Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician suspects that a malware infection on a Windows 10 workstation is communicating with a remote command-and-control server. The technician needs to identify which process is making outbound connections. Which built-in Windows tool is best suited for this task?

⚠ Common exam trap

Many exam-takers choose Task Manager because it is the most familiar tool for viewing processes and basic network activity, but they overlook that Resource Monitor provides the granular, per-connection details needed to identify C2 communications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Resource Monitor

Resource Monitor (resmon.exe) provides real-time monitoring of network activity, including which processes are making outbound connections, the remote IP addresses, and the protocols used (TCP/UDP). This makes it the best built-in tool for identifying a process communicating with a command-and-control server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Task Manager

    Why it's wrong here

    Task Manager's Performance tab provides an aggregate network utilization graph, and the Processes tab may show a numeric value of total network bytes per process, but it does not enumerate individual TCP connections. It lacks remote IP addresses, destination ports, and connection states such as ESTABLISHED or SYN_SENT. Without those endpoint details, a technician cannot determine whether a process is communicating with a known command-and-control server or merely performing a routine Windows update.

  • ✓

    Resource Monitor

    Why this is correct

    Resource Monitor (resmon.exe) offers a Network tab that drills into real-time per-process network activity, listing every active TCP connection alongside the owning process, local and remote IP addresses, ports, and the protocol state (e.g., ESTABLISHED, LISTENING). This direct visibility into outbound destinations makes it the ideal built-in tool for spotting a process that is repeatedly connecting to an unfamiliar or blacklisted IP address on an unusual port, a common indicator of C2 communication.

  • ✗

    Performance Monitor

    Why it's wrong here

    Performance Monitor (perfmon.exe) is a performance logging utility that records counters—such as total network throughput or CPU activity—into a Data Collector Set for later analysis. It cannot display a live list of per-process TCP endpoints; its network counters are aggregated at the interface level rather than by application or socket. Attempting to identify a specific suspicious connection with this tool would require constructing custom counters that provide only throughput figures, not destination addresses or connection state, making it unsuitable for this investigation.

  • ✗

    Event Viewer

    Why it's wrong here

    Event Viewer is the central repository for Windows logs, including Security, System, and Application events; it can contain audit entries like process creation (Event 4688) or, if advanced audit policies are configured, network connection events. However, these network-related events are not generated by default, and the viewer provides no live, continuously updated list of current outbound connections per process. By the time an event is logged, it may be too late or incomplete for identifying the specific remote endpoint a malicious process is communicating with, so it is not the tool for real-time C2 detection.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.