CS0-003 Security Operations Practice Question
A security analyst is reviewing NetFlow data and notices a significant amount of traffic from an internal host to a known malicious IP address on port 443. What tool would be most effective for further analyzing the payload of this traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wireshark
Wireshark captures and analyzes packet payloads, which is necessary for examining the content of encrypted or unencrypted traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nikto
Why it's wrong here
Nikto is an active web application scanner that sends crafted HTTP requests to a target server to enumerate dangerous files, outdated software, and misconfigurations; it does not passively capture or reconstruct existing network traffic, so it cannot inspect the payload of the suspicious flow already observed.
- ✓
Wireshark
Why this is correct
Wireshark captures and decodes packets in real time or from a saved capture file, reassembling TCP streams and, where the session is unencrypted or keys are available, rendering application-layer payload content, protocol fields, and TLS handshake metadata needed to determine what data is actually being exchanged with the malicious IP.
- ✗
Nmap
Why it's wrong here
Nmap sends probe packets to discover open ports, running services, and OS fingerprints on a target host; it has no capability to capture or decode the content of an already-flowing traffic session, making it irrelevant to payload analysis.
- ✗
tcpdump
Why it's wrong here
tcpdump can capture the same raw packets as Wireshark from the command line and write them to a pcap file, but it lacks Wireshark's built-in protocol dissectors, stream-reassembly views, and filtering GUI, making deep interactive payload inspection considerably slower and less thorough.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.