CS0-003 Incident Response and Management Practice Question
An organization has been experiencing repeated phishing attacks that bypass email filters. The incident response team wants to enhance detection by creating rules based on characteristics of the phishing emails. Which of the following IOCs would be most effective for detecting similar phishing campaigns?
⚠ Common exam trap
A common mix-up: candidates confuse host-based IOCs (hashes, registry keys) with network/email-layer IOCs — candidates often pick file hashes because they sound 'technical,' but the question asks about detecting phishing emails at the filter-bypass stage, which requires email-observable indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email subject lines and sender domain
Email subject lines and sender domains are the most effective IOCs for detecting phishing campaigns that bypass email filters, because these characteristics are directly observable at the email gateway and are commonly reused across a campaign. Attackers often reuse subject line templates and sender domains (or lookalike domains) across many messages, making them reliable detection pivots. Unlike file hashes or registry keys, these IOCs do not require the payload to execute or the attachment to be present, so they catch the phishing attempt at delivery time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Registry keys modified by the payload
Why it's wrong here
Registry key modifications are host-based, post-execution artifacts that only occur after a user has already downloaded and executed the malicious payload. Because they do not exist within the email itself, they cannot be used by mail gateways to detect or block incoming phishing campaigns before they reach user inboxes.
- ✗
File hashes of attached malware
Why it's wrong here
While file hashes are highly specific indicators of compromise, attackers easily bypass hash-based detection by slightly altering the malware's binary structure or using polymorphic packers for each email. Consequently, relying on file hashes is ineffective for blocking a broad, evolving phishing campaign that distributes unique file variants to different targets.
- ✗
IP addresses of the phishing servers
Why it's wrong here
Threat actors frequently rotate their sending infrastructure, utilize compromised legitimate mail servers, or leverage dynamic cloud IP addresses to bypass reputation-based blocks. Because these IP addresses change rapidly during a campaign, they are highly volatile and unreliable indicators for long-term or consistent filtering compared to domain-level and structural email indicators.
- ✓
Email subject lines and sender domain
Why this is correct
Email subject lines and sender domains serve as highly effective, static indicators of compromise that can be ingested directly into secure email gateways (SEGs) to block incoming campaigns. By creating transport rules or blocklists based on these specific header elements, security analysts can proactively intercept and neutralize widespread phishing waves before users interact with them.
Go deeper
Related to this question
Learn chapter
Legal Considerations in Incident Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.