CS0-003 Reporting and Communication Practice Question
A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)
⚠ Common exam trap
CS0-004 often tests the confusion between tactical and strategic intelligence audiences, tempting candidates to select 'executive leadership' or 'board' because those roles sound authoritative, when in fact they consume strategic, not atomic, intelligence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SOC analysts
SOC analysts (B) are a primary consumer of tactical IoCs because they monitor SIEM alerts, tune detection rules, and hunt for the listed IP addresses, domains, and file hashes in day-to-day security operations. Incident responders (D) also need these atomic indicators to scope and contain active compromises, for example by searching endpoints for the specified file hashes or blocking the malicious domains and IPs at the perimeter. Both roles operate at the tactical level where concrete, machine-readable indicators drive immediate detection and response actions. By contrast, the board of directors (A) and executive leadership (C) consume strategic intelligence such as risk trends, business impact, and threat landscape summaries, not raw IoCs. Network engineers (E) focus on routing, switching, and infrastructure availability, so while they may implement blocks, they are not a primary audience for interpreting threat intelligence reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Board of directors
Why it's wrong here
The board of directors requires high-level information about organizational risk exposure, financial impact, and strategic threat trends rather than raw technical artifacts. A list of IoCs such as file hashes and C2 domains contains no executive context and would obscure the risk narrative. Board communications should be distilled into key risk metrics and mitigation status, not left as technical indicators for the C-suite to interpret.
- ✓
SOC analysts
Why this is correct
SOC analysts are the primary consumers for a report consisting of technical IoCs, as they operationalize these indicators into detection logic such as SIEM signatures and alert rules. The report should be structured to support correlation with telemetry, enabling prioritization and investigation of matching events. For the SOC, IoCs serve as the foundational input for proactive threat detection and ongoing security monitoring.
- ✗
Executive leadership
Why it's wrong here
Executive leadership, like the C-suite, consumes threat intelligence at a strategic level, focused on how threats affect business objectives, regulatory compliance, and resource allocation. Detailed indicators of compromise lack decision-making context and are typically stripped of the tactical specificity this audience neither needs nor wants. An executive-facing summary would consist of executive dashboards and geographic campaign trends, not raw technical artifacts.
- ✓
Incident responders
Why this is correct
Incident responders directly leverage IoCs during active investigations to scope the incident, query endpoint and network telemetry, and identify additional affected hosts. The indicators provide a concrete baseline for containment, eradication, and forensic correlation, and the report can guide hunt team activities. Though the SOC may triage alerts from the same indicators, IR is a key secondary audience for operational support during a confirmed breach.
- ✗
Network engineers
Why it's wrong here
Network engineers typically require operational security guidance — such as firewall rule recommendations, filtering guidance, or network segmentation changes — rather than a raw IOC report. While they may act on specific malicious infrastructure, IoCs are normally handed to the security detection teams to convert into detect-and-respond actions. Without transformation into network-specific mitigations, the report has limited direct utility for infrastructure teams.
Go deeper
Related to this question
Learn chapter
Lessons Learned and Post-Incident Activities
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Threat intelligence
Threat intelligence is evidence-based knowledge about existing or emerging cyber threats that helps organizations defend against attacks.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.