CAS-004 Security Operations Practice Question
A security analyst is performing dynamic malware analysis in a sandbox. The analyst observes that the malware sample attempts to connect to a command-and-control (C2) server but fails. The analyst wants to modify the sandbox environment to allow the malware to communicate with the C2 server to observe its behavior. Which TWO of the following changes should the analyst make? (Choose two.)
⚠ Common exam trap
The trap here is thinking that simply allowing all outbound traffic or using a VPN will solve the problem, when in fact controlled simulation is the safe and effective approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the sandbox to use a simulated internet service (INetSim) to respond to network requests.
To allow the malware to communicate with its C2 server in a safe manner, the analyst should simulate network services. INetSim provides fake responses to common protocols, and a fake DNS server redirects C2 domains to a local listener. Both techniques enable observation of the malware's network behavior without risking actual external communication. Disabling the firewall or using a VPN could expose the real C2 and is unsafe. Resource adjustments do not solve the network issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the sandbox to use a simulated internet service (INetSim) to respond to network requests.
Why this is correct
INetSim simulates common internet services, allowing malware to receive responses as if it were communicating with real servers. This can trick the malware into revealing its C2 behavior, such as HTTP requests or DNS queries. It is a safe way to observe network activity without allowing actual external connections, which is essential in a sandbox environment.
- ✓
Set up a fake DNS server to resolve the C2 domain to a local listener.
Why this is correct
Setting up a fake DNS server to redirect the C2 domain to a local listener allows the analyst to intercept and respond to the malware's network requests. This enables observation of the malware's communication patterns without connecting to the actual C2. It is a common technique in sandbox environments to simulate network services and analyze behavior safely.
- ✗
Use a VPN to route all sandbox traffic through a different country.
Why it's wrong here
Using a VPN to route traffic through another country does not simulate the C2 server; it simply changes the apparent origin of the traffic. The malware would still attempt to connect to the real C2, which might be blocked or could lead to unintended consequences. This does not provide a controlled environment for observation and is not a recommended practice.
- ✗
Increase the sandbox's CPU and memory resources to prevent timeouts.
Why it's wrong here
Increasing CPU and memory resources can help with performance but does not address the network communication issue. The malware fails to connect to the C2 server due to network restrictions, not resource limitations. While adequate resources are important for analysis, they are not relevant to enabling C2 communication in this scenario.
- ✗
Disable the sandbox's firewall to allow all outbound traffic to the internet.
Why it's wrong here
Disabling the firewall to allow all outbound traffic would permit the malware to communicate with the real C2 server, which could be dangerous and might alert the attacker. It also violates the principle of containment. While it would allow observation, it is not a recommended practice for dynamic analysis due to security risks. A controlled simulation is preferred.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.