Courseiva
easyMultiple Select

CS0-003 Practice Question: A security analyst is reviewing alerts from an IDS

A security analyst is reviewing alerts from an IDS. Which TWO indicators are most likely to suggest a successful command and control (C2) communication? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between attempted and successful C2 communication, where candidates mistakenly choose indicators like DNS queries or inbound connections as proof of success, but only outbound beaconing or sustained data transfer on unusual ports confirms an established C2 channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A high volume of outbound traffic to an unusual destination IP on port 443

Option B is correct because sustained outbound traffic to an unusual external IP over port 443 is a classic C2 indicator: attackers frequently tunnel C2 over HTTPS (TCP 443) to blend with legitimate web traffic, and the destination being atypical for the environment raises suspicion. Option E is correct because regular beaconing to an external IP with consistent payload sizes reflects the periodic check-in pattern used by implants (e.g., fixed intervals with jitter and uniform packet sizes), which is a hallmark of established C2 channels. Option A does not belong because an inbound connection from a malicious IP to a mail server suggests scanning, exploitation, or spam relay activity rather than an internal host initiating C2. Option C does not belong because a single large upload to cloud storage is more indicative of data exfiltration than C2, and cloud storage is a legitimate service. Option D does not belong because a DNS query for a malicious domain indicates possible resolution or attempted contact, but a single query alone does not demonstrate the sustained, bidirectional communication characteristic of successful C2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An inbound connection from a known malicious IP to the mail server

    Why it's wrong here

    An inbound connection from a known malicious IP to a mail server typically signifies an attempted intrusion or initial compromise, such as a phishing attack or exploitation attempt. While critical to investigate, this traffic pattern represents an external entity trying to gain access into the network, rather than an established command-and-control (C2) channel originating from a compromised internal host communicating out to its controller. C2 channels are characterized by the internal host initiating communication.

  • ✓

    A high volume of outbound traffic to an unusual destination IP on port 443

    Why this is correct

    A high volume of outbound traffic directed to an unusual or previously unseen external IP address, especially over port 443, is a strong indicator of potential command-and-control (C2) activity or data exfiltration. Attackers frequently use port 443 to masquerade malicious traffic as legitimate HTTPS, blending in with normal web browsing to evade detection. The sheer volume and unusual destination suggest more than typical user activity, pointing towards a compromised internal host communicating with an external controller.

  • ✗

    A single large file upload to a cloud storage service

    Why it's wrong here

    A single large file upload to a cloud storage service, while potentially warranting investigation for data loss prevention policies, is not inherently indicative of command-and-control (C2) activity. This behavior is often a a legitimate business function, such as backing up data or sharing large project files. C2 communication typically involves persistent, often smaller, periodic communications or specific command execution, rather than a singular large data transfer event.

  • ✗

    An internal host performing a DNS query for a known malicious domain

    Why it's wrong here

    An internal host performing a DNS query for a known malicious domain is a critical alert, indicating an attempt to resolve a hostile resource, often a precursor to establishing a command-and-control (C2) channel. However, a successful DNS query alone does not confirm an established C2 communication. The query might be blocked by a DNS sinkhole, or the subsequent connection attempt could fail, meaning the C2 channel was never successfully formed or utilized for ongoing communication.

  • ✓

    Regular beaconing activity to an external IP with consistent payload sizes

    Why this is correct

    Regular beaconing activity, characterized by periodic, consistent outbound communications to an external IP address, often with uniform payload sizes and intervals, is a classic signature of command-and-control (C2) communication. This pattern allows a compromised host to "check in" with its controller, signaling its availability for commands or exfiltrating small amounts of data, without drawing immediate attention through erratic or high-volume traffic. The predictability of this behavior is a key indicator.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.