CS0-003 Security Operations Practice Question
Which log source would best help detect an attacker using a domain generation algorithm (DGA) to communicate with a command and control server?
⚠ Common exam trap
CS0-004 often tests the misconception that firewall logs are sufficient for detecting C2, but DGA communication is best identified at the DNS layer before any IP connection is made.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DNS query logs
DNS query logs are the best source because DGA malware generates many pseudo-random domain names and attempts to resolve them to locate its C2 server. These queries appear as high volumes of unique, algorithmically generated domains (e.g., 'ajk3n4lkj.com') that often result in NXDOMAIN responses. Firewall logs only show IP connections, not the domain names, and cloud audit logs track API activity, not DNS. Authentication logs record login events, unrelated to DGA traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall logs
Why it's wrong here
While firewall logs provide valuable IP-to-IP connection details, port numbers, and traffic volume, they typically lack the application-layer domain name resolution details needed to identify DGA patterns. Without deep packet inspection or specific layer 7 logging enabled, firewalls cannot capture the specific domain queries initiated by the malware.
- ✗
Cloud audit logs
Why it's wrong here
Cloud audit logs, such as AWS CloudTrail or Azure Activity Logs, record API calls, resource provisioning, and configuration changes within a cloud environment. They do not capture internal or external DNS resolution requests made by compromised workloads, making them ineffective for spotting domain generation algorithms.
- ✓
DNS query logs
Why this is correct
DNS query logs record every domain resolution request made by internal hosts, capturing the specific high-entropy, randomized domain names characteristic of Domain Generation Algorithms (DGAs). Analyzing these logs allows security analysts to detect anomalous NXDOMAIN spikes and identify compromised systems attempting to contact dynamic command-and-control servers.
- ✗
Authentication logs
Why it's wrong here
Authentication logs track user login attempts, session establishments, privilege escalations, and credential usage across systems. Because they focus strictly on identity and access management events, they contain no network-level resolution data and cannot assist in identifying DGA-based command-and-control traffic.
Visual reference
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Log source
A log source is any system, device, or application that generates and records event data, such as timestamps and activities, for monitoring and security analysis.
Key term
Cloud Audit Logs
Cloud Audit Logs are a record of actions taken by users, services, and resources inside a cloud environment, capturing who did what, when, and from where.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.