CS0-003 Security Operations Practice Question
A security analyst is hunting for signs of lateral movement in the network. Which THREE indicators are most consistent with lateral movement techniques?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An RDP connection from a domain controller to a workstation
Lateral movement often involves remote execution tools (PsExec), remote service creation, and suspicious RDP connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unusual outbound DNS queries to known malicious domains
Why it's wrong here
Outbound DNS queries directed at known malicious domains or using domain generation algorithms (DGAs) typically indicate command-and-control (C2) beaconing or data exfiltration. While this represents a critical security incident, it signifies external communication with an attacker-controlled server rather than internal lateral movement between local network assets.
- ✓
An RDP connection from a domain controller to a workstation
Why this is correct
In a secure architecture, administrative traffic flows from privileged workstations to domain controllers, never the reverse. An outbound Remote Desktop Protocol (RDP) connection originating from a domain controller to a standard workstation is highly anomalous and strongly indicates an adversary is leveraging compromised domain-level credentials to pivot downstream.
- ✓
Creation of a new service on a remote system using sc.exe
Why this is correct
The utilization of the service control manager utility (sc.exe) to register and start a new service on a remote host is a classic technique for executing arbitrary code across the network. This behavior directly facilitates lateral movement by allowing an attacker with administrative privileges to establish persistence and run malicious payloads on target systems.
- ✗
Multiple failed logins from a single workstation to many servers
Why it's wrong here
A high volume of failed authentication attempts across multiple servers is characteristic of active credential harvesting, such as brute-force or password-spraying attacks. Lateral movement, by contrast, typically involves the stealthy abuse of already-compromised, valid credentials to transition between systems without triggering authentication failure alarms.
- ✓
Execution of PsExec from a non-administrative workstation
Why this is correct
PsExec is a powerful administrative tool frequently co-opted by threat actors to execute processes on remote systems. Its execution from a standard, non-administrative workstation is a major red flag, indicating that an attacker is attempting to pivot to other network segments using compromised local admin credentials.
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.