Hashes, IP addresses, domains
These three are fast to deploy and easy to match exactly, which is why feeds are full of them. A hash almost never misfires; IP addresses and domains do, once hosting is shared or an address is reassigned. They are also the cheapest for the attacker to replace: recompiling or padding a file changes its hash, and new infrastructure is a rental away. Domains rank slightly higher than IP addresses because they have to be registered and paid for, but DGA malware and fast-flux hosting are built to make even that cheap.
The CS0-004 objectives name only two classes, atomic and behavioral. In the original taxonomy from the Lockheed Martin kill chain paper (Hutchins, Cloppert and Amin), a hash is a computed indicator. If a question offers only the two exam terms, a hash is plainly not the behavioral one.
Network and host artifacts, tools
Artifacts are traces the attacker's method leaves: a fixed URI path the implant always requests, an odd user-agent string the tool sets, a named pipe or a registry value used for persistence. Changing them means changing configuration or code, which annoys the attacker and slows them down.
Detecting a tool, for example with a YARA rule written against the code of a custom loader, forces the attacker to find or build a replacement. That costs time and skill.
TTPs
At the top you detect the behavior itself, whatever file, address or tool carries it: for example, any account that creates a new service on a remote server through an administrative share, whatever the binary is called. To evade that, the adversary has to learn a new way of working. Mapping such behaviors to MITRE ATT&CK techniques is how teams describe them on the exam and in practice.
Threat hunting works from the same end of the pyramid. A hunt starts with a hypothesis about a behavior, such as an adversary using built-in tools to move between servers, and searches your own telemetry for it. A hunt built on a list of hashes is closer to a lookup than a hunt.
You may meet the term indicator of attack (IoA) in vendor material for behavior-based detection. It is not in the CySA+ CS0-004 objectives, so when an option set uses the objectives' words, answer in those.