nerdexam
CompTIA

CAS-005 · Question #375

An analyst is working to address a potential compromise of a corporate endpoint and discovers the attacker accessed a user's credentials. However, it is unclear if the system baseline was modified…

The correct answer is B. Bit-level disk duplication. Bit-level disk duplication is the best option in this scenario for supporting forensic activities. It involves creating an exact, sector-by-sector copy of the hard drive, which allows forensic analysts to examine the entire disk, including deleted files, hidden data, or…

Submitted by skyler.x· Mar 6, 2026Security Operations

Question

An analyst is working to address a potential compromise of a corporate endpoint and discovers the attacker accessed a user's credentials. However, it is unclear if the system baseline was modified to achieve persistence. Which of the following would most likely support forensic activities in this scenario?

Options

  • ASide-channel analysis
  • BBit-level disk duplication
  • CSoftware composition analysis
  • DSCAP scanner

How the community answered

(47 responses)
  • A
    4% (2)
  • B
    70% (33)
  • C
    6% (3)
  • D
    19% (9)

Explanation

Bit-level disk duplication is the best option in this scenario for supporting forensic activities. It involves creating an exact, sector-by-sector copy of the hard drive, which allows forensic analysts to examine the entire disk, including deleted files, hidden data, or modifications that may have been made by the attacker to achieve persistence. This approach provides the most comprehensive data for investigating the potential compromise and determining if the system baseline was modified.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice