Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

During a security incident, a SOC analyst identifies a process with a suspicious hash on several endpoints. The analyst wants to determine if this hash is known to be malicious by querying internal and external threat intelligence sources. Which standard should the analyst use to structure the threat intelligence data for automated sharing?

⚠ Common exam trap

The trap is the classic STIX-vs-TAXII confusion: candidates see 'automated sharing' and pick TAXII, but the question asks which standard structures the data — that is STIX; TAXII only transports it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

STIX

STIX (Structured Threat Information eXpression) is the OASIS standard that defines the structured language and data model for representing cyber threat intelligence — indicators, malware, attack patterns, and their relationships — in a machine-readable JSON format. When an analyst needs to structure threat intelligence data (such as a suspicious file hash) for automated sharing, STIX is the correct standard because it defines the content schema itself. TAXII is the transport protocol that carries STIX, not the structuring standard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    TAXII

    Why it's wrong here

    TAXII defines the transport protocol for exchanging threat intelligence over HTTPS, not the structure of the indicators themselves. It is tempting because TAXII and STIX are usually deployed together, but STIX supplies the data model describing hashes and relationships. TAXII would be correct when specifying how services request and deliver collections.

  • ✓

    STIX

    Why this is correct

    STIX provides a structured, machine-readable schema for expressing indicators, malware and relationships, enabling automated exchange between platforms via TAXII. It satisfies the requirement to structure threat intelligence for automated sharing, unlike prose formats or vulnerability scoring systems.

  • ✗

    OpenIOC

    Why it's wrong here

    OpenIOC is a host-indicator format for describing artefacts found on a compromised machine, not a transport standard for automated indicator exchange between platforms. It is tempting because it structures compromise evidence, and would suit documenting forensic findings from a single endpoint investigation.

  • ✗

    CybOX

    Why it's wrong here

    CybOX defines observable cyber objects and their properties, but it is a data model rather than a complete sharing protocol with transport bindings. It is tempting because it underpins STIX, and would be the right choice when modelling low-level observables for a detection tool.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.