CompTIA CySA+ CS0-003 (V3) Practice Question

A security analyst is reviewing network flow data from a critical web server. The analyst observes a consistent, low-volume, hourly outbound connection over TCP port 443 to an IP address with no associated domain name and a poor reputation score. The server also shows a 15% increase in CPU usage and a large volume of successful authentication logs from the corporate IP range. Which finding is the strongest indicator of a potential command-and-control (C2) channel?

  • The use of TCP port 443 for the outbound connection

  • The large volume of successful authentications

  • The 15% increase in CPU usage

  • The consistent, low-volume connection to the low-reputation IP

CompTIA CySA+ CS0-003 (V3)
Incident Response and Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot