Courseiva

CS0-003 Incident Response and Management Practice Question

Which of the following is an example of a behavioral indicator of compromise (IOC) observed during dynamic malware analysis?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Outbound network connection to a known malicious IP

Dynamic analysis monitors behavior such as network connections, file system changes, and process creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PE section names

    Why it's wrong here

    PE section names (e.g., .text, .rdata, .UPX0) are extracted by parsing the portable executable header without ever running the sample, so they belong to static analysis. A behavioral IOC requires observing the program actually execute in a sandbox, which section names alone never demonstrate.

  • ✗

    File hash

    Why it's wrong here

    A cryptographic hash such as MD5 or SHA-256 is computed directly from the binary's bytes on disk and identifies a specific file instance, making it a static IOC used for signature matching and threat-intel lookups rather than an artifact of runtime behavior.

  • ✗

    Domain name

    Why it's wrong here

    A domain name harvested from strings, config blocks, or threat feeds is a fixed data point tied to infrastructure attribution and can be checked before detonation, so on its own it is classified as a static/atomic IOC rather than something derived from observed process behavior.

  • ✓

    Outbound network connection to a known malicious IP

    Why this is correct

    Watching the sample actually open a socket and beacon out to a known-bad IP during sandbox detonation is a runtime action captured by network monitoring tools like Wireshark or Cuckoo, exemplifying a behavioral IOC because it reflects what the malware does, not just what it is.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.