hardMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A SOC analyst notices a spike in outbound traffic…
A SOC analyst notices a spike in outbound traffic from a server that normally only serves web pages. The signature-based IDS did not alert. What should the analyst do next?
⚠ Common exam trap
CompTIA often tests the misconception that a signature-based IDS failing to alert means the traffic is safe, leading candidates to incorrectly choose increasing IDS sensitivity or checking for zero-days, rather than recognizing that the analyst must pivot to threat intelligence to identify unknown or evasive threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query threat intelligence for the destination IPs
Querying threat intelligence for the destination IPs is the correct next step because the spike in outbound traffic from a web server suggests a potential data exfiltration attempt or command-and-control (C2) communication. Since the signature-based IDS did not alert, the traffic may be using non-standard ports or encrypted channels that evade known signatures. Threat intelligence can reveal if the destination IPs are associated with known malicious actors, botnets, or recent threat campaigns, providing context to determine if the traffic is benign or malicious.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Query threat intelligence for the destination IPs
Why this is correct
A spike in outbound traffic from a server is inherently suspicious, necessitating immediate investigation. Querying threat intelligence platforms (TIPs) or open-source intelligence (OSINT) feeds with the destination IPs is a crucial initial step in incident response. This action quickly correlates observed indicators of compromise (IOCs) with known malicious infrastructure, such as command-and-control (C2) servers, botnet nodes, or phishing sites. This provides immediate context on the potential threat actor or malware family involved, allowing the analyst to rapidly assess the severity and nature of the incident without disrupting operations.
- ✗
Disable the server immediately
Why it's wrong here
Disabling the server immediately is a premature and potentially disruptive action that should be avoided as an initial response. While containment is a critical phase in incident response, it should only occur after initial investigation confirms malicious activity and after carefully considering business impact and forensic requirements. Abruptly shutting down a server can disrupt critical business operations, prevent further observation of the attacker's behavior, and potentially destroy volatile forensic evidence needed for root cause analysis and attribution.
- ✗
Check for zero-day vulnerabilities
Why it's wrong here
Checking specifically for zero-day vulnerabilities is an overly narrow and unlikely initial response to a general spike in outbound traffic. A spike in outbound traffic is far more commonly associated with known malware communicating with command-and-control (C2) infrastructure or data exfiltration, rather than an unknown, unpatched vulnerability. Without any specific indicators pointing to a zero-day exploit, focusing on this highly specialized and difficult-to-detect threat diverts resources from more probable and actionable investigative paths.
- ✗
Increase the IDS sensitivity threshold
Why it's wrong here
Increasing the Intrusion Detection System (IDS) sensitivity threshold is counterproductive and an inappropriate response in this scenario. A higher sensitivity threshold would generate a significantly larger volume of alerts, including many false positives, creating excessive noise that could obscure actual malicious activity and overwhelm analysts. The immediate need is to understand the nature of the *already observed* suspicious traffic, not to generate more alerts that might not be relevant or actionable for the current incident.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
SOC
A Security Operations Center (SOC) is a centralized team that monitors, detects, analyzes, and responds to cybersecurity incidents to protect an organization's information systems.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.