Triage BoardGet the app

Domain 1 · Security Operations

Tools that find malicious activity

Security analysis tools on CS0-004 come down to two questions: which tool to reach for, and what its output proves (objective 1.3). The list runs from packet capture and intrusion detection through threat-intel platforms, endpoint telemetry, file analysis and sandboxes to regular expressions and scripting, and the exam rewards knowing what each one cannot see.

  • Exam code CS0-004
  • Domain weight 34%
  • Tickets here 16

What 1.3 covers and how it shows up

1.3 is a “given a scenario” objective in the CS0-004 exam objectives (version 2.0, checked October 2026). Expect output more than definitions: a capture summary, a detection rule, a command line, a regex, a JSON or EVTX record. CompTIA's own examples of performance-based questions (PBQs) for CS0-004 include analyzing SIEM alerts, reviewing logs and investigating IoCs (CompTIA’s CS0-004 FAQ, June 12, 2026).

Keep 1.3 apart from objective 2.2. Nmap, Nessus, Burp Suite and the cloud scanners belong to vulnerability assessment tools; 1.3 is about finding an attacker who is already active.

The tool list, grouped by what it reads

CS0-004 objective 1.3 tools: input and output
GroupNamed toolsReadsGives you
Packet captureWireshark, tcpdumpPacketspcap files, decoded sessions
Network detectionSnort, Suricata, ZeekLive trafficAlerts (Snort, Suricata), protocol logs (Zeek)
CorrelationSIEMLogs from many sourcesCorrelated alerts, searches
Threat-intel platformsOTX, MISP, OpenCTIShared indicators and reportsEnrichment and feeds
Endpoint detectionEDR, XDRProcess, file, registry, network eventsDetections, host isolation
Device managementMDMDevice inventory and settingsCompliance state, remote lock or wipe
LookupsWHOIS, AbuseIPDB, GeoIP, MXToolboxRegistration, abuse reports, location, mail DNSContext for an IP or domain
File analysisstrings, VirusTotal, YARA, CyberChefFiles and encoded dataReadable text, verdicts, rule matches, decoded output
SandboxesJoe Sandbox, CuckooA sample, executed in isolationA behavior report
Behavior analyticsUEBA (for example OpenUBA)User and entity activityDeviation from baseline
Scripting and formatsPython, PowerShell, shell; JSON, XML, YAML, EVTXAnything you can parseFiltered, reshaped data

Signature IDS, network monitor or file rule

Snort and Suricata, Zeek and YARA compared
PointSnort / SuricataZeekYARA
Looks atNetwork trafficNetwork trafficFiles and memory
Main outputAlerts; blocks when inlineStructured logs per protocolMatches against a rule
Rule styleSignatures for traffic patternsEvent-driven scriptsStrings plus a condition
Typical exam useWhich alert fired and whyWhich log holds the recordClassifying a malware family
Stops trafficYes, in inline IPS modeNot its main roleNo

Documentation: Suricata docs, Zeek docs, YARA docs (checked October 2026).

Reading the output, tool by tool

tcpdump and Wireshark

The two use different filter languages, and distractors swap them. tcpdump takes Berkeley Packet Filter capture filters such as host 192.0.2.10 and port 53, with -i for the interface, -n to skip name resolution, -w to write a file and -r to read one. Wireshark display filters look like ip.addr == 192.0.2.10 && dns and only hide packets already captured (tcpdump manual, Wireshark filter reference).

Zeek

Zeek writes one log per protocol: conn.log for every connection with duration and byte counts, dns.log for queries and answers, and more. Long, regular connections in conn.log and odd query names in dns.log lead into DNS tunneling, DGA and fast flux.

SIEM, EDR and the rest of the stack

A SIEM correlates what other tools send it; EDR sees inside one host; XDR stitches endpoint, network, cloud and email together. The boundaries are drawn in SIEM vs SOAR vs EDR (and XDR, UEBA). Threat-intel platforms such as MISP and OpenCTI connect this objective to threat intelligence and hunting.

Files, encodings and lookups

strings pulls readable text out of a binary. CyberChef decodes layers (Base64, hex, XOR, URL encoding), and an obfuscated command in an exhibit is often one Base64 step from readable. MXToolbox reads a domain's MX, SPF and DMARC records, which settles whether a sender is authorized.

Scripting

You will read code more than write it. Recognize PowerShell queries such as Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625} (failed logons), a Python loop over JSON events, and the shape of an EVTX record next to the same event in JSON. Which sources produce those records in the first place is covered in architecture and logging for security operations.

Regex patterns to read on sight

regexPatterns an exhibit may quote, each followed by what it matches
\b(?:\d{1,3}\.){3}\d{1,3}\b        # IPv4-shaped text, also 999.0.0.1example.com                          # unescaped dot: also matches exampleXcomexample\.com                         # literal dot^Failed password for (\S+) from (\S+) # captures user and source address\b[A-Fa-f0-9]{64}\b                  # a SHA-256 hash(?i)powershell(\.exe)?\s+-e(nc)?\s   # PowerShell with an encoded command

An unescaped dot matches any single character. In a detection rule that silently widens the match; in an allow-list it can let a lookalike through.

Uploading a file shares itTrap

Submitting a file to a public multi-engine scanner such as VirusTotal makes it available to other subscribers of that service. For an internal document or a sample that may contain company data, search by hash first. Options that upload sensitive material for a quick verdict are written to look efficient.

Run the tools, then answer

Start with the tool output on the ticket, whether it is a command line, a packet capture or a sandbox summary, and decide what it shows before reading the options.

Ticket 1 / 16

0 right

INC-001

Which log file in Zeek records HTTP requests made by devices on the network?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. Aconn.log records a summary of every TCP, UDP, and ICMP connection, not the details of HTTP requests.
  2. BCorrect: Zeek writes HTTP request details, such as host, URI, method, user agent, and status code, to http.log.
  3. Cweird.log records unusual or malformed protocol activity that Zeek's parsers could not handle normally.
  4. Ddns.log records DNS queries and responses only; it holds no HTTP request data.

INC-002

What two primary components do NIDS signature rules have?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: A Snort-style NIDS rule has a header (action, protocol, addresses, ports, direction) and options in parentheses (content matches, message, SID, and other criteria).
  2. BRules describe what to match in a packet, but 'packet' is not a section of the rule.
  3. CRules have no footer section; everything after the header is the options block.
  4. D'TCP rules' is not a rule component; TCP is just one protocol value that can appear in the header.

INC-003

You need to capture live network traffic on a Linux system for analysis. Which command should you use?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. Aifconfig shows and configures network interfaces; it does not capture traffic.
  2. Bnetstat lists connections, listening ports, and statistics, but it does not capture packet contents.
  3. Cping tests whether a host is reachable with ICMP echo requests; it does not capture traffic.
  4. DCorrect: tcpdump captures live packets from an interface and can save them to a pcap file with -w for later analysis.

INC-004

Examine the packet capture table. Which flows represent fully established TCP sessions?

Exhibit

FlowTimestampFlags SequenceLength (bytes)
Flow110:01:00SYN only60
Flow210:01:01SYN, SYN/ACK, ACK60, 60, 52
Flow310:01:02SYN, RST60, 40
Flow410:01:03SYN, SYN/ACK, ACK, PSH/ACK60, 60, 52, 200

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASYN followed by any ACK is a loose rule; a session is established only after the full SYN, SYN/ACK, ACK sequence, not just any ACK.
  2. BCorrect: Flows 2 and 4 both complete the three-way handshake (SYN, SYN/ACK, ACK), and Flow 4 then carries data with PSH/ACK.
  3. CPacket count is not the test; a flow could have three packets without completing the handshake.
  4. DEvery flow starts with a SYN, including Flow 1 (no reply) and Flow 3 (reset), so a SYN alone proves nothing.

INC-005

Which option for the find command will return files that were modified within the last 7 days?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. A-size matches files by size and ignores when they were modified.
  2. B-name matches files by name pattern and says nothing about modification time.
  3. C-type matches by file type, such as regular file or directory.
  4. DCorrect: -mtime -7 matches files whose content was modified less than 7 days ago.

INC-006

An administrator needs to monitor the active connections and identify applications that established these connections on a Linux system. Which command should they use?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. Anetstat -ano is the Windows form; it shows the owning process ID but not the program name, and Linux netstat does not use -o that way.
  2. B-v only makes the output more verbose; it does not map connections to programs.
  3. C-s prints per-protocol statistics and lists no individual connections.
  4. DCorrect: On Linux, -n shows numeric addresses, -a shows all sockets, and -p adds the PID and program name that owns each connection.

INC-007

Which type of monitoring inspects data flow at the network perimeter without examining the data payload within each packet?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: flow analysis looks at metadata such as addresses, ports, protocols, timing and byte counts, without opening packet payloads.
  2. BHeuristic analysis judges behavior or code against rules of thumb, and it often needs to inspect content.
  3. CSignature-based detection matches known patterns, usually inside packet payloads, so it does examine the data.
  4. DPacket analysis captures and decodes full packets, payload included, the opposite of what the stem describes.

INC-008

An analyst receives a potentially malicious executable from a phishing email triage. To ensure safety and maximize intelligence gathering before any dynamic detonation, which sequence represents the correct non-executive triage procedure?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Hashing, string extraction, PE header review, and checks for packing are static steps that run nothing, so they are the safe first pass before any detonation.
  2. BRunning the file in a debugger is dynamic analysis, which the scenario says comes later.
  3. CPatching import tables modifies the sample, and entropy is calculated from the file itself; 'dynamic execution entropy' is not a static triage step.
  4. DA disassembler does not execute a binary, and dropped files only exist after execution, so this sequence assumes the file has already run.

INC-009

A proposed sandbox allows malware to resolve external DNS and initiate outbound HTTPS. Which configuration gap most undermines safe dynamic analysis?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ABlocking egress and allowing only local DNS is a safe configuration and leaves no gap.
  2. BRedirecting outbound traffic to a logged internal sinkhole is a recommended practice, so it is no gap.
  3. CCorrect: Without egress controls or sinkholing, the sample can reach real C2 servers, alert the attacker, download more payloads, or attack other systems.
  4. DRunning the sample with admin rights and logging file writes is common in a sandbox; it is not the gap that lets malware reach live C2.

INC-010

Sandbox output shows a sample with multiple AV detections, YARA behavioral strings matching known C2, and observed callbacks to three distinct external hosts. What confidence level applies and what action follows?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AHigh confidence is right, but waiting for user confirmation delays containment that the evidence already justifies.
  2. BSeveral independent signals agree, so low confidence understates the evidence, and more AV scans add little.
  3. CAV detections, a YARA match to known C2, and real callbacks are more than medium confidence, and monitoring alone lets the threat continue.
  4. DCorrect: Independent signals that agree, AV detections, a YARA C2 match, and observed callbacks, give high confidence, so the next step is isolating the affected host.

INC-011

During urgent triage of a suspected campaign, WHOIS shows recent domain registration. Why should passive DNS history be consulted next?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Passive DNS shows which IPs and domains the indicator has resolved to over time, which quickly links the new domain to related campaign infrastructure.
  2. BWHOIS gives registration details only, which can be privacy-protected or fake, and has no resolution history.
  3. CPassive DNS is not slower than WHOIS, and speed is not the reason to choose either one.
  4. DStopping after WHOIS leaves infrastructure links unknown, which is exactly what a campaign investigation needs.

INC-012

An analyst receives an impossible travel alert for a user logging in from domestic and foreign IPs simultaneously. What is the most appropriate first action?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AIsolating the workstation before confirming the alert can disrupt a legitimate user, and the alert concerns a sign-in, not necessarily a compromised workstation.
  2. BA password reset is a reasonable containment step only after the alert is validated; doing it first may respond to a false positive.
  3. CCorrect: Impossible travel alerts often come from VPNs, proxies, or outdated GeoIP data, so the first step is to confirm the location data is accurate before acting.
  4. DEscalating before basic validation sends possible false positives to the response team.

INC-013

A SOC analyst suspects a specific malicious user-agent string is being used for C2. Which combination of data sources and pivot sequence best confirms compromised hosts while minimizing noise?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ANetFlow has no user-agent strings, and vulnerability scan output does not show C2 activity.
  2. BDNS logs do not contain user-agent strings, and WHOIS describes domains without saying which internal hosts are compromised.
  3. CCorrect: Proxy logs show which hosts sent the suspicious user-agent, and EDR process telemetry then confirms which process on each host made the request.
  4. DFirewall logs lack HTTP user-agent data, and SIEM alerts depend on rules that may not yet cover this string.

INC-014

Which of the following commands will search for the patterns "error-a", "error-b", and "error-c" in a log file named logs.txt?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: The bracket expression [abc] matches exactly one of a, b, or c, so the pattern matches error-a, error-b, and error-c.
  2. B^ anchors to the start of a line, so placing it in the middle of the pattern does not create a character set.
  3. C$ anchors to the end of a line, and inside double quotes the shell may expand $abc as a variable, so this does not match the three strings.
  4. D* repeats the preceding character zero or more times; it does not choose between a, b, and c.

INC-015

Which line shows data from one command piped into another command in Windows PowerShell?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. A& is not the pipeline operator; in PowerShell it is the call operator, and a trailing & starts a background job in PowerShell 7.
  2. B> redirects output to a file, so this would write to a file named Sort-Object instead of passing objects to the cmdlet.
  3. C>> appends output to a file instead of passing it to another command.
  4. DCorrect: The pipe | sends the objects from Get-Process into Sort-Object, which sorts them by CPU.

INC-016

A security analyst is reviewing a triage report for a novel polymorphic payload. Traditional antivirus marked the file as clean, but other security controls flagged suspicious activities. Based on the detection matrix, what is the best justification for escalating this alert to incident response?

Exhibit

Security ControlVerdictConfidenceKey Indicator
AntivirusCleanHighNo signature database match
EDRSuspiciousMediumSpawning cmd.exe from winword.exe
Network IDSMaliciousHighOutbound connection to known C2 IP
SandboxMaliciousHighProcess hollowing and registry persistence

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: The EDR, network IDS, and sandbox results agree with each other, and a clean AV verdict is expected for a novel polymorphic sample, so the combined evidence justifies escalation.
  2. BSignature-based AV is weakest against novel polymorphic malware, because the signature does not exist yet.
  3. CMedium-confidence EDR alerts should be correlated with other evidence instead of being dismissed because one scanner found nothing.
  4. DA clean AV result cannot prove that a high-confidence IDS hit to a known C2 IP is a false positive.

Shift tally

0 / 0

Before exam day, be able to

  • Read tcpdump flags -i, -n, -w, -r and a BPF filter
  • Write a Wireshark display filter for one host and one protocol
  • Name the Zeek logs for connections and DNS
  • Tell a YARA rule from a network IDS rule by its target
  • Spot Base64 and decode it in CyberChef
  • Read a JSON event and the matching EVTX record
  • Write a regex with an escaped dot and a capture group
  • Explain each tool's blind spot, then test it on the PBQ format guide

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.