CompTIA CAS-005 Question Answer
A security engineer receives an alert from the SIEM platform indicating a possible malicious action on the internal network. The engineer generates a report that outputs the logs associated with the incident:

Which of the following actions best enables the engineer to investigate further?
CompTIA CAS-005 Summary
- Vendor: CompTIA
- Product: CAS-005
- Update on: Dec 8, 2025
- Questions: 326

