CS0-003 Security Operations Practice Question
An analyst is investigating a suspected data exfiltration via HTTP. The analyst examines a PCAP file and finds a series of HTTP POST requests to an external site with varying 'Content-Length' values. The payloads appear to be base64-encoded strings. Which tool would be most effective for extracting and decoding the payloads for analysis?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Python with scapy
Python with scapy allows custom scripting to extract and decode payloads from PCAP files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
While Wireshark is an excellent tool for interactive packet analysis and manual inspection of individual streams, it lacks the native, robust scripting capabilities required to automate the bulk extraction and base64 decoding of payloads across thousands of HTTP requests. Manually exporting each object is highly inefficient and impractical for large-scale incident response investigations.
- ✓
Python with scapy
Why this is correct
Python paired with the Scapy library provides a powerful programmatic environment to parse packet capture (PCAP) files. It allows analysts to write custom scripts that target specific layers, extract HTTP payload data, programmatically decode base64-encoded strings, and automate the identification of exfiltrated data at scale.
- ✗
tcpdump
Why it's wrong here
The tcpdump utility is a lightweight, command-line packet analyzer designed primarily for capturing and filtering network traffic. Although it can write packets to a file or display raw ASCII/HEX output, it does not possess the high-level application layer parsing or programmatic decoding features needed to reconstruct and decode complex payloads.
- ✗
NetFlow
Why it's wrong here
NetFlow metadata provides high-level visibility into network conversations, including source/destination IPs, ports, timestamps, and byte counts. However, because NetFlow does not capture actual packet payloads, it is impossible to use this data to inspect, reconstruct, or decode the specific application-layer contents of suspected exfiltration traffic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.