Triage BoardGet the app

Domain 1 · Security Operations

Threat intelligence and threat hunting

Threat intelligence is evaluated knowledge about adversaries; threat hunting is a deliberate search of your own environment for activity your detections missed. Objective 1.4 of CS0-004 checks that you can grade intelligence, choose indicators that keep working, and frame a hunt as a hypothesis you can test.

  • Exam code CS0-004
  • Domain weight 34%
  • Tickets here 16

Where 1.4 sits in the domain

1.4 is a concepts objective in the CS0-004 exam objectives (version 2.0, checked October 2026). It names threat actors, TTPs (tactics, techniques and procedures), confidence levels, collection and sharing, the IoC lifecycle, threat modeling with STRIDE, threat mapping and cyber deception. The Pyramid of Pain and STRIDE are new names compared with CS0-003, and “cyber deception” widens the honeypots and active defense that CS0-003 already listed.

MITRE ATT&CK appears here for TTPs and attribution and again in attack frameworks (objective 3.1). As of ATT&CK v19, checked October 2026, the Enterprise matrix lists 15 tactics, and TA0005, long called Defense Evasion, is now named Stealth (MITRE ATT&CK Enterprise tactics). Prep material written earlier says 14.

Intelligence sources

Collection sources named in 1.4, with what each is good and bad at
SourceExamplesStrengthWeakness
Open source (OSINT)Public reports, open feeds, OTXFree, broadNoisy, uneven quality
Closed sourceCommercial feeds, paid reportsCurated, with contextCost, limits on resharing
Sharing communitiesSector groups, government advisoriesPeers' sightingsNeeds trust and handling rules
InternalYour incidents, SIEM data, past huntsMost relevantNarrow view

Sharing formats are an aside here: STIX describes intelligence objects and TAXII transports them (OASIS CTI documentation). Neither name appears in the CS0-004 objectives.

Confidence: three tests

Timeliness
Is it current enough to act on? An address an actor abandoned months ago is history.
Relevance
Does it apply to your sector, your technology and your exposure? Intel about software you do not run is noise.
Accuracy
Is it correct and corroborated? One uncorroborated report earns low confidence however alarming it reads.

Which indicators last

TTPsToughToolsChallengingNetwork/host artifactsAnnoyingDomain namesSimpleIP addressesEasyHash valuesTrivial
Bianco's Pyramid of Pain (2013): the higher the layer, the more it costs an adversary to change

Indicators, actors and TTPs

Atomic, computed and behavioral

The taxonomy comes from the Lockheed Martin Kill Chain paper by Hutchins and colleagues. Atomic indicators cannot be broken down further: IP addresses, domain names, email addresses, CVE identifiers. Computed indicators are derived from data, such as file hashes and regular expressions. Behavioral indicators combine the others into a pattern of activity. CS0-004 names the atomic and behavioral ends, and the exam favors behavioral detection because it survives an adversary's cosmetic changes. The pyramid above puts hash values at the bottom for the same reason; the Pyramid of Pain page works through it layer by layer.

The IoC lifecycle

An indicator is discovered, enriched and scored, deployed into detections or shared, and then retired when it ages out. Threat-intel platforms such as MISP and OpenCTI manage that cycle (see the analysis tools guide), and the raw signals an indicator starts from are cataloged in indicators of malicious activity. Leaving stale indicators in a blocklist costs performance and produces false matches when an address changes hands.

Actors

An advanced persistent threat (APT) is defined by resources and patience: long dwell time and the ability to retool when blocked. An insider threat works from legitimate access, and can be careless as well as malicious. Attribution is a judgment backed by TTPs, infrastructure and tooling, and it is always stated with a confidence level.

Threat mapping and heat maps

Map known adversary techniques against your detections in an ATT&CK heat map and the gaps become a hunt list.

A hypothesis-driven hunt

  1. State a testable hypothesis

    Example: remote-administration tools are running on finance workstations outside the approved software list.

  2. Pick the data

    EDR software-install and process events, the software inventory, proxy logs for the vendors' domains.

  3. Set scope and a time limit

    Name the host group and the look-back window up front, so the hunt ends with a result either way.

  4. Search and pivot

    Each hit becomes a new question: which user, which parent process, which other hosts.

  5. Close with an outcome

    A finding goes to incident response. An empty result is documented and, where possible, turned into a standing detection with the help of SOC automation and process improvement.

STRIDE in one table

STRIDE threat categories, the property each violates, and a fictional example
ThreatViolatesExample
SpoofingAuthenticationA fake SSO login page
TamperingIntegrityPrice edited in transit
RepudiationNon-repudiationDenied approval, no log
Information disclosureConfidentialityAPI leaks others' records
Denial of serviceAvailabilityLogin page flooded
Elevation of privilegeAuthorizationUser reaches admin tools

Mapping per Microsoft Threat Modeling Tool threats (checked October 2026).

Deception: honeypots then, cyber deception nowNote

Decoys come in sizes: a honeypot is one fake system, a honeynet a fake network, a honeytoken a fake credential, file or database record. Two exam traps: a decoy must be isolated so that it cannot become a pivot into real systems, and its alerts are only worth something if someone is watching them.

Hunting drill

This queue mixes three jobs: profiling an actor, grading a piece of intelligence and planning a hunt.

Ticket 1 / 16

0 right

INC-001

Which type of threat actor is known to disrupt systems or networks as a form of protest against financial institutions?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ANation-state actors pursue strategic goals such as espionage or sabotage, not public protest.
  2. BOrganized crime is driven by profit, so disruption as protest does not fit its motive.
  3. CAn APT is defined by long-term, stealthy access for espionage or theft, the opposite of a visible protest disruption.
  4. DCorrect: hacktivists attack for political or social causes, and disrupting or defacing financial institutions is a typical form of protest.

INC-002

Which type of cyber adversary typically has backing from national governments and aims to conduct sophisticated cyber espionage operations?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ACyber vandals cause disruption for its own sake and lack government backing or espionage goals.
  2. BScript kiddies are unskilled attackers who run existing tools, the opposite of funded espionage operators.
  3. CSpammers send bulk unsolicited messages for profit and do not run sophisticated espionage campaigns.
  4. DCorrect: APT groups are well-resourced, often state-sponsored, and maintain long-term covert access for espionage.

INC-003

Which type of threat actor is primarily motivated by financial gain through deploying ransomware attacks?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AInsiders may steal or sabotage out of grievance or for money, but ransomware campaigns for profit are not what defines them.
  2. BNation-states mainly pursue strategic or geopolitical goals, even if some use ransomware as cover.
  3. CCorrect: cybercriminal gangs run ransomware as a business, encrypting or stealing data to extort payment.
  4. DHacktivists are driven by ideology and publicity; ransom payments are what motivate organized crime.

INC-004

Observed TTPs include T1059.001, infrastructure reuse across three campaigns, and tooling fingerprints matching a known cluster. Which actor hypothesis is most supportable?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ANothing in the evidence names APT29, and technique and infrastructure overlap alone does not justify high confidence in a named group.
  2. BDefinite attribution to a nation-state is overstated, since shared tooling and infrastructure can be reused or copied by other actors.
  3. CCorrect: technique overlap, reused infrastructure and matching tooling together support a medium-confidence link to the known cluster, without overclaiming.
  4. DThe evidence goes well beyond timing, so a timing-only, low-confidence match undersells what was observed.

INC-005

A security operations team is implementing a threat hunting program. Which data source would be MOST valuable for identifying potential persistence mechanisms installed by attackers?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. APacket captures show network activity but not the autorun entries and scheduled tasks where persistence lives on the host.
  2. BCorrect: registry Run keys, scheduled tasks and startup folders are where attackers place persistence so their code runs again after a reboot.
  3. CPhysical security logs track badge and door access and cannot show software persistence on hosts.
  4. DEnvironmental monitoring tracks temperature and power, which has nothing to do with attacker persistence.

INC-006

Analysts possess IoCs for suspected dormant C2. Which sequence best begins a hunt across tenant environments?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: proxy logs reveal periodic beacon timing to the suspect destinations, and EDR then ties each hit to the process on the host.
  2. BRaw DNS totals and every HTTP 200 response are huge, unfocused data sets that bury the beacon pattern in noise.
  3. CTotal outbound bytes shows volume but not timing or destination, and dormant beacons send very little data.
  4. DEDR alone lacks the network timing view that exposes beaconing, so correlating with proxy data is what confirms the C2.

INC-007

Given IoCs consisting of three domains, two IPs, and five file hashes, which hunt sequence most effectively expands scope of compromise?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ASearching only for hashes ignores the domain and IP IoCs, and file hashes are trivial for attackers to change.
  2. BStarting with all user activity across the domain is unfocused and does not use the IoCs in hand.
  3. COne hour of EDR alerts is too narrow in time and in data source to scope a compromise.
  4. DCorrect: network logs find which hosts contacted the IoC domains and IPs, and EDR then confirms the matching files and processes on those hosts.

INC-008

A SOC analyst suspects credential dumping on domain controllers. Which hypothesis, telemetry sources, and timebox best support a focused threat hunt?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: a testable hypothesis (LSASS access on domain controllers), the right telemetry (EDR plus authentication logs) and a short timebox keep the hunt focused.
  2. BNetwork-only data cannot show a process reading LSASS memory, and all outbound SMB is far broader than the hypothesis.
  3. CCredential dumping happens on the domain controllers, so failed logons on member servers are the wrong place and the wrong signal.
  4. DPowerShell anywhere over two weeks is too broad to be a focused hunt and does not target credential dumping on domain controllers.

INC-009

You set up a simulated environment that mimics an enterprise network to monitor and analyze malicious activities. What type of security mechanism did you implement?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ADLP inspects and blocks sensitive data leaving the organization; it does not simulate a network to study attackers.
  2. BAn IDS watches real production traffic for attacks rather than building a decoy environment.
  3. CCorrect: a honeynet is a network of decoy systems built to attract attackers so their behavior can be observed and analyzed.
  4. DAn IPS blocks attacks inline on real traffic; it does not create a fake environment to lure attackers.

INC-010

What is the primary benefit of implementing deception technology (such as honeypots) in a security operations environment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ADeception adds systems to deploy and monitor, so it does not reduce staffing.
  2. BCorrect: decoys have no legitimate use, so any interaction is a high-fidelity alert, often early in the attacker's reconnaissance.
  3. CHoneypots detect and study attackers; they do not stop attacks from happening.
  4. DDeception supplements defense in depth and replaces none of the firewalls, patching or endpoint controls.

INC-011

A security team plans deception deployment in a segmented network. Which placement and monitoring approach is optimal?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AMinimal logging throws away the forensic value of a decoy, and a public DMZ attracts constant internet noise.
  2. BWithout packet capture the team learns that an attacker touched the decoy but not what they did.
  3. CHoneypots on production servers mix decoy and real traffic and risk disrupting services, while normal user accounts there trigger false alarms.
  4. DCorrect: decoys placed where no legitimate user goes produce near-zero false positives, and strict logging with packet capture records what the attacker did.

INC-012

Following an analysis of recent cybersecurity breaches, the IT director recognizes the need for a collaborative effort within the private sector to share threat intelligence, assess vulnerabilities, and discuss responses to cyber threats. Which type of organization should the IT director join?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASIGINT is signals intelligence that governments gather from intercepted communications, which makes it no private-sector sharing body.
  2. BCorrect: an ISAC is a sector-based organization where private-sector members share threat intelligence and coordinate responses.
  3. CA CSIRT handles incidents for its own organization or constituency rather than serving as an industry information-sharing forum.
  4. DOASIS is a standards body (it maintains STIX and TAXII, for example) and does not run a threat-sharing community.

INC-013

Which protocol is commonly used for real-time communication of cybersecurity threat intelligence between different organizations and security teams?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: TAXII is the transport protocol (over HTTPS) for exchanging threat intelligence, typically STIX content, between organizations.
  2. BSTIX is the language and format for describing threat intelligence, while TAXII is the protocol that transports it.
  3. CTTPs describe how adversaries operate, so they are intelligence content instead of a communication protocol.
  4. DOpenIOC is a format for describing indicators and has no role as an exchange protocol.

INC-014

A security operations team wants to implement a strategy that provides an early warning of potential attacks. Which of the following would be most effective?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: threat intelligence feeds bring in indicators and TTPs from attacks seen elsewhere, giving warning before they reach your environment.
  2. BTraining reduces user-driven risk but gives no warning about attacks being prepared or under way.
  3. CPenetration testing finds weaknesses at a point in time but does not warn of what attackers are currently doing.
  4. DVulnerability scanning shows your own weaknesses and gives no external warning of active campaigns.

INC-015

Passive DNS shows an IP resolved to many short-lived malicious domains and belongs to an ASN known for bulletproof hosting. What is the most likely assessment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. APassive DNS history and ASN reputation are strong evidence on their own, so a sandbox is not required to form an assessment.
  2. BHaving no current resolutions does not clear an IP whose history is full of short-lived malicious domains.
  3. CThe evidence justifies concern, but blocking with no investigation skips checking internal impact and business use.
  4. DCorrect: repeated short-lived malicious domains on a bulletproof-hosting ASN point to malicious infrastructure, which warrants checking internal telemetry for contact.

INC-016

During threat modeling, a team finds that an internal API accepts a forged identity token and then acts as another ordinary user with the same rights. In STRIDE, which threat is this and which property does it violate?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ATampering is unauthorized change to data or code; the issue here is a false identity, not altered data.
  2. BRepudiation is denying an action without proof otherwise; the finding is about posing as someone else.
  3. CThe forged identity has the same rights as the caller's peers, so no higher privilege is gained.
  4. DCorrect: pretending to be another identity is spoofing, and the property it breaks is authentication.

Shift tally

0 / 0

Standards behind this page

  1. MITRE, ATT&CK Enterprise tactics (v19) (checked October 9, 2026)
  2. David J. Bianco, The Pyramid of Pain · 2013 blog post (checked October 9, 2026)
  3. Lockheed Martin, Intelligence-Driven Computer Network Defense (Hutchins, Cloppert and Amin) (checked October 9, 2026)
  4. CompTIA CySA+ CS0-004 exam objectives, version 2.0 (PDF) (checked October 9, 2026)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.