nerdexam
CompTIA

CAS-005 · Question #345

A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbo

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #345. The question stem and answer options stay visible for context.

Submitted by hassan_iq· Mar 6, 2026Security Operations

Question

A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbound traffic from any infected machines. Which of the following is the most appropriate action for the systems administrator to take?

Options

  • AMonitor for IoCs associated with C&C communications.
  • BTune alerts to Identify changes to administrative groups.
  • CReview NetFlow logs for unexpected increases in egress traffic.
  • DPerform binary hash comparisons to identify infected devices.

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice