CS0-003 Incident Response and Management Practice Question
An organization uses MISP as its threat intelligence platform. After a security incident, the team wants to share IOCs with other trusted organizations. Which standard should they use to package and exchange the threat intelligence?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
STIX/TAXII
STIX (Structured Threat Information Expression) is the standard for describing threat intelligence, and TAXII is the protocol for sharing it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMP
Why it's wrong here
Simple Network Management Protocol (SNMP) is designed for monitoring and managing network devices, such as routers and switches, by collecting system metrics and sending alerts (traps). It lacks the schema, data models, and transport mechanisms required to represent and distribute complex threat intelligence indicators or adversary behaviors.
- ✗
NetFlow
Why it's wrong here
NetFlow is a proprietary Cisco protocol used to collect IP network traffic statistics and monitor flow data for bandwidth and security analysis. While it helps security analysts detect anomalies and investigate incidents within a network, it does not serve as a format or protocol for exchanging structured threat intelligence feeds between external platforms.
- ✗
SMTP
Why it's wrong here
Simple Mail Transfer Protocol (SMTP) is the standard protocol used for transmitting electronic mail across IP networks. Although security teams may receive unstructured threat advisories via email, SMTP is not designed to parse, synchronize, or automate the exchange of machine-readable threat intelligence indicators between platforms like MISP.
- ✓
STIX/TAXII
Why this is correct
Structured Threat Information Expression (STIX) provides a standardized XML/JSON schema to represent cyber threat intelligence, while Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol used to securely route this data. MISP natively supports STIX/TAXII to enable automated, machine-to-machine sharing of indicators of compromise (IoCs) and threat actor profiles across diverse security tools.
Go deeper
Related to this question
Learn chapter
Critical Windows Event IDs for Security
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.