Courseiva

CS0-003 Incident Response and Management Practice Question

An organization has identified indicators of compromise (IOCs) from a recent incident. Which data format is specifically designed for sharing threat intelligence in a standardized, machine-readable way?

⚠ Common exam trap

CS0-004 often tests whether candidates pick a generic serialization format like JSON instead of the domain-specific threat-intelligence standard STIX, so remember STIX is the schema and JSON is merely one possible encoding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

STIX

STIX (Structured Threat Information Expression) is a standardized language and serialization format specifically designed by MITRE and OASIS to represent and share cyber threat intelligence in a machine-readable way. It defines domain objects like Indicator, Malware, ThreatActor, and Relationship, and is typically transported via TAXII. JSON, CSV, and PDF are generic data formats not purpose-built for threat intel semantics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PDF

    Why it's wrong here

    Portable Document Format (PDF) is a human-readable document format designed for presentation rather than automated data exchange. While useful for executive summaries or security reports, it lacks the structured, machine-readable schema required for security tools to automatically parse, ingest, and act upon threat intelligence indicators in real-time.

  • ✗

    CSV

    Why it's wrong here

    Comma-Separated Values (CSV) is a flat, tabular format that lacks a standardized schema for representing complex threat relationships. While it can list simple indicators like IP addresses or file hashes, it cannot natively represent the multi-dimensional relationships between threat actors, campaigns, and malware behaviors that modern threat intelligence platforms require.

  • ✗

    JSON

    Why it's wrong here

    JavaScript Object Notation (JSON) is a generic data-interchange format rather than a specialized threat intelligence standard. Although STIX itself is serialized in JSON, raw or non-standardized JSON lacks the predefined, universally understood taxonomies and schemas necessary for disparate security systems to interpret threat data consistently without custom parsing scripts.

  • ✓

    STIX

    Why this is correct

    Structured Threat Information Expression (STIX) is an industry-standard language specifically designed to standardize the representation of cyber threat intelligence. It enables organizations to share structured threat data—including indicators, adversaries, and tactics—in a consistent, machine-readable format that security tools like SIEMs, SOAR platforms, and firewalls can automatically ingest and operationalize.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.