CompTIA SecurityX CAS-005 Practice Question

While reviewing access logs, a security team discovers an account with privileges transferring restricted files to a cloud repository. The team suspects an internal data leak. Which action is most effective at confirming unauthorized file movements by the account in question?

  • Remove administrative privileges for every user in the department

  • Review recent access logs for that account and compare them to historical usage trends

  • Install a new operating system on the workstation used by the account

  • Block all outgoing connections from the office network

CompTIA SecurityX CAS-005
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot