CS0-003 Incident Response and Management Practice Question
A SOC analyst receives an alert from a threat intelligence platform (TIP) about a new phishing campaign. The indicator is a URL. Which enrichment source is BEST for determining the URL's current hosting infrastructure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passive DNS
Passive DNS allows querying historical and current IP addresses associated with a domain, revealing hosting changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VirusTotal
Why it's wrong here
While VirusTotal aggregates antivirus scan results and can show historical file-to-IP relationships, it is primarily a malware analysis platform. It does not reliably provide a continuous, real-time historical record of domain-to-IP resolution mappings needed to track dynamic DNS changes.
- ✗
WHOIS
Why it's wrong here
WHOIS queries retrieve domain registration data, such as the registrar, creation dates, and administrative contact information. However, this protocol does not track active DNS resolution history or map domain names to their corresponding IP addresses over time.
- ✗
Shodan
Why it's wrong here
Shodan acts as a search engine for internet-connected devices, indexing open ports, running services, and system banners. It is designed for asset discovery and vulnerability assessment rather than reconstructing the historical DNS resolution path of a specific domain.
- ✓
Passive DNS
Why this is correct
Passive DNS databases log DNS query and response transactions captured by sensors across the internet. This allows analysts to reconstruct historical domain-to-IP mappings, identify fast-flux DNS techniques, and pinpoint when a malicious domain pointed to specific infrastructure.
Visual reference
Go deeper
Related to this question
Learn chapter
Insider Threat Investigation
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.