CS0-003 Incident Response and Management Practice Question
An organization uses MISP (Malware Information Sharing Platform) to share threat intelligence with trusted partners. Which of the following standards is commonly used by MISP to structure and exchange threat intelligence data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
STIX/TAXII
STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Indicator Information) are standards for exchanging cyber threat intelligence. MISP supports STIX and TAXII for sharing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NetFlow
Why it's wrong here
NetFlow exports metadata about IP flows — addresses, ports, byte counts — for traffic analysis; it lacks the indicator, attribute and relationship schema MISP requires to exchange threat intelligence. NetFlow is the right choice for detecting anomalous traffic patterns and volumetric behaviour on routers.
- ✗
SNMP
Why it's wrong here
SNMP polls and traps management counters and device state; it defines no taxonomy for indicators, observables or adversary attributes, so MISP cannot structure threat intelligence with it. SNMP is correct for monitoring interface statistics, uptime and hardware health across network devices.
- ✓
STIX/TAXII
Why this is correct
STIX provides a structured language for describing threat indicators, while TAXII defines the transport protocol for exchanging that data between platforms. MISP natively supports both, satisfying the requirement to structure and exchange threat intelligence with trusted partners. OpenIOC and PDF are unrelated formats, and Microsoft Entra ID governs identity, not intelligence sharing.
- ✗
Syslog
Why it's wrong here
Syslog transports device event and log messages to a collector; it carries no structured threat-intelligence objects, attributes or indicators, so MISP cannot use it to exchange data with partners. Syslog is the right choice for centralised logging and correlation of infrastructure events.
Go deeper
Related to this question
Learn chapter
Malware Sandboxing and Detonation
Key term
TAXII
TAXII (Trusted Automated eXchange of Indicator Information) is a standardized protocol that enables the automated sharing of cyber threat intelligence (CTI) between organizations and security systems.
Key term
Threat intelligence
Threat intelligence is evidence-based knowledge about existing or emerging cyber threats that helps organizations defend against attacks.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.