Courseiva
mediumMultiple Choice

CS0-003 Practice Question: The SOC receives an alert from a network sensor…

The SOC receives an alert from a network sensor showing an internal host communicating with a known malicious IP over HTTPS. The analyst cannot find any process making outbound connections on the host. What should the analyst do next?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check for hidden processes or rootkits using specialized tools

The absence of a visible process making outbound connections suggests the presence of a rootkit or hidden process that evades standard detection. Using specialized tools to check for hidden processes or rootkits is the appropriate next step to identify the malicious activity before taking containment or remediation actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Capture a memory dump of the host

    Why it's wrong here

    A memory dump captures volatile process artefacts, but the analyst needs to identify the live connection's owning process first; dumping memory does not reveal the socket-to-PID mapping directly. It is tempting because memory forensics exposes injected or hidden code, and would be correct once a suspicious process is identified and must be preserved before termination.

  • ✗

    Block the IP at the firewall

    Why it's wrong here

    Blocking the IP stops the traffic but destroys the evidence needed to identify the compromised process and its persistence mechanism, leaving the host infected. It is tempting as immediate containment, and would be correct if the priority were halting active exfiltration rather than investigating an unresolved internal compromise.

  • ✓

    Check for hidden processes or rootkits using specialized tools

    Why this is correct

    A malicious outbound HTTPS connection with no visible owning process indicates the connection is hidden from standard process enumeration, typical of rootkit or kernel-level concealment. Specialised tools such as memory or kernel inspection utilities can reveal hidden processes that Task Manager or netstat alone would miss.

  • ✗

    Reimage the host immediately

    Why it's wrong here

    Reimaging destroys volatile and forensic evidence before the cause of the unexplained outbound connection is identified, and the compromise could recur. It is tempting as guaranteed eradication, and would be correct after the intrusion is scoped and the host is confirmed beyond remediation.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.