CAS-004 Security Operations Practice Question
A security team is implementing a threat intelligence program and wants to consume intelligence from various sources. Which TWO of the following are commonly used threat intelligence feeds or sharing mechanisms? (Select TWO.)
⚠ Common exam trap
The trap is picking generic protocols (DNS, HTTP, SMTP) because they're used to transport threat intel — but the question asks for sharing mechanisms/feeds, which are ISACs and STIX/TAXII.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ISACs
ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that collect, analyze, and share threat intelligence among their members, making them a standard threat intelligence sharing mechanism. STIX/TAXII is also correct: STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is the application-layer protocol used to exchange that STIX data over HTTPS. By contrast, DNS, SMTP, and HTTP are general-purpose network protocols used for name resolution, email transport, and web communication respectively; while threat intelligence may traverse them, they are not themselves threat intelligence feeds or sharing mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS
Why it's wrong here
DNS resolves domain names and transports queries; it is not a threat intelligence feed or sharing mechanism. It tempts because attackers abuse DNS and DNS logs can reveal malicious domains, but structured indicator exchange uses formats such as STIX/TAXII, not the DNS protocol itself.
- ✗
SMTP
Why it's wrong here
SMTP delivers email; it is a transport protocol, not a threat intelligence feed or sharing mechanism. It tempts because email alerts and mailing lists often carry indicators, but structured machine-readable exchange relies on STIX over TAXII, not SMTP itself.
- ✗
HTTP
Why it's wrong here
HTTP is a generic transport protocol, not a threat intelligence feed or sharing mechanism. It tempts because TAXII servers are reached over HTTPS, but the sharing mechanism is TAXII with STIX payloads; HTTP alone carries no indicator semantics or exchange model.
- ✓
ISACs
Why this is correct
ISACs are sector-specific non-profit bodies through which member organisations share threat indicators, incidents and mitigation guidance. Consuming their feeds satisfies the stem's requirement for a commonly used threat intelligence sharing mechanism, alongside ISAO and CERT channels.
- ✓
STIX/TAXII
Why this is correct
STIX defines a structured language for describing threat indicators, and TAXII specifies the transport protocol for exchanging that intelligence between systems. Together they satisfy the stem's requirement for a commonly used sharing mechanism, enabling automated feed consumption across platforms.
Visual reference
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.