
CompTIACySA+
Domain 1Objective 4
Threat Intelligence and Hunting CS0-003 Practice Questions (Page 6)
Part of the Security operations domain, which accounts for 33% of the CS0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~21–36 in this domain), expect 4–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
33%of the exam
Questions 26–29
- 26
A security analyst discovers a new malware variant and wants to share the indicators of compromise (IOCs) with other organizations to help them defend against it. Which standard format is commonly used for sharing this type of threat intelligence?
Select an answer first - 27
A threat intelligence analyst is evaluating a report from a commercial feed that indicates a specific file hash is malicious. The feed is from a reputable vendor, but the analyst's own sandbox analysis shows the file is benign. The analyst must decide whether to add the hash to the blocklist. What should the analyst do?
Select an answer first - 28
A security operations center wants to enhance its threat intelligence collection but has a limited budget. The team is considering using open-source intelligence (OSINT) and a commercial threat intelligence feed. Which approach would best balance cost and intelligence quality?
Select an answer first - 29
A threat hunter is reviewing logs and notices that a user account is logging in at unusual hours and accessing files that are not related to their job role. Which threat hunting technique is being used to identify this potential threat?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CS0-003
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CS0-003” is a trademark of its owner, used for identification only.