CS0-003 Security Operations Practice Question
An analyst is investigating a suspicious email attachment. The sandbox analysis shows that the document drops a binary that connects to an external IP on port 4444. Which network analysis tool is best suited to confirm if any internal hosts are communicating on that port?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow analyzer
NetFlow collects metadata about network flows, including destination IP and port, enabling analysts to query for all traffic on a specific port across the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tcpdump
Why it's wrong here
While tcpdump is an excellent command-line utility for capturing and filtering live packet data on a specific local interface, it is not designed for enterprise-wide historical querying. Attempting to use it to search across multiple distributed hosts is highly inefficient and lacks the centralized aggregation capabilities required for rapid incident response.
- ✗
nmap
Why it's wrong here
Nmap is an active network scanning and host discovery tool used to map topology, identify open ports, and detect operating systems. It cannot perform passive analysis of historical network traffic or search past connection logs, making it useless for identifying which internal hosts previously communicated with an external command-and-control server.
- ✗
Wireshark
Why it's wrong here
Wireshark is a GUI-based packet analyzer ideal for deep-dive inspection of individual PCAP files. However, because it processes full packet payloads, it consumes massive storage and memory, making it completely unscalable for performing rapid, retrospective searches across an entire enterprise network's historical traffic.
- ✓
NetFlow analyzer
Why this is correct
A NetFlow analyzer aggregates metadata about network conversations, such as source/destination IPs, ports, and timestamps, without the overhead of full packet payloads. This lightweight data structure allows security analysts to rapidly query months of historical traffic across the entire enterprise to pinpoint which hosts communicated with a malicious external IP.
Go deeper
Related to this question
Learn chapter
Zeek for Network Traffic Analysis
Key term
Sandbox analysis
Sandbox analysis is a security technique where suspicious files or code are executed in an isolated, controlled environment to observe their behavior without risking harm to the live network.
Key term
Metadata
Metadata is data that describes other data, providing context such as when a file was created, who created it, or its size.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.