nerdexam
CompTIA

CAS-005 · Question #496

Protected company data was recently exfiltrated. The SOC did not find any indication of a network or outside physical intrusion, and the DLP systems reported no unusual activity. The incident response

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #496. The question stem and answer options stay visible for context.

Submitted by akirajp· Mar 6, 2026Security Operations

Question

Protected company data was recently exfiltrated. The SOC did not find any indication of a network or outside physical intrusion, and the DLP systems reported no unusual activity. The incident response team determined a text file was encrypted and reviews the following:

Which of the following is the most appropriate action for the team to take?

Exhibits

CAS-005 question #496 exhibit 1
CAS-005 question #496 exhibit 2

Options

  • AReview the email security settings for proper configurations.
  • BInvestigate whether the employee had access to the data that was leaked.
  • CScan attachments with a third-party virus scan to independently confirm the results.
  • DAnalyze the hardware for undetected supply chain vulnerabilities that may have been exploited.

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice