CompTIA CySA + CS0-004 (V4) Exam (New Version) Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A vulnerability scanner reports a critical finding on a server, but manual verification confirms the vulnerable software was never actually installed on that host. Separately, a scanner fails to flag a genuinely vulnerable application because it was running on a non-standard port. Which two criteria do these two situations represent, respectively?

Explanation

The finding that manual verification disproves is a false positive, since the scanner reported a vulnerability that was not actually present, while the missed genuinely vulnerable application is a false negative. A true positive would be a correctly identified real vulnerability, a true negative would be correctly identifying a non-vulnerable system, and patch availability concerns whether a fix exists.

Submit
Please wait...
About This Quiz
CompTIA CySA + Cs0-004 (V4) Exam (New Version) Practice Test 4 - Quiz

This practice resource focuses on the CompTIA CySA + CS0-004 exam, evaluating your knowledge in threat detection, analysis, and response. It is designed to enhance your skills in identifying vulnerabilities and implementing security measures, making it essential for anyone preparing for a career in cybersecurity. Engage with real-world scenarios to... see moreboost your confidence and readiness for the exam. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Match each SOC performance metric below to its correct definition.

Explanation

Alert volume measures raw workload, mean time to close measures how long tickets take from creation to closure, phishing campaign click rate measures user susceptibility, and false-positive rate measures alert quality, each capturing a different dimension of SOC performance.

Submit

3. A security analyst determines that a confirmed ransomware infection meets the organization's formal criteria for a major incident, triggering the incident response plan and notifying senior leadership immediately rather than treating it as a routine ticket. Which concept does this formal determination represent?

Explanation

Formally determining that an event meets the criteria for a major incident and triggering the response plan with leadership notification is incident declaration and escalation. Post-incident reporting happens after resolution, shift handover concerns transferring an ongoing incident, operational security awareness concerns communication channels, and an internal threat intelligence report focuses on adversary context.

Submit

4. A proposed patch for a critical finding is expected to break an integration with a partner's system, and separately, the vendor contract explicitly prohibits the customer from modifying the software directly. Which two inhibitors to remediation do these two constraints represent, respectively?

Explanation

A patch expected to break an existing integration illustrates degrading functionality, while a contract prohibiting direct modification illustrates a contractual agreement inhibitor. Legacy systems concern outdated technology rather than contract terms, business process interruption concerns operational downtime, and patch availability concerns whether a fix exists at all.

Submit

5. Before publishing a vulnerability management report, the program manager identifies which findings should go to the engineering team for remediation, which should go to the CISO for risk acceptance decisions, and which should go to compliance for regulatory tracking. This process is best described as which reporting concept?

Explanation

Determining which findings go to which audience and tailoring communication accordingly is exactly what stakeholder identification and communication involves. Action plans track remediation steps, metrics and KPIs measure program performance, risk scorecards visualize overall posture, and compliance findings document specific regulatory gaps.

Submit

6. Match each observed attacker action to its corresponding Cyber Kill Chain stage.

Explanation

These four actions map directly onto later Cyber Kill Chain stages. Delivery is the transmission of the malicious payload, installation is when the malware establishes persistence, command and control is the ongoing connection back to attacker infrastructure, and actions on objectives is when the attacker carries out their actual goal.

Submit

7. Following a post-incident review of a successful phishing attack, the team decides to implement mandatory security awareness training for all employees and to enable a new email banner flagging external senders. Which incident response activity does this decision represent?

Explanation

Deciding on and implementing specific changes to prevent a similar incident from recurring is corrective action development, which follows root cause analysis. Root cause analysis determines why the incident happened as a separate, earlier step, and triage, escalation, and log collection all occur during the active incident.

Submit

8. After collecting and correlating logs from several systems, an analyst arranges every relevant event, from initial compromise to data exfiltration, in chronological order to understand exactly how the attack unfolded. Which activity does this represent?

Explanation

Arranging every relevant event in chronological order to understand how an attack unfolded is the establishment of a timeline. Triage is a quicker initial urgency check, root cause analysis determines why the incident happened, escalation concerns notifying appropriate personnel, and chain of custody concerns evidence handling documentation.

Submit

9. During the early stages of an investigation, an analyst pulls relevant firewall, DNS, and authentication logs covering the suspected time window from multiple systems into a central location for review. Which incident response activity does this represent?

Explanation

Log collection is the act of gathering relevant logs from multiple systems into a central location for review. Log correlation links related entries together after collection, augmentation and enrichment adds external context, establishing a timeline sequences events chronologically, and triage is an earlier, quicker urgency assessment.

Submit

10. As part of incident response preparation, a team documents a specific step-by-step technical procedure for handling ransomware detections, and separately assigns named individuals to the incident commander, communications lead, and technical lead positions before any incident occurs. Which two preparation activities do these represent, respectively?

Explanation

Documenting a specific step-by-step technical procedure for a scenario like ransomware is playbook creation, while assigning named individuals to specific response positions in advance is defining roles. Developing an incident response plan is the broader document these support, performing training tests the plan rather than creating it, and log collection is unrelated.

Submit

11. Weeks after an incident has been fully remediated and systems restored to normal operation, the security team compiles lessons learned, updates playbooks based on gaps identified, and files a formal report. Which incident response phase does this work belong to?

Explanation

The post-incident phase includes compiling lessons learned, updating playbooks, and formal reporting, all of which happen after systems are already restored. Recovery is the phase where systems are actually restored, eradication removes the threat, containment limits spread during the active incident, and analysis happens earlier.

Submit

12. A vendor provides a formal, itemized list of every open-source and third-party component included in their software product, along with version numbers, so customers can check each component against known vulnerabilities. Complete the sentence: this document is called a ______.

Explanation

A software bill of materials, or SBOM, itemizes every component in a piece of software so organizations can check for known vulnerabilities in their third-party and open-source dependencies. This directly supports third-party and supply chain risk management by making the dependency tree visible and auditable.

Submit

13. A security team identifies dozens of unused, internet-facing subdomains and legacy services still reachable from outside the organization, none of which serve a current business purpose. Decommissioning these unused, exposed assets is best described as which mitigation strategy?

Explanation

Attack surface management focuses on identifying and reducing the total set of exposed, reachable assets, including decommissioning unused internet-facing subdomains and legacy services. Secure coding best practices apply during development, patching and configuration management address flaws in assets still in use, and compensating controls and exceptions manage risk on findings that cannot be directly remediated.

Submit

14. A systems administrator disables unused services, removes default accounts, and applies a strict baseline configuration to a newly provisioned server before it goes into production. This set of actions is best described as which OS concept?

Explanation

System hardening involves reducing a system's attack surface by disabling unnecessary services, removing default accounts, and applying secure baseline configurations. File structure management concerns organizing critical files, process monitoring concerns observing running processes, data protection concerns safeguarding data itself, and encryption concerns confidentiality rather than baseline configuration.

Submit

15. An analyst wants a fast, template-driven vulnerability scanner that can be extended with community-contributed detection templates for newly disclosed CVEs, rather than relying solely on a traditional commercial scanner's built-in signature database. Which tool best fits this description?

Explanation

Nuclei is a fast, template-driven scanner whose detection logic comes from community-contributed YAML templates, frequently updated for newly disclosed CVEs. Nessus and OpenVAS are more traditional signature-based scanners with built-in databases, and Masscan and Angry IP Scanner focus on high-speed port and host discovery.

Submit

16. A red team wants to safely emulate known adversary techniques, such as specific MITRE ATT&CK behaviors, against production systems to validate whether existing detection controls actually catch them, without causing real damage. Which category of tool is designed for this purpose?

Explanation

Breach attack simulation tools such as Atomic Red Team or Caldera are purpose-built to safely emulate known adversary techniques against real environments. Vulnerability scanners identify weaknesses, network scanning and mapping tools discover hosts, web application scanners target application-layer flaws, and cloud infrastructure assessment tools check cloud configuration.

Submit

17. A vulnerability management team wants continuous, real-time visibility into laptop configurations even when those laptops are off the corporate network, by installing lightweight software directly on each device. Which scanning approach does this describe?

Explanation

Agent-based scanning installs lightweight software directly on each endpoint, allowing continuous visibility even off the corporate network. Agentless scanning relies on network-based or credentialed remote checks, passive scanning observes traffic rather than installing software, discovery scanning finds devices, and external scanning views systems from outside the perimeter.

Submit

18. An attacker gains the ability to inject malicious or mislabeled samples into the dataset used to train a company's AI-based fraud detection model, causing the model to systematically miss a specific type of fraudulent transaction once deployed. Which AI risk does this scenario describe?

Explanation

Model poisoning occurs when an attacker corrupts the training data itself so the resulting model behaves incorrectly in a way that benefits the attacker. Hallucination involves the model fabricating output, data exposure involves leaking information, a malicious prompt manipulates a deployed model's input, and governance failure is an organizational gap.

Submit

19. A threat intelligence analyst gathers information about a target organization's employees, technology stack, and public-facing infrastructure entirely from publicly available sources such as job postings, social media, and DNS records. This collection approach is best described as which method?

Explanation

Gathering information entirely from publicly available sources is the definition of open-source intelligence. Closed-source intelligence comes from restricted or paid sources, threat intelligence sharing involves exchanging data between organizations, IoC collection focuses on specific compromise indicators, and cyber deception involves actively misleading an adversary.

Submit

20. Before investigating further, an analyst wants a quick check on whether an external IP address seen in a firewall log has a history of being associated with malicious activity reported by other organizations. Which type of tool provides this information?

Explanation

Domain and IP reputation services such as AbuseIPDB aggregate reports from many organizations about known malicious IPs and domains. Sandboxing analyzes file behavior, file analysis tools examine file content directly, UEBA analyzes internal user and entity behavior, and packet analysis inspects traffic content.

Submit

21. An analyst needs a centralized platform to aggregate logs from firewalls, servers, and endpoints, correlate related events across those sources, and generate alerts when suspicious patterns emerge. Which tool category is designed for this purpose?

Explanation

A SIEM is specifically designed to aggregate logs from many sources, correlate related events, and generate alerts based on suspicious patterns across the environment. EDR is scoped to endpoint telemetry alone, sandboxing analyzes files in isolation, a threat-intelligence platform manages external indicator data, and a vulnerability scanner identifies weaknesses.

Submit

22. An analyst investigating two phishing reports finds that one email links to a domain that closely mimics the company's real domain with a single character swapped, while a second email links through a shortened URL service that obscures the true destination until clicked. Which two social engineering techniques do these two emails represent, respectively?

Explanation

A domain with a single swapped character closely mimicking the real one is typosquatting, while a shortened link that hides its true destination is a URL shortener technique. Business email compromise typically involves executive impersonation and financial requests rather than domain tricks, and impossible travel and enumeration are unrelated indicator categories.

Submit

23. A network monitoring tool flags outbound traffic from an internal server to an external IP address over port 4444, a port not associated with any approved application on that server. Which network-related indicator category does this best represent?

Explanation

Traffic on a port not associated with any approved application, such as port 4444, is a classic example of activity on unexpected ports. A rogue device refers to an unauthorized device, enumeration refers to systematic probing, and impossible travel and business email compromise are identity- and email-based indicators unrelated to port activity.

Submit

24. A company deploys one tool to enforce encryption and remote wipe policies on employee smartphones, and a separate tool to monitor and respond to threats on laptops and desktops. Which two device management concepts do these two tools represent, respectively?

Explanation

The tool enforcing encryption and remote wipe on smartphones falls under mobile device management, while the tool monitoring and responding to threats on laptops and desktops falls under endpoint device management. Privileged access management governs elevated account access, secrets management protects credentials, and network access control governs what devices can join a network.

Submit

25. A security team reviewing a cloud native application's attack surface notes that most of its functionality is exposed through numerous machine-to-machine interfaces that accept requests and return structured data, rather than through a traditional web front end. Which infrastructure concept represents this primary attack surface?

Explanation

APIs are the machine-to-machine interfaces that accept requests and return structured data, and in a cloud native application they are often the primary way functionality is exposed. Virtualization and containerization describe how workloads run, hybrid cloud describes an infrastructure mix, and cloud native describes a design philosophy rather than the specific interface layer.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A vulnerability scanner reports a critical finding on a server, but...
Match each SOC performance metric below to its correct definition.
A security analyst determines that a confirmed ransomware infection...
A proposed patch for a critical finding is expected to break an...
Before publishing a vulnerability management report, the program...
Match each observed attacker action to its corresponding Cyber Kill...
Following a post-incident review of a successful phishing attack, the...
After collecting and correlating logs from several systems, an analyst...
During the early stages of an investigation, an analyst pulls relevant...
As part of incident response preparation, a team documents a specific...
Weeks after an incident has been fully remediated and systems restored...
A vendor provides a formal, itemized list of every open-source and...
A security team identifies dozens of unused, internet-facing...
A systems administrator disables unused services, removes default...
An analyst wants a fast, template-driven vulnerability scanner that...
A red team wants to safely emulate known adversary techniques, such as...
A vulnerability management team wants continuous, real-time visibility...
An attacker gains the ability to inject malicious or mislabeled...
A threat intelligence analyst gathers information about a target...
Before investigating further, an analyst wants a quick check on...
An analyst needs a centralized platform to aggregate logs from...
An analyst investigating two phishing reports finds that one email...
A network monitoring tool flags outbound traffic from an internal...
A company deploys one tool to enforce encryption and remote wipe...
A security team reviewing a cloud native application's attack surface...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!