CS0-003 Security Operations Practice Question
During a threat hunting engagement, a hunter creates a hypothesis that adversaries may be using PowerShell to perform reconnaissance via Active Directory cmdlets. The hunter decides to look for events where PowerShell loaded the ActiveDirectory module. Which of the following detection techniques is most appropriate?
⚠ Common exam trap
CS0-004 often tests the misconception that network-level tools (packet capture) or file-scanning tools (YARA) can detect in-memory PowerShell activity, when only script block or module logging provides that visibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a SIEM correlation rule that triggers on Event ID 4104 (PowerShell Script Block Logging)
Event ID 4104 is generated by PowerShell Script Block Logging and captures the actual script block text executed, including the commands that import and invoke Active Directory cmdlets. A SIEM correlation rule on 4104 can detect patterns like 'Import-Module ActiveDirectory' or 'Get-ADUser' that indicate AD reconnaissance. This gives the hunter visibility into the exact PowerShell code executed on endpoints, which is the most direct evidence of the hypothesized behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a SIEM correlation rule that triggers on Event ID 4104 (PowerShell Script Block Logging)
Why this is correct
Script Block Logging (Event ID 4104) records the actual PowerShell code executed, so loading the ActiveDirectory module and running its cmdlets is captured verbatim. This satisfies the hypothesis by surfacing AD reconnaissance commands that module-loading events alone would miss.
- ✗
Perform a packet capture to analyze PowerShell network traffic
Why it's wrong here
Packet capture inspects network traffic, but loading the ActiveDirectory module is a host-side PowerShell event leaving no distinctive wire signature. It is tempting because PowerShell remoting generates network traffic, and capture would be correct if the hypothesis concerned command-and-control or exfiltration over the network.
- ✗
Deploy a YARA rule on endpoints to scan for malicious PowerShell scripts
Why it's wrong here
YARA matches file content against signatures, so it cannot detect a module being loaded into a live PowerShell session. It is tempting because YARA is a familiar hunting tool, and it would be correct if the hunter had recovered malicious script files or samples needing pattern identification.
- ✗
Use osquery to query running PowerShell processes
Why it's wrong here
osquery enumerates current process and system state, missing the historical module-load event the hypothesis targets. It is tempting because osquery can list running processes, and it would be correct if the hunt required point-in-time visibility of active processes rather than retrospective event analysis.
Go deeper
Related to this question
Learn chapter
Mobile Device Forensics and MDM Evidence
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.