nerdexam
CompTIA

CAS-005 · Question #498

During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing: - Source of the malicious files - Initial attack v

The correct answer is D. Collecting operational system logs and storage disk data. Collecting operating system logs and storage disk data provides historical records of file creation, modifications, user activity, and system events. These artifacts are essential for reconstructing a detailed timeline of the attack, including the source of malicious files, initi

Submitted by viktor_hu· Mar 6, 2026Security Operations

Question

During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing:

  • Source of the malicious files
  • Initial attack vector
  • Lateral movement activities

The next step in the playbook is to reconstruct a timeline. Which of the following best supports this effort?

Options

  • AExecuting decompilation of binary files
  • BAnalyzing all network routes and connections
  • CPerforming primary memory analysis
  • DCollecting operational system logs and storage disk data

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    16% (3)
  • C
    5% (1)
  • D
    74% (14)

Explanation

Collecting operating system logs and storage disk data provides historical records of file creation, modifications, user activity, and system events. These artifacts are essential for reconstructing a detailed timeline of the attack, including the source of malicious files, initial entry, and lateral

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice