CS0-003 Security Operations Practice Question
An analyst is investigating a potential data exfiltration via DNS. Which tool would best help identify DNS tunnelling by analyzing packet payloads and query patterns?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wireshark
Wireshark can capture and analyze DNS packets in detail, including payload and query patterns, making it suitable for detecting DNS tunnelling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Wireshark
Why this is correct
Wireshark is a graphical packet analyzer that allows analysts to perform deep packet inspection on captured network traffic. By reconstructing TCP streams and dissecting application-layer payloads, it enables the precise identification of sensitive data being exfiltrated. This granular visibility is crucial for verifying the exact contents of suspicious transmissions.
- ✗
tcpdump
Why it's wrong here
While tcpdump is an excellent command-line utility for capturing and filtering raw packet data on a network interface, it lacks the advanced protocol dissection and graphical stream reconstruction capabilities of Wireshark. Analyzing complex application-layer data exfiltration directly in a terminal using tcpdump is highly inefficient and prone to oversight compared to using a dedicated GUI analyzer.
- ✗
nmap
Why it's wrong here
Nmap is a network scanning and host discovery tool used primarily for mapping active hosts, identifying open ports, and fingerprinting operating systems. It does not capture, record, or analyze transit network traffic payloads, making it entirely unsuitable for investigating or reconstructing a data exfiltration event after it has occurred.
- ✗
NetFlow
Why it's wrong here
NetFlow generates high-level metadata summarizing network conversations, including source/destination IPs, ports, protocols, and volume of data transferred. Although NetFlow is invaluable for detecting anomalies or identifying that a large transfer occurred, it does not capture the actual packet payloads, preventing analysts from verifying what specific data was exfiltrated.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.