Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

CAS-004 Security Operations Practice Question

During a penetration test, the tester has gained initial access to a network and now aims to move laterally to a sensitive database server. Which phase of the penetration testing lifecycle does this activity represent?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Post-exploitation

Lateral movement occurs after initial access is gained, which is the defining characteristic of the post-exploitation phase. In the penetration testing lifecycle, post-exploitation encompasses activities such as lateral movement, privilege escalation, and data exfiltration, whereas exploitation focuses on gaining the initial foothold through vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Exploitation

    Why it's wrong here

    Exploitation is the phase where vulnerabilities are actively used to breach the system and gain initial access, not lateral movement after access is established.

  • Post-exploitation

    Why this is correct

    Post-exploitation is the correct phase, as it involves activities performed after initial access, including lateral movement to other systems and maintaining persistence.

  • Reporting

    Why it's wrong here

    Reporting is the final phase where findings are documented and presented; it does not include active network traversal.

  • Reconnaissance

    Why it's wrong here

    Reconnaissance is the information-gathering phase that occurs before any access is obtained; lateral movement is a post-access activity.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.