Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is conducting a threat hunt based on the hypothesis that an adversary may have used PowerShell to execute malicious scripts. Which threat hunting methodology is being employed?

⚠ Common exam trap

CAS-005 often tests the confusion between hypothesis-driven and TTP-driven hunting, where candidates incorrectly select TTP-driven when a specific hypothesis is being tested.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hypothesis-driven hunting

Hypothesis-driven hunting starts with a specific hypothesis, such as 'an adversary may have used PowerShell to execute malicious scripts,' and then tests that hypothesis through data analysis. This is exactly what the analyst is doing. TTP-driven hunting is broader and focuses on known adversary tactics, techniques, and procedures, while IoC-driven hunting uses specific indicators of compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IoC-driven hunting

    Why it's wrong here

    IoC-driven hunting begins from known artefacts such as file hashes, domains or IP addresses, not from an assumed adversary technique. The hypothesis names PowerShell execution, a behaviour. IoC hunting suits sweeping for previously identified malware indicators across the estate.

  • ✗

    TTP-driven hunting

    Why it's wrong here

    TTP-driven hunting starts from observed adversary tradecraft, not a single tool. The hypothesis names PowerShell, a technique, without linking it to a known threat actor's documented procedures, so it lacks the TTP anchor this methodology requires. It would fit if hunting for a specific group's known PowerShell command patterns.

  • ✗

    Baseline-driven hunting

    Why it's wrong here

    Baseline-driven hunting starts from deviations in normal behaviour rather than a stated adversary technique, so it does not match a hypothesis naming PowerShell execution. It suits detecting anomalies when no specific threat behaviour is assumed, such as spotting unusual login volumes.

  • ✓

    Hypothesis-driven hunting

    Why this is correct

    The analyst starts from a stated proposition about adversary behaviour, then searches telemetry to confirm or refute it. That is hypothesis-driven hunting, distinct from intelligence-driven hunting (led by feeds) or baseline/anomaly approaches that flag deviations without a prior premise.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.