Courseiva

CS0-003 Incident Response and Management Practice Question

An organization uses MISP (Malware Information Sharing Platform) to share threat intelligence with trusted partners. Which of the following standards is commonly used by MISP to structure and exchange threat intelligence data?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

STIX/TAXII

STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Indicator Information) are standards for exchanging cyber threat intelligence. MISP supports STIX and TAXII for sharing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NetFlow

    Why it's wrong here

    NetFlow exports metadata about IP flows — addresses, ports, byte counts — for traffic analysis; it lacks the indicator, attribute and relationship schema MISP requires to exchange threat intelligence. NetFlow is the right choice for detecting anomalous traffic patterns and volumetric behaviour on routers.

  • ✗

    SNMP

    Why it's wrong here

    SNMP polls and traps management counters and device state; it defines no taxonomy for indicators, observables or adversary attributes, so MISP cannot structure threat intelligence with it. SNMP is correct for monitoring interface statistics, uptime and hardware health across network devices.

  • ✓

    STIX/TAXII

    Why this is correct

    STIX provides a structured language for describing threat indicators, while TAXII defines the transport protocol for exchanging that data between platforms. MISP natively supports both, satisfying the requirement to structure and exchange threat intelligence with trusted partners. OpenIOC and PDF are unrelated formats, and Microsoft Entra ID governs identity, not intelligence sharing.

  • ✗

    Syslog

    Why it's wrong here

    Syslog transports device event and log messages to a collector; it carries no structured threat-intelligence objects, attributes or indicators, so MISP cannot use it to exchange data with partners. Syslog is the right choice for centralised logging and correlation of infrastructure events.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.