CAS-004 Security Operations Practice Question
A security analyst is investigating a potential advanced persistent threat (APT) that has evaded traditional signature-based defenses. The analyst hypothesizes that the attacker is using a specific technique from the MITRE ATT&CK framework: process injection. Which threat hunting methodology is most appropriate for this scenario?
⚠ Common exam trap
CAS-005 often tests the distinction between reactive IoC/signature-based hunting and proactive hypothesis-driven hunting, tricking candidates into choosing familiar but ineffective methods like SIEM rules or IoC feeds when the scenario explicitly states evasion of traditional defenses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
Hypothesis-driven hunting is the most appropriate because the analyst has a specific, testable hypothesis: the attacker is using process injection, a known ATT&CK technique (T1055). This methodology involves proactively searching for evidence of that technique—such as anomalous memory allocations, thread execution, or API calls—rather than waiting for alerts. It directly addresses the scenario where signature-based defenses have failed, as it focuses on behavioral artifacts rather than static indicators.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TTP-driven hunting by analyzing adversary behaviors mapped to the ATT&CK framework
Why it's wrong here
TTP-driven hunting is the correct methodology here, so this option does not fail the scenario. It maps observed adversary behaviours to ATT&CK techniques such as process injection, guiding hypothesis formation and detection queries. Signature, IOC or anomaly hunting would miss injection because it leaves no unique file hash.
- ✓
Hypothesis-driven hunting based on a specific technique (process injection) and searching for evidence in memory and process activity
Why this is correct
Hypothesis-driven hunting tests the specific process injection technique by examining memory and process activity for injected code, hollowed processes or anomalous API calls. This targeted approach suits an APT that evades signature-based defences, since it searches for behavioural evidence rather than known indicators.
- ✗
Automated hunting using SIEM correlation rules that trigger on known malicious file hashes
Why it's wrong here
Hash-based SIEM correlation rules detect known malicious files, not process injection, which executes within legitimate processes and leaves no distinctive file hash. It is tempting because automated correlation is valuable for high-volume IoC matching, and it would be correct when hunting known malware families with published hashes.
- ✗
IoC-driven hunting using known indicators of compromise from open-source feeds
Why it's wrong here
IoC-driven hunting relies on known indicators from feeds, which signature-based defences already consume; process injection produces behavioural artefacts, not published hashes or domains. It is tempting because IoC feeds are easy to operationalise and effective against commodity malware, but an APT using injection evades such static indicators.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.