Courseiva

CS0-003 Incident Response and Management Practice Question

A security analyst is reviewing indicators of compromise (IOCs) from a recent phishing campaign. Which of the following is an example of an email-related IOC?

⚠ Common exam trap

CS0-004 often tests IOC categorization — candidates pick C or D because they are 'from the email,' but the exam distinguishes email-header IOCs from network and file IOCs, and only the sender address lives in the email header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Suspicious sender email address

A suspicious sender email address is an email-header-level artifact — it appears in the From, Reply-To, or Return-Path fields and is directly tied to the phishing email itself. That makes it an email-related IOC, unlike network or file artifacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Domain name in the URL

    Why it's wrong here

    While a domain name within a URL can be found inside an email body, it is classified as a network or web-based indicator of compromise (IOC). Security tools categorize URLs and domains under network threat intelligence rather than email-specific metadata, as they are resolved via DNS and accessed via HTTP/HTTPS.

  • ✓

    Suspicious sender email address

    Why this is correct

    The sender's email address is a primary, direct email indicator of compromise found within the SMTP envelope or mail headers (such as the "From:" field). Analysts use this specific attribute to create mail transport rules, blocklists, and search mailboxes for phishing campaigns targeting the organization.

  • ✗

    IP address of the sender's mail server

    Why it's wrong here

    The IP address of the originating mail server is categorized as a network-level indicator of compromise. Although it appears in the SMTP "Received" headers, network firewalls, intrusion detection systems, and IP reputation lists process this data, making it a broader network IOC rather than an application-specific email indicator.

  • ✗

    File hash of an attachment

    Why it's wrong here

    A cryptographic file hash (such as MD5, SHA-1, or SHA-256) of an attachment is classified as a host-based or file-level indicator of compromise. While the file may be delivered via email, the hash itself is used by endpoint detection and response (EDR) systems and antivirus tools to identify malicious payloads on disk.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.