nerdexam
CompTIA

CAS-005 · Question #283

A technician is reviewing the logs and notices a large number of files were transferred to remote sites over the course of three months. This activity then stopped. The files were transferred via…

The correct answer is C. An advanced persistent threat. The scenario describes a prolonged, stealthy operation where files were exfiltrated over three months via secure channels (TLS-protected HTTP) from unexpected systems, then ceased. This aligns with an Advanced Persistent Threat (APT), characterized by long-term, targeted…

Submitted by jordan8· Mar 6, 2026Security Operations

Question

A technician is reviewing the logs and notices a large number of files were transferred to remote sites over the course of three months. This activity then stopped. The files were transferred via TLS-protected HTTP sessions from systems that do not normally send traffic to those sites. The technician will define this threat as:

Options

  • AA decrypting RSA using an obsolete and weakened encryption attack.
  • BA zero-day attack.
  • CAn advanced persistent threat.
  • DAn on-path attack.

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    25% (7)
  • C
    57% (16)
  • D
    11% (3)

Explanation

The scenario describes a prolonged, stealthy operation where files were exfiltrated over three months via secure channels (TLS-protected HTTP) from unexpected systems, then ceased. This aligns with an Advanced Persistent Threat (APT), characterized by long-term, targeted attacks aimed at data theft or surveillance, often using sophisticated methods to remain undetected.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice