CS0-003 Incident Response and Management Practice Question
During dynamic analysis of a suspicious file in a sandbox environment, which THREE behaviors are considered indicators of compromise (IOCs) that suggest malicious activity? (Choose THREE.)
⚠ Common exam trap
The trap is selecting behaviors that seem suspicious but are actually benign, such as a file reading itself; candidates may overestimate the maliciousness of self-referential actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating a registry run key to achieve persistence.
Option A is correct because creating a registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run) is a classic persistence mechanism that causes malware to execute automatically at user logon or system startup, making it a strong IOC. Option B is correct because outbound network connections to a known malicious IP indicate command-and-control (C2) communication, data exfiltration, or payload retrieval, which are hallmark malicious behaviors observed during sandbox dynamic analysis. Option D is correct because dropping an executable into the Startup folder (e.g., %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) establishes persistence by launching the file automatically at user logon, another well-known IOC. Option C is not an IOC because a file reading its own content is common benign behavior (e.g., self-verification, configuration parsing) and does not by itself indicate malicious activity. Option E is not an IOC because opening a pre-existing text file is normal, expected behavior for many legitimate applications and lacks the persistence, network, or payload-dropping characteristics of malicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creating a registry run key to achieve persistence.
Why this is correct
A registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is an autostart extension point that launches a specified executable at user logon. Malware frequently adds entries here to achieve persistence, ensuring the malicious code runs on every subsequent login. Sandbox analysis treats this as high-risk because legitimate programs rarely modify such keys during a single execution, especially with randomly named or masqueraded values.
- ✓
Outbound network connections to a known malicious IP.
Why this is correct
During dynamic analysis, the sandbox monitors all outbound traffic for indicators of compromise. A connection to a known malicious IP address strongly suggests command-and-control (C2) communication, data exfiltration, or retrieval of additional payloads. This is a critical behavioral signature, as even files that perform no file system writes may be conducting covert network activity that aligns with threat intelligence.
- ✗
The file reading its own content.
Why it's wrong here
An executable reading its own content is commonly seen in legitimate software for integrity checks, resource extraction, or digital signature verification. This action does not modify the system, create persistence, or communicate externally, so it is not inherently malicious. In a sandbox, it may be an anti-tampering technique, but without other suspicious behaviors, it is insufficient to classify the sample as malware.
- ✓
Dropping an executable file in the startup folder.
Why this is correct
The Windows Startup folder (e.g., shell:startup) is a user-level autostart location that runs any executable or shortcut at logon. Malware often drops a payload here to establish persistence without requiring elevated privileges or registry changes. Sandbox detonation flags this because it creates a persistent file system artifact that ensures malicious code executes on future login sessions, a classic persistence technique.
- ✗
Opening a text file that was already present.
Why it's wrong here
Opening a text file that already exists on the system is typical benign behavior, as many programs read configuration files, documentation, or data samples during normal operation. This action involves no writes to autostart locations, no modification of system settings, and no external communication. Without additional malicious context, such a file read is considered neutral and does not indicate compromise.
Go deeper
Related to this question
Learn chapter
User and Entity Behaviour Analytics (UEBA)
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.