Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam CAS-005 Topic 1 Question 12 Discussion

Actual exam question for CompTIA's CAS-005 exam
Question #: 12
Topic #: 1
[All CAS-005 Questions]

An analyst reviews a SIEM and generates the following report:

Only HOST002 is authorized for internet traffic. Which of the following statements is accurate?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed

Understanding the Security Event:

HOST002 is the only device authorized for internet traffic. However, the SIEM logs show that VM002 is making network connections to web.corp.local.

This indicates unauthorized access, which could be a sign of lateral movement or network infection.

This is a red flag for potential malware, unauthorized software, or a compromised host.

Why Option D is Correct:

Unusual network traffic patterns are often an indicator of a compromised system.

VM002 should not be communicating externally, but it is.

This suggests a possible breach or malware infection attempting to communicate with a command-and-control (C2) server.

Why Other Options Are Incorrect:

A (Misconfiguration): While a misconfiguration could explain the unauthorized connections, the pattern of activity suggests something more malicious.

B (Security incident on HOST002): The issue is not with HOST002. The suspicious activity is from VM002.

C (False positives): The repeated pattern of unauthorized connections makes false positives unlikely.


CompTIA SecurityX CAS-005 Official Study Guide: Chapter on SIEM & Incident Analysis

MITRE ATT&CK Tactics: Lateral Movement & Network-based Attacks

Contribute your Thoughts:

Lorenza
11 days ago
I disagree, I believe option D is more likely. There might be a network infection.
upvoted 0 times
...
Terrilyn
12 days ago
I think option A is correct. VM002 needs to be revised.
upvoted 0 times
...
Nieves
12 days ago
The VM002 host is definitely misconfigured. The network team needs to take a closer look and get that fixed ASAP.
upvoted 0 times
...

Save Cancel