StudyToCert

All certifications / CySA+ / Lessons

CompTIA CySA+ CS0-004 · Domain 1: Security operations

Network indicators: beaconing, unusual bandwidth, irregular peer-to-peer traffic, rogue devices, scans, unexpected ports

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Network indicators are patterns in traffic that suggest compromise. They matter because malware almost always has to communicate: to receive commands, to spread, or to send stolen data out. You find these patterns in firewall logs, NetFlow or similar flow records, proxy and Domain Name System (DNS) logs, and packet captures. Most network indicators only make sense against a baseline, meaning a picture of what normal traffic looks like for that host, subnet or time of day.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CySA+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CySA+ study plan