Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst is reviewing NetFlow data and notices a significant amount of traffic from an internal host to a known malicious IP address on port 443. What tool would be most effective for further analyzing the payload of this traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wireshark

Wireshark captures and analyzes packet payloads, which is necessary for examining the content of encrypted or unencrypted traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nikto

    Why it's wrong here

    Nikto is an active web application scanner that sends crafted HTTP requests to a target server to enumerate dangerous files, outdated software, and misconfigurations; it does not passively capture or reconstruct existing network traffic, so it cannot inspect the payload of the suspicious flow already observed.

  • ✓

    Wireshark

    Why this is correct

    Wireshark captures and decodes packets in real time or from a saved capture file, reassembling TCP streams and, where the session is unencrypted or keys are available, rendering application-layer payload content, protocol fields, and TLS handshake metadata needed to determine what data is actually being exchanged with the malicious IP.

  • ✗

    Nmap

    Why it's wrong here

    Nmap sends probe packets to discover open ports, running services, and OS fingerprints on a target host; it has no capability to capture or decode the content of an already-flowing traffic session, making it irrelevant to payload analysis.

  • ✗

    tcpdump

    Why it's wrong here

    tcpdump can capture the same raw packets as Wireshark from the command line and write them to a pcap file, but it lacks Wireshark's built-in protocol dissectors, stream-reassembly views, and filtering GUI, making deep interactive payload inspection considerably slower and less thorough.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.