CS0-003 Incident Response and Management Practice Question
During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?
⚠ Common exam trap
CompTIA CySA+ often tests the distinction between indicators of activity (network connections, file drops) and indicators of persistence (registry Run keys, scheduled tasks, services), and the trap here is that candidates confuse a common malware behavior (like connecting to a C2 server) with a mechanism that ensures the malware runs again after reboot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The registry modification to the Run key
The registry modification to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is the most indicative of persistence because this specific key is designed to automatically launch programs when a user logs in. By adding a value here, the malware ensures it executes on every system startup, which is the definition of persistence. In contrast, network connections and file drops are common during execution but do not inherently guarantee re-execution after a reboot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The registry modification to the Run key
Why this is correct
The HKCU\Software\Microsoft\Windows\CurrentVersion\Run key causes the referenced program to execute automatically at user logon, establishing persistence across reboots. The outbound port 443 connection indicates command-and-control, and the dropped system32 DLL is a payload artefact, but only the Run key modification ensures the malware survives restarts.
- ✗
The network connection over port 443
Why it's wrong here
Outbound port 443 traffic indicates command-and-control or exfiltration, not persistence; it dies when the host reboots. It is tempting because beaconing to a remote IP is a classic network IOC, and it would be the right answer if the question asked which indicator reveals active communication with attacker infrastructure.
- ✗
The remote IP address
Why it's wrong here
A remote IP address identifies attacker infrastructure for blocking or hunting, but it grants no survival mechanism across reboots. It is tempting because IPs are easily actioned as firewall blocks, and it would be correct if the question asked which IOC enables immediate network containment of the campaign.
- ✗
The dropped DLL file hash
Why it's wrong here
A file hash identifies one specific DLL sample and changes with any recompilation, so it cannot indicate persistence behaviour. It is tempting because dropped artefacts are tangible evidence, but the Run registry key is the mechanism that executes the malware at logon, making that registry modification the persistence IOC.
Go deeper
Related to this question
Learn chapter
Microsoft Sentinel for CySA+
Key term
IOC
IOC stands for Indicator of Compromise, which is forensic evidence that a system has been breached or infected by malware.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.