Courseiva
Security Operations →mediumMultiple Choice

CS0-003 Security Operations Practice Question

During a threat hunting engagement, a hunter creates a hypothesis that adversaries may be using PowerShell to perform reconnaissance via Active Directory cmdlets. The hunter decides to look for events where PowerShell loaded the ActiveDirectory module. Which of the following detection techniques is most appropriate?

⚠ Common exam trap

CS0-004 often tests the misconception that network-level tools (packet capture) or file-scanning tools (YARA) can detect in-memory PowerShell activity, when only script block or module logging provides that visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a SIEM correlation rule that triggers on Event ID 4104 (PowerShell Script Block Logging)

Event ID 4104 is generated by PowerShell Script Block Logging and captures the actual script block text executed, including the commands that import and invoke Active Directory cmdlets. A SIEM correlation rule on 4104 can detect patterns like 'Import-Module ActiveDirectory' or 'Get-ADUser' that indicate AD reconnaissance. This gives the hunter visibility into the exact PowerShell code executed on endpoints, which is the most direct evidence of the hypothesized behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a SIEM correlation rule that triggers on Event ID 4104 (PowerShell Script Block Logging)

    Why this is correct

    Script Block Logging (Event ID 4104) records the actual PowerShell code executed, so loading the ActiveDirectory module and running its cmdlets is captured verbatim. This satisfies the hypothesis by surfacing AD reconnaissance commands that module-loading events alone would miss.

  • ✗

    Perform a packet capture to analyze PowerShell network traffic

    Why it's wrong here

    Packet capture inspects network traffic, but loading the ActiveDirectory module is a host-side PowerShell event leaving no distinctive wire signature. It is tempting because PowerShell remoting generates network traffic, and capture would be correct if the hypothesis concerned command-and-control or exfiltration over the network.

  • ✗

    Deploy a YARA rule on endpoints to scan for malicious PowerShell scripts

    Why it's wrong here

    YARA matches file content against signatures, so it cannot detect a module being loaded into a live PowerShell session. It is tempting because YARA is a familiar hunting tool, and it would be correct if the hunter had recovered malicious script files or samples needing pattern identification.

  • ✗

    Use osquery to query running PowerShell processes

    Why it's wrong here

    osquery enumerates current process and system state, missing the historical module-load event the hypothesis targets. It is tempting because osquery can list running processes, and it would be correct if the hunt required point-in-time visibility of active processes rather than retrospective event analysis.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.