CS0-003 Security Operations Practice Question
An analyst is investigating a host that communicates with a domain using a DGA-like algorithm. The domain name appears random and resolves to different IPs over time. Which threat-hunting technique would best identify the DGA pattern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS log analysis for entropy and frequency
DGA domains can be detected by analyzing DNS query patterns for algorithmic generation, often using frequency analysis or ML models.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sigma rule on process creation events
Why it's wrong here
Sigma rules targeting process creation events are designed to detect suspicious execution behaviors, parent-child process relationships, and command-line arguments. They lack the capability to inspect active network-layer transactions or analyze the specific domain names queried by a running process. Consequently, they cannot identify the algorithmic patterns or high-entropy strings characteristic of Domain Generation Algorithms (DGAs).
- ✗
NetFlow analysis for data volume
Why it's wrong here
NetFlow analysis provides high-level metadata regarding network sessions, including source/destination IP addresses, ports, and data volume. However, NetFlow does not capture application-layer payloads or the specific domain names requested during DNS resolution. Because it lacks visibility into the actual domain strings, it cannot be used to detect the structural randomness or high-entropy characteristics of DGA-generated domains.
- ✗
YARA rule matching on process memory
Why it's wrong here
YARA rules are primarily utilized to scan files or active process memory for specific byte sequences, strings, or cryptographic signatures associated with known malware. While YARA can identify a malware binary residing in memory, it is not designed to monitor real-time network traffic or analyze the statistical properties of DNS queries. Therefore, it cannot dynamically detect DGA activity based on query frequency or domain name entropy.
- ✓
DNS log analysis for entropy and frequency
Why this is correct
DNS log analysis is the most effective method for identifying Domain Generation Algorithm (DGA) activity by examining the structural properties of queried domains. Analysts can calculate the Shannon entropy of domain strings to detect anomalous randomness and monitor query frequency for rapid bursts of failed resolutions (NXDOMAIN responses). This mathematical and behavioral analysis directly exposes the automated, algorithmic nature of DGA-based command-and-control (C2) communication.
Visual reference
Go deeper
Related to this question
Learn chapter
Identity-Based Attack Patterns: Pass-the-Hash, Kerberoasting
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.