CAS-004 Security Operations Practice Question
During an incident response, a security analyst identifies a previously unknown malware variant. Which type of threat intelligence feed would provide the most timely and structured information about this threat?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
STIX/TAXII feed
STIX/TAXII enables sharing of structured threat intelligence in a standardized format, allowing for automated consumption and immediate updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
STIX/TAXII feed
Why this is correct
STIX/TAXII provides structured, machine-readable threat intelligence.
- ✗
An ISAC
Why it's wrong here
ISACs are community-based, but may not be as immediate or structured as automated feeds.
- ✗
Open source intelligence (OSINT)
Why it's wrong here
OSINT is unstructured and requires manual analysis.
- ✗
A commercial threat feed
Why it's wrong here
Commercial feeds are useful but may have delays; STIX/TAXII is the standard for structured, automated sharing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.