Courseiva

CS0-003 Incident Response and Management Practice Question

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a workstation to an external IP address known for command and control (C2) activity. Which classification should the analyst assign to this incident?

⚠ Common exam trap

CS0-004 often tests the ability to distinguish between incident classifications based on observable indicators; candidates might confuse malware with data breach when seeing outbound traffic, but the key is that C2 communication indicates an active malware infection, not necessarily a confirmed data breach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Malware

The suspicious outbound traffic to a known C2 IP indicates that the workstation is likely infected with malware that is beaconing to its command and control server. This is a classic indicator of a malware infection, where the compromised host communicates with an external entity for instructions or data exfiltration. Therefore, the incident should be classified as malware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Insider threat

    Why it's wrong here

    While an insider threat involves authorized users abusing their privileges or intentionally leaking data, the scenario describes outbound C2 traffic from a workstation. This pattern strongly points to an external threat actor controlling a compromised host rather than malicious or negligent actions by an authorized internal employee.

  • ✗

    Data breach

    Why it's wrong here

    A data breach specifically requires confirmed unauthorized access, acquisition, or exfiltration of sensitive information. Although the outbound connection to a known malicious IP is highly suspicious, classifying this immediately as a data breach is premature without forensic evidence of actual data transfer or exposure.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering vector used to harvest credentials or deliver payloads, typically initiated via email, SMS, or voice. Because the detection phase has flagged active network-layer communication with a command-and-control server rather than an incoming deceptive message, phishing is not the active incident type.

  • ✓

    Malware

    Why this is correct

    Outbound beaconing or persistent connections to a known command-and-control (C2) IP address are primary indicators of compromise (IoCs) associated with malware infections, such as trojans or botnet agents. Identifying this traffic during the detection and analysis phase allows analysts to confirm the presence of malicious software executing on the workstation.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.