CAS-004 Security Operations Practice Question
A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
Hypothesis-driven hunting starts with a specific hypothesis based on threat intelligence or a known TTP, such as process injection. This approach is proactive and focuses on detecting behaviors consistent with the hypothesis, unlike IoC-driven hunting which relies on known indicators.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TTP-driven hunting by analyzing adversary behaviors mapped to the ATT&CK framework
Why it's wrong here
TTP-driven hunting is similar but broader; the scenario specifically starts with a hypothesis about a technique, which is more aligned with hypothesis-driven hunting.
- ✓
Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
Why this is correct
Hypothesis-driven hunting starts with a hypothesis about adversary behavior and proactively searches for evidence, making it ideal for detecting novel or evasive techniques.
- ✗
Automated hunting using SIEM correlation rules that trigger on known malicious file hashes
Why it's wrong here
This is reactive and signature-based; it would miss novel attacks that do not match known hashes.
- ✗
IoC-driven hunting using known indicators of compromise from open-source feeds
Why it's wrong here
IoC-driven hunting relies on known IOCs, which an APT may not have left behind; it is reactive.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.