Courseiva
mediumMultiple Choice

CAS-004 Practice Question: An incident responder notices that a compromised…

An incident responder notices that a compromised host is sending encrypted C2 traffic over TCP port 443. The existing firewall rule allows outbound HTTPS (443) to any destination. Which change to the security architecture would best detect this behavior while minimizing impact on legitimate traffic?

⚠ Common exam trap

A common mix-up: candidates assume a network-based IDS can detect malicious traffic in encrypted streams, but without decryption (as in a forward proxy with SSL inspection), the IDS sees only ciphertext and cannot analyze the payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a forward proxy with SSL/TLS inspection

A forward proxy with SSL/TLS inspection decrypts outbound HTTPS traffic, allowing the security team to inspect the payload of connections over TCP 443. This reveals encrypted C2 traffic that would otherwise be hidden within legitimate HTTPS flows, while still permitting authorized business traffic to pass through after inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy a forward proxy with SSL/TLS inspection

    Why this is correct

    TLS inspection terminates the encrypted session at the proxy, exposing the plaintext C2 payload for signature and behavioural analysis. The existing any-destination 443 rule otherwise renders the traffic opaque, so this satisfies the detection requirement while legitimate HTTPS continues through the same proxy path.

  • ✗

    Block outbound TCP 443 and require users to use a VPN

    Why it's wrong here

    Blocking outbound 443 forces legitimate HTTPS through a VPN, breaking web access for every user and still permitting tunnelled C2 inside the VPN. It is tempting as a blunt containment measure during active exfiltration, but TLS inspection or egress filtering by destination reputation detects the beaconing without halting normal traffic.

  • ✗

    Enable logging on the firewall for all outbound 443 traffic

    Why it's wrong here

    Firewall logs record connection metadata — source, destination, port, bytes — but the C2 payload stays encrypted, so logging alone never reveals the command-and-control channel. It is tempting because logging is low-impact and cheap, and it would be the right first step for auditing egress destinations, yet detection requires TLS inspection or behavioural analysis.

  • ✗

    Install a network-based IDS on the internal side of the firewall

    Why it's wrong here

    An IDS on the internal side sees only encrypted TLS bytes, so signature matching cannot identify the C2 channel; placing it inside also misses traffic that never traverses that segment. It is tempting because IDS deployment is non-disruptive, and it would be correct for detecting cleartext attacks or lateral movement within the internal network.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.