easyMultiple Choice
CS0-003 Practice Question: A SOC analyst receives an alert about a potential…
A SOC analyst receives an alert about a potential data exfiltration via DNS tunneling. Which of the following tools would best help the analyst investigate the alert?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between metadata-only tools (NetFlow) and full-packet capture (PCAP), expecting candidates to recognize that only PCAP provides the granularity needed for protocol-specific abuse like DNS tunneling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PCAP capture
PCAP capture (D) is the correct tool because DNS tunneling involves encoding data within DNS queries and responses, which can only be fully analyzed by inspecting the raw packet payloads. PCAP files allow the analyst to examine the actual DNS packet contents, including query names, response records, and timing patterns, which are essential for detecting anomalous DNS traffic indicative of tunneling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Endpoint Detection and Response (EDR)
Why it's wrong here
Endpoint Detection and Response (EDR) solutions primarily focus on endpoint activities, including process execution, file system changes, and network connection metadata. While EDR can log DNS requests made by processes, it typically captures only the query and response codes, not the full DNS payload content necessary to identify sophisticated data exfiltration techniques like DNS tunneling. Analyzing the actual data within the DNS query or response fields for anomalous patterns is beyond its standard scope.
- ✗
Antivirus logs
Why it's wrong here
Antivirus logs are designed to record events related to malware detection, quarantine, and removal, as well as file system scans. They focus on identifying known malicious signatures or behavioral anomalies at the file and process level. Antivirus software does not typically monitor or log network traffic, especially not the granular details of DNS queries and responses, making it ineffective for detecting DNS tunneling.
- ✗
NetFlow
Why it's wrong here
NetFlow, or similar flow data protocols like IPFIX, provides aggregated network session metadata such as source/destination IP addresses, ports, protocols, and byte/packet counts. While it can indicate that DNS traffic occurred between specific hosts, it explicitly does not capture the actual content of the DNS queries or responses. Therefore, NetFlow cannot reveal the encoded data within DNS requests or responses indicative of tunneling.
- ✓
PCAP capture
Why this is correct
A full Packet Capture (PCAP) provides a complete, byte-for-byte recording of all network traffic, including the entire headers and payloads of DNS queries and responses. This granular level of detail is crucial for detecting DNS tunneling, as it allows analysts to inspect the specific fields within DNS packets (e.g., query names, TXT records) for unusually long strings, non-standard characters, or encoded data that signifies covert communication. PCAP enables deep forensic analysis necessary to uncover such sophisticated exfiltration methods.
Visual reference
Go deeper
Related to this question
Learn chapter
Cloud Incident Response in AWS and Azure
Key term
SOC
A Security Operations Center (SOC) is a centralized team that monitors, detects, analyzes, and responds to cybersecurity incidents to protect an organization's information systems.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.