CompTIA CySA + CS0-004 (V4) Exam (New Version) Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A vulnerability management program has two open findings with identical CVSS base scores, but threat intelligence suggests one is far more likely to be exploited in the next 30 days than the other. Which scoring system captures that likelihood-of-exploitation dimension?

Explanation

The Exploit Prediction Scoring System estimates the probability a vulnerability will be exploited in the wild within a given timeframe, exactly the dimension CVSS does not capture on its own. CVSS scores severity and impact characteristics, while SLA, KPI, and SBOM are unrelated to exploit likelihood.

Submit
Please wait...
About This Quiz
CompTIA CySA + Cs0-004 (V4) Exam (New Version) Practice Test 1 - Quiz

This practice assessment focuses on the CompTIA CySA + CS0-004 certification, evaluating your skills in threat detection and response, security monitoring, and incident management. It's an essential resource for anyone aiming to deepen their understanding of cybersecurity concepts and prepare for the certification exam effectively.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Match each security operations metric to its correct definition.

Explanation

These four metrics measure different stages of the detection and response lifecycle. MTTD measures how quickly a compromise is discovered, MTTR measures how quickly the team acts once detected, mean time to remediate measures how long full resolution takes, and false-positive rate measures alert quality rather than speed.

Submit

3. During a ransomware incident affecting customer data, the incident commander needs input on the organization's legal breach notification obligations and the timeframes required by applicable regulations. Which internal stakeholder group should take the lead on this determination?

Explanation

The legal team determines regulatory obligations and mandated timeframes for breach notification, providing the guardrails that shape when and how the organization must report. Public relations handles public messaging, law enforcement handles criminal investigation, IT operations focuses on technical remediation, and customers are a notification target rather than the group determining legal obligations.

Submit

4. A CISO wants a single report showing overall risk posture trends over the last quarter, broken down by business unit, to present to the board. Which reporting artifact is best suited to this need?

Explanation

A risk scorecard aggregates and visualizes risk posture and trends across the organization in a format suited to executive and board-level reporting. A raw vulnerability scan report is too granular for this audience, an SLA defines expected service performance rather than risk trends, a compliance finding documents a specific gap, and an action plan tracks remediation steps rather than overall posture.

Submit

5. A vulnerability management team identifies a critical finding on a manufacturing system, but the plant cannot take the system offline during production hours without halting revenue-generating operations. Which inhibitor to remediation does this scenario illustrate?

Explanation

Business process interruption describes situations where applying a fix would disrupt an active, revenue-generating operation, exactly as described with the production system that cannot go offline. Legacy and proprietary systems refer to outdated or vendor-locked technology, contractual agreements involve third-party obligations, and patch availability refers to whether a fix even exists, none of which match the operational downtime concern here.

Submit

6. After a phishing-driven incident is fully remediated, the incident response team holds a post-incident review. Which two activities belong in this post-incident phase?

Explanation

Root cause analysis and corrective action development both happen in the post-incident phase, where the team determines why the incident occurred and defines changes to prevent recurrence. Isolating affected targets and evidence gathering happen earlier during containment and analysis, and timeline establishment happens during analysis rather than after the incident is closed.

Submit

7. An analyst confirms that a workstation is actively communicating with a known command-and-control server. The workstation is not business-critical, and the analyst has authority to act immediately. What is the most appropriate next step before further analysis continues?

Explanation

Once command-and-control activity is confirmed, isolating the affected host limits further damage and prevents lateral movement while the investigation continues. Root cause analysis and the executive summary come later in the process, releasing from isolation happens only after remediation is verified, and updating the communication plan is a longer-term administrative task rather than an immediate containment action.

Submit

8. A SIEM generates a raw alert showing only a source IP and destination port, with no context about which user or asset was involved. An analyst adds threat intelligence data and asset ownership information to the alert before triaging it. This step is best described as which part of the incident response process?

Explanation

Log augmentation and enrichment adds external context, such as threat intelligence or asset ownership data, to a raw log entry so analysts have more to work with before deciding how to respond. Log correlation instead links multiple related log entries together, timeline establishment sequences events chronologically, root cause analysis happens after the incident, and triage is the decision step that typically follows enrichment.

Submit

9. During an active investigation, an analyst images a compromised laptop's hard drive and hands the image to a third-party forensics vendor for deeper analysis. What must be maintained throughout this handoff to ensure the evidence remains admissible later?

Explanation

Chain of custody documents who handled evidence, when, and under what conditions, at every step from collection to analysis, which is essential if the evidence is later used in legal or disciplinary proceedings. Integrity validation and preservation support the broader chain of custody process, a legal hold prevents deletion of relevant data, and escalation is about notifying the right people, none of which alone cover the full handoff requirement.

Submit

10. Match each incident response phase to its correct position in the standard sequence.

Explanation

The full sequence runs preparation, detection, analysis, containment, eradication, recovery, and post-incident, so detection is the second phase, containment the fourth, eradication the fifth, and recovery the sixth. Skipping or reordering these phases, such as eradicating before properly containing, risks letting the threat persist or spread further.

Submit

11. An analyst wants to model the relationships between the adversary, the tools used, the infrastructure involved, and the victim organization in a single intrusion, rather than mapping the sequential stages of the attack. Which framework fits this need?

Explanation

The Diamond Model explicitly maps the four core features of an intrusion, adversary, capability, infrastructure, and victim, and the relationships between them. The Cyber Kill Chain models sequential attack stages instead, MITRE ATT&CK catalogs specific techniques, STRIDE is used for threat modeling software, and the Pyramid of Pain ranks indicator value.

Submit

12. Match each control example to its correct control type.

Explanation

Administrative controls are policies and training, physical controls are tangible barriers like badge readers, and technical controls are enforced through technology such as firewall rules and automated session timeouts, which is why two of the four examples here map to the technical category.

Submit

13. A critical legacy application cannot be patched for a known vulnerability without breaking core business functionality, and the vendor has not released a fix. Which two mitigation strategies would a vulnerability management program most appropriately apply here?

Explanation

When no patch is available, a documented exception paired with a compensating control such as segmentation or added monitoring is the standard way to manage residual risk formally rather than leaving it untracked. Ignoring the finding or waiting indefinitely leaves risk unmanaged, and decommissioning a business-critical application is rarely a proportionate first response.

Submit

14. A SOC analyst correlating alerts from a firewall, an EDR agent, and a Windows domain controller finds that timestamps on ostensibly simultaneous events are off by several minutes across the three sources, making it hard to build an accurate incident timeline. Which logging concept, if implemented consistently across all three systems, would most directly resolve this problem?

Explanation

Time synchronization, typically via NTP, keeps clocks aligned across disparate systems so timestamps can be trusted for correlation and timeline reconstruction. Retention controls how long logs are kept, integrity hashing protects against tampering, and ingestion or configuration govern how logs are collected, none of which fix clock drift between hosts.

Submit

15. An analyst wants to intercept and manipulate HTTP requests between a browser and a web application to manually test for injection flaws, rather than just running an automated crawl. Which tool is best suited to this interactive testing style?

Explanation

Burp Suite operates as an intercepting proxy, letting an analyst capture, modify, and replay individual HTTP requests for hands-on manual testing. Nikto is primarily an automated web server scanner, OpenVAS and Nessus are general-purpose vulnerability scanners, and Masscan is built for high-speed port scanning rather than manipulating application traffic.

Submit

16. A team monitoring a fragile industrial control system network wants to identify vulnerable devices without sending any probe traffic that could disrupt sensitive equipment. Which scanning approach fits this constraint?

Explanation

Passive scanning observes existing network traffic to infer device and vulnerability information without injecting packets, avoiding the risk of disrupting sensitive ICS equipment. Active scanning sends probes that could destabilize fragile devices, agent-based and credentialed scanning both require software or logins on each host, and baseline scanning checks configuration against a standard rather than avoiding network impact.

Submit

17. A vulnerability management team wants scan results that reflect missing patches and misconfigurations at the operating system and application level, not just what is visible from the network perimeter. Which scan approach should they use?

Explanation

Credentialed scanning logs into the target with valid credentials, letting the scanner inspect patches, configurations, and local vulnerabilities far more deeply than an unauthenticated view. Non-credentialed and external scans only see what is exposed on the network, and discovery scanning finds devices rather than assessing vulnerabilities.

Submit

18. A security team deploys an AI assistant to help draft incident summaries from raw log data. During testing, the assistant confidently states that a specific IP address was involved in the incident, but that IP never appears anywhere in the underlying logs. This is best described as which AI risk?

Explanation

Hallucination occurs when a model generates confident, plausible-sounding output not actually supported by its input data, exactly as described here. Data exposure involves the model leaking sensitive information, model poisoning involves an attacker corrupting training data, and a malicious prompt is an input crafted to manipulate model behavior, none of which match a fabricated fact in output.

Submit

19. A threat hunter is documenting indicators of compromise from a recent investigation and wants to classify them correctly for future detection tuning. Which two of the following are recognized IoC type classifications?

Explanation

IoCs are commonly classified as atomic, a single discrete value like an IP address or hash, or behavioral, a pattern of activity such as a sequence of process executions. Structural, predictive, and categorical are not recognized IoC classification types in this framework.

Submit

20. A threat intelligence analyst wants to prioritize indicators that are most costly for an adversary to change if detected, rather than indicators like file hashes that attackers can alter with almost no effort. Which model directly supports this kind of prioritization?

Explanation

The Pyramid of Pain ranks indicator types by how much cost they impose on an adversary when defenders act on them, with TTPs at the top being hardest to change and hashes at the bottom being trivial to change. MITRE ATT&CK catalogs adversary techniques, the Diamond Model maps relationships between adversary, capability, infrastructure, and victim, and STRIDE is a threat modeling framework, none of which rank indicators by attacker cost.

Submit

21. An analyst has written a set of pattern-matching rules to identify a family of malware based on strings and byte sequences found in infected files, and wants to scan a directory of suspicious binaries against those rules. Complete the sentence: the analyst would use ______ to run these detection rules against the files.

Explanation

YARA is purpose-built for writing and applying pattern-matching rules that identify malware families by their strings and byte sequences. Tools like Wireshark or tcpdump analyze network traffic rather than static files, so they do not fit this use case.

Submit

22. An analyst needs to capture and inspect live network traffic on a Linux server from the command line, without a graphical interface, to confirm whether a host is beaconing to an external IP on an unusual port. Which tool best fits this specific task?

Explanation

tcpdump is a lightweight, command-line packet capture tool well suited to headless Linux servers, which makes it the right fit here. Wireshark performs similar analysis but is primarily a GUI tool, CyberChef decodes and transforms data rather than capturing packets, YARA matches file patterns, and MXToolbox analyzes email and DNS records.

Submit

23. A user's account authenticates successfully from an IP address in Chicago at 9:02 AM and then from an IP address in Singapore at 9:14 AM, with no VPN or travel on record. Which indicator category does this scenario describe?

Explanation

Impossible travel flags authentications from geographically distant locations in a window too short for actual travel, suggesting credential compromise or account sharing. Enumeration involves systematically probing for valid accounts or resources, typosquatting is a domain-based social engineering technique, and the other options describe unrelated attack patterns.

Submit

24. An EDR alert shows that certutil.exe was used on a workstation to download a file from an external URL, something this built-in Windows utility is not normally used for on this network. This behavior is best classified as which type of indicator?

Explanation

certutil.exe is a legitimate, signed Windows binary that attackers commonly repurpose to download or decode payloads, which is the definition of a LOLBin. The activity described is inbound retrieval rather than data leaving the host, it is not a new device on the network, and it is not a configuration change or a performance issue.

Submit

25. During a security review, an analyst discovers that a CI/CD pipeline script contains a hardcoded database password committed to source control. Which IAM-related practice would have prevented this exposure?

Explanation

Secrets management stores and injects credentials like database passwords at runtime from a secure vault rather than embedding them in code or scripts. PAM controls elevated account access, MFA and SSO govern how users authenticate, and RBAC controls what an authenticated user can do, none of which stop a credential from being hardcoded into source in the first place.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A vulnerability management program has two open findings with...
Match each security operations metric to its correct definition.
During a ransomware incident affecting customer data, the incident...
A CISO wants a single report showing overall risk posture trends over...
A vulnerability management team identifies a critical finding on a...
After a phishing-driven incident is fully remediated, the incident...
An analyst confirms that a workstation is actively communicating with...
A SIEM generates a raw alert showing only a source IP and destination...
During an active investigation, an analyst images a compromised...
Match each incident response phase to its correct position in the...
An analyst wants to model the relationships between the adversary, the...
Match each control example to its correct control type.
A critical legacy application cannot be patched for a known...
A SOC analyst correlating alerts from a firewall, an EDR agent, and a...
An analyst wants to intercept and manipulate HTTP requests between a...
A team monitoring a fragile industrial control system network wants to...
A vulnerability management team wants scan results that reflect...
A security team deploys an AI assistant to help draft incident...
A threat hunter is documenting indicators of compromise from a recent...
A threat intelligence analyst wants to prioritize indicators that are...
An analyst has written a set of pattern-matching rules to identify a...
An analyst needs to capture and inspect live network traffic on a...
A user's account authenticates successfully from an IP address in...
An EDR alert shows that certutil.exe was used on a workstation to...
During a security review, an analyst discovers that a CI/CD pipeline...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!