Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

A security analyst is performing dynamic malware analysis in a sandbox. The analyst observes that the malware sample attempts to connect to a command-and-control (C2) server but fails. The analyst wants to modify the sandbox environment to allow the malware to communicate with the C2 server to observe its behavior. Which TWO of the following changes should the analyst make? (Choose two.)

⚠ Common exam trap

The trap here is thinking that simply allowing all outbound traffic or using a VPN will solve the problem, when in fact controlled simulation is the safe and effective approach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the sandbox to use a simulated internet service (INetSim) to respond to network requests.

To allow the malware to communicate with its C2 server in a safe manner, the analyst should simulate network services. INetSim provides fake responses to common protocols, and a fake DNS server redirects C2 domains to a local listener. Both techniques enable observation of the malware's network behavior without risking actual external communication. Disabling the firewall or using a VPN could expose the real C2 and is unsafe. Resource adjustments do not solve the network issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the sandbox to use a simulated internet service (INetSim) to respond to network requests.

    Why this is correct

    INetSim simulates common internet services, allowing malware to receive responses as if it were communicating with real servers. This can trick the malware into revealing its C2 behavior, such as HTTP requests or DNS queries. It is a safe way to observe network activity without allowing actual external connections, which is essential in a sandbox environment.

  • ✓

    Set up a fake DNS server to resolve the C2 domain to a local listener.

    Why this is correct

    Setting up a fake DNS server to redirect the C2 domain to a local listener allows the analyst to intercept and respond to the malware's network requests. This enables observation of the malware's communication patterns without connecting to the actual C2. It is a common technique in sandbox environments to simulate network services and analyze behavior safely.

  • ✗

    Use a VPN to route all sandbox traffic through a different country.

    Why it's wrong here

    Using a VPN to route traffic through another country does not simulate the C2 server; it simply changes the apparent origin of the traffic. The malware would still attempt to connect to the real C2, which might be blocked or could lead to unintended consequences. This does not provide a controlled environment for observation and is not a recommended practice.

  • ✗

    Increase the sandbox's CPU and memory resources to prevent timeouts.

    Why it's wrong here

    Increasing CPU and memory resources can help with performance but does not address the network communication issue. The malware fails to connect to the C2 server due to network restrictions, not resource limitations. While adequate resources are important for analysis, they are not relevant to enabling C2 communication in this scenario.

  • ✗

    Disable the sandbox's firewall to allow all outbound traffic to the internet.

    Why it's wrong here

    Disabling the firewall to allow all outbound traffic would permit the malware to communicate with the real C2 server, which could be dangerous and might alert the attacker. It also violates the principle of containment. While it would allow observation, it is not a recommended practice for dynamic analysis due to security risks. A controlled simulation is preferred.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.