CAS-004 Security Operations Practice Question
During a penetration test, the tester has gained initial access to a network and now aims to move laterally to a sensitive database server. Which phase of the penetration testing lifecycle does this activity represent?
⚠ Common exam trap
The trap is equating 'gaining access' with 'exploitation' — lateral movement after initial access is post-exploitation, not exploitation itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Post-exploitation
Post-exploitation is the phase after initial access where the tester maintains access, escalates privileges, moves laterally, and gathers additional data. Moving laterally to a sensitive database server after gaining initial access is a classic post-exploitation activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploitation
Why it's wrong here
Exploitation delivers the payload that leverages a vulnerability to gain the initial foothold, such as executing an exploit against a vulnerable service. Here access already exists; the tester is pivoting to other internal hosts, which is a distinct later phase. Exploitation would be correct if the tester were still obtaining that first access.
- ✓
Post-exploitation
Why this is correct
Post-exploitation covers actions taken after initial access, including privilege escalation, credential harvesting and lateral movement toward higher-value targets such as the database server. The tester already holds a foothold, so this phase matches the described activity.
- ✗
Reporting
Why it's wrong here
Reporting documents findings, evidence, risk ratings and remediation guidance after testing concludes. It involves no host-to-host pivoting, so it cannot describe lateral movement. Reporting would be the correct phase once the tester has finished moving through the environment and is compiling the final deliverable for stakeholders.
- ✗
Reconnaissance
Why it's wrong here
Reconnaissance gathers information about targets before any access is obtained, using techniques such as scanning and enumeration. Lateral movement occurs after initial access, so it belongs to a later phase. Reconnaissance would be the correct answer only when the tester is still profiling the environment without a foothold.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.