
CompTIASecurityX (CASP+)
Domain 4Objective 3
Threat Hunting CAS-005 Practice Questions (Page 5)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
15concepts
22%of the exam
Questions 21–25
- 21
Which statement correctly describes the relationship between STIX and TAXII?
Select an answer first - 22
A hospital's security team has identified a new ransomware variant targeting healthcare-specific software. They want to share the indicators of compromise (IoCs) with other hospitals in their region to help them defend against the same threat. The team is a member of a regional Health Information Sharing and Analysis Center (H-ISAC). What is the MOST effective way to share this intelligence?
Select an answer first - 23
Which task is typically performed by a Threat Intelligence Platform (TIP)?
Select an answer first - 24
Which type of information can be represented in a STIX document?
Select an answer first - 25
A security team has deployed a honeypot and a User Behavior Analytics (UBA) system. The honeypot is a fake file server that has been accessed by an internal user account. The UBA flags the same user account for accessing a large number of files on the real file server in a short period, which is unusual for that user. The analyst must determine if the honeypot access is related to the UBA alert. Which investigation step would provide the STRONGEST evidence of a link?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.