Threat intelligence is evaluated knowledge about adversaries; threat hunting is a deliberate search of your own environment for activity your detections missed. Objective 1.4 of CS0-004 checks that you can grade intelligence, choose indicators that keep working, and frame a hunt as a hypothesis you can test.
Exam code CS0-004
Domain weight 34%
Tickets here 16
01Where 1.4 sits in the domain
1.4 is a concepts objective in the CS0-004 exam objectives (version 2.0, checked October 2026). It names threat actors, TTPs (tactics, techniques and procedures), confidence levels, collection and sharing, the IoC lifecycle, threat modeling with STRIDE, threat mapping and cyber deception. The Pyramid of Pain and STRIDE are new names compared with CS0-003, and “cyber deception” widens the honeypots and active defense that CS0-003 already listed.
MITRE ATT&CK appears here for TTPs and attribution and again in attack frameworks (objective 3.1). As of ATT&CK v19, checked October 2026, the Enterprise matrix lists 15 tactics, and TA0005, long called Defense Evasion, is now named Stealth (MITRE ATT&CK Enterprise tactics). Prep material written earlier says 14.
02Intelligence sources
Collection sources named in 1.4, with what each is good and bad atscroll →
Source
Examples
Strength
Weakness
Open source (OSINT)
Public reports, open feeds, OTX
Free, broad
Noisy, uneven quality
Closed source
Commercial feeds, paid reports
Curated, with context
Cost, limits on resharing
Sharing communities
Sector groups, government advisories
Peers' sightings
Needs trust and handling rules
Internal
Your incidents, SIEM data, past hunts
Most relevant
Narrow view
Sharing formats are an aside here: STIX describes intelligence objects and TAXII transports them (OASIS CTI documentation). Neither name appears in the CS0-004 objectives.
03Confidence: three tests
Timeliness
Is it current enough to act on? An address an actor abandoned months ago is history.
Relevance
Does it apply to your sector, your technology and your exposure? Intel about software you do not run is noise.
Accuracy
Is it correct and corroborated? One uncorroborated report earns low confidence however alarming it reads.
04Which indicators last
scroll →
Bianco's Pyramid of Pain (2013): the higher the layer, the more it costs an adversary to change
05Indicators, actors and TTPs
Atomic, computed and behavioral
The taxonomy comes from the Lockheed Martin Kill Chain paper by Hutchins and colleagues. Atomic indicators cannot be broken down further: IP addresses, domain names, email addresses, CVE identifiers. Computed indicators are derived from data, such as file hashes and regular expressions. Behavioral indicators combine the others into a pattern of activity. CS0-004 names the atomic and behavioral ends, and the exam favors behavioral detection because it survives an adversary's cosmetic changes. The pyramid above puts hash values at the bottom for the same reason; the Pyramid of Pain page works through it layer by layer.
The IoC lifecycle
An indicator is discovered, enriched and scored, deployed into detections or shared, and then retired when it ages out. Threat-intel platforms such as MISP and OpenCTI manage that cycle (see the analysis tools guide), and the raw signals an indicator starts from are cataloged in indicators of malicious activity. Leaving stale indicators in a blocklist costs performance and produces false matches when an address changes hands.
Actors
An advanced persistent threat (APT) is defined by resources and patience: long dwell time and the ability to retool when blocked. An insider threat works from legitimate access, and can be careless as well as malicious. Attribution is a judgment backed by TTPs, infrastructure and tooling, and it is always stated with a confidence level.
Threat mapping and heat maps
Map known adversary techniques against your detections in an ATT&CK heat map and the gaps become a hunt list.
06A hypothesis-driven hunt
State a testable hypothesis
Example: remote-administration tools are running on finance workstations outside the approved software list.
Pick the data
EDR software-install and process events, the software inventory, proxy logs for the vendors' domains.
Set scope and a time limit
Name the host group and the look-back window up front, so the hunt ends with a result either way.
Search and pivot
Each hit becomes a new question: which user, which parent process, which other hosts.
Close with an outcome
A finding goes to incident response. An empty result is documented and, where possible, turned into a standing detection with the help of SOC automation and process improvement.
07STRIDE in one table
STRIDE threat categories, the property each violates, and a fictional examplescroll →
Decoys come in sizes: a honeypot is one fake system, a honeynet a fake network, a honeytoken a fake credential, file or database record. Two exam traps: a decoy must be isolated so that it cannot become a pivot into real systems, and its alerts are only worth something if someone is watching them.
08Hunting drill
This queue mixes three jobs: profiling an actor, grading a piece of intelligence and planning a hunt.
Ticket 1 / 16
0 right
INC-001
Which type of threat actor is known to disrupt systems or networks as a form of protest against financial institutions?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
ANation-state actors pursue strategic goals such as espionage or sabotage, not public protest.
BOrganized crime is driven by profit, so disruption as protest does not fit its motive.
CAn APT is defined by long-term, stealthy access for espionage or theft, the opposite of a visible protest disruption.
DCorrect: hacktivists attack for political or social causes, and disrupting or defacing financial institutions is a typical form of protest.
INC-002
Which type of cyber adversary typically has backing from national governments and aims to conduct sophisticated cyber espionage operations?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
ACyber vandals cause disruption for its own sake and lack government backing or espionage goals.
BScript kiddies are unskilled attackers who run existing tools, the opposite of funded espionage operators.
CSpammers send bulk unsolicited messages for profit and do not run sophisticated espionage campaigns.
DCorrect: APT groups are well-resourced, often state-sponsored, and maintain long-term covert access for espionage.
INC-003
Which type of threat actor is primarily motivated by financial gain through deploying ransomware attacks?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AInsiders may steal or sabotage out of grievance or for money, but ransomware campaigns for profit are not what defines them.
BNation-states mainly pursue strategic or geopolitical goals, even if some use ransomware as cover.
CCorrect: cybercriminal gangs run ransomware as a business, encrypting or stealing data to extort payment.
DHacktivists are driven by ideology and publicity; ransom payments are what motivate organized crime.
INC-004
Observed TTPs include T1059.001, infrastructure reuse across three campaigns, and tooling fingerprints matching a known cluster. Which actor hypothesis is most supportable?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ANothing in the evidence names APT29, and technique and infrastructure overlap alone does not justify high confidence in a named group.
BDefinite attribution to a nation-state is overstated, since shared tooling and infrastructure can be reused or copied by other actors.
CCorrect: technique overlap, reused infrastructure and matching tooling together support a medium-confidence link to the known cluster, without overclaiming.
DThe evidence goes well beyond timing, so a timing-only, low-confidence match undersells what was observed.
INC-005
A security operations team is implementing a threat hunting program. Which data source would be MOST valuable for identifying potential persistence mechanisms installed by attackers?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
APacket captures show network activity but not the autorun entries and scheduled tasks where persistence lives on the host.
BCorrect: registry Run keys, scheduled tasks and startup folders are where attackers place persistence so their code runs again after a reboot.
CPhysical security logs track badge and door access and cannot show software persistence on hosts.
DEnvironmental monitoring tracks temperature and power, which has nothing to do with attacker persistence.
INC-006
Analysts possess IoCs for suspected dormant C2. Which sequence best begins a hunt across tenant environments?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: proxy logs reveal periodic beacon timing to the suspect destinations, and EDR then ties each hit to the process on the host.
BRaw DNS totals and every HTTP 200 response are huge, unfocused data sets that bury the beacon pattern in noise.
CTotal outbound bytes shows volume but not timing or destination, and dormant beacons send very little data.
DEDR alone lacks the network timing view that exposes beaconing, so correlating with proxy data is what confirms the C2.
INC-007
Given IoCs consisting of three domains, two IPs, and five file hashes, which hunt sequence most effectively expands scope of compromise?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
ASearching only for hashes ignores the domain and IP IoCs, and file hashes are trivial for attackers to change.
BStarting with all user activity across the domain is unfocused and does not use the IoCs in hand.
COne hour of EDR alerts is too narrow in time and in data source to scope a compromise.
DCorrect: network logs find which hosts contacted the IoC domains and IPs, and EDR then confirms the matching files and processes on those hosts.
INC-008
A SOC analyst suspects credential dumping on domain controllers. Which hypothesis, telemetry sources, and timebox best support a focused threat hunt?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: a testable hypothesis (LSASS access on domain controllers), the right telemetry (EDR plus authentication logs) and a short timebox keep the hunt focused.
BNetwork-only data cannot show a process reading LSASS memory, and all outbound SMB is far broader than the hypothesis.
CCredential dumping happens on the domain controllers, so failed logons on member servers are the wrong place and the wrong signal.
DPowerShell anywhere over two weeks is too broad to be a focused hunt and does not target credential dumping on domain controllers.
INC-009
You set up a simulated environment that mimics an enterprise network to monitor and analyze malicious activities. What type of security mechanism did you implement?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ADLP inspects and blocks sensitive data leaving the organization; it does not simulate a network to study attackers.
BAn IDS watches real production traffic for attacks rather than building a decoy environment.
CCorrect: a honeynet is a network of decoy systems built to attract attackers so their behavior can be observed and analyzed.
DAn IPS blocks attacks inline on real traffic; it does not create a fake environment to lure attackers.
INC-010
What is the primary benefit of implementing deception technology (such as honeypots) in a security operations environment?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
ADeception adds systems to deploy and monitor, so it does not reduce staffing.
BCorrect: decoys have no legitimate use, so any interaction is a high-fidelity alert, often early in the attacker's reconnaissance.
CHoneypots detect and study attackers; they do not stop attacks from happening.
DDeception supplements defense in depth and replaces none of the firewalls, patching or endpoint controls.
INC-011
A security team plans deception deployment in a segmented network. Which placement and monitoring approach is optimal?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
AMinimal logging throws away the forensic value of a decoy, and a public DMZ attracts constant internet noise.
BWithout packet capture the team learns that an attacker touched the decoy but not what they did.
CHoneypots on production servers mix decoy and real traffic and risk disrupting services, while normal user accounts there trigger false alarms.
DCorrect: decoys placed where no legitimate user goes produce near-zero false positives, and strict logging with packet capture records what the attacker did.
INC-012
Following an analysis of recent cybersecurity breaches, the IT director recognizes the need for a collaborative effort within the private sector to share threat intelligence, assess vulnerabilities, and discuss responses to cyber threats. Which type of organization should the IT director join?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
ASIGINT is signals intelligence that governments gather from intercepted communications, which makes it no private-sector sharing body.
BCorrect: an ISAC is a sector-based organization where private-sector members share threat intelligence and coordinate responses.
CA CSIRT handles incidents for its own organization or constituency rather than serving as an industry information-sharing forum.
DOASIS is a standards body (it maintains STIX and TAXII, for example) and does not run a threat-sharing community.
INC-013
Which protocol is commonly used for real-time communication of cybersecurity threat intelligence between different organizations and security teams?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: TAXII is the transport protocol (over HTTPS) for exchanging threat intelligence, typically STIX content, between organizations.
BSTIX is the language and format for describing threat intelligence, while TAXII is the protocol that transports it.
CTTPs describe how adversaries operate, so they are intelligence content instead of a communication protocol.
DOpenIOC is a format for describing indicators and has no role as an exchange protocol.
INC-014
A security operations team wants to implement a strategy that provides an early warning of potential attacks. Which of the following would be most effective?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: threat intelligence feeds bring in indicators and TTPs from attacks seen elsewhere, giving warning before they reach your environment.
BTraining reduces user-driven risk but gives no warning about attacks being prepared or under way.
CPenetration testing finds weaknesses at a point in time but does not warn of what attackers are currently doing.
DVulnerability scanning shows your own weaknesses and gives no external warning of active campaigns.
INC-015
Passive DNS shows an IP resolved to many short-lived malicious domains and belongs to an ASN known for bulletproof hosting. What is the most likely assessment?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
APassive DNS history and ASN reputation are strong evidence on their own, so a sandbox is not required to form an assessment.
BHaving no current resolutions does not clear an IP whose history is full of short-lived malicious domains.
CThe evidence justifies concern, but blocking with no investigation skips checking internal impact and business use.
DCorrect: repeated short-lived malicious domains on a bulletproof-hosting ASN point to malicious infrastructure, which warrants checking internal telemetry for contact.
INC-016
During threat modeling, a team finds that an internal API accepts a forged identity token and then acts as another ordinary user with the same rights. In STRIDE, which threat is this and which property does it violate?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
ATampering is unauthorized change to data or code; the issue here is a false identity, not altered data.
BRepudiation is denying an action without proof otherwise; the finding is about posing as someone else.
CThe forged identity has the same rights as the caller's peers, so no higher privilege is gained.
DCorrect: pretending to be another identity is spoofing, and the property it breaks is authentication.