CS0-003 Security Operations Practice Question
During a traffic analysis, a security analyst observes repeated outbound connections from an internal workstation to an external IP address on TCP port 53 at irregular intervals. The connections are small and occur every few minutes. Which technique is most likely being used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS tunneling
DNS normally uses UDP, but TCP port 53 can be used for DNS tunneling. The small, irregular connections to a single external IP suggest data exfiltration via DNS tunneling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTP smuggling
Why it's wrong here
HTTP request smuggling relies on manipulating HTTP/1.1 headers, such as Content-Length and Transfer-Encoding, to desynchronize the request processing between front-end proxies and back-end servers. Because this attack vector is strictly confined to HTTP/HTTPS application-layer traffic, typically on ports 80 and 443, it does not explain anomalous or repeated traffic observed on TCP port 53.
- ✗
TCP handshake anomaly
Why it's wrong here
A TCP handshake anomaly involves malformed packets, incomplete handshakes like SYN floods, or out-of-order flags during the connection establishment phase. In this scenario, the connections are successfully completing and transmitting payload data over port 53, indicating that the transport-layer handshake mechanism itself is functioning normally without protocol violations.
- ✓
DNS tunneling
Why this is correct
DNS tunneling encapsulates non-DNS traffic, such as SSH, HTTP, or proprietary data exfiltration protocols, within DNS queries and responses. While standard DNS queries typically utilize UDP port 53, attackers frequently fall back to or abuse TCP port 53 to bypass standard UDP-based inspection filters and transmit larger payloads or maintain persistent, stateful connection channels.
- ✗
Beaconing
Why it's wrong here
Beaconing is a command-and-control (C2) communication pattern characterized by highly regular, predictable, and periodic polling intervals used by malware to check in with its controller. The presence of highly irregular or sporadic traffic intervals observed in this traffic analysis contradicts the highly structured, heartbeat-like timing signature that defines classic beaconing behavior.
Visual reference
Go deeper
Related to this question
Learn chapter
Security Posture Reporting and Dashboards
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.