Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 226–300

701 questions total · 10pages · All types, answers revealed

Page 3

Page 4 of 10

Page 5
226
MCQmedium

A security analyst is configuring a container scanning tool to identify vulnerabilities in Docker images before deployment. Which of the following tools is specifically designed for container image vulnerability scanning?

A.Burp Suite
B.Nessus
C.Trivy
D.OpenVAS
AnswerC

Trivy scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines before deployment. This satisfies the requirement for a tool specifically designed for container image vulnerability scanning, unlike general-purpose scanners.

Why this answer

Trivy is an open-source vulnerability scanner from Aqua Security specifically designed to scan container images, filesystems, and IaC for vulnerabilities and misconfigurations. It integrates directly with Docker and CI/CD pipelines to detect CVEs in OS packages and application dependencies before deployment. This makes it the correct tool for pre-deployment container image scanning.

Exam trap

CS0-004 often tests the confusion between network vulnerability scanners (Nessus, OpenVAS) and container-specific scanners (Trivy, Clair, Anchore) — candidates pick Nessus because it is the most familiar vulnerability tool.

How to eliminate wrong answers

Option A is wrong because Burp Suite is a web application security testing tool for HTTP traffic, not container image scanning. Option B is wrong because Nessus is a general-purpose network vulnerability scanner that targets hosts and services, not container image layers. Option D is wrong because OpenVAS is an open-source network vulnerability scanner similar to Nessus, also not designed for container image analysis.

227
MCQmedium

During an incident, which of the following should be the FIRST priority when communicating with law enforcement?

A.Sharing the incident response plan
B.Requesting a warrant for internal investigation
C.Coordinating evidence collection and preservation
D.Providing a list of affected customers
AnswerC

Establishing a coordinated approach to evidence collection and preservation is the critical first step to ensure all digital forensics remain legally admissible. This collaboration prevents the organization from inadvertently altering or destroying volatile data, such as RAM or active network logs, which law enforcement needs to establish a proper chain of custody.

Why this answer

Law enforcement may need to preserve evidence for legal proceedings. Coordination ensures that evidence is handled properly and that the organization does not inadvertently destroy or compromise evidence.

228
MCQmedium

A vulnerability scan of an internal web server shows a critical vulnerability with a CVSS score of 9.8. The server is behind a WAF and is only accessible from internal IPs. Which of the following is the best next step?

A.Apply the patch immediately regardless of impact
B.Disable the server until a patch is available
C.Perform a risk assessment considering compensating controls
D.Ignore the finding because the server is internal
AnswerC

A CVSS base score reflects theoretical severity in a vacuum and does not account for environmental factors such as the WAF filtering malicious payloads and network ACLs restricting access to internal IPs; a documented risk assessment weighs these compensating controls against exploitability and business impact to set an appropriate remediation timeline.

Why this answer

CVSS score reflects severity but not exploitability in the specific environment. Considering compensating controls (WAF, network ACLs) may reduce risk, so a risk assessment is needed before patching.

229
MCQhard

During a post-incident review, the incident response team identifies that the mean time to detect (MTTD) for incidents is significantly higher than industry benchmarks. Which of the following improvements would most directly reduce MTTD?

A.Increasing the number of forensic analysts on call.
B.Conducting more frequent tabletop exercises.
C.Implementing automated alerting based on threat intelligence.
D.Rotating credentials after each incident.
AnswerC

Automated alerting driven by threat intelligence continuously matches live telemetry against known indicators of compromise and behavioral patterns in near real time, directly closing the gap between when malicious activity occurs and when it is surfaced to an analyst, which is precisely the mechanism that lowers mean time to detect.

Why this answer

Mean time to detect (MTTD) measures how quickly incidents are identified. Implementing automated alerting based on threat intelligence directly improves detection speed by continuously monitoring for known indicators of compromise and generating alerts in real time. This reduces the time between an incident occurring and the team becoming aware of it.

Exam trap

The trap is conflating detection with response; candidates may choose options that improve response (more analysts, tabletop exercises) but the question specifically asks for reducing MTTD, which requires faster detection mechanisms like automated threat intelligence alerting.

How to eliminate wrong answers

Option A is wrong because increasing forensic analysts improves response and investigation after detection, not the speed of detection itself. Option B is wrong because tabletop exercises improve preparedness and response processes but do not directly reduce the time to detect live incidents. Option D is wrong because rotating credentials after incidents is a containment/remediation step and does not affect detection speed.

230
MCQeasy

An organization has identified indicators of compromise (IOCs) from a recent incident. Which data format is specifically designed for sharing threat intelligence in a standardized, machine-readable way?

A.PDF
B.CSV
C.JSON
D.STIX
AnswerD

Structured Threat Information Expression (STIX) is an industry-standard language specifically designed to standardize the representation of cyber threat intelligence. It enables organizations to share structured threat data—including indicators, adversaries, and tactics—in a consistent, machine-readable format that security tools like SIEMs, SOAR platforms, and firewalls can automatically ingest and operationalize.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language and serialization format specifically designed by MITRE and OASIS to represent and share cyber threat intelligence in a machine-readable way. It defines domain objects like Indicator, Malware, ThreatActor, and Relationship, and is typically transported via TAXII. JSON, CSV, and PDF are generic data formats not purpose-built for threat intel semantics.

Exam trap

CS0-004 often tests whether candidates pick a generic serialization format like JSON instead of the domain-specific threat-intelligence standard STIX, so remember STIX is the schema and JSON is merely one possible encoding.

How to eliminate wrong answers

Option A is wrong because PDF is a human-readable document format with no machine-parseable schema for threat intel objects. Option B is wrong because CSV is a flat tabular format that cannot express the graph relationships (e.g., indicator-indicates-malware) central to threat intelligence. Option C is wrong because JSON is only a generic serialization syntax; while STIX can be serialized as JSON, JSON alone carries no threat-intel schema or vocabulary.

231
MCQmedium

During a post-incident review, the CSIRT identifies that the mean time to detect (MTTD) is significantly higher than the industry benchmark. Which initiative would MOST likely reduce MTTD?

A.Conducting more frequent tabletop exercises
B.Rotating credentials for all service accounts
C.Deploying additional endpoint detection and response (EDR) sensors
D.Implementing a new patch management process
AnswerC

Deploying additional EDR sensors directly addresses visibility gaps by expanding host-level monitoring across the enterprise. This allows the security team to collect real-time telemetry, analyze behavioral anomalies, and rapidly detect malicious activities, thereby significantly reducing the mean time to detect (MTTD) future incidents.

Why this answer

Improving detection capabilities through enhanced monitoring and alerting reduces detection time.

232
MCQmedium

A security analyst is investigating a potential data exfiltration incident. They notice a host sending large amounts of data to an external IP address using DNS queries. Which technique is most likely being used?

A.DNS tunneling
B.DGA
C.HTTP smuggling
D.Beaconing
AnswerA

DNS tunneling abuses the DNS protocol to bypass network security controls by encoding exfiltrated data or command-and-control (C2) payloads within DNS queries and responses (such as TXT, CNAME, or MX records). Because firewalls typically allow unrestricted outbound UDP port 53 traffic to resolve domain names, attackers can establish a covert bidirectional communication channel to slowly leak sensitive information without triggering traditional perimeter defenses.

Why this answer

DNS tunneling encodes data in DNS queries and responses, allowing exfiltration over port 53, which is often allowed through firewalls.

233
MCQmedium

An analyst is prioritizing vulnerabilities for remediation. The vulnerability has a high CVSS score but is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has a low EPSS score. The affected asset is a publicly accessible web server handling sensitive customer data. Which factor should the analyst consider as most critical for prioritization?

A.The absence from the KEV catalog
B.The business context of asset criticality and exposure
C.The low EPSS score
D.The high CVSS score alone
AnswerB

Effective vulnerability management requires aligning technical severity with business impact. Prioritizing remediation based on asset criticality ensures that high-value systems containing sensitive data or supporting mission-critical operations are patched first. Additionally, evaluating network exposure, such as whether an asset is internet-facing, helps security teams address the most immediate and viable attack vectors.

Why this answer

EPSS indicates likelihood of exploitation, but business context (asset criticality and exposure) can override low EPSS if the asset is high-value and exposed. Thus, the analyst should consider the business context.

234
Multi-Selecthard

During a threat hunt, an analyst identifies a suspicious process that is making outbound connections to multiple IP addresses on port 443 using TLS. The analyst suspects data exfiltration. Which THREE techniques would best help confirm this hypothesis?

Select 3 answers
A.Review EDR telemetry for file reads on sensitive documents prior to the connections
B.Inspect the TLS certificate presented by the remote server
C.Perform a memory dump of the process and look for encryption keys
D.Analyse NetFlow/IPFIX data for unusual data transfer volumes
E.Check the process' command line for suspicious parameters
AnswersA, D, E

Correlating EDR file-read telemetry with the timing of outbound TLS connections links sensitive document access to subsequent transmission. That temporal association distinguishes genuine staging and exfiltration from benign encrypted traffic, directly supporting the exfiltration hypothesis.

Why this answer

Option A is correct because correlating EDR file-read telemetry on sensitive documents with the timing of the outbound TLS connections establishes the data-collection stage of exfiltration, showing what data the process accessed before sending it. Option D is correct because NetFlow/IPFIX records byte and packet counts per flow, so unusually large outbound volumes to multiple destinations on port 443 reveal the data-transfer stage that distinguishes exfiltration from benign browsing. Option E is correct because the process command line often exposes exfiltration tooling and parameters such as destination lists, upload flags, or encoded payload arguments that explain the connections.

Option B does not belong because inspecting the remote TLS certificate only identifies the server or its issuer and does not confirm that data was stolen. Option C does not belong because dumping process memory to hunt for encryption keys is complex and unreliable, and finding keys would not by itself prove exfiltration occurred.

235
MCQhard

Refer to the exhibit. A security auditor finds this IAM policy attached to a user account. Which of the following describes the primary security concern?

A.The policy is missing a NotAction element
B.The policy allows read-only access
C.The policy uses a wildcard resource
D.The policy allows all S3 actions, which can lead to data exposure
AnswerD

By utilizing the s3:* wildcard action, the policy grants unrestricted administrative permissions across the entire Simple Storage Service. This allows unauthorized users or compromised roles to perform destructive operations like deleting entire buckets, modifying access control lists, or exfiltrating sensitive data, directly leading to severe data exposure.

Why this answer

The policy allows all S3 actions (s3:*) on all resources (Resource "*"), which means the user can read, write, delete, and modify any S3 bucket. This extreme level of access can lead to data exposure or deletion. The wildcard resource (option C) is part of the problem, but the combination of all actions is the core issue.

Options A and B are incorrect; a NotAction element is not relevant here, and read-only access would be less permissive.

236
MCQeasy

A third-party provider caused an outage during remediation. What should the communication to the vendor focus on? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?

A.Confidential unrelated customer data
B.Internal blame speculation
C.A public press statement draft first
D.Timeline, service impact, evidence, required corrective actions, and contractual follow-up
AnswerD

This comprehensive set of information provides the third-party provider with all necessary factual details to fully understand the incident, its ramifications, and the precise expectations for resolution and future prevention. A clear timeline establishes the sequence of events, service impact quantifies the damage, and concrete evidence supports the claims, ensuring a shared understanding. Specifying required corrective actions and contractual follow-up ensures accountability and aligns remediation efforts directly with service level agreements (SLAs) and legal obligations, facilitating a structured and effective response.

Why this answer

It provides a structured, factual communication that addresses the legal and privacy stakeholder's need for accountability, risk assessment, and contractual compliance. The timeline and evidence establish the sequence of events, service impact quantifies the breach of SLA, required corrective actions demonstrate remediation steps, and contractual follow-up triggers legal review of penalties or liabilities. This approach avoids speculation and focuses on verifiable data, which is critical for legal teams to assess regulatory obligations (e.g., GDPR breach notification timelines) and potential litigation.

Exam trap

CompTIA often tests the misconception that legal stakeholders need immediate public relations content or internal blame assignments, but the trap here is that legal teams require objective, evidence-based data to assess liability and regulatory compliance, not subjective or premature communications.

How to eliminate wrong answers

Option A is wrong because disclosing confidential unrelated customer data would violate data protection laws (e.g., GDPR Article 5) and is irrelevant to the vendor's outage; legal stakeholders need only data directly tied to the incident. Option B is wrong because internal blame speculation is subjective, unverifiable, and could create legal liability or prejudice; legal teams require objective facts, not finger-pointing. Option C is wrong because drafting a public press statement before internal legal review risks premature disclosure, misrepresentation, or admission of fault, which could harm regulatory defense or contractual negotiations.

237
Multi-Selecthard

Which THREE elements are essential components of a comprehensive post-incident report?

Select 3 answers
A.Root cause analysis
B.Timeline of events leading up to and during the incident
C.List of all employee usernames and passwords
D.Budget report for the incident response team
E.Lessons learned and recommendations for improvement
AnswersA, B, E

A comprehensive incident report must identify the fundamental vulnerability or failure vector that allowed the security incident to occur. Conducting a root cause analysis ensures that remediation efforts target the source of the compromise rather than just treating superficial symptoms, preventing future exploitation of the same vector.

Why this answer

Root cause analysis (RCA) is essential because it identifies the underlying technical failure—such as a misconfigured firewall rule, an unpatched CVE, or a phishing campaign—that allowed the incident to occur. Without RCA, the report would only describe symptoms, not the fundamental vulnerability that must be addressed to prevent recurrence.

Exam trap

CompTIA often tests the distinction between operational necessities (like budgets or credential lists) and the mandatory technical/analytical components of a post-incident report, trapping candidates who confuse administrative tasks with incident documentation requirements.

238
MCQeasy

An analyst needs to capture the contents of volatile memory from a Windows system suspected of being compromised. Which tool should the analyst use to acquire a memory image?

A.WinPmem
B.LiME
C.FTK Imager
D.dd
AnswerA

WinPmem is an open-source, dedicated physical memory acquisition tool designed specifically for Windows operating systems. It utilizes a kernel driver to safely bypass operating system restrictions and read raw physical memory (RAM), dumping it into standard formats like RAW or ELF for subsequent forensic analysis. This makes it the ideal choice for capturing volatile memory on a Windows host.

Why this answer

WinPmem is a memory acquisition tool for Windows systems, capable of capturing RAM contents for analysis.

239
MCQhard

An analyst runs a YARA rule against a set of files and gets a hit. The rule was written to detect a specific malware family. What is the PRIMARY purpose of using YARA rules in this context?

A.To sandbox the malware for dynamic analysis
B.To identify files that match known malware characteristics
C.To verify the hash of the malware sample
D.To extract strings from the malware
AnswerB

YARA rules define combinations of strings, byte sequences, and boolean logic that describe a malware family's known characteristics, and running a rule against a file set flags any files whose content matches those defined patterns, which is precisely why the analyst got a hit here.

Why this answer

YARA is a pattern-matching tool used to identify and classify malware samples based on textual or binary patterns.

240
MCQmedium

A threat hunter is creating a hypothesis based on recent threat intelligence about a new ransomware variant that uses scheduled tasks for persistence. Which of the following MITRE ATT&CK techniques should the hunter focus on?

A.T1547.001 - Registry Run Keys / Startup Folder
B.T1053.005 - Scheduled Task
C.T1071.001 - Web Protocols
D.T1059.001 - PowerShell
AnswerB

MITRE ATT&CK technique T1053.005 specifically represents the abuse of the Windows Task Scheduler to achieve persistence or elevate privileges. Threat actors leverage utilities like `schtasks.exe` or the Task Scheduler API to register malicious tasks that execute periodically or under specific trigger conditions, ensuring continuous access to the compromised host.

Why this answer

Scheduled tasks are a persistence technique (T1053.005) in the MITRE ATT&CK framework. The hunter should look for unusual scheduled tasks.

241
MCQeasy

A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request? For control selection, Which control best addresses the stated weakness without hiding risk?

A.A DNS MX record report
B.A software bill of materials
C.A building floor plan
D.A password complexity screenshot only
AnswerB

A software bill of materials enumerates every included library and its version, directly satisfying the requirement for visibility into third-party components within the regulated product. This transparency lets the security team identify vulnerable or outdated dependencies, supporting accurate risk assessment rather than concealing exposure behind vendor assurances.

Why this answer

A software bill of materials (SBOM) provides a formal, machine-readable inventory of all components, libraries, and versions used in a software product. This directly gives the security team the visibility needed for vulnerability management in a regulated environment, aligning with frameworks like NIST SP 800-53 and Executive Order 14028.

Exam trap

The CS0-004 exam often tests the distinction between operational artifacts (like DNS records) and software composition artifacts (like SBOMs), trapping candidates who confuse network visibility with application-level visibility.

How to eliminate wrong answers

Option A is wrong because a DNS MX record report only reveals mail exchange server configurations, not software libraries or versions. Option C is wrong because a building floor plan describes physical layout, not software composition. Option D is wrong because a password complexity screenshot only shows password policy settings, not the included libraries and their versions.

242
MCQmedium

An analyst uses Trivy to scan a container image in a CI/CD pipeline. The scan identifies a vulnerability in an open-source library included in the image. The library is not used by the application code. Which of the following actions should the analyst recommend?

A.Accept the risk because the library is not used
B.Add a web application firewall (WAF) to protect the container
C.Remove the unused library from the image
D.Patch the library to the latest version
AnswerC

Removing the unused library directly eliminates the vulnerability from the container image, adhering to the principle of least utility and minimizing the attack surface. This approach prevents potential exploitation, reduces the overall image size, and streamlines future vulnerability scanning processes. It represents the most secure and efficient remediation strategy for unused dependencies.

Why this answer

Unused components should be removed to reduce attack surface. Patching the library might be unnecessary if not used. Adding a WAF doesn't fix container image vulnerabilities.

Accepting risk may be justified but removal is better.

243
Multi-Selecthard

A vulnerability scan of a segmented OT network must avoid disrupting fragile devices. Which controls are appropriate? (Choose two.)

Select 2 answers
A.Use approved safe-check profiles or passive discovery where required
B.Scan from random external hosts
C.Run aggressive exploit checks without approval
D.Coordinate test windows and scope with OT owners
AnswersA, D

Using approved safe-check profiles ensures that vulnerability scans are configured with non-intrusive settings specifically designed for sensitive OT equipment, minimizing the risk of operational disruption. Passive discovery methods, such as network traffic analysis, further reduce impact by observing system behavior without direct interaction, which is crucial for maintaining the stability and safety of critical industrial control systems.

Why this answer

Safe-check profiles (e.g., Nessus 'safe checks' mode) disable active exploits and denial-of-service tests, while passive discovery (e.g., using NetFlow or SNMP traps) never sends packets to fragile OT devices. This prevents disruption to legacy PLCs, RTUs, or other industrial controllers that may crash under aggressive scanning.

Exam trap

The CS0-004 exam often tests the misconception that scanning from random external hosts improves stealth or coverage, but in OT segmentation, the priority is avoiding disruption—not hiding the scan source.

244
MCQeasy

Which of the following is the BEST method to prioritize vulnerabilities for remediation?

A.By asset criticality and exploitability
B.By availability of patch
C.By CVSS score
D.By number of affected hosts
AnswerA

Prioritising by asset criticality and exploitability directs remediation to vulnerabilities on business-critical systems that attackers can realistically exploit, satisfying the stem's demand for the best prioritisation method rather than ranking by raw CVSS score or scan order alone.

Why this answer

Prioritizing vulnerabilities by asset criticality and exploitability is the best method because it combines business impact with the likelihood of exploitation. Asset criticality ensures that vulnerabilities on high-value systems are addressed first, while exploitability (e.g., presence of a public exploit, active exploitation in the wild) indicates urgency. This risk-based approach is more effective than using a single metric like CVSS alone.

Exam trap

CS0-004 often tests the difference between CVSS (severity) and actual risk (likelihood + impact), leading candidates to choose CVSS score as the sole prioritization metric.

How to eliminate wrong answers

Option B is wrong because patch availability does not indicate risk; a patch may exist for a low-impact vulnerability while a critical one remains unpatched. Option C is wrong because CVSS score alone ignores the context of the asset and whether the vulnerability is actually exploitable in the environment. Option D is wrong because the number of affected hosts does not account for the importance of those hosts or the severity of the vulnerability.

245
MCQhard

An analyst is investigating a potential memory injection attack on a Windows system. Which of the following memory analysis artifacts is most indicative of code injection?

A.A process with a memory region that is both writable and executable (RWX)
B.A process that is running from a temp directory
C.A process that has an unusually high handle count
D.A process with multiple threads in a suspended state
AnswerA

Memory injection techniques, such as process hollowing or DLL injection, require allocating memory with write permissions to copy payload code, and then execute permissions to run it. Legitimate software rarely allocates memory regions with concurrent Read-Write-Execute (RWX) permissions due to security mitigations like Data Execution Prevention (DEP) or W^X (Write XOR Execute). Finding an RWX memory region strongly indicates that shellcode has been injected and is prepared for execution.

Why this answer

A process that is executing in a region of memory that is both writable and executable (RWX) is a strong indicator of injected code, as legitimate processes typically have separate write and execute permissions.

246
MCQeasy

Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?

A.Mean Time to Resolve (MTTR)
B.Patch SLA compliance percentage
C.Mean Time to Remediate (MTTRem)
D.Mean Time to Detect (MTTD)
AnswerD

Mean Time to Detect (MTTD) is the correct metric, as it measures the average elapsed time between the initial occurrence of a security incident—such as an intrusion or malware compromise—and the moment it is identified by monitoring tools or security personnel. Shorter MTTD directly reduces attacker dwell time and potential damage. This metric is specifically designed to gauge the speed and effectiveness of an organization's detection capabilities.

Why this answer

Mean Time to Detect (MTTD) is the average time to detect an incident.

247
Multi-Selectmedium

A security analyst is reviewing the output of a vulnerability scan and sees a finding for a web application that uses a known vulnerable version of Apache Struts. Which TWO of the following actions should the analyst prioritize?

Select 2 answers
A.Remove the Apache Struts component entirely
B.Reboot the web server to clear memory
C.Update Apache Struts to the latest patched version
D.Disable the web application until further notice
E.Implement a WAF rule to block known exploit patterns
AnswersC, E

Upgrading Apache Struts to the latest patched version is the primary remediation because it replaces the vulnerable code with a release that includes the security fix for the specific CVE. This action directly addresses the root cause of the flaw and eliminates the attack vector for known exploit patterns. Vendor patches are thoroughly tested and are the most reliable way to restore a secure state.

Why this answer

Option C is correct because upgrading Apache Struts to the latest patched version directly remediates the underlying vulnerability (e.g., the CVE affecting that specific Struts release) and eliminates the exploitable code path. Option E is correct because a WAF rule blocking known exploit patterns (such as OGNL injection payloads targeting Struts' Content-Type or action parameters) provides immediate compensating protection while the patch is scheduled and deployed. Option A is not appropriate as a priority action because removing the Struts component entirely would likely break the web application's functionality rather than remediate it.

Option B is irrelevant because rebooting the web server does not remove or patch the vulnerable Struts library and provides no security benefit. Option D is overly disruptive; taking the application offline is a last resort and not a prioritized remediation step when patching and WAF mitigation are available.

Exam trap

CS0-004 often tests remediation prioritization, tempting candidates toward drastic actions (remove, disable, reboot) instead of the balanced patch-plus-compensating-control approach.

248
MCQeasy

During a post-incident review, the security team needs to communicate findings to the IT operations team. Which communication method is MOST effective for this audience?

A.A presentation with graphs and trends
B.A detailed technical report including indicators of compromise and remediation procedures
C.An informal email with bullet points and no specific actions
D.A one-page executive summary with risk ratings
AnswerB

This comprehensive document delivers the exact technical artifacts, such as file hashes, malicious IP addresses, and registry modifications, alongside step-by-step recovery instructions. This level of detail allows the operations team to effectively purge threats, update firewall rules, and harden systems against future incursions.

Why this answer

The IT operations team needs actionable technical details to implement remediation and prevent recurrence. A detailed technical report with indicators of compromise (IoCs) and remediation procedures provides the precise commands, log entries, and configuration changes required for their work, making it the most effective method for this audience.

Exam trap

CompTIA often tests the distinction between audience-appropriate communication formats, and the trap here is that candidates may choose the executive summary (Option D) thinking it's concise, but fail to recognize that the IT operations team requires the full technical depth of a detailed report to perform their duties effectively.

How to eliminate wrong answers

Option A is wrong because a presentation with graphs and trends is more suitable for executive or management briefings, lacking the specific technical details (e.g., file hashes, IP addresses, registry keys) that the IT operations team needs to act. Option C is wrong because an informal email with bullet points and no specific actions omits critical remediation steps and IoCs, leaving the IT operations team without clear guidance on what to do. Option D is wrong because a one-page executive summary with risk ratings is designed for non-technical stakeholders, not for the IT operations team who require in-depth technical data to perform system changes.

249
MCQmedium

A security team is configuring a vulnerability scanner for external scanning of their public-facing web applications. Which scan type will provide the most accurate assessment of vulnerabilities without requiring credentials?

A.External scan
B.Agent-based scan
C.Authenticated scan
D.Internal scan
AnswerA

External scans are conducted from outside the organization's network perimeter, directly simulating the perspective of an external attacker targeting public-facing assets. This approach identifies exposed ports, misconfigured firewalls, and unpatched vulnerabilities in public web applications without requiring internal network access or system credentials.

Why this answer

An external scan assesses the attack surface from the internet perspective, typically without credentials. Agent-based and authenticated scans require credentials or internal access.

250
MCQmedium

A company uses Lynis for compliance scanning on Linux servers. During a scan, Lynis reports that the system has world-writable files in critical directories. Which CIS Benchmark recommendation does this finding relate to?

A.Ensure no world-writable files exist
B.Ensure system is configured to forward logs to a central server
C.Ensure permissions on /etc/shadow are configured
D.Ensure separate partition exists for /tmp
AnswerA

This finding maps directly to the CIS Benchmark recommendation that requires no world-writable files to exist in system directories, since files writable by any user create a path for unprivileged accounts or compromised processes to modify binaries, configuration files, or scripts that later run with elevated privileges.

Why this answer

CIS Benchmarks include recommendations to restrict file permissions, such as ensuring no world-writable files exist in system directories.

251
MCQmedium

A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is executive leadership, which content choice is most appropriate?

A.SLA compliance by severity, asset owner, and business unit
B.A list of all closed tickets with no dates
C.A vendor price comparison
D.A report sorted only by scanner plugin ID
AnswerA

SLA compliance by severity, asset owner and business unit shows whether critical findings were remediated within policy timelines, grouped by accountable owner and business area. This directly answers the executive audience's question about remediation performance against agreed targets.

Why this answer

It directly maps to the requirement of showing whether critical findings are fixed within policy timelines. SLA compliance by severity, asset owner, and business unit provides the necessary metrics to track remediation against defined service-level agreements, which is exactly what a vulnerability programme needs to demonstrate adherence to policy timelines. For executive leadership, this content choice is most appropriate as it offers a high-level, actionable view of compliance status across organizational units without technical noise.

Exam trap

The CS0-004 exam often tests the misconception that any list of closed tickets is sufficient for compliance reporting, but without date fields or SLA context, such a list is useless for proving policy adherence.

How to eliminate wrong answers

Option B is wrong because a list of all closed tickets with no dates provides no temporal context to assess whether fixes were completed within policy timelines; it fails to show SLA compliance or any measure of timeliness. Option C is wrong because a vendor price comparison is irrelevant to tracking vulnerability remediation timelines or SLA compliance; it addresses procurement concerns, not the operational effectiveness of a vulnerability management programme.

252
Multi-Selectmedium

A security analyst is reviewing logs from a network intrusion detection system (NIDS) and sees the following alert: "ET TROJAN Possible ZeuS/Poison Ivy Activity". The analyst wants to verify if the traffic is malicious. Which TWO of the following actions should the analyst take? (Select two.)

Select 2 answers
A.Disable the NIDS signature to prevent false positives.
B.Perform a packet capture of the session for further analysis.
C.Check the source IP against threat intelligence feeds.
D.Restart the NIDS service.
E.Correlate the alert with other logs (e.g., firewall, proxy).
AnswersC, E

Querying external threat intelligence feeds allows the analyst to quickly determine if the originating IP address has a known history of malicious activity, such as being part of a botnet or hosting malware. This external context helps validate the severity and likelihood of a true positive alert.

Why this answer

Checking the source IP against threat intelligence feeds (e.g., AlienVault OTX, VirusTotal, or commercial feeds) allows the analyst to determine if the IP is known for hosting ZeuS/Poison Ivy command-and-control (C2) infrastructure. This action directly validates whether the alert corresponds to a known malicious entity, reducing reliance on signature-based detection alone.

Exam trap

The CS0-004 exam often tests the distinction between reactive analysis (packet capture) and proactive verification (threat intelligence correlation), trapping candidates who think packet capture is the first step instead of a follow-up action.

253
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address. The username used does not exist in Active Directory. The analyst checks the source IP and finds it belongs to a known vulnerability scanner. What classification should the analyst assign to this alert?

A.False negative
B.True positive
C.True negative
D.False positive
AnswerD

A false positive occurs when benign or authorized activity, such as an approved internal vulnerability scan, triggers a security alert as if it were malicious. Analysts must tune SIEM rules to recognize these authorized sources to prevent alert fatigue from these non-threatening events.

Why this answer

A false positive is an alert that fires but does not represent a genuine security incident. Here, the 'failed login' is benign because the source is an authorized vulnerability scanner and the username does not exist — there is no real attacker or compromised account, so the SIEM rule matched on activity that is expected and non-malicious.

Exam trap

CS0-004 often tests the confusion between 'false positive' and 'true negative' — candidates forget that a false positive requires an alert to have actually fired on benign activity.

How to eliminate wrong answers

Option A is wrong because a false negative is a real incident that the SIEM failed to detect — the opposite of what occurred here (the alert did fire). Option B is wrong because a true positive means the alert correctly identified a real security event; a scanner probing a non-existent account is not an actual attack. Option C is wrong because a true negative is the correct absence of an alert — no alert was suppressed here; an alert was generated and then correctly dismissed.

254
MCQeasy

A SOC analyst receives an alert about a potential data exfiltration via DNS tunneling. Which of the following tools would best help the analyst investigate the alert?

A.Endpoint Detection and Response (EDR)
B.Antivirus logs
C.NetFlow
D.PCAP capture
AnswerD

A full Packet Capture (PCAP) provides a complete, byte-for-byte recording of all network traffic, including the entire headers and payloads of DNS queries and responses. This granular level of detail is crucial for detecting DNS tunneling, as it allows analysts to inspect the specific fields within DNS packets (e.g., query names, TXT records) for unusually long strings, non-standard characters, or encoded data that signifies covert communication. PCAP enables deep forensic analysis necessary to uncover such sophisticated exfiltration methods.

Why this answer

PCAP capture (D) is the correct tool because DNS tunneling involves encoding data within DNS queries and responses, which can only be fully analyzed by inspecting the raw packet payloads. PCAP files allow the analyst to examine the actual DNS packet contents, including query names, response records, and timing patterns, which are essential for detecting anomalous DNS traffic indicative of tunneling.

Exam trap

The CS0-004 exam often tests the distinction between metadata-only tools (NetFlow) and full-packet capture (PCAP), expecting candidates to recognize that only PCAP provides the granularity needed for protocol-specific abuse like DNS tunneling.

How to eliminate wrong answers

Option A is wrong because EDR focuses on endpoint-level events (processes, file changes, registry modifications) and cannot directly inspect network-level DNS packet payloads for tunneling patterns. Option B is wrong because antivirus logs primarily detect known malware signatures and file-based threats, not network protocol anomalies like DNS tunneling. Option C is wrong because NetFlow provides metadata (source/destination IPs, ports, byte counts) but lacks the packet-level detail needed to see the actual data being tunneled within DNS queries.

255
MCQeasy

Which type of threat intelligence report is MOST appropriate for a Chief Information Security Officer (CISO) to understand the overall threat landscape and make strategic decisions?

A.Strategic intelligence
B.Operational intelligence
C.Technical intelligence
D.Tactical intelligence
AnswerA

Strategic intelligence provides high-level, non-technical insights into long-term threat landscapes, emerging risk trends, and geopolitical motivations. It is tailored specifically for C-level executives and board members to guide long-term financial planning, risk management, and organizational security posture alignment.

Why this answer

Strategic intelligence provides high-level analysis of threats, trends, and risks that impact business decisions. It is designed for senior management and executives.

256
Multi-Selecthard

An application has a high CVSS vulnerability, but a WAF rule blocks known exploit payloads. What should the team still do? (Choose two.)

Select 2 answers
A.Validate the WAF rule against bypass and false-positive risk
B.Remove the application from vulnerability scans
C.Mark the vulnerability as permanently remediated
D.Track the vulnerability until the underlying flaw is fixed
AnswersA, D

While a Web Application Firewall (WAF) rule serves as an effective compensating control, it must be rigorously validated to ensure attackers cannot bypass it using encoding or alternative payloads. Additionally, testing prevents the rule from generating excessive false positives that could disrupt legitimate application traffic.

Why this answer

A WAF rule blocking known exploit payloads does not guarantee complete protection, as attackers can craft bypass techniques such as encoding, parameter pollution, or using different HTTP methods. Validating the rule against bypass and false-positive risks ensures the WAF is effective without disrupting legitimate traffic, which is critical for maintaining both security and availability.

Exam trap

The CS0-004 exam often tests the misconception that a compensating control like a WAF rule is equivalent to a permanent fix, leading candidates to incorrectly mark the vulnerability as remediated without addressing the root cause in the application code.

257
MCQmedium

A security analyst is preparing an after-action report for a phishing incident. Which component is MOST critical to include to prevent recurrence?

A.Timeline of the incident
B.Lessons learned and recommendations
C.Impact assessment
D.Root cause analysis
AnswerB

This section is the primary driver of continuous improvement in the incident response lifecycle. It translates the findings of the post-incident review into actionable security controls, policy updates, and architectural modifications designed to eliminate vulnerabilities and prevent similar security incidents from recurring.

Why this answer

An after-action report exists to drive improvement, so the component that directly prevents recurrence is the lessons learned and recommendations section, which translates findings into concrete process, tooling, or training changes. While timeline, impact, and root cause feed into it, only lessons learned and recommendations prescribe the corrective actions that stop the same phishing incident from succeeding again.

Exam trap

CS0-004 often tests the confusion between root cause analysis and lessons learned — candidates pick D because 'root cause' sounds like the deepest answer, but the question asks what prevents recurrence, which is the recommendation output, not the diagnostic input.

How to eliminate wrong answers

Option A is wrong because a timeline documents what happened chronologically but does not by itself change controls or user behavior to prevent recurrence. Option C is wrong because an impact assessment quantifies damage (financial, data, reputational) but is descriptive, not prescriptive, and does not stop a repeat incident. Option D is wrong because root cause analysis identifies why the incident occurred but stops short of the actionable remediation steps — it is an input to lessons learned, not the preventive output itself.

258
Multi-Selecthard

A vulnerability appears critical but the vulnerable feature is disabled. What should the analyst document before downgrading? (Choose two.)

Select 2 answers
A.Approval and rationale for the severity change
B.Deletion of the original scanner finding
C.The analyst's personal preference for fewer tickets
D.Evidence that the affected feature or code path is not reachable
AnswersA, D

When modifying the severity of a vulnerability, formal approval and a documented rationale are required to maintain compliance and governance. This ensures that any deviation from standard CVSS scores is justified by business context or compensating controls, preventing unauthorized or arbitrary risk acceptance.

Why this answer

When a vulnerability is critical but the vulnerable feature is disabled, the analyst must document the approval and rationale for the severity change to maintain an accurate risk register and audit trail. This ensures that the decision to downgrade is justified, traceable, and compliant with organizational change management policies, preventing arbitrary adjustments that could obscure true risk posture.

Exam trap

The CS0-004 exam often tests the misconception that deleting or ignoring a scanner finding is acceptable when a vulnerability is not exploitable, but the correct approach is to document the rationale and obtain approval for a severity downgrade while preserving the finding for audit and compliance purposes.

259
MCQhard

A post-incident report finds that no one owned a failed alert integration. What should the corrective action include? If the primary audience is SOC manager, which content choice is most appropriate?

A.No action because the incident is closed
B.Named owner, due date, acceptance criteria, and retest plan
C.A vague recommendation to improve security
D.Deletion of the integration record
AnswerB

Assigning a named owner ensures accountability for the corrective action, while a due date provides a timeline for completion. Clearly defined acceptance criteria establish what constitutes a successful resolution, making the outcome measurable and verifiable. Finally, a retest plan is crucial to validate that the implemented fix effectively addresses the original issue and does not introduce new vulnerabilities, thereby ensuring the long-term efficacy of the security improvement.

Why this answer

A failed alert integration represents a gap in detection capability that must be formally remediated. Assigning a named owner ensures accountability, a due date enforces timely resolution, acceptance criteria define what constitutes success, and a retest plan verifies that the fix works. Without these elements, the same failure could recur, leaving the SOC blind to future incidents.

Exam trap

The CS0-004 exam often tests the misconception that closing an incident means the problem is solved, when in fact post-incident corrective actions must address root causes with measurable, accountable steps to prevent recurrence.

How to eliminate wrong answers

Option A is wrong because closing the incident does not resolve the underlying technical failure; the integration will remain broken, creating a persistent blind spot in monitoring. Option C is wrong because a vague recommendation lacks the specificity needed to implement a fix—no owner, no deadline, and no measurable success criteria means the issue will likely be ignored or forgotten. Option D is wrong because deleting the integration record removes the alert channel entirely, which could violate compliance requirements (e.g., PCI DSS logging mandates) and eliminates any chance of restoring the integration.

260
MCQhard

During an audit, the compliance team needs to provide evidence that access reviews are performed regularly. Which of the following is the BEST evidence?

A.A list of user accounts with last login dates
B.A policy stating that access reviews should be done quarterly
C.Email reminders sent to managers to perform reviews
D.Signed and dated access review reports
AnswerD

Correct. Signed and dated reports establish accountability, a specific date of execution, and the reviewer's attestation that access was examined and adjudicated, which is the direct, verifiable artifact auditors require to confirm a control operated as designed.

Why this answer

Completed access review reports with timestamps and signatures provide clear evidence that reviews were conducted.

261
MCQhard

During a ransomware incident, the incident response team needs to preserve evidence before containment. Which of the following actions should be performed BEFORE isolating the infected system from the network?

A.Capture the contents of RAM.
B.Run an antivirus scan.
C.Disable the network interface.
D.Capture a forensic image of the hard drive.
AnswerA

Volatile memory contains critical, ephemeral evidence such as active network connections, running processes, decrypted ransomware keys, and unencrypted payloads. According to the Order of Volatility (RFC 3227), RAM must be captured first because any subsequent system interaction or shutdown will permanently destroy or alter this highly perishable data.

Why this answer

The order of volatility requires capturing volatile data like RAM before shutting down or isolating the system, as isolation may alter or lose memory contents.

262
MCQhard

A post-incident report finds that no one owned a failed alert integration. What should the corrective action include?

A.No action because the incident is closed
B.A vague recommendation to improve security
C.Deletion of the integration record
D.Named owner, due date, acceptance criteria, and retest plan
AnswerD

A named owner closes the accountability gap the report identified, while the due date enforces timely remediation. Acceptance criteria define what a successful alert integration looks like, and the retest plan verifies the fix actually works, preventing the same unowned failure recurring.

Why this answer

A post-incident finding of an unowned alert integration indicates a process gap that must be closed with a named owner, a due date, acceptance criteria, and a retest plan. This ensures accountability, a measurable fix, and verification that the integration is properly configured and monitored, preventing future failures.

Exam trap

The CS0-004 exam often tests the principle that corrective actions must be specific, measurable, and accountable, so the trap is choosing a vague or dismissive option (like 'no action' or 'vague recommendation') instead of the one that enforces ownership and verification.

How to eliminate wrong answers

Option A is wrong because closing the incident does not resolve the root cause; without corrective action, the failed integration will recur. Option B is wrong because a vague recommendation lacks the specificity needed to assign ownership, set a deadline, or define success criteria, making it unenforceable and unverifiable. Option C is wrong because deleting the integration record removes evidence of the failure and does not address the underlying lack of ownership or configuration issue.

263
MCQhard

During a post-incident review, the team finds that the detection was delayed by 4 hours because the SIEM rule had a low priority and was not monitored after hours. Which improvement is most effective?

A.Increase the priority of the rule
B.Add automated response actions to the rule
C.Include the rule in a watchlist
D.Implement 24/7 SOC operations
AnswerD

Ensures that alerts are monitored around the clock.

Why this answer

Implementing 24/7 SOC coverage directly addresses the root cause of the detection delay: the lack of after-hours monitoring. Increasing rule priority (A) does not ensure monitoring outside business hours. Adding automated response actions (B) may speed up response but does not solve the detection gap.

Including the rule in a watchlist (C) focuses visibility but still relies on human review, which is absent after hours.

Exam trap

Candidates may assume that increasing the priority of a rule or adding automation will solve delays, but the core issue is the lack of after-hours monitoring, which only 24/7 SOC coverage addresses.

264
MCQeasy

A security analyst detects unusual outbound traffic from a workstation. Which immediate action should the analyst take?

A.Run a full antivirus scan
B.Create a memory dump
C.Disconnect the network cable
D.Reimage the system
AnswerC

Physically disconnecting the network cable or disabling the network interface card (NIC) is the fastest way to achieve network isolation. This immediate containment action instantly severs the connection to external malicious servers, preventing further data exfiltration and stopping lateral movement within the enterprise network.

Why this answer

Disconnecting the network cable immediately isolates the workstation from the network, containing potential data exfiltration or lateral movement. This is the first step in incident response containment, as it stops the suspicious outbound traffic without destroying volatile evidence like running processes or network connections.

Exam trap

CompTIA often tests the distinction between containment, eradication, and recovery phases; the trap here is that candidates confuse immediate containment (disconnect) with forensic collection (memory dump) or remediation (reimage), leading them to choose a later-phase action instead of the first response step.

How to eliminate wrong answers

Option A is wrong because running a full antivirus scan takes time and may alert the attacker or trigger destructive actions before containment; it also does not stop ongoing outbound traffic. Option B is wrong because creating a memory dump is a forensic step that should occur after containment, not as an immediate action, and it does not halt the suspicious traffic. Option D is wrong because reimaging the system destroys all evidence and prevents forensic analysis of the incident; it is a recovery step, not an immediate containment action.

265
MCQeasy

Which vulnerability scanner is an open-source tool commonly used for network vulnerability scanning?

A.OpenVAS
B.Qualys
C.Nessus
D.Rapid7 InsightVM
AnswerA

OpenVAS, now maintained under the Greenbone Vulnerability Management project, is fully open-source and free to use, with a continuously updated feed of network vulnerability tests maintained by the community and Greenbone. It performs authenticated and unauthenticated network scans and is widely deployed by organizations that want scanning capability without commercial licensing costs.

Why this answer

OpenVAS is a well-known open-source vulnerability scanner.

266
MCQhard

During a threat hunt, an analyst uses osquery to query endpoints for processes that have spawned from Microsoft Word but have network connections. Which of the following TTPs does this technique most likely detect?

A.Pass-the-hash attack
B.Spearphishing attachment leading to macro execution
C.Kerberoasting
D.Data exfiltration over DNS
AnswerB

When a user opens a malicious spearphishing attachment, embedded VBA macros often execute and spawn child processes such as PowerShell, cmd.exe, or lolbins to download secondary payloads. Detecting Microsoft Word (winword.exe) spawning these command-line interpreters via osquery is a classic indicator of this initial access technique.

Why this answer

Attackers often use macro-enabled documents to execute code, making Word spawn abnormal child processes like PowerShell or cmd.exe, which then connect outbound.

267
Multi-Selectmedium

A security analyst is investigating a potential malware infection on a Windows workstation. The analyst needs to collect evidence while preserving the order of volatility. Which TWO pieces of data should the analyst collect FIRST? (Select TWO)

Select 2 answers
A.System event logs
B.Contents of the hard drive
C.Registry hives
D.Contents of RAM
E.Running processes and network connections
AnswersD, E

RAM is the most volatile data source because it holds running code, decrypted data, cached credentials, and the current state of the operating system. This information disappears the instant the system loses power or is rebooted, so capturing a memory dump is the highest-priority step. Without it, analysts lose the only copy of in-memory malware behavior and live artifacts.

Why this answer

Options D and E are correct because they represent the most volatile data on a Windows workstation, which must be captured before it is lost on shutdown, reboot, or continued system activity. Contents of RAM (D) hold live memory artifacts such as injected code, encryption keys, and uncommitted malware traces that vanish when power is removed, making it the highest-priority acquisition under the order of volatility. Running processes and network connections (E) are also highly volatile, since process tables, handles, and active TCP/UDP sessions change or disappear rapidly and reveal the malware's execution and command-and-control activity.

By contrast, system event logs (A) and registry hives (C) persist on disk and are less volatile, so they are collected after memory and live-state data, while the contents of the hard drive (B) are the least volatile and typically imaged last.

Exam trap

CS0-004 often tests the order of volatility by presenting disk-based artifacts (logs, registry, hard drive) as attractive options, when RAM and live process/network state must always be collected first.

268
MCQmedium

During a threat hunting exercise, a hunter creates a hypothesis that a threat actor is using PowerShell to download payloads from a remote server. Which ATT&CK technique is the hunter most likely investigating?

A.T1047 - Windows Management Instrumentation
B.T1105 - Ingress Tool Transfer
C.T1071.001 - Web Protocols
D.T1059.001 - PowerShell
AnswerB

This technique precisely describes the action of an adversary transferring tools, utilities, or malware payloads from an external system into the target environment. When a threat hunter focuses on detecting PowerShell-based file downloads, they are specifically hunting for evidence of this ingress activity to identify initial staging or tool installation.

Why this answer

T1105 (Ingress Tool Transfer) covers the adversary transferring tools or payloads into the victim environment from an external system, including via PowerShell downloads. The hypothesis — PowerShell downloading payloads from a remote server — maps directly to the transfer of a tool into the environment. T1059.001 describes PowerShell execution itself, but the specific behavior of pulling a payload in is T1105.

Exam trap

CS0-004 often tests the overlap between PowerShell execution (T1059.001) and the payload download behavior (T1105) — candidates pick the execution technique when the hypothesis is specifically about transferring a tool into the environment.

How to eliminate wrong answers

Option A (T1047) is wrong because WMI is a lateral movement/execution technique using Windows Management Instrumentation, not the transfer of a payload from a remote server. Option C (T1071.001) is wrong because Web Protocols (HTTP/HTTPS) is a command-and-control channel technique — it describes the C2 protocol, not the act of downloading a tool. Option D (T1059.001) is wrong because PowerShell is the execution vehicle; the question's hypothesis emphasizes downloading payloads, which is the ingress transfer behavior, not merely running PowerShell.

269
MCQhard

A security analyst is investigating a potential data breach and needs to collect evidence from a compromised Windows server. The server is still running, and the analyst wants to capture memory, network connections, and process list without writing unnecessary data to disk. Which of the following sequences of commands (tools) should the analyst use to adhere to order of volatility?

A.tasklist, netstat -an, then memory dump
B.memory dump, disk image, then network connections
C.memory dump, netstat -an, then tasklist
D.netstat -an, tasklist, then memory dump
AnswerC

This option correctly follows the order of volatility for evidence collection in a digital forensics investigation. A 'memory dump' captures the most volatile data, the contents of RAM, which can contain critical artifacts like running processes, open files, and network connections. Subsequently, 'netstat -an' captures active network connections, which are less volatile than RAM but more dynamic than a process list. Finally, 'tasklist' captures the running processes, which are the least volatile of these three dynamic data types, ensuring that the most ephemeral evidence is preserved first.

Why this answer

It follows the order of volatility (OOV) principle, which dictates that the most volatile data (memory) should be captured first, followed by network connections (netstat -an), and then the process list (tasklist). Memory is lost when the system is powered off, so it must be collected before any other evidence. Network connections and process lists are less volatile but still transient, and capturing them after memory ensures minimal data loss while avoiding unnecessary writes to disk that could overwrite evidence.

Exam trap

CompTIA often tests the misconception that network connections or process lists are more volatile than memory, leading candidates to choose options that capture them first, but memory is the most volatile because it is lost on power loss and contains critical runtime artifacts like decrypted data and active malware code.

How to eliminate wrong answers

Option A is wrong because it starts with tasklist and netstat -an before memory dump, violating the order of volatility by capturing less volatile data first while the most volatile evidence (memory) is left until last, risking loss if the system crashes or is shut down. Option B is wrong because it includes disk image, which is non-volatile and should be collected after volatile data; placing it before network connections and after memory dump ignores the OOV hierarchy and wastes time on persistent storage while transient data decays. Option D is wrong because it captures netstat -an and tasklist before memory dump, again violating OOV by prioritizing network and process data over the most critical volatile evidence (memory), which could be lost before it is collected.

270
MCQeasy

During a network traffic analysis, a security analyst notices a high volume of DNS queries to a domain that is algorithmically generated. The domain names follow a random pattern and are not resolved to known IP addresses. Which technique is most likely being used?

A.DNS tunneling
B.Beaconing
C.Domain generation algorithm (DGA)
D.HTTP smuggling
AnswerC

A Domain Generation Algorithm (DGA) is a technique used by malware to periodically generate a large number of pseudo-random domain names that can be used as rendezvous points for command-and-control (C2) servers. This allows attackers to evade static domain blocking and IP reputation lists, as the malware and the attacker only need to register a single domain from the generated list to establish a successful connection.

Why this answer

Domain Generation Algorithms (DGAs) are commonly used by malware to generate a large number of potential C2 domain names to evade static blocklists.

271
MCQeasy

A cybersecurity analyst is preparing a report for the executive leadership team. Which type of report is most appropriate for communicating high-level security posture and risk to non-technical stakeholders?

A.Threat intelligence feed
B.Technical vulnerability report
C.Executive dashboard
D.Incident response playbook
AnswerC

An executive dashboard aggregates complex security data into high-level key performance indicators (KPIs) and risk metrics, such as overall compliance posture and mean time to detect (MTTD). This visual format allows non-technical leadership to quickly grasp the organization's current security posture and make informed resource allocation decisions.

Why this answer

Executive dashboards provide a high-level overview of security posture, using metrics and visualizations that are easily understood by non-technical stakeholders. Technical reports are too detailed.

272
MCQhard

After containing a data breach, the incident response team discovers that an attacker exfiltrated sensitive data over DNS tunneling. Which of the following detection rules would BEST identify similar activity in the future?

A.An SIEM alert for any DNS query exceeding 100 bytes
B.A Snort rule blocking traffic to known malicious IPs
C.A firewall rule that blocks all DNS requests from internal servers
D.A YARA rule that flags DNS queries with high entropy domain names
AnswerD

DNS tunneling utilities typically encode stolen data or command-and-control instructions into the subdomain portion of a query, resulting in highly randomized, high-entropy character strings. Using a YARA rule or similar detection mechanism to analyze DNS logs for high-entropy domains allows security analysts to precisely identify anomalous, machine-generated queries indicative of exfiltration without disrupting legitimate network traffic.

Why this answer

DNS tunneling often involves unusual domain names with high entropy or long subdomains. A YARA rule targeting DNS query patterns can detect such anomalies.

273
MCQeasy

A cybersecurity analyst is preparing a vulnerability report for the IT manager. Which section should summarize the most critical risks for the organization?

A.Remediation timeline
B.Risk acceptance
C.Findings by severity
D.Executive summary
AnswerD

This section is designed specifically for leadership and non-technical stakeholders, distilling complex technical findings into a high-level overview of critical risks, business impacts, and strategic recommendations. It provides the necessary context for resource allocation and risk management decisions without overwhelming the reader with granular vulnerability data.

Why this answer

The executive summary provides a high-level overview of the most critical risks and recommended actions for management.

274
MCQmedium

A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is business service owner, which content choice is most appropriate?

A.SLA compliance by severity, asset owner, and business unit
B.A report sorted only by scanner plugin ID
C.A vendor price comparison
D.A list of all closed tickets with no dates
AnswerA

SLA compliance by severity, asset owner, and business unit provides the most comprehensive view for a vulnerability program. It directly measures the timeliness of critical vulnerability remediation against established service level agreements, broken down by the responsible parties and their organizational context. This granular reporting enables accountability, highlights areas of non-compliance, and effectively demonstrates whether critical risks are being addressed promptly, aligning security efforts with business objectives.

Why this answer

An SLA compliance report by severity, asset owner, and business unit directly maps to the requirement of showing whether critical findings are fixed within policy timelines. This report allows the vulnerability program to track remediation against defined service-level agreements (SLAs), and the breakdown by business unit and asset owner provides the business service owner with actionable, ownership-specific data to drive accountability and resource allocation.

Exam trap

The CS0-004 exam often tests the distinction between technical raw data (e.g., plugin ID sort) and business-oriented, decision-support reports (e.g., SLA compliance by business unit) to see if candidates understand that reporting must be tailored to the audience's role and responsibility.

How to eliminate wrong answers

Option B is wrong because a report sorted only by scanner plugin ID is purely technical and lacks any context of severity, asset ownership, or business unit; it cannot demonstrate compliance with policy timelines or provide the business service owner with the necessary business-level view. Option C is wrong because a vendor price comparison is unrelated to vulnerability remediation timelines or SLA compliance; it addresses procurement decisions, not operational reporting on finding remediation.

275
Multi-Selectmedium

A company uses a patch management tool to track compliance across its server fleet. The security team needs to prioritize vulnerabilities for patching. Which THREE factors should be considered when prioritizing?

Select 3 answers
A.EPSS probability score
B.Asset criticality and exposure
C.Availability of a patch from the vendor
D.CVSS base score
E.Number of plugins that detected the vulnerability
AnswersA, B, D

The EPSS probability score is a data-driven metric from FIRST that estimates the likelihood a vulnerability will be exploited in the wild within 30 days. It is derived from real-world exploit data, CVE attributes, and threat intelligence, making it a strong indicator of active exploitation risk. As a correct prioritization input, it helps security teams focus on vulnerabilities that are most likely to be attacked, rather than just those with high theoretical severity. This is a valid and important factor for risk-based prioritization.

Why this answer

Option A (EPSS probability score) is correct because the Exploit Prediction Scoring System estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, giving a forward-looking, threat-based signal that helps rank which CVEs to patch first. Option B (Asset criticality and exposure) is correct because the same vulnerability poses very different risk depending on whether the affected server is internet-facing, holds sensitive data, or supports a critical business function, so business context must weight the technical severity. Option D (CVSS base score) is correct because it provides a standardized, vendor-neutral measure of the intrinsic severity of a vulnerability (attack vector, complexity, privileges, impact), forming the baseline technical input for prioritization.

Option C (availability of a patch from the vendor) is not a prioritization factor per se — if no patch exists, the issue is handled through compensating controls or mitigation, and patch availability does not indicate how urgent or risky the vulnerability is. Option E (number of plugins that detected the vulnerability) is irrelevant because multiple scanners reporting the same CVE is a detection artifact, not a measure of exploit likelihood or business impact.

Exam trap

CS0-004 often tests the confusion between CVSS (severity) and EPSS (exploit likelihood), or mistakenly treating patch availability as a prioritization factor.

276
MCQmedium

You are a security analyst for a mid-sized financial services company. At 2:30 PM, the endpoint detection and response (EDR) console alerts on three workstations in the accounting department, indicating that files are being encrypted with a '.encrypt' extension and a ransom note named 'READ_ME_NOW.html' has been dropped. The workstations are connected to a file server that hosts shared financial records and a domain controller that handles authentication. The file server and domain controller have not shown signs of compromise yet. Your incident response plan states that containment must begin within 15 minutes of detection. Based on your analysis of the EDR telemetry, the encryption process appears to be spreading via SMB connections from the first infected workstation. Which of the following is the BEST immediate containment action to prevent further spread while preserving evidence?

A.Immediately isolate the three workstations by disconnecting their network cables at the patch panel or disabling their switch ports.
B.Shut down the file server and domain controller to protect critical systems from potential encryption.
C.Power off the three infected workstations immediately to contain the encryption process.
D.Apply the latest SMB vulnerability patch to the file server and domain controller to block the propagation vector.
AnswerA

This action is the most effective initial containment strategy. Disconnecting network cables or disabling switch ports immediately prevents further lateral movement of the ransomware to other systems, including critical servers, while keeping the infected workstations powered on. This preserves volatile memory and disk state, which is crucial for forensic analysis to identify the initial infection vector, malware characteristics, and potential exfiltration attempts before remediation.

Why this answer

Immediately isolating the three infected workstations at the network level (disconnecting cables or disabling switch ports) stops the SMB-based encryption propagation without destroying volatile forensic data. This containment action preserves the running processes, memory, and disk state for later analysis, which would be lost if the systems were powered off. The 15-minute containment window makes network isolation the fastest and most effective method to halt lateral movement while maintaining evidence integrity.

Exam trap

CompTIA often tests the distinction between containment (stopping the spread) and eradication (removing the threat), and the trap here is that candidates confuse immediate containment with remediation actions like patching or shutting down systems, which either take too long or destroy evidence.

How to eliminate wrong answers

Option B is wrong because shutting down the file server and domain controller would disrupt business operations for all users, not just the infected workstations, and would not stop the encryption already running on the three workstations; it also destroys volatile evidence on those critical servers. Option C is wrong because powering off the infected workstations destroys volatile evidence (memory, active network connections, running processes) that is crucial for forensic analysis and attribution, and it does not prevent the encryption process from having already spread via SMB if other systems are already compromised. Option D is wrong because applying a patch is a remediation step, not an immediate containment action; it takes time to download and install, and it does not stop the active encryption and propagation that is already occurring over SMB connections from the infected workstations.

277
MCQhard

A cloud security analyst is reviewing a misconfiguration in an AWS S3 bucket that allows public read access. The bucket contains sensitive customer data. Which of the following CIS AWS Foundations Benchmark checks would most likely identify this issue?

A.Enable default encryption for S3 buckets
B.Enable S3 bucket logging
C.Enable versioning on S3 buckets
D.Ensure S3 buckets do not allow public read access
AnswerD

This CIS control checks bucket ACLs and bucket policies for statements granting access to 'Everyone' or 'AuthenticatedUsers' groups, which is precisely the misconfiguration exposing sensitive customer data, making it the check that flags and drives remediation of the finding.

Why this answer

CIS AWS Foundations Benchmark includes a control for ensuring S3 buckets do not allow public read access. The control is typically '1.5 Ensure S3 bucket policy restricts public read access'. 'Enable S3 bucket logging' is about logging, not access. 'Enable default encryption' is about encryption. 'Enable versioning' is about data protection.

278
MCQmedium

A security analyst is configuring a vulnerability scan using OpenVAS. The scan should identify missing patches on Windows servers. Which of the following scan types should the analyst select?

A.Credentialed scan
B.Passive scan
C.Unauthenticated scan
D.Port scan
AnswerA

Credentialed scans utilize valid administrative or user credentials to authenticate directly to the target system. This allows the scanner to query the local registry, inspect the file system, and query package managers to verify the exact patch levels and configuration settings. Consequently, this approach provides the most accurate assessment with minimal false positives.

Why this answer

OpenVAS uses authenticated scans to check for missing patches. Unauthenticated scans only detect open ports and services. A credentialed scan with valid credentials allows checking patch levels.

279
MCQeasy

During which phase of the NIST SP 800-61 incident response lifecycle would an organization conduct a lessons learned meeting?

A.Containment, Eradication, and Recovery
B.Detection and Analysis
C.Post-Incident Activity
D.Preparation
AnswerC

NIST SP 800-61 explicitly places the lessons-learned meeting within Post-Incident Activity, where the team reviews the full incident timeline, evaluates response effectiveness, updates playbooks and detection rules, and produces a formal report once containment and recovery are complete.

Why this answer

The post-incident activity phase includes lessons learned, root cause analysis, and improvement actions.

280
Multi-Selectmedium

A security analyst is using OpenVAS to scan a network. The scan identifies several vulnerabilities. Which TWO of the following are valid components of a CVSS v3.1 base score? (Select the two correct answers.)

Select 2 answers
A.Exploitability (E)
B.Confidence (C)
C.Remediation Level (RL)
D.Scope (S)
E.Attack Vector (AV)
AnswersD, E

Scope (S) is a correct base metric in CVSS v3.1, measuring whether a vulnerability in one vulnerable component can impact resources beyond its security scope. A changed scope indicates that exploitation may affect other components, increasing the overall severity. OpenVAS includes Scope in the base vector, so it is a valid base metric.

Why this answer

Scope (S) is a valid CVSS v3.1 base metric that indicates whether a vulnerability can affect resources beyond the security scope of the vulnerable component, with values Unchanged (U) or Changed (C). Attack Vector (AV) is also a valid base metric describing the context in which the vulnerability is exploitable, with values Network (N), Adjacent (A), Local (L), or Physical (P). Both belong to the Base metric group, which also includes Attack Complexity (AC), Privileges Required (PR), User Interaction (UI), Confidentiality (C), Integrity (I), and Availability (A).

Exploitability (E), Confidence (C), and Remediation Level (RL) are not base metrics: E and RL are Temporal metrics in CVSS v3.1, and Confidence is a metric from the older CVSS v2 environmental scoring, not part of CVSS v3.1 base scoring.

Exam trap

CS0-004 often tests the boundary between CVSS metric groups — candidates confuse Temporal metrics like Exploitability and Remediation Level with Base metrics.

281
MCQhard

During a threat hunt, an analyst queries osquery to find processes where the 'cmdline' contains ' -e ' and the parent process is not 'explorer.exe'. This query is designed to detect which technique?

A.Malicious PowerShell execution
B.Lateral movement via PsExec
C.DLL injection via rundll32
D.Scheduled task creation
AnswerA

Threat actors frequently utilize PowerShell to execute obfuscated payloads, often passing Base64-encoded scripts via the `-e` or `-EncodedCommand` flags to bypass legacy security controls. An osquery search targeting these specific command-line arguments, especially when spawned by unusual parent processes like web servers or office applications, is a classic method for detecting active malicious PowerShell execution.

Why this answer

PowerShell with -e (encoded command) is often used for obfuscation; unusual parent processes suggest malicious execution.

282
MCQmedium

A security analyst is reviewing a Kubernetes cluster configuration. Which of the following misconfigurations poses the MOST severe security risk?

A.Using hostPath mounts with read-only access
B.Using ConfigMaps for non-sensitive data
C.Privileged containers with unrestricted host access
D.Running containers as non-root user
AnswerC

A privileged container runs with nearly all Linux capabilities enabled and direct access to host devices, meaning a compromised container can mount the host filesystem, load kernel modules, and effectively break out of container isolation entirely, giving an attacker root-equivalent control over the underlying node.

Why this answer

Privileged containers bypass all security restrictions and can access the host system, posing the most severe risk.

283
Multi-Selectmedium

A security analyst is preparing a vulnerability report for management. Which TWO elements should be included in the executive summary? (Select TWO.)

Select 2 answers
A.Raw CVSS scores for all vulnerabilities
B.Detailed technical description of each vulnerability
C.Network topology diagrams
D.Overall risk posture summary
E.Key findings that require management attention
AnswersD, E

An overall risk posture summary aggregates findings into a concise, qualitative rating—such as high/medium/low—or a weighted risk score that reflects the organization's relative exposure. This gives management a rapid understanding of whether immediate attention is required and how the current risk compares to prior assessments or industry benchmarks. It directly enables informed, risk-based decisions about prioritizing remediation efforts and allocating resources.

Why this answer

The executive summary is written for management, so it must translate technical findings into business-relevant information. Option D (Overall risk posture summary) is correct because it gives leadership a high-level view of the organization's aggregate exposure and whether risk is increasing or decreasing. Option E (Key findings that require management attention) is correct because it highlights the critical issues that need decisions, resources, or remediation prioritization from leadership.

Options A and B are incorrect because raw CVSS scores and detailed technical descriptions belong in the technical body of the report, not the executive summary. Option C is also incorrect because network topology diagrams are supporting technical artifacts, not executive-level summary content.

Exam trap

CS0-004 often tests whether candidates can distinguish between technical report content (raw CVSS, detailed descriptions, topology diagrams) and executive-level content (risk posture, key findings) appropriate for management.

284
MCQmedium

A security analyst needs to present a risk register to a non-technical board. Which of the following formats is most appropriate?

A.A timeline of past incidents
B.A heat map with risk ratings and business impact descriptions
C.A list of CVEs with CVSS scores
D.A detailed network diagram with vulnerability locations
AnswerB

A heat map converts likelihood and impact into colour-coded bands, letting a non-technical board grasp relative exposure at a glance without interpreting raw scores. Pairing each rating with a business impact description satisfies the stem's constraint: communicating risk to an audience lacking technical background, so prioritisation and funding decisions can be made quickly.

Why this answer

A heat map with risk ratings and business impact descriptions is most appropriate for a non-technical board because it visually communicates risk severity and business consequences without requiring technical expertise. It translates technical risks into business terms, facilitating informed decision-making.

Exam trap

CS0-004 often tests the ability to tailor communication to different audiences, and candidates may choose technical formats like CVE lists or network diagrams that are inappropriate for non-technical stakeholders.

How to eliminate wrong answers

Option A is wrong because a timeline of past incidents is historical and does not provide a forward-looking risk assessment. Option C is wrong because a list of CVEs with CVSS scores is highly technical and not easily understood by non-technical audiences. Option D is wrong because a detailed network diagram with vulnerability locations is too technical and focuses on technical details rather than business impact.

285
Multi-Selectmedium

Which three of the following are best practices for integrating vulnerability scanning into a continuous integration/continuous deployment (CI/CD) pipeline? (Choose three.)

Select 3 answers
.Scanning only the production environment after deployment to ensure real-world security
.Embedding static application security testing (SAST) into the build phase to catch code-level vulnerabilities early
.Using container image scanning tools to detect known vulnerabilities in base images before deployment
.Disabling all vulnerability scanning during development to accelerate build times
.Automating dynamic application security testing (DAST) in a staging environment that mirrors production
.Scanning dependencies only when a new vulnerability disclosure is published

Why this answer

Embedding SAST into the build phase is a best practice because it allows developers to identify and fix code-level vulnerabilities (e.g., SQL injection, buffer overflows) early in the development lifecycle, reducing remediation cost and preventing insecure code from progressing further down the pipeline. This shift-left approach aligns with DevSecOps principles by catching flaws before they reach integration or production environments.

Exam trap

CompTIA often tests the misconception that security scanning should be deferred to later stages (like production) to avoid slowing down development, but the correct approach is to integrate scanning early and often (shift-left) while using automated gates to maintain both speed and security.

286
MCQeasy

Which metric measures the average time it takes to identify a security incident from the moment it occurs?

A.MTTRem
B.MTTR
C.SLA compliance
D.MTTD
AnswerD

MTTD, Mean Time to Detect, is precisely the metric that measures the average elapsed time between when a security incident actually begins and when the security team becomes aware of it, making it the key indicator of detection capability and a primary driver of overall breach cost and dwell time.

Why this answer

MTTD (Mean Time to Detect) measures the average time to detect an incident.

287
Multi-Selectmedium

A security analyst is prioritizing vulnerabilities for a critical internet-facing application server. The analyst has CVSS scores, EPSS scores, and access to the CISA KEV catalog. Which TWO factors should the analyst consider as the most important for determining remediation priority? (Select TWO)

Select 2 answers
A.Asset criticality and business context
B.CVSS base score
C.Number of plugins detecting the vulnerability
D.EPSS score
E.CISA Known Exploited Vulnerabilities (KEV) catalog
AnswersA, E

Asset criticality and business context are central to vulnerability prioritization because they determine the potential impact on operations, data confidentiality, and compliance. A critical internet-facing server, for example, represents a higher risk to the organization if compromised, even when the vulnerability's severity is moderate. Contextual factors such as exposure, sensitive data, and required availability turn a generic technical finding into a prioritized business risk.

Why this answer

Option A (Asset criticality and business context) is correct because remediation priority must reflect the value and exposure of the affected system; a critical internet-facing application server supporting key business functions warrants higher priority than a low-value internal host, regardless of raw severity scores. Option E (CISA Known Exploited Vulnerabilities (KEV) catalog) is correct because KEV lists vulnerabilities known to be actively exploited in the wild, which is the strongest evidence of immediate real-world risk and should drive urgent remediation. CVSS base score (B) measures intrinsic technical severity but not exploit likelihood or business impact, so it is only one input and not the top priority factor.

EPSS score (D) estimates the probability of exploitation but does not capture asset importance or confirmed exploitation like KEV does. The number of plugins detecting the vulnerability (C) is a scanner artifact and has no bearing on actual risk or remediation priority.

Exam trap

CS0-004 often tests the misconception that CVSS base score alone is sufficient for prioritization, ignoring the need to incorporate asset criticality and active exploitation evidence like KEV.

288
MCQeasy

A security analyst is reviewing vulnerability scan results and notices that a critical vulnerability on a web server has a CVSS v3.1 base score of 9.8 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which component of the CVSS vector indicates that the vulnerability can be exploited from a remote network?

A.PR:N
B.AV:N
C.AC:L
D.UI:N
AnswerB

The Attack Vector (AV) metric represents the context in which vulnerability exploitation is possible. A value of AV:N (Network) explicitly indicates that the vulnerability is exploitable remotely over the network, meaning the attacker does not need local, physical, or adjacent network access to compromise the target.

Why this answer

AV stands for Attack Vector. AV:N means the vulnerability is exploitable over a network, indicating remote exploitation.

289
MCQhard

A security team is using EPSS scores and CISA KEV catalog to prioritize vulnerabilities. Which combination of factors would indicate the HIGHEST priority for remediation?

A.Medium CVSS score and high asset criticality
B.High EPSS score and presence in KEV catalog
C.High CVSS score and low EPSS score
D.Low CVSS score and presence in KEV catalog
AnswerB

This combination represents the highest remediation priority because the CISA KEV catalog confirms the vulnerability is currently being exploited in the wild, while a high EPSS score mathematically predicts a high probability of imminent exploitation. Leveraging both threat-centric metrics allows security analysts to transition from theoretical severity to active risk-based patching.

Why this answer

CISA KEV catalog contains vulnerabilities known to be exploited in the wild, and a high EPSS score indicates a high probability of exploitation. Together, they indicate the highest priority.

290
MCQhard

A security analyst is using Nessus to scan a network. The scan completes and reports a vulnerability with a CVSS v3.1 base score of 5.3 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability is a low-information disclosure issue that reveals the server's internal IP address in HTTP headers. The asset is a public-facing web server. Which of the following best describes the risk level and appropriate response?

A.Low risk; no action needed because internal IP disclosure is not a vulnerability.
B.Critical risk because the server is public-facing; immediate patching is required.
C.Medium risk; schedule a configuration change to remove the header during the next maintenance window.
D.High risk due to public exposure; apply an emergency patch to hide the header.
AnswerC

Disclosing internal IP addresses in HTTP headers is typically classified as a medium-risk vulnerability that facilitates external reconnaissance. Remediation involves modifying the web server configuration to prevent the disclosure, which is a non-emergency change that should be scheduled during a standard maintenance window to avoid service disruption.

Why this answer

The CVSS score is 5.3 (Medium) with low impact on confidentiality and no impact on integrity or availability. Although it is a public-facing server, the risk is low because the information disclosed is minimal (internal IP), which may already be known or easily guessable. The appropriate response is to schedule remediation during normal maintenance, not an emergency.

291
Multi-Selecthard

After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)

Select 3 answers
A.Place legal holds on relevant data
B.Delete all logs to prevent data leakage
C.Publish details on social media immediately
D.Coordinate with law enforcement
E.Notify affected customers as required by law
AnswersA, D, E

Placing a legal hold on relevant data is a legally binding directive that suspends all normal deletion, rotation, and destruction policies for potentially relevant information. In a ransomware incident, this preserves logs, endpoint artifacts, and backup copies, ensuring a complete forensic record for litigation or regulatory investigation. Without a legal hold, automated processes such as log rotation or archive purging could destroy evidence, leading to spoliation sanctions and undermining the ability to prove the scope of the breach.

Why this answer

Option A is correct because placing legal holds on relevant data preserves logs, backups, and affected systems as potential evidence for forensic investigation, regulatory inquiries, and possible litigation, preventing routine deletion or overwriting. Option D is correct because coordinating with law enforcement (e.g., FBI, Secret Service, or local cybercrime units) is a standard incident-response step that supports evidence handling, threat attribution, and may be legally required or beneficial for the organization. Option E is correct because notifying affected customers as required by law satisfies breach-notification obligations under regulations such as GDPR, HIPAA, or state data-breach statutes, which mandate timely disclosure when personal or protected data is compromised.

Option B is not appropriate because deleting logs destroys forensic evidence, violates legal-hold and retention requirements, and impedes incident investigation. Option C is not appropriate because publishing details on social media immediately can compromise the investigation, leak sensitive information, and should instead be handled through a coordinated, approved communications plan.

Exam trap

CS0-004 often tests the misconception that deleting logs or posting on social media is a valid containment or communication step, when both undermine legal and forensic obligations.

292
MCQmedium

A security analyst is reviewing the results of a vulnerability scan and notices that several vulnerabilities have high CVSS scores but low EPSS scores. The analyst also cross-references the CISA Known Exploited Vulnerabilities (KEV) catalog and finds that none of these vulnerabilities are listed. Which approach should the analyst take when prioritizing remediation?

A.Remediate vulnerabilities with high CVSS scores only if they are internet-facing.
B.Prioritize based on EPSS scores and KEV status, but also consider business context.
C.Remediate only vulnerabilities found in the KEV catalog.
D.Remediate all vulnerabilities with CVSS scores above 9.0 immediately.
AnswerB

Combining the Exploit Prediction Scoring System (EPSS) and CISA's Known Exploited Vulnerabilities (KEV) catalog allows analysts to focus on threats with active, real-world exploitation activity. Integrating business context ensures that remediation efforts are directed toward high-value assets that directly impact organizational operations. This risk-based approach optimizes resource allocation and significantly reduces actual organizational exposure compared to relying solely on static severity scores.

Why this answer

EPSS predicts the likelihood of exploitation, and KEV lists vulnerabilities known to be exploited in the wild. High CVSS but low EPSS and not in KEV suggests the vulnerability may be severe but unlikely to be exploited currently. However, business context such as asset criticality and exposure should be considered; if the asset is critical and exposed, remediation should still be prioritized despite low exploitation likelihood.

293
Multi-Selectmedium

A security analyst is prioritizing vulnerabilities discovered during a scan. Which TWO factors should the analyst consider as part of business context to determine remediation priority? (Select TWO.)

Select 2 answers
A.Asset exposure
B.CVSS base score
C.Patch availability
D.Exploit availability
E.Asset criticality
AnswersA, E

Exposure determines the likelihood of attack, considering whether the asset is internet-facing or reachable by potential adversaries. It directly influences the probability of exploitation, making it a fundamental factor in prioritizing vulnerabilities. Without exposure, even a critical vulnerability on an internal system poses less immediate risk. Therefore, asset exposure is the primary determinant for prioritizing remediation efforts.

Why this answer

Asset exposure (A) is a business-context factor because it describes whether the vulnerable asset is reachable from untrusted networks such as the internet, DMZ, or internal segments, directly affecting the likelihood of exploitation and thus remediation priority. Asset criticality (E) is also business context because it reflects the asset's role and value to the organization—such as processing regulated data, supporting revenue-generating services, or being a domain controller—which determines the business impact if compromised. In contrast, CVSS base score (B) is a technical severity metric derived from intrinsic vulnerability characteristics and does not by itself capture business context.

Patch availability (C) is a remediation logistics factor, and exploit availability (D) is a threat-intelligence factor; neither is a business-context input for prioritization.

Exam trap

CS0-004 often tests the distinction between technical severity metrics (CVSS, EPSS, exploit availability) and business-context factors (asset exposure, asset criticality) — candidates frequently pick CVSS because it 'sounds like' a prioritization input.

294
MCQeasy

Which metric measures the average time taken to fix a vulnerability after it is identified?

A.Mean time to remediate (MTTRem)
B.Mean time to detect (MTTD)
C.Mean time to respond (MTTR)
D.Patch SLA compliance %
AnswerA

Mean time to remediate is calculated as the average duration between when a vulnerability is identified and when it is actually fixed or closed, making it the direct metric for tracking remediation speed described in the question.

Why this answer

Mean time to remediate (MTTRem) is defined as the average elapsed time between when a vulnerability is identified and when it is fully remediated (patched, mitigated, or accepted with compensating controls). This matches the question's wording exactly — identification to fix.

Exam trap

CS0-004 often tests the MTTR vs MTTRem vs MTTD acronym collision — candidates pick C because MTTR is the more familiar term, but MTTR is response time, while MTTRem is specifically remediation time after identification.

How to eliminate wrong answers

Option B is wrong because MTTD measures the time from when a vulnerability or incident actually occurs (or is introduced) to when it is detected — it stops at detection, not remediation. Option C is wrong because MTTR (mean time to respond) measures time from detection to the start of response or containment, not to full remediation, and is more commonly used for incidents than vulnerabilities. Option D is wrong because patch SLA compliance % is a ratio of patches completed within a defined window, not an average time measurement, so it does not express 'average time taken to fix.'

295
Multi-Selecthard

A responder is acquiring evidence from a potentially compromised server. Which actions support forensic integrity? (Choose two.)

Select 2 answers
A.Calculate and record hashes of acquired images
B.Disable all logging before acquisition
C.Maintain chain-of-custody documentation
D.Edit suspicious files to see whether malware reacts
AnswersA, C

Calculating cryptographic hashes (such as SHA-256) of acquired forensic images immediately after acquisition establishes a baseline for integrity verification. This mathematical proof ensures that the evidence has not been altered during subsequent analysis, which is critical for admissibility in legal proceedings.

Why this answer

Calculating and recording hashes (e.g., SHA-256) of acquired disk images ensures data integrity by providing a cryptographic fingerprint that can be used later to verify that the evidence has not been altered. This is a foundational step in forensic acquisition, as any modification to the image will produce a different hash, proving tampering or corruption.

Exam trap

The CS0-004 exam often tests the misconception that disabling logging helps preserve the integrity of the acquisition process, when in fact it destroys potential evidence and violates forensic best practices.

296
MCQmedium

A security analyst is configuring a vulnerability scan for a demilitarized zone (DMZ) containing public-facing web servers. The analyst wants to minimize the risk of causing a denial-of-service condition on the servers. Which of the following scan settings should be configured?

A.Enable a full port scan.
B.Disable safe checks to speed up the scan.
C.Increase the scan timeout values.
D.Limit the number of concurrent checks.
AnswerD

Limiting the number of concurrent checks directly controls how many vulnerability tests or network connections the scanner initiates simultaneously against a target system or across the network. This crucial configuration reduces the immediate load placed on the target and the network infrastructure, preventing resource exhaustion. By pacing the scan, it significantly lowers the risk of inadvertently causing a denial-of-service condition or overwhelming critical services, thereby ensuring operational stability during the assessment.

Why this answer

Limiting the number of concurrent checks (option D) reduces the simultaneous requests sent to the target servers, which prevents overwhelming the web server's connection pool or CPU. This is the most direct way to minimize the risk of a denial-of-service condition during a vulnerability scan, especially in a DMZ with public-facing servers that may have limited resources.

Exam trap

CompTIA often tests the misconception that increasing timeout values or disabling safe checks will reduce the risk of denial-of-service, when in fact these settings either increase load or remove protections, making the scan more dangerous.

How to eliminate wrong answers

Option A is wrong because enabling a full port scan increases the number of probes sent to all 65,535 ports, which can overwhelm the server and cause a denial-of-service condition. Option B is wrong because disabling safe checks removes the scanner's built-in safeguards that prevent dangerous or intrusive tests, increasing the risk of crashing the server. Option C is wrong because increasing scan timeout values only extends the wait time for responses, which does not reduce the load on the server and may actually prolong the scan's impact.

297
Multi-Selecthard

A cloud workload identity begins accessing secrets outside its normal application scope. Which evidence should be reviewed? (Choose two.)

Select 2 answers
A.Cloud audit logs for secret-read operations
B.Legacy fax transmission logs
C.Recent role assignment or policy changes for the workload identity
D.The colour of the application logo
AnswersA, C

Cloud audit logs, specifically those tracking data plane operations like secret-read events, provide granular details on which secrets were accessed, by which identity, from what source IP, and at what timestamp. This direct evidence is crucial for identifying unauthorized secret access and understanding the scope of a potential compromise, directly addressing the scenario of a workload identity accessing secrets outside its expected scope.

Why this answer

Cloud audit logs record all API calls, including secret-read operations. If a workload identity is accessing secrets outside its normal scope, the audit logs will show the specific secret-read API calls (e.g., GetSecretValue in AWS Secrets Manager or accessSecretVersion in Google Cloud Secret Manager) made by that identity. Reviewing these logs directly confirms the anomalous access pattern and identifies which secrets were retrieved, providing the primary evidence of the breach.

Exam trap

The CS0-004 exam often tests the distinction between 'what happened' (audit logs) and 'why it could happen' (policy changes), and the trap here is that candidates may overlook the policy change evidence because they focus only on the direct access logs, missing the root cause of the permission misconfiguration.

298
Multi-Selecthard

A vulnerability dashboard for executives should avoid raw technical overload. Which views are useful? (Choose two.)

Select 2 answers
A.A list of scanner process IDs
B.Unfiltered plugin-output text
C.Critical exposure trend by business service
D.SLA compliance and overdue remediation by owner
AnswersC, D

Presenting critical exposure trends, specifically categorized by business service, offers executives a strategic and actionable view of the organization's evolving risk posture. This metric indicates whether the most severe risks are increasing or decreasing within specific operational areas, directly linking security posture to business impact. Such trends enable informed resource allocation and strategic decision-making to mitigate risks affecting critical business functions.

Why this answer

Executive dashboards must communicate risk in business terms, not technical raw data. A trend of critical exposures by business service translates vulnerability severity into operational impact, enabling prioritization of remediation resources without requiring technical expertise. This aligns with the Reporting and Communication domain's emphasis on tailoring information to the audience.

Exam trap

The CS0-004 exam often tests the distinction between raw technical data (useful for analysts) and summarized business-contextual views (useful for executives), trapping candidates who think any vulnerability data is appropriate for all audiences.

299
MCQmedium

A vulnerability report is presented to the IT manager. The report lists 15 critical, 40 high, 100 medium, and 200 low vulnerabilities. The IT manager asks which vulnerabilities should be prioritized for remediation. According to the vulnerability report structure, which section should the analyst reference?

A.Findings by severity
B.Executive summary
C.Remediation timeline
D.Risk acceptance
AnswerA

The findings-by-severity section breaks the full vulnerability list down into the critical, high, medium, and low buckets shown in the manager's report, giving the analyst the exact grouped detail needed to identify which of the 15 critical and 40 high items must be remediated first.

Why this answer

The 'Findings by severity' section groups vulnerabilities by their severity ratings (critical, high, medium, low), which directly answers the manager's question about prioritization. Since the report lists counts per severity, this section provides the structured breakdown needed to identify which vulnerabilities to address first. The other sections serve different purposes: executive summary gives a high-level overview, remediation timeline outlines when fixes should occur, and risk acceptance documents decisions to accept certain risks.

Exam trap

CS0-004 often tests the distinction between report sections, and candidates may confuse the executive summary (which provides a high-level overview) with the detailed severity breakdown needed for prioritization.

How to eliminate wrong answers

Option B is wrong because the executive summary provides a high-level overview for management, not the detailed severity breakdown needed for prioritization. Option C is wrong because the remediation timeline specifies deadlines for fixing vulnerabilities, not which ones to prioritize based on severity. Option D is wrong because risk acceptance is a formal decision to accept certain risks, not a section that lists vulnerabilities by severity for prioritization.

300
Matchingmedium

Match each security tool to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Network scanning and enumeration

Packet analysis

Exploitation framework

Web application security testing

Intrusion detection and prevention

Why these pairings

Nmap is for network scanning, Wireshark for protocol analysis, Metasploit for penetration testing, and Burp Suite for web application testing. Common confusions include misattributing these roles.

Page 3

Page 4 of 10

Page 5

All pages