← Back

19 Investigation Tools & Threat Hunting Practice Questions & Answers

Every Investigation Tools & Threat Hunting practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.

Start practice test →
  1. 1. A security operations centre retains 7 days of full packet capture and 12 months of flow records. An investigation opens into traffic from 30 days ago, when an internal workstation exchanged data with an external address later identified as a command-and-control host. What can the analyst still establish from the surviving data?

    • A.That the sessions occurred and, from the flow records, which files were transferred, since flow summarises each payload it observes.
    • B.That the sessions occurred, with their times, duration, ports, direction and byte counts, but not the content that was carried.✓ Answer
    • C.Nothing useful, because flow records are discarded whenever the matching packet capture ages out of the retention window.
    • D.The full request and response bodies, because flow records store the first bytes of every session for exactly this purpose.

    Flow (session-summary) records keep metadata — addresses, ports, timestamps, duration and byte counts — and by design discard payload, so once the capture window has aged out the analyst can prove that the conversation happened and when, but can never recover what was sent. That asymmetry is why full capture is kept for days at high cost while flow is kept for months cheaply.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (packet capture vs. flow/session analysis); RFC 7011 (IPFIX) — flow records describe traffic metadata, not payloadReport a problem with this question

  2. 2. A user forwards a document attachment that the mail gateway delivered. Static inspection shows one macro that builds a long Base64 string at runtime, no readable URLs or domains, and a file digest that no reputation source recognises. What is the appropriate next step and why?

    • A.Detonate the document in an isolated instrumented environment, because the behaviour it builds at runtime is visible only on execution.✓ Answer
    • B.Upload the document to a public multi-engine scanner, because an unrecognised digest simply means the file must be added to those engines.
    • C.Close it as benign, because the mail gateway already delivered it and no reputation source flags the digest as malicious.
    • D.Push the digest to the endpoint fleet as a blocking indicator, because that neutralises the sample without the cost of any further analysis.

    Static inspection cannot see behaviour that a sample assembles only at execution time, so a document whose macro builds its payload at runtime has to be executed under observation — in an isolated, instrumented environment — to reveal the processes, files and network destinations it uses. An unrecognised digest means only that nobody has submitted that file before, and a gateway pass is not a verdict.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (static analysis vs. dynamic/sandbox detonation)Report a problem with this question

  3. 3. Only firewall, proxy and authentication logs are forwarded to the SIEM. An analyst must determine whether a spreadsheet application on one workstation started a scripting interpreter, and what that interpreter started in turn. Which source answers the question?

    • A.A SIEM correlation rule joining proxy and authentication events, which reconstructs the missing parent-child chain by timing.
    • B.A perimeter packet capture filtered to that workstation's address, which shows the interpreter's own image name in the session.
    • C.The endpoint agent's own process telemetry on that host, which records each process with its parent and its command line.✓ Answer
    • D.The proxy log entries for that workstation, which name the process that opened each outbound request alongside the URL.

    Process ancestry and command lines exist only in host-level telemetry: an endpoint agent records each process creation with its parent and arguments, which is exactly the question being asked. Network, proxy and authentication records describe connections and logons and never carry which process on the host initiated them, so no correlation rule over those sources can reconstruct a parent-child chain.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (endpoint detection and response telemetry vs. network and log sources)Report a problem with this question

  4. 4. An analyst writes a SIEM correlation rule: alert when one account authenticates successfully from two different countries within one hour. It now fires several hundred times a day, almost all on staff whose sessions egress through a cloud access gateway in another country and whose phones use foreign carrier addresses. What does this illustrate about correlation rules?

    • A.A rule of this kind cannot be written at all, because an account's country is derived data and no correlation engine may key on a derived field.
    • B.The logic is sound and the fix is simply a longer window, since widening the interval removes the coincidences that are creating the noise.
    • C.A rule expresses co-occurrence inside a window but not legitimacy, so it needs local context such as known egress ranges to be meaningful.✓ Answer
    • D.Correlation is the wrong construct here, because sequence and timing belong only to signature matching performed on raw network traffic.

    A correlation rule can express relationships between events — co-occurrence, ordering and thresholds inside a time window — but it has no concept of whether the relationship is legitimate, so fidelity comes from enriching it with knowledge of this environment, such as the organisation's own gateway egress ranges and expected carrier space. Widening the window would make the same rule match more pairs, not fewer.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (SIEM correlation and analysis; context enrichment for alert fidelity)Report a problem with this question

  5. 5. An analyst submits the SHA-256 digest of a suspicious executable to a file-reputation service, which answers 'not found'. The binary was written to disk an hour earlier by a process the endpoint agent had flagged as unusual. How should the 'not found' result be read?

    • A.The file has been assessed as clean by a very large corpus, so the host can be released to the user and the ticket can be closed.
    • B.No sample with that digest has been submitted before, which is expected for freshly built binaries, so local analysis must continue.✓ Answer
    • C.The service indexes a different digest algorithm, so recomputing the file's MD5 value returns the verdict that is genuinely held on it.
    • D.The file is packed, and because packing changes a digest it must be unpacked before any reputation service can return a verdict.

    A reputation lookup answers only one question: has anyone seen this exact byte sequence before. Absence is therefore not a clean verdict — attackers routinely recompile or pad a payload per target so that its digest is unique — and the correct move is local static and dynamic analysis together with the process lineage that wrote the file.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (hashing utilities and file reputation analysis; limits of digest-based verdicts)Report a problem with this question

  6. 6. A credential-phishing message reached three mailboxes, and the analyst wants to identify the infrastructure that actually delivered it in order to search for other recipients. The message carries a From display name matching an executive, a Reply-To at a free mail provider, an X-Originating-IP header, and a Received chain of five hops. Which element is the most reliable pivot?

    • A.The X-Originating-IP header, since the sending client inserts its own true address there before the message leaves the network.
    • B.The Reply-To address, since replies must reach the operator and therefore resolve to the infrastructure that delivered the message.
    • C.The From display name, since gateways rewrite that field to the verified sending domain once authentication checks have completed.
    • D.The Received hop written by the organisation's own inbound gateway, since hops added upstream of it are supplied by the sender.✓ Answer

    Each receiving mail transfer agent prepends its own Received trace field, so the chain is trustworthy only from the first hop under your control downwards; everything above it, along with From, Reply-To and any X- header, is text the sender chose and can forge. The gateway's own hop therefore gives the address that genuinely delivered the message, which is the field to pivot on across the mail store.

    Source: RFC 5321 §4.4 (trace information: Received fields prepended by each receiving MTA); CompTIA CySA+ CS0-004 Obj. 1.3 (email header analysis)Report a problem with this question

  7. 7. A 4 GB packet capture was taken at a core switch's mirror port. The team must determine whether an internal application still transmits account credentials in the clear to a legacy service on TCP 23. Which technique answers that question?

    • A.Compute the capture file's digest and submit it to a reputation service to see whether this traffic is already known to be hostile.
    • B.Replay the capture through a signature-based sensor and treat the absence of any rule match as proof that the transport is encrypted.
    • C.Read the router's flow records for the same period and compare the byte count of each session against the size that is expected.
    • D.Open the capture in a protocol analyser, filter to TCP 23 and follow the stream to read the bytes the two hosts exchanged.✓ Answer

    Only full packet capture holds payload, and a protocol analyser can filter to the port and reassemble the application stream so the credential exchange is read exactly as it crossed the wire. Flow byte counts and signature hits describe that sessions existed or matched a rule, but neither can show which characters were transmitted, so neither can confirm or rule out cleartext authentication.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (packet capture and protocol analysis: stream reassembly)Report a problem with this question

  8. 8. A sample detonated in an automated analysis environment exits after two minutes with no files written and no network connections. Static strings from the same binary include names of virtualisation drivers, a check for installed office documents, and a long sleep call. What is the best conclusion and next action?

    • A.The sample probably recognised the analysis environment; extend the run and add realistic host artefacts before recording any verdict.✓ Answer
    • B.The static strings are a false lead, since compilers embed driver names routinely; submit the binary to more analysis services instead.
    • C.The environment failed; rebuild it and replay the same two-minute run, because evasion checks cannot survive a clean rebuild of the host.
    • D.The sample is inert; record it as benign and add its digest to the environment's allowlist so that future runs are not repeated.

    Sandbox-aware malware looks for virtualisation artefacts, an implausibly empty user profile or a short observation window and simply sleeps through it, so silence in an instrumented run is not evidence that a sample is harmless; the strings recovered here are precisely those checks. The analysis environment has to be given more time and made to look and behave like a used workstation before any verdict is recorded.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (dynamic analysis and sandbox-evasion behaviour)Report a problem with this question

  9. 9. An endpoint agent records this command line on a workstation: powershell.exe -nop -w hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoA... , and the parent process is a mail client. Which step establishes the intent of this execution fastest?

    • A.Decode the Base64 argument offline and read the reconstructed script, which names the objects and the addresses it would contact.✓ Answer
    • B.Search the encoded string itself against indicator feeds, since an encoded argument is the durable artefact that defenders exchange.
    • C.Run the whole command line on a spare workstation and watch the console output, since the script prints whatever it is fetching.
    • D.Submit powershell.exe itself to a reputation service, since a verdict on the interpreter establishes whether this run was hostile.

    An encoded command argument is obfuscation, not encryption: decoding the Base64 to text offline reconstructs the script and immediately exposes the destinations and actions it would perform, with nothing executed. The blob itself changes with every build so it is a poor indicator, and the interpreter is a legitimate signed system binary, which is why this living-off-the-land pattern must be judged on parent process and command line rather than on file reputation.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (decoding obfuscated payloads; abuse of living-off-the-land binaries)Report a problem with this question

  10. 10. A hunt team needs, for every connection on a monitored segment over the last month, a record of protocol, duration, bytes and the server name requested in each TLS handshake. Storing payload for a month is not affordable. Which monitoring approach meets the requirement?

    • A.A signature-based sensor on the same span, whose alert records already describe every connection the segment carried during the month.
    • B.The routers' flow records, which list the server name from each handshake alongside the addresses, ports and byte counts per session.
    • C.A passive sensor that parses traffic and writes per-connection protocol metadata logs, including handshake fields, but keeps no payload.✓ Answer
    • D.Full packet capture kept for a month at reduced resolution, by truncating every packet to its first bytes and discarding the remainder.

    A network-security-monitoring sensor parses live traffic and writes one compact protocol log per connection, including application-layer fields such as the requested server name, which is what makes a month of searchable history possible without storing payload. Signature sensors log only rule matches, and router flow records carry the five-tuple, timing and counts but no application-layer content at all.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3 (network security monitoring: protocol metadata logging vs. signature IDS vs. flow data)Report a problem with this question

  11. 11. Six workstations in different departments each opened outbound TLS sessions to different external addresses. In every session the server presented a self-signed certificate with the same fingerprint, an issuer string of 'localhost' and a two-year validity. What does this support, and how should the analyst pivot?

    • A.Six unrelated misconfigured internal services are being reached; correct each certificate and no further investigation is warranted here.
    • B.The sessions cannot be assessed without decryption; deploy inspection on the egress path before drawing any conclusion from them.
    • C.One toolkit is in use across the six hosts; hunt on the certificate fingerprint to find further sessions and additional addresses.✓ Answer
    • D.The addresses are the durable artefact here; block all six at the perimeter and treat the certificate detail as incidental noise.

    A server certificate fingerprint is an artefact of the attacker's own tooling, so one identical self-signed certificate appearing across unrelated hosts and unrelated addresses ties those sessions to a single toolkit. That makes the fingerprint a far stronger pivot than any one address, which an operator can rotate in minutes, and it can be hunted historically without decrypting anything.

    Source: CompTIA CySA+ CS0-004 Obj. 1.3–1.4 (certificate and host artefacts as investigative pivots; Pyramid of Pain — tooling artefacts outrank addresses)Report a problem with this question

  12. 12. A sector report describes an intrusion set: initial access through a flaw in one vendor's remote-access appliance, then abuse of the victim's identity provider to mint long-lived tokens, then staging in a cloud storage service. It lists 60 addresses and 8 hashes. The reading organisation runs a different appliance vendor but the same identity provider and storage service. What makes this report actionable there?

    • A.The identity and storage steps map to technology in use, so those behaviours can become local detections and configuration checks.✓ Answer
    • B.None of it applies, because the remote-access appliance named as the entry point is not deployed anywhere in this environment.
    • C.All of it applies equally, because an intrusion-set report describes an adversary rather than the particular products a victim ran.
    • D.The 60 addresses and 8 hashes are the actionable part, so blocking every one of them is the step that matters most on receipt.

    Intelligence becomes actionable when it can change something in this environment, so the reported steps that touch technology actually deployed — token issuance abuse at the identity provider and staging in the cloud storage service — can be converted into detections, hunts and configuration checks. Indicators tied to an appliance nobody runs are context worth reading, not work worth doing, and a bulk block of stale addresses is effort without coverage.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (threat intelligence properties: relevance and applicability to the environment)Report a problem with this question

  13. 13. An intelligence report lists 40 addresses, 12 domains, 3 file hashes and one described behaviour: a signed scripting host creating a scheduled task named to resemble a vendor update job. Six weeks later 38 of the addresses no longer answer and all 3 hashes have changed. Which element still carries detection value, and why?

    • A.The addresses the report lists, because infrastructure reuse between campaigns makes address lists the most durable content of such reports.
    • B.The file hashes the report lists, because a compiled payload must stay byte-identical for the campaign's own loader to run it on each victim.
    • C.The domain names the report lists, because registration and certificate costs make a domain the hardest artefact to replace at short notice.
    • D.The behaviour the report describes, because rebuilding a working persistence routine costs an adversary far more than rotating infrastructure.✓ Answer

    Addresses, domains and file hashes are cheap for an adversary to rotate, which is why they expire quickly, whereas a working persistence routine represents engineering effort and operator habit, so a detection written on that behaviour keeps firing after the infrastructure and the binaries change. This ordering of artefact durability, from trivially changed indicators up to tactics and techniques, is the whole point of the Pyramid of Pain.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (indicator durability); Pyramid of Pain (D. Bianco) — TTPs are the costliest artefacts for an adversary to changeReport a problem with this question

  14. 14. A single-source feed entry marks an address as active command-and-control, with low confidence and a first-seen date nine months old. The address belongs to a shared range at a large hosting provider, and the organisation's own telemetry shows no connection to it in the retained period. An analyst proposes adding it to the perimeter deny list today. Which response is sound?

    • A.Block it now, because a deny-list entry is cheap and reversible and a low-confidence indicator still outweighs an absent local sighting.
    • B.Keep it as a low-priority hunting lead and as detection enrichment, because blocking a shared address on low confidence breaks legitimate services.✓ Answer
    • C.Discard the entry entirely, because an item from a single source with low confidence has no place in any defensive workflow whatsoever.
    • D.Escalate it as a confirmed incident, because a command-and-control label from any feed means at least one host in scope is already compromised.

    Confidence and source reliability decide what an analyst does with a report, not merely whether it is filed: a single-source, low-confidence, nine-month-old entry on shared hosting space justifies enrichment and a retrospective hunt, while a perimeter block would also cut off every legitimate service sharing that address. The absence of any local sighting means nothing yet meets the bar for declaring an incident.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (intelligence confidence levels, source reliability and timeliness)Report a problem with this question

  15. 15. A team wants to share what it learned from an intrusion with a sector sharing community. The draft package contains the adversary's domains and a persistence technique description, and also internal hostnames, the affected employee's mailbox address and a link to the internal ticket. What is the right handling?

    • A.Share the package unchanged, because recipients need the raw material to judge it and can be trusted to discard the internal parts.
    • B.Share the adversary-attributable artefacts and the technique description, strip internal and personal identifiers, and state redistribution limits.✓ Answer
    • C.Share nothing until the intrusion is publicly disclosed, because any early release creates liability that outweighs the defensive benefit.
    • D.Share only the domains, because a technique description is proprietary detection logic that a sharing community has no legitimate use for.

    Sharing is useful only when the recipient receives adversary-attributable content — infrastructure and, above all, behaviour others can detect — and it is safe only when victim and internal detail is removed and handling and redistribution expectations are attached. Sanitising the package therefore satisfies both, whereas dumping it raw exposes the organisation and its employee and withholding it forfeits the defensive value.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (information sharing and collaboration; handling and redistribution designations)Report a problem with this question

  16. 16. A hunt is proposed as: 'look through DNS logs for anything unusual'. The hunt lead asks for it to be restated so that the result can be judged either way. Which restatement is a usable hypothesis?

    • A.DNS is being abused somewhere in the estate; we would see it by reviewing every domain resolved during the period, one by one.
    • B.An internal host is tunnelling data over DNS; we would see sustained long, high-entropy labels sent to one registered domain.✓ Answer
    • C.Some DNS answers are malicious; we would see it by alerting on every response that returns a name-error result to any internal client.
    • D.The resolver is generating more traffic than it did last quarter; we would see it as a rise in total query volume across all clients.

    A hunting hypothesis has to name a specific adversary behaviour, the telemetry that would carry it and the observable evidence that would confirm or refute it, so that the search can end in a defensible yes or no. 'Anything unusual' and 'abused somewhere' cannot be refuted and therefore produce browsing, while a volume trend and an alert on name-error responses measure something other than the behaviour in question.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (hypothesis-driven threat hunting; testing and documenting conclusions)Report a problem with this question

  17. 17. A hunt for a registry-based persistence technique searches 90 days of endpoint telemetry and finds nothing. The endpoint agent is installed on 82 percent of workstations and does record writes to the registry keys in question. What does the negative result legitimately support?

    • A.That the hunt was wasted effort, since a hunt only creates value when it ends in a confirmed finding that an incident case can act on.
    • B.That the environment is free of this persistence technique, so the hypothesis can be marked disproven and dropped from the hunt backlog.
    • C.That the behaviour is absent from the covered hosts for those 90 days, with the uncovered 18 percent and older activity still unknown.✓ Answer
    • D.That the agent's registry recording is faulty, because a technique this common would otherwise appear somewhere in 90 days of telemetry.

    A negative hunt result is bounded by visibility and retention: it supports the claim that the hunted behaviour does not appear in the telemetry that exists, for the hosts covered and the period searched, and nothing more. The honest output is a documented scope with its gaps named — here the 18 percent of workstations without an agent and anything older than the retained 90 days — which is itself a useful finding about coverage.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (documenting and testing hunt conclusions; visibility and coverage gaps)Report a problem with this question

  18. 18. A hunt finds three hosts on which a scripting interpreter loaded a library from a user-writable directory. The files are removed and the hosts are cleaned. What must happen for the hunt to leave lasting value?

    • A.Express the behaviour as an automated detection, tune it against normal activity and confirm that it fires on a replayed example.✓ Answer
    • B.Schedule the same manual query to be repeated monthly, since a query that found something once is the durable control here.
    • C.Add the three library digests to the blocking list, since that stops the same loads recurring on any host in the environment.
    • D.Record the finding in the hunt report and in the incident case, since documenting the pattern in writing is what makes it reusable.

    A hunt pays back when the behaviour it uncovered becomes an automated detection that has been tuned against normal activity and validated to fire, because that removes the need to repeat the manual search and catches the next instance at the time it happens. File digests break as soon as the library is recompiled, and a monthly manual query leaves the environment blind between runs.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (threat hunting outcomes: new detections and reduced attack surface)Report a problem with this question

  19. 19. During a busy week a manager reassigns the two hunters to the alert queue, on the grounds that both jobs are 'reading logs'. What is the accurate distinction, and what does the reassignment cost?

    • A.Triage and hunting are the same activity at different volumes, so the only cost is that hunting resumes later than was planned.
    • B.Hunting differs only in tooling, since hunters query the same console with the same saved searches, so nothing of substance is given up.
    • C.Hunting is the escalation path for alerts that analysts cannot close, so the cost is longer handling times on the queue's hardest tickets.
    • D.Triage starts from alerts an existing rule raised; hunting starts from a hypothesis about behaviour no rule covers, so gap discovery stops.✓ Answer

    Alert triage is reactive: the work arrives from rules that already exist, and each item has a defined path to closure. Hunting is proactive and hypothesis-driven, deliberately searching telemetry where no rule fires, so pausing it does not merely delay a queue — it suspends the only activity that finds the detection gaps, and those gaps stay open for as long as the hunters are on the queue.

    Source: CompTIA CySA+ CS0-004 Obj. 1.4 (threat hunting as proactive, hypothesis-driven work distinct from alert-driven triage)Report a problem with this question

Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →