Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

Which log source would best help detect an attacker using a domain generation algorithm (DGA) to communicate with a command and control server?

⚠ Common exam trap

CS0-004 often tests the misconception that firewall logs are sufficient for detecting C2, but DGA communication is best identified at the DNS layer before any IP connection is made.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS query logs

DNS query logs are the best source because DGA malware generates many pseudo-random domain names and attempts to resolve them to locate its C2 server. These queries appear as high volumes of unique, algorithmically generated domains (e.g., 'ajk3n4lkj.com') that often result in NXDOMAIN responses. Firewall logs only show IP connections, not the domain names, and cloud audit logs track API activity, not DNS. Authentication logs record login events, unrelated to DGA traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall logs

    Why it's wrong here

    While firewall logs provide valuable IP-to-IP connection details, port numbers, and traffic volume, they typically lack the application-layer domain name resolution details needed to identify DGA patterns. Without deep packet inspection or specific layer 7 logging enabled, firewalls cannot capture the specific domain queries initiated by the malware.

  • ✗

    Cloud audit logs

    Why it's wrong here

    Cloud audit logs, such as AWS CloudTrail or Azure Activity Logs, record API calls, resource provisioning, and configuration changes within a cloud environment. They do not capture internal or external DNS resolution requests made by compromised workloads, making them ineffective for spotting domain generation algorithms.

  • ✓

    DNS query logs

    Why this is correct

    DNS query logs record every domain resolution request made by internal hosts, capturing the specific high-entropy, randomized domain names characteristic of Domain Generation Algorithms (DGAs). Analyzing these logs allows security analysts to detect anomalous NXDOMAIN spikes and identify compromised systems attempting to contact dynamic command-and-control servers.

  • ✗

    Authentication logs

    Why it's wrong here

    Authentication logs track user login attempts, session establishments, privilege escalations, and credential usage across systems. Because they focus strictly on identity and access management events, they contain no network-level resolution data and cannot assist in identifying DGA-based command-and-control traffic.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.