220-1102 Security Practice Question
A technician suspects that a malware infection on a Windows 10 workstation is communicating with a remote command-and-control server. The technician needs to identify which process is making outbound connections. Which built-in Windows tool is best suited for this task?
⚠ Common exam trap
Many exam-takers choose Task Manager because it is the most familiar tool for viewing processes and basic network activity, but they overlook that Resource Monitor provides the granular, per-connection details needed to identify C2 communications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource Monitor
Resource Monitor (resmon.exe) provides real-time monitoring of network activity, including which processes are making outbound connections, the remote IP addresses, and the protocols used (TCP/UDP). This makes it the best built-in tool for identifying a process communicating with a command-and-control server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Task Manager
Why it's wrong here
Task Manager's Performance tab provides an aggregate network utilization graph, and the Processes tab may show a numeric value of total network bytes per process, but it does not enumerate individual TCP connections. It lacks remote IP addresses, destination ports, and connection states such as ESTABLISHED or SYN_SENT. Without those endpoint details, a technician cannot determine whether a process is communicating with a known command-and-control server or merely performing a routine Windows update.
- ✓
Resource Monitor
Why this is correct
Resource Monitor (resmon.exe) offers a Network tab that drills into real-time per-process network activity, listing every active TCP connection alongside the owning process, local and remote IP addresses, ports, and the protocol state (e.g., ESTABLISHED, LISTENING). This direct visibility into outbound destinations makes it the ideal built-in tool for spotting a process that is repeatedly connecting to an unfamiliar or blacklisted IP address on an unusual port, a common indicator of C2 communication.
- ✗
Performance Monitor
Why it's wrong here
Performance Monitor (perfmon.exe) is a performance logging utility that records counters—such as total network throughput or CPU activity—into a Data Collector Set for later analysis. It cannot display a live list of per-process TCP endpoints; its network counters are aggregated at the interface level rather than by application or socket. Attempting to identify a specific suspicious connection with this tool would require constructing custom counters that provide only throughput figures, not destination addresses or connection state, making it unsuitable for this investigation.
- ✗
Event Viewer
Why it's wrong here
Event Viewer is the central repository for Windows logs, including Security, System, and Application events; it can contain audit entries like process creation (Event 4688) or, if advanced audit policies are configured, network connection events. However, these network-related events are not generated by default, and the viewer provides no live, continuously updated list of current outbound connections per process. By the time an event is logged, it may be too late or incomplete for identifying the specific remote endpoint a malicious process is communicating with, so it is not the tool for real-time C2 detection.
Visual reference
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.