Courseiva

CS0-003 Incident Response and Management Practice Question

After a DDoS attack, the CSIRT wants to share IOCs with other organizations. Which protocol is specifically designed for automated, real-time threat intelligence sharing?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TAXII

TAXII (Trusted Automated Exchange of Indicator Information) is the protocol for exchanging threat intelligence over HTTPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HTTP

    Why it's wrong here

    While HTTP (or HTTPS) serves as the underlying transport layer protocol for many web-based services, it lacks a standardized schema or native capabilities for structuring and exchanging threat intelligence. It is a general-purpose application layer protocol rather than a dedicated framework designed for automated, real-time ingestion of Indicators of Compromise (IoCs) by security tools.

  • ✗

    SMTP

    Why it's wrong here

    Simple Mail Transfer Protocol (SMTP) is designed for transmitting electronic mail messages between servers. Although security teams can manually email threat reports using SMTP, it does not support the automated, machine-to-machine parsing and real-time synchronization required for dynamic IoC dissemination across security appliances like firewalls and SIEMs.

  • ✓

    TAXII

    Why this is correct

    Trusted Automated eXchange of Indicator Information (TAXII) is an application-layer protocol specifically designed to route cyber threat intelligence (CTI) over HTTPS. It supports common sharing models such as hub-and-spoke or peer-to-peer, allowing CSIRTs to automate the secure distribution and ingestion of STIX-formatted IoCs directly into security tools.

  • ✗

    FTP

    Why it's wrong here

    File Transfer Protocol (FTP) is a legacy protocol used to copy files from one host to another over a network. It lacks the structured messaging, publish-subscribe architecture, and real-time query capabilities necessary to dynamically distribute threat intelligence feeds to automated security orchestration and response platforms.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.