Courseiva
hardMultiple Select

CS0-003 Practice Question: A host is suspected of running fileless malware

A host is suspected of running fileless malware. Which artefacts should be collected quickly? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that fileless malware leaves no artifacts at all, leading candidates to overlook memory and live response data, or to choose irrelevant options like cafeteria purchases that seem like a distractor but have no forensic value.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Memory image or live response data

Fileless malware operates in memory without writing to disk, so capturing a memory image or live response data preserves the malicious code, injected DLLs, and process hollowing artifacts that would vanish on reboot. Active network connections and running processes reveal the malware's C2 communications and its in-memory execution context, which are critical for identifying the infection vector and scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Memory image or live response data

    Why this is correct

    Fileless malware resides primarily in volatile memory (RAM) or executes via legitimate system tools like PowerShell or WMI without writing traditional files to the disk. Capturing a memory image or gathering live response data is critical because rebooting or shutting down the system will destroy this volatile evidence, preventing successful forensic reconstruction.

  • ✓

    Active network connections and running processes

    Why this is correct

    Analyzing active network connections and running processes allows analysts to identify anomalous outbound traffic, unauthorized listening ports, and suspicious parent-child process relationships. This live state data captures the real-time behavior of the fileless threat, which often relies on active network sockets to maintain command-and-control channels.

  • ✗

    A list of cafeteria purchases

    Why it's wrong here

    Financial transactions, such as a list of cafeteria purchases, do not contain any technical indicators of compromise, network metadata, or system state information. While physical security or insider threat investigations might occasionally leverage administrative records, these purchases are entirely unrelated to the technical analysis of fileless malware execution.

  • ✗

    A printed office map

    Why it's wrong here

    A printed office map represents physical facility layout data rather than digital forensic evidence. It cannot preserve host compromise indicators, volatile memory states, or network configurations, making it completely useless for identifying or analyzing fileless malware running on an endpoint.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.