Courseiva

CCNA Security Operations Questions

75 of 164 questions · Page 2/3 · Security Operations · Answers revealed

76
MCQmedium

Which CVSS metric component is used to reflect the impact of a vulnerability based on the specific environment of an organization?

A.Attack vector metric
B.Temporal metric
C.Environmental metric
D.Base metric
AnswerC

The environmental metric group modifies the base score using factors unique to the organisation's deployment, such as modified attack vector, confidentiality, integrity and availability requirements. It therefore reflects impact within a specific environment, exactly the constraint the question specifies.

Why this answer

The Environmental metric in CVSS adjusts the Base score to reflect the specific environment of an organization, including factors like modified attack vector, confidentiality, integrity, and availability requirements. It is the component explicitly designed to capture organization-specific impact.

Exam trap

CAS-005 often tests the confusion between Temporal metrics (time-based changes) and Environmental metrics (organization-specific context), causing candidates to pick Temporal when the question mentions the organization's environment.

How to eliminate wrong answers

Option A is wrong because Attack Vector is a Base metric that describes how the vulnerability is exploited (network, adjacent, local, physical) and is not environment-specific. Option B is wrong because Temporal metrics reflect characteristics that change over time, such as exploit code maturity, remediation level, and report confidence — not the organization's environment. Option D is wrong because Base metrics represent the intrinsic characteristics of the vulnerability that are constant across environments.

77
MCQmedium

A security analyst is investigating a potential security incident and needs to determine the order of events. The analyst has collected logs from various sources, including Windows Event Logs, firewall logs, and IDS alerts. Which of the following should the analyst do FIRST to establish a timeline?

A.Create a visual representation of the incident using a timeline tool
B.Correlate the IDS alerts with firewall logs to identify the attacker's IP address
C.Review Windows Event Logs for failed login attempts
D.Normalize the timestamps from all log sources to a common time zone and format
AnswerD

Logs from different sources may use different time zones, formats, or clock settings. Normalizing timestamps to a common standard (e.g., UTC) is essential to accurately correlate events and establish a timeline. Without this step, the analyst might misinterpret the sequence of events. This is a fundamental step in incident response and forensic analysis to ensure data integrity and consistency across disparate sources.

Why this answer

To establish an accurate timeline, the analyst must first normalize timestamps from all log sources to a common time zone and format. This ensures that events can be correctly ordered and correlated. Without this step, any subsequent analysis or correlation could be flawed due to time discrepancies.

The other actions are important but should be performed after timestamp normalization.

Exam trap

The trap here is jumping directly into log analysis or correlation without first ensuring that timestamps are consistent, which can lead to an incorrect sequence of events.

78
MCQhard

A security operations center (SOC) analyst is tuning a SIEM correlation rule to detect lateral movement using pass-the-hash attacks. The analyst wants to minimize false positives while ensuring detection of true positives. Which approach is most effective for reducing false positives in this scenario?

A.Alert on any use of NTLM authentication
B.Alert on multiple failed logins followed by a successful login from a different workstation
C.Disable NTLM authentication across the network
D.Compare authentication events against a baseline of normal user behavior and alert on anomalies
AnswerD

Baselining normal authentication behaviour lets the rule flag deviations such as a single account authenticating to many hosts rapidly, which typifies pass-the-hash lateral movement. This behavioural axis, rather than static signature matching, suppresses benign administrative logons and reduces false positives while retaining true-positive detection.

Why this answer

Comparing authentication events against a baseline of normal user behavior and alerting on anomalies is the most effective approach to reduce false positives while detecting pass-the-hash attacks. Pass-the-hash involves using stolen NTLM hashes to authenticate, often from unusual workstations or at unusual times. A baseline of normal behavior can identify deviations such as a user authenticating from a new workstation or at odd hours, which are strong indicators of compromise.

This approach is more precise than blanket rules.

Exam trap

The trap is choosing overly broad rules (like any NTLM) or generic patterns (failed logins) that cause false positives; the question emphasizes minimizing false positives, so behavior baselining is the best answer.

How to eliminate wrong answers

Option A is wrong because alerting on any NTLM authentication would generate massive false positives, as NTLM is still widely used for legitimate authentication. Option B is wrong because multiple failed logins followed by a successful login from a different workstation is a generic pattern that may indicate brute force or other issues, but it is not specific to pass-the-hash and can generate false positives. Option C is wrong because disabling NTLM authentication across the network is a drastic mitigation, not a detection tuning approach, and may break legacy applications.

79
MCQmedium

A security analyst is using Volatility to analyze a memory dump from a compromised Windows system. The analyst suspects that a rootkit is hiding processes. Which Volatility plugin should the analyst use to detect hidden processes?

A.pslist
B.psxview
C.malfind
D.pstree
AnswerB

psxview cross-references multiple process-listing sources, including EPROCESS linked lists, CSRSS handles and session structures, exposing processes hidden from any single view. Rootkits unlink entries from the standard list, so this plugin's comparison directly satisfies the requirement to detect hidden processes.

Why this answer

The 'psxview' plugin compares process listings from different sources (e.g., EPROCESS list, PspCidTable) to find discrepancies, which can reveal hidden processes.

80
MCQhard

During an incident response, a forensic analyst captures the memory of a compromised Windows system. Using Volatility, the analyst runs the 'pslist' command and sees a suspicious process 'svchost.exe' with a parent process 'explorer.exe'. Which Volatility plugin should the analyst use next to detect potential process hollowing?

A.netscan
B.psxview
C.dlllist
D.malfind
AnswerD

malfind scans process memory for injected code by locating regions with executable permissions lacking a mapped file on disk, the hallmark of process hollowing. Given the suspicious svchost.exe parented by explorer.exe, it directly tests the injected-code hypothesis pslist cannot confirm.

Why this answer

The malfind plugin is specifically designed to detect injected code and process hollowing by scanning process memory for regions with suspicious characteristics such as PAGE_EXECUTE_READWRITE permissions and MZ/PE headers in non-image memory. Given the suspicious svchost.exe parented by explorer.exe (svchost should normally be parented by services.exe), malfind is the correct next step to confirm hollowing or injection.

Exam trap

The trap is picking a plugin that sounds memory-related (psxview, dlllist) but actually serves a different purpose — only malfind scans for injected/hollowed executable memory regions.

How to eliminate wrong answers

Option A is wrong because netscan enumerates network connections and listening ports; it can show C2 traffic but does not detect process hollowing or injected code in memory. Option B is wrong because psxview cross-references multiple process-listing methods to find hidden processes (rootkit detection), which is useful for DKOM hiding but not for identifying hollowed process memory. Option C is wrong because dlllist lists loaded DLLs per process; while it can reveal missing or unexpected modules, it does not scan for injected executable memory regions the way malfind does.

81
MCQmedium

A security operations team is deploying a new endpoint agent. They want to enforce a policy that only executables signed by trusted publishers and with a valid certificate chain are allowed to run, even if the user has local administrator rights. Which Windows feature should they configure to meet this requirement?

A.Windows Defender Application Control (WDAC)
B.User Account Control (UAC)
C.Software Restriction Policies (SRP)
D.AppLocker
AnswerA

WDAC is a kernel-enforced code integrity feature that can enforce policies requiring all executables to be signed by trusted publishers with a valid certificate chain. It operates at the kernel level and cannot be bypassed by local administrators, making it suitable for this strict requirement. It also supports audit mode and multiple policy formats.

Why this answer

Windows Defender Application Control (WDAC) is the correct choice because it enforces code integrity at the kernel level, requiring all executables to have a valid certificate chain from a trusted publisher. It cannot be bypassed by local administrators, unlike AppLocker or SRP. UAC only manages elevation prompts and does not validate signatures, so it fails to meet the strict policy requirement.

Exam trap

The trap here is confusing application control features like AppLocker with kernel-enforced code integrity like WDAC, assuming they provide the same level of certificate validation.

82
Multi-Selecthard

A security analyst is using the MITRE ATT&CK framework to map adversarial behaviors. Which THREE of the following are tactics defined by ATT&CK? (Select THREE.)

Select 3 answers
A.Incident response
B.Privilege escalation
C.Persistence
D.Exfiltration
E.Phishing
AnswersB, C, D

Privilege escalation is one of the fourteen enterprise tactics in MITRE ATT&CK, describing the adversary's goal of gaining higher-level permissions. It sits alongside discovery and lateral movement as a tactical category, under which specific techniques such as exploitation for privilege escalation are catalogued.

Why this answer

Privilege escalation (B) is a valid ATT&CK tactic (TA0004) describing techniques adversaries use to gain higher-level permissions on a system or network, such as exploiting vulnerabilities or abusing elevation control mechanisms. Persistence (C) is a valid tactic (TA0003) covering techniques like scheduled tasks, registry Run keys, or creating accounts that let adversaries maintain their foothold across restarts or credential changes. Exfiltration (D) is a valid tactic (TA0010) describing techniques used to steal data from the target network, such as exfiltration over C2 channel or over alternative protocols.

Incident response (A) is not an ATT&CK tactic; it is a defensive workflow, and ATT&CK's tactics are adversary goals, not response phases. Phishing (E) is not a tactic but a technique (T1566) that falls under the Initial Access tactic, so it does not qualify as a tactic itself.

83
MCQmedium

An organization is implementing a SOAR solution to automate responses to common incidents. They want to create a playbook for phishing email handling. Which of the following actions should be automated in the playbook after a user reports a suspicious email?

A.Extract URLs and attachments, query threat intel feeds, and if malicious, block indicators and isolate the affected endpoint
B.Call the user to confirm they clicked the link
C.Send a warning email to all users
D.Immediately delete the email from all user inboxes
AnswerA

Extracting URLs and attachments, querying threat intelligence, then blocking indicators and isolating the endpoint chains deterministic enrichment and containment actions that require no human judgement, satisfying the stem's automation requirement. These steps execute faster than manual triage while preserving analyst review for ambiguous verdicts.

Why this answer

A phishing-handling playbook should automate the enrichment and containment steps: extract URLs and attachments, query threat intelligence feeds, and if indicators are malicious, block them and isolate the affected endpoint. This is the standard SOAR pattern of 'enrich, decide, contain' that reduces mean time to respond and removes manual toil. It is deterministic, API-driven, and safe to automate.

Exam trap

CAS-005 often tests whether candidates pick a manual or overly broad action (call the user, warn everyone, delete all emails) instead of the targeted enrich-and-contain automation that SOAR is designed for.

How to eliminate wrong answers

Option B is wrong because calling the user to confirm a click is a manual, human-dependent step that does not scale and is not a reliable automated action. Option C is wrong because blasting a warning email to all users is a broad communication action, not a targeted response, and can cause panic or be ignored. Option D is wrong because immediately deleting the email from all inboxes is a blunt action that can destroy evidence and may not be technically feasible or appropriate before analysis.

84
Multi-Selecthard

A threat intelligence analyst is profiling a threat actor that has been targeting the energy sector. Which THREE of the following attributes are most important to include in a threat actor profile? Select THREE.

Select 3 answers
A.Vulnerabilities exploited (CVEs)
B.Motivations and objectives
C.Targeted industries and regions
D.Tactics, Techniques, and Procedures (TTPs)
E.List of known indicators of compromise (IOCs)
AnswersB, C, D

Motivations and objectives reveal why the actor targets the energy sector, guiding attribution and prioritisation of defences against likely campaigns. Including intent distinguishes state-sponsored espionage from financially driven crimeware, shaping the strategic response beyond raw indicators.

Why this answer

Option B (Motivations and objectives) is correct because understanding why an actor targets the energy sector — whether for espionage, disruption, or financial gain — drives their targeting logic, persistence, and operational tempo, which is essential for prioritizing defenses. Option C (Targeted industries and regions) is correct because identifying the specific industries and geographic regions the actor focuses on enables sector-specific and region-specific threat modeling and intelligence sharing for energy organizations. Option D (Tactics, Techniques, and Procedures (TTPs)) is correct because TTPs describe the actor's behavioral patterns and tradecraft, which are more durable than atomic indicators and directly inform detection engineering and defensive countermeasures.

Option A (Vulnerabilities exploited) is not among the three most important profile attributes because specific CVEs are tactical, time-bound details that change frequently and are better tracked as vulnerability intelligence rather than core actor profiling. Option E (List of known indicators of compromise) is also not among the three most important because IOCs are volatile, easily changed by the adversary, and represent artifacts rather than the actor's enduring characteristics.

Exam trap

CAS-005 often tests the difference between strategic threat actor attributes (motivation, targets, TTPs) and tactical artifacts (CVEs, IOCs), tricking candidates into selecting volatile indicators as core profile elements.

85
MCQeasy

During a security incident, the incident response team has identified the root cause and removed the threat from all affected systems. Which phase of the incident response lifecycle involves returning systems to normal operation and monitoring for any signs of recurrence?

A.Eradication
B.Containment
C.Recovery
D.Lessons Learned
AnswerC

Recovery restores systems to normal operation after eradication, then monitors for recurrence. The stem's constraint — root cause identified and threat removed — places the incident exactly at the transition from eradication into recovery, where validated restoration and post-restoration monitoring occur.

Why this answer

The Recovery phase of the incident response lifecycle focuses on restoring systems to normal operation after the threat has been eradicated. It involves bringing systems back online, validating their integrity, and monitoring for any signs of recurrence. This phase ensures that the organization can resume business operations securely.

Exam trap

CAS-005 often tests the order and definitions of incident response phases, and candidates may confuse Recovery with Eradication or Containment, especially when the question mentions removing the threat.

How to eliminate wrong answers

Option A is wrong because Eradication involves removing the threat from the environment, not returning systems to normal operation. Option B is wrong because Containment focuses on limiting the spread of the incident, not recovery. Option D is wrong because Lessons Learned is a post-incident phase where the team reviews the incident to improve future response, not the phase where systems are restored.

86
MCQmedium

A security operations center (SOC) analyst is investigating a potential malware infection on a workstation. The analyst wants to perform static analysis on a suspicious executable. Which tool or technique is most appropriate for examining the executable without executing it?

A.Run the executable in a sandbox
B.Use a memory forensics tool like Volatility
C.Use the strings command to extract readable ASCII and Unicode strings
D.Perform a network traffic capture
AnswerC

The strings command extracts readable ASCII and Unicode sequences from a binary without executing it, revealing URLs, file paths and messages. This satisfies the stem's static analysis constraint, unlike dynamic tools that run the executable in a sandbox.

Why this answer

Static analysis involves examining an executable without running it. The strings command extracts readable ASCII and Unicode strings from a binary, which can reveal URLs, IP addresses, error messages, and other indicators without executing the code. This is a safe and quick method for initial triage of suspicious files.

Exam trap

CAS-005 often tests the distinction between static and dynamic analysis, and candidates may choose sandboxing (dynamic) when asked for a non-execution method.

How to eliminate wrong answers

Option A is wrong because running the executable in a sandbox is dynamic analysis, which involves execution and may be risky if the sandbox is not properly isolated. Option B is wrong because memory forensics tools like Volatility analyze memory dumps of running systems, not static executables. Option D is wrong because network traffic capture analyzes network communications, not the executable itself.

87
MCQhard

A security analyst is investigating a possible insider threat. The analyst has access to endpoint detection and response (EDR) telemetry, network flow logs, and authentication logs. The analyst suspects that a user is exfiltrating data by encoding it into DNS queries to a domain controlled by the attacker. Which data source and analysis technique would best confirm this activity?

A.Inspect DNS query logs for unusually long or high-entropy subdomain strings and repeated queries to the same domain.
B.Review authentication logs for anomalous login times or locations from the user's account.
C.Correlate EDR process creation events with network connections to known malicious IP addresses.
D.Analyze network flow logs for large outbound data transfers to external IP addresses.
AnswerA

DNS exfiltration often encodes data in subdomains, resulting in long, random-looking strings. Analyzing DNS query logs for such patterns, especially repeated queries to a single domain, can reveal tunneling. This directly addresses the scenario and uses the appropriate data source.

Why this answer

DNS exfiltration hides data in DNS queries, typically as encoded subdomains. The most direct way to confirm is to examine DNS query logs for indicators like long, high-entropy labels and repetitive queries to the same domain. Other data sources may show related activity but do not directly reveal the DNS-based channel.

Exam trap

The trap here is assuming that network flow logs will show large data transfers, but DNS exfiltration uses many small queries that may not exceed volume thresholds.

88
MCQhard

A SOC analyst is investigating a suspicious process that is making outbound connections to an unknown IP address. The analyst wants to examine the process memory for injected code. Which Volatility plugin is most appropriate for detecting code injection by listing all Virtual Address Descriptors (VADs) that are mapped as executable and writable?

A.netscan
B.malfind
C.pslist
D.dlllist
AnswerB

The malfind plugin scans process memory for VAD regions marked both executable and writable, flagging likely injected code such as reflective DLL injection or shellcode. Other plugins enumerate handles, connections or loaded modules, but none specifically target executable-writable memory mappings.

Why this answer

The malfind Volatility plugin is designed to detect code injection by scanning for memory regions that are both executable and writable, which is atypical for legitimate code. It lists Virtual Address Descriptors (VADs) with these permissions and can identify injected code, such as that from malware. This directly addresses the analyst's need to examine process memory for injected code.

Exam trap

CAS-005 often tests the specific Volatility plugin for detecting code injection, and candidates may confuse malfind with pslist or dlllist, which do not analyze memory permissions.

How to eliminate wrong answers

Option A is wrong because netscan lists network connections and does not analyze memory for code injection. Option C is wrong because pslist lists running processes but does not inspect memory permissions or detect injected code. Option D is wrong because dlllist lists loaded DLLs but does not identify suspicious memory regions with executable and writable permissions.

89
MCQeasy

Which of the following is the primary advantage of using STIX and TAXII for threat intelligence sharing?

A.They replace the need for a SIEM system
B.They perform dynamic analysis of malware samples
C.They provide real-time blocking of malicious IPs
D.They allow automated sharing of threat intelligence in a standardized format
AnswerD

STIX provides a structured language for describing indicators, actors and campaigns, while TAXII defines the transport protocol for exchanging that content. Together they let platforms ingest and act on intelligence automatically, removing manual reformatting between vendors.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is a protocol for exchanging that intelligence. Together, they enable automated sharing of threat intelligence in a standardized format, improving interoperability and speed of information exchange.

Exam trap

CAS-005 often tests the purpose of STIX/TAXII, and candidates may confuse them with analysis or blocking tools, rather than standards for sharing.

How to eliminate wrong answers

Option A is wrong because STIX/TAXII do not replace SIEM systems; they complement them by providing threat intelligence feeds. Option B is wrong because STIX/TAXII are not analysis tools; they are for representation and exchange, not dynamic malware analysis. Option C is wrong because STIX/TAXII do not perform blocking; they facilitate sharing of intelligence that can be used by other systems to block threats.

90
MCQmedium

A security team is evaluating an EDR solution. Which of the following capabilities is a primary differentiator between EDR and traditional antivirus?

A.Centralized policy management
B.File integrity monitoring
C.Signature-based detection of known malware
D.Behavioral analysis and detection
AnswerD

Behavioural analysis and detection distinguishes EDR from signature-based antivirus, which matches only known file hashes. EDR continuously monitors process behaviour, registry changes and API calls, then correlates these events to identify anomalous activity such as living-off-the-land techniques that traditional antivirus, lacking behavioural telemetry, would miss entirely.

Why this answer

EDR's primary differentiator from traditional antivirus is its use of behavioral analysis and detection. Traditional AV relies on static signatures to identify known malware, whereas EDR continuously records endpoint telemetry (process trees, registry changes, network connections) and applies behavioral heuristics, machine learning, and threat intelligence to detect novel or fileless attacks. This allows EDR to identify malicious activity even when no signature exists, and to provide detection, investigation, and response capabilities rather than just prevention.

Exam trap

CAS-005 often tests the misconception that EDR is simply 'next-gen antivirus' with signatures plus a cloud console, causing candidates to pick centralized management or signature detection instead of behavioral analysis.

How to eliminate wrong answers

Option A is wrong because centralized policy management is a common feature of both traditional AV (via management consoles like Symantec Endpoint Protection Manager) and EDR platforms, so it is not a differentiator. Option B is wrong because file integrity monitoring (FIM) is a separate capability often provided by HIDS/HIPS or compliance tools (e.g., Tripwire, OSSEC) and is not the defining characteristic of EDR. Option C is wrong because signature-based detection of known malware is the core mechanism of traditional antivirus, not a differentiator—EDR actually de-emphasizes signatures in favor of behavioral analytics.

91
MCQeasy

An organization wants to deploy a technology that lures attackers into a controlled environment to observe their tactics, techniques, and procedures (TTPs). Which deception technology should the organization implement?

A.Honeytoken
B.EDR
C.Honeypot
D.SIEM
AnswerC

A honeypot is a decoy system deliberately exposed to attract attackers, letting defenders observe their tactics, techniques and procedures within a controlled, monitored environment. It satisfies the requirement to lure adversaries and record their behaviour without risking production assets.

Why this answer

A honeypot is a decoy system intentionally designed to attract and deceive attackers, allowing defenders to observe their tactics, techniques, and procedures (TTPs) in a controlled environment. It mimics vulnerable services or entire networks, and any interaction with it is inherently suspicious, providing high-fidelity threat intelligence with minimal false positives. This matches the requirement to 'lure attackers into a controlled environment' for TTP observation.

Exam trap

CAS-005 often tests the confusion between honeypots and honeytokens—candidates may pick honeytoken thinking it 'lures' attackers, but honeytokens are passive tripwires, not interactive decoy environments.

How to eliminate wrong answers

Option A is wrong because a honeytoken is a single fake artifact (e.g., a credential, file, or URL) used to detect unauthorized access or data exfiltration, not a full environment for observing attacker behavior. Option B is wrong because EDR is a defensive endpoint monitoring and response tool, not a deception technology designed to lure attackers. Option D is wrong because SIEM aggregates and correlates log data for detection and compliance, but it does not actively lure or deceive attackers.

92
MCQmedium

A vulnerability scanner reports a critical vulnerability with a CVSS base score of 9.8 on a public-facing web server. However, the server has a compensating control: a Web Application Firewall (WAF) that blocks exploit attempts. How should the security team prioritize patching this vulnerability?

A.Schedule patching during the next maintenance window
B.Defer patching indefinitely since the WAF mitigates the risk
C.Immediately patch the vulnerability as soon as possible
D.Increase the WAF rule strictness and delay patching
AnswerC

A CVSS base score of 9.8 on an internet-facing server warrants immediate remediation; a WAF is a compensating detective or blocking control, not a substitute for patching, since bypasses and rule gaps exist. Delaying based on the WAF leaves the underlying exploitable flaw unaddressed.

Why this answer

The vulnerability has a CVSS base score of 9.8, which is Critical, and the server is public-facing, meaning it is directly exposed to potential attackers. While a WAF provides a compensating control, it is not a foolproof mitigation—WAFs can be bypassed through evasion techniques, misconfigurations, or zero-day exploits. Therefore, the security team should prioritize immediate patching to eliminate the underlying vulnerability, as recommended by risk management frameworks like NIST and CIS.

The WAF reduces immediate risk but does not eliminate it, so patching remains urgent.

Exam trap

CAS-005 often tests the misconception that a compensating control like a WAF can replace the need for immediate patching, but the exam expects candidates to recognize that critical vulnerabilities on public-facing systems require urgent remediation regardless of compensating controls.

How to eliminate wrong answers

Option A is wrong because scheduling patching during the next maintenance window delays remediation of a critical vulnerability on an internet-facing system, leaving a window of exposure that could be exploited if the WAF fails. Option B is wrong because deferring patching indefinitely based solely on a WAF is dangerous; WAFs are not infallible and can be bypassed, and the vulnerability remains unaddressed. Option D is wrong because increasing WAF rule strictness does not fix the underlying flaw and may cause false positives or operational issues, while still leaving the system vulnerable if the WAF is circumvented.

93
MCQmedium

A security analyst is reviewing a suspicious email reported by a user. The email contains a link to a domain that was registered three days ago and hosts a JavaScript file. The analyst wants to safely analyze the JavaScript file to understand its behavior without risking infection. Which of the following approaches is MOST appropriate?

A.Open the link in a sandboxed virtual machine with no network access and execute the JavaScript in a browser.
B.Download the JavaScript file and analyze its code using a text editor and a deobfuscation tool.
C.Submit the URL to a public online JavaScript sandbox and review the execution trace.
D.Use a command-line tool to fetch the JavaScript file and pipe it directly to a JavaScript engine for execution.
AnswerB

Downloading the file and performing static analysis with a text editor and deobfuscation tools allows the analyst to understand the script's logic, identify obfuscation techniques, and extract indicators without executing it. This avoids any risk of infection and is a standard safe practice for analyzing potentially malicious scripts.

Why this answer

Static analysis of the JavaScript file by downloading it and examining its code with deobfuscation tools is the safest and most informative approach. It allows the analyst to understand the script's functionality, extract indicators, and determine its malicious intent without any risk of executing the code. This method is preferred when the goal is to understand behavior without infection.

Exam trap

The trap here is assuming that any execution, even in a sandbox, is safe, when in fact static analysis avoids execution entirely and is often sufficient for JavaScript.

94
MCQmedium

A penetration tester is performing a test against a web application. During active reconnaissance, the tester discovers that the application discloses version numbers in HTTP headers. Which phase of the penetration testing lifecycle does this activity belong to?

A.Reconnaissance
B.Post-exploitation
C.Exploitation
D.Reporting
AnswerA

Banner grabbing and header inspection gather information about the target's technology stack without exploiting it, which is active reconnaissance within the reconnaissance phase. It precedes scanning, exploitation and post-exploitation, satisfying the lifecycle stage where target intelligence is collected.

Why this answer

Active reconnaissance involves directly interacting with the target to gather information, such as by sending probes and analyzing responses. Discovering version numbers via HTTP headers is a form of active reconnaissance because the tester is making requests and inferring information from the responses.

95
MCQmedium

A security analyst is reviewing a suspicious email reported by a user. The email contains an attachment named 'invoice.pdf.exe'. Which type of malware analysis technique should the analyst perform first to determine if the file is malicious?

A.Reverse engineering
B.Static analysis
C.Dynamic analysis in a sandbox
D.Memory forensics
AnswerB

Static analysis examines the file's structure, strings and headers without executing it, safely revealing the double extension and embedded indicators. This satisfies the stem's need to determine maliciousness first, before risking execution in a sandbox.

Why this answer

Static analysis examines the file without executing it, inspecting headers, strings, hashes, and embedded indicators (e.g., PE headers, suspicious imports) to quickly determine if it is malicious. For a double-extension file like 'invoice.pdf.exe', static analysis is the safest first step because it avoids any risk of execution and can often reveal known malware signatures or obfuscation. It is faster and less resource-intensive than dynamic analysis or reverse engineering, making it the standard initial triage technique.

Exam trap

CAS-005 often tests the confusion between static and dynamic analysis — candidates may think 'sandbox' is always first, but the safest and fastest initial triage for an unknown file is static analysis, not execution.

How to eliminate wrong answers

Option A is wrong because reverse engineering is a deep, time-consuming process used after initial triage confirms the file is suspicious; it is not the first step. Option C is wrong because dynamic analysis in a sandbox executes the malware, which carries risk and requires more setup; it is typically performed after static analysis indicates the file is likely malicious. Option D is wrong because memory forensics analyzes volatile memory (RAM) of a running system, not a file attachment, and is irrelevant to initial file triage.

96
Multi-Selecthard

A security engineer is reviewing the results of a penetration test. The tester successfully exploited a vulnerability in a web application and escalated privileges to domain admin. Which THREE of the following findings should be included in the technical report to provide actionable remediation steps? (Select THREE.)

Select 3 answers
A.The estimated financial loss from the exploit
B.The recommendation to patch the web application
C.The exact command used to exploit the vulnerability
D.The name and contact of the penetration tester
E.The step-by-step path from initial access to domain admin
AnswersB, C, E

Recommending the patch gives the remediation team the specific fix that closes the exploited web application vulnerability, addressing the initial access vector. This satisfies the stem's requirement for actionable remediation steps in the technical report.

Why this answer

Option B is correct because the technical report must provide actionable remediation, and recommending that the web application be patched directly addresses the exploited vulnerability and prevents recurrence. Option C is correct because documenting the exact command used to exploit the vulnerability gives defenders a reproducible proof of concept, enabling them to verify the flaw and test that remediation actually blocks the attack. Option E is correct because the step-by-step path from initial access to domain admin illustrates the full attack chain and privilege-escalation weaknesses, which is essential for prioritizing fixes to identity, segmentation, and tiered administration controls.

Option A does not belong because estimated financial loss is a business-impact or risk-management metric, not a technical remediation step. Option D does not belong because the tester's name and contact details are administrative metadata, not actionable technical remediation guidance.

Exam trap

CAS-005 often tests the distinction between technical remediation content and business/administrative content—candidates may incorrectly include financial loss or tester contact details, which belong in the executive summary or administrative section.

97
MCQmedium

A vulnerability management team is prioritizing patches for a set of critical vulnerabilities. Vulnerability A has a CVSS base score of 9.8, vulnerability B has a CVSS base score of 7.5, and vulnerability C has a CVSS base score of 8.2. However, vulnerability B is actively being exploited in the wild, while the others are not. Which vulnerability should be patched first according to best practices?

A.All three should be patched simultaneously
B.Vulnerability B because it is actively exploited
C.Vulnerability C because it has a higher base score than B
D.Vulnerability A because it has the highest base score
AnswerB

CVSS base scores measure intrinsic severity only, not real-world threat. Exploit availability and active exploitation are captured by temporal and threat metrics, which raise actual risk. Since B is being exploited in the wild, it poses immediate likelihood of compromise, so best practise prioritises it over higher-scoring but unexploited flaws.

Why this answer

Vulnerability B should be patched first because it is actively being exploited in the wild. While CVSS base scores indicate severity, active exploitation means the vulnerability poses an immediate and real threat. Best practices prioritize vulnerabilities with known exploits, especially those used in active attacks, over higher-scored but unexploited ones.

Exam trap

The trap is focusing solely on CVSS scores and ignoring the critical factor of active exploitation, which should override base score in prioritization.

How to eliminate wrong answers

Option A is wrong because patching all simultaneously may not be feasible and ignores prioritization based on risk; it also does not address the immediate threat of active exploitation. Option C is wrong because vulnerability C has a higher base score than B, but it is not actively exploited, so it is less urgent than B. Option D is wrong because vulnerability A has the highest base score, but without active exploitation, it is less urgent than B, which is being exploited.

98
MCQmedium

A security analyst is reviewing the following command executed on a Linux server: 'nmap -sS -Pn -p 80,443 192.168.1.0/24'. Which of the following BEST describes the purpose of this command?

A.Perform a ping sweep to identify live hosts on the subnet, then scan ports 80 and 443
B.Perform a TCP connect scan on all ports across the subnet, including host discovery
C.Perform a TCP SYN scan on ports 80 and 443 across the subnet, skipping host discovery
D.Perform a UDP scan on ports 80 and 443 across the subnet, skipping host discovery
AnswerC

The -sS flag initiates a TCP SYN scan (half-open scan), which is stealthy because it does not complete the TCP handshake. The -Pn flag disables host discovery (ping), treating all hosts as online. The -p 80,443 specifies ports 80 and 443. The target is the subnet 192.168.1.0/24. This command is used to quickly identify web servers on the network without performing a full port scan or host discovery, which can be noisy and slow.

Why this answer

The command uses -sS for a TCP SYN scan, -Pn to skip host discovery, and -p 80,443 to target specific ports. This is a common reconnaissance technique to quickly identify web servers on a subnet without the noise of a full port scan or host discovery. The other options misinterpret the flags or the scan type.

Exam trap

The trap here is confusing -Pn (skip host discovery) with -sn (ping sweep), and -sS (SYN scan) with -sT (connect scan).

99
Multi-Selecthard

A security analyst is reviewing a packet capture (PCAP) from a suspected command-and-control (C2) channel. The analyst observes periodic outbound connections to an external IP address over TCP port 443. The traffic is encrypted with TLS, but the analyst suspects it may be malicious. Which TWO of the following techniques would be MOST effective to identify the malicious nature of the traffic without decrypting the payload? (Choose two.)

Select 2 answers
A.Examine the packet sizes and timing intervals for patterns.
B.Run a vulnerability scanner against the external IP address.
C.Perform deep packet inspection (DPI) to examine the payload contents.
D.Analyze the TLS certificate presented by the external server for anomalies.
E.Decrypt the TLS traffic using the server's public key.
AnswersA, D

Even with encryption, the size and timing of packets can reveal patterns. C2 channels often exhibit regular beaconing intervals, consistent packet sizes, or specific request-response patterns. Analyzing these metadata can indicate automated malicious communication. This technique is effective because it does not require payload decryption and can be automated in network monitoring tools.

Why this answer

Analyzing the TLS certificate can reveal anomalies like self-signed or expired certificates, which are common in malicious C2 infrastructure. Examining packet sizes and timing intervals can expose beaconing patterns typical of automated C2 communication. Both techniques work without decrypting the payload.

Deep packet inspection requires decryption, using the public key for decryption is impossible, and vulnerability scanning does not analyze the traffic itself.

Exam trap

The trap here is assuming that deep packet inspection can reveal encrypted payload contents without decryption, or that the server's public key can decrypt TLS traffic.

100
MCQeasy

Which of the following is a key benefit of using an Extended Detection and Response (XDR) solution over traditional Endpoint Detection and Response (EDR)?

A.XDR only works with a single vendor's products
B.XDR eliminates the need for SIEM and SOAR systems
C.XDR only focuses on network traffic analysis
D.XDR provides centralized visibility across multiple security layers including endpoints, network, and cloud
AnswerD

XDR natively ingests and correlates telemetry from endpoints, network, cloud and identity into one console, satisfying the stem's cross-layer visibility requirement. EDR's scope stops at the endpoint agent, so it cannot surface network or cloud signals. This broader correlation is the defining architectural difference between the two.

Why this answer

XDR extends detection beyond endpoints to include network, email, cloud, and other data sources, providing broader visibility and correlation across the entire environment.

101
MCQhard

A security analyst is investigating a potential data exfiltration incident. Network logs show a large volume of outbound traffic from an internal database server to an unfamiliar external IP address over port 443. The traffic occurs daily at 02:00 and lasts for exactly 15 minutes. The analyst suspects the use of a covert channel. Which of the following techniques is the analyst MOST likely observing?

A.Scheduled data transfer using a covert channel over HTTPS
B.DNS tunneling
C.ICMP exfiltration
D.Domain fronting
AnswerA

The traffic is outbound on port 443 (HTTPS), occurs at a fixed time daily, and lasts a consistent duration. This pattern suggests an automated, scheduled exfiltration using a covert channel that blends with normal HTTPS traffic. The use of port 443 helps evade detection that focuses on non-standard ports, and the regularity indicates a scripted task rather than interactive user activity.

Why this answer

The combination of HTTPS (port 443), a fixed daily schedule, and a consistent short duration strongly suggests an automated exfiltration script using a covert channel that mimics legitimate web traffic. This method allows data to leave the network without raising alarms based on port or protocol anomalies. The unfamiliar external IP and the database server as the source further point to a compromised host exfiltrating data via an encrypted channel.

Exam trap

The trap here is focusing on the term 'covert channel' and jumping to DNS tunneling or ICMP, when the port and traffic pattern clearly indicate HTTPS-based exfiltration.

102
MCQeasy

Which of the following is the primary purpose of a honeypot in a security operations environment?

A.To encrypt sensitive data at rest
B.To replace the need for traditional firewalls
C.To block malicious traffic at the network perimeter
D.To provide early detection of unauthorized activity
AnswerD

A honeypot is a decoy system with no legitimate production role, so any interaction with it is inherently suspicious. This lets the SOC detect unauthorised activity early, before attackers reach real assets, satisfying the requirement for early warning rather than prevention or attribution.

Why this answer

A honeypot is a decoy system designed to attract and detect attackers. Its primary purpose is to provide early detection of unauthorized activity by luring attackers away from real systems and alerting security teams to their presence and methods.

Exam trap

CAS-005 often tests the misconception that honeypots are preventive controls like firewalls, when they are actually detective controls focused on early warning and intelligence gathering.

How to eliminate wrong answers

Option A is wrong because encryption of sensitive data at rest is a data protection measure, not the purpose of a honeypot. Option B is wrong because honeypots do not replace firewalls; they are complementary tools for detection, not prevention. Option C is wrong because blocking malicious traffic at the perimeter is the role of firewalls and intrusion prevention systems, not honeypots, which are designed to monitor and deceive.

103
MCQmedium

A security analyst receives an alert from the SIEM indicating multiple failed logon attempts from an external IP address followed by a successful logon for a domain admin account. Which phase of the incident response lifecycle is the analyst currently in?

A.Lessons learned
B.Containment
C.Detection
D.Preparation
AnswerC

Detection covers monitoring and identifying security events, so receiving and triaging the SIEM alert places the analyst squarely in this phase. The failed logons followed by a successful domain admin logon constitute the indicator being detected, before any containment, eradication or recovery activity begins.

Why this answer

The analyst is in the Detection phase because they are analyzing an alert from the SIEM indicating suspicious activity. Detection involves monitoring and identifying potential security incidents through alerts, logs, and other tools. The analyst has not yet moved to containment or other phases; they are still assessing the alert.

Exam trap

CAS-005 often tests the confusion between Detection and Containment; candidates may think that receiving an alert means they are already containing, but containment requires active steps to limit damage.

How to eliminate wrong answers

Option A is wrong because Lessons Learned occurs after an incident is resolved, to improve future response. Option B is wrong because Containment involves taking action to stop the spread of an incident, which has not happened yet. Option D is wrong because Preparation involves establishing plans and capabilities before an incident occurs, not responding to an alert.

104
MCQmedium

During a digital forensics investigation, an analyst needs to acquire the contents of RAM from a compromised server. Which order of volatility should the analyst follow?

A.Capture the swap file first, then RAM
B.Capture network connections first, then RAM
C.Capture the hard drive image first, then RAM
D.Capture RAM first, then the hard drive
AnswerD

RAM is volatile and lost on power-off, so it must be captured before the hard drive, which retains data persistently. This ordering follows the RFC 3227 volatility principle, satisfying the stem's requirement to acquire the most perishable evidence first.

Why this answer

The order of volatility (RFC 3227) dictates that the most volatile evidence be collected first: CPU registers and cache, then RAM, then swap/pagefile, then network state, then disk. RAM is far more volatile than disk, so it must be captured before the hard drive image. This preserves evidence like running processes, encryption keys, and network connections that vanish on power-off.

Exam trap

CAS-005 often tests the order of volatility — candidates pick 'hard drive first' because disk imaging is the most familiar forensic step, but the rule is always most-volatile-first, and RAM beats disk every time.

How to eliminate wrong answers

Option A is wrong because the swap file resides on disk and is less volatile than RAM — capturing it first violates the order of volatility and risks losing RAM contents. Option B is wrong because while network connections are volatile, they are captured as part of or alongside RAM acquisition (e.g., via netstat output saved to the forensic image), and the question asks for the correct overall order — RAM precedes disk, and network state is typically captured during live response before or with RAM, not as a separate first step ahead of RAM in this framing. Option C is wrong because imaging the hard drive first is the classic order-of-volatility violation — disk is the least volatile of the listed items, so doing it first destroys or overlooks the more volatile RAM evidence.

105
MCQmedium

A security analyst is investigating a potential insider threat. The analyst has access to logs from a Data Loss Prevention (DLP) system that flagged an employee for sending a large number of documents to a personal cloud storage account. The analyst needs to determine if this is a malicious exfiltration attempt or legitimate business activity. Which of the following actions should the analyst take FIRST?

A.Review the DLP alert details, including the file names, sizes, and destination, and compare with the employee's normal behavior.
B.Immediately disable the employee's account to prevent further data loss.
C.Escalate to the legal department to prepare for potential litigation.
D.Interview the employee's manager to ask if the employee is authorized to share documents externally.
AnswerA

Reviewing the alert details and comparing with the employee's baseline behavior helps determine if the activity is anomalous. This initial triage provides context to decide if further investigation or escalation is needed. It is non-disruptive and gathers evidence before taking action, which is the correct first step in incident response.

Why this answer

The first step in investigating a potential insider threat is to review the DLP alert details and compare them with the employee's normal behavior. This triage helps determine whether the activity is anomalous and warrants further investigation. It is non-disruptive and preserves the ability to gather additional evidence before taking any action that could alert the employee or disrupt business.

Exam trap

The trap here is jumping to containment actions like disabling the account or escalating to legal before confirming the activity is actually malicious.

106
MCQmedium

A SOC team is implementing a SOAR playbook to automate response to phishing emails reported by users. Which step should be included in the playbook to prevent other users from accessing the malicious link?

A.Isolate the reporter's workstation
B.Reset the reporter's password
C.Block the malicious URL in the web proxy
D.Delete the email from all mailboxes
AnswerC

A web proxy enforces URL filtering at the egress path, so adding the malicious URL to its blocklist stops any user from resolving or reaching that link. This satisfies the requirement to prevent other users accessing it, containing the campaign before further credentials or payloads are delivered.

Why this answer

Blocking the malicious URL in the web proxy prevents all users from accessing the phishing link, effectively containing the threat. This step is proactive and protects the entire organization, not just the reporter.

Exam trap

CAS-005 often tests the difference between containment and remediation actions, leading candidates to choose actions that address the reporter's device rather than organization-wide protection.

How to eliminate wrong answers

Option A is wrong because isolating the reporter's workstation is a reactive measure that only contains the incident on one device and does not prevent others from clicking the link. Option B is wrong because resetting the reporter's password is only necessary if credentials were compromised, and it does not block the URL. Option D is wrong because deleting the email from all mailboxes is a good step but does not prevent users who may have already clicked or received the link via other means; blocking the URL is more comprehensive.

107
MCQeasy

A security analyst is configuring an EDR solution to detect a specific fileless attack technique where malicious code is injected into the memory of a legitimate process. The analyst wants to trigger an alert when a process attempts to write to the memory of another process. Which Windows API function should the EDR monitor to detect this activity?

A.NtCreateThreadEx
B.CreateRemoteThread
C.WriteProcessMemory
D.VirtualAllocEx
AnswerC

WriteProcessMemory is the Windows API function used to write data to the memory of another process. Monitoring this API will directly detect attempts to inject code or modify memory in a remote process, which is a common step in fileless attacks. This aligns precisely with the requirement to detect memory writing to another process.

Why this answer

The correct API to monitor for detecting memory writes to another process is WriteProcessMemory. This function is commonly used in process injection and fileless malware to place malicious code into a legitimate process's memory space. Monitoring it provides direct visibility into the injection attempt.

Other APIs like CreateRemoteThread or VirtualAllocEx are related but do not directly capture the write operation.

Exam trap

The trap here is confusing memory allocation or thread creation APIs with the actual memory writing API, leading to monitoring the wrong function.

108
MCQeasy

A security administrator is configuring a new endpoint detection and response (EDR) solution. The administrator wants to ensure that the EDR agent can detect and block malicious activities in real-time. Which of the following capabilities is MOST essential for the EDR agent to achieve this goal?

A.Periodic full disk scans scheduled during off-hours.
B.Integration with a security information and event management (SIEM) system.
C.User behavior analytics (UBA) to detect insider threats.
D.Continuous monitoring of process and file system activity.
AnswerD

EDR solutions rely on continuous monitoring of endpoint activities such as process creation, file modifications, and network connections to detect malicious behavior in real-time. This telemetry is essential for identifying indicators of compromise and triggering automated responses. Without continuous monitoring, the EDR would lack the data needed to detect and block threats as they occur.

Why this answer

EDR agents must continuously monitor endpoint activities such as process execution, file system changes, and network connections to detect and block malicious behavior in real-time. This telemetry enables behavioral analysis and immediate response. SIEM integration, scheduled scans, and UBA are valuable but do not provide the real-time detection and blocking capability that continuous monitoring offers.

Exam trap

The trap here is confusing SIEM integration or scheduled scans with the real-time monitoring that is fundamental to EDR's detection and blocking capabilities.

109
MCQhard

A security analyst is investigating a malware sample and wants to determine its capabilities without executing it. The analyst examines the binary's imports, strings, and structure. What type of analysis is being performed?

A.Memory analysis
B.Static analysis
C.Reverse engineering
D.Dynamic analysis
AnswerB

Static analysis examines a binary's code, imports, strings and structure without running it, directly satisfying the stem's constraint of determining capabilities without execution. Unlike dynamic analysis, which observes runtime behaviour in a sandbox, static analysis reveals potential functionality through inspection alone, making it the appropriate technique here.

Why this answer

Static analysis involves examining a file's code, structure, and metadata without running it. By inspecting imports, strings, and headers, the analyst gains insight into potential functionality (e.g., API calls, embedded URLs) without risking execution. This is the definition of static analysis, as opposed to dynamic analysis which requires running the sample.

Reverse engineering is a broader process that includes static and dynamic techniques, but the specific actions described are classic static analysis.

Exam trap

The trap here is confusing static analysis with reverse engineering, as both involve examining code without execution, but reverse engineering is a broader process that includes static and dynamic methods; the question specifically describes non-execution inspection of imports, strings, and structure, which is static analysis.

How to eliminate wrong answers

Option A is wrong because memory analysis involves examining volatile memory (RAM) to capture running processes, network connections, or injected code, which requires the malware to have executed. Option C is wrong because reverse engineering is a more comprehensive discipline that often includes disassembly, debugging, and behavioral analysis; while static analysis is a part of it, the question specifically describes the non-execution examination of imports, strings, and structure, which is static analysis. Option D is wrong because dynamic analysis requires executing the malware in a controlled environment to observe its behavior, such as monitoring file system changes, registry modifications, or network traffic.

110
Multi-Selecteasy

A security analyst is reviewing CVSS scores for vulnerability prioritization. Which TWO of the following are component metric groups in CVSS v3?

Select 2 answers
A.Impact
B.Temporal
C.Exploitability
D.Environmental
E.Attack Vector
AnswersB, D

Temporal metrics capture characteristics that change over time, such as exploit code maturity, remediation level and report confidence, modifying the Base score without altering the intrinsic vulnerability. CVSS v3 defines exactly three metric groups: Base, Temporal and Environmental.

Why this answer

In CVSS v3, the score is built from three metric groups: Base, Temporal, and Environmental. Option B (Temporal) is correct because it is one of the three metric groups, capturing characteristics that change over time such as Exploit Code Maturity, Remediation Level, and Report Confidence. Option D (Environmental) is also correct because it is a metric group that lets analysts customize the score based on their own environment, including Confidentiality/Integrity/Availability Requirements and modified base metrics.

The unmarked options do not belong because Impact, Exploitability, and Attack Vector are not metric groups; Impact and Exploitability are Base metric sub-scores, and Attack Vector is a single Base metric, not a group.

Exam trap

CAS-005 often tests the distinction between CVSS metric groups and their sub-metrics, tricking candidates into selecting Impact or Exploitability as standalone groups when they are actually Base sub-components.

111
MCQmedium

During a penetration test, the tester has gained initial access to a web server and wants to move laterally to a database server. Which of the following techniques would be most effective for identifying valid credentials that could be reused on the database server?

A.Running a port scan on the internal network
B.Deploying a web shell for persistent access
C.Conducting a SQL injection on the database server
D.Using Mimikatz to dump credentials from memory
AnswerD

Mimikatz extracts plaintext passwords, NTLM hashes and Kerberos tickets from LSASS memory on the compromised host. Reused local or domain credentials harvested this way frequently authenticate to the database server, satisfying the objective of finding valid reusable credentials.

Why this answer

Mimikatz extracts plaintext passwords, NTLM hashes, and Kerberos tickets from LSASS memory on a compromised Windows host. Because administrators frequently reuse local or domain credentials across servers, harvested credentials can be replayed against the database server via SMB, RDP, or native database authentication. This directly satisfies the objective of identifying reusable valid credentials for lateral movement.

Exam trap

CAS-005 often tests the distinction between reconnaissance actions (port scanning, web shell deployment) and credential-access techniques, tricking candidates into selecting an option that provides access or persistence rather than the credential discovery the question explicitly asks for.

How to eliminate wrong answers

Option A is wrong because a port scan only enumerates open ports and services, revealing reachability but never yielding credential material. Option B is wrong because a web shell provides persistent remote code execution on the already-compromised web server; it does not extract or discover credentials for other systems. Option C is wrong because SQL injection against the database server targets data extraction or query manipulation, not credential harvesting from the web server's memory, and it assumes an exploitable injection point that may not exist.

112
MCQmedium

A security operations center (SOC) analyst is investigating a potential phishing incident. The analyst has a suspicious email and wants to safely analyze any URLs without directly visiting them from a corporate workstation. Which of the following techniques should the analyst use to examine the URL's reputation and content?

A.Copy the URL into a text editor and inspect the domain for typosquatting, then use a WHOIS lookup to determine the registrar.
B.Forward the email to a personal email account and open the URL on a personal device to see if it is malicious.
C.Use a URL sandboxing service that detonates the URL in an isolated environment and provides a screenshot and network traffic analysis.
D.Use a command-line tool like curl to fetch the URL headers and HTML content, then analyze the response for malicious scripts.
AnswerC

URL sandboxing services, such as VirusTotal or URLScan.io, allow analysts to submit a URL and have it rendered in a controlled, isolated environment. This reveals the final destination, any drive-by downloads, and network connections without risking the corporate workstation. It is a safe and efficient method for initial triage of suspicious URLs.

Why this answer

URL sandboxing services are designed to safely analyze URLs by rendering them in an isolated environment. They provide valuable information such as screenshots, final URL, and network requests, which help determine if the URL is malicious. This approach protects the analyst's workstation and the corporate network while gathering actionable intelligence.

Exam trap

The trap here is assuming that passive inspection or using local tools like curl is sufficient for safe analysis, when in fact dynamic sandboxing is required to observe behavior without risk.

113
Multi-Selecthard

A security analyst is investigating a potential compromise of a Windows server. The analyst suspects that an attacker used a technique to dump credentials from memory. Which TWO of the following artifacts or events would MOST likely indicate that a credential dumping tool such as Mimikatz was executed? (Choose two.)

Select 2 answers
A.Event ID 4624 with logon type 3 (network) for a service account
B.Event ID 10 from Sysmon showing lsass.exe accessed by an unsigned process
C.Event ID 4688 with process creation for lsass.exe
D.Event ID 7045 with a new service named 'MimikatzSvc'
E.Event ID 4656 with handle to lsass.exe requesting PROCESS_VM_READ
AnswersB, E

Sysmon Event ID 10 logs process access, including when a process opens a handle to another process. If an unsigned process accesses lsass.exe, it is highly suspicious because legitimate processes accessing lsass are typically signed by Microsoft. This event is a strong indicator of credential dumping attempts, as tools like Mimikatz often run as unsigned binaries or injected code.

Why this answer

The correct indicators are a handle request to lsass.exe with PROCESS_VM_READ (Event ID 4656) and Sysmon Event ID 10 showing lsass.exe accessed by an unsigned process. Both directly relate to unauthorized memory reading of the Local Security Authority Subsystem Service, which stores credentials. The other events are either normal system activities or too generic to specifically indicate credential dumping.

Exam trap

The trap here is assuming that any process creation or service installation involving lsass or Mimikatz is a clear indicator, when in fact credential dumping is best detected by monitoring access to lsass memory.

114
MCQmedium

A security operations center (SOC) analyst is reviewing logs from a Linux web server and notices a high volume of requests containing encoded characters such as %2e%2e%2f and %00 in the URI. The analyst suspects an attempt to exploit a path traversal vulnerability. Which of the following log sources would BEST confirm whether the attack was successful?

A.Firewall logs showing allowed outbound connections from the web server to a database server.
B.Intrusion detection system (IDS) alerts indicating a path traversal signature match.
C.Web server access logs showing HTTP 200 responses for requests containing encoded traversal sequences.
D.Authentication logs showing multiple failed login attempts from the same IP address.
AnswerC

HTTP 200 responses to traversal attempts indicate the server processed the requests successfully, which may mean files outside the web root were accessed. This directly confirms potential success, unlike error codes. Correlating with file access logs can further validate, but the access logs are the primary source for web-based attacks.

Why this answer

To confirm a path traversal attack's success, the analyst needs evidence that the server actually processed the malicious requests and potentially returned sensitive files. Web server access logs with HTTP 200 responses to traversal attempts provide that evidence. Other log sources may indicate attempts or unrelated activity but do not directly confirm file access.

Exam trap

The trap here is assuming that an IDS alert or firewall log confirms a successful attack, when they only show attempts or unrelated traffic.

115
MCQmedium

A security analyst is reviewing a suspicious process that has been identified on an endpoint. The analyst wants to determine if the process has any network connections and what data it might be sending. Which tool is most appropriate for analyzing the memory of the affected system to identify network connections and potential data exfiltration?

A.Wireshark
B.Volatility
C.Autopsy
D.Nmap
AnswerB

Volatility performs memory forensics, parsing a captured RAM image to enumerate running processes, their network sockets and injected artefacts. That directly satisfies the requirement to analyse memory for network connections and potential exfiltration, which disk-based or live-response tools cannot reconstruct from volatile state.

Why this answer

Volatility is a memory forensics framework that analyzes RAM dumps to extract running processes, network connections, and injected code. It is the most appropriate tool for examining memory to identify network connections and potential data exfiltration from a suspicious process.

Exam trap

CAS-005 often tests the confusion between network forensics tools (Wireshark, Nmap) and memory forensics tools (Volatility), causing candidates to select a network analysis tool when the question explicitly asks for memory analysis.

How to eliminate wrong answers

Option A (Wireshark) is wrong because Wireshark captures and analyzes live network traffic, not memory — it cannot inspect process memory or identify which process initiated a connection. Option C (Autopsy) is wrong because Autopsy is a disk forensics tool for file system analysis, not memory analysis. Option D (Nmap) is wrong because Nmap is a network scanning tool for host and port discovery, not memory forensics.

116
Multi-Selecthard

A security analyst is reviewing a potentially malicious PowerShell script that was executed on a workstation. The script contains obfuscated code and makes network connections. The analyst wants to perform dynamic analysis to understand its behavior. Which TWO of the following methods would BEST allow the analyst to observe the script's runtime actions in a controlled environment? (Choose two.)

Select 2 answers
A.Use PowerShell's Constrained Language Mode to restrict script execution
B.Set up a debugger and step through the script line by line
C.Execute the script in an isolated sandbox with network simulation and monitor API calls
D.Perform static analysis by extracting strings and examining the abstract syntax tree
E.Run the script on a production workstation with logging enabled
AnswersB, C

Using a debugger to step through the script line by line allows the analyst to observe variable values, function calls, and execution flow in real time. This is a powerful dynamic analysis method for understanding obfuscated scripts. It can reveal decryption routines and network calls as they happen, without needing to fully deobfuscate statically.

Why this answer

Dynamic analysis involves executing the script in a controlled environment to observe its behavior. An isolated sandbox with network simulation allows safe execution and monitoring of API calls, network traffic, and system changes. Stepping through the script with a debugger provides line-by-line visibility into its execution, revealing obfuscated logic and runtime actions.

Both methods are essential for understanding malicious scripts without risking production systems.

Exam trap

The trap here is confusing static analysis or restrictive controls with dynamic analysis, which requires executing the code in a safe environment to observe behavior.

117
MCQmedium

A security analyst is investigating a potential insider threat. The analyst needs to correlate user activity across multiple systems, including file access, email, and web browsing, to build a timeline of events. Which data source is MOST critical for this correlation?

A.Endpoint detection and response (EDR) telemetry
B.Active Directory authentication logs
C.NetFlow records
D.Firewall logs
AnswerA

EDR telemetry captures detailed endpoint activity, including process execution, file operations, network connections, and user context. This rich data enables correlation of user actions across systems, making it the most critical source for building a comprehensive timeline of insider activity.

Why this answer

EDR telemetry is the most critical data source because it provides detailed, user-attributed activity across endpoints, including file, process, and network events. This allows the analyst to correlate actions across multiple systems and construct a timeline, whereas other sources offer only partial or network-level visibility.

Exam trap

The trap here is assuming that network-centric logs like NetFlow or firewall logs can provide user-level activity correlation, when they lack identity and application context.

118
MCQmedium

A penetration tester is performing a test against a web application. The rules of engagement prohibit any denial of service (DoS) attacks. Which of the following actions is most likely prohibited by this restriction?

A.Performing a SQL injection that deletes a table
B.Exploiting a file upload vulnerability to upload a web shell
C.Using a tool to send thousands of requests to overwhelm the server
D.Running a directory brute-force tool
AnswerC

Flooding the server with thousands of requests is a volumetric denial-of-service technique, consuming resources until legitimate users are denied service. The rules of engagement explicitly prohibit DoS, so this action falls squarely within the restriction, unlike enumeration or injection testing which do not deny availability.

Why this answer

Using a tool to send thousands of requests to overwhelm the server is a denial-of-service (DoS) attack, which is explicitly prohibited by the rules of engagement. This action aims to exhaust server resources, causing service unavailability.

Exam trap

CAS-005 often tests the interpretation of rules of engagement, and candidates may confuse other malicious actions (like SQL injection) with DoS, failing to recognize that DoS specifically targets availability.

How to eliminate wrong answers

Option A is wrong because SQL injection that deletes a table is a data integrity attack, not a DoS, though it may cause disruption, it is not primarily about overwhelming the server. Option B is wrong because uploading a web shell is a remote code execution attack, not a DoS. Option D is wrong because directory brute-forcing is a reconnaissance or access attempt, not a DoS, though it generates traffic, it does not aim to overwhelm the server.

119
MCQeasy

A security analyst is performing incident response and needs to collect evidence from a live system. Which of the following should be collected first to preserve volatile data?

A.Memory (RAM)
B.Network connections
C.Hard drive contents
D.System logs
AnswerA

RAM is the most volatile evidence, lost on power-down or reboot, so it must be captured before disk, logs or network state. Collecting memory first preserves running processes, injected code and encryption keys that would otherwise be irretrievable, satisfying the order-of-volatility constraint.

Why this answer

Memory (RAM) is the most volatile evidence on a live system — it contains running processes, encryption keys, network connections, and uncommitted data that vanish the moment the system is powered off or rebooted. Collecting RAM first preserves this ephemeral state before it is lost. This follows the order of volatility principle in digital forensics.

Exam trap

CAS-005 often tests the order of volatility — candidates pick network connections or logs thinking they are 'more volatile' because they change frequently, but RAM is the most volatile and must be collected first.

How to eliminate wrong answers

Option B is wrong because network connections, while volatile, are partially captured in memory and can be re-collected via netstat or similar tools — they are less volatile than RAM contents. Option C is wrong because hard drive contents are non-volatile and persist across reboots, so they can be collected later without loss. Option D is wrong because system logs are typically written to disk (non-volatile) and may also exist in memory, but they are less volatile than raw RAM and can be collected after memory.

120
MCQhard

A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?

A.TTP-driven hunting by analyzing adversary behaviors mapped to the ATT&CK framework
B.Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
C.Automated hunting using SIEM correlation rules that trigger on known malicious file hashes
D.IoC-driven hunting using known indicators of compromise from open-source feeds
AnswerB

Hypothesis-driven hunting tests the specific process injection technique by examining memory and process activity for injected code, hollowed processes or anomalous API calls. This targeted approach suits an APT that evades signature-based defences, since it searches for behavioural evidence rather than known indicators.

Why this answer

Hypothesis-driven hunting is the most appropriate because the analyst has a specific, testable hypothesis: the attacker is using process injection, a known ATT&CK technique (T1055). This methodology involves proactively searching for evidence of that technique—such as anomalous memory allocations, thread execution, or API calls—rather than waiting for alerts. It directly addresses the scenario where signature-based defenses have failed, as it focuses on behavioral artifacts rather than static indicators.

Exam trap

CAS-005 often tests the distinction between reactive IoC/signature-based hunting and proactive hypothesis-driven hunting, tricking candidates into choosing familiar but ineffective methods like SIEM rules or IoC feeds when the scenario explicitly states evasion of traditional defenses.

How to eliminate wrong answers

Option A is wrong because TTP-driven hunting is broader and focuses on mapping adversary behaviors to multiple techniques, not a single hypothesized technique; it lacks the specificity of a hypothesis-driven approach. Option C is wrong because automated hunting with SIEM rules based on known malicious file hashes is essentially signature-based detection, which the scenario states has already been evaded. Option D is wrong because IoC-driven hunting relies on known indicators (e.g., IPs, domains, hashes) from feeds, which are reactive and easily bypassed by APTs, contrary to the proactive, technique-focused hunt needed here.

121
MCQhard

A security analyst is using a SOAR platform to automate response to phishing emails reported by users. The playbook should perform the following actions in order: (1) extract indicators from the email, (2) query threat intelligence feeds for reputation, (3) if malicious, block the sender's domain at the email gateway and delete the email from all user inboxes. Which type of playbook step is most appropriate for step 3?

A.Playbook trigger
B.Output step
C.Action step
D.Conditional step
AnswerC

Blocking the sender's domain at the gateway and deleting the email from all inboxes are automated response actions executed against infrastructure. An action step performs these containment tasks, satisfying the playbook requirement that step 3 remediate confirmed-malicious email rather than merely enrich or decide.

Why this answer

Step 3 involves performing concrete actions: blocking the sender's domain and deleting the email. In SOAR playbooks, these are action steps that execute response activities.

Exam trap

The trap is confusing conditional step with action step because step 3 is preceded by a condition ('if malicious'), but the step itself is the action taken, not the evaluation.

How to eliminate wrong answers

Option A (playbook trigger) is wrong because a trigger initiates the playbook, not an intermediate response action. Option B (output step) is wrong because output steps present results or notifications, not perform blocking or deletion. Option D (conditional step) is wrong because a conditional step evaluates logic (e.g., if malicious), but step 3 is the execution after the condition is met.

122
MCQhard

A security team is analyzing a suspicious binary using static analysis. They run the strings command and observe references to 'CreateRemoteThread' and 'WriteProcessMemory'. Which technique is the binary likely employing?

A.DLL sideloading
B.Reflective DLL loading
C.Process injection
D.API hooking
AnswerC

CreateRemoteThread and WriteProcessMemory are the canonical Windows API pair for injecting code into another process's address space. Their presence in the import table indicates the binary writes a payload into a remote process and starts it via a new thread, which is process injection.

Why this answer

The presence of 'CreateRemoteThread' and 'WriteProcessMemory' in the strings output strongly indicates process injection. These Windows API functions are commonly used together to inject code into another process: WriteProcessMemory writes the malicious code into the target process's memory, and CreateRemoteThread executes it.

Exam trap

CAS-005 often tests the identification of techniques based on API calls, and candidates may confuse process injection with DLL sideloading or reflective loading, especially if they are not familiar with the specific API combinations.

How to eliminate wrong answers

Option A is wrong because DLL sideloading involves placing a malicious DLL alongside a legitimate executable to be loaded, and it typically does not require CreateRemoteThread or WriteProcessMemory. Option B is wrong because reflective DLL loading is a technique where a DLL loads itself into memory without using the Windows loader, often using functions like VirtualAlloc and LoadLibrary, but not necessarily CreateRemoteThread and WriteProcessMemory. Option D is wrong because API hooking involves intercepting calls to functions, often using techniques like IAT hooking or inline hooking, and does not typically use CreateRemoteThread and WriteProcessMemory for the hooking itself.

123
MCQhard

A security operations center (SOC) analyst is investigating an alert indicating potential credential dumping on a Windows server. The analyst reviews the process execution logs and sees that a process named 'lsass.exe' was accessed by an unsigned binary. Which of the following techniques is the attacker MOST likely using?

A.LSASS memory dumping
B.Pass-the-hash
C.Kerberoasting
D.DCSync
AnswerA

LSASS (Local Security Authority Subsystem Service) stores credential material in memory, including password hashes and Kerberos tickets. Attackers often target lsass.exe to dump these credentials using tools like Mimikatz, ProcDump, or Task Manager. The scenario describes an unsigned binary accessing lsass.exe, which is a common indicator of credential dumping. This technique allows the attacker to obtain credentials for lateral movement and privilege escalation.

Why this answer

The scenario describes an unsigned binary accessing lsass.exe, which is a strong indicator of credential dumping. LSASS stores credentials in memory, and attackers use tools like Mimikatz to extract them. This allows the attacker to obtain password hashes or plaintext passwords for lateral movement.

The other techniques do not involve direct access to lsass.exe.

Exam trap

The trap here is assuming that any credential-related attack involves lsass.exe, but techniques like Kerberoasting and DCSync do not access lsass.exe directly.

124
MCQmedium

A security operations center (SOC) analyst receives an alert from the endpoint detection and response (EDR) platform indicating that a process on a finance workstation has made an outbound connection to a known command-and-control (C2) domain. The analyst wants to quickly determine the full scope of the incident, including other hosts that may have communicated with the same domain. Which of the following actions should the analyst take FIRST?

A.Run a full antivirus scan on the finance workstation to remove any malware.
B.Immediately isolate the finance workstation from the network using the EDR console.
C.Block the C2 domain at the perimeter firewall to prevent further communication.
D.Query the SIEM for all events matching the C2 domain and create a timeline of affected hosts.
AnswerD

Querying the SIEM for the C2 domain leverages centralized log aggregation to identify all hosts that communicated with the malicious domain, providing immediate scope. This is a core incident response step: containment and eradication depend on understanding the blast radius. The SIEM retains historical network and endpoint logs, enabling rapid correlation across the environment without disrupting systems.

Why this answer

In incident response, scoping the incident is critical before containment or remediation. Querying the SIEM for the C2 domain rapidly identifies all hosts that communicated with the malicious infrastructure, revealing the full extent of the compromise. This allows the analyst to prioritize containment efforts and avoid missing additional compromised systems.

Other actions like isolation or blocking are containment steps that should follow scoping.

Exam trap

The trap here is assuming that immediate containment (isolation or blocking) is always the first step, when in fact scoping the incident to understand its breadth must precede containment to avoid incomplete response.

125
Multi-Selecthard

A security analyst is investigating a suspected data exfiltration incident. The analyst has captured network traffic and wants to identify evidence of data being transferred over a covert channel. Which TWO of the following techniques would BEST help detect covert channels in the network traffic? (Choose two.)

Select 2 answers
A.Analyze DNS query patterns for unusually long or high-entropy subdomains.
B.Inspect ICMP packets for unusual payload sizes or patterns.
C.Scan internal hosts for open ports that could be used for data transfer.
D.Examine NetFlow records for spikes in outbound traffic volume during off-hours.
E.Monitor for large file transfers over HTTP/HTTPS to known cloud storage services.
AnswersA, B

DNS tunneling often encodes data in subdomains, resulting in long, high-entropy labels. Analyzing DNS query patterns for these anomalies can reveal covert channels that bypass traditional perimeter controls. This technique is effective because DNS is frequently allowed outbound, and attackers abuse it to exfiltrate data or maintain C2. Monitoring for statistical anomalies in DNS queries is a key detection method.

Why this answer

Covert channels often hide data within protocols that are typically allowed through firewalls, such as DNS and ICMP. Analyzing DNS for long, high-entropy subdomains can reveal DNS tunneling, while inspecting ICMP payloads for anomalies can detect ICMP tunneling. Both techniques focus on the content and patterns within these protocols, which is essential for identifying stealthy exfiltration.

Exam trap

The trap here is focusing on volume-based anomalies or open ports, which may indicate exfiltration but fail to detect covert channels that hide within allowed protocols using encoding or tunneling.

126
MCQeasy

A security administrator is implementing a new policy that requires all employees to use multi-factor authentication (MFA) for accessing cloud applications. The administrator wants to choose an MFA method that is resistant to phishing attacks. Which of the following MFA methods should the administrator select?

A.FIDO2 security keys
B.Push notifications with number matching
C.Time-based one-time passwords (TOTP) generated by an authenticator app
D.SMS-based one-time codes
AnswerA

FIDO2 security keys use public-key cryptography and are bound to the origin, making them highly resistant to phishing. The authentication is scoped to the legitimate website, so even if a user is tricked into visiting a phishing site, the key will not release credentials. This is the strongest phishing-resistant MFA method among the options.

Why this answer

FIDO2 security keys are phishing-resistant because they use public-key cryptography and the authentication is bound to the specific origin. Even if a user is directed to a phishing site, the key will not authenticate to the fraudulent domain. Other methods like SMS, push notifications, and TOTP are vulnerable to real-time phishing or interception, so FIDO2 is the most secure choice for this requirement.

Exam trap

The trap here is assuming that any MFA method is phishing-resistant, but only those based on FIDO2/WebAuthn provide origin-bound credentials that cannot be replayed on a phishing site.

127
MCQmedium

During a security incident, a SOC analyst identifies a process with a suspicious hash on several endpoints. The analyst wants to determine if this hash is known to be malicious by querying internal and external threat intelligence sources. Which standard should the analyst use to structure the threat intelligence data for automated sharing?

A.TAXII
B.STIX
C.OpenIOC
D.CybOX
AnswerB

STIX provides a structured, machine-readable schema for expressing indicators, malware and relationships, enabling automated exchange between platforms via TAXII. It satisfies the requirement to structure threat intelligence for automated sharing, unlike prose formats or vulnerability scoring systems.

Why this answer

STIX (Structured Threat Information eXpression) is the OASIS standard that defines the structured language and data model for representing cyber threat intelligence — indicators, malware, attack patterns, and their relationships — in a machine-readable JSON format. When an analyst needs to structure threat intelligence data (such as a suspicious file hash) for automated sharing, STIX is the correct standard because it defines the content schema itself. TAXII is the transport protocol that carries STIX, not the structuring standard.

Exam trap

The trap is the classic STIX-vs-TAXII confusion: candidates see 'automated sharing' and pick TAXII, but the question asks which standard structures the data — that is STIX; TAXII only transports it.

How to eliminate wrong answers

Option A is wrong because TAXII (Trusted Automated eXchange of Indicator Information) is the transport/exchange protocol for moving threat intelligence between systems, not the data structuring standard — it defines how to send data, not how to format it. Option C is wrong because OpenIOC is a legacy Mandiant (FireEye) indicator format that predates STIX and is largely deprecated; it is not the current standard for automated sharing. Option D is wrong because CybOX (Cyber Observable eXpression) was a separate OASIS standard for representing cyber observables, but its functionality was merged into STIX 2.x, so CybOX is no longer the standalone standard to use for structuring threat intelligence.

128
MCQmedium

A security operations center (SOC) analyst is investigating a potential security incident. The analyst needs to determine the order of events on a compromised Windows host. The analyst has access to the following artifacts: a memory dump, the Windows Event Log, and the file system metadata. Which of the following provides the most reliable timeline of user and system activity?

A.A combination of all three artifacts correlated together.
B.The memory dump, because it contains running processes and network connections at the time of capture.
C.The Windows Event Log, because it records all system and application events with timestamps.
D.The file system metadata, because it includes timestamps for file creation, modification, and access.
AnswerA

Correlating multiple artifacts provides the most reliable timeline. The Windows Event Log gives system and security events, file system metadata shows file operations, and memory dump reveals running processes and network state. Together, they compensate for individual limitations and provide a more complete picture. This approach is standard in digital forensics to establish an accurate sequence of events.

Why this answer

The most reliable timeline is obtained by correlating the Windows Event Log, file system metadata, and memory dump. Each source has unique data and limitations; combining them allows the analyst to cross-validate timestamps and activities. For example, a process execution in the event log can be linked to a file creation in metadata and a network connection in memory.

This multi-source correlation is essential for accurate incident reconstruction.

Exam trap

The trap here is assuming any single artifact provides a complete and tamper-proof timeline, when in fact each has gaps and can be manipulated.

129
MCQeasy

A security analyst is reviewing a SIEM alert that indicates a user's credentials were used to log in from two different countries within a span of 10 minutes. This is likely an indicator of what type of attack?

A.Brute-force attack
B.Man-in-the-middle attack
C.Credential theft and reuse
D.Pass-the-hash attack
AnswerC

Impossible travel detects the same credentials authenticating from geographically distant locations within a timeframe too short for physical transit. The 10-minute, two-country constraint makes concurrent credential theft and reuse the mechanism, since one user cannot be in both places.

Why this answer

A single user account authenticating from two geographically distant countries within 10 minutes is physically impossible for one person to do via normal travel, which strongly indicates the credentials have been stolen and are being reused by an attacker from a different location. This is the classic 'impossible travel' indicator of credential theft and reuse. The legitimate user and the attacker are using the same credentials from different locations, producing the anomalous login pattern.

Exam trap

The trap is focusing on the authentication mechanism (pass-the-hash, brute-force) rather than the behavioral signal (impossible travel); candidates who overthink the technical attack vector miss that two successful logins from distant countries in minutes is the textbook credential-theft-and-reuse indicator.

How to eliminate wrong answers

Option A is wrong because a brute-force attack involves many failed authentication attempts against an account, not two successful logins from different countries; the alert shows successful credential use, not repeated failures. Option B is wrong because a man-in-the-middle attack intercepts or alters traffic between two parties, which would not by itself produce two successful logins from different geographic locations. Option D is wrong because a pass-the-hash attack uses a captured NTLM hash to authenticate without the plaintext password, typically within the same network or domain, and does not inherently produce geographically dispersed logins — the question's key signal is location and timing, not the authentication mechanism.

130
MCQmedium

A vulnerability has a CVSS base score of 9.8. The vulnerability is present on a server that is not exposed to the internet but is accessible to internal users with valid credentials. Which CVSS metric should be adjusted to reflect the reduced risk?

A.None, the base score should be used as-is
B.Temporal score
C.Environmental score
D.Base score
AnswerC

The Environmental score adjusts the base metrics to reflect the assessed organisation's actual context, including mitigations and asset exposure. Since the server is internal-only and requires valid credentials, that reduced exploitability is captured here, not in the Temporal score, which covers exploit maturity and remediation level.

Why this answer

The Environmental Score allows customization based on specific organizational context, such as modified access requirements.

131
Multi-Selectmedium

A SOC team is implementing a SOAR playbook to automate the response to phishing emails reported by users. The playbook should perform initial triage and, if the email is determined to be malicious, take containment actions. Which TWO of the following actions should be included in the playbook? (Choose TWO.)

Select 2 answers
A.Send an alert to the user's manager for approval
B.Automatically create a ticket in the service desk system
C.Automatically block the sender's email address in the email gateway
D.Initiate a full antivirus scan on the user's workstation
E.Extract embedded URLs and file hashes for threat intelligence lookup
AnswersC, E

Blocking the sender's address at the gateway contains the campaign, preventing further delivery from that source to any recipient. This satisfies the playbook's containment requirement once triage confirms the email is malicious, limiting spread without manual intervention.

Why this answer

Option E is correct because extracting embedded URLs and file hashes is a core initial triage step in a phishing SOAR playbook — these indicators are submitted to threat intelligence platforms (e.g., VirusTotal, MISP) to determine whether the email is malicious before any containment action is taken. Option C is correct because, once the email is confirmed malicious, blocking the sender's address at the email gateway is a standard, low-risk containment action that prevents further messages from that sender reaching other users. Option A is not appropriate because requiring manager approval introduces a manual delay that defeats the purpose of an automated SOAR playbook and is not a triage or containment action.

Option B is not a triage or containment action; ticketing is a documentation/notification step, not part of the initial decision or containment logic. Option D is not indicated here because a full antivirus scan on the workstation is a host-level remediation action that is not triggered by email triage alone and would typically follow only if the user executed an attachment or payload.

Exam trap

The trap is selecting administrative or heavy remediation actions (ticket creation, manager approval, full AV scan) instead of the core triage and containment actions (IOC extraction and sender blocking); candidates must distinguish between 'nice to have' workflow steps and the essential automated triage/containment actions the question asks for.

132
Multi-Selectmedium

A security analyst is investigating a potential data exfiltration incident. The analyst needs to preserve evidence for legal proceedings. Which two actions must the analyst take to maintain the chain of custody? (Select TWO).

Select 2 answers
A.Encrypt the evidence with a personal key
B.Share the evidence with all team members for analysis
C.Document every person who accesses the evidence and the time of access
D.Run antivirus scans on the evidence to ensure it is safe
E.Create a forensic image of the hard drive using a write-blocker
AnswersC, E

A documented access log records every individual who handles the evidence and when, forming the unbroken accountability trail that chain of custody demands for legal admissibility. Without this audit record, opposing counsel can challenge evidence integrity, so it directly satisfies the stem's legal-preservation constraint.

Why this answer

Option C is correct because chain of custody requires an unbroken, auditable record documenting every individual who handles or accesses the evidence, along with the date and time of each access, which is essential for the evidence to be admissible in legal proceedings. Option E is correct because creating a forensic image of the hard drive using a write-blocker preserves the original evidence in an unaltered state while allowing analysis to be performed on the copy; the write-blocker prevents any modification to the source drive, maintaining its integrity. Option A is incorrect because encrypting evidence with a personal key could render it inaccessible to investigators or the court and does not support an auditable custody record.

Option B is incorrect because indiscriminately sharing evidence with all team members breaks the controlled, documented access that chain of custody demands. Option D is incorrect because running antivirus scans can modify files or metadata on the evidence, potentially altering or destroying forensic artifacts.

Exam trap

CAS-005 often tests the misconception that antivirus scanning or encryption is part of evidence preservation; in reality, these actions can alter or restrict access to evidence, breaking the chain of custody.

133
Multi-Selecthard

During a penetration test, the tester has gained initial access to a web server and wants to perform lateral movement to reach a database server. The tester enumerates the network and finds that the web server has two network interfaces: one connected to a DMZ and one to an internal network. The database server is on the internal network. Which TWO techniques could the tester use to pivot from the web server to the database server? (Choose TWO.)

Select 2 answers
A.Use SSH tunneling to create a local forward to the database server's port
B.Perform a SQL injection attack against the database server
C.Deploy a reverse shell from the web server to the tester's machine
D.Install a keylogger on the web server to capture database credentials
E.Use Metasploit's route add command to add a route to the internal subnet through the web server
AnswersA, E

SSH local port forwarding binds a listener on the tester's host that relays traffic through the compromised dual-homed web server to the database server's internal port, exploiting the web server's DMZ and internal interfaces to cross the network boundary.

Why this answer

Option A is correct because SSH local port forwarding (ssh -L) lets the tester tunnel traffic from their machine through the compromised web server to reach the database server's port on the internal network, effectively pivoting across the dual-homed host. Option E is correct because Metasploit's 'route add' command (e.g., route add <internal_subnet> <session_id>) configures the framework to route traffic for the internal subnet through the existing Meterpreter session on the web server, enabling pivoting to the database server. Option B is incorrect because SQL injection targets a database through a vulnerable web application and does not provide network-level pivoting from the web server to the internal database server.

Option C is incorrect because a reverse shell only establishes command-and-control back to the tester's machine; it does not route traffic into the internal network. Option D is incorrect because a keylogger passively captures credentials on the web server and does not create a pivot path to the database server.

134
Multi-Selecthard

A security analyst is investigating a suspected data exfiltration incident. The analyst has captured full packet data from the network tap and wants to identify the exfiltration channel. Which TWO of the following techniques would be most effective for analyzing the captured traffic to detect covert exfiltration? (Choose two.)

Select 2 answers
A.Inspect HTTP User-Agent strings for outdated browser versions
B.Analyze DNS query lengths and entropy for signs of DNS tunneling
C.Review SMTP traffic for email attachments with double extensions
D.Check for ARP spoofing by comparing MAC addresses to a baseline
E.Reassemble TCP sessions and examine payload sizes and timing for beaconing
AnswersB, E

DNS tunneling often encodes data in subdomains of DNS queries, resulting in unusually long or high-entropy domain names. By analyzing query lengths and entropy, the analyst can identify anomalous DNS traffic that may indicate exfiltration. This technique is effective because DNS is commonly allowed through firewalls and can be used as a covert channel.

Why this answer

Analyzing DNS query lengths and entropy can reveal DNS tunneling, a common exfiltration method. Reassembling TCP sessions to examine payload sizes and timing helps detect beaconing and automated data transfers. Both techniques directly analyze the captured traffic for anomalies indicative of covert exfiltration, making them the most effective choices.

Exam trap

The trap here is selecting techniques that focus on malware delivery or network attacks rather than the actual exfiltration channel, such as checking User-Agent strings or ARP spoofing.

135
MCQhard

A security analyst is investigating a potential data exfiltration incident. The analyst observes a large outbound transfer of encrypted traffic to an unfamiliar IP address over port 443. The organization uses a next-generation firewall (NGFW) with TLS inspection enabled. Which of the following actions would BEST determine if the traffic is malicious?

A.Check the endpoint detection and response (EDR) logs for process execution on the source host.
B.Decrypt the TLS traffic using the NGFW and inspect the payload for sensitive data patterns.
C.Analyze NetFlow records to identify the volume and frequency of the transfer.
D.Perform a WHOIS lookup on the destination IP address to determine its reputation.
AnswerB

With TLS inspection enabled, the NGFW can decrypt and inspect the traffic. Examining the payload for sensitive data patterns (e.g., PII, credit card numbers) directly determines if exfiltration occurred. This is the most effective method because it analyzes content, not just metadata, and can confirm malicious intent.

Why this answer

The most definitive way to determine if the encrypted traffic is malicious is to inspect its decrypted payload for sensitive data. The NGFW with TLS inspection can perform this decryption and content analysis. Other methods provide context or metadata but cannot confirm the actual data being exfiltrated.

Exam trap

The trap here is relying on metadata like NetFlow or WHOIS when the question asks to determine if the traffic is malicious, which requires content inspection.

136
Multi-Selecthard

A security analyst is investigating a potential advanced persistent threat (APT) that has been evading traditional detection. The analyst decides to use User and Entity Behavior Analytics (UEBA) to identify anomalous activity. Which TWO of the following activities would be most indicative of a potential compromise when analyzed through UEBA? (Choose TWO.)

Select 2 answers
A.A service account authenticating to a database server every 5 minutes
B.A user logging in from a remote location at 3:00 AM, which is outside their normal working hours
C.A user accessing a large number of files on a file server that they do not normally access
D.A user connecting to the corporate VPN from a hotel during a business trip
E.An administrator running a scheduled antivirus scan on a server
AnswersB, C

UEBA baselines each user's normal login patterns, so a 3:00 AM session from an unusual remote location deviates sharply on time and geolocation axes. That behavioural anomaly indicates possible credential compromise, unlike routine activity matching established patterns.

Why this answer

Option B is correct because UEBA baselines each user's normal login behavior, so a login from a remote location at 3:00 AM deviates from that user's established time-of-day and geographic pattern, which is a classic anomaly indicating possible credential compromise or unauthorized access. Option C is correct because UEBA tracks entity-to-resource relationships, and a user suddenly accessing a large volume of files they do not normally touch signals abnormal data access consistent with reconnaissance or exfiltration by an APT. Option A is not indicative because a service account authenticating to a database every 5 minutes is a predictable, recurring pattern that UEBA would learn as normal baseline behavior.

Option D is not indicative because connecting to the corporate VPN from a hotel during a business trip is consistent with legitimate, expected remote-work behavior. Option E is not indicative because a scheduled antivirus scan run by an administrator is a routine, authorized administrative task that matches normal baseline activity.

137
Multi-Selecthard

A senior security architect is designing a detection strategy for advanced persistent threats (APTs) that employ living-off-the-land (LotL) techniques. Which THREE of the following approaches are most effective for detecting LotL activities? (Choose three.)

Select 3 answers
A.User and Entity Behavior Analytics (UEBA)
B.Deploying honeytokens and honeypots
C.Signature-based detection on malicious file hashes
D.Monitoring for native tool usage with EDR and logging command-line arguments
E.Blocking all scripts and macros by default
AnswersA, B, D

LotL attacks abuse legitimate native tools, so signature and IOC matching fail. UEBA establishes behavioural baselines and flags deviations such as unusual tool invocation, odd hours or atypical data access, detecting misuse of trusted binaries without relying on known malware indicators.

Why this answer

Option A (UEBA) is correct because LotL attacks abuse legitimate credentials and tools, so baselining normal user and entity behavior and flagging anomalies (e.g., unusual process lineage, off-hours privileged activity) is one of the few ways to surface attacker activity that leaves no malicious binary. Option B (honeytokens and honeypots) is correct because decoy credentials, files, and hosts have no legitimate use, so any interaction with them is high-fidelity evidence of an intruder performing reconnaissance or lateral movement with native tooling. Option D (monitoring native tool usage with EDR and command-line argument logging) is correct because LotL techniques rely on built-in binaries such as PowerShell, WMI, certutil, and rundll32, and capturing process creation with full command lines (e.g., via Sysmon Event ID 1 or EDR telemetry) exposes suspicious invocations like encoded PowerShell or certutil -urlcache.

Option C is not correct because signature-based detection on known malicious file hashes cannot detect LotL activity, which by definition uses already-installed, signed, legitimate system binaries that have no malicious hash. Option E is not correct because blanket blocking of all scripts and macros is a preventive hardening control, not a detection approach, and it is impractical and would not identify an adversary already operating with native tools.

Exam trap

CAS-005 often tests the misconception that signature-based detection is effective against LotL, when in fact LotL uses legitimate binaries that evade hash-based detection.

138
MCQeasy

A security administrator is configuring a new wireless network for a corporate office. The network must support the latest security standard that provides robust encryption and protection against offline dictionary attacks. Which of the following should the administrator implement?

A.WPA3-Personal with SAE
B.WPA2-Enterprise with PEAP-MSCHAPv2
C.WEP with 128-bit key
D.WPA2-Personal with AES-CCMP
AnswerA

WPA3-Personal with Simultaneous Authentication of Equals (SAE) replaces the pre-shared key handshake with a secure password-authenticated key exchange, which resists offline dictionary attacks. It is the latest Wi-Fi security standard and provides forward secrecy. This meets the requirement for robust encryption and protection against offline attacks.

Why this answer

WPA3-Personal with SAE is the correct choice because it introduces a secure handshake that prevents offline dictionary attacks and provides forward secrecy. WPA2-Personal is vulnerable to offline attacks, WPA2-Enterprise with PEAP-MSCHAPv2 lacks the latest protections, and WEP is obsolete and insecure.

Exam trap

The trap here is assuming that WPA2-Enterprise is automatically more secure than WPA3-Personal, overlooking that WPA3-Personal includes SAE which specifically mitigates offline dictionary attacks.

139
Multi-Selecteasy

A security team is evaluating endpoint detection and response (EDR) solutions. They want a solution that can detect fileless malware and malicious PowerShell scripts. Which TWO capabilities should the team prioritize? (Choose TWO.)

Select 2 answers
A.Signature-based detection of known malware
B.Network traffic analysis for C2 communication
C.Behavioral monitoring of script execution (e.g., PowerShell)
D.Automated firewall rule creation
E.Memory scanning capabilities
AnswersC, E

Fileless malware and malicious PowerShell leave no executable on disk, so behavioural monitoring of script execution detects suspicious command patterns, encoded payloads and anomalous process behaviour in memory. This satisfies the stem's requirement to catch threats that evade signature-based file scanning.

Why this answer

Option C is correct because behavioral monitoring of script execution detects malicious PowerShell activity by analyzing command-line arguments, script block logging (Event ID 4104), and suspicious behaviors like encoded commands or download cradles, which is essential for catching script-based attacks that evade static signatures. Option E is correct because fileless malware resides in memory (e.g., injected into processes like powershell.exe or wmic.exe) rather than on disk, so memory scanning is required to detect these in-memory artifacts, reflective DLL injections, and shellcode that leave no file footprint. Option A is not the priority because signature-based detection relies on known file hashes and patterns, which fileless and obfuscated PowerShell threats typically avoid.

Option B, while useful for identifying command-and-control traffic, addresses network-level detection rather than the endpoint fileless/script execution behaviors the team specifically wants. Option D is unrelated to detection, as automated firewall rule creation is a response/containment action, not a detection capability for fileless malware or malicious scripts.

Exam trap

CAS-005 often tests the distinction between detection capabilities and response actions, so the trap is selecting network analysis or firewall automation when the question specifically asks about detecting fileless and script-based threats.

140
Multi-Selecthard

A security analyst is investigating a security incident and needs to collect volatile evidence from a compromised Windows system. The analyst must preserve the evidence in a forensically sound manner. Which TWO of the following actions should the analyst take to ensure the integrity of the volatile data? (Choose two.)

Select 2 answers
A.Document the system time and date
B.Defragment the hard drive
C.Run a full antivirus scan
D.Capture a memory dump using a tool like WinPmem
E.Shut down the system to preserve the state
AnswersA, D

Recording the system time and date is essential for establishing a timeline and correlating events across logs. Time discrepancies can affect the interpretation of evidence, so documenting the current system time (including timezone) before any changes is a fundamental forensic step. This helps maintain the integrity and context of the volatile data collected, ensuring that timestamps in memory or logs are accurately mapped.

Why this answer

To preserve volatile evidence, the analyst must capture memory contents and document the system time. Memory dumps capture running processes and network connections, which are lost on shutdown. Documenting system time ensures accurate timeline correlation.

Actions like antivirus scans, shutdown, and defragmentation modify the system and destroy evidence, so they should be avoided. Thus, the correct actions are memory capture and time documentation.

Exam trap

The trap here is assuming that shutting down the system preserves evidence, when it actually destroys volatile data like RAM.

141
MCQeasy

A security analyst is collecting evidence from a compromised workstation. Which of the following should be collected first to preserve volatile data?

A.Memory dump
B.Hard drive image
C.Network capture
D.Event logs
AnswerA

A memory dump captures RAM contents, which are lost when the workstation powers off, making it the most volatile evidence. Collecting it first satisfies the stem's requirement to preserve volatile data before disk, logs or other less perishable sources.

Why this answer

Volatile data such as memory contents, running processes, network connections, and encryption keys are lost when the system is powered off or rebooted. A memory dump must be collected first to preserve this evidence. Hard drive images, network captures, and event logs are either non-volatile or can be collected later without the same urgency.

Exam trap

CAS-005 often tests the misconception that hard drive images should be collected first, when in fact volatile memory must be preserved before any non-volatile data.

How to eliminate wrong answers

Option B is wrong because a hard drive image is non-volatile and can be collected after memory, though it should still be done before powering off if possible. Option C is wrong because network capture is not stored on the workstation and can be collected from network devices, though it is time-sensitive. Option D is wrong because event logs are stored on disk and are non-volatile, so they can be collected after memory.

142
MCQmedium

An organization wants to detect and respond to advanced threats that may evade traditional endpoint security solutions. They deploy an EDR solution that provides real-time visibility into endpoint activities. However, the security team is overwhelmed by alerts. Which technology can be integrated with EDR to automate response actions and reduce alert fatigue?

A.SIEM with correlation rules
B.Network traffic analysis (NTA)
C.Deception technology
D.SOAR platform
AnswerD

A SOAR platform ingests EDR alerts and executes automated playbooks, enriching, correlating and remediating them without analyst intervention. This directly addresses the stated constraint of alert fatigue by reducing the volume requiring manual triage, while preserving the real-time endpoint visibility EDR already provides.

Why this answer

A SOAR (Security Orchestration, Automation, and Response) platform integrates with EDR and other security tools to automate response actions such as isolating endpoints, blocking IPs, and enriching alerts, which directly reduces alert fatigue by handling repetitive triage tasks. SOAR playbooks codify response procedures and can execute them at machine speed, freeing analysts for higher-value work.

Exam trap

CAS-005 often tests the distinction between detection, orchestration, and response — the trap is choosing SIEM because it is familiar, when the question specifically asks for automation of response actions to reduce alert fatigue.

How to eliminate wrong answers

Option A is wrong because a SIEM with correlation rules aggregates and correlates logs to improve detection, but it does not automate response actions — it still generates alerts that require human triage, so alert fatigue persists. Option B is wrong because network traffic analysis provides additional visibility into network-level threats but does not automate endpoint response or reduce the volume of EDR alerts. Option C is wrong because deception technology uses decoys and honeypots to detect attackers who have bypassed perimeter defenses; it is a detection capability, not an automation or response orchestration layer.

143
MCQmedium

A penetration tester is in the post-exploitation phase and wants to maintain access to a compromised system. Which of the following techniques is most effective for establishing persistent access while evading detection?

A.Uploading a web shell to a publicly accessible directory
B.Creating a new local user account with administrative privileges
C.Installing a rogue certificate authority
D.Creating a scheduled task that executes a reverse shell
AnswerD

A scheduled task runs the reverse shell at defined intervals or logon, surviving reboots without a persistent service or startup folder entry. This satisfies maintaining access while blending into legitimate Windows Task Scheduler activity, evading detection better than always-on listeners or new local accounts.

Why this answer

A scheduled task (cron on Linux, Task Scheduler on Windows) that periodically launches a reverse shell is a classic persistence mechanism that blends into normal system activity, survives reboots, and is harder to detect than a static web shell or a new admin account. It provides recurring, stealthy access without leaving obvious artifacts like a listening service or a conspicuous privileged account.

Exam trap

The trap is equating 'persistence' with 'access' — CAS-005 candidates pick web shells or admin accounts because they grant access, but those are noisy and easily detected, whereas the question emphasizes evading detection, which favors scheduled tasks.

How to eliminate wrong answers

Option A is wrong because a web shell in a public directory is easily discovered by file integrity monitoring, web scanners, and defenders reviewing web roots, and it depends on the web service staying exposed. Option B is wrong because creating a new local admin account is highly visible in account audits, EDR, and SIEM alerts, and is a well-known IOC. Option C is wrong because installing a rogue CA is a man-in-the-middle/trust-abuse technique for intercepting traffic, not a persistence mechanism for maintaining interactive access to a single host.

144
MCQmedium

A security analyst is monitoring network traffic and observes a high volume of DNS queries for randomly generated domain names that return NXDOMAIN responses. The queries originate from a single workstation and occur at regular intervals. Which of the following is the MOST likely explanation for this activity?

A.DNS tunneling for data exfiltration
B.A domain generation algorithm (DGA) used by malware for command and control
C.A network scan using DNS enumeration techniques
D.A misconfigured DNS server causing excessive recursive lookups
AnswerB

A DGA is a technique used by malware to generate a large number of pseudo-random domain names to avoid detection and disruption of command-and-control (C2) servers. The malware attempts to resolve these domains until one resolves to an active C2 server. The high volume of NXDOMAIN responses and regular intervals are characteristic of DGA activity, as the malware periodically tries to contact its C2 infrastructure.

Why this answer

The scenario describes a workstation making repeated DNS queries for random domain names that do not resolve. This behavior is a hallmark of a domain generation algorithm (DGA) used by malware to locate its command-and-control server. DGAs generate many domain names, and the malware attempts to resolve them until one succeeds.

The regular intervals and NXDOMAIN responses are typical of this technique.

Exam trap

The trap here is confusing DGA activity with DNS tunneling, as both involve DNS but have different traffic patterns and purposes.

145
Multi-Selectmedium

A SOC analyst is investigating a potential data exfiltration incident. The analyst suspects that an insider is using encrypted tunnels to transfer data. Which TWO of the following network traffic analysis (NTA) indicators are most likely to suggest encrypted exfiltration? (Choose two.)

Select 2 answers
A.Large data transfers to an external IP address during non-business hours
B.Multiple HTTP GET requests to a known content delivery network
C.A single large file upload to a cloud storage provider during work hours
D.Repeated connections to an external host on a non-standard port using TLS
E.High volumes of DNS queries to a single external domain
AnswersA, D

Volume and timing are the discriminators: bulk transfers to an external address outside business hours deviate from the insider's normal baseline. Encryption hides payload content, so NTA must rely on flow metadata such as byte counts and temporal patterns to flag exfiltration.

Why this answer

Option A is correct because large outbound data transfers to an external IP address outside normal business hours are a classic NTA indicator of exfiltration, as insiders often schedule bulk transfers when monitoring and user activity are lower. Option D is correct because repeated TLS connections to an external host on a non-standard port strongly suggest an encrypted tunnel or covert channel, since TLS hides payload contents and the non-standard port deviates from normal HTTPS/443 behavior. Option B is not correct because multiple HTTP GET requests to a known CDN are typically normal web browsing or content retrieval and do not indicate large-scale encrypted exfiltration.

Option C is not correct because a single large upload to a cloud storage provider during work hours may be legitimate business activity and lacks the suspicious timing or tunneling characteristics of insider exfiltration. Option E is not correct because high DNS query volume to one domain more likely indicates DNS tunneling or beaconing, but the question specifically asks for indicators of encrypted exfiltration tunnels rather than DNS-based covert channels.

Exam trap

CAS-005 often tests the misconception that any large upload is exfiltration, when in fact context such as timing, destination, and port usage is critical to distinguish malicious from legitimate activity.

146
MCQmedium

A security operations center (SOC) is evaluating a new endpoint detection and response (EDR) tool. The tool reports a suspicious process that is making outbound network connections to a known command-and-control (C2) server. The SOC analyst wants to confirm the process is malicious by examining the process's parent-child relationships and command-line arguments. Which of the following should the analyst use to BEST achieve this?

A.Endpoint process monitoring with Sysmon
B.Full packet capture
C.NetFlow analysis
D.Windows Event Log subscription for Security events
AnswerA

Sysmon, when configured with appropriate rules, logs process creation events including parent process ID, command-line arguments, and hashes. This data allows the analyst to trace the suspicious process's lineage and inspect its command line for malicious indicators. It directly answers the need to examine parent-child relationships and arguments, making it the best choice.

Why this answer

The analyst needs endpoint process context, specifically parent-child relationships and command-line arguments, to confirm malicious behavior. Sysmon provides detailed process creation events including parent process ID, command line, and hashes, enabling correlation of the suspicious process with its origin and intent. Network-based tools like NetFlow and packet capture lack endpoint process visibility, while standard Windows Security logs may not capture full command lines.

Sysmon is the appropriate tool for this level of endpoint telemetry.

Exam trap

The trap here is assuming that network flow data or packet captures can reveal endpoint process details, when they only show network-level information.

147
MCQmedium

During a penetration test, the tester has gained initial access to a network and now aims to move laterally to a sensitive database server. Which phase of the penetration testing lifecycle does this activity represent?

A.Exploitation
B.Post-exploitation
C.Reporting
D.Reconnaissance
AnswerB

Post-exploitation covers actions taken after initial access, including privilege escalation, credential harvesting and lateral movement toward higher-value targets such as the database server. The tester already holds a foothold, so this phase matches the described activity.

Why this answer

Post-exploitation is the phase after initial access where the tester maintains access, escalates privileges, moves laterally, and gathers additional data. Moving laterally to a sensitive database server after gaining initial access is a classic post-exploitation activity.

Exam trap

The trap is equating 'gaining access' with 'exploitation' — lateral movement after initial access is post-exploitation, not exploitation itself.

How to eliminate wrong answers

Option A is wrong because exploitation is the act of leveraging a vulnerability to gain initial access or execute code, not the subsequent lateral movement. Option C is wrong because reporting is the final phase where findings are documented and communicated, not an active attack phase. Option D is wrong because reconnaissance is the pre-attack phase of information gathering, which occurs before any access is obtained.

148
MCQmedium

A security analyst is conducting a threat hunt based on the hypothesis that an adversary may have used PowerShell to execute malicious scripts. Which threat hunting methodology is being employed?

A.IoC-driven hunting
B.TTP-driven hunting
C.Baseline-driven hunting
D.Hypothesis-driven hunting
AnswerD

The analyst starts from a stated proposition about adversary behaviour, then searches telemetry to confirm or refute it. That is hypothesis-driven hunting, distinct from intelligence-driven hunting (led by feeds) or baseline/anomaly approaches that flag deviations without a prior premise.

Why this answer

Hypothesis-driven hunting starts with a specific hypothesis, such as 'an adversary may have used PowerShell to execute malicious scripts,' and then tests that hypothesis through data analysis. This is exactly what the analyst is doing. TTP-driven hunting is broader and focuses on known adversary tactics, techniques, and procedures, while IoC-driven hunting uses specific indicators of compromise.

Exam trap

CAS-005 often tests the confusion between hypothesis-driven and TTP-driven hunting, where candidates incorrectly select TTP-driven when a specific hypothesis is being tested.

How to eliminate wrong answers

Option A is wrong because IoC-driven hunting relies on known indicators like file hashes or IP addresses, which are not mentioned here. Option B is wrong because TTP-driven hunting is based on known adversary TTPs, but the analyst is testing a specific hypothesis rather than generally hunting for TTPs. Option C is wrong because baseline-driven hunting looks for deviations from normal behavior, which is not the stated approach.

149
MCQmedium

A security operations team is implementing a new SIEM and wants to ensure that log sources are properly synchronized. The team notices that some events appear out of order in the SIEM interface. Which of the following is the most likely cause and the best solution?

A.The network latency between log sources and the SIEM is causing delays. Deploy log collectors closer to the sources.
B.The SIEM is not parsing timestamps correctly. Update the SIEM's log parsers to recognize the timestamp format.
C.The SIEM is using a different time zone than the log sources. Configure all log sources to use UTC.
D.The log sources are not synchronized with a common time source. Implement NTP on all log sources and the SIEM.
AnswerD

Out-of-order events in a SIEM are often caused by clock skew between log sources. If clocks are not synchronized, timestamps can be inaccurate, leading to events being sorted incorrectly. Implementing NTP ensures all systems have consistent time, which is critical for correlation. This is the most likely cause and the best solution to maintain event order.

Why this answer

The most likely cause of out-of-order events is clock skew due to unsynchronized clocks on log sources. Even small differences in system time can cause events to be sorted incorrectly. Implementing NTP on all log sources and the SIEM ensures a consistent time reference.

This is a fundamental requirement for accurate log correlation and timeline analysis. Other factors like time zone or parsing issues can also cause problems, but clock skew is the primary culprit for subtle ordering issues.

Exam trap

The trap here is blaming the SIEM's parsing or time zone settings when the underlying issue is often unsynchronized clocks on the sources.

150
MCQeasy

An organization deploys honeypots to detect attackers. Which type of deception technology is being used?

A.Honeytokens
B.Bait networks
C.Honeypots
D.Honeynets
AnswerC

Honeypots are decoy systems that deliberately expose fake vulnerabilities to lure attackers, logging their activity without risking real assets. This directly satisfies the stem's requirement for deception technology, since honeypots constitute the deception mechanism itself rather than a detection or prevention control layered alongside it.

Why this answer

Honeypots are decoy systems designed to lure attackers and detect unauthorized activity.

← PreviousPage 2 of 3 · 164 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Operations questions.