Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 1Objective 4

Threat Intelligence and Hunting CS0-003 Practice Questions (Page 1)

Part of the Security operations domain, which accounts for 33% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~21–36 in this domain), expect 4–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
33%of the exam

Questions 1–5

  1. 1application · medium

    A threat hunter is looking for signs of a specific advanced persistent threat (APT) group known to use PowerShell scripts for reconnaissance and to maintain persistence via scheduled tasks. The hunter has access to endpoint logs and wants to proactively search for these TTPs. Which approach should the hunter take?

    Select an answer first
  2. 2expert · hard

    A threat hunter is investigating a potential compromise where an attacker is using a legitimate remote management tool to control a server. The hunter has access to network and endpoint logs. Which technique would be most effective in detecting this activity?

    Select an answer first
  3. 3foundation · easy

    A security team discovers that a competitor has been systematically stealing proprietary research data over several months. The attacks are highly sophisticated, use custom malware, and appear to be funded by a foreign government. Which type of threat actor is most likely responsible?

    Select an answer first
  4. 4foundation · easy

    A threat intelligence analyst receives a report from a well-known, reputable security vendor about a new malware campaign. The report includes detailed technical indicators and is corroborated by two other independent sources. How should the analyst assess the confidence level of this intelligence?

    Select an answer first
  5. 5application · medium

    A security team at a financial institution has identified a new phishing campaign targeting their customers. They want to share this intelligence with other organizations in their sector to help prevent similar attacks. Which method is most appropriate for sharing this threat intelligence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.