Courseiva

CS0-003 Incident Response and Management Practice Question

During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?

⚠ Common exam trap

CompTIA CySA+ often tests the distinction between indicators of activity (network connections, file drops) and indicators of persistence (registry Run keys, scheduled tasks, services), and the trap here is that candidates confuse a common malware behavior (like connecting to a C2 server) with a mechanism that ensures the malware runs again after reboot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The registry modification to the Run key

The registry modification to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is the most indicative of persistence because this specific key is designed to automatically launch programs when a user logs in. By adding a value here, the malware ensures it executes on every system startup, which is the definition of persistence. In contrast, network connections and file drops are common during execution but do not inherently guarantee re-execution after a reboot.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The registry modification to the Run key

    Why this is correct

    The HKCU\Software\Microsoft\Windows\CurrentVersion\Run key causes the referenced program to execute automatically at user logon, establishing persistence across reboots. The outbound port 443 connection indicates command-and-control, and the dropped system32 DLL is a payload artefact, but only the Run key modification ensures the malware survives restarts.

  • ✗

    The network connection over port 443

    Why it's wrong here

    Outbound port 443 traffic indicates command-and-control or exfiltration, not persistence; it dies when the host reboots. It is tempting because beaconing to a remote IP is a classic network IOC, and it would be the right answer if the question asked which indicator reveals active communication with attacker infrastructure.

  • ✗

    The remote IP address

    Why it's wrong here

    A remote IP address identifies attacker infrastructure for blocking or hunting, but it grants no survival mechanism across reboots. It is tempting because IPs are easily actioned as firewall blocks, and it would be correct if the question asked which IOC enables immediate network containment of the campaign.

  • ✗

    The dropped DLL file hash

    Why it's wrong here

    A file hash identifies one specific DLL sample and changes with any recompilation, so it cannot indicate persistence behaviour. It is tempting because dropped artefacts are tangible evidence, but the Run registry key is the mechanism that executes the malware at logon, making that registry modification the persistence IOC.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.