CompTIA CySA + CS0-004 (V4) Exam (New Version) Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. After a critical vulnerability is patched on a production server, the vulnerability management team re-scans the system to confirm the finding no longer appears before formally closing the ticket. Which concept does this re-scan represent?

Explanation

Validation of remediation confirms a fix was actually effective by re-checking the system after the patch is applied. Scoring methods and context awareness inform prioritization before remediation, compensating controls are an alternative to direct remediation, and true positive rate measures detection accuracy.

Submit
Please wait...
About This Quiz
CompTIA CySA + Cs0-004 (V4) Exam (New Version) Practice Test 3 - Quiz

This practice test focuses on the CompTIA CySA + CS0-004 exam, evaluating your understanding of cybersecurity analysis and threat detection. It covers essential skills such as identifying vulnerabilities, analyzing security incidents, and implementing effective security measures. This resource is crucial for anyone preparing for the certification, ensuring you are well-equipped... see morewith the knowledge needed to succeed in the cybersecurity field. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A security awareness report tracks the percentage of employees who clicked a link in a simulated phishing email during the last quarterly test. Complete the sentence: this specific metric is called the ______.

Explanation

The phishing campaign click rate specifically measures the percentage of recipients who clicked a link in a simulated or real phishing test, making it a direct measure of user susceptibility rather than a technical detection metric like alert volume or mean time to detect.

Submit

3. Following a confirmed data breach involving customer personal information, the incident commander needs to loop in the external body responsible for receiving the organization's mandated breach notification filing, separately from the body responsible for investigating the criminal aspect of the intrusion. Which two stakeholder groups does this describe, respectively?

Explanation

The body that receives the organization's mandated breach notification filing is the regulatory reporting agency, while the body responsible for investigating the criminal aspect is law enforcement. Public relations manages public messaging, the legal team advises internally rather than being the external recipient, and customers are a notification target.

Submit

4. A vulnerability management program is contractually required to patch all critical findings within 14 days of discovery. Which reporting element captures this specific requirement?

Explanation

A service-level agreement defines an expected performance threshold, such as this contractual 14-day patch requirement. Trends show directional change over time rather than a fixed threshold, a risk scorecard aggregates broader risk posture, compliance findings document gaps against a standard, and an action plan tracks remediation steps.

Submit

5. A vulnerability finding affects a 15-year-old inventory system running on an unsupported operating system that the vendor no longer patches. Which inhibitor to remediation does this scenario most directly illustrate?

Explanation

An outdated system running on an unsupported OS with no further vendor patches is the definition of a legacy systems inhibitor. Proprietary systems refer to vendor lock-in on modification rights, contractual agreements involve third-party obligations, business process interruption concerns operational downtime, and degrading functionality concerns a fix breaking something else.

Submit

6. A forensic examiner creates a cryptographic hash of a disk image immediately after acquisition and again before analysis to confirm nothing changed in between, and separately stores the original image in a locked, access-controlled evidence room. Which two evidence gathering concepts do these two actions represent, respectively?

Explanation

Comparing cryptographic hashes before and after handling confirms data integrity validation, while storing the original in a secure, access-controlled location represents preservation. Chain of custody documents the full handling history, legal hold suspends deletion schedules, and triage is an early urgency assessment.

Submit

7. A previously isolated server has had its malware removed and its vulnerabilities patched. Before reconnecting it to the production network, what should the incident response team confirm?

Explanation

Verifying that remediation was effective and the system is genuinely clean is required before releasing a system from isolation, to avoid reintroducing the threat. The executive summary, communication plan, after action report, and formal closure are all later reporting and wrap-up activities.

Submit

8. A junior analyst investigating a moderate-severity alert discovers evidence suggesting the attacker has already accessed the organization's core financial database. Given the increased scope and sensitivity, what should the analyst do next?

Explanation

When an investigation reveals a scope or sensitivity beyond the initial assessment, escalating to senior responders or the incident commander ensures the incident gets appropriate attention and authority. Continuing alone risks delay on a high-stakes incident, and customer notification, executive summaries, and closure all come later after proper assessment.

Submit

9. During an investigation into a suspected insider data theft, legal counsel instructs the IT team to suspend the normal automatic deletion schedule for a specific employee's email and file access logs, since litigation is anticipated. Which evidence gathering concept does this instruction represent?

Explanation

A legal hold suspends normal data destruction or retention schedules for specific records when litigation is anticipated. Chain of custody tracks who handled evidence, data integrity validation confirms evidence has not been altered, preservation is a broader concept a legal hold helps enforce, and escalation concerns notifying the right people.

Submit

10. After an alert is detected, an analyst spends time examining logs, correlating related events, and confirming whether the activity is truly malicious before deciding on a containment approach. Which incident response phase does this work belong to?

Explanation

The analysis phase involves examining and correlating data to confirm whether an alert represents genuine malicious activity before any containment decision. Detection is the initial identification, containment happens once confirmed, eradication removes the threat, and post-incident happens after full resolution.

Submit

11. During an active investigation, the incident response team tags each observed attacker action, such as credential dumping and lateral movement, with a standardized technique identifier so the findings can be compared against other known intrusions. Which resource are they using to standardize this tagging?

Explanation

MITRE ATT&CK provides a standardized catalog of adversary techniques that incident responders commonly use to tag observed behavior for comparison. STRIDE is a design-time threat modeling framework, the Diamond Model maps relationships between intrusion elements, the Pyramid of Pain ranks indicator value, and the Cyber Kill Chain models attack stages.

Submit

12. Match each application security concept to its correct description.

Explanation

SAST examines source code directly without running the application, DAST tests the application while it is running, and SAMM provides a broader maturity framework for evaluating software security practices across an organization.

Submit

13. A security architecture includes a firewall rule that blocks known-malicious IP addresses before they can reach internal systems, and a separate SIEM alert rule that flags suspicious login attempts after they occur so an analyst can investigate. Which two control functions do these represent, respectively?

Explanation

The firewall rule blocking malicious traffic before it reaches internal systems is a preventative control, while the SIEM alert flagging suspicious logins after they occur is a detective control. Responsive controls act during or after an incident, corrective controls restore systems afterward, and administrative controls are policy-based rather than technical.

Submit

14. A SOC lead is concerned that an attacker with elevated access could quietly modify log entries to cover their tracks after an intrusion. Which logging concept specifically addresses this risk?

Explanation

Log integrity and security controls, such as write-once storage or cryptographic hashing, protect logs from being altered after the fact. Retention governs how long logs are kept, time synchronization aligns clocks, and ingestion and configuration govern collection rather than tamper protection.

Submit

15. An analyst wants to assess whether cloud storage buckets, IAM policies, and security groups across an AWS environment follow security best practices. Which category of tool is purpose-built for this kind of cloud configuration assessment?

Explanation

Cloud infrastructure assessment tools such as Prowler or ScoutSuite are purpose-built to evaluate cloud configurations. Multipurpose network tools and vulnerability scanners are generally built for on-premises assessment, breach attack simulation tools test detection capability, and web application scanners target application-layer flaws.

Submit

16. A team wants to verify that server configurations align with a widely recognized, vendor-neutral set of hardening recommendations, rather than checking for specific missing patches. Which resource would they scan against?

Explanation

CIS benchmarks provide vendor-neutral, consensus-based configuration hardening standards. CVSS and EPSS score vulnerability severity and exploit likelihood rather than configuration compliance, an SBOM inventories software components, and SAMM is a software assurance maturity model.

Submit

17. A vulnerability management team wants scan results run from a system sitting inside the corporate network and a separate scan from a cloud-hosted system outside the corporate perimeter, targeting the same set of servers. This comparison illustrates which pair of scan types?

Explanation

Scanning from inside versus outside the corporate network is precisely the distinction between internal and external scanning. Credentialed versus non-credentialed concerns authentication, active versus passive concerns probe traffic, agent versus agentless concerns software deployment, and discovery versus baseline concerns scan purpose.

Submit

18. A company deploys an internal AI chatbot connected to its knowledge base. In one incident, the chatbot reveals confidential salary data to an employee who should not have access to it. In a separate incident, an external user crafts a specially worded input designed to trick the chatbot into ignoring its safety instructions. Which two AI risks do these incidents represent, respectively?

Explanation

The chatbot revealing confidential data it should not have shared is a data exposure risk, while the specially crafted input designed to bypass safety instructions is a malicious prompt. Model poisoning involves corrupting training data, hallucination involves fabricating information, and governance failure is a broader organizational gap.

Submit

19. A development team is reviewing a new application's design and wants to systematically consider threats like an attacker impersonating a legitimate user, tampering with data in transit, or denying service to legitimate users. Which threat modeling framework structures this kind of analysis?

Explanation

STRIDE structures threat modeling around six categories including spoofing, tampering, and denial of service, directly covering impersonation, tampering, and denial of service. MITRE ATT&CK catalogs real-world observed techniques, and the other frameworks serve different purposes related to analyzing actual intrusions.

Submit

20. After analyzing a set of observed tactics and techniques from an intrusion, an analyst cross-references them against a public knowledge base of adversary behavior to identify which known threat group's known patterns most closely match. This activity relies most directly on which resource?

Explanation

MITRE ATT&CK is a public knowledge base cataloging adversary tactics and techniques mapped to known threat groups. STRIDE is a software threat modeling framework, the Pyramid of Pain ranks indicator value, and the Cyber Kill Chain and Diamond Model describe attack progression and intrusion relationships rather than a technique-to-group knowledge base.

Submit

21. An analyst wants to safely detonate a suspicious executable in an isolated environment to observe its behavior, such as which files it creates or which network connections it attempts, without risking the production network. Which category of tool is designed for this purpose?

Explanation

Sandboxing tools like Cuckoo Sandbox or Joe Sandbox execute suspicious files in an isolated environment specifically to observe their behavior safely. Packet analysis inspects network traffic, domain and IP reputation checks external indicators, UEBA analyzes behavior patterns, and log analysis reviews existing log data.

Submit

22. An attacker impersonates a company's CFO in an email to the accounts payable team, urgently requesting a wire transfer to a new vendor account, using a domain that closely resembles the real company domain. Which type of attack does this scenario describe?

Explanation

Business email compromise involves impersonating a trusted executive to manipulate an employee into an unauthorized financial transaction. Typosquatting is one technique supporting this broader BEC pattern, while URL shorteners, enumeration, and impossible travel describe unrelated techniques.

Submit

23. An EDR tool flags a workstation compressing a large volume of internal documents into a password-protected archive and then uploading that archive to a personal cloud storage account. This behavior is best classified as which host-related indicator?

Explanation

Compressing sensitive files and uploading them to an external, personal account is a classic pattern of data exfiltration. Resource consumption refers to abnormal CPU or memory usage, unauthorized software refers to unapproved applications, file system changes refer to unexpected file modifications, and an anomalous rogue process refers to unexpected running processes.

Submit

24. An organization wants to ensure that administrators must check out a time-limited, monitored credential before accessing a domain controller, rather than using a standing admin account indefinitely. Which IAM concept does this control represent?

Explanation

PAM governs how elevated accounts are checked out, time-limited, and monitored. SSO and MFA concern how a user authenticates, secrets management stores credentials for applications and scripts, and RBAC defines permission sets rather than session-based elevation.

Submit

25. A development team packages an application along with its dependencies into a lightweight, portable unit that shares the host operating system's kernel rather than running a full separate OS instance. Which infrastructure concept does this describe?

Explanation

Containerization packages an application with its dependencies into a lightweight unit that shares the host OS kernel, unlike virtualization which runs full separate guest operating systems. Cloud native describes a design philosophy, API-based architecture concerns communication, and hybrid cloud describes infrastructure mix.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
After a critical vulnerability is patched on a production server, the...
A security awareness report tracks the percentage of employees who...
Following a confirmed data breach involving customer personal...
A vulnerability management program is contractually required to patch...
A vulnerability finding affects a 15-year-old inventory system running...
A forensic examiner creates a cryptographic hash of a disk image...
A previously isolated server has had its malware removed and its...
A junior analyst investigating a moderate-severity alert discovers...
During an investigation into a suspected insider data theft, legal...
After an alert is detected, an analyst spends time examining logs,...
During an active investigation, the incident response team tags each...
Match each application security concept to its correct description.
A security architecture includes a firewall rule that blocks...
A SOC lead is concerned that an attacker with elevated access could...
An analyst wants to assess whether cloud storage buckets, IAM...
A team wants to verify that server configurations align with a widely...
A vulnerability management team wants scan results run from a system...
A company deploys an internal AI chatbot connected to its knowledge...
A development team is reviewing a new application's design and wants...
After analyzing a set of observed tactics and techniques from an...
An analyst wants to safely detonate a suspicious executable in an...
An attacker impersonates a company's CFO in an email to the accounts...
An EDR tool flags a workstation compressing a large volume of internal...
An organization wants to ensure that administrators must check out a...
A development team packages an application along with its dependencies...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!