Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 1–75

701 questions total · 10pages · All types, answers revealed

Page 1 of 10

Page 2
1
MCQeasy

A security analyst needs to present vulnerability scan results to a non-technical manager. Which of the following is MOST important to include?

A.Summary of critical vulnerabilities with associated business risk and recommended actions
B.Raw scan output with IP addresses and ports
C.Detailed exploit code for critical vulnerabilities
D.List of all CVSS scores with no further explanation
AnswerA

A non-technical manager needs business context, not raw technical detail. Summarising critical vulnerabilities alongside their business risk and recommended remediation actions translates scanner output into decision-ready information, satisfying the stem's requirement to communicate findings effectively to a non-technical audience.

Why this answer

When presenting vulnerability scan results to a non-technical manager, the most important information is a summary of critical vulnerabilities with associated business risk and recommended actions. This approach translates technical details into business impact, enabling the manager to understand the urgency and make informed decisions about resource allocation. Options B and C are too technical, while Option D lacks context and prioritization.

2
MCQeasy

During a network traffic review, an analyst notices encrypted traffic to an unusual external IP address on TCP port 53. What is the most likely anomaly this indicates?

A.Normal DNS resolution
B.Beaconing to command and control
C.Data exfiltration via DNS tunnelling
D.HTTP smuggling attack
AnswerC

Attackers frequently use DNS tunneling to bypass firewalls by encapsulating non-DNS protocols and encrypted payloads inside DNS packets. Because TCP port 53 allows for larger, reliable data streams compared to UDP, persistent encrypted traffic on this port is a classic indicator of an active data exfiltration channel.

Why this answer

Port 53 is used for DNS, which typically uses UDP. Encrypted traffic on TCP/53 suggests DNS tunnelling, where data is exfiltrated inside DNS queries and responses.

3
MCQeasy

Refer to the exhibit. The output is from a Linux system running `netstat -an`. Which of the following ports is likely being used for remote command-and-control communication?

A.54321
B.22
C.53
D.80
AnswerA

Port 54321 falls into the dynamic/private port range, typically used for ephemeral client-side connections. However, if observed as a listening port or as the destination port for an established connection to an external IP, it becomes highly anomalous. Attackers frequently utilize high, non-standard ports for command and control (C2) communication or data exfiltration to bypass basic firewall rules and blend with legitimate outbound traffic, making it a strong indicator of compromise.

Why this answer

Port 54321 is a high-numbered ephemeral port that is not associated with any standard service, making it a common choice for malware or remote access tools (RATs) to establish command-and-control (C2) communication. In the netstat -an output, an established connection on a non-standard high port from the local system to a remote IP is a strong indicator of C2 activity, as legitimate services typically use well-known ports.

Exam trap

CompTIA often tests the concept that high-numbered ephemeral ports (above 1024) with no associated standard service are strong indicators of C2 activity, tricking candidates into choosing common service ports like 22, 53, or 80 because they are familiar, even though those are legitimate and monitored.

How to eliminate wrong answers

Option B is wrong because port 22 is the default for SSH, a legitimate remote administration protocol, and while it can be abused for C2, it is not the likely port for covert C2 communication in this context. Option C is wrong because port 53 is used for DNS, which is essential for name resolution; although DNS can be tunnelled for C2, the direct use of port 53 for an established connection (not just queries) is less common and would be more conspicuous. Option D is wrong because port 80 is the standard HTTP port for web traffic; while HTTP can be used for C2, it is a well-known port that is heavily monitored and less likely to be used for stealthy C2 compared to a non-standard high port.

4
MCQmedium

An analyst identifies a security policy violation during a routine audit. The violation does not pose immediate risk. Which of the following is the BEST way to report this finding?

A.Create a formal report with the finding, policy references, and recommended remediation
B.Mention it casually in a team meeting
C.Send an instant message to the system owner
D.Immediately report it to the Chief Information Security Officer
AnswerA

Formalizing the security policy violation in a structured report ensures that the finding is properly documented for compliance and audit trails. Including specific policy references and actionable remediation steps provides the system owner with the necessary context to resolve the issue while establishing accountability and a clear path for follow-up verification.

Why this answer

A formal report is the best method for documenting a security policy violation because it provides a permanent, auditable record that includes specific policy references and recommended remediation steps. This aligns with the reporting and communication domain's emphasis on structured, traceable documentation for non-urgent findings, ensuring proper tracking and accountability without causing unnecessary alarm.

Exam trap

CompTIA often tests the distinction between formal reporting for non-urgent findings versus immediate escalation for critical threats, trapping candidates who confuse 'no immediate risk' with 'requires urgent action' or choose informal communication methods.

How to eliminate wrong answers

Option B is wrong because casually mentioning a policy violation in a team meeting lacks formal documentation, making it impossible to track remediation or prove compliance during audits. Option C is wrong because sending an instant message to the system owner is informal and ephemeral, providing no permanent record or policy reference for future review. Option D is wrong because immediately reporting a non-urgent violation to the Chief Information Security Officer escalates unnecessarily, bypassing standard reporting channels and overwhelming leadership with low-priority issues.

5
MCQmedium

When performing digital forensics, which of the following represents the correct order of volatility from most volatile to least volatile?

A.RAM, CPU registers, disk, swap, logs, archived media
B.Swap, RAM, CPU registers, disk, logs, archived media
C.Archived media, logs, disk, swap, RAM, CPU registers
D.CPU registers, RAM, swap, disk, logs, archived media
AnswerD

This is the standard order of volatility used in digital forensics, ranking evidence by how quickly it is lost. CPU registers are the most volatile, holding the CPU's current working values and disappearing in nanoseconds; RAM follows, losing all data when power is removed; swap is a disk-backed file that may persist but is overwritten and purged; then disk, logs (which are written regularly but more durable), and finally archived media, which is deliberately preserved and least volatile. Following this order ensures the most fragile evidence is collected first.

Why this answer

The order of volatility, per RFC 3227, runs from most volatile to least: CPU registers and cache, RAM, swap/pagefile, disk (local), logs (remote), and archived media. Option D follows this sequence exactly. Capturing the most volatile data first preserves evidence that would otherwise be lost when the system powers down or memory is overwritten.

Exam trap

CS0-004 often tests the RAM-vs-CPU-registers and RAM-vs-swap ordering; candidates who memorize 'RAM first' forget that registers and cache are even more volatile.

How to eliminate wrong answers

Option A is wrong because it places RAM before CPU registers — registers and cache are more volatile than RAM since they are overwritten on every instruction cycle. Option B is wrong because it places swap before RAM; swap is disk-backed and persists longer than RAM, so it is less volatile. Option C is wrong because it reverses the entire order, listing archived media (least volatile) first and CPU registers (most volatile) last — the exact inverse of the correct sequence.

6
MCQeasy

A mid-sized e-commerce company uses a multi-cloud environment with AWS and Azure. The vulnerability management team performs monthly authenticated scans using a commercial scanner. During the last scan, a critical remote code execution vulnerability (CVE-2023-XXXX) was identified on an EC2 instance running a legacy application. The application owner states that the instance cannot be patched immediately because the patch would break compatibility with a third-party API. The instance has direct internet access and handles PCI data. The CISO wants to reduce risk to an acceptable level within 48 hours. Which course of action should the analyst recommend?

A.Place the EC2 instance behind a web application firewall (WAF) and restrict inbound access to known IPs using security groups.
B.Decommission the instance and remove the legacy application from service immediately.
C.Apply the vendor-recommended patch after testing in a dev environment within two weeks.
D.Disable TLS 1.0 and enable TLS 1.2 on the instance to reduce the attack surface.
AnswerA

This is a strong immediate mitigation strategy. A Web Application Firewall (WAF) inspects HTTP/S traffic and can block common attack patterns, including those leading to Remote Code Execution (RCE), without requiring application changes. Security groups act as a virtual firewall, limiting network access to only necessary IP addresses, significantly reducing the attack surface and potential for exploitation while a permanent fix is developed. This provides immediate protection for PCI data.

Why this answer

Placing the EC2 instance behind a WAF and restricting inbound access to known IPs via security groups provides immediate, compensating controls that reduce the attack surface for the critical RCE vulnerability. Since the instance cannot be patched within 48 hours, this network-layer isolation (WAF filtering malicious payloads, security groups limiting source IPs) aligns with the CISO's risk reduction requirement while maintaining business operations and PCI compliance.

Exam trap

CompTIA often tests the concept that compensating controls (like WAF + security group restrictions) are acceptable for immediate risk reduction when patching is not feasible, and candidates mistakenly choose a delayed patch (Option C) or an irrelevant security fix (Option D) instead of the correct network-layer mitigation.

How to eliminate wrong answers

Option B is wrong because decommissioning the instance immediately would break the legacy application and the third-party API integration, causing unacceptable business disruption and potential PCI data processing failure; the CISO asked for risk reduction, not removal. Option C is wrong because applying the patch in two weeks violates the 48-hour risk reduction mandate and does not address the immediate threat; the analyst must recommend a compensating control, not a delayed patch. Option D is wrong because disabling TLS 1.0 and enabling TLS 1.2 addresses encryption weaknesses, not the remote code execution vulnerability (CVE-2023-XXXX); it does not mitigate the specific RCE attack vector.

7
MCQmedium

A security analyst is configuring a SIEM correlation rule to detect potential brute-force attacks. Which log source combination is most appropriate for this rule?

A.Authentication logs and firewall logs
B.Authentication logs and DNS logs
C.Firewall logs and IDS logs
D.Endpoint logs and cloud audit logs
AnswerA

Correlating authentication logs with firewall logs allows analysts to map failed login attempts to specific external IP addresses and network traffic patterns. This combination is essential for identifying distributed brute-force attacks, as it links application-level credential failures with network-level connection attempts.

Why this answer

Authentication logs show login attempts, and firewall logs show source IPs; combining them can detect multiple failed logins from an IP.

8
MCQmedium

A company uses a mix of Windows and Linux servers. The vulnerability scanner reports a critical remote code execution vulnerability in Apache Struts (CVE-2017-5638) on a web server located in the DMZ. This server is behind a load balancer with an identical twin server that does not appear vulnerable. The security team needs to implement immediate remediation while minimizing downtime. What should the analyst do?

A.Re-image the server with a hardened operating system
B.Implement a virtual patch via web application firewall (WAF) rules
C.Shut down the vulnerable server until a patch can be tested
D.Apply the vendor patch immediately during business hours
AnswerB

Implementing a virtual patch through WAF rules provides an immediate and non-intrusive layer of protection by inspecting and filtering malicious traffic targeting the Apache Struts vulnerability. This method blocks known exploit patterns at the network edge, preventing successful attacks from reaching the vulnerable application without requiring changes to the server or application code. It effectively buys critical time for security teams to thoroughly test and deploy the official vendor patch in a controlled manner, minimizing service disruption.

Why this answer

Implementing a virtual patch via WAF rules can immediately block exploitation attempts against CVE-2017-5638 (Apache Struts) without modifying the server or taking it offline. The WAF inspects HTTP requests for malicious Content-Type headers used in the exploit and drops them, providing protection while the identical twin server remains unaffected and the vulnerable server can be patched later with minimal downtime.

Exam trap

The trap here is that candidates may choose immediate patching (Option D) without considering the requirement to minimize downtime, or they may choose shutdown (Option C) thinking it's the safest, but the scenario explicitly prioritizes uptime over a full patch cycle.

How to eliminate wrong answers

Option A is wrong because re-imaging the server with a hardened OS does not address the specific Apache Struts vulnerability and introduces significant downtime, which contradicts the requirement to minimize downtime. Option C is wrong because shutting down the vulnerable server would cause an outage for the DMZ web service, and the load balancer would route all traffic to the twin server, potentially overloading it or exposing a single point of failure. Option D is wrong because applying the vendor patch immediately during business hours risks service disruption if the patch introduces compatibility issues or requires a restart, and the scenario explicitly calls for minimizing downtime.

9
MCQeasy

A security analyst is reviewing a vulnerability scan report and notices a plugin that identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The CVSS vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which attack vector is indicated?

A.Network
B.Adjacent network
C.Local
D.Physical
AnswerA

AV:N (Attack Vector: Network) means the vulnerable component is bound to the network stack and the attacker's path to exploit lies through a routable network connection, potentially even across the internet, rather than requiring physical or local access. This is the highest-severity attack vector value because it maximizes the pool of potential attackers, contributing to this vulnerability's near-maximum CVSS base score of 9.8 alongside low complexity and no required privileges or user interaction.

Why this answer

AV:N indicates network attack vector, meaning the vulnerability can be exploited remotely over the network without any physical or local access.

10
MCQhard

A vulnerability management team is evaluating a critical vulnerability in a legacy application that cannot be patched. The application is used by a small number of users internally. Which of the following is the best compensating control to reduce risk?

A.Implement network segmentation to restrict access to the application
B.Enable application whitelisting on all endpoints
C.Encrypt all data in transit
D.Disable the application until a patch is available
AnswerA

Implementing network segmentation isolates the vulnerable legacy application within a restricted network zone, such as a dedicated VLAN or DMZ. This control significantly reduces the attack surface by ensuring only authorized users and systems can communicate with the application, effectively mitigating the risk of lateral movement and unauthorized exploitation when no patch is available.

Why this answer

When patching is not possible, compensating controls like network segmentation can limit exposure. Disabling the application would impact business. Application whitelisting might be too broad.

Encryption doesn't prevent exploitation of the vulnerability.

11
Multi-Selectmedium

After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)

Select 3 answers
A.Disabling user accounts that clicked the phishing link
B.Updating email filtering rules and detection signatures
C.Sharing indicators of compromise with other organizations via a threat intelligence platform
D.Conducting a lessons learned meeting to identify process improvements
E.Reimaging all affected workstations
AnswersB, C, D

Updating email filtering rules and detection signatures is a direct, preventive improvement that uses indicators from the phishing campaign (such as sender domain, subject line patterns, and payload hashes) to enhance the email security gateway. This action hardens the environment against similar attacks by proactively blocking malicious emails before they reach users. It is a classic post-incident activity because it closes the specific vulnerability that allowed the phishing email to be delivered, reducing the likelihood of recurrence.

Why this answer

Option B is correct because updating email filtering rules and detection signatures directly operationalizes the lessons from the phishing incident, enabling future similar messages to be blocked or flagged based on the observed sender, subject, URL, or attachment characteristics. Option C is correct because sharing indicators of compromise (IOCs) such as malicious domains, IP addresses, and file hashes through a threat intelligence platform helps other organizations detect the same campaign and can yield reciprocal intelligence that improves the team's own defenses. Option D is correct because a lessons learned meeting is a core post-incident activity that reviews the timeline, root cause, and response effectiveness to identify concrete process, tooling, and training improvements.

Option A is not a post-incident improvement action; disabling accounts is a containment step during the incident, and it does not by itself enhance future detection. Option E is also not a detection improvement; reimaging workstations is an eradication/recovery action for affected hosts and does not build capability to detect similar attacks later.

Exam trap

CS0-004 often tests the confusion between containment/recovery actions (disabling accounts, reimaging hosts) and true post-incident improvement activities (lessons learned, detection tuning, intel sharing).

12
MCQhard

An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?

A.A screenshot of the control configuration
B.A policy document describing the control
C.A control effectiveness report with test results and metrics
D.An email from the system owner stating the control is working
AnswerC

A control effectiveness report supplies measured test results and metrics, giving auditors objective proof that the control operates as intended rather than merely existing. This directly satisfies the stem's requirement to demonstrate effectiveness, since design documentation or policy statements alone cannot evidence actual performance.

Why this answer

A control effectiveness report with test results and metrics provides objective, measurable evidence that the control actually works as intended, which is what auditors require. Configuration screenshots and policy documents only show intent or design, not operational effectiveness.

Exam trap

CS0-004 often tests the difference between design evidence (policies, screenshots) and operating effectiveness evidence (test results, metrics), tempting candidates to pick a configuration screenshot because it 'shows' the control.

How to eliminate wrong answers

Option A is wrong because a screenshot of the configuration shows the control was set up but not that it functions correctly or is enforced over time. Option B is wrong because a policy document describes what should be done, which is design evidence, not proof of operating effectiveness. Option D is wrong because an email assertion from the system owner is subjective, unverified, and lacks the test data auditors need to conclude the control is effective.

13
Multi-Selecteasy

Which THREE of the following are common containment techniques used during incident response?

Select 3 answers
A.Disconnect the network cable
B.Shut down the system
C.Reimage the system
D.Block IP addresses at the firewall
E.Change passwords for compromised accounts
AnswersA, D, E

Physically disconnecting the network interface card or disabling the switch port provides immediate physical-layer isolation. This action instantly halts lateral movement and command-and-control traffic without altering the volatile memory of the compromised host, preserving crucial forensic evidence.

Why this answer

Disconnecting the network cable is a common containment technique because it immediately isolates the affected system from the network, preventing the spread of malware or unauthorized access. This physical disconnection ensures that no further network-based communication can occur, which is critical for containing incidents like ransomware or data exfiltration. It is a rapid, low-level action that does not rely on software or OS controls, making it effective even if the system is compromised.

Exam trap

CompTIA often tests the distinction between containment, eradication, and recovery phases, so the trap here is confusing actions like shutting down or reimaging (which belong to later phases) with true containment techniques that isolate the threat without destroying evidence.

14
MCQeasy

An organization is implementing a patch management process. Which of the following is the BEST practice before deploying patches to production systems?

A.Disable automatic updates and deploy patches manually without testing
B.Immediately apply all patches to production to minimize exposure time
C.Test patches in a staging environment that mirrors production
D.Only apply patches that have a CVSS score of 9.0 or higher
AnswerC

Validating patches within a dedicated staging environment that closely replicates the production architecture is a fundamental security best practice. This process allows administrators to identify compatibility issues, assess performance impacts, and ensure system stability before deploying the updates to live, mission-critical systems.

Why this answer

Best practice for patch management includes testing patches in a staging environment that closely mirrors production before deploying to production. This allows identification of compatibility issues, performance impacts, or conflicts without disrupting critical systems. It balances security with operational stability.

Exam trap

CS0-004 often tests the balance between security and availability, where candidates might choose immediate patching to minimize exposure, but best practice emphasizes testing first to avoid disruption.

How to eliminate wrong answers

Option A is wrong because disabling automatic updates and deploying manually without testing increases risk of unpatched vulnerabilities and human error; testing is essential. Option B is wrong because immediately applying all patches to production without testing can cause outages due to unforeseen issues, violating change management best practices. Option D is wrong because only applying patches with CVSS 9.0 or higher ignores other vulnerabilities that may be exploitable in the organization's context; a risk-based approach is better.

15
Multi-Selectmedium

A security analyst is conducting a vulnerability assessment of a Kubernetes cluster. Which TWO of the following are common misconfigurations that could lead to security risks? (Select TWO.)

Select 2 answers
A.Setting resource limits on containers
B.Configuring network policies to restrict traffic
C.Running containers in privileged mode
D.Using read-only root filesystems
E.Using hostPath mounts
AnswersC, E

Running containers in privileged mode grants them every Linux capability, disables seccomp and AppArmor/SELinux confinement, and exposes all host devices, effectively removing isolation between the container and the host kernel. An attacker who exploits a vulnerability in a privileged container can trivially escalate to full host control, making it one of the most dangerous container misconfigurations. During a vulnerability assessment, this should immediately be flagged as a critical finding.

Why this answer

Option C is correct because running containers in privileged mode disables the container's isolation from the host, granting access to all Linux capabilities and devices (equivalent to --privileged), which allows a compromised container to escape and control the node. Option E is correct because hostPath mounts expose a file or directory from the node's filesystem directly into the pod, so a container can read or modify sensitive host paths such as /etc, /var/run/docker.sock, or /proc, enabling privilege escalation and node compromise. Options A and D are not misconfigurations but hardening measures: resource limits mitigate denial-of-service and noisy-neighbor risks, and read-only root filesystems prevent runtime tampering with container binaries.

Option B is also a security control, not a risk, since Kubernetes NetworkPolicies restrict pod-to-pod traffic and enforce segmentation.

Exam trap

CS0-004 often tests the inversion of security best practices, so candidates must recognize that resource limits, network policies, and read-only filesystems are protections, while privileged mode and hostPath mounts are risks.

16
MCQeasy

An organization wants to detect threats in their AWS environment using a cloud-native service that monitors for suspicious API calls and potential credential compromise. Which service should they use?

A.AWS Config
B.AWS GuardDuty
C.AWS CloudTrail
D.AWS Inspector
AnswerB

AWS GuardDuty is a continuous security monitoring and threat detection service that analyzes VPC Flow Logs, AWS CloudTrail management event logs, CloudTrail S3 data events, and DNS logs. It utilizes threat intelligence feeds, machine learning, and anomaly detection to identify malicious activities, such as compromised EC2 instances, credential exfiltration, or unauthorized access within the AWS environment.

Why this answer

AWS GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior in AWS accounts. It analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to detect suspicious API calls, credential compromise, and other threats using machine learning and threat intelligence. This directly matches the requirement for a cloud-native service to detect threats.

Exam trap

CS0-004 often tests the confusion between logging services (CloudTrail) and threat detection services (GuardDuty), where candidates might choose CloudTrail because it logs API calls, but it does not analyze them for threats.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration auditing service that records resource configurations and evaluates compliance, but it does not detect threats or suspicious API calls. Option C is wrong because AWS CloudTrail logs API activity but does not analyze it for threats; it is a logging service, not a detection service. Option D is wrong because AWS Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and network reachability, but it does not monitor for suspicious API calls or credential compromise.

17
MCQmedium

A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?

A.7 days
B.24 hours
C.48 hours
D.72 hours
AnswerD

Under Article 33 of the GDPR, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is delayed beyond this window, the controller must provide a reasoned justification for the delay.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of a breach.

18
MCQmedium

During a vulnerability scan, an analyst identifies a plugin that reports a vulnerability with a CVSS v3.1 base score of 7.5. The vector string includes AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. Which of the following is the primary impact of this vulnerability?

A.Integrity
B.Scope change
C.Availability
D.Confidentiality
AnswerC

The vector's Availability metric is A:H, meaning High, the only impact metric set above None in this string, indicating the vulnerability can fully deny access to the affected resource, for example through a crash or resource exhaustion condition, making Availability the clear primary impact and consistent with a 7.5 base score driven almost entirely by this single high-impact metric.

Why this answer

The CIA impact ratings show A:H (Availability High), meaning the vulnerability primarily impacts availability. C:N and I:N indicate no impact on confidentiality or integrity.

19
MCQmedium

A vulnerability scanner reports a plugin that identifies a web application vulnerability related to the failure to validate user input, allowing an attacker to inject malicious scripts that execute in other users' browsers. Which OWASP Top 10 category does this vulnerability fall under?

A.Injection
B.Security Misconfiguration
C.Cryptographic Failures
D.Broken Access Control
AnswerA

Injection vulnerabilities occur when untrusted user input is interpreted as part of a command or query, leading to unauthorized execution. In OWASP frameworks, Cross-Site Scripting (XSS) is classified as a form of injection because malicious scripts are injected into trusted web applications to execute in the victim's browser.

Why this answer

The description matches cross-site scripting (XSS), which is part of the OWASP Top 10 category 'Injection' (formerly separate, but in 2021 XSS is included in Injection).

20
MCQmedium

Which of the following BEST describes the purpose of a risk register in the context of reporting and communication?

A.To document vulnerabilities found during scans
B.To record all security incidents and their outcomes
C.To list compliance requirements and deadlines
D.To provide a structured way to track identified risks, their likelihood, impact, and mitigation actions
AnswerD

A risk register is the central governance artifact that catalogs identified risks alongside their likelihood, potential impact, assigned owner, and planned or in-progress mitigation actions, giving leadership a consistent, prioritized view for reporting and decision-making across the organization's entire risk landscape rather than any single risk source.

Why this answer

A risk register is a central document that captures identified risks, their assessments, mitigation plans, and status. It supports ongoing risk management and communication to stakeholders.

21
MCQhard

During forensic analysis of a compromised Linux server, an analyst needs to acquire memory evidence. The server is running and the analyst has root access. Which of the following tools should the analyst use to capture the contents of RAM with the least impact on the system?

A.WinPmem
B.FTK Imager
C.dd if=/dev/mem of=mem.dump
D.LiME
AnswerD

LiME (Linux Memory Extractor) is a loadable kernel module purpose-built for forensically sound live acquisition on Linux, capturing physical memory directly into a file or over the network with atomic, kernel-level access that avoids the instability and incompleteness risks of userland tools like dd, making it the appropriate low-impact choice here.

Why this answer

LiME (Linux Memory Extractor) is a loadable kernel module that dumps memory and is designed to minimize footprint. It is commonly used for Linux memory acquisition.

22
MCQmedium

During incident response, the team identifies that an attacker used a compromised third-party vendor account to access the network. Which of the following should the team do first?

A.Change all system passwords
B.Revoke the vendor's access
C.Conduct forensic analysis on the vendor's account
D.Notify law enforcement
AnswerB

Revoking the compromised vendor account's access is the most immediate and effective containment action. This step instantly terminates active sessions and prevents the attacker from leveraging the established credentials to move laterally or exfiltrate sensitive data, aligning with the containment phase of the incident response lifecycle.

Why this answer

The immediate priority is to contain the breach by revoking the compromised third-party vendor's access. This stops the attacker from using the valid session or credentials to move laterally or exfiltrate data. Changing all system passwords (A) is too broad and time-consuming, while forensic analysis (C) and law enforcement notification (D) are secondary steps that occur after containment.

Exam trap

CompTIA often tests the 'containment before eradication' principle, and the trap here is that candidates choose forensic analysis (C) first, mistakenly thinking evidence preservation is more urgent than stopping the active attack.

How to eliminate wrong answers

Option A is wrong because changing all system passwords is a broad, time-consuming action that does not immediately stop the attacker's active session; the attacker may still have tokens or session cookies that bypass password changes. Option C is wrong because conducting forensic analysis on the vendor's account before revoking access allows the attacker to continue their malicious activities, violating the containment-first principle of incident response. Option D is wrong because notifying law enforcement is a post-containment step; the team must first stop the active threat before involving external parties.

23
MCQeasy

Which metric would best indicate the effectiveness of an organization's patch management program?

A.Phishing simulation click rates
B.Open vulnerability counts by severity
C.Mean time to detect (MTTD)
D.Patch SLA compliance percentage
AnswerD

Patch SLA compliance percentage directly measures the proportion of patches applied within the stipulated timeframes, such as critical patches within 48 hours or high-severity within 30 days. It quantifies adherence to the patching policy and reflects the organization's ability to remediate known vulnerabilities on schedule. This is the most relevant benchmark because it captures timeliness, completeness, and scheduling discipline, which are the core factors of patch management effectiveness.

Why this answer

Patch SLA compliance percentage directly measures whether patches were applied within the organization's defined remediation windows (for example, critical patches within 14 days), which is the clearest indicator that the patch management program is working as designed. It ties patch deployment outcomes to policy requirements, making it the most direct effectiveness metric.

Exam trap

CS0-004 often tests the difference between metrics that measure patch program execution (SLA compliance) versus adjacent security metrics (MTTD, phishing click rate, vulnerability counts), so candidates who equate 'fewer vulnerabilities' with 'effective patching' choose the wrong answer.

How to eliminate wrong answers

Option A is wrong because phishing simulation click rates measure security awareness training effectiveness, not patch deployment. Option B is wrong because open vulnerability counts by severity show exposure but not whether the patch program is meeting its remediation timelines — counts can rise from new discoveries even when patching is effective. Option C is wrong because MTTD measures detection speed in incident response, not patch management performance.

24
MCQmedium

A legacy system cannot be patched because the vendor no longer supports the application. What should the vulnerability manager request? For stakeholder management, Which documentation or approval is required to keep the programme defensible?

A.Give all users local admin rights
B.Mark the vulnerability as fixed
C.Remove the system from future reports
D.Documented risk acceptance with compensating controls and a migration/remediation plan
AnswerD

When patching is impossible, formal risk management dictates documenting the risk with executive sign-off while implementing compensating controls, such as network segmentation or strict access control lists. Additionally, establishing a clear migration or decommissioning timeline ensures the organization has a defined exit path to eliminate the legacy liability.

Why this answer

When a legacy system cannot be patched due to vendor end-of-life, the vulnerability manager must formally document the risk acceptance, including compensating controls (e.g., network segmentation, host-based firewall rules) and a migration or remediation plan. This documentation is essential for stakeholder management to demonstrate due diligence and maintain a defensible security posture against audits or compliance reviews.

Exam trap

CompTIA often tests the misconception that removing a system from reports or marking a vulnerability as fixed is acceptable, but the correct approach is always to formally document risk acceptance with compensating controls and a migration plan.

How to eliminate wrong answers

Option A is wrong because granting all users local admin rights would increase the attack surface and eliminate any privilege boundaries, directly violating the principle of least privilege and making the system more vulnerable to exploitation. Option B is wrong because marking the vulnerability as fixed when no patch has been applied is a false declaration; vulnerabilities must be remediated, mitigated, or accepted, not falsely closed. Option C is wrong because removing the system from future reports hides the risk from stakeholders and auditors, undermining transparency and the defensibility of the vulnerability management program.

25
MCQmedium

During incident reconstruction, firewall events appear five minutes earlier than endpoint events for the same connection. What should the analyst check first?

A.Time synchronization and timezone normalization across log sources
B.Delete one source from the timeline
C.Assume the firewall logs are falsified
D.Prioritize only the source with the highest EPS
AnswerA

Clock drift and timezone parsing commonly distort event order in SIEM timelines.

Why this answer

The five-minute discrepancy between firewall and endpoint events for the same connection is a classic symptom of clock drift or misconfigured time synchronization. The analyst should first check NTP (Network Time Protocol) settings and timezone normalization across all log sources to ensure timestamps are aligned. Without synchronized time, correlation of events during incident reconstruction is unreliable, making this the foundational step in root-cause analysis.

Exam trap

The CS0-004 exam often tests the misconception that timestamp discrepancies are due to log falsification or that deleting or prioritizing logs is a valid troubleshooting step, when the correct first action is always to verify time synchronization and normalization across all sources.

How to eliminate wrong answers

Option B is wrong because deleting one source from the timeline removes potentially critical evidence and does not resolve the underlying time discrepancy; it merely hides the symptom. Option C is wrong because assuming the firewall logs are falsified without evidence is a premature conclusion that ignores the more common and plausible cause of clock drift or misconfiguration. Option D is wrong because prioritizing the source with the highest Events Per Second (EPS) does not address timestamp alignment; EPS measures log volume, not temporal accuracy, and could lead to overlooking valid data from lower-volume sources.

26
MCQeasy

During an incident response engagement, a junior analyst asks the team lead about the purpose of a lessons learned meeting. Which of the following BEST describes the primary objective of this meeting?

A.To determine the exact financial cost of the incident for insurance claims.
B.To assign blame for the incident to the responsible parties.
C.To identify improvements to the incident response process and prevent recurrence.
D.To provide a detailed technical walkthrough of the malware for all attendees.
AnswerC

The primary objective of a lessons learned meeting is to review the incident response and identify what went well and what needs improvement. It aims to enhance future detection, response, and recovery. This meeting often results in actionable recommendations for updating plans, training, and tools. It is a key step in the continuous improvement of the incident response capability. The focus is on process enhancement, not punishment.

Why this answer

The lessons learned meeting is a post-incident review focused on improving the incident response process. It identifies strengths and weaknesses in detection, analysis, containment, eradication, and recovery. The outcome should be actionable recommendations to prevent similar incidents and enhance future response.

Blame, financial calculations, and deep technical dives are not the primary objectives. A blameless, improvement-oriented approach is most effective.

Exam trap

The trap here is assuming that the lessons learned meeting is for assigning blame or calculating costs, when its true purpose is process improvement.

27
MCQmedium

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies an alert indicating a high volume of outbound traffic from a critical server to an unknown IP address. Which of the following actions should the analyst perform FIRST?

A.Correlate the alert with firewall logs and other security tools.
B.Notify law enforcement immediately.
C.Isolate the server from the network to prevent data exfiltration.
D.Rebuild the server from a known good backup.
AnswerA

During the Detection and Analysis phase of NIST SP 800-61 Rev 2, analysts must validate precursors and indicators to confirm if an actual incident has occurred. Correlating the initial alert with complementary data sources, such as firewall logs, DNS queries, and host-based intrusion detection systems, helps establish the scope, reduce false positives, and build a timeline before taking disruptive actions.

Why this answer

In the NIST SP 800-61 Detection and Analysis phase, the analyst's first priority is to validate and understand the alert before taking disruptive action. Correlating the alert with firewall logs and other security tools confirms whether the outbound traffic is truly malicious, identifies the destination, and establishes scope — this is the analysis step that precedes containment. Acting on an unverified alert risks unnecessary downtime and destroys evidence needed for the investigation.

Exam trap

The trap here is conflating urgency with action — candidates often pick 'isolate the server' because it feels like the safest immediate step, but NIST SP 800-61 explicitly places containment after detection and analysis.

How to eliminate wrong answers

Option B is wrong because notifying law enforcement is premature and typically occurs after internal validation and escalation procedures, not as a first response to an unconfirmed alert. Option C is wrong because isolation is a Containment-phase action that should follow analysis; isolating immediately on an unverified alert can disrupt critical services and destroy volatile evidence. Option D is wrong because rebuilding from backup is a recovery action taken after eradication, and doing so before analysis would eliminate forensic artifacts and potentially reintroduce the compromise.

28
MCQmedium

A SOC analyst reviews DNS telemetry and sees a workstation resolving hundreds of algorithmically generated domains at fixed intervals, with most responses returning NXDOMAIN. What evidence should the analyst prioritize to validate command-and-control beaconing? In the evidence source phase, Which evidence source best supports or refutes the detection?

A.Search only for successful HTTP 200 responses
B.Delete the host from the SIEM asset inventory
C.Block all DNS traffic from the subnet
D.Correlate DNS query logs with endpoint process and network connection telemetry
AnswerD

Correlating DNS query logs with endpoint process and network connection telemetry is the most effective approach to validate and understand suspicious DGA activity. This comprehensive analysis allows security analysts to pinpoint the specific process generating the unusual DNS queries, observe subsequent network connection attempts (or failures), and confirm if the host is indeed attempting outbound command-and-control communication, thereby enabling precise and targeted remediation efforts.

Why this answer

Correlating DNS query logs with endpoint process and network connection telemetry (Option D) provides direct evidence of command-and-control (C2) beaconing by linking the algorithmically generated domain (AGD) queries to a specific process initiating outbound connections. This cross-referencing validates whether the DNS activity is part of a malware's C2 channel, as legitimate applications rarely generate hundreds of NXDOMAIN responses at fixed intervals. The SOC analyst can confirm the detection by identifying the parent process (e.g., a suspicious executable) and matching its network connections to the queried domains.

Exam trap

The trap here is that candidates often focus on the DNS NXDOMAIN responses alone and choose a reactive action like blocking traffic (Option C) or deleting the host (Option B), instead of recognizing that correlation with endpoint telemetry is required to validate the detection before any response.

How to eliminate wrong answers

Option A is wrong because searching only for successful HTTP 200 responses ignores the core indicator of C2 beaconing—the repeated NXDOMAIN responses—and would miss malware that uses DNS tunneling or fails to resolve before switching domains. Option B is wrong because deleting the host from the SIEM asset inventory removes visibility into the suspicious activity, destroying evidence and preventing further analysis of the beaconing behavior. Option C is wrong because blocking all DNS traffic from the subnet is an overly disruptive response that would break legitimate network operations and does not help validate the detection; it should only be considered as a containment step after confirmation.

29
MCQeasy

An analyst is using AWS GuardDuty and sees a finding that an EC2 instance is communicating with a known command-and-control (C2) IP address. What type of alert is this?

A.CASB alert investigation
B.Vulnerability scan result
C.Cloud audit log analysis
D.Threat intelligence finding
AnswerD

AWS GuardDuty actively leverages continuously updated threat intelligence feeds, including lists of known malicious IP addresses, domains, and attack signatures, to identify suspicious activity. When an EC2 instance communicates with an IP address or domain identified as a known command and control (C2) server by these feeds, GuardDuty generates a finding, indicating a high probability of compromise and C2 communication.

Why this answer

GuardDuty detects threats based on known malicious IPs, so communication with a C2 IP is a security finding indicating a potential compromise.

30
MCQeasy

Which of the following is an example of a behavioral indicator of compromise (IOC) observed during dynamic malware analysis?

A.PE section names
B.File hash
C.Domain name
D.Outbound network connection to a known malicious IP
AnswerD

Watching the sample actually open a socket and beacon out to a known-bad IP during sandbox detonation is a runtime action captured by network monitoring tools like Wireshark or Cuckoo, exemplifying a behavioral IOC because it reflects what the malware does, not just what it is.

Why this answer

Dynamic analysis monitors behavior such as network connections, file system changes, and process creation.

31
MCQmedium

A phishing simulation is conducted, and the click rate is reported to management. What does a high click rate indicate?

A.Employees are well-trained in security
B.The phishing simulation was not realistic
C.The organization has strong technical controls
D.There is a need for more security awareness training
AnswerD

A high click rate during a phishing exercise serves as a key performance indicator (KPI) that employees are highly susceptible to social engineering attacks. To mitigate this risk, the organization must implement targeted, frequent security awareness training and follow-up simulations to educate users on identifying phishing indicators, thereby strengthening the human element of defense-in-depth.

Why this answer

A high click rate suggests that employees are susceptible to phishing, indicating a need for security awareness training.

32
MCQmedium

A security analyst is investigating a potential data breach. The analyst needs to preserve evidence before containment. Which of the following actions is MOST appropriate at this stage?

A.Powering off the system
B.Blocking the attacker's IP at the firewall
C.Disabling the user's account
D.Creating a forensic image of the hard drive
AnswerD

Creating a bit-stream forensic image of the hard drive ensures that a mathematically precise copy of the non-volatile storage is preserved for analysis. This process utilizes write-blockers to prevent any modification to the original media, maintaining chain of custody and evidence integrity. It allows investigators to safely analyze deleted files, slack space, and system artifacts without altering the source system.

Why this answer

Creating a forensic image of the hard drive is the most appropriate action to preserve evidence before containment. A forensic image is a bit-for-bit copy of the storage media that captures the system state, including deleted files, memory remnants, and metadata, without altering the original. This preserves the integrity of evidence for later analysis and legal proceedings.

Powering off, blocking IPs, or disabling accounts are containment actions that can destroy volatile evidence and should be done after imaging.

Exam trap

CS0-004 often tests the confusion between containment and evidence preservation, tricking candidates into selecting actions that alter system state or alert the attacker instead of preserving forensic evidence.

How to eliminate wrong answers

Option A is wrong because powering off the system can destroy volatile evidence in memory (RAM), such as running processes, network connections, and encryption keys, and may also trigger anti-forensic mechanisms. Option B is wrong because blocking the attacker's IP at the firewall is a containment action that can alert the attacker and cause them to destroy evidence or pivot, and it does not preserve local evidence. Option C is wrong because disabling the user's account is also a containment action that may tip off the attacker and does not capture the current state of the system for forensic analysis.

33
Multi-Selecteasy

A security analyst is selecting tools for vulnerability management. Which THREE of the following are vulnerability scanning tools?

Select 3 answers
A.Lynis
B.Nessus
C.Wireshark
D.Qualys
E.OpenVAS
AnswersB, D, E

Nessus is a commercial vulnerability scanner developed by Tenable that actively scans hosts and network services, comparing software versions and configurations against a comprehensive plugin database of known Common Vulnerabilities and Exposures (CVEs). It supports credentialed scans, agent-based scanning, and integration with patch management and SIEM platforms, making it a primary tool for continuous vulnerability management. This directly matches the goal of identifying exploitable weaknesses across an enterprise.

Why this answer

Nessus (B) is a commercial vulnerability scanner from Tenable that performs credentialed and uncredentialed scans to detect missing patches, misconfigurations, and CVEs, making it a core vulnerability management tool. Qualys (D) is a cloud-based vulnerability management platform whose QualysGuard/VMDR scanners continuously assess hosts and web applications for vulnerabilities, so it clearly belongs in this category. OpenVAS (E), maintained as the Greenbone Vulnerability Management (GVM) scanner, is an open-source vulnerability scanner that uses network vulnerability tests (NVTs) to identify known flaws, qualifying it as a scanning tool.

Lynis (A) is a host-based security auditing tool that checks system hardening and compliance rather than scanning for vulnerabilities across assets, and Wireshark (C) is a packet capture and protocol analysis tool used for traffic inspection, not vulnerability scanning.

Exam trap

CS0-004 often tests tool categorization, so candidates confuse host auditing tools like Lynis or protocol analyzers like Wireshark with true vulnerability scanners, which enumerate CVEs against targets.

34
MCQmedium

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which of the following is the most appropriate next step?

A.Notify law enforcement immediately.
B.Immediately isolate the host from the network.
C.Rebuild the host from a known good image.
D.Collect additional logs and perform a deeper analysis to confirm the compromise.
AnswerD

The detection and analysis phase focuses on validating alerts to minimize false positives and accurately scope the potential incident. Gathering supplementary log sources, correlating event data, and conducting deeper forensic analysis are essential steps to confirm that a true compromise has occurred before initiating disruptive containment actions.

Why this answer

After detection, the analyst should collect additional data to confirm the incident and scope the impact before proceeding to containment.

35
Multi-Selectmedium

A security analyst is tuning a SIEM rule that generates alerts for every failed login attempt. The rule is causing alert fatigue. Which TWO actions would reduce false positives while maintaining security visibility?

Select 2 answers
A.Aggregate alerts by source IP and time window
B.Disable the rule entirely
C.Whitelist IP addresses of internal services that generate repeated failed logins
D.Increase the alert severity threshold
E.Increase the log retention period
AnswersA, C

Aggregating alerts by source IP and time window groups multiple failed login attempts into a single, consolidated alert, effectively suppressing repetitive notifications while still preserving detection of brute-force or credential-stuffing activity. This correlation technique condenses dozens or hundreds of individual events into one actionable incident, reducing analyst alert fatigue and allowing the security team to focus on the actual attack pattern rather than being overwhelmed by event-level noise.

Why this answer

Option A is correct because aggregating failed-login alerts by source IP and time window (e.g., using a threshold such as 5 failures in 5 minutes) collapses repetitive noise into a single meaningful event, preserving visibility into brute-force patterns while cutting alert volume. Option C is correct because whitelisting known internal service IPs that legitimately produce repeated failed logins (e.g., misconfigured service accounts or scanners) suppresses expected benign activity without hiding genuine external attack attempts. Option B is wrong because disabling the rule entirely eliminates detection of brute-force and credential-stuffing attacks, destroying security visibility.

Option D is wrong because raising the severity threshold only changes how alerts are labeled or escalated; it does not reduce the number of false-positive alerts generated. Option E is wrong because increasing log retention affects storage duration, not alert generation, so it does nothing to address alert fatigue.

Exam trap

The trap is choosing severity threshold changes or retention increases as if they reduce alert volume — they do not; only aggregation, correlation, and suppression actually cut false positives.

36
MCQhard

A security analyst is evaluating a vulnerability with CVSS v3.1 base score: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N. Which of the following best describes the scope and impact of this vulnerability?

A.Scope is unchanged, high impact on confidentiality only
B.Scope is changed, high impact on integrity only
C.Scope is unchanged, high impact on confidentiality and integrity
D.Scope is changed, high impact on confidentiality only
AnswerD

This is correct: the vector specifies S:C (Scope Changed) and C:H (high confidentiality impact), while integrity and availability are None (I:N/A:N). A Changed scope means the vulnerability affects resources outside the vulnerable component's security authority, and the only rated impact is disclosure of sensitive information. These values exactly match the analyst's finding.

Why this answer

The CVSS v3.1 vector AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N indicates Scope is Changed (S:C) and Confidentiality impact is High (C:H), while Integrity (I:N) and Availability (A:N) impacts are None. Therefore, the correct description is scope changed with high impact on confidentiality only. The other options misstate either the scope or the impacted security property.

Exam trap

CS0-004 often tests precise CVSS vector parsing, so candidates who skim the string and assume multiple impacts or unchanged scope (because only one impact is High) select the wrong description.

How to eliminate wrong answers

Option A is wrong because it claims scope is unchanged, but the vector specifies S:C (Scope Changed). Option B is wrong because it claims high impact on integrity, but the vector shows I:N (Integrity None). Option C is wrong because it claims scope unchanged and high impact on both confidentiality and integrity, but the vector shows S:C and I:N.

37
Multi-Selectmedium

A SOAR playbook enriches suspicious IP addresses. Which enrichment sources are useful? (Choose two.)

Select 2 answers
A.Threat intelligence reputation and first-seen date
B.Internal asset and previous-seen telemetry
C.Random social media comments about cybersecurity
D.Office chair inventory
AnswersA, B

Querying external threat intelligence feeds for an IP's reputation score and first-seen registration date provides critical external context. This data helps the SOAR playbook assess the likelihood of malicious activity, such as identifying newly registered domains or known command-and-control nodes, enabling automated, risk-based triaging.

Why this answer

Threat intelligence reputation feeds (e.g., VirusTotal, AlienVault OTX) provide a risk score and first-seen date for an IP, which helps determine if it is known for malicious activity and how recently it became active. Internal asset and previous-seen telemetry (e.g., from a SIEM or asset management database) reveals if the IP belongs to an internal host or has been observed in past incidents, enabling context-aware response. Both sources directly support enrichment by adding authoritative, actionable data to the playbook.

Exam trap

The CS0-004 exam often tests the distinction between authoritative, structured enrichment sources (threat intel feeds, internal logs) versus irrelevant or untrusted data (social media, physical inventory) to see if candidates understand that SOAR automation requires reliable, machine-readable inputs.

38
MCQhard

An analyst is evaluating the performance of the security operations center (SOC). Which metric best indicates the team's ability to contain an active threat?

A.Mean time to detect (MTTD)
B.Patch SLA compliance %
C.Mean time to respond (MTTR)
D.Open vulnerability counts by severity
AnswerC

Mean time to respond (MTTR) is the definitive metric for evaluating the speed of incident containment and mitigation. It measures the average time elapsed from the moment an alert is detected to when the threat is successfully isolated or neutralized, directly reflecting SOC operational efficiency during active incidents.

Why this answer

Mean Time to Respond (MTTR) measures the average time taken to contain and remediate an incident, directly reflecting containment speed.

39
Multi-Selecteasy

During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?

Select 3 answers
A.Implement additional network monitoring sensors.
B.Enhance SIEM correlation rules based on current threat intelligence.
C.Subscribe to threat intelligence feeds to enrich alerts.
D.Increase the frequency of vulnerability scans.
E.Reduce the retention period for logs.
AnswersA, B, C

Deploying additional network monitoring sensors at segmentation boundaries and critical ingress/egress points eliminates the blind spots that allowed this incident to go undetected. These sensors capture full packet data, NetFlow metadata, or IDS/IPS alerts, enabling analysts to detect lateral movement and command-and-control activity that passive host-based tools might miss. This is a direct corrective action to improve visibility and reduce time-to-detection for future attacks.

Why this answer

Option A is correct because deploying additional network monitoring sensors (e.g., IDS/IPS or network TAP/SPAN-based collectors) increases visibility across network segments, allowing malicious traffic and anomalies to be observed sooner and thereby lowering MTTD. Option B is correct because tuning and expanding SIEM correlation rules with current threat intelligence lets the platform detect multi-event attack patterns and known adversary techniques faster, directly reducing the time between compromise and alerting. Option C is correct because subscribing to threat intelligence feeds enriches alerts with indicators of compromise (IOCs) and contextual data, enabling analysts to recognize and prioritize malicious activity more quickly.

Option D is not appropriate because vulnerability scans identify unpatched weaknesses on a scheduled basis and do not provide real-time detection of active intrusions, so they do not materially improve MTTD. Option E is not appropriate because reducing log retention removes historical evidence needed for correlation and forensic analysis, which would likely degrade detection and investigation capabilities rather than improve them.

Exam trap

CompTIA often tests whether candidates confuse detection improvement with prevention or hygiene activities; vulnerability scanning and log reduction sound security-related but do not reduce MTTD.

40
Multi-Selectmedium

During a security incident, a cybersecurity analyst must communicate with various stakeholders. Which TWO are appropriate internal escalation paths? (Select TWO.)

Select 2 answers
A.Legal and compliance department
B.Law enforcement
C.Customers
D.Incident response team
E.Media
AnswersA, D

The legal and compliance department is the correct first point of contact because it ensures the organization satisfies statutory and regulatory breach notification obligations (e.g., GDPR, HIPAA, SEC rules) before any public or external disclosure. They also provide legal counsel on preservation of evidence and attorney-client privilege, which directly influences containment and eradication actions. Engaging this internal team early prevents costly penalties and legal exposure from mishandled incident response.

Why this answer

Option A (Legal and compliance department) is correct because internal escalation during a security incident must include legal and compliance so they can assess regulatory notification duties (e.g., GDPR, HIPAA, PCI DSS), preserve legal privilege, and advise on breach disclosure obligations. Option D (Incident response team) is correct because the IR team is the core internal group that triages, contains, eradicates, and recovers from the incident, and it is the primary escalation path for technical and procedural coordination. Option B (Law enforcement) is not an internal path; it is an external authority engaged only when required or appropriate, often after legal review.

Option C (Customers) is external and typically notified only after legal/comms approval, not as an escalation path. Option E (Media) is external and handled through public relations or communications, not an internal escalation route.

Exam trap

CS0-004 often tests the boundary between internal and external stakeholders, tempting candidates to select law enforcement or customers because they are commonly involved in incident response overall.

41
Multi-Selecthard

A security analyst is reviewing a containerized application for vulnerabilities. The analyst uses a container image scanner and identifies several issues. Which THREE of the following are common container and Kubernetes misconfigurations that the analyst should prioritize? (Choose three.)

Select 3 answers
A.Overly permissive RBAC configurations
B.Keeping container images up to date
C.Running containers with the 'privileged' flag
D.Implementing network policies to restrict pod communication
E.Using hostPath mounts
AnswersA, C, E

Overly permissive RBAC bindings grant cluster-wide or wildcard permissions, letting a compromised workload escalate privileges or reach other namespaces. Auditing roles, ClusterRoleBindings and service accounts for excessive verbs and resources is a priority Kubernetes hardening check.

Why this answer

Option A (Overly permissive RBAC configurations) is correct because Kubernetes RBAC roles bound with wildcards or cluster-admin privileges grant excessive permissions, enabling privilege escalation and lateral movement across the cluster. Option C (Running containers with the 'privileged' flag) is correct because a privileged container disables most namespace isolation and gains near-full access to host devices and kernel capabilities, effectively breaking container boundaries. Option E (Using hostPath mounts) is correct because hostPath volumes expose node filesystem paths to pods, allowing access to sensitive host files such as /var/run/docker.sock or /etc, which can lead to node compromise.

Option B is not a misconfiguration but a security best practice, since updating images remediates known CVEs rather than introducing risk. Option D is also a recommended hardening control, as network policies restrict pod-to-pod traffic and reduce lateral movement, so it is not a misconfiguration to prioritize.

42
MCQeasy

Which of the following is a primary benefit of using credentialed vulnerability scans over non-credentialed scans?

A.They are less likely to crash services
B.They provide more accurate results by checking internal configurations
C.They are faster and less intrusive
D.They do not require network access
AnswerB

Logging in with valid credentials lets the scanner query installed package versions, registry keys, running services, and local patch levels directly from the OS, producing far fewer false positives and negatives than inferring vulnerabilities purely from external banners and network responses.

Why this answer

Credentialed scans can access the OS and applications, allowing deeper inspection of installed software, patches, and configuration settings.

43
MCQmedium

An EDR alert shows powershell.exe launched by winword.exe with an encoded command line and outbound HTTPS shortly after a user opened an email attachment. What is the BEST first analytic pivot that balances containment with evidence preservation?

A.Close the alert because HTTPS is expected traffic
B.Disable the SIEM parser for PowerShell events
C.Decode the command and inspect the process tree, parent document, and network destination
D.Reimage every workstation in the department
AnswerC

Encoded PowerShell launched by Office is a high-signal chain; decoding and process-tree review confirms intent and scope.

Why this answer

The encoded PowerShell command is the most direct artifact of the attacker's intent; decoding it reveals the executed payload, while inspecting the process tree confirms the parent-child relationship (winword.exe spawning powershell.exe), the parent document identifies the phishing vector, and the network destination pinpoints the C2 server. This triage provides the evidence needed for containment without destroying forensic data.

Exam trap

The CS0-004 exam often tests the misconception that HTTPS traffic is inherently safe or that immediate containment (like reimaging) is always the best first step, when in reality the priority is to preserve and analyze volatile evidence before taking irreversible actions.

How to eliminate wrong answers

Option A is wrong because outbound HTTPS from a PowerShell process spawned by winword.exe is highly anomalous—attackers frequently use HTTPS to blend in with legitimate traffic, so closing the alert ignores a clear indicator of compromise. Option B is wrong because disabling the SIEM parser for PowerShell events would blind the security team to all future PowerShell activity, including legitimate administrative tasks, and does nothing to address the current alert. Option D is wrong because reimaging every workstation is an extreme, untargeted response that destroys volatile evidence (e.g., memory, process trees, network connections) and is premature before confirming the scope of the infection.

44
Multi-Selecthard

A SIEM receives endpoint, firewall, identity, and cloud logs for the same incident, but timestamps do not align across sources. Which actions should the analyst take before finalizing the timeline? (Choose two.)

Select 2 answers
A.Assume the latest arriving event happened last
B.Verify time synchronization and timezone parsing for each source
C.Discard every source except the firewall
D.Normalize events to a common timestamp standard such as UTC
AnswersB, D

Accurate time synchronization, typically via NTP, across all log-generating systems and SIEM components is critical to prevent clock drift, which can cause events to appear out of sequence. Furthermore, correctly parsing and converting timestamps from various sources, which might use different local timezones or formats, ensures that all events are consistently represented against a common temporal baseline. This verification step is essential for building a reliable chronological incident timeline.

Why this answer

Without verifying time synchronization (e.g., NTP configuration) and timezone parsing for each log source, the analyst cannot trust the chronological order of events. A SIEM relies on accurate timestamps to correlate logs from endpoints, firewalls, identity systems, and cloud platforms; misaligned timestamps can lead to incorrect incident reconstruction.

Exam trap

The CS0-004 exam often tests the misconception that you can simply trust the order logs arrive in the SIEM, but the trap is that arrival order does not equal occurrence order due to network latency, buffering, and clock skew.

45
MCQeasy

A security analyst is reviewing SIEM alerts and notices a high volume of alerts for a specific event ID that has been determined to be benign. Which action should the analyst take to reduce noise?

A.Increase the severity of the alert
B.Reclassify the alert as a true positive
C.Create a suppression rule for that event ID
D.Disable the SIEM correlation engine
AnswerC

Implementing a suppression rule allows the SIEM to filter out or silence specific, known-benign event IDs under defined conditions. This directly reduces alert fatigue and noise in the console, allowing analysts to focus on legitimate security threats without losing the underlying log data.

Why this answer

True positive alerts are genuine threats; false positives are benign. Tuning the SIEM to suppress known false positives reduces alert fatigue.

46
Multi-Selecthard

An analyst suspects DNS tunnelling but wants to avoid over-escalating normal CDN behaviour. Which comparisons help? (Choose two.)

Select 2 answers
A.Baseline query length, entropy, and subdomain uniqueness for the host
B.Compare query rate and destination domains against peer hosts
C.Check whether the user likes the website
D.Count the number of icons on the desktop
AnswersA, B

Establishing a baseline of query length, Shannon entropy, and subdomain uniqueness allows analysts to detect the high-entropy, long, and highly unique subdomains typical of DNS tunneling payloads. Because DNS tunnels encode data such as SSH or VPN traffic within TXT, CNAME, or AAAA queries, these requests deviate significantly from a host's normal, structured DNS patterns. Monitoring these specific label characteristics helps identify exfiltration or command-and-control channels without generating excessive false positives.

Why this answer

DNS tunnelling encodes non-DNS data (e.g., file exfiltration or C2 commands) into DNS queries, often producing abnormally long, high-entropy subdomains. Comparing current query length, entropy, and subdomain uniqueness against a baseline for the same host helps distinguish tunnelling from legitimate CDN traffic, which typically uses short, predictable subdomains. This approach focuses on the structural characteristics of the queries themselves, avoiding false positives from normal CDN behaviour.

Exam trap

The trap here is that candidates may confuse DNS tunnelling detection with generic anomaly detection, overlooking the need for a host-specific baseline to avoid flagging legitimate CDN traffic that naturally has higher query rates or longer subdomains.

47
MCQmedium

During a network traffic analysis, a security analyst observes repeated connections from an internal host to a known malicious IP on port 4444. The payload appears to be encrypted. Which type of activity is most likely indicated?

A.Port scanning activity
B.Command and control beaconing
C.Data exfiltration via DNS tunnelling
D.Lateral movement using SMB
AnswerB

Command and control (C2) beaconing involves an infected host periodically initiating outbound connections to a C2 server, often on a non-standard port like 4444, to check for new commands or upload data. These connections are typically regular, repetitive, and consistent in their destination and port, fitting the description of repeated connections to a single IP on port 4444. This behavior establishes a persistent communication channel for remote control of the compromised system.

Why this answer

Repeated connections to a known malicious IP on a non-standard port with encrypted payloads strongly suggest command and control (C2) beaconing.

48
MCQhard

An analyst is investigating a host that communicates with a domain using a DGA-like algorithm. The domain name appears random and resolves to different IPs over time. Which threat-hunting technique would best identify the DGA pattern?

A.Sigma rule on process creation events
B.NetFlow analysis for data volume
C.YARA rule matching on process memory
D.DNS log analysis for entropy and frequency
AnswerD

DNS log analysis is the most effective method for identifying Domain Generation Algorithm (DGA) activity by examining the structural properties of queried domains. Analysts can calculate the Shannon entropy of domain strings to detect anomalous randomness and monitor query frequency for rapid bursts of failed resolutions (NXDOMAIN responses). This mathematical and behavioral analysis directly exposes the automated, algorithmic nature of DGA-based command-and-control (C2) communication.

Why this answer

DGA domains can be detected by analyzing DNS query patterns for algorithmic generation, often using frequency analysis or ML models.

49
Multi-Selecteasy

A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)

Select 3 answers
A.Phishing simulation click rates
B.Number of security incidents by category
C.Mean time to detect (MTTD)
D.Vulnerability scan details for individual hosts
E.Firewall rule change request logs
AnswersA, B, C

Phishing simulation click rates are a leading indicator of user resilience to social engineering attacks, directly measuring the effectiveness of security awareness training. A high click rate signals elevated human risk, while declining clicks over successive campaigns demonstrate improved workforce behavior. This metric is strategic because it quantifies a primary attack vector—email—and supports data-driven adjustments to training content and cadence.

Why this answer

Phishing simulation click rates (A) are appropriate because they express human-risk exposure as a simple percentage that executives can trend over time to judge the effectiveness of security awareness training. Number of security incidents by category (B) is right because it gives leadership a business-level view of what kinds of threats are materializing and where to direct risk-reduction investment. Mean time to detect (C) is right because it is a key operational KPI showing how quickly the security program identifies threats, which executives use to assess detection capability and response readiness.

The unmarked options do not belong: vulnerability scan details for individual hosts (D) are too granular and technical for an executive dashboard, and firewall rule change request logs (E) are operational change-management records rather than strategic risk metrics.

Exam trap

CS0-004 often tests audience-appropriate metrics — candidates pick detailed operational data (per-host vulns, firewall logs) because it is 'more security data,' but executives need aggregated, trend-based, business-relevant metrics.

50
Multi-Selectmedium

A vulnerability management team is prioritizing vulnerabilities for remediation. They have a list of vulnerabilities with different characteristics. According to best practices, which TWO factors should be considered when prioritizing vulnerabilities? (Select TWO.)

Select 2 answers
A.The CVSS base score
B.The asset's criticality to the business
C.The availability of a patch
D.Whether the vulnerability is listed in the CISA KEV catalog
E.The number of open ports on the asset
AnswersB, D

Asset criticality is the correct primary driver for prioritization because it directly captures the potential business impact if confidentiality, integrity, or availability is compromised. A vulnerability on a server that processes financial transactions or contains protected health information poses far greater risk than the same CVE on an internet-facing demo server with no sensitive data. This aligns with risk-based vulnerability management, where risk equals the likelihood of exploitation multiplied by the consequence to the business.

Why this answer

Option B is correct because an asset's criticality to the business determines the real-world impact of exploitation, so a high-severity vulnerability on a mission-critical server should be remediated before the same vulnerability on a low-value test machine. Option D is correct because the CISA Known Exploited Vulnerabilities (KEV) catalog identifies vulnerabilities that are actively exploited in the wild, which is a strong signal to prioritize them regardless of other factors. The CVSS base score (A) reflects intrinsic severity but not business context or exploitation activity, so it is only one input rather than a standalone prioritization factor.

Patch availability (C) affects remediation timing but does not by itself indicate risk priority, and the number of open ports (E) is an attack-surface indicator, not a standard vulnerability prioritization criterion.

Exam trap

The trap is treating CVSS base score as the sole prioritization metric; candidates who select it ignore that business criticality and active exploitation (KEV) are what convert technical severity into actual organizational risk.

51
Matchingmedium

Match each analysis technique to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Matches known patterns

Identifies deviations from baseline

Uses rules to detect suspicious behavior

Monitors actions over time

Applies mathematical models

Why these pairings

Behavioral analysis monitors entity behavior; signature-based uses known patterns; anomaly-based uses baselines; heuristic uses rules. Common confusions include swapping behavioral and anomaly definitions or misassigning signature analysis.

52
Multi-Selectmedium

During a security incident, a digital forensics investigator must preserve evidence according to best practices. Which three of the following actions align with proper forensic procedures? (Choose three.)

Select 3 answers
.Calculate and document cryptographic hashes of acquired images.
.Boot the suspect system to check for running processes.
.Maintain a documented chain of custody for all evidence.
.Use a write blocker when creating disk images.
.Store original evidence on the same network as the investigation.
.Reinstall the operating system before imaging to ensure stability.

Why this answer

Calculating and documenting cryptographic hashes (e.g., SHA-256) of acquired images ensures data integrity by providing a verifiable fingerprint that can prove the image has not been altered since acquisition. Maintaining a documented chain of custody tracks every person who handled the evidence, preserving its admissibility in legal proceedings. Using a write blocker when creating disk images prevents any accidental writes to the original media, which is critical to avoid altering the evidence.

Exam trap

CompTIA often tests the misconception that booting a system to check processes is acceptable, but in forensic procedures, any live interaction with the original evidence is prohibited to avoid altering the state.

53
MCQmedium

An organization uses automated patch management for workstations but manual patching for servers. After a critical vulnerability is announced, the security team wants to expedite patching for servers. Which of the following is the BEST approach?

A.Test the patch in a staging environment and then deploy
B.Disable the affected services until the patch can be applied
C.Deploy the patch immediately to all servers
D.Implement virtual patching via an IPS
AnswerA

Testing a patch in a staging environment is the most prudent and recommended practice before deploying it to production systems, especially with automated patch management. This process allows administrators to thoroughly evaluate the patch's compatibility with existing applications and configurations, identify potential regressions, and confirm its effectiveness in a controlled, non-production setting. This crucial step minimizes the risk of introducing new vulnerabilities, system instability, or service outages that could arise from an untested patch in a live environment.

Why this answer

Testing the patch in a staging environment before deploying to production servers validates compatibility and stability, reducing the risk of service disruption. This approach balances the urgency of a critical vulnerability with the need to maintain server availability, which is especially important given that manual patching is the standard procedure for servers. Staging allows the security team to identify any conflicts with existing configurations or dependencies before widespread deployment.

Exam trap

The trap here is that candidates may choose immediate deployment (Option C) due to the urgency of a critical vulnerability, overlooking the operational risk of untested patches in a manual patching environment, while CompTIA often tests the principle that security must be balanced with availability and change management processes.

How to eliminate wrong answers

Option B is wrong because disabling affected services may cause significant business disruption and does not address the underlying vulnerability; it is a temporary workaround that still leaves the system vulnerable if the service is re-enabled without patching. Option C is wrong because deploying the patch immediately to all servers without testing can lead to unforeseen compatibility issues, crashes, or service outages, which is particularly risky in a manual patching environment where automated rollback mechanisms may not be in place. Option D is wrong because implementing virtual patching via an IPS only provides a detection and blocking layer at the network level, but does not remediate the actual vulnerability on the server; it can be bypassed and adds latency, making it a compensating control rather than a definitive fix.

54
MCQmedium

After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?

A.Timeline
B.Lessons learned
C.Root cause
D.Impact assessment
AnswerA

The timeline is the chronological reconstruction of every observable event leading up to, during, and after the security incident. It consolidates artifacts like log entries, file system changes, network flows, and user actions into a coherent sequence. This component is foundational because it enables analysts to map the attack lifecycle and determine the exact order of compromise, which is essential for effective containment and eradication.

Why this answer

The Timeline section of an incident report presents a chronological sequence of events — detection, containment, eradication, recovery — with timestamps. It is specifically designed to reconstruct what happened and when, which is exactly what the question asks for.

Exam trap

CS0-004 often tests the confusion between Timeline (chronological sequence) and Root Cause (underlying cause) — candidates pick Root Cause because it sounds more analytical, but the question specifically asks for a chronological sequence.

How to eliminate wrong answers

Option B is wrong because Lessons Learned captures what went well, what didn't, and recommendations for improvement — it is forward-looking, not a chronological record. Option C is wrong because Root Cause identifies the underlying cause of the incident, not the sequence of events. Option D is wrong because Impact Assessment quantifies the scope, cost, and affected systems/users, not the timeline of events.

55
Multi-Selectmedium

A security analyst is performing a vulnerability assessment and needs to identify potential misconfigurations in a Kubernetes cluster. Which TWO of the following are common Kubernetes misconfigurations that should be checked? (Select TWO.)

Select 2 answers
A.Privileged containers
B.Using network policies
C.hostPath mounts
D.Running containers as non-root user
E.Using ConfigMaps for non-sensitive data
AnswersA, C

Privileged containers run with all Linux capabilities and disable isolation mechanisms such as seccomp, AppArmor, or SELinux, effectively granting the process root-equivalent access to the host kernel and devices. This means a malicious or compromised workload inside the container can directly attempt to escape the container and compromise the underlying node. Thus, enabling privileged mode is a critical misconfiguration that should be avoided in standard deployments.

Why this answer

Option A (Privileged containers) is correct because running a container with securityContext.privileged: true grants it nearly all capabilities of the host, effectively removing container isolation and allowing access to host devices and kernel features, which is a classic Kubernetes misconfiguration flagged by tools like kube-bench and CIS benchmarks. Option C (hostPath mounts) is correct because mounting a host directory or file into a pod (volumes.hostPath) exposes the node's filesystem to the container, enabling privilege escalation, persistence, or node compromise if an attacker gains code execution. Option B (Using network policies) is not a misconfiguration — network policies are a security best practice that restrict pod-to-pod traffic, and their absence would be the issue, not their use.

Option D (Running containers as non-root user) is not a misconfiguration — setting runAsNonRoot: true or a non-zero runAsUser is a hardening measure that reduces risk. Option E (Using ConfigMaps for non-sensitive data) is not a misconfiguration — ConfigMaps are the intended mechanism for non-confidential configuration data, whereas Secrets should be used for sensitive values.

Exam trap

CS0-004 often tests whether candidates can distinguish between secure configurations (network policies, non-root users, ConfigMaps for non-sensitive data) and actual misconfigurations (privileged containers, hostPath mounts), so candidates must know which options represent risks rather than best practices.

56
MCQmedium

During a vulnerability assessment, a security analyst discovers a web application that is vulnerable to SQL injection. The application is a legacy system that cannot be easily patched. The analyst recommends implementing a web application firewall (WAF) rule to block malicious SQL patterns. Which type of control does this represent?

A.Corrective control
B.Preventive control
C.Detective control
D.Compensating control
AnswerD

A compensating control is an alternative safeguard put in place to mitigate risk when a primary security control, such as applying a vendor patch, is technically or operationally unfeasible. By configuring the Web Application Firewall to block exploits targeting the specific vulnerability, the organization successfully reduces the associated risk to an acceptable level without modifying the underlying application code.

Why this answer

A compensating control is an alternative control that mitigates risk when the primary control (patch) cannot be applied.

57
MCQmedium

An organization is implementing configuration management and decides to use CIS Benchmarks to harden their servers. They choose Level 1 benchmarks for most servers but Level 2 for highly sensitive systems. What is the key difference between Level 1 and Level 2 CIS benchmarks?

A.Level 1 is more restrictive and secure than Level 2
B.Level 2 guidelines are more restrictive and may impact system functionality
C.Level 1 is for cloud systems, Level 2 for on-premises
D.Level 2 is only for DoD environments
AnswerB

Correct. Level 2 benchmarks apply defense-in-depth hardening intended for high-security environments and often disable features, ports, or services that could affect usability or compatibility, so CIS explicitly recommends testing Level 2 changes before production deployment due to potential functional impact.

Why this answer

CIS Level 1 benchmarks are basic security recommendations that can be implemented with minimal impact, while Level 2 includes more restrictive controls that may affect system functionality but provide higher security.

58
MCQmedium

A SOC analyst receives a file from an unknown source via email. The analyst wants to analyze the file without executing it to determine its functionality. Which type of analysis should be performed?

A.Behavioral analysis.
B.Memory analysis.
C.Dynamic analysis.
D.Static analysis.
AnswerD

Static analysis is the safest initial step for evaluating an unknown file because it allows the analyst to inspect the file's metadata, PE headers, import tables, and embedded strings without executing the code. By avoiding execution, the analyst eliminates the risk of system infection or triggering anti-analysis logic embedded within the malware.

Why this answer

Static analysis involves examining a file's code, structure, and metadata without executing it, making it the correct choice for determining functionality while avoiding execution risks. Techniques include inspecting strings, headers, and disassembled code to identify malicious indicators like embedded URLs or API calls.

Exam trap

CompTIA often tests the distinction between static and dynamic analysis by emphasizing the 'without executing' condition, leading candidates to confuse behavioral or dynamic analysis as valid options despite the explicit constraint.

How to eliminate wrong answers

Option A is wrong because behavioral analysis requires executing the file in a controlled environment to observe its actions, which contradicts the requirement to analyze without execution. Option B is wrong because memory analysis examines volatile memory (RAM) from a running system, not a file in isolation, and typically requires execution to capture artifacts. Option C is wrong because dynamic analysis involves running the file in a sandbox or debugger to observe runtime behavior, which directly violates the 'without executing it' constraint.

59
MCQeasy

Which metric is commonly used to measure the average time it takes to identify that a security incident has occurred?

A.MTTD (Mean Time to Detect)
B.MTTRem (Mean Time to Remediate)
C.MTTR (Mean Time to Respond)
D.Patch SLA Compliance %
AnswerA

Mean Time to Detect (MTTD) is the key security metric that quantifies the average duration between the initial occurrence of a security incident or compromise and its formal identification by security tools or analysts. Minimizing MTTD is critical for reducing attacker dwell time and limiting the potential blast radius of an intrusion.

Why this answer

Mean Time to Detect (MTTD) measures the average time between the start of an incident and its detection. It is a key metric for evaluating the effectiveness of monitoring and detection capabilities.

60
MCQhard

During a threat hunting exercise, an analyst uses osquery to query process events on endpoints. They discover a process named 'svchost.exe' running under a user account with parent process 'cmd.exe'. Which of the following describes this observation?

A.Normal behavior for Windows services
B.Evidence of a DLL injection attack
C.Potential LOLBin abuse with anomalous parent-child relationship
D.Indicative of a process hollowing attack
AnswerC

Attackers frequently leverage legitimate binaries like svchost.exe as Living off the Land Binaries (LOLBins) to evade detection and bypass application whitelisting. In a standard Windows environment, services.exe is the exclusive parent process of svchost.exe. Observing cmd.exe spawning svchost.exe represents an anomalous parent-child relationship that strongly indicates an adversary attempting to masquerade malicious execution under a trusted system process name.

Why this answer

svchost.exe should normally run under SYSTEM or NETWORK SERVICE with 'services.exe' as parent. A user-level svchost.exe with cmd.exe parent indicates a potential LOLBin misuse.

61
MCQmedium

A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is technical remediation owner, which content choice is most appropriate?

A.SLA compliance by severity, asset owner, and business unit
B.A list of all closed tickets with no dates
C.A vendor price comparison
D.A report sorted only by scanner plugin ID
AnswerA

SLA compliance by severity, asset owner, and business unit directly answers whether critical findings were remediated within policy timelines, and grouping by owner gives technical remediation owners the actionable view they need to address their own overdue items.

Why this answer

An SLA compliance report by severity, asset owner, and business unit directly maps to the goal of showing whether critical findings are fixed within policy timelines. This report filters by severity (e.g., critical), includes remediation deadlines (SLA), and groups by asset owner and business unit, enabling technical remediation owners to track overdue items and prioritize fixes. It aligns with the NIST SP 800-55 framework for measuring security effectiveness through compliance metrics.

Exam trap

The CS0-004 exam often tests the distinction between operational metrics (SLA compliance) and raw data (closed tickets) or irrelevant business data (vendor costs), trapping candidates who confuse 'showing compliance' with 'listing activity' or 'financial analysis'.

How to eliminate wrong answers

Option B is wrong because a list of all closed tickets with no dates provides no temporal context to determine if fixes were completed within policy timelines; without timestamps, SLA compliance cannot be measured. Option C is wrong because a vendor price comparison is irrelevant to vulnerability remediation timelines and technical remediation ownership; it addresses procurement, not security operations or SLA adherence.

62
MCQeasy

After a phishing simulation, the security team wants to report the results to management. Which metric is most appropriate to include in the report?

A.Total number of employees
B.Number of phishing emails blocked at the gateway
C.Mean time to detect phishing emails
D.Phishing simulation click rate
AnswerD

The click rate is the primary metric for assessing user susceptibility during a controlled simulation, calculated by dividing the number of users who clicked the link by the total number of emails delivered. This directly measures the effectiveness of security awareness training and identifies high-risk groups requiring targeted remediation.

Why this answer

Phishing simulation click rate measures the percentage of users who clicked a simulated phishing link, a key metric for security awareness.

63
Multi-Selecteasy

A security analyst is setting up a vulnerability management program and needs to select tools for container image scanning. Which THREE of the following are commonly used container image scanning tools? (Select THREE.)

Select 3 answers
A.Snyk
B.OpenVAS
C.Burp Suite
D.Clair
E.Trivy
AnswersA, D, E

Snyk scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines and registries. It is a widely adopted container image scanning tool, satisfying the selection criterion for this programme.

Why this answer

Snyk (A) is a widely used container image scanning tool that detects known vulnerabilities in OS packages and application dependencies within images, integrating into CI/CD pipelines. Clair (D) is an open-source static analysis tool from CoreOS/Quay that scans container image layers against vulnerability databases to report known CVEs. Trivy (E) is an Aqua Security open-source scanner that detects OS package and language-specific dependency vulnerabilities, misconfigurations, and secrets in container images.

OpenVAS (B) is a network vulnerability scanner for hosts and services, not a container image scanner, and Burp Suite (C) is a web application security testing proxy, so neither is designed for scanning container images.

Exam trap

The trap is picking a well-known security tool (OpenVAS, Burp) that scans networks or web apps rather than container images — candidates who don't distinguish scanner categories will select the wrong tool.

64
MCQmedium

A security analyst at a small company notices that several workstations in the finance department are communicating with an external IP address known to be associated with a command-and-control server. The analyst checks the host-based firewall logs and sees that outbound connections to that IP are allowed. Which of the following is the BEST immediate action to take?

A.Disconnect the workstations from the network.
B.Block the IP at the perimeter firewall.
C.Update the antivirus definitions.
D.Run a full antivirus scan on the affected workstations.
AnswerA

Isolating the hosts immediately severs the active command-and-control channel, halting data exfiltration or payload retrieval. Since the host-based firewall already permits that outbound traffic, containment must happen at the network layer; disconnecting the workstations is the fastest way to stop ongoing compromise before forensic investigation begins.

Why this answer

Disconnecting the workstations from the network immediately stops the active command-and-control communication and prevents further data exfiltration or lateral movement, which is the priority during a suspected active compromise. Containment precedes remediation, so isolating the hosts is the correct first action before blocking IPs, updating signatures, or scanning. This preserves the ability to perform forensics while halting the threat.

Exam trap

CS0-004 often tests the ordering of incident response steps, tricking candidates into choosing remediation actions (blocking, scanning, updating) before containment (isolating the host).

How to eliminate wrong answers

Option B is wrong because blocking the IP at the perimeter firewall is a network-level mitigation that does not stop the already-infected hosts from communicating via alternate C2 channels or IPs, and it may tip off the attacker; it is also not the immediate containment step. Option C is wrong because updating antivirus definitions is a remediation step that takes time and does not stop the active C2 session. Option D is wrong because running a full scan is a detection/remediation action that can take hours and does not contain the active threat; containment must come first.

65
Multi-Selectmedium

A security analyst needs to communicate the results of a vulnerability scan to different stakeholders. Which TWO of the following are appropriate reporting formats for executive-level stakeholders?

Select 2 answers
A.A one-page executive summary with risk ratings and business impact
B.A dashboard showing trend analysis and high-level metrics
C.A detailed remediation checklist for system administrators
D.A raw output from the vulnerability scanner
E.A technical report listing CVSS scores and exploit details
AnswersA, B

This document translates complex technical vulnerabilities into business risk and financial impact, which is essential for executive decision-making. By keeping it to a single page, it ensures that leadership can quickly grasp the organization's current risk posture and allocate resources effectively without getting bogged down in technical minutiae.

Why this answer

Executive-level stakeholders require high-level, business-focused information to make strategic decisions. A one-page executive summary with risk ratings and business impact (Option A) provides a concise overview of the most critical vulnerabilities, their potential effect on operations, and recommended actions without technical jargon. A dashboard showing trend analysis and high-level metrics (Option B) allows executives to quickly assess the organization's security posture over time, track remediation progress, and identify emerging risks through visual data.

Exam trap

CompTIA often tests the distinction between stakeholder-appropriate reporting formats, and the trap here is that candidates mistakenly choose technical options (like CVSS scores or raw scanner output) because they focus on the data's accuracy rather than the audience's need for actionable, non-technical summaries.

66
MCQhard

A CSIRT is following its incident response plan during a confirmed data breach. The team lead needs to ensure that all evidence collected is admissible in a future legal proceeding. Which of the following should the team lead implement FIRST?

A.Notify law enforcement and await their instructions before collecting any evidence.
B.Establish a chain of custody log for all evidence items.
C.Create a full forensic image of every affected system's hard drive.
D.Interview all employees who have access to the affected systems.
AnswerB

A chain of custody log documents every person who handled evidence, when, and why. It is the foundational requirement for evidence integrity and admissibility. Without it, even properly collected evidence can be challenged in court. The log should be started at the beginning of evidence collection and maintained throughout the incident. This is the first step to ensure legal defensibility.

Why this answer

A chain of custody log is the first legal safeguard because it documents the who, what, when, and why of evidence handling. Without it, any forensic image or log can be challenged as tampered or unauthenticated. Other actions like imaging or interviews are important but do not by themselves ensure admissibility.

The team lead should initiate the chain of custody before or during the first evidence collection.

Exam trap

The trap here is confusing the order of operations: collecting evidence without first establishing a chain of custody can render even technically perfect forensic images inadmissible.

67
MCQmedium

A company uses Qualys to scan their internal network. The scan report shows a vulnerability with plugin output indicating that the server is running a version of Apache httpd vulnerable to CVE-2023-1234. The asset is a development web server that is not exposed to the internet. The CVSS score is 7.5 (High). However, the EPSS score is 0.001 (very low). Which of the following should be the primary factor in prioritizing this vulnerability?

A.The CVSS score of 7.5 indicates high severity, so it should be remediated immediately.
B.The EPSS score of 0.001 indicates very low exploitability, so remediation can be delayed.
C.The asset is a development server not exposed to the internet, so remediation should be scheduled during normal maintenance.
D.The vulnerability is in Apache httpd, which is widely used, so it must be patched within 24 hours.
AnswerC

This option correctly synthesizes business context and risk-based vulnerability management. Because the asset is a non-production development server isolated from the internet, the actual risk of exploitation is significantly mitigated. Combining this low exposure with a low EPSS score justifies scheduling the patch during routine maintenance windows rather than disrupting operations with an emergency deployment.

Why this answer

Since the EPSS score is very low, the likelihood of exploitation in the wild is minimal. Additionally, the asset is not internet-facing, reducing exposure. The best approach is to consider the business context and asset criticality; development servers may be lower priority.

However, among the options, the EPSS score is a strong indicator of exploitability. But given the low EPSS, the vulnerability might be deprioritized. The question asks for primary factor; business context (asset criticality and exposure) is key.

But options include both EPSS and business context. The answer should be business context because the asset is internal and EPSS low, but business context might still prioritize if critical. However, in this scenario, the development server is likely not critical.

The most appropriate is to consider the business context including asset criticality and exposure.

68
MCQmedium

A UEBA rule flags a user authenticating from London and Singapore within 12 minutes, followed by a mailbox forwarding rule creation. What should the analyst investigate first? In the evidence source phase, Which evidence source best supports or refutes the detection?

A.Only the user's browser cache
B.Sign-in logs, MFA result, device details, and mailbox audit events
C.Only DHCP logs from the London office
D.The organisation's public DNS zone file
AnswerB

Sign-in logs, MFA results, device details and mailbox audit events directly evidence the impossible-travel alert and the subsequent forwarding rule creation, letting the analyst confirm or refute the UEBA detection across both authentication and post-compromise activity.

Why this answer

The detection of a user authenticating from geographically distant locations within 12 minutes strongly suggests credential theft or token replay, and the subsequent mailbox forwarding rule creation indicates a data exfiltration attempt. The analyst must first correlate sign-in logs (to verify the source IPs and timestamps), MFA results (to check if MFA was satisfied or bypassed), device details (to identify if a known or managed device was used), and mailbox audit events (to confirm who created the forwarding rule and when). This combination directly validates or refutes the UEBA alert by providing the evidence needed to distinguish between a legitimate user with a VPN or a compromised account.

Exam trap

The CS0-004 exam often tests the misconception that a single log source (like DHCP or browser cache) is sufficient to investigate impossible travel and mailbox rule changes, when in reality multiple correlated evidence sources (sign-in logs, MFA, device details, and audit events) are required to confirm or refute the alert.

How to eliminate wrong answers

Option A is wrong because browser cache only stores local web data (cookies, history, cached pages) and cannot provide authentication timestamps, IP geolocation, MFA status, or mailbox audit trails needed to investigate a cross-geography login and rule creation. Option C is wrong because DHCP logs from the London office only record IP address leases and cannot show authentication events, MFA results, device details, or mailbox changes; they are irrelevant to verifying the Singapore login or the forwarding rule creation.

69
Multi-Selectmedium

A security analyst is hunting for signs of lateral movement in the network. Which THREE indicators are most consistent with lateral movement techniques?

Select 3 answers
A.Unusual outbound DNS queries to known malicious domains
B.An RDP connection from a domain controller to a workstation
C.Creation of a new service on a remote system using sc.exe
D.Multiple failed logins from a single workstation to many servers
E.Execution of PsExec from a non-administrative workstation
AnswersB, C, E

In a secure architecture, administrative traffic flows from privileged workstations to domain controllers, never the reverse. An outbound Remote Desktop Protocol (RDP) connection originating from a domain controller to a standard workstation is highly anomalous and strongly indicates an adversary is leveraging compromised domain-level credentials to pivot downstream.

Why this answer

Lateral movement often involves remote execution tools (PsExec), remote service creation, and suspicious RDP connections.

70
Multi-Selecteasy

A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)

Select 2 answers
A.Open vulnerability counts by severity
B.Security incidents by category
C.Patch SLA compliance %
D.Mean time to detect (MTTD)
E.Phishing simulation click rates
AnswersA, C

Tracks the number of unresolved vulnerabilities broken down by CVSS severity level (e.g., critical, high, medium, low). This is a core patch-management metric because it directly reflects the current attack-surface exposure and backlog of unpatched systems, which compliance frameworks typically require to be monitored and reduced over time.

Why this answer

Option A (Open vulnerability counts by severity) is correct because it directly reflects the backlog of unpatched exposures, and breaking it down by severity (critical/high/medium/low) shows whether the most dangerous CVEs are being remediated promptly, which is a core evidence point for patch management effectiveness. Option C (Patch SLA compliance %) is correct because it measures the percentage of patches applied within the organization's defined remediation timeframes (e.g., critical within 7 days, high within 30 days), directly demonstrating the discipline and performance of the patch management process. Option B (Security incidents by category) is not specific to patching—it describes overall incident trends and could stem from phishing, misconfiguration, or insider activity rather than patch status.

Option D (Mean time to detect) measures detection capability (SOC/monitoring efficiency), not remediation of vulnerabilities. Option E (Phishing simulation click rates) is a security awareness metric and has no direct bearing on patch management.

Exam trap

CS0-004 often tests whether candidates can distinguish patch management metrics (open vulns, SLA compliance) from adjacent security metrics (MTTD, phishing click rate, incident categories) that sound security-related but measure different programs.

71
MCQmedium

A company is implementing a security monitoring solution for its cloud infrastructure. The security team wants to detect attempts to disable logging on critical instances. Which of the following should be configured?

A.VPC Flow Logs
B.CloudTrail (API logging)
C.Host-based intrusion detection (HIDS)
D.Scheduled vulnerability scans
AnswerB

CloudTrail is a critical service designed to record API calls made to the cloud provider's services, whether by users, roles, or other services. It provides a comprehensive audit trail of management plane activities, including creating, modifying, or deleting resources and configurations. This makes it ideal for detecting unauthorized changes to security monitoring solutions, such as disabling or altering logging configurations, as these actions are performed via API calls.

Why this answer

CloudTrail (API logging) is the correct choice because it records all API calls made to the cloud provider's control plane, including actions that modify logging configurations such as disabling or stopping logging on critical instances. By monitoring CloudTrail events, the security team can detect attempts to disable logging via API calls like `StopLogging` or `UpdateTrail`, enabling timely alerting and response.

Exam trap

The CS0-004 exam often tests the distinction between data plane monitoring (VPC Flow Logs) and control plane monitoring (CloudTrail), leading candidates to choose VPC Flow Logs because they think 'logging' refers to network logs rather than API activity logs.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at the data plane level, not control plane actions like disabling logging services. Option C is wrong because Host-based intrusion detection (HIDS) monitors system-level activities (file changes, processes) on individual instances, but cannot detect cloud API calls that disable logging at the infrastructure level. Option D is wrong because scheduled vulnerability scans assess known security weaknesses (e.g., missing patches) and do not provide real-time detection of logging configuration changes.

72
MCQmedium

During the detection and analysis phase of an incident, an analyst identifies a file with a hash that matches a known malware signature. The analyst wants to enrich this IOC with additional context. Which resource is BEST suited for this enrichment?

A.Shodan
B.WHOIS lookup
C.VirusTotal
D.Passive DNS
AnswerC

VirusTotal is an industry-standard threat intelligence platform that aggregates antivirus engines and website scanners to analyze submitted files, URLs, and cryptographic hashes. During incident detection, analysts query VirusTotal with a file's MD5, SHA-1, or SHA-256 hash to rapidly determine if known malware has been previously identified by the security community.

Why this answer

VirusTotal aggregates antivirus scan results and provides additional context such as file metadata, behavior, and community comments.

73
MCQmedium

A web application security tester uses Burp Suite to test an API endpoint. The tester sends a request with a modified HTTP method and discovers that the API accepts DELETE requests on an endpoint that should only allow GET. This is an example of which OWASP Top 10 vulnerability?

A.Injection
B.Security Misconfiguration
C.Server-Side Request Forgery (SSRF)
D.Broken Access Control
AnswerD

Broken access control is the correct answer because it directly describes a failure to enforce restrictions on what authenticated users are allowed to do. By manipulating parameters, headers, or API endpoints in Burp Suite, testers can identify flaws like Insecure Direct Object References (IDOR) or privilege escalation, which allow unauthorized data access.

Why this answer

Improper handling of HTTP methods can lead to broken access control, allowing unauthorized actions.

74
MCQmedium

A security operations center (SOC) analyst receives an alert about a potential ransomware infection on a critical server. The incident response team needs to contain the threat quickly. Which of the following should be performed FIRST as a short-term containment measure?

A.Disable the user account associated with the alert
B.Run a full antivirus scan on the server
C.Isolate the affected network segment
D.Rebuild the server from a clean backup
AnswerC

Isolating the affected network segment is the most effective short-term containment action to prevent the lateral movement of ransomware to other critical systems. By restricting network traffic at the switch, router, or firewall level, the analyst halts the spread of the infection while preserving the volatile memory of the affected server for subsequent forensic analysis.

Why this answer

Short-term containment focuses on immediate isolation to prevent further damage. Isolating the affected network segment stops the ransomware from spreading to other systems.

75
MCQmedium

After containing a malware outbreak, the incident response team performs static malware analysis on a suspicious executable. Which of the following artifacts would be most helpful in creating a YARA rule to detect variants of the malware?

A.The creation timestamp of the file
B.The file size of the executable
C.The packer used to obfuscate the executable
D.The import table showing API calls like WriteProcessMemory and CreateRemoteThread
AnswerD

Targeting specific Windows API functions within the Portable Executable (PE) import table, such as WriteProcessMemory and CreateRemoteThread, allows YARA rules to identify the underlying functional capabilities of the malware, such as process injection. Because these APIs are essential for the malware's injection mechanism, they serve as robust, behavior-based indicators that remain consistent across different compiled versions and packaging variations.

Why this answer

Import table analysis reveals API calls and DLLs used by the malware, which are often consistent across variants and useful for detection.

Page 1 of 10

Page 2

All pages