Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIACySA+

Domain 1Objective 4

Threat Intelligence and Hunting CS0-003 Practice Questions (Page 5)

Part of the Security operations domain, which accounts for 33% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~21–36 in this domain), expect 4–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
33%of the exam

Questions 21–25

  1. 21expert · hard

    A security analyst is investigating a series of attacks where the attacker used a phishing email to deliver a macro-enabled document, then used PowerShell to download a payload, and finally used scheduled tasks for persistence. The analyst wants to map these actions to the MITRE ATT&CK framework to identify gaps in detection. Which tactic would the analyst NOT find in the ATT&CK framework for these actions?

    Select an answer first
  2. 22application · medium

    A security team at a hospital has detected a ransomware attack and wants to share indicators of compromise (IOCs) with other healthcare organizations to help them defend against the same campaign. Which method should they use to share this intelligence?

    Select an answer first
  3. 23foundation · easy

    An organization subscribes to a commercial threat intelligence feed that provides real-time indicators of compromise and analysis from a paid vendor. Which type of threat intelligence collection method does this represent?

    Select an answer first
  4. 24application · medium

    A threat intelligence analyst at a security operations center is evaluating a new intelligence feed that reports a specific IP address as a command-and-control server. The feed is from a small, newly established vendor with no track record, and the report is based on a single sandbox analysis. The analyst must decide whether to block the IP address. What should the analyst do?

    Select an answer first
  5. 25expert · hard

    A threat hunter is looking for signs of a specific APT group that is known to use living-off-the-land binaries (LOLBins) and to maintain persistence via WMI event subscriptions. The hunter has access to endpoint logs and wants to proactively search for these TTPs. Which approach should the hunter take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.