Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

During an incident response engagement, the security team identifies that a compromised host has been communicating with multiple external IP addresses using encrypted channels. The team needs to determine which processes initiated the connections. Which type of evidence collection should be performed first to preserve the most volatile data?

⚠ Common exam trap

CAS-005 often tests the order of volatility, and candidates frequently choose disk imaging or log export because they seem more permanent, forgetting that RAM is the most volatile and must be captured first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a memory capture using a tool like DumpIt or winpmem

Memory capture is the correct first step because running processes, active network connections, and encryption keys exist only in volatile memory (RAM) and are lost on shutdown or reboot. Tools like DumpIt or winpmem preserve this state, including the process-to-connection mapping needed to identify which process initiated the encrypted channels. The order of volatility in digital forensics dictates that RAM be collected before disk or logs, since it is the most transient evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Export the Windows event logs related to network activity

    Why it's wrong here

    Windows event logs are stored on disk, so they are less volatile than running process and connection state, and they may not map connections to processes. It is tempting because logs are easy to export, and this would be correct if the team needed historical authentication or system activity rather than live network state.

  • ✗

    Execute a network scan from the compromised host to identify active connections

    Why it's wrong here

    A network scan generates new traffic and overwrites the volatile connection state (ARP cache, TCP table) that must be captured first. Scanning suits active vulnerability discovery on a host you control, not preserving evidence of established encrypted sessions.

  • ✗

    Capture a full disk image using FTK Imager

    Why it's wrong here

    A full disk image captures non-volatile storage and misses running processes and active connections, which vanish on shutdown. It is tempting because imaging preserves everything for later analysis, and it would be correct once volatile data has been collected and the host can be taken offline.

  • ✓

    Perform a memory capture using a tool like DumpIt or winpmem

    Why this is correct

    RAM holds running processes, open sockets and encryption keys, and is lost on shutdown or reboot. Capturing memory first with DumpIt or winpmem preserves the process-to-connection mapping the team needs, satisfying the requirement to collect the most volatile evidence before disk artefacts.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.