nerdexam
CompTIA

CAS-005 · Question #27

A company recently experienced an incident in which an advanced threat actor was able to shim malicious code against the hardware stack of a domain controller. The forensic team cryptographically vali

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #27. The question stem and answer options stay visible for context.

Submitted by manish99· Mar 6, 2026Security Engineering

Question

A company recently experienced an incident in which an advanced threat actor was able to shim malicious code against the hardware stack of a domain controller. The forensic team cryptographically validated that both the underlying firmware of the box and the operating system had not been compromised. However, the attacker was able to exfiltrate information from the server using a steganographic technique within LDAP. Which of the following is the best way to reduce the risk of reoccurrence?

Options

  • AEnforcing allow lists for authorized network pons and protocols
  • BMeasuring and attesting to the entire boot chain
  • CRolling the cryptographic keys used for hardware security modules
  • DUsing code signing to verify the source of OS updates

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice