CAS-004 Security Operations Practice Question
A security analyst is conducting a threat hunt based on the hypothesis that an adversary may have used PowerShell to execute malicious scripts. Which threat hunting methodology is being employed?
⚠ Common exam trap
CAS-005 often tests the confusion between hypothesis-driven and TTP-driven hunting, where candidates incorrectly select TTP-driven when a specific hypothesis is being tested.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hypothesis-driven hunting
Hypothesis-driven hunting starts with a specific hypothesis, such as 'an adversary may have used PowerShell to execute malicious scripts,' and then tests that hypothesis through data analysis. This is exactly what the analyst is doing. TTP-driven hunting is broader and focuses on known adversary tactics, techniques, and procedures, while IoC-driven hunting uses specific indicators of compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IoC-driven hunting
Why it's wrong here
IoC-driven hunting begins from known artefacts such as file hashes, domains or IP addresses, not from an assumed adversary technique. The hypothesis names PowerShell execution, a behaviour. IoC hunting suits sweeping for previously identified malware indicators across the estate.
- ✗
TTP-driven hunting
Why it's wrong here
TTP-driven hunting starts from observed adversary tradecraft, not a single tool. The hypothesis names PowerShell, a technique, without linking it to a known threat actor's documented procedures, so it lacks the TTP anchor this methodology requires. It would fit if hunting for a specific group's known PowerShell command patterns.
- ✗
Baseline-driven hunting
Why it's wrong here
Baseline-driven hunting starts from deviations in normal behaviour rather than a stated adversary technique, so it does not match a hypothesis naming PowerShell execution. It suits detecting anomalies when no specific threat behaviour is assumed, such as spotting unusual login volumes.
- ✓
Hypothesis-driven hunting
Why this is correct
The analyst starts from a stated proposition about adversary behaviour, then searches telemetry to confirm or refute it. That is hypothesis-driven hunting, distinct from intelligence-driven hunting (led by feeds) or baseline/anomaly approaches that flag deviations without a prior premise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.