
CompTIASecurityX (CASP+)
Domain 4Objective 4
Incident Response CAS-005 Practice Questions (Page 3)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
22%of the exam
Questions 11–15
- 11
Which of the following is an example of an indicator of compromise (IoC) that can be extracted from a malware sample?
Select an answer first - 12
During incident response, a team has isolated a malware sample. They need to quickly identify other hosts in the environment that may be compromised by the same malware. Which set of artifacts should the team extract from the sample to search the network?
Select an answer first - 13
A security team has discovered a new malware variant that shares code similarities with a known threat group's previous tools. The team wants to support attribution to that group. Which analysis technique would provide the strongest evidence of a common author?
Select an answer first - 14
A security researcher is analyzing a new piece of malware and suspects it was written by the same group that created a previous campaign. The researcher has access to both samples. Which combination of evidence would provide the strongest attribution?
Select an answer first - 15
What type of information can be gathered from analyzing the metadata of a malware file?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.