nerdexam
CompTIA

CAS-005 · Question #166

A small number but steady series of attempts to breach the network has been occurring over a long period of time. During an investigation, a SOC analyst finds that traffic is exiting the network to kn

The correct answer is A. Supply chain. The presence of a rogue network device sending traffic to malicious hosts over a long period strongly indicates a supply chain attack, where a malicious component was introduced into the network.

Submitted by lucia.co· Mar 6, 2026Security Operations

Question

A small number but steady series of attempts to breach the network has been occurring over a long period of time. During an investigation, a SOC analyst finds that traffic is exiting the network to known malicious hosts and is originating from a rogue network device. Which of the following attack vectors is most likely being used to breach the network?

Options

  • ASupply chain
  • BBuffer overflow
  • CSocial engineering
  • DRansomware

How the community answered

(36 responses)
  • A
    78% (28)
  • B
    8% (3)
  • C
    11% (4)
  • D
    3% (1)

Why each option

The presence of a rogue network device sending traffic to malicious hosts over a long period strongly indicates a supply chain attack, where a malicious component was introduced into the network.

ASupply chainCorrect

A supply chain attack involves targeting an organization by compromising less secure elements in its supply chain, such as introducing a rogue device or backdoored software before it reaches the intended victim.

BBuffer overflow

A buffer overflow is a specific type of software vulnerability exploitation, not an attack vector involving rogue network devices and long-term exfiltration.

CSocial engineering

Social engineering typically targets individuals to gain access or information, and while it could lead to a device being installed, the description of 'rogue network device' and long-term, steady exfiltration points more to a pre-meditated insertion rather than just user manipulation.

DRansomware

Ransomware is a type of malware that encrypts data for a ransom, and while it could be delivered via various means, it does not directly describe the 'rogue network device' and 'traffic exiting to malicious hosts' scenario as the primary attack vector.

Concept tested: Supply chain attack characteristics

Source: https://learn.microsoft.com/en-us/azure/architecture/framework/security/design-supply-chain-security

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice