Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

A security analyst notices that a firewall log shows outbound traffic from an internal server to an external IP address on TCP port 443, but the server is not configured to make any outbound connections. The analyst checks previous logs and finds similar connections every 60 minutes. What type of activity is most likely occurring?

⚠ Common exam trap

CS0-004 often tests the assumption that any HTTPS traffic is benign — candidates pick 'software update' because port 443 looks legitimate, missing the unexpected source and fixed interval that signal C2 beaconing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Beaconing to a command-and-control server

Regular outbound connections every 60 minutes to an external IP on port 443 from a server that should not make outbound connections is a textbook beaconing pattern. Malware uses periodic callbacks to a command-and-control (C2) server to receive instructions and exfiltrate data, often disguising traffic as HTTPS to evade detection. The fixed interval and unexpected destination strongly indicate C2 beaconing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Beaconing to a command-and-control server

    Why this is correct

    This behavior is characteristic of malware beaconing, where a compromised host establishes periodic, scheduled outbound connections to a command-and-control (C2) server to receive instructions. Utilizing port 443 allows this malicious traffic to blend seamlessly with legitimate, encrypted HTTPS web traffic, bypassing basic firewall inspection.

  • ✗

    Normal software update check

    Why it's wrong here

    While software update checks frequently utilize HTTPS, they typically target reputable, vendor-owned domain names rather than a single, unverified external IP address. Furthermore, a secure internal server not configured for general outbound access should not be initiating hourly external connections, making this behavior highly anomalous.

  • ✗

    DNS tunneling

    Why it's wrong here

    DNS tunneling is an evasion technique that encapsulates non-DNS traffic within standard DNS queries and responses. This specific attack vector relies on UDP or TCP port 53 to communicate with a rogue nameserver, which does not align with the outbound port 443 traffic observed in the firewall logs.

  • ✗

    Data exfiltration via FTP

    Why it's wrong here

    File Transfer Protocol (FTP) is a legacy protocol designed for moving files and operates over TCP ports 20 and 21. Because the firewall log specifically indicates outbound traffic over port 443 (HTTPS), FTP is ruled out as the transport mechanism for this activity.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.