Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

An analyst is investigating a suspicious email attachment. The sandbox analysis shows that the document drops a binary that connects to an external IP on port 4444. Which network analysis tool is best suited to confirm if any internal hosts are communicating on that port?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetFlow analyzer

NetFlow collects metadata about network flows, including destination IP and port, enabling analysts to query for all traffic on a specific port across the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tcpdump

    Why it's wrong here

    While tcpdump is an excellent command-line utility for capturing and filtering live packet data on a specific local interface, it is not designed for enterprise-wide historical querying. Attempting to use it to search across multiple distributed hosts is highly inefficient and lacks the centralized aggregation capabilities required for rapid incident response.

  • ✗

    nmap

    Why it's wrong here

    Nmap is an active network scanning and host discovery tool used to map topology, identify open ports, and detect operating systems. It cannot perform passive analysis of historical network traffic or search past connection logs, making it useless for identifying which internal hosts previously communicated with an external command-and-control server.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a GUI-based packet analyzer ideal for deep-dive inspection of individual PCAP files. However, because it processes full packet payloads, it consumes massive storage and memory, making it completely unscalable for performing rapid, retrospective searches across an entire enterprise network's historical traffic.

  • ✓

    NetFlow analyzer

    Why this is correct

    A NetFlow analyzer aggregates metadata about network conversations, such as source/destination IPs, ports, and timestamps, without the overhead of full packet payloads. This lightweight data structure allows security analysts to rapidly query months of historical traffic across the entire enterprise to pinpoint which hosts communicated with a malicious external IP.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.