
CompTIASecurityX (CASP+)
Domain 4Objective 4
Incident Response CAS-005 Practice Questions (Page 1)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
22%of the exam
Questions 1–5
- 1
What does code stylometry analyze in malware to help attribute it to a specific author or group?
Select an answer first - 2
What is the primary purpose of root cause analysis in incident response?
Select an answer first - 3
After a security incident, the incident response team has identified the malware and the affected systems. The team now needs to determine how the attacker initially gained access to prevent future occurrences. Which activity should the team perform?
Select an answer first - 4
What is the primary purpose of extracting indicators of compromise (IoCs) from a malware sample?
Select an answer first - 5
An organization is concerned about a new malware strain that appears to be polymorphic. The security team wants to analyze the malware's behavior and extract IoCs, but the malware may change its code each time it runs. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.