CAS-004 Security Operations Practice Question
A security analyst is reviewing firewall logs and notices a large number of outbound connections from an internal server to various external IP addresses on port 443. The connections are occurring at regular intervals and transferring small amounts of data. Which of the following is the MOST likely explanation for this activity?
⚠ Common exam trap
The trap here is assuming that any outbound HTTPS traffic is benign, when in fact attackers commonly use port 443 for C2 to blend in with normal web traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server is beaconing to a command-and-control (C2) server as part of a malware infection.
The pattern of regular outbound connections to multiple external IPs on port 443 with small data transfers is a classic indicator of C2 beaconing. Malware often uses HTTPS to evade detection and communicates periodically to receive commands or exfiltrate small amounts of data. This behavior warrants further investigation, such as checking the server for malware and analyzing the destinations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server is performing legitimate software updates from various vendors.
Why it's wrong here
While software updates can involve outbound HTTPS connections, they typically go to known vendor domains and are not to multiple random external IPs. Updates also usually transfer larger amounts of data. The regular interval and small data size are more indicative of beaconing than updates. Additionally, multiple vendors updating simultaneously is less likely.
- ✗
The server is using a peer-to-peer file-sharing application for legitimate business purposes.
Why it's wrong here
Peer-to-peer file sharing typically involves many connections to various IPs, but it usually transfers larger amounts of data and may use non-standard ports. While it can use port 443, the regular interval and small data size are more consistent with beaconing. Legitimate P2P would likely show more varied traffic patterns and larger transfers.
- ✓
The server is beaconing to a command-and-control (C2) server as part of a malware infection.
Why this is correct
Regular outbound connections to multiple external IPs on port 443 with small data transfers are characteristic of C2 beaconing. Malware often uses HTTPS to blend in with normal traffic. The periodic nature and multiple destinations suggest a compromised host attempting to communicate with its controller, possibly using domain generation algorithms (DGAs) or fast-flux.
- ✗
The server is experiencing a distributed denial-of-service (DDoS) attack from external sources.
Why it's wrong here
A DDoS attack would involve inbound traffic to the server, not outbound connections from the server. The logs show outbound connections, so the server is initiating them. This suggests the server is the source of the traffic, not the target. Therefore, DDoS is not the correct explanation.
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.