CAS-004 Security Operations Practice Question
During a security incident, a SOC analyst identifies a process with a suspicious hash on several endpoints. The analyst wants to determine if this hash is known to be malicious by querying internal and external threat intelligence sources. Which standard should the analyst use to structure the threat intelligence data for automated sharing?
⚠ Common exam trap
The trap is the classic STIX-vs-TAXII confusion: candidates see 'automated sharing' and pick TAXII, but the question asks which standard structures the data — that is STIX; TAXII only transports it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
STIX
STIX (Structured Threat Information eXpression) is the OASIS standard that defines the structured language and data model for representing cyber threat intelligence — indicators, malware, attack patterns, and their relationships — in a machine-readable JSON format. When an analyst needs to structure threat intelligence data (such as a suspicious file hash) for automated sharing, STIX is the correct standard because it defines the content schema itself. TAXII is the transport protocol that carries STIX, not the structuring standard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TAXII
Why it's wrong here
TAXII defines the transport protocol for exchanging threat intelligence over HTTPS, not the structure of the indicators themselves. It is tempting because TAXII and STIX are usually deployed together, but STIX supplies the data model describing hashes and relationships. TAXII would be correct when specifying how services request and deliver collections.
- ✓
STIX
Why this is correct
STIX provides a structured, machine-readable schema for expressing indicators, malware and relationships, enabling automated exchange between platforms via TAXII. It satisfies the requirement to structure threat intelligence for automated sharing, unlike prose formats or vulnerability scoring systems.
- ✗
OpenIOC
Why it's wrong here
OpenIOC is a host-indicator format for describing artefacts found on a compromised machine, not a transport standard for automated indicator exchange between platforms. It is tempting because it structures compromise evidence, and would suit documenting forensic findings from a single endpoint investigation.
- ✗
CybOX
Why it's wrong here
CybOX defines observable cyber objects and their properties, but it is a data model rather than a complete sharing protocol with transport bindings. It is tempting because it underpins STIX, and would be the right choice when modelling low-level observables for a detection tool.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.