Courseiva
mediumMultiple Select

CS0-003 Practice Question: A SOAR playbook enriches suspicious IP addresses

A SOAR playbook enriches suspicious IP addresses. Which enrichment sources are useful? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between authoritative, structured enrichment sources (threat intel feeds, internal logs) versus irrelevant or untrusted data (social media, physical inventory) to see if candidates understand that SOAR automation requires reliable, machine-readable inputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Threat intelligence reputation and first-seen date

Threat intelligence reputation feeds (e.g., VirusTotal, AlienVault OTX) provide a risk score and first-seen date for an IP, which helps determine if it is known for malicious activity and how recently it became active. Internal asset and previous-seen telemetry (e.g., from a SIEM or asset management database) reveals if the IP belongs to an internal host or has been observed in past incidents, enabling context-aware response. Both sources directly support enrichment by adding authoritative, actionable data to the playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Threat intelligence reputation and first-seen date

    Why this is correct

    Querying external threat intelligence feeds for an IP's reputation score and first-seen registration date provides critical external context. This data helps the SOAR playbook assess the likelihood of malicious activity, such as identifying newly registered domains or known command-and-control nodes, enabling automated, risk-based triaging.

  • ✓

    Internal asset and previous-seen telemetry

    Why this is correct

    Correlating an external IP address with internal asset databases and historical network telemetry allows the SOAR platform to establish baseline behavior. This internal context helps analysts determine if the communication is a routine business transaction or an anomalous connection indicating potential data exfiltration or lateral movement.

  • ✗

    Random social media comments about cybersecurity

    Why it's wrong here

    Social media commentary lacks the structured, vetted, and verified nature required for automated threat intelligence. Relying on unvetted public posts introduces high rates of false positives and noise into the SOAR workflow, rendering it ineffective for automated decision-making. Playbooks require structured, authoritative data sources to execute reliable enrichment actions.

  • ✗

    Office chair inventory

    Why it's wrong here

    Physical facilities and furniture inventories do not contain network, host, or identity data relevant to security investigations. A SOAR playbook requires technical context, such as IP-to-MAC mappings or active directory details, to assess network risk. Non-IT physical assets provide zero utility for correlating network telemetry or determining IP maliciousness.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.