Courseiva
Security Operations →hardMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is investigating a host that communicates with a domain using a DGA-like algorithm. The domain name appears random and resolves to different IPs over time. Which threat-hunting technique would best identify the DGA pattern?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS log analysis for entropy and frequency

DGA domains can be detected by analyzing DNS query patterns for algorithmic generation, often using frequency analysis or ML models.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sigma rule on process creation events

    Why it's wrong here

    Sigma rules targeting process creation events are designed to detect suspicious execution behaviors, parent-child process relationships, and command-line arguments. They lack the capability to inspect active network-layer transactions or analyze the specific domain names queried by a running process. Consequently, they cannot identify the algorithmic patterns or high-entropy strings characteristic of Domain Generation Algorithms (DGAs).

  • ✗

    NetFlow analysis for data volume

    Why it's wrong here

    NetFlow analysis provides high-level metadata regarding network sessions, including source/destination IP addresses, ports, and data volume. However, NetFlow does not capture application-layer payloads or the specific domain names requested during DNS resolution. Because it lacks visibility into the actual domain strings, it cannot be used to detect the structural randomness or high-entropy characteristics of DGA-generated domains.

  • ✗

    YARA rule matching on process memory

    Why it's wrong here

    YARA rules are primarily utilized to scan files or active process memory for specific byte sequences, strings, or cryptographic signatures associated with known malware. While YARA can identify a malware binary residing in memory, it is not designed to monitor real-time network traffic or analyze the statistical properties of DNS queries. Therefore, it cannot dynamically detect DGA activity based on query frequency or domain name entropy.

  • ✓

    DNS log analysis for entropy and frequency

    Why this is correct

    DNS log analysis is the most effective method for identifying Domain Generation Algorithm (DGA) activity by examining the structural properties of queried domains. Analysts can calculate the Shannon entropy of domain strings to detect anomalous randomness and monitor query frequency for rapid bursts of failed resolutions (NXDOMAIN responses). This mathematical and behavioral analysis directly exposes the automated, algorithmic nature of DGA-based command-and-control (C2) communication.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.