nerdexam
CompTIA

CAS-005 · Question #209

After a cybersecurity incident, a security analyst was able to collect a binary that the attacker used on the compromised server. Then the analyst ran the following command: Which of the following opt

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #209. The question stem and answer options stay visible for context.

Submitted by andres_qro· Mar 6, 2026Security Operations

Question

After a cybersecurity incident, a security analyst was able to collect a binary that the attacker used on the compromised server. Then the analyst ran the following command:

Which of the following options describes what the analyst is trying to do?

Exhibits

CAS-005 question #209 exhibit 1
CAS-005 question #209 exhibit 2

Options

  • ATo reconstruct the timeline of commands executed by the binary
  • BTo extract IoCs from the binary used on the attack
  • CTo replicate the attack in a secure environment
  • DTo debug the binary to analyze low-level instructions

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice