
CompTIACySA+
Domain 1Objective 4
Threat Intelligence and Hunting CS0-003 Practice Questions (Page 4)
Part of the Security operations domain, which accounts for 33% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~21–36 in this domain), expect 4–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
33%of the exam
Questions 16–20
- 16
A threat hunter is investigating a potential data exfiltration incident. The hunter notices large outbound data transfers to a cloud storage service that is not commonly used by the organization. The transfers occur during off-hours and from a single workstation. Which hypothesis should the hunter test first?
Select an answer first - 17
A threat hunter is reviewing network traffic logs and notices a series of outbound connections to a known malicious domain from several workstations. The connections occur at irregular intervals and use HTTPS. The hunter wants to determine if this is a coordinated attack or isolated infections. Which technique should the hunter use?
Select an answer first - 18
A security analyst observes a series of distributed denial-of-service (DDoS) attacks and website defacements targeting a government agency. The attacks appear to be politically motivated and are accompanied by public statements criticizing the agency's policies. Which type of threat actor is most likely responsible?
Select an answer first - 19
A threat intelligence analyst is reviewing two reports about a new malware strain. The first report is from a well-known security vendor with a long track record, based on multiple sandbox analyses and real-world observations. The second report is from an anonymous source on a dark web forum, claiming the malware is a state-sponsored tool. The analyst must decide which report to trust more. What should the analyst do?
Select an answer first - 20
A security analyst is investigating a breach at a defense contractor. The attacker used a zero-day exploit in a widely used software, moved laterally using legitimate credentials, and exfiltrated data via encrypted channels. The attack was highly sophisticated and targeted specific research documents. Which threat actor type is most likely responsible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.