Courseiva
Security Operations →mediumMultiple Select

CS0-003 Security Operations Practice Question

A security analyst is reviewing network traffic and suspects a host is infected with malware that uses a domain generation algorithm (DGA) for C2 communication. Which two of the following indicators are most consistent with DGA activity?

⚠ Common exam trap

CS0-004 often tests the confusion between DGA indicators (random domains, NXDOMAIN floods) and fixed-C2 beaconing (consistent intervals to one IP), so candidates pick the beaconing pattern as DGA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Frequent DNS queries to domains with random-looking, long subdomains

Option B is correct because DGA malware generates large numbers of pseudo-random domain names (often long, high-entropy subdomains) and the infected host repeatedly queries them while attempting to locate its C2 server. Option D is correct because most algorithmically generated domains are unregistered, so the resolver typically returns NXDOMAIN for the vast majority of these queries, producing a distinctive high-volume NXDOMAIN pattern. Option A is not indicative of DGA activity, since using internal DNS resolvers is normal enterprise behavior and says nothing about the queried domain names. Option C is not indicative because DGA domains are newly generated and unregistered, so they would not have a high Alexa ranking. Option E is not indicative because consistent intervals to a single IP suggest beaconing to a fixed C2, whereas DGA relies on constantly changing domain names.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All DNS queries are to internal DNS servers

    Why it's wrong here

    Internal DNS servers are the standard recursive resolvers for enterprise clients; all DNS queries being directed to them simply reflects normal network configuration. Attackers rarely force clients to use external resolvers because doing so would create anomalous traffic and potentially alert security tools. Thus, this is a benign indicator and does not suggest malicious activity.

  • ✓

    Frequent DNS queries to domains with random-looking, long subdomains

    Why this is correct

    Frequent queries to domains with random-looking, long subdomains are a hallmark of Domain Generation Algorithms (DGAs). Malware uses DGAs to generate pseudorandom domain names as rendezvous points with command-and-control (C2) servers, often producing long, alphanumeric subdomains that appear nonsensical. The high query rate to such domains is a strong indicator of compromise because legitimate users rarely make repeated queries to random subdomains.

  • ✗

    DNS queries to domains with a high Alexa ranking

    Why it's wrong here

    DNS queries to domains with a high Alexa ranking are typically not suspicious because attackers rarely use popular, well-known domains. These domains are more likely to be monitored by security researchers and are often already blocked or sinkholed, making them unreliable for stealthy C2 communications. Therefore, this pattern does not indicate malicious activity.

  • ✓

    High volume of DNS queries resulting in NXDOMAIN responses

    Why this is correct

    A high volume of DNS queries resulting in NXDOMAIN responses is a classic sign of DGA-based malware. The malware rapidly queries many algorithmically generated domains to find the one that is currently registered for C2; unregistered or sinkholed domains produce NXDOMAIN errors. A surge in such responses, especially to random-looking names, is a common heuristic used by security tools to detect DGA activity.

  • ✗

    Consistent DNS query intervals to a single IP

    Why it's wrong here

    Consistent DNS query intervals to a single IP address are more indicative of beaconing to a fixed C2 server, not DGA behavior. DGA malware generates and queries many different domain names, whereas static beaconing relies on a constant, periodic connection to one endpoint. This pattern is a different kind of C2 indicator and does not align with the random, evolving nature of DGA-generated domains.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.