Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 676–701

701 questions total · 10pages · All types, answers revealed

Page 9

Page 10 of 10

676
MCQmedium

The SOC receives an alert from a network sensor showing an internal host communicating with a known malicious IP over HTTPS. The analyst cannot find any process making outbound connections on the host. What should the analyst do next?

A.Capture a memory dump of the host
B.Block the IP at the firewall
C.Check for hidden processes or rootkits using specialized tools
D.Reimage the host immediately
AnswerC

A malicious outbound HTTPS connection with no visible owning process indicates the connection is hidden from standard process enumeration, typical of rootkit or kernel-level concealment. Specialised tools such as memory or kernel inspection utilities can reveal hidden processes that Task Manager or netstat alone would miss.

Why this answer

The absence of a visible process making outbound connections suggests the presence of a rootkit or hidden process that evades standard detection. Using specialized tools to check for hidden processes or rootkits is the appropriate next step to identify the malicious activity before taking containment or remediation actions.

677
Multi-Selectmedium

A SOC analyst is investigating an alert from Azure Sentinel indicating a user account logged in from an unfamiliar location. The analyst wants to determine if this is a true positive. Which TWO additional log sources should the analyst correlate to make an informed decision?

Select 2 answers
A.Azure Security Center alerts
B.Azure Network Watcher flow logs
C.Azure Activity Logs
D.Azure Key Vault logs
E.Azure AD sign-in logs
AnswersC, E

Correct. Activity Logs record subscription-level control-plane operations performed by the account after authentication, so correlating them reveals whether the session was used to create, modify, or delete resources, which is a strong indicator of malicious intent versus benign access.

Why this answer

Azure AD sign-in logs provide authentication details, and Azure Activity Logs provide management plane activity. Correlating these can reveal if the sign-in was part of administrative actions or other anomalies.

678
MCQmedium

During a patch management process, an organization uses a staging environment to test patches before deployment. Which of the following is the primary purpose of patch testing in a staging environment?

A.To create a backup of production systems
B.To speed up the patch deployment process
C.To validate that the patch addresses the vulnerability without causing regressions
D.To comply with licensing requirements
AnswerC

The primary objective of staging is to verify that the patch successfully remediates the targeted security vulnerability while ensuring it does not break existing functionality or cause system regressions. This validation phase allows administrators to observe system behavior, application dependencies, and performance metrics under realistic conditions before a full production rollout.

Why this answer

The primary purpose of patch testing in a staging environment is to validate that the patch actually remediates the vulnerability it targets while ensuring it does not introduce regressions or break existing functionality. Staging mirrors production closely enough to catch compatibility issues before the patch reaches live systems, which is the core of a controlled patch management process.

Exam trap

CS0-004 often tests whether candidates confuse the purpose of patch testing (validate fix + no regressions) with adjacent activities like backups, speed, or licensing, which are plausible but incorrect.

How to eliminate wrong answers

Option A is wrong because creating backups of production systems is a separate backup/disaster-recovery activity, not the purpose of patch testing in staging. Option B is wrong because staging actually slows down deployment by adding a validation step — the goal is safety and correctness, not speed. Option D is wrong because licensing compliance is unrelated to patch testing; licensing is handled through asset management and procurement, not staging validation.

679
Multi-Selectmedium

A security analyst is prioritizing vulnerabilities for remediation. Which THREE factors from the CISA Known Exploited Vulnerabilities (KEV) catalog should the analyst consider? (Select THREE.)

Select 3 answers
A.EPSS probability score
B.Date the vulnerability was added to the catalog
C.CVSS base score
D.Vulnerability name or CVE ID
E.Affected vendor or product
AnswersB, D, E

The KEV catalog includes a 'Date Added' field that records when a vulnerability was first identified as known exploited, allowing security teams to prioritize based on how recent and relevant the active exploitation is. This date is crucial because newer entries often warrant immediate attention, as attackers may be actively leveraging them. In contrast to CVSS or EPSS scores, this date is a distinct component of the KEV record itself, making it the right field when consulting the catalog for prioritization.

Why this answer

The CISA KEV catalog entry for each vulnerability includes the date it was added to the catalog (option B), which indicates how long the vulnerability has been known to be actively exploited and helps prioritize remediation urgency. It also lists the vulnerability name or CVE ID (option D), which uniquely identifies the specific flaw so the analyst can map it to affected systems and track remediation. The affected vendor or product (option E) is likewise a core KEV field, telling the analyst which technologies are at risk and whether they are present in the environment.

EPSS probability score (option A) is not part of the KEV catalog; it comes from the separate EPSS model maintained by FIRST. CVSS base score (option C) is also not a KEV catalog field; it is published by NVD or the vendor and is not included in KEV entries.

Exam trap

The trap is confusing KEV catalog fields with external metrics like EPSS and CVSS — candidates pick those because they are familiar, but they are not part of the KEV catalog itself.

680
MCQhard

During forensic analysis of a compromised server, an analyst needs to preserve evidence in order of volatility. Which of the following actions should the analyst perform FIRST?

A.Collect log files from the system
B.Create a forensic image of the hard drive
C.Run antivirus scan
D.Acquire a memory dump using WinPmem
AnswerD

Volatile memory (RAM) contains transient data such as active network connections, running processes, and unencrypted cryptographic keys that are lost upon system shutdown or reboot. Utilizing a dedicated tool like WinPmem allows analysts to capture a physical memory dump immediately after securing the system. This adheres strictly to the Order of Volatility, ensuring critical, short-lived evidence is preserved before any disk-based collection occurs.

Why this answer

The order of volatility dictates collecting the most perishable evidence first. RAM contents — running processes, network connections, encryption keys, and injected code — vanish on reboot or power loss, so acquiring a memory dump with a tool like WinPmem must be the first action. Only after memory is captured should the analyst move to less volatile sources.

Exam trap

The trap is prioritizing the disk image or logs because they feel like 'the evidence,' when the order of volatility demands the most ephemeral source — RAM — be captured first.

How to eliminate wrong answers

Option A is wrong because log files reside on disk and persist across reboots, making them less volatile than RAM; they should be collected after memory. Option B is wrong because a forensic disk image captures persistent storage, which is far less volatile than memory and can be acquired later without losing data. Option C is wrong because running an antivirus scan modifies the system (quarantining files, altering timestamps, consuming CPU) and can destroy volatile evidence — it is an investigative action, not an evidence-preservation step, and should never precede memory capture.

681
MCQmedium

An analyst wants to capture all traffic to and from a specific IP address for analysis. Which command-line tool is most appropriate?

A.nmap -sS 10.0.0.1
B.netstat -ant | grep 10.0.0.1
C.iptables -L -v
D.tcpdump host 10.0.0.1
AnswerD

Tcpdump is a powerful command-line packet analyzer that captures and displays network traffic. The `host 10.0.0.1` filter expression precisely instructs `tcpdump` to capture all packets where the source IP address is `10.0.0.1` or the destination IP address is `10.0.0.1`. This effectively captures all inbound and outbound network traffic associated with the specified host, fulfilling the requirement to capture all traffic to and from it.

Why this answer

`tcpdump host 10.0.0.1` captures all packets where the source or destination IP address matches 10.0.0.1, making it the ideal tool for capturing all traffic to and from a specific IP for analysis. It operates at the packet level, using libpcap to intercept raw network frames, and the `host` filter instructs it to match both directions of traffic without additional parsing or state tracking.

Exam trap

The trap here is that candidates confuse tools that probe or display state (nmap, netstat, iptables) with tools that capture raw traffic (tcpdump), leading them to select a tool that does not actually capture packets for analysis.

How to eliminate wrong answers

Option A is wrong because `nmap -sS 10.0.0.1` performs a SYN stealth scan against the target IP, which sends crafted packets to probe open ports, not capture existing traffic. Option B is wrong because `netstat -ant | grep 10.0.0.1` displays current network connections and listening ports from the system's socket table, but it does not capture live packets or traffic content; it only shows connection state at a single point in time. Option C is wrong because `iptables -L -v` lists the current firewall rules and their packet/byte counters, but it does not capture or log individual packets for analysis; it only shows aggregate statistics for rules.

682
MCQmedium

An organization has experienced a data breach involving personally identifiable information (PII). The incident response team has contained the breach and eradicated the threat. During the post-incident activity phase, which activity is MOST critical to prevent future similar incidents?

A.Resetting all user passwords
B.Updating the firewall rules to block the attacker's IP
C.Conducting a root cause analysis
D.Restoring data from backups
AnswerC

Performing a root cause analysis (RCA) is the definitive post-incident activity required to identify the underlying vulnerabilities and systemic failures that allowed the breach to succeed. By pinpointing the exact vector, security teams can implement permanent, strategic remediation controls to prevent similar incidents.

Why this answer

Conducting a root cause analysis helps identify the underlying vulnerability or weakness that led to the breach, enabling the organization to implement corrective measures and prevent recurrence.

683
Multi-Selecteasy

An analyst is configuring correlation rules in a SIEM. Which TWO data sources are essential for detecting lateral movement using pass-the-hash attacks?

Select 2 answers
A.Firewall logs
B.Authentication logs (e.g., Windows Event ID 4624)
C.DNS logs
D.Endpoint process creation logs (e.g., Event ID 4688)
E.Vulnerability scan results
AnswersB, D

Authentication logs, specifically Windows Event ID 4624, are central to detecting pass-the-hash because they record successful and failed logon events, including the logon type, authentication package (e.g., NTLM), source workstation, and target account. In a PtH attack, an attacker uses an NTLM hash as if it were a password; the logon event will typically show a network logon (Type 3) using NTLM, often from a non-domain host or in conjunction with suspicious source IP addresses. Correlating these 4624 events with known user activity patterns can reveal an attacker authenticating with a hash from an unauthorized source.

Why this answer

Authentication logs such as Windows Event ID 4624 are essential because they record logon events, including the logon type (e.g., Type 3 network logon) and authentication package (NTLM), which reveal the credential reuse characteristic of pass-the-hash lateral movement. Endpoint process creation logs such as Event ID 4688 are also essential because they capture the execution of tools and commands (e.g., cmd.exe, PsExec, net use) spawned after the attacker authenticates with the stolen hash, providing the behavioral evidence of movement on the target host. Firewall logs only show network connections and cannot confirm authentication or credential reuse, so they are insufficient on their own.

DNS logs may reveal resolution of internal hosts but do not show authentication or process execution tied to pass-the-hash. Vulnerability scan results identify missing patches or misconfigurations but do not record the runtime authentication and process activity needed to detect an active pass-the-hash attack.

Exam trap

CS0-004 often tests the misconception that network or vulnerability data detects credential-based lateral movement, when pass-the-hash is only visible through authentication and process creation telemetry correlated together.

684
Multi-Selectmedium

An incident response team is analyzing a suspected malware outbreak on a corporate network. Which three of the following actions should be performed as part of the containment phase? (Choose three.)

Select 3 answers
.Isolating affected systems from the network by disabling their network interfaces.
.Creating a forensic image of the infected systems for later analysis.
.Blocking outbound communication from infected hosts at the firewall.
.Identifying and patching the vulnerability exploited by the malware.
.Implementing network segmentation to prevent lateral movement.
.Notifying law enforcement agencies about the incident.

Why this answer

Isolating affected systems from the network by disabling their network interfaces is a core containment action because it immediately stops the malware from communicating with command-and-control (C2) servers or spreading to other hosts. Blocking outbound communication from infected hosts at the firewall prevents data exfiltration and further C2 activity without requiring physical access to each machine. Implementing network segmentation (e.g., VLANs or ACLs) restricts lateral movement by limiting the infected system's ability to reach other subnets, which is critical in containing a worm or ransomware outbreak.

Exam trap

CompTIA often tests the distinction between containment actions (immediate isolation) and eradication actions (patching, imaging), so candidates mistakenly select 'creating a forensic image' or 'patching the vulnerability' as containment steps when they actually belong to later phases of the incident response process.

685
MCQeasy

An organization performs quarterly vulnerability scans of its internal network. The scans have a high number of false positives for out-of-date software that is actually up to date. Which of the following would BEST improve the accuracy of the scans?

A.Disable verbose output to reduce clutter.
B.Implement credential-based scanning.
C.Increase scan frequency to monthly.
D.Use a different vulnerability scanner.
AnswerB

Implementing credential-based scanning significantly enhances accuracy by allowing the scanner to log into target systems and perform authenticated, local checks. This enables the tool to inspect actual patch levels, system configurations, installed software versions, and internal service states directly, rather than relying solely on network-level inferences. By gaining this internal visibility, the scanner can definitively confirm the presence or absence of vulnerabilities, drastically reducing both false positives and false negatives.

Why this answer

Credential-based scanning (authenticated scanning) allows the scanner to log into target systems with valid credentials, enabling it to query the local registry or package manager for the exact installed software versions. This eliminates reliance on banner grabbing or service fingerprinting, which often produce false positives when out-of-date software is detected based on network-level heuristics rather than actual installed patches.

Exam trap

The trap here is that candidates assume false positives are caused by scanner quality or frequency, rather than recognizing that unauthenticated scanning inherently lacks the visibility needed to confirm patch levels, making credential-based scanning the only direct solution.

How to eliminate wrong answers

Option A is wrong because disabling verbose output only reduces the amount of log data; it does not change the underlying detection method, so false positives from unauthenticated fingerprinting would persist. Option C is wrong because increasing scan frequency to monthly does not address the root cause of false positives; it merely repeats the same inaccurate detection more often, potentially increasing noise. Option D is wrong because simply using a different vulnerability scanner without enabling credential-based scanning would likely yield similar false positives, as most scanners rely on unauthenticated fingerprinting by default and require credentials to improve accuracy.

686
MCQeasy

An analyst receives a threat intelligence feed containing IOCs in STIX format. Which of the following BEST describes the purpose of STIX?

A.A protocol for real-time log collection
B.A framework for automating incident response
C.A standardized language for threat intelligence
D.A tool for malware analysis
AnswerC

Structured Threat Information Expression (STIX) is an XML/JSON-based serialization language that standardizes the representation of cyber threat intelligence. It allows organizations to share structured data about threat actors, campaigns, indicators, and tactics in a consistent, machine-readable format.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language and serialization format for representing cyber threat intelligence, including indicators, threat actors, campaigns, and relationships. It is designed to be machine-readable and interoperable, allowing organizations to share threat intelligence consistently. Therefore, the best description is that STIX is a standardized language for threat intelligence.

Exam trap

CS0-004 often tests the difference between STIX and TAXII, and candidates commonly confuse the content format (STIX) with the transport protocol (TAXII) or with incident response automation.

How to eliminate wrong answers

Option A is wrong because real-time log collection is handled by protocols like syslog, SNMP, or APIs, not STIX. Option B is wrong because automating incident response is the role of SOAR platforms and standards like CACAO, not STIX itself. Option D is wrong because malware analysis tools include sandboxes and reverse-engineering frameworks; STIX is a data format, not an analysis tool.

687
MCQmedium

A threat hunter is reviewing osquery data from endpoints and notices that the Windows Registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' contains an entry for 'C:\Users\Public\svchost.exe'. Which of the following best describes the significance of this finding?

A.Confirms a false positive because svchost.exe is always legitimate
B.Indicates a scheduled task has been created
C.Suggests persistence via a malicious binary masquerading as svchost.exe
D.Indicates a legitimate application installed for all users
AnswerC

This is correct because the registry Run key is a classic persistence mechanism used to ensure malware executes automatically when a user logs in. Furthermore, legitimate "svchost.exe" binaries must execute exclusively from the System32 directory; finding an executable with this name in a user-writable directory like the Public folder strongly indicates a masquerading technique.

Why this answer

The Run key is a common persistence location in the Windows Registry. The entry points to 'C:\Users\Public\svchost.exe', which is suspicious because legitimate svchost.exe resides in C:\Windows\System32 and is never in the Users\Public folder. This strongly suggests a malicious binary masquerading as a legitimate system process to maintain persistence and evade detection.

Exam trap

CS0-004 often tests the misconception that any file named svchost.exe is legitimate, but the path is the key indicator; candidates might overlook the non-standard location.

How to eliminate wrong answers

Option A is wrong because while svchost.exe is a legitimate Windows process, its presence in a non-standard path like C:\Users\Public is highly anomalous and indicates compromise, not a false positive. Option B is wrong because scheduled tasks are stored in the Task Scheduler library, not in the Run key; the Run key indicates autostart via registry. Option D is wrong because legitimate applications rarely install to C:\Users\Public and use the name svchost.exe, which is a system process; this is a classic malware tactic.

688
MCQhard

A large enterprise uses a vulnerability management platform that integrates with Active Directory and a configuration management database (CMDB). During a quarterly scan, a critical vulnerability (CVE-2021-44228) is detected on a legacy application server running an end-of-life (EOL) version of Java. The server supports a critical business process and cannot be upgraded or patched because the vendor no longer provides updates. The analyst must reduce the risk to an acceptable level. What is the best approach?

A.Remove the server from the network until it can be replaced
B.Apply a vendor-supplied hotfix to mitigate the vulnerability
C.Replace the server with a newer model that supports patching
D.Implement network segmentation and strict access controls to limit exposure
AnswerD

When direct patching is impossible due to EOL constraints, implementing compensating controls such as VLAN segmentation, firewall ACLs, and microsegmentation is the industry-standard approach. This restricts lateral movement, isolates the vulnerable system from untrusted zones, and minimizes the overall attack surface while preserving critical business operations.

Why this answer

Network segmentation combined with strict access controls limits the attack surface and potential impact, providing a practical risk reduction when patching is not possible. Removing the server would disrupt business, hotfixes are unavailable, and replacement is a long-term project.

689
MCQmedium

After a DDoS attack, the CSIRT wants to share IOCs with other organizations. Which protocol is specifically designed for automated, real-time threat intelligence sharing?

A.HTTP
B.SMTP
C.TAXII
D.FTP
AnswerC

Trusted Automated eXchange of Indicator Information (TAXII) is an application-layer protocol specifically designed to route cyber threat intelligence (CTI) over HTTPS. It supports common sharing models such as hub-and-spoke or peer-to-peer, allowing CSIRTs to automate the secure distribution and ingestion of STIX-formatted IoCs directly into security tools.

Why this answer

TAXII (Trusted Automated Exchange of Indicator Information) is the protocol for exchanging threat intelligence over HTTPS.

690
Multi-Selecthard

A regulator asks for incident evidence after a data exposure. Which items should be coordinated before disclosure? (Choose two.)

Select 2 answers
A.Evidence package with timeline, scope, and affected data categories
B.Unreviewed analyst speculation
C.Passwords for all production systems
D.Legal review of notification obligations
AnswersA, D

A comprehensive evidence package, detailing the incident's timeline, scope, and specific categories of affected data, is crucial for regulatory reporting. This structured approach ensures that all pertinent facts are presented clearly and accurately, supporting the organization's compliance efforts and demonstrating due diligence in incident response. Such a package provides verifiable information necessary for regulators to assess the incident's impact and the organization's handling of it.

Why this answer

A coordinated evidence package ensures that the disclosure to the regulator includes a verified timeline, scope, and affected data categories, which is essential for demonstrating due diligence and compliance with breach notification laws. Without this coordination, the evidence may be incomplete or inconsistent, potentially leading to regulatory penalties or loss of trust.

Exam trap

The CS0-004 exam often tests the distinction between raw, unverified data and coordinated, legally reviewed evidence, so candidates mistakenly choose 'unreviewed analyst speculation' thinking it provides timely insight, but it fails the admissibility and accuracy requirements for regulatory disclosure.

691
MCQeasy

A security analyst is reviewing a SIEM alert for a single failed login attempt from an internal IP address to a file server. The analyst determines this is a false positive. Which step should the analyst take next?

A.Escalate to a senior analyst
B.Disable the SIEM alert permanently
C.Tune the alert to suppress similar events
D.Create a correlation rule to link with other events
AnswerC

Tuning the alert is the industry-standard method for managing false positives because it refines the detection logic to exclude benign, repetitive behavior. By adding specific exclusions, such as a trusted IP address or a known service account, the analyst reduces noise and alert fatigue without compromising the SIEM's ability to identify actual threats.

Why this answer

After confirming a false positive, the analyst should tune the alert to reduce noise. This may involve adjusting thresholds or whitelisting the source.

692
Multi-Selecthard

A security analyst is conducting a proactive threat hunt for lateral movement techniques. The analyst examines EDR data for unusual parent-child process relationships. Which three process chains are indicative of lateral movement? (Select THREE.)

Select 3 answers
A.svchost.exe spawning schtasks.exe
B.explorer.exe spawning cmd.exe
C.services.exe spawning cmd.exe
D.wmiprvse.exe spawning cmd.exe
E.rundll32.exe spawning powershell.exe
AnswersA, C, D

svchost.exe normally hosts service DLLs and does not spawn schtasks.exe. This parent-child pairing indicates a service being abused to create a scheduled task, a common lateral movement and persistence technique for executing code on a remote host.

Why this answer

Option A is correct because svchost.exe normally hosts Windows services and should not directly spawn schtasks.exe; this parent-child chain indicates a service abusing the Task Scheduler to create or run a remote task for lateral movement. Option C is correct because services.exe is the Service Control Manager and spawning cmd.exe directly is anomalous, often reflecting a malicious service or PsExec-style remote service creation used to execute commands on a target host. Option D is correct because wmiprvse.exe is the WMI provider host, and a WMI provider spawning cmd.exe is a classic sign of remote WMI execution (for example, wmic /node: process call create) used for lateral movement.

Option B is not indicative by itself because explorer.exe spawning cmd.exe is a common, legitimate user action such as opening a command prompt. Option E is not a reliable lateral-movement indicator because rundll32.exe spawning powershell.exe, while suspicious in some contexts, is a generic execution chain that can occur from local scripts or malware and does not specifically demonstrate lateral movement.

Exam trap

CS0-004 often tests the ability to distinguish between benign and malicious process chains, and candidates may incorrectly select explorer.exe spawning cmd.exe (a common user action) or rundll32.exe spawning powershell.exe (more associated with execution than lateral movement) as indicators of lateral movement.

693
MCQhard

An analyst is reviewing a vulnerability scan report for a containerized application. The scan identifies a critical vulnerability in a base image used by multiple containers. The application is deployed in a Kubernetes cluster with network policies restricting ingress. The vulnerability has a CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). However, the EPSS score is 0.001 (0.1%). Which of the following should the analyst prioritize?

A.Apply a virtual patch via a web application firewall (WAF)
B.Ignore the vulnerability because it is in a container image
C.Schedule the patch for the next maintenance window because of low EPSS and network controls
D.Immediately patch the vulnerability within 24 hours due to the high CVSS score
AnswerC

An EPSS score of 0.1% indicates the vulnerability has near-negligible real-world exploitation likelihood in the next 30 days, and the Kubernetes NetworkPolicy restricting ingress further reduces the attack surface by limiting who can even reach the affected containers. Combining low predicted exploitation with existing compensating controls justifies routine remediation timing rather than emergency action, letting the team patch the base image and redeploy during the normal maintenance cycle.

Why this answer

Despite high CVSS, the EPSS score indicates extremely low likelihood of exploitation in the wild. The business context and compensating controls (network policies) reduce risk. Therefore, remediation can be scheduled in normal patch cycle.

694
MCQhard

A security team is scanning container images with Trivy and finds a vulnerability with CVSS v3.1 vector AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H. The vulnerability exists in a container running as a privileged container on a Kubernetes cluster. The team is prioritizing based on risk. Given the CVSS vector, which factor most significantly reduces the likelihood of exploitation in this context?

A.Attack Vector: Local
B.Privileges Required: High
C.Attack Complexity: High
D.User Interaction: None
AnswerA

An Attack Vector of Local (AV:L) significantly reduces the exploitability score because the attacker cannot exploit the vulnerability over the network. They must already possess local shell access, console access, or the ability to execute code locally on the container or host, creating a major barrier to entry compared to Network-based attacks.

Why this answer

AV:L (Local) means the attacker must have local access to exploit. AC:H (High) and PR:H (High) are also limiting, but the attack vector being local means remote exploitation is not possible, which is a strong limiting factor. However, the question asks 'most significantly reduces the likelihood'.

While local access is limiting, Attack Complexity High also reduces likelihood. But AV:L is more significant because it restricts the attack source. In the context of a container, local access might be more achievable, but still the vector shows it's not remotely exploitable.

The best answer is Attack Vector: Local.

695
MCQhard

A vulnerability report has 900 findings. One medium CVSS vulnerability is listed in CISA KEV and has high EPSS; several high CVSS issues are not exploitable in the environment. What should the analyst recommend? For business prioritization, Which recommendation gives the best risk-based order of work?

A.Always sort only by CVSS base score
B.Remediate alphabetically by CVE ID
C.Prioritize the KEV/high-EPSS issue after confirming asset exposure
D.Remediate only vulnerabilities with vendor logos in the report
AnswerC

Prioritising the KEV/high-EPSS finding reflects genuine exploitation risk rather than raw CVSS severity, since CISA KEV confirms active exploitation and high EPSS predicts imminent attacks. Confirming asset exposure first filters out non-reachable systems, satisfying the stem's requirement for a risk-based order that discounts the several high-CVSS but non-exploitable issues.

Why this answer

It combines threat intelligence (CISA KEV and high EPSS) with environmental context (asset exposure) to prioritize the vulnerability that is actively exploited and likely to be used in attacks, even though its CVSS base score is medium. This aligns with risk-based vulnerability management, which weights exploitability and business impact over raw severity scores.

Exam trap

The CS0-004 exam often tests the misconception that CVSS base score alone determines priority, but the trap here is that candidates ignore the KEV/EPSS context and choose to remediate high-CVSS issues first, failing to apply risk-based prioritization that accounts for real-world exploitability.

How to eliminate wrong answers

Option A is wrong because sorting only by CVSS base score ignores exploitability context (e.g., KEV, EPSS) and environmental mitigations, leading to wasted effort on high-CVSS but non-exploitable issues. Option B is wrong because remediating alphabetically by CVE ID has no relation to risk, exploitability, or business impact, and is a purely arbitrary ordering. Option D is wrong because vendor logos do not indicate exploitability or risk; a vulnerability with a vendor logo may still be non-exploitable in the environment, while a KEV-listed vulnerability without a logo poses real threat.

696
Multi-Selecthard

A cloud security posture tool reports public access on object storage. Which follow-up checks matter? (Choose two.)

Select 2 answers
A.Whether the storage account name is short
B.Whether sensitive objects were accessed or downloaded
C.Whether the administrator uses dark mode
D.Whether public access is effectively allowed by bucket and account policies
AnswersB, D

Once a Cloud Security Posture Management (CSPM) tool identifies potential public access, determining whether sensitive objects were actually accessed or downloaded is critical for incident response and impact assessment. This moves beyond a misconfiguration alert to evidence of potential data exfiltration or unauthorized access, directly informing the severity of the incident and necessary remediation steps. It helps quantify the actual damage and regulatory reporting requirements.

Why this answer

The primary concern with public access to object storage is data exposure. Checking whether sensitive objects were accessed or downloaded determines if a breach actually occurred, which is a critical follow-up step in vulnerability management. Without this check, you cannot assess the real-world impact of the misconfiguration.

Exam trap

The trap here is that candidates often focus on the misconfiguration itself (public access) rather than the necessary forensic step of verifying actual data exposure, leading them to pick irrelevant options like account name length or UI settings.

697
Multi-Selectmedium

Which three of the following are key considerations when implementing a vulnerability management lifecycle in an enterprise environment? (Choose three.)

Select 3 answers
.Establishing a remediation prioritization framework based on asset criticality and exploitability
.Scanning all assets with the highest possible scan intensity to ensure no vulnerability is missed
.Integrating threat intelligence feeds to contextualize vulnerabilities and focus on active threats
.Performing vulnerability scans only during off-peak hours to minimize network disruption
.Defining a formal remediation SLA that aligns with organizational risk tolerance
.Using default scan credentials from the vulnerability scanner vendor for consistency

Why this answer

Establishing a remediation prioritization framework based on asset criticality and exploitability is correct because it ensures that vulnerabilities posing the greatest risk to the business are addressed first. This aligns with risk-based vulnerability management, where not all vulnerabilities are equal; prioritizing by asset value and exploitability (e.g., CVSS exploitability metrics or active exploitation evidence) optimizes resource allocation and reduces overall risk exposure.

Exam trap

CompTIA often tests the distinction between operational best practices (like scanning intensity or timing) and strategic lifecycle components (like prioritization frameworks, threat intelligence integration, and SLA definitions), leading candidates to confuse tactical scanning habits with core lifecycle pillars.

698
MCQhard

During a forensic investigation of a compromised Linux server, the analyst needs to acquire memory for analysis. The system is running and the analyst cannot power it off. Which tool is MOST appropriate for acquiring memory in this scenario?

A.LiME
B.FTK Imager
C.WinPmem
D.dd
AnswerA

LiME (Linux Memory Extractor) is a kernel-mode tool specifically designed for volatile memory acquisition on Linux systems. It operates as a Kernel Loadable Module (LKM), allowing investigators to capture full RAM dumps with minimal footprint and high integrity, even bypassing restrictions that might block user-space memory access.

Why this answer

LiME (Linux Memory Extractor) is a tool designed for acquiring memory from Linux systems while they are running, and it can be loaded as a kernel module without shutting down.

699
MCQeasy

Which of the following is the correct order of volatility for digital evidence?

A.Swap, RAM, CPU registers, disk, logs
B.Disk, RAM, swap, CPU registers, logs
C.RAM, CPU registers, swap, disk, logs
D.CPU registers, RAM, swap, disk, logs
AnswerD

This sequence accurately represents the descending order of volatility according to RFC 3227 guidelines. CPU registers and cache are the most transient, followed by system RAM, then swap/paging files, local hard disks, and finally remote or archived logs. Following this order during an incident response ensures that the most fragile, short-lived digital evidence is preserved before it is overwritten by system processes or power loss.

Why this answer

The order of volatility: CPU registers and cache (most volatile), then RAM, then swap/page file, then disk, then network logs, then archived media (least volatile).

700
MCQeasy

Which tool would best allow a security analyst to capture and analyze packets in real time to investigate a network anomaly?

A.Metasploit
B.Wireshark
C.Nmap
D.Nikto
AnswerB

Wireshark is a premier open-source packet analyzer that intercepts and decodes network traffic in real time. It allows security analysts to capture raw frames from a network interface card in promiscuous mode, filter traffic using display filters, and perform deep packet inspection to troubleshoot anomalies or detect malicious payloads.

Why this answer

Wireshark is a network protocol analyzer that captures and inspects packets in real time, making it ideal for real-time traffic analysis.

701
MCQeasy

A security analyst is configuring a container image scanning tool to identify vulnerabilities in a Docker image before deployment. Which of the following tools is commonly used for container image scanning?

A.Metasploit
B.Nmap
C.Wireshark
D.Trivy
AnswerD

Trivy is an open-source vulnerability scanner specifically designed for containers and other cloud-native targets. It quickly scans container images, filesystems, and Git repositories to detect known vulnerabilities (CVEs), misconfigurations, and leaked secrets, making it ideal for integration into CI/CD pipelines.

Why this answer

Trivy is a popular open-source container image vulnerability scanner. It is widely used for scanning Docker images for known vulnerabilities.

Page 9

Page 10 of 10

All pages