CompTIA CySA + CS0-004 (V4) Exam (New Version) Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A vulnerability management team notes that one finding, if exploited, could allow full remote code execution on a customer-facing server, while a separate finding has no vendor-released fix available despite being known for over a year. Which two prioritization criteria do these two notes represent, respectively?

Explanation

The potential for full remote code execution describes impact, the severity of consequences if exploited, while the lack of a vendor-released fix describes patch and remediation availability. Asset value concerns how important the affected system is, exploitability concerns how easily the flaw can be exploited, and true positive rate concerns detection accuracy.

Submit
Please wait...
About This Quiz
CompTIA CySA + Cs0-004 (V4) Exam (New Version) Practice Test  5 - Quiz

This practice assessment focuses on the CompTIA CySA + CS0-004 certification, evaluating your knowledge in threat detection, analysis, and response strategies. It covers essential concepts in cybersecurity, including security architecture, incident response, and vulnerability management. This resource is invaluable for those preparing for the certification exam, as it helps reinforce... see morecritical skills and knowledge needed in the field of cybersecurity. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. After an incident, the threat intelligence team produces a document specifically tailored to this organization's environment, detailing which of the observed adversary's tactics are most relevant to the company's own systems and where similar exposure might exist elsewhere in the environment. Which reporting artifact does this describe?

Explanation

A report specifically tailored to the organization's own environment, translating observed adversary tactics into relevance for the company's own systems, is an internal threat intelligence report. An executive summary is a concise leadership overview, an after action report documents the incident record, a risk scorecard summarizes overall risk posture, and compliance findings document regulatory gaps.

Submit

3. During an ongoing incident, the security team ensures that updates are communicated consistently through a dedicated incident Slack channel and a scheduled email digest, rather than through ad hoc phone calls that different people might miss. This practice is best described as which concept?

Explanation

Operational security awareness includes establishing consistent, defined communication channels during an incident so updates reach the right people reliably. An executive summary is a specific leadership-facing document, shift handover concerns transferring incident status between teams, post-incident reporting happens after resolution, and an internal threat intelligence report focuses on adversary context.

Submit

4. A remediation effort for a critical finding stalls for weeks because it requires sign-off from three separate committees before any change can be implemented on the affected system, even though the technical fix itself is simple. Which inhibitor to remediation does this scenario illustrate?

Explanation

A remediation process that stalls due to multiple layers of required committee sign-off, independent of technical complexity, illustrates an organizational governance inhibitor. Legacy systems and patch availability concern the technology itself, business process interruption concerns operational downtime, and degrading functionality concerns a fix breaking something else.

Submit

5. A quarterly vulnerability management report includes a ranked list of the five highest-impact unresolved findings across the organization, intended to focus leadership attention on what matters most. Which reporting element does this ranked list represent?

Explanation

A ranked list of the highest-impact unresolved findings is specifically the top risks element of vulnerability management reporting. Trends show directional change over time, an SLA defines a performance threshold, a risk scorecard is a broader visual summary of overall posture, and compliance findings document gaps against a specific standard.

Submit

6. An analyst explains to a junior team member that one framework organizes an attack into a fixed set of sequential stages from reconnaissance to actions on objectives, while a second framework instead catalogs hundreds of specific, granular techniques that do not have to occur in any fixed order. Which two frameworks is the analyst describing, respectively?

Explanation

The Cyber Kill Chain organizes an attack into a fixed, sequential set of stages, while MITRE ATT&CK catalogs a much larger and more granular set of specific techniques that do not follow a required fixed order. The Diamond Model maps relationships between intrusion elements, STRIDE is a design-time threat modeling framework, and the Pyramid of Pain ranks indicator value.

Submit

7. After containing and eradicating a malware infection that spread through a phishing email, the team investigates and determines that the actual underlying reason the malware executed was an outdated email filtering rule that failed to catch a known malicious attachment type. This determination is the result of which activity?

Explanation

Identifying the actual underlying reason an incident occurred is root cause analysis, which typically precedes deciding on specific corrective actions. Establishing a timeline sequences events without necessarily explaining why they happened, triage is an early urgency assessment, chain of custody concerns evidence handling, and corrective action development is the subsequent step.

Submit

8. A security team runs an exercise in which participants actually execute real technical steps, such as isolating a mock-infected virtual machine and running actual remediation scripts in a sandboxed lab environment, rather than only discussing the response verbally. Which type of training exercise does this describe?

Explanation

A simulation has participants actually execute real technical steps in a controlled or sandboxed environment, unlike a tabletop exercise where the response is only discussed verbally. Awareness training focuses on general security education, and a root cause analysis workshop or post-incident review both happen after a real incident.

Submit

9. As part of recovering from a server compromise, the team rebuilds the affected server from a known-good image and reapplies the organization's standard configuration baseline before returning it to production. This specific technical activity is best described as which incident response task?

Explanation

Rebuilding a server from a known-good image and reapplying a standard baseline is performing restoration, the hands-on technical work of returning a system to a trusted state. Root cause analysis determines why the incident occurred, establishing a timeline sequences events, escalation concerns notification, and corrective action development defines broader preventive changes.

Submit

10. After malware has been fully removed from all affected systems, the team restores the systems from clean backups, reconnects them to the network, and closely monitors them for any signs of reinfection before declaring the incident resolved. Which phase does this describe?

Explanation

Restoring systems from clean backups, reconnecting them, and monitoring for reinfection after the malware is already removed is the recovery phase. Containment and eradication happen earlier while the threat is still active or being removed, preparation happens before any incident, and analysis happens early on.

Submit

11. During an active ransomware incident, the response team disconnects infected machines from the network to stop further spread, but has not yet removed the malware itself from those machines. Which incident response phase best describes the action taken so far?

Explanation

Disconnecting infected machines to stop further spread, without yet removing the malware itself, is containment. Eradication would involve actually removing the malware, recovery would involve restoring systems, analysis happens before containment, and post-incident happens well after the threat is fully resolved.

Submit

12. A development team wants an automated tool that scans their application's dependency tree to identify which open-source libraries are included and whether any of them have known vulnerabilities. Which practice does this describe?

Explanation

Software composition analysis specifically scans an application's dependency tree to identify included open-source components and flag known vulnerabilities. SAST analyzes an organization's own source code, DAST tests a running application's behavior, SAMM is a broader maturity framework, and supply chain risk assessment is a broader concept SCA tooling directly supports.

Submit

13. Match each risk concept to its correct description.

Explanation

Risk appetite defines how much risk an organization is willing to tolerate, inherent risk describes the raw exposure before any controls are applied, and residual risk describes what remains after controls have been put in place.

Submit

14. A security team wants to bring log data from a newly deployed cloud application into their existing SIEM so it can be analyzed alongside on-premises logs. Setting up this initial collection pipeline is best described as which logging concept?

Explanation

Log ingestion is the process of collecting and bringing log data from a source into a central platform like a SIEM for analysis. Retention concerns how long data is kept, time synchronization concerns clock alignment, integrity concerns tamper protection, and configuration concerns what and how events are recorded at the source.

Submit

15. An analyst needs to quickly sweep an entire large external IP range to identify which hosts have any ports open at all, prioritizing speed over deep service identification, before running more detailed tools against the responsive hosts. Which tool is best suited to this initial high-speed sweep?

Explanation

Masscan is built for extremely high-speed scanning across very large IP ranges, prioritizing speed to quickly identify responsive hosts. Nmap offers deeper service detection but at slower speed across large ranges, Burp Suite targets web application traffic, Nuclei runs template-based vulnerability checks, and OpenVAS performs deeper vulnerability assessment.

Submit

16. A retailer runs a baseline scan specifically to verify its payment card processing systems meet a payment industry security standard, and separately runs another baseline scan against a broader international information security management standard used across its entire organization. Which two security baseline frameworks do these two scans represent, respectively?

Explanation

The scan focused specifically on payment card processing systems checks against PCI DSS, while the broader international information security management standard used organization-wide is the ISO 27000 series. CIS benchmarks provide vendor-neutral configuration hardening guidance rather than a payment-specific or ISO-branded standard, CVSS scores vulnerability severity, and SAMM is a maturity model.

Submit

17. Before scheduling a vulnerability scan against a segment containing point-of-sale terminals during business hours, a team considers the potential performance impact on those terminals and decides to run the scan overnight instead, outside of peak transaction times. Which planning consideration is being addressed here?

Explanation

Considering the timing and potential performance impact of a scan on sensitive systems, and adjusting the schedule accordingly, is exactly what planning considerations such as scheduling and performance address. Scan type selection concerns which method to use, asset inventory concerns knowing what exists, discovery scanning identifies devices, and security baseline scanning checks configuration compliance.

Submit

18. An organization drafts a formal policy specifying which categories of data may never be entered into a public AI chatbot, and requires employees to complete training before using any AI tool for work purposes. Which AI-related concept does this policy represent?

Explanation

A formal policy governing what data may or may not be entered into AI tools, paired with required training, is governance in the form of AI usage policies. AI risk assessment would evaluate specific risks rather than set usage rules, and model poisoning prevention, hallucination mitigation, and data exposure remediation are technical or incident-response responses rather than governance itself.

Submit

19. A threat intelligence report includes an indicator that was verified by three independent sources within the last 24 hours and directly matches the organization's own technology stack, versus another indicator from a single source that is several months old and describes a platform the organization does not use. Which concept explains why the first indicator should be treated with more confidence?

Explanation

Confidence-level impacts such as timeliness, relevance, and accuracy explain why a recent, multi-source, directly relevant indicator carries more weight. Attribution concerns identifying who is responsible, threat modeling structures design-time threat analysis, cyber deception involves actively misleading an adversary, and the Pyramid of Pain ranks indicator types by attacker cost.

Submit

20. An analyst needs to review native Windows Event Log files exported from a compromised server to look for suspicious logon events. Complete the sentence: these native Windows log files typically use the ______ file format.

Explanation

EVTX is the native file format used by the Windows Event Log service to store event records, including logon events, encountered when exporting and reviewing these logs from a Windows server.

Submit

21. An analyst has a string of data that appears to be Base64-encoded and then XOR-obfuscated, and wants to interactively chain together decoding operations to reveal the original plaintext without writing custom code. Which tool is designed for this kind of interactive data transformation?

Explanation

CyberChef provides a drag-and-drop interface for chaining together decoding, decryption, and other data transformation operations. YARA matches file patterns rather than transforming data, tcpdump captures network traffic, MXToolbox analyzes email and DNS records, and OpenVAS scans for vulnerabilities.

Submit

22. A web application that normally handles thousands of requests per minute suddenly becomes unresponsive after receiving a flood of malformed requests from a range of external IP addresses. Which application-related indicator category does this best represent?

Explanation

The application becoming unresponsive due to a flood of malformed requests is service disruption, where availability itself is impacted. Anomalous activity is a broader category, unauthorized configuration refers to unapproved settings changes, and enumeration and impossible travel describe unrelated reconnaissance and identity indicators.

Submit

23. An EDR alert shows that an employee installed an unapproved file-sharing application on their workstation, and separately shows that a different workstation's CPU usage has been pegged at 100 percent for hours with no obvious legitimate cause. Which two host-related indicator categories do these two findings represent, respectively?

Explanation

Installing an unapproved application is unauthorized software, while sustained abnormally high CPU usage with no legitimate explanation is resource consumption. File system changes would involve unexpected file modification, data exfiltration involves data leaving the network, and a rogue process refers to an unexpected running process rather than overall resource usage.

Submit

24. An analyst is reviewing the specific supervisory system that collects real-time data from field sensors and allows human operators to monitor and adjust an entire industrial process, such as a power grid, from a central control room. Which term specifically describes this supervisory system?

Explanation

SCADA specifically refers to the supervisory system that collects real-time field data and allows centralized human monitoring and control of an industrial process. OT and ICS are broader umbrella terms SCADA falls under, critical infrastructure is a broader sector-level classification, and cloud native infrastructure is unrelated to industrial control.

Submit

25. A company adopts a cloud-delivered service that combines networking and security functions like SD-WAN and secure web gateways into a single subscription for its distributed workforce, and separately maintains some workloads on-premises while running others in a public cloud provider. Which two network architecture concepts do these two situations represent, respectively?

Explanation

The cloud-delivered bundle of networking and security functions for a distributed workforce is SASE, while running some workloads on-premises and others in public cloud is hybrid cloud. ZTNA specifically concerns identity- and device-based access control, a VLAN segments a local network, and software-defined networking is a broader networking approach.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A vulnerability management team notes that one finding, if exploited,...
After an incident, the threat intelligence team produces a document...
During an ongoing incident, the security team ensures that updates are...
A remediation effort for a critical finding stalls for weeks because...
A quarterly vulnerability management report includes a ranked list of...
An analyst explains to a junior team member that one framework...
After containing and eradicating a malware infection that spread...
A security team runs an exercise in which participants actually...
As part of recovering from a server compromise, the team rebuilds the...
After malware has been fully removed from all affected systems, the...
During an active ransomware incident, the response team disconnects...
A development team wants an automated tool that scans their...
Match each risk concept to its correct description.
A security team wants to bring log data from a newly deployed cloud...
An analyst needs to quickly sweep an entire large external IP range to...
A retailer runs a baseline scan specifically to verify its payment...
Before scheduling a vulnerability scan against a segment containing...
An organization drafts a formal policy specifying which categories of...
A threat intelligence report includes an indicator that was verified...
An analyst needs to review native Windows Event Log files exported...
An analyst has a string of data that appears to be Base64-encoded and...
A web application that normally handles thousands of requests per...
An EDR alert shows that an employee installed an unapproved...
An analyst is reviewing the specific supervisory system that collects...
A company adopts a cloud-delivered service that combines networking...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!