mediumMultiple Choice
CS0-003 Practice Question: The SOC receives an alert from a network sensor…
The SOC receives an alert from a network sensor showing an internal host communicating with a known malicious IP over HTTPS. The analyst cannot find any process making outbound connections on the host. What should the analyst do next?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check for hidden processes or rootkits using specialized tools
The absence of a visible process making outbound connections suggests the presence of a rootkit or hidden process that evades standard detection. Using specialized tools to check for hidden processes or rootkits is the appropriate next step to identify the malicious activity before taking containment or remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Capture a memory dump of the host
Why it's wrong here
A memory dump captures volatile process artefacts, but the analyst needs to identify the live connection's owning process first; dumping memory does not reveal the socket-to-PID mapping directly. It is tempting because memory forensics exposes injected or hidden code, and would be correct once a suspicious process is identified and must be preserved before termination.
- ✗
Block the IP at the firewall
Why it's wrong here
Blocking the IP stops the traffic but destroys the evidence needed to identify the compromised process and its persistence mechanism, leaving the host infected. It is tempting as immediate containment, and would be correct if the priority were halting active exfiltration rather than investigating an unresolved internal compromise.
- ✓
Check for hidden processes or rootkits using specialized tools
Why this is correct
A malicious outbound HTTPS connection with no visible owning process indicates the connection is hidden from standard process enumeration, typical of rootkit or kernel-level concealment. Specialised tools such as memory or kernel inspection utilities can reveal hidden processes that Task Manager or netstat alone would miss.
- ✗
Reimage the host immediately
Why it's wrong here
Reimaging destroys volatile and forensic evidence before the cause of the unexplained outbound connection is identified, and the compromise could recur. It is tempting as guaranteed eradication, and would be correct after the intrusion is scoped and the host is confirmed beyond remediation.
Go deeper
Related to this question
Learn chapter
Attack Simulation Tools: Atomic Red Team
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Rootkit
A rootkit is a type of malware that hides its presence and the presence of other malicious software on a computer, often by modifying the operating system itself.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.