mediumMultiple Choice
CAS-004 Practice Question: An incident responder notices that a compromised…
An incident responder notices that a compromised host is sending encrypted C2 traffic over TCP port 443. The existing firewall rule allows outbound HTTPS (443) to any destination. Which change to the security architecture would best detect this behavior while minimizing impact on legitimate traffic?
⚠ Common exam trap
A common mix-up: candidates assume a network-based IDS can detect malicious traffic in encrypted streams, but without decryption (as in a forward proxy with SSL inspection), the IDS sees only ciphertext and cannot analyze the payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a forward proxy with SSL/TLS inspection
A forward proxy with SSL/TLS inspection decrypts outbound HTTPS traffic, allowing the security team to inspect the payload of connections over TCP 443. This reveals encrypted C2 traffic that would otherwise be hidden within legitimate HTTPS flows, while still permitting authorized business traffic to pass through after inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a forward proxy with SSL/TLS inspection
Why this is correct
TLS inspection terminates the encrypted session at the proxy, exposing the plaintext C2 payload for signature and behavioural analysis. The existing any-destination 443 rule otherwise renders the traffic opaque, so this satisfies the detection requirement while legitimate HTTPS continues through the same proxy path.
- ✗
Block outbound TCP 443 and require users to use a VPN
Why it's wrong here
Blocking outbound 443 forces legitimate HTTPS through a VPN, breaking web access for every user and still permitting tunnelled C2 inside the VPN. It is tempting as a blunt containment measure during active exfiltration, but TLS inspection or egress filtering by destination reputation detects the beaconing without halting normal traffic.
- ✗
Enable logging on the firewall for all outbound 443 traffic
Why it's wrong here
Firewall logs record connection metadata — source, destination, port, bytes — but the C2 payload stays encrypted, so logging alone never reveals the command-and-control channel. It is tempting because logging is low-impact and cheap, and it would be the right first step for auditing egress destinations, yet detection requires TLS inspection or behavioural analysis.
- ✗
Install a network-based IDS on the internal side of the firewall
Why it's wrong here
An IDS on the internal side sees only encrypted TLS bytes, so signature matching cannot identify the C2 channel; placing it inside also misses traffic that never traverses that segment. It is tempting because IDS deployment is non-disruptive, and it would be correct for detecting cleartext attacks or lateral movement within the internal network.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.