
CompTIASecurityX (CASP+)
Domain 4Objective 4
Incident Response CAS-005 Practice Questions (Page 4)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
7concepts
22%of the exam
Questions 16–20
- 16
An analyst is examining a malicious PDF file that was used in a targeted attack. The analyst wants to determine the creator of the PDF and the software used to create it. The PDF's metadata has been stripped. Which technique could still provide clues about the creator?
Select an answer first - 17
Which of the following is a key output of a root cause analysis?
Select an answer first - 18
After a data breach, the incident response team determines that the attacker exploited a vulnerability in a web application. The team has patched the vulnerability and removed the malware. What is the next step to ensure the incident does not recur?
Select an answer first - 19
Which of the following is a typical feature examined in code stylometry?
Select an answer first - 20
What is the primary purpose of using a malware sandbox during incident response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.