CS0-003 Security Operations Practice Question
A security analyst notices that a firewall log shows outbound traffic from an internal server to an external IP address on TCP port 443, but the server is not configured to make any outbound connections. The analyst checks previous logs and finds similar connections every 60 minutes. What type of activity is most likely occurring?
⚠ Common exam trap
CS0-004 often tests the assumption that any HTTPS traffic is benign — candidates pick 'software update' because port 443 looks legitimate, missing the unexpected source and fixed interval that signal C2 beaconing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Beaconing to a command-and-control server
Regular outbound connections every 60 minutes to an external IP on port 443 from a server that should not make outbound connections is a textbook beaconing pattern. Malware uses periodic callbacks to a command-and-control (C2) server to receive instructions and exfiltrate data, often disguising traffic as HTTPS to evade detection. The fixed interval and unexpected destination strongly indicate C2 beaconing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Beaconing to a command-and-control server
Why this is correct
This behavior is characteristic of malware beaconing, where a compromised host establishes periodic, scheduled outbound connections to a command-and-control (C2) server to receive instructions. Utilizing port 443 allows this malicious traffic to blend seamlessly with legitimate, encrypted HTTPS web traffic, bypassing basic firewall inspection.
- ✗
Normal software update check
Why it's wrong here
While software update checks frequently utilize HTTPS, they typically target reputable, vendor-owned domain names rather than a single, unverified external IP address. Furthermore, a secure internal server not configured for general outbound access should not be initiating hourly external connections, making this behavior highly anomalous.
- ✗
DNS tunneling
Why it's wrong here
DNS tunneling is an evasion technique that encapsulates non-DNS traffic within standard DNS queries and responses. This specific attack vector relies on UDP or TCP port 53 to communicate with a rogue nameserver, which does not align with the outbound port 443 traffic observed in the firewall logs.
- ✗
Data exfiltration via FTP
Why it's wrong here
File Transfer Protocol (FTP) is a legacy protocol designed for moving files and operates over TCP ports 20 and 21. Because the firewall log specifically indicates outbound traffic over port 443 (HTTPS), FTP is ruled out as the transport mechanism for this activity.
Visual reference
Go deeper
Related to this question
Learn chapter
Data Breach Incident Response
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.