CAS-004 Security Operations Practice Question
A security analyst is reviewing a packet capture (PCAP) from a suspected command-and-control (C2) channel. The analyst observes periodic outbound connections to an external IP address over TCP port 443. The traffic is encrypted with TLS, but the analyst suspects it may be malicious. Which TWO of the following techniques would be MOST effective to identify the malicious nature of the traffic without decrypting the payload? (Choose two.)
⚠ Common exam trap
The trap here is assuming that deep packet inspection can reveal encrypted payload contents without decryption, or that the server's public key can decrypt TLS traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Examine the packet sizes and timing intervals for patterns.
Analyzing the TLS certificate can reveal anomalies like self-signed or expired certificates, which are common in malicious C2 infrastructure. Examining packet sizes and timing intervals can expose beaconing patterns typical of automated C2 communication. Both techniques work without decrypting the payload. Deep packet inspection requires decryption, using the public key for decryption is impossible, and vulnerability scanning does not analyze the traffic itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Examine the packet sizes and timing intervals for patterns.
Why this is correct
Even with encryption, the size and timing of packets can reveal patterns. C2 channels often exhibit regular beaconing intervals, consistent packet sizes, or specific request-response patterns. Analyzing these metadata can indicate automated malicious communication. This technique is effective because it does not require payload decryption and can be automated in network monitoring tools.
- ✗
Run a vulnerability scanner against the external IP address.
Why it's wrong here
Running a vulnerability scanner against an external IP address may identify open ports or known vulnerabilities, but it does not analyze the traffic itself. It could be considered active reconnaissance and may alert the attacker. Moreover, it does not help in identifying the malicious nature of the encrypted C2 traffic from the PCAP. Thus, it is not the most effective technique for this scenario.
- ✗
Perform deep packet inspection (DPI) to examine the payload contents.
Why it's wrong here
Deep packet inspection would require decrypting the TLS traffic, which is not possible without the private key or a man-in-the-middle setup. Since the traffic is encrypted, DPI cannot inspect the payload contents directly. While DPI can analyze headers and metadata, it does not reveal the encrypted application data. Thus, it is not effective without decryption.
- ✓
Analyze the TLS certificate presented by the external server for anomalies.
Why this is correct
Malicious C2 servers often use self-signed, expired, or mismatched TLS certificates. Analyzing the certificate can reveal indicators such as a default certificate, unusual issuer, or discrepancies with the domain name. This is a passive technique that does not require decryption and can quickly flag suspicious infrastructure. It is a standard method in network forensics for identifying malicious TLS traffic.
- ✗
Decrypt the TLS traffic using the server's public key.
Why it's wrong here
The server's public key cannot decrypt TLS traffic; only the private key can. In TLS, the session keys are established using asymmetric cryptography, but the public key is used for encryption or key exchange, not decryption. Without the private key or a session key log, decryption is infeasible. Thus, this option is technically incorrect and not a viable technique.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.