nerdexam
CompTIA

CAS-005 · Question #431

A security manager has written an incident response playbook for insider attacks and is ready to begin testing it. Which of the following should the manager conduct to test the playbook?

The correct answer is D. Threat emulation. Threat emulation (also known as adversary or red-team simulation) involves deliberately mimicking insider tactics, techniques, and procedures to validate the playbook’s controls and procedures in a controlled exercise. This approach directly tests whether the detection, containme

Submitted by paula_co· Mar 6, 2026Security Operations

Question

A security manager has written an incident response playbook for insider attacks and is ready to begin testing it. Which of the following should the manager conduct to test the playbook?

Options

  • AAutomated vulnerability scanning
  • BCentralized logging, data analytics, and visualization
  • CThreat hunting
  • DThreat emulation

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    12% (3)
  • D
    80% (20)

Explanation

Threat emulation (also known as adversary or red-team simulation) involves deliberately mimicking insider tactics, techniques, and procedures to validate the playbook’s controls and procedures in a controlled exercise. This approach directly tests whether the detection, containment, and response steps work as designed against realistic insider behaviors.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice