Courseiva
hardMultiple ChoiceObjective-mapped

CS0-003 Practice Question: A SOC analyst notices a spike in outbound traffic…

A SOC analyst notices a spike in outbound traffic from a server that normally only serves web pages. The signature-based IDS did not alert. What should the analyst do next?

⚠ Common exam trap

CompTIA often tests the misconception that a signature-based IDS failing to alert means the traffic is safe, leading candidates to incorrectly choose increasing IDS sensitivity or checking for zero-days, rather than recognizing that the analyst must pivot to threat intelligence to identify unknown or evasive threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Query threat intelligence for the destination IPs

Querying threat intelligence for the destination IPs is the correct next step because the spike in outbound traffic from a web server suggests a potential data exfiltration attempt or command-and-control (C2) communication. Since the signature-based IDS did not alert, the traffic may be using non-standard ports or encrypted channels that evade known signatures. Threat intelligence can reveal if the destination IPs are associated with known malicious actors, botnets, or recent threat campaigns, providing context to determine if the traffic is benign or malicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Query threat intelligence for the destination IPs

    Why this is correct

    A spike in outbound traffic from a server is inherently suspicious, necessitating immediate investigation. Querying threat intelligence platforms (TIPs) or open-source intelligence (OSINT) feeds with the destination IPs is a crucial initial step in incident response. This action quickly correlates observed indicators of compromise (IOCs) with known malicious infrastructure, such as command-and-control (C2) servers, botnet nodes, or phishing sites. This provides immediate context on the potential threat actor or malware family involved, allowing the analyst to rapidly assess the severity and nature of the incident without disrupting operations.

  • Disable the server immediately

    Why it's wrong here

    Disabling the server immediately is a premature and potentially disruptive action that should be avoided as an initial response. While containment is a critical phase in incident response, it should only occur after initial investigation confirms malicious activity and after carefully considering business impact and forensic requirements. Abruptly shutting down a server can disrupt critical business operations, prevent further observation of the attacker's behavior, and potentially destroy volatile forensic evidence needed for root cause analysis and attribution.

  • Check for zero-day vulnerabilities

    Why it's wrong here

    Checking specifically for zero-day vulnerabilities is an overly narrow and unlikely initial response to a general spike in outbound traffic. A spike in outbound traffic is far more commonly associated with known malware communicating with command-and-control (C2) infrastructure or data exfiltration, rather than an unknown, unpatched vulnerability. Without any specific indicators pointing to a zero-day exploit, focusing on this highly specialized and difficult-to-detect threat diverts resources from more probable and actionable investigative paths.

  • Increase the IDS sensitivity threshold

    Why it's wrong here

    Increasing the Intrusion Detection System (IDS) sensitivity threshold is counterproductive and an inappropriate response in this scenario. A higher sensitivity threshold would generate a significantly larger volume of alerts, including many false positives, creating excessive noise that could obscure actual malicious activity and overwhelm analysts. The immediate need is to understand the nature of the *already observed* suspicious traffic, not to generate more alerts that might not be relevant or actionable for the current incident.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.