CS0-003 Security Operations Practice Question
During a network traffic analysis, a security analyst notices a host communicating with an external IP address over TCP port 443 using a self-signed certificate. The traffic flows are consistent in size and occur every 60 seconds. The external IP is not on any threat intelligence feeds. What does this pattern most likely indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Command and control beaconing
Regular, periodic connections of consistent size to an external host over HTTPS suggest beaconing, often used by malware for command and control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Lateral movement attempt
Why it's wrong here
Lateral movement involves an attacker moving systematically through an internal network to compromise additional hosts or escalate privileges. This activity is characterized by east-west traffic patterns, such as internal RDP, SSH, or SMB connections, rather than consistent outbound north-south HTTPS connections to an external server.
- ✗
Data exfiltration via DNS tunneling
Why it's wrong here
While DNS tunneling is a method for bypassing security controls, it relies on encapsulating non-DNS protocols within DNS queries (port 53) directed at a rogue nameserver. The scenario describes consistent, periodic HTTPS traffic (port 443), which does not match the high-volume, encoded TXT or CNAME query patterns typical of DNS-based exfiltration.
- ✓
Command and control beaconing
Why this is correct
Command and control (C2) beaconing is characterized by compromised internal hosts making periodic, highly consistent outbound connections to external malicious infrastructure to check for instructions. These regular intervals, often referred to as heartbeat signals, are designed to maintain persistence and bypass standard firewalls by masquerading as legitimate outbound HTTPS traffic.
- ✗
Normal web browsing
Why it's wrong here
Standard user web browsing exhibits highly irregular, bursty traffic patterns with varied destination domains, request sizes, and active hours. In contrast, the highly structured, repetitive, and automated nature of the observed outbound connections points to programmatic activity rather than human-driven web navigation.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Baseline and Anomaly Detection
Key term
Threat intelligence
Threat intelligence is evidence-based knowledge about existing or emerging cyber threats that helps organizations defend against attacks.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.