1.4 Compare and contrast threat-intelligence and threat-hunting concepts.
Objective 1.4 sits in Security Operations, which carries 33% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
An ISAC sends your team an advisory marked TLP:AMBER. A partner MSP that handles your monitoring asks for a copy. May you share it?
Correct.
Concept
Sharing labels bound how far intelligence may travel. Each label draws a specific boundary, and honoring it is what keeps sources willing to share the next advisory.
Why C
TLP:AMBER permits limited disclosure on a need-to-know basis within the recipient's organization and its clients, so a partner acting for you can receive it.
Now you: objective 1.4 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
Your SOC receives indicators marked TLP:AMBER+STRICT. The team wants to pass them to a downstream client for blocking. What is the constraint?
Sample question 2 of 3
During an incident call, a peer verbally shares a TLP:RED indicator. A teammate who missed the call asks you to forward it. What should you do?
Sample question 3 of 3
A vendor labels a bulletin TLP:GREEN and asks your team how far the community may spread it. What do you tell them is the boundary?
Full CySA+ question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Operations
- 1.1 1.1 Explain the importance of system and network architecture concepts in security operations.
- 1.2 1.2 Given a scenario, analyze indicators of potentially malicious activity.
- 1.3 1.3 Given a scenario, use appropriate tools or techniques to determine malicious activity.
- 1.5 1.5 Explain the importance of efficiency and process improvement in security operations.