CompTIA CySA + CS0-004 (V4) Exam (New Version) Practice Test 2

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A vulnerability management team is prioritizing two findings of similar severity. Finding A has a public proof-of-concept exploit actively being used in the wild, and Finding B affects a server holding highly sensitive customer financial data. Which two prioritization criteria are illustrated by Findings A and B, respectively?

Explanation

Finding A illustrates active exploitation and threat intelligence, since a known exploit is actively in use, while Finding B illustrates asset value, since the system holds highly sensitive data. Patch availability concerns whether a fix exists, true positive rate concerns detection accuracy, and scoring methods refer to systems like CVSS rather than these specific criteria.

Submit
Please wait...
About This Quiz
CompTIA CySA + Cs0-004 (V4) Exam (New Version) Practice Test 2 - Quiz

This assessment focuses on the CompTIA CySA + CS0-004 (V4) exam, evaluating your knowledge of cybersecurity analysis, threat detection, and incident response. It is designed for those preparing for the certification, helping you to reinforce your understanding of critical concepts and skills in cybersecurity. By practicing with real exam-style questions,... see moreyou can enhance your readiness and confidence for the actual test. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Match each post-incident reporting element to its correct description.

Explanation

The after action report formally documents the full incident record, lessons learned captures process improvement discussion, root cause analysis identifies why the incident happened, and shift or incident handover ensures continuity when responsibility transfers between teams.

Submit

3. After a major incident is resolved, the CISO needs a concise, non-technical document summarizing what happened, its business impact, and the key actions taken, to share with company leadership. Which reporting artifact fits this need?

Explanation

An executive summary distills an incident into a concise, non-technical overview tailored for leadership consumption. An after action report and root cause analysis document are typically more detailed and technical, an internal threat intelligence report focuses on adversary context, and shift handover notes are operational rather than executive-facing.

Submit

4. A remediation action plan for a critical finding notes that the fix cannot proceed until a separate network team completes an unrelated firewall migration first, and that if the deadline is missed, the finding must be escalated to the CISO. Which two action plan elements does this note describe?

Explanation

The requirement to escalate to the CISO if a deadline is missed describes escalation, while the reliance on another team's unrelated work first describes a dependency. Risk appetite concerns organizational risk tolerance broadly, SLA defines expected performance, and stakeholder identification names who needs to be informed.

Submit

5. An auditor asks for documentation showing specifically which of an organization's systems fail to meet PCI DSS requirements, rather than a general list of all discovered vulnerabilities. Which reporting artifact should the team provide?

Explanation

Compliance findings specifically document gaps against a named standard such as PCI DSS. A general vulnerability scan report covers all discovered issues regardless of framework, a risk scorecard summarizes overall risk trends, an action plan tracks remediation steps, and metrics/KPIs measure program performance rather than compliance status.

Submit

6. An incident commander is deciding which of three simultaneous alerts to address first. One alert affects a single non-critical test server, another affects the production payment processing system, and a third shows early signs of ransomware spreading across multiple endpoints. Which two factors should most heavily drive the prioritization decision here?

Explanation

Determining severity and impact, and prioritizing based on business criticality and scope, are exactly the factors that separate a low-impact test server incident from a production payment system compromise or a spreading ransomware event. Establishment of a timeline and chain of custody are evidentiary activities for deeper investigation, and post-incident reporting happens after resolution.

Submit

7. A SIEM fires a high-severity alert for a possible ransomware indicator at 2 AM. Before any deeper analysis begins, an on-call analyst quickly reviews the alert to decide whether it requires immediate escalation or can wait until morning. Which incident response activity does this quick initial assessment represent?

Explanation

Triage is the quick initial assessment of an alert's severity and urgency to decide how it should be handled next. Root cause analysis and post-incident reporting happen much later, establishing a timeline is a more detailed reconstruction step, and evidence gathering is a distinct forensic activity.

Submit

8. A security team wants to test its incident response plan by having stakeholders talk through their roles and decisions during a hypothetical breach scenario in a conference room, without actually taking any systems offline or executing real technical actions. Which type of training exercise does this describe?

Explanation

A tabletop exercise walks stakeholders through a hypothetical scenario verbally without executing real technical actions. A simulation involves participants taking real actions in a controlled environment, and penetration tests, red team engagements, and live-fire drills all involve executing technical actions rather than only discussion.

Submit

9. A company's new incident response documentation describes how alerts will be triaged and remediated, while a separate document specifies who will speak to the media and when customers will be notified during an incident. These two documents respectively represent which pair of plans?

Explanation

The first document describing triage and remediation is the incident response plan, while the second describing media and customer communication is the communication plan. A playbook or runbook would detail specific technical procedures, and the other pairs describe different scopes of documentation entirely.

Submit

10. Before any incident has occurred, a security team establishes an incident response plan, provisions forensic tooling, and trains staff on their roles during a breach. Which phase of the incident response process does this work belong to?

Explanation

Preparation is the phase where an organization builds the plans, tools, and trained personnel needed to respond effectively before an incident occurs. Detection and analysis happen once suspicious activity is identified, containment happens during an active incident, and post-incident work happens after resolution.

Submit

11. An analyst wants to model the relationships between the adversary, the tools they used, the infrastructure involved, and the victim organization in a single intrusion, rather than mapping the sequential stages of the attack. Which framework fits this need?

Explanation

The Diamond Model explicitly maps the four core features of an intrusion and the relationships between them. The Cyber Kill Chain models sequential attack stages instead, MITRE ATT&CK catalogs specific techniques, STRIDE is for threat modeling software, and the Pyramid of Pain ranks indicator value.

Submit

12. Match each scenario to the risk management strategy it best represents.

Explanation

Transferring risk shifts financial impact to a third party such as an insurer, avoiding risk eliminates the risky activity altogether, mitigating risk reduces likelihood or impact through controls, and accepting risk formally acknowledges a finding within tolerance without further action.

Submit

13. A vulnerability scanner flags a critical finding on a server, but that server sits on a fully isolated network segment with no connectivity to the internet or any other internal system. Which concept should most directly influence how this finding is prioritized?

Explanation

Context awareness considers the environment a vulnerable asset sits in, adjusting prioritization since an isolated system carries much lower real-world risk despite a high raw score. Scoring methods produce the base severity without this context, validation of remediation happens after a fix, and secure coding or patch management are mitigation actions rather than prioritization factors.

Submit

14. A company's data retention policy requires that security logs be retrievable for forensic investigations up to 18 months after an event, but the SIEM's default configuration only stores logs online for 90 days before deleting them. Which logging concept must be addressed to meet this policy requirement?

Explanation

Log retention defines how long logs stay retrievable, so extending it closes the gap between the 90-day default and the 18-month requirement. Time synchronization aligns clocks, ingestion governs collection, integrity protects against tampering, and configuration governs what is recorded, none of which control storage duration.

Submit

15. An analyst wants to enumerate open ports, running services, and service versions across a subnet as an early reconnaissance step, without yet attempting to exploit anything. Which tool is the standard choice for this task?

Explanation

Nmap is the standard tool for port scanning and service or version enumeration during reconnaissance. Metasploit Framework develops and executes exploits, Maltego maps open-source intelligence relationships, Recon-ng is a web-based reconnaissance framework, and Burp Suite targets web application traffic.

Submit

16. An analyst runs a scan specifically intended to identify what type of operating system and services are running on each live host on a subnet, without yet checking for specific vulnerabilities. This activity is best described as which scan type?

Explanation

Discovery scanning, including mapping scans and device fingerprinting, identifies live hosts and their OS or services as a precursor to deeper assessment. Security baseline scanning checks configuration against a standard, credentialed scanning requires logging in, passive scanning avoids sending probes, and agentless scanning describes a deployment model.

Submit

17. A vulnerability management program is producing scan results that consistently miss several servers that IT confirms exist on the network. Before improving scan configuration, what foundational step should the team address first?

Explanation

An accurate asset inventory is the foundation of vulnerability management; without knowing what assets exist, scans cannot be scoped to cover them regardless of scan type or configuration. Credentialed scanning improves the depth of results on known assets, discovery and passive scanning can help find devices but are tactics rather than the foundational inventory itself, and baseline scanning checks configuration rather than asset coverage.

Submit

18. A SOC is manually performing the same ten triage steps for every phishing alert, including checking sender reputation, extracting URLs, and opening a ticket, which consumes significant analyst time. Which technology is specifically designed to automate this kind of repetitive, multi-step workflow?

Explanation

SOAR platforms automate and orchestrate repetitive, multi-step analyst workflows like phishing triage. A SIEM correlates logs but does not itself orchestrate response workflows, IaC automates infrastructure provisioning, UEBA focuses on behavioral analytics, and a vulnerability scanner identifies weaknesses rather than automating response.

Submit

19. An investigation reveals two separate incidents: one involving a foreign nation-state group that maintained stealthy access to a network for over a year to steal intellectual property, and another involving a disgruntled employee who used their legitimate access to delete critical files before resigning. Which two threat actor categories do these incidents represent, respectively?

Explanation

A well-resourced, stealthy group maintaining long-term access matches the definition of an advanced persistent threat, while an employee misusing legitimate access from within is a textbook insider threat. Hacktivists are typically ideologically motivated, script kiddies use unsophisticated pre-built tools, and competitor is not a formal threat actor category here.

Submit

20. A security team wants a single tool that not only detects and responds to threats on laptops and servers but also correlates that telemetry with data from email and cloud sources to see the full scope of an attack. Which category of tool best matches this description?

Explanation

XDR extends beyond a single endpoint's telemetry to correlate data across endpoints, email, cloud, and other sources into a unified view. MDM manages device configuration, EDR is scoped to endpoint telemetry alone, SIEM aggregates logs broadly without being endpoint-focused, and UEBA focuses specifically on behavioral analytics.

Submit

21. A threat intelligence team wants to set up a self-hosted platform where they can store, correlate, and share structured indicator data internally and with trusted partner organizations, rather than relying solely on a public feed. Which tool best fits this need?

Explanation

MISP is designed as a self-hosted platform for storing, correlating, and sharing structured threat intelligence, including with trusted partner communities. OTX is a public community feed rather than self-hosted, VirusTotal analyzes files and URLs, CyberChef transforms data, and Recon-ng is a reconnaissance framework.

Submit

22. A cloud security team notices that a storage bucket's access policy was silently changed to allow public read access, and shortly afterward outbound data transfer costs from that bucket spike well above baseline. This combination most likely indicates which cloud-related indicator?

Explanation

The combination of an unauthorized policy change exposing data publicly and a spike in outbound transfer strongly suggests the resource has been compromised and is being used to exfiltrate data. Unauthorized configuration alone would not explain the traffic spike, and the remaining options describe unrelated attack categories.

Submit

23. During a network audit, an analyst finds an unauthorized wireless access point plugged into a conference room switch, and separately notices a burst of sequential SNMP queries against every IP in a subnet from an unrecognized host. Which two network-related indicator categories do these findings represent, respectively?

Explanation

The unauthorized access point is a rogue device connected without approval, while the systematic SNMP sweep across a subnet is enumeration. Unexpected port activity, data exfiltration, and impossible travel describe different indicator patterns not present here.

Submit

24. An analyst is asked to assess security controls for a water treatment facility's control systems that monitor and adjust valves and pumps in real time. These systems fall under which category of critical infrastructure concepts?

Explanation

Operational technology refers to hardware and software that monitors and controls physical devices and processes, such as valves and pumps, and includes SCADA and ICS components. The remaining options describe compute architecture or identity concepts rather than physical process control.

Submit

25. A company wants to grant remote employees access to specific internal applications based on continuous verification of identity and device posture, rather than placing them on the corporate network via a traditional VPN with broad access. Which architecture concept best matches this approach?

Explanation

ZTNA grants access to specific applications based on continuous identity and device verification rather than broad network-level trust. SASE is a broader cloud-delivered networking and security framework, hybrid cloud describes an infrastructure mix, VLAN segmentation divides a local network, and SCADA relates to industrial control systems.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A vulnerability management team is prioritizing two findings of...
Match each post-incident reporting element to its correct description.
After a major incident is resolved, the CISO needs a concise,...
A remediation action plan for a critical finding notes that the fix...
An auditor asks for documentation showing specifically which of an...
An incident commander is deciding which of three simultaneous alerts...
A SIEM fires a high-severity alert for a possible ransomware indicator...
A security team wants to test its incident response plan by having...
A company's new incident response documentation describes how alerts...
Before any incident has occurred, a security team establishes an...
An analyst wants to model the relationships between the adversary, the...
Match each scenario to the risk management strategy it best...
A vulnerability scanner flags a critical finding on a server, but that...
A company's data retention policy requires that security logs be...
An analyst wants to enumerate open ports, running services, and...
An analyst runs a scan specifically intended to identify what type of...
A vulnerability management program is producing scan results that...
A SOC is manually performing the same ten triage steps for every...
An investigation reveals two separate incidents: one involving a...
A security team wants a single tool that not only detects and responds...
A threat intelligence team wants to set up a self-hosted platform...
A cloud security team notices that a storage bucket's access policy...
During a network audit, an analyst finds an unauthorized wireless...
An analyst is asked to assess security controls for a water treatment...
A company wants to grant remote employees access to specific internal...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!