CS0-003 Incident Response and Management Practice Question
Which of the following is an example of a behavioral indicator of compromise (IOC) observed during dynamic malware analysis?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Outbound network connection to a known malicious IP
Dynamic analysis monitors behavior such as network connections, file system changes, and process creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PE section names
Why it's wrong here
PE section names (e.g., .text, .rdata, .UPX0) are extracted by parsing the portable executable header without ever running the sample, so they belong to static analysis. A behavioral IOC requires observing the program actually execute in a sandbox, which section names alone never demonstrate.
- ✗
File hash
Why it's wrong here
A cryptographic hash such as MD5 or SHA-256 is computed directly from the binary's bytes on disk and identifies a specific file instance, making it a static IOC used for signature matching and threat-intel lookups rather than an artifact of runtime behavior.
- ✗
Domain name
Why it's wrong here
A domain name harvested from strings, config blocks, or threat feeds is a fixed data point tied to infrastructure attribution and can be checked before detonation, so on its own it is classified as a static/atomic IOC rather than something derived from observed process behavior.
- ✓
Outbound network connection to a known malicious IP
Why this is correct
Watching the sample actually open a socket and beacon out to a known-bad IP during sandbox detonation is a runtime action captured by network monitoring tools like Wireshark or Cuckoo, exemplifying a behavioral IOC because it reflects what the malware does, not just what it is.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Malware analysis
Malware analysis is the process of examining malicious software to understand its behavior, origin, and impact, enabling defenders to detect, contain, and prevent future attacks.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.