nerdexam
CompTIA

CAS-005 · Question #136

SIMULATION During the course of normal SOC operations, three anomalous events occurred and were flagged as potential IoCs. Evidence for each of these potential IoCs is provided. INSTRUCTIONS Review ea

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #136. The question stem and answer options stay visible for context.

Submitted by hans_de· Mar 6, 2026Security Operations

Question

SIMULATION During the course of normal SOC operations, three anomalous events occurred and were flagged as potential IoCs. Evidence for each of these potential IoCs is provided. INSTRUCTIONS Review each of the events and select the appropriate analysis and action options for each IoC. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Answer:

IoC 1 Indicators:

DNS queries for a suspicious subdomain (update.s.domain, *.s.domain) Responses include odd CNAME and A records Activity resembles contacting a malicious domain Correct Selections:

Analysis: The service is attempting to resolve a malicious domain Action: Implement a blocklist for known malicious ports IoC 2 Indicators:

ICMP Echo (ping) requests from 10.0.5.5 to multiple hosts All packets are dropped Suggests a device is probing the network Correct Selections:

Analysis: Someone is footprinting a network subnet Action: Block ping requests across the WAN interface IoC 3 Indicators:

BitTorrent traffic (/announce?info_hash, peer_id, application/x-bittorrent) Indicates P2P protocol activity Correct Selections:

Analysis: An employee is using P2P services to download files Action: Enforce endpoint controls on third-party software installations

Exhibits

CAS-005 question #136 exhibit 1
CAS-005 question #136 exhibit 2
CAS-005 question #136 exhibit 3
CAS-005 question #136 exhibit 4
CAS-005 question #136 exhibit 5
CAS-005 question #136 exhibit 6

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Incident Response#Threat Detection#Network Security#Security Controls
Full CAS-005 Practice