Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

During a network traffic analysis, a security analyst notices a host communicating with an external IP address over TCP port 443 using a self-signed certificate. The traffic flows are consistent in size and occur every 60 seconds. The external IP is not on any threat intelligence feeds. What does this pattern most likely indicate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command and control beaconing

Regular, periodic connections of consistent size to an external host over HTTPS suggest beaconing, often used by malware for command and control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Lateral movement attempt

    Why it's wrong here

    Lateral movement involves an attacker moving systematically through an internal network to compromise additional hosts or escalate privileges. This activity is characterized by east-west traffic patterns, such as internal RDP, SSH, or SMB connections, rather than consistent outbound north-south HTTPS connections to an external server.

  • ✗

    Data exfiltration via DNS tunneling

    Why it's wrong here

    While DNS tunneling is a method for bypassing security controls, it relies on encapsulating non-DNS protocols within DNS queries (port 53) directed at a rogue nameserver. The scenario describes consistent, periodic HTTPS traffic (port 443), which does not match the high-volume, encoded TXT or CNAME query patterns typical of DNS-based exfiltration.

  • ✓

    Command and control beaconing

    Why this is correct

    Command and control (C2) beaconing is characterized by compromised internal hosts making periodic, highly consistent outbound connections to external malicious infrastructure to check for instructions. These regular intervals, often referred to as heartbeat signals, are designed to maintain persistence and bypass standard firewalls by masquerading as legitimate outbound HTTPS traffic.

  • ✗

    Normal web browsing

    Why it's wrong here

    Standard user web browsing exhibits highly irregular, bursty traffic patterns with varied destination domains, request sizes, and active hours. In contrast, the highly structured, repetitive, and automated nature of the observed outbound connections points to programmatic activity rather than human-driven web navigation.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.