Triage BoardGet the app

Concept · Threat intel and hunting

The Pyramid of Pain and IoC quality

The Pyramid of Pain ranks indicators by how much it costs an attacker when you detect and deny them: hash values at the bottom are trivial to change, and tactics, techniques and procedures (TTPs) at the top are the hardest. Objective 1.4 of the CS0-004 exam names the pyramid next to atomic and behavioral indicators of compromise (IoCs) and intelligence confidence, so questions ask both which indicator hurts the attacker most and how far to trust it. It is part of threat intelligence and hunting.

  • Exam code CS0-004
  • Tickets here 8

Three kinds of indicator

Atomic
A single value that means something on its own and can't be broken down further: an IP address, a domain name, an email address, a Common Vulnerabilities and Exposures (CVE) identifier.
Computed
A value derived from incident data, such as a file hash or a regular expression written to match a sample.
Behavioral
A combination of atomic and computed indicators, often with logic, that describes how the intruder operates. This is where TTPs live.

The pyramid, bottom to top

TTPstoughToolschallengingNetwork/host artifactsannoyingDomain namessimpleIP addresseseasyHash valuestrivial
David Bianco's 2013 levels with his labels for the attacker's cost of changing each one

Level by level

Hashes, IP addresses, domains

These three are fast to deploy and easy to match exactly, which is why feeds are full of them. A hash almost never misfires; IP addresses and domains do, once hosting is shared or an address is reassigned. They are also the cheapest for the attacker to replace: recompiling or padding a file changes its hash, and new infrastructure is a rental away. Domains rank slightly higher than IP addresses because they have to be registered and paid for, but DGA malware and fast-flux hosting are built to make even that cheap.

The CS0-004 objectives name only two classes, atomic and behavioral. In the original taxonomy from the Lockheed Martin kill chain paper (Hutchins, Cloppert and Amin), a hash is a computed indicator. If a question offers only the two exam terms, a hash is plainly not the behavioral one.

Network and host artifacts, tools

Artifacts are traces the attacker's method leaves: a fixed URI path the implant always requests, an odd user-agent string the tool sets, a named pipe or a registry value used for persistence. Changing them means changing configuration or code, which annoys the attacker and slows them down.

Detecting a tool, for example with a YARA rule written against the code of a custom loader, forces the attacker to find or build a replacement. That costs time and skill.

TTPs

At the top you detect the behavior itself, whatever file, address or tool carries it: for example, any account that creates a new service on a remote server through an administrative share, whatever the binary is called. To evade that, the adversary has to learn a new way of working. Mapping such behaviors to MITRE ATT&CK techniques is how teams describe them on the exam and in practice.

Threat hunting works from the same end of the pyramid. A hunt starts with a hypothesis about a behavior, such as an adversary using built-in tools to move between servers, and searches your own telemetry for it. A hunt built on a list of hashes is closer to a lookup than a hunt.

You may meet the term indicator of attack (IoA) in vendor material for behavior-based detection. It is not in the CySA+ CS0-004 objectives, so when an option set uses the objectives' words, answer in those.

Before you trust an indicator

The three confidence tests objective 1.4 names, applied to a feed entry
TestWhat you askWhat a failure looks like
TimelinessIs it still current?An address from an old report now belongs to a shared hosting provider
RelevanceDoes it apply to us?A feed about industrial control systems in a network that runs none
AccuracyIs it correct and specific?A domain flagged because one page on a large public site was abused

Easy to block, easy to dodgeRule

A hash blocklist feels strong because it never misfires. The pyramid measures something else: how quickly the attacker can route around the detection. When a question asks which detection costs the adversary most, climb toward TTPs. When it asks which indicator is safest to block automatically, the answer can sit lower down. Read which of the two the stem wants.

Climb or block

Two different questions run through this set: where an indicator sits on the pyramid, and whether a source deserves trust.

Ticket 1 / 8

0 right

INC-001

Following a sandbox execution, a threat hunter needs to generate actionable indicators of compromise (IOCs) to implement detection rules. Which of the following extracted indicators is high-fidelity enough to be blocked without causing widespread false positives?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA major public DNS resolver is used by countless legitimate hosts, so blocking its IP would break name resolution widely.
  2. BCorrect: a hardcoded mutex unique to the malware family appears only on infected hosts, so it is a high-fidelity host artifact with almost no false positives.
  3. CA popular browser's standard user-agent string matches normal traffic from most users.
  4. DA GET to a legitimate news site's root page is normal browsing, often a connectivity check by the malware, and blocking it would hit many users.

INC-002

A new open-source threat feed generates thousands of low-quality IoCs daily. Which ingestion controls best prevent alert storms while retaining forensic value?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAuto-quarantining on low-quality indicators would isolate legitimate hosts and cause the alert storm the team wants to avoid.
  2. BCorrect: normalizing, scoring by quality, throttling and staging for analyst review keeps the data searchable for forensics while stopping noisy indicators from driving alerts.
  3. CRaw, unscored storage keeps the data but gives no way to prioritize or act on it.
  4. DHigh-severity alerts on every match from a noisy feed is the definition of an alert storm.

INC-003

Ninety-day metrics for a threat feed show rising false positives and declining true-positive coverage. Which adjustment is warranted?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ARemoving the feed immediately throws away the coverage it still provides, without first trying to tune it.
  2. BCorrect: lowering the feed's score and throttling it reduces noise now, and a set reassessment window decides whether to keep or drop it.
  3. CMore volume from a feed whose quality is falling adds noise without restoring coverage.
  4. DAccepting the noise wastes analyst time and lets rising false positives bury real detections.

INC-004

Given domain reputation data, passive DNS history, sandbox results, and internal sightings, which process yields a defensible blocking decision for a suspected malicious domain?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA fixed hit count is arbitrary, ignores source quality and recency, and can delay blocking a clearly malicious domain.
  2. BCorrect: weighing source provenance, independent sightings, recency and behavioral evidence into a confidence score gives a documented, defensible basis for blocking.
  3. CA single vendor listing can be wrong or stale, so blocking on it alone risks false positives.
  4. DWaiting only for sandbox confirmation ignores the other evidence and delays action, since many samples evade sandboxes.

INC-005

An analyst receives a single-vendor high-severity alert for an IP address. What is the most appropriate next step before containment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA permanent block based on one unverified source risks blocking a legitimate or shared IP indefinitely.
  2. BCorrect: enriching with multi-vendor reputation, passive DNS and internal sightings establishes confidence and scope before acting.
  3. CBlocking right away on a single vendor's alert risks disrupting legitimate traffic if the alert is wrong.
  4. DLogging only future connections misses past activity and does nothing to validate the alert.

INC-006

According to the Pyramid of Pain, which list orders indicator types from easiest to hardest for an adversary to change?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AHashes sit below IP addresses as the cheapest to change, and network or host artifacts sit below tools.
  2. BIP addresses sit below domain names, and TTPs, not tools, are at the top of the pyramid.
  3. CCorrect: the pyramid rises from trivial-to-change hashes to TTPs, which cost the adversary the most to change.
  4. DThis puts domains at the bottom, but recompiling to get a new hash is easier than registering new domains.

INC-007

After an intrusion, a SOC can build one new detection from the incident report. If it works, which one imposes the most cost on the adversary?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AHashes are at the base of the pyramid; recompiling or repacking the dropper produces a new hash.
  2. BDomains cost a little more than IPs to replace, but registering new ones is still routine for an adversary.
  3. CIP addresses are near the bottom of the pyramid; the adversary can move to new hosting quickly.
  4. DCorrect: detecting a technique (TTP) forces the adversary to change how they operate, the most costly change.

INC-008

Which of these is a behavioral indicator of compromise rather than an atomic one?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA hash is a single static value, not a pattern of activity, so it is not behavioral.
  2. BCorrect: it describes a pattern of activity across processes and the network, which makes it behavioral.
  3. CA single IP address is atomic: one value that can be matched or blocked directly.
  4. DA domain is a single value from a feed, so it is atomic even when it is high quality.

Shift tally

0 / 0

Sources

  1. David J. Bianco, The Pyramid of Pain (checked October 9, 2026)
  2. Lockheed Martin, Intelligence-Driven Computer Network Defense (Hutchins, Cloppert and Amin) · atomic, computed and behavioral indicators (checked October 9, 2026)
  3. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) · objective 1.4 (checked October 9, 2026)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.