CompTIA
CAS-005 · Question #345
A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbo
Sign in or unlock CAS-005 to reveal the answer and full explanation for question #345. The question stem and answer options stay visible for context.
Submitted by hassan_iq· Mar 6, 2026Security Operations
Question
A systems administrator is working with the SOC to identify potential intrusions associated with ransomware. The SOC wants the systems administrator to perform network-level analysis to identify outbound traffic from any infected machines. Which of the following is the most appropriate action for the systems administrator to take?
Options
- AMonitor for IoCs associated with C&C communications.
- BTune alerts to Identify changes to administrative groups.
- CReview NetFlow logs for unexpected increases in egress traffic.
- DPerform binary hash comparisons to identify infected devices.
Unlock CAS-005 to see the answer
You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.