Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is investigating a potential data exfiltration via DNS. Which tool would best help identify DNS tunnelling by analyzing packet payloads and query patterns?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wireshark

Wireshark can capture and analyze DNS packets in detail, including payload and query patterns, making it suitable for detecting DNS tunnelling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Wireshark

    Why this is correct

    Wireshark is a graphical packet analyzer that allows analysts to perform deep packet inspection on captured network traffic. By reconstructing TCP streams and dissecting application-layer payloads, it enables the precise identification of sensitive data being exfiltrated. This granular visibility is crucial for verifying the exact contents of suspicious transmissions.

  • ✗

    tcpdump

    Why it's wrong here

    While tcpdump is an excellent command-line utility for capturing and filtering raw packet data on a network interface, it lacks the advanced protocol dissection and graphical stream reconstruction capabilities of Wireshark. Analyzing complex application-layer data exfiltration directly in a terminal using tcpdump is highly inefficient and prone to oversight compared to using a dedicated GUI analyzer.

  • ✗

    nmap

    Why it's wrong here

    Nmap is a network scanning and host discovery tool used primarily for mapping active hosts, identifying open ports, and fingerprinting operating systems. It does not capture, record, or analyze transit network traffic payloads, making it entirely unsuitable for investigating or reconstructing a data exfiltration event after it has occurred.

  • ✗

    NetFlow

    Why it's wrong here

    NetFlow generates high-level metadata summarizing network conversations, including source/destination IPs, ports, protocols, and volume of data transferred. Although NetFlow is invaluable for detecting anomalies or identifying that a large transfer occurred, it does not capture the actual packet payloads, preventing analysts from verifying what specific data was exfiltrated.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.