Courseiva

CS0-003 Incident Response and Management Practice Question

During dynamic analysis of a malware sample in a sandbox, the analyst observes that the malware attempts to connect to an IP address 198.51.100.23 and modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which IOC type is the IP address an example of?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network indicator

IP addresses are a common type of indicator of compromise, representing network-based IOCs that can be used for detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Network indicator

    Why this is correct

    During dynamic analysis in a sandbox, observing a malware sample attempt to establish outbound connections to specific external IP addresses provides critical network indicators. These IP addresses serve as network-based indicators of compromise (IOCs) that security analysts can use to configure firewalls, intrusion detection systems, and blocklists to prevent further communication with command-and-control (C2) servers.

  • ✗

    File hash

    Why it's wrong here

    A file hash, such as an MD5, SHA-1, or SHA-256 signature, is a cryptographic representation of a file's static contents. While file hashes are vital host-based indicators of compromise used to identify malicious binaries on endpoints, they do not represent network-level communication telemetry like IP addresses or port numbers.

  • ✗

    Email indicator

    Why it's wrong here

    Email indicators of compromise specifically encompass elements found within email headers and bodies, such as sender addresses, subject lines, attachment names, and malicious URLs embedded in the message. Although phishing emails are common delivery vectors for malware, raw IP addresses observed during active runtime execution are classified as network indicators rather than email-specific metadata.

  • ✗

    Domain name

    Why it's wrong here

    Although domain names are also categorized as network-based indicators of compromise, they represent human-readable alphanumeric strings resolved via DNS, such as malicious C2 domains. Because the specific artifact identified in this scenario is a raw IP address rather than a fully qualified domain name (FQDN), this classification is technically inaccurate.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.