hardMultiple Select
CS0-003 Practice Question: A host is suspected of running fileless malware
A host is suspected of running fileless malware. Which artefacts should be collected quickly? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that fileless malware leaves no artifacts at all, leading candidates to overlook memory and live response data, or to choose irrelevant options like cafeteria purchases that seem like a distractor but have no forensic value.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Memory image or live response data
Fileless malware operates in memory without writing to disk, so capturing a memory image or live response data preserves the malicious code, injected DLLs, and process hollowing artifacts that would vanish on reboot. Active network connections and running processes reveal the malware's C2 communications and its in-memory execution context, which are critical for identifying the infection vector and scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Memory image or live response data
Why this is correct
Fileless malware resides primarily in volatile memory (RAM) or executes via legitimate system tools like PowerShell or WMI without writing traditional files to the disk. Capturing a memory image or gathering live response data is critical because rebooting or shutting down the system will destroy this volatile evidence, preventing successful forensic reconstruction.
- ✓
Active network connections and running processes
Why this is correct
Analyzing active network connections and running processes allows analysts to identify anomalous outbound traffic, unauthorized listening ports, and suspicious parent-child process relationships. This live state data captures the real-time behavior of the fileless threat, which often relies on active network sockets to maintain command-and-control channels.
- ✗
A list of cafeteria purchases
Why it's wrong here
Financial transactions, such as a list of cafeteria purchases, do not contain any technical indicators of compromise, network metadata, or system state information. While physical security or insider threat investigations might occasionally leverage administrative records, these purchases are entirely unrelated to the technical analysis of fileless malware execution.
- ✗
A printed office map
Why it's wrong here
A printed office map represents physical facility layout data rather than digital forensic evidence. It cannot preserve host compromise indicators, volatile memory states, or network configurations, making it completely useless for identifying or analyzing fileless malware running on an endpoint.
Go deeper
Related to this question
Learn chapter
DDoS Attack Incident Response
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Fileless malware
Fileless malware is a type of malicious activity that uses legitimate system tools and memory to execute attacks, leaving no traditional file on the hard drive.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.