CS0-003 Incident Response and Management Practice Question
A security analyst is reviewing indicators of compromise (IOCs) from a recent phishing campaign. Which of the following is an example of an email-related IOC?
⚠ Common exam trap
CS0-004 often tests IOC categorization — candidates pick C or D because they are 'from the email,' but the exam distinguishes email-header IOCs from network and file IOCs, and only the sender address lives in the email header.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Suspicious sender email address
A suspicious sender email address is an email-header-level artifact — it appears in the From, Reply-To, or Return-Path fields and is directly tied to the phishing email itself. That makes it an email-related IOC, unlike network or file artifacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Domain name in the URL
Why it's wrong here
While a domain name within a URL can be found inside an email body, it is classified as a network or web-based indicator of compromise (IOC). Security tools categorize URLs and domains under network threat intelligence rather than email-specific metadata, as they are resolved via DNS and accessed via HTTP/HTTPS.
- ✓
Suspicious sender email address
Why this is correct
The sender's email address is a primary, direct email indicator of compromise found within the SMTP envelope or mail headers (such as the "From:" field). Analysts use this specific attribute to create mail transport rules, blocklists, and search mailboxes for phishing campaigns targeting the organization.
- ✗
IP address of the sender's mail server
Why it's wrong here
The IP address of the originating mail server is categorized as a network-level indicator of compromise. Although it appears in the SMTP "Received" headers, network firewalls, intrusion detection systems, and IP reputation lists process this data, making it a broader network IOC rather than an application-specific email indicator.
- ✗
File hash of an attachment
Why it's wrong here
A cryptographic file hash (such as MD5, SHA-1, or SHA-256) of an attachment is classified as a host-based or file-level indicator of compromise. While the file may be delivered via email, the hash itself is used by endpoint detection and response (EDR) systems and antivirus tools to identify malicious payloads on disk.
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
IOC
IOC stands for Indicator of Compromise, which is forensic evidence that a system has been breached or infected by malware.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.