CS0-003 Reporting and Communication Practice Question
A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tactical intelligence
Tactical intelligence includes IoCs such as IP addresses, domain names, and hashes that can be used for detection and blocking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tactical intelligence
Why this is correct
Tactical threat intelligence focuses on the immediate, real-time indicators of compromise (IoCs) such as malicious IP addresses, domain names, and file hashes. Security analysts ingest this data directly into security information and event management (SIEM) systems and firewalls to automate threat detection and block active attacks.
- ✗
Strategic intelligence
Why it's wrong here
Strategic intelligence provides a broad, high-level overview of the threat landscape, focusing on long-term trends, geopolitical risks, and financial impacts. It is designed for executive-level decision-makers to guide security budgets, policy development, and organizational risk management rather than immediate technical defense.
- ✗
Technical intelligence
Why it's wrong here
While technical intelligence involves analyzing specific physical and digital artifacts of an attack, such as malware samples or system vulnerabilities, CompTIA specifically categorizes the actionable feed of IoCs (like IPs and hashes) as tactical intelligence. Technical intelligence focuses more on the forensic analysis of tools rather than the immediate operational deployment of threat feeds.
- ✗
Operational intelligence
Why it's wrong here
Operational intelligence centers on the tactics, techniques, and procedures (TTPs) of specific threat actors and active campaigns. It helps security operations center (SOC) managers understand the "how" and "who" behind an attack to anticipate future adversary behavior, rather than focusing on the raw, automated ingestion of low-level indicators.
Go deeper
Related to this question
Learn chapter
Network Baseline and Anomaly Detection
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.