CS0-003 Incident Response and Management Practice Question
A security analyst is reviewing IOCs from a threat intelligence feed. The analyst wants to enrich the IOCs using open-source tools. Which THREE tools are commonly used for IOC enrichment? (Select three.)
⚠ Common exam trap
CS0-004 often tests whether candidates confuse enrichment tools (reputation, registration, exposure data) with analysis or scanning tools (Wireshark, Nmap), so options that are legitimate security tools but not enrichment sources are the trap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WHOIS
WHOIS (A) is correct because it enriches domain and IP IOCs with registration data such as registrar, creation/expiration dates, name servers, and registrant contact details, which help attribute infrastructure to threat actors. VirusTotal (C) is correct because it aggregates results from dozens of antivirus engines, URL/domain scanners, and sandboxes to provide reputation, detection ratios, and behavioral context for hashes, URLs, domains, and IPs. Shodan (D) is correct because it enriches IP and service IOCs with internet-facing banner data, open ports, service versions, TLS certificates, and geolocation, revealing exposed infrastructure tied to an indicator. Wireshark (B) is a packet capture and protocol analysis tool used for live traffic inspection, not for querying external reputation or registration data about IOCs. Nmap (E) is a network scanning and host-discovery utility used to probe systems directly, not an open-source enrichment service that correlates IOCs against third-party intelligence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
WHOIS
Why this is correct
WHOIS queries domain registration databases, returning registrar, registrant contact, creation and expiration dates, and nameserver records. For an IOC like a known malicious domain, WHOIS enables analysts to pivot on registration metadata, identify shared infrastructure, or detect typosquatting and recently registered domains. It is a read-only lookup service, not a traffic analysis tool, making it a first-line passive enrichment source.
- ✗
Wireshark
Why it's wrong here
Wireshark's core purpose is deep packet inspection and live protocol analysis, capturing frames off the wire for offline examination. It does not query external intelligence sources, maintain reputation databases, or enrich an IOC's context by itself; rather, it would be used after an incident to inspect traffic patterns. For static IOC enrichment, it offers no registration or device-level metadata, so it is not a suitable analysis tool.
- ✓
VirusTotal
Why this is correct
VirusTotal aggregates results from over 70 antivirus engines and other sandboxing services; an analyst can submit a file hash, URL, or domain to see detection ratios, threat classifications, and community comments. It also provides related samples, vendor-specific detection labels, and a visual relationship graph, which helps determine the breadth of an indicator's maliciousness. Using its API, security teams can automate bulk IOC reputation checks, making it a key triage tool.
- ✓
Shodan
Why this is correct
Shodan is a search engine for internet-facing devices, indexing banners, open ports, SSL certificates, and service fingerprints such as HTTP or FTP headers. When an IOC is an IP address, Shodan can reveal the organization, hosting provider, geographic location, and exposed services, letting analysts spot compromised infrastructure or vulnerable industrial controls. It does not analyze packet captures or run AV checks, but it is vital for understanding device-level exposure tied to an IP.
- ✗
Nmap
Why it's wrong here
Nmap is an active network scanning tool used to discover hosts, map open ports, and detect service versions on a target network during penetration testing or reconnaissance. It generates its own traffic and requires a live target to scan, whereas IOC enrichment relies on passive queries to third-party databases to gather existing context. Running Nmap against a known IOC IP provides no historical or threat intelligence data, and could even alert network defenders, so it is not an enrichment technique.
Go deeper
Related to this question
Learn chapter
SIGMA and YARA Detection Rules
Key term
IOC
IOC stands for Indicator of Compromise, which is forensic evidence that a system has been breached or infected by malware.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.