 15 minutes. The analyst suspects the use of a covert channel. Which of the following techniques is the analyst MOST likely observing?
Hard102Which of the following is the primary purpose of a honeypot in a security operations environment?
Easy103A security analyst receives an alert from the SIEM indicating multiple failed logon attempts from an external IP address followed by a successful logon for a domain admin account. Which phase of the incident response lifecycle is the analyst currently in?
Medium104During a digital forensics investigation, an analyst needs to acquire the contents of RAM from a compromised server. Which order of volatility should the analyst follow?
Medium105A security analyst is investigating a potential insider threat. The analyst has access to logs from a Data Loss Prevention (DLP) system that flagged an employee for sending a large number of documents to a personal cloud storage account. The analyst needs to determine if this is a malicious exfiltration attempt or legitimate business activity. Which of the following actions should the analyst take FIRST?
Medium106A SOC team is implementing a SOAR playbook to automate response to phishing emails reported by users. Which step should be included in the playbook to prevent other users from accessing the malicious link?
Medium107A security analyst is configuring an EDR solution to detect a specific fileless attack technique where malicious code is injected into the memory of a legitimate process. The analyst wants to trigger an alert when a process attempts to write to the memory of another process. Which Windows API function should the EDR monitor to detect this activity?
Easy108A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR agent can detect and block malicious activities in real-time. Which of the following capabilities is MOST essential for the EDR agent to achieve this goal?
Easy109A security analyst is investigating a malware sample and wants to determine its capabilities without executing it. The analyst examines the binary's imports, strings, and structure. What type of analysis is being performed?
Hard110A security analyst is reviewing CVSS scores for vulnerability prioritization. Which TWO of the following are component metric groups in CVSS v3?
Easy111During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which of the following techniques would be most effective for identifying valid credentials that could be reused on the database server?
Medium112A security operations center (SOC) analyst is investigating a potential phishing incident. The analyst has a suspicious email and wants to safely analyze any URLs without directly visiting them from a corporate workstation. Which of the following techniques should the analyst use to examine the URL's reputation and content?
Medium113A security analyst is investigating a potential compromise of a Windows server. The analyst suspects that an attacker used a technique to dump credentials from memory. Which TWO of the following artifacts or events would MOST likely indicate that a credential dumping tool such as Mimikatz was executed? (Choose two.)
Hard114A security operations center (SOC) analyst is reviewing logs from a Linux web server and notices a high volume of requests containing encoded characters such as %2e%2e%2f and %00 in the URI. The analyst suspects an attempt to exploit a path traversal vulnerability. Which of the following log sources would BEST confirm whether the attack was successful?
Medium115A security analyst is reviewing a suspicious process that has been identified on an endpoint. The analyst wants to determine if the process has any network connections and what data it might be sending. Which tool is most appropriate for analyzing the memory of the affected system to identify network connections and potential data exfiltration?
Medium116A security analyst is reviewing a potentially malicious PowerShell script that was executed on a workstation. The script contains obfuscated code and makes network connections. The analyst wants to perform dynamic analysis to understand its behavior. Which TWO of the following methods would BEST allow the analyst to observe the script's runtime actions in a controlled environment? (Choose two.)
Hard117A security analyst is investigating a potential insider threat. The analyst needs to correlate user activity across multiple systems, including file access, email, and web browsing, to build a timeline of events. Which data source is MOST critical for this correlation?
Medium118A penetration tester is performing a test against a web application. The rules of engagement prohibit any denial of service (DoS) attacks. Which of the following actions is most likely prohibited by this restriction?
Medium119A security analyst is performing incident response and needs to collect evidence from a live system. Which of the following should be collected first to preserve volatile data?
Easy120A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?
Hard121A security analyst is using a SOAR platform to automate response to phishing emails reported by users. The playbook should perform the following actions in order: (1) extract indicators from the email, (2) query threat intelligence feeds for reputation, (3) if malicious, block the sender's domain at the email gateway and delete the email from all user inboxes. Which type of playbook step is most appropriate for step 3?
Hard122A security team is analyzing a suspicious binary using static analysis. They run the strings command and observe references to 'CreateRemoteThread' and 'WriteProcessMemory'. Which technique is the binary likely employing?
Hard123A security operations center (SOC) analyst is investigating an alert indicating potential credential dumping on a Windows server. The analyst reviews the process execution logs and sees that a process named 'lsass.exe' was accessed by an unsigned binary. Which of the following techniques is the attacker MOST likely using?
Hard124A security operations center (SOC) analyst receives an alert from the endpoint detection and response (EDR) platform indicating that a process on a finance workstation has made an outbound connection to a known command-and-control (C2) domain. The analyst wants to quickly determine the full scope of the incident, including other hosts that may have communicated with the same domain. Which of the following actions should the analyst take FIRST?
Medium125A security analyst is investigating a suspected data exfiltration incident. The analyst has captured network traffic and wants to identify evidence of data being transferred over a covert channel. Which TWO of the following techniques would BEST help detect covert channels in the network traffic? (Choose two.)
Hard126A security administrator is implementing a new policy that requires all employees to use multi-factor authentication (MFA) for accessing cloud applications. The administrator wants to choose an MFA method that is resistant to phishing attacks. Which of the following MFA methods should the administrator select?
Easy127During a security incident, a SOC analyst identifies a process with a suspicious hash on several endpoints. The analyst wants to determine if this hash is known to be malicious by querying internal and external threat intelligence sources. Which standard should the analyst use to structure the threat intelligence data for automated sharing?
Medium128A security operations center (SOC) analyst is investigating a potential security incident. The analyst needs to determine the order of events on a compromised Windows host. The analyst has access to the following artifacts: a memory dump, the Windows Event Log, and the file system metadata. Which of the following provides the most reliable timeline of user and system activity?
Medium129A security analyst is reviewing a SIEM alert that indicates a user's credentials were used to log in from two different countries within a span of 10 minutes. This is likely an indicator of what type of attack?
Easy130A vulnerability has a CVSS base score of 9.8. The vulnerability is present on a server that is not exposed to the internet but is accessible to internal users with valid credentials. Which CVSS metric should be adjusted to reflect the reduced risk?
Medium131A SOC team is implementing a SOAR playbook to automate the response to phishing emails reported by users. The playbook should perform initial triage and, if the email is determined to be malicious, take containment actions. Which TWO of the following actions should be included in the playbook? (Choose TWO.)
Medium132A security analyst is investigating a potential data exfiltration incident. The analyst needs to preserve evidence for legal proceedings. Which two actions must the analyst take to maintain the chain of custody? (Select TWO).
Medium133During a penetration test, the tester has gained initial access to a web server and wants to perform lateral movement to reach a database server. The tester enumerates the network and finds that the web server has two network interfaces: one connected to a DMZ and one to an internal network. The database server is on the internal network. Which TWO techniques could the tester use to pivot from the web server to the database server? (Choose TWO.)
Hard134A security analyst is investigating a suspected data exfiltration incident. The analyst has captured full packet data from the network tap and wants to identify the exfiltration channel. Which TWO of the following techniques would be most effective for analyzing the captured traffic to detect covert exfiltration? (Choose two.)
Hard135A security analyst is investigating a potential data exfiltration incident. The analyst observes a large outbound transfer of encrypted traffic to an unfamiliar IP address over port 443. The organization uses a next-generation firewall (NGFW) with TLS inspection enabled. Which of the following actions would BEST determine if the traffic is malicious?
Hard136A security analyst is investigating a potential advanced persistent threat (APT) that has been evading traditional detection. The analyst decides to use User and Entity Behavior Analytics (UEBA) to identify anomalous activity. Which TWO of the following activities would be most indicative of a potential compromise when analyzed through UEBA? (Choose TWO.)
Hard137A senior security architect is designing a detection strategy for advanced persistent threats (APTs) that employ living-off-the-land (LotL) techniques. Which THREE of the following approaches are most effective for detecting LotL activities? (Choose three.)
Hard138A security administrator is configuring a new wireless network for a corporate office. The network must support the latest security standard that provides robust encryption and protection against offline dictionary attacks. Which of the following should the administrator implement?
Easy139A security team is evaluating endpoint detection and response (EDR) solutions. They want a solution that can detect fileless malware and malicious PowerShell scripts. Which TWO capabilities should the team prioritize? (Choose TWO.)
Easy140A security analyst is investigating a security incident and needs to collect volatile evidence from a compromised Windows system. The analyst must preserve the evidence in a forensically sound manner. Which TWO of the following actions should the analyst take to ensure the integrity of the volatile data? (Choose two.)
Hard141A security analyst is collecting evidence from a compromised workstation. Which of the following should be collected first to preserve volatile data?
Easy142An organization wants to detect and respond to advanced threats that may evade traditional endpoint security solutions. They deploy an EDR solution that provides real-time visibility into endpoint activities. However, the security team is overwhelmed by alerts. Which technology can be integrated with EDR to automate response actions and reduce alert fatigue?
Medium143A penetration tester is in the post-exploitation phase and wants to maintain access to a compromised system. Which of the following techniques is most effective for establishing persistent access while evading detection?
Medium144A security analyst is monitoring network traffic and observes a high volume of DNS queries for randomly generated domain names that return NXDOMAIN responses. The queries originate from a single workstation and occur at regular intervals. Which of the following is the MOST likely explanation for this activity?
Medium145A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an insider is using encrypted tunnels to transfer data. Which TWO of the following network traffic analysis (NTA) indicators are most likely to suggest encrypted exfiltration? (Choose two.)
Medium146A security operations center (SOC) is evaluating a new endpoint detection and response (EDR) tool. The tool reports a suspicious process that is making outbound network connections to a known command-and-control (C2) server. The SOC analyst wants to confirm the process is malicious by examining the process's parent-child relationships and command-line arguments. Which of the following should the analyst use to BEST achieve this?
Medium147During a penetration test, the tester has gained initial access to a network and now aims to move laterally to a sensitive database server. Which phase of the penetration testing lifecycle does this activity represent?
Medium148A security analyst is conducting a threat hunt based on the hypothesis that an adversary may have used PowerShell to execute malicious scripts. Which threat hunting methodology is being employed?
Medium149A security operations team is implementing a new SIEM and wants to ensure that log sources are properly synchronized. The team notices that some events appear out of order in the SIEM interface. Which of the following is the most likely cause and the best solution?
Medium150An organization deploys honeypots to detect attackers. Which type of deception technology is being used?
Easy151A penetration tester is performing reconnaissance against a target. Which TWO of the following are examples of active reconnaissance? (Select TWO.)
Medium152During an incident response, a forensic examiner is collecting evidence from a compromised Windows workstation. The examiner must follow proper order of volatility to preserve potential evidence. Which THREE of the following items should be collected first, before the others? (Choose THREE.)
Hard153During a threat hunting exercise, a security analyst hypothesizes that adversaries may be using PowerShell to execute commands in memory. Which threat hunting methodology is being employed?
Easy154A security analyst is reviewing a suspicious file. Which static analysis technique would the analyst use to examine the file without executing it?
Easy155A security operations team is implementing deception technology to detect lateral movement. Which TWO of the following are examples of deception technologies? (Select TWO.)
Medium156A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR can detect malicious activities such as process injection and credential dumping. Which of the following capabilities is MOST important for the EDR to have?
Easy157A security engineer is designing a network segmentation strategy for a new data center. The engineer wants to ensure that if a web server in the DMZ is compromised, the attacker cannot directly access the internal database servers. Which of the following controls would BEST achieve this objective?
Medium158A security analyst is investigating a potential malware infection on a Windows workstation. The analyst wants to perform live response to collect volatile data. Which of the following commands or tools should the analyst use to capture volatile data? (Choose two.)
Medium159During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?
Medium160A security team is implementing a new detection rule in their SIEM to identify brute-force attacks against a web application. The rule should trigger when there are more than 10 failed login attempts from the same source IP within 5 minutes. Which of the following data sources is MOST critical for this detection?
Medium161During a threat hunting exercise, a hunter uses the MITRE ATT&CK framework to identify a series of behaviors: an attacker used PowerShell to download a payload, then created a scheduled task for persistence, and finally performed credential dumping via LSASS. Which ATT&CK tactic is associated with the credential dumping technique?
Hard162A security team is implementing a new endpoint detection and response (EDR) solution. The team wants to ensure the EDR can detect advanced threats that use fileless malware techniques. Which TWO of the following capabilities are MOST important for detecting fileless malware? (Choose two.)
Hard163A penetration tester is conducting a test against a web application. The client has defined rules of engagement that prohibit any denial of service attacks. The tester discovers an endpoint that is vulnerable to command injection. Which THREE of the following actions should the tester take to validate the vulnerability while staying within scope? (Choose THREE.)
Medium164An incident response team is handling a ransomware incident. The team has successfully contained the threat and is now in the eradication phase. Which THREE actions are appropriate for the eradication phase? (Select THREE.)
HardOther domains
All CAS-005 exam domains
Frequently asked questions
- What does the Security Operations domain cover on the CAS-005 exam?
- A candidate must apply the correct methodology, evidence order, or incident phase to a scenario. The single most important thing: preserve volatile data first and never execute a sample when static analysis is requested.
- How many questions are in this domain?
- This page lists all 164 Security Operations questions in the CAS-005 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Operations questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.