mediumMultiple Select
CS0-003 Practice Question: A SOAR playbook enriches suspicious IP addresses
A SOAR playbook enriches suspicious IP addresses. Which enrichment sources are useful? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between authoritative, structured enrichment sources (threat intel feeds, internal logs) versus irrelevant or untrusted data (social media, physical inventory) to see if candidates understand that SOAR automation requires reliable, machine-readable inputs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat intelligence reputation and first-seen date
Threat intelligence reputation feeds (e.g., VirusTotal, AlienVault OTX) provide a risk score and first-seen date for an IP, which helps determine if it is known for malicious activity and how recently it became active. Internal asset and previous-seen telemetry (e.g., from a SIEM or asset management database) reveals if the IP belongs to an internal host or has been observed in past incidents, enabling context-aware response. Both sources directly support enrichment by adding authoritative, actionable data to the playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Threat intelligence reputation and first-seen date
Why this is correct
Querying external threat intelligence feeds for an IP's reputation score and first-seen registration date provides critical external context. This data helps the SOAR playbook assess the likelihood of malicious activity, such as identifying newly registered domains or known command-and-control nodes, enabling automated, risk-based triaging.
- ✓
Internal asset and previous-seen telemetry
Why this is correct
Correlating an external IP address with internal asset databases and historical network telemetry allows the SOAR platform to establish baseline behavior. This internal context helps analysts determine if the communication is a routine business transaction or an anomalous connection indicating potential data exfiltration or lateral movement.
- ✗
Random social media comments about cybersecurity
Why it's wrong here
Social media commentary lacks the structured, vetted, and verified nature required for automated threat intelligence. Relying on unvetted public posts introduces high rates of false positives and noise into the SOAR workflow, rendering it ineffective for automated decision-making. Playbooks require structured, authoritative data sources to execute reliable enrichment actions.
- ✗
Office chair inventory
Why it's wrong here
Physical facilities and furniture inventories do not contain network, host, or identity data relevant to security investigations. A SOAR playbook requires technical context, such as IP-to-MAC mappings or active directory details, to assess network risk. Non-IT physical assets provide zero utility for correlating network telemetry or determining IP maliciousness.
Go deeper
Related to this question
Learn chapter
Business Email Compromise (BEC) Response
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.