nerdexam
CompTIA

CAS-005 · Question #23

A security analyst wants to use lessons learned from a prior incident response to reduce dwell time in the future. The analyst is using the following data points: Which of the following would the…

The correct answer is A. Adjusting the SIEM to alert on attempts to visit phishing sites. The data indicates that admin1 visited a suspicious domain (hacking.com), which triggered an alert. Adjusting the SIEM to alert on attempts to visit phishing sites would allow for faster identification of potentially malicious activity in the future. This approach directly…

Submitted by jakub_pl· Mar 6, 2026Security Operations

Question

A security analyst wants to use lessons learned from a prior incident response to reduce dwell time in the future. The analyst is using the following data points:

Which of the following would the analyst most likely recommend?

Exhibits

CAS-005 question #23 exhibit 1
CAS-005 question #23 exhibit 2

Options

  • AAdjusting the SIEM to alert on attempts to visit phishing sites
  • BAllowing TRACE method traffic to enable better log correlation
  • CEnabling alerting on all suspicious administrator behavior
  • Dutilizing allow lists on the WAF for all users using GFT methods

How the community answered

(54 responses)
  • A
    81% (44)
  • B
    6% (3)
  • C
    9% (5)
  • D
    4% (2)

Explanation

The data indicates that admin1 visited a suspicious domain (hacking.com), which triggered an alert. Adjusting the SIEM to alert on attempts to visit phishing sites would allow for faster identification of potentially malicious activity in the future. This approach directly addresses reducing dwell time by alerting on suspicious or malicious site visits, helping security teams to act

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice