
CompTIASecurityX (CASP+)
Domain 4Objective 3
Threat Hunting CAS-005 Practice Questions (Page 6)
Part of the Security operations domain, which accounts for 22% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
15concepts
22%of the exam
Questions 26–30
- 26
A large enterprise's security team is monitoring dark web forums for mentions of their company. They find a post where a user is selling what appears to be a database dump of customer records. The team wants to verify if the data is genuine and belongs to them without exposing more data or alerting the seller. Which action is the MOST appropriate?
Select an answer first - 27
Why are honeypots considered a valuable source of threat intelligence despite being decoy systems?
Select an answer first - 28
What is the primary purpose of YARA rules?
Select an answer first - 29
A network administrator is configuring an intrusion detection system (IDS) to monitor for a known exploit that sends a specific string of bytes to a web server on port 80. The administrator wants to create a rule that will generate an alert when this specific traffic pattern is observed. Which rule language is the MOST appropriate for this task?
Select an answer first - 30
An analyst is looking for threat intelligence that is specific to the financial services industry. Which external source would be most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.