Courseiva

CS0-003 Reporting and Communication Practice Question

A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tactical intelligence

Tactical intelligence includes IoCs such as IP addresses, domain names, and hashes that can be used for detection and blocking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tactical intelligence

    Why this is correct

    Tactical threat intelligence focuses on the immediate, real-time indicators of compromise (IoCs) such as malicious IP addresses, domain names, and file hashes. Security analysts ingest this data directly into security information and event management (SIEM) systems and firewalls to automate threat detection and block active attacks.

  • ✗

    Strategic intelligence

    Why it's wrong here

    Strategic intelligence provides a broad, high-level overview of the threat landscape, focusing on long-term trends, geopolitical risks, and financial impacts. It is designed for executive-level decision-makers to guide security budgets, policy development, and organizational risk management rather than immediate technical defense.

  • ✗

    Technical intelligence

    Why it's wrong here

    While technical intelligence involves analyzing specific physical and digital artifacts of an attack, such as malware samples or system vulnerabilities, CompTIA specifically categorizes the actionable feed of IoCs (like IPs and hashes) as tactical intelligence. Technical intelligence focuses more on the forensic analysis of tools rather than the immediate operational deployment of threat feeds.

  • ✗

    Operational intelligence

    Why it's wrong here

    Operational intelligence centers on the tactics, techniques, and procedures (TTPs) of specific threat actors and active campaigns. It helps security operations center (SOC) managers understand the "how" and "who" behind an attack to anticipate future adversary behavior, rather than focusing on the raw, automated ingestion of low-level indicators.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.