Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 301–375

701 questions total · 10pages · All types, answers revealed

Page 4

Page 5 of 10

Page 6
301
MCQhard

A threat hunter analyzes NetFlow data and observes a host communicating with multiple external IP addresses on high-numbered ports (e.g., 49300-49500) during off-hours. The communications are short-lived and occur in burst patterns. The hunter suspects data exfiltration. Which of the following analysis techniques would best confirm or refute this suspicion?

A.Correlate with authentication logs to see if the user is logged in
B.Check the host's registry for persistence mechanisms
C.Perform a full packet capture on the host's traffic
D.Review DNS logs for domain generation algorithm patterns
AnswerC

Performing a full packet capture (PCAP) is the most effective action because it allows the analyst to conduct deep packet inspection on the suspicious traffic. By analyzing the actual payloads and protocol headers, the threat hunter can definitively determine if sensitive data is being exfiltrated or if the traffic is benign. This provides the granular visibility that high-level NetFlow metadata lacks, confirming the exact nature of the transmission.

Why this answer

A full packet capture provides the actual payload and protocol details of the suspicious traffic, allowing the hunter to confirm whether data is being exfiltrated (e.g., via HTTP POST, DNS tunneling, or custom protocols) and to identify the destination and content. NetFlow only provides metadata (IPs, ports, bytes, timestamps), so packet-level inspection is required to validate the exfiltration hypothesis. This is the most direct confirmatory technique.

Exam trap

CS0-004 often tests the distinction between flow metadata (NetFlow) and payload inspection (packet capture), so candidates must recognize that confirming exfiltration requires seeing the actual data, not just traffic patterns.

How to eliminate wrong answers

Option A is wrong because authentication logs only show whether a user is logged in; they do not reveal what data is being transmitted or to where, and attackers often use compromised service accounts or scheduled tasks. Option B is wrong because checking the registry for persistence identifies how an attacker maintains access, not whether data is being exfiltrated. Option D is wrong because DNS logs may reveal DGA patterns, but the observed traffic is on high-numbered ports to multiple external IPs, not necessarily DNS; reviewing DNS logs would not confirm the actual data transfer.

302
Multi-Selectmedium

A security analyst is configuring a vulnerability scanner for an internal network. Which two settings are most important for reducing false positives during the scan? (Choose two.)

Select 2 answers
A.Disabling unnecessary plug-ins
B.Enabling credentialed scanning
C.Using a higher scan intensity
D.Scanning from multiple IP addresses
E.Scanning only during business hours
AnswersA, B

Disabling unnecessary plug-ins prevents the scanner from running checks that are not relevant to the environment, such as Windows-specific tests against Linux hosts. Each plug-in produces findings, and if it probes for software or services that are absent, it can generate false positives based on erroneous banner matches. By tailoring the active plug-in set to the actual asset inventory and exposed services, the analyst reduces meaningless alerts and focuses the scan on likely vulnerabilities. This is a core tuning step that directly reduces false positives while preserving comprehensive coverage.

Why this answer

Option A is correct because disabling unnecessary plug-ins prevents the scanner from running checks that do not apply to the target hosts, such as Windows-specific or web-application tests against systems that do not use those technologies, which otherwise produce misleading findings. Option B is correct because credentialed scanning lets the scanner authenticate to hosts and read local configuration, patch levels, and installed software directly, so it can confirm whether a vulnerability actually exists instead of inferring it from ambiguous banner or version data, which is the single most effective way to cut false positives. Option C is wrong because raising scan intensity only makes the scan more aggressive and can increase false positives and network disruption rather than reduce them.

Option D is wrong because scanning from multiple source IP addresses does not improve accuracy and may complicate firewall or IDS behavior. Option E is wrong because restricting the scan window to business hours affects availability and timing, not the accuracy of the results.

Exam trap

CS0-004 often tests the difference between scan accuracy (credentialed scanning, plug-in tuning) and scan logistics (intensity, scheduling, source IPs), tempting candidates to pick operational settings that do not address false positives.

303
Multi-Selecteasy

A security analyst is performing a vulnerability scan on an internal network. The analyst wants to ensure the scanner can identify vulnerabilities in applications that require authentication. Which TWO scan configurations should be used?

Select 2 answers
A.Scan with default credentials
B.Non-credentialed scan
C.Agent-based scan
D.External scan
E.Credentialed scan
AnswersC, E

Agent-based scans utilize a lightweight software package installed directly on the target endpoint to perform local, authenticated assessments. This method eliminates the need to manage network credentials or open inbound ports, allowing the agent to execute with local system privileges. It is highly effective for transient assets, such as remote laptops, which may not be consistently connected to the corporate network during scheduled network scans.

Why this answer

Credentialed scans allow the scanner to authenticate to systems and perform deeper checks, while authenticated scans (agent-based) can also provide access.

304
MCQmedium

A security analyst detects ransomware on a critical server. Which containment strategy should be implemented FIRST to minimize damage?

A.Run a full antivirus scan on the server
B.Block the ransomware's command-and-control IP at the firewall
C.Rebuild the server from a clean backup
D.Disconnect the server from the network
AnswerD

Disconnecting the server from the network is the primary containment action to halt active ransomware propagation. This immediate physical or logical isolation prevents the malware from encrypting mapped network drives, communicating with its command-and-control server, or spreading to other vulnerable hosts on the segment.

Why this answer

Immediate network isolation (short-term containment) stops lateral spread and limits damage.

305
MCQeasy

Which of the following log sources would be most useful for detecting DNS tunneling?

A.DNS logs
B.Firewall logs
C.Authentication logs
D.Endpoint EDR logs
AnswerA

DNS logs record the specific domain queries (such as TXT, CNAME, or MX records) and responses that are manipulated during a DNS tunneling attack. Analyzing these logs allows security analysts to detect anomalies like unusually long subdomains, high query volume to a single authoritative name server, and encoded payloads within the queries.

Why this answer

DNS tunneling encodes data inside DNS queries and responses (often in subdomain labels or TXT records), so the authoritative DNS server logs and recursive resolver query logs are the only place where the full query strings are visible. Analyzing DNS logs for high-entropy subdomains, unusual query volume, or long TXT responses is the primary detection method. Firewall, auth, and EDR logs lack the DNS payload detail needed to spot the tunnel.

Exam trap

The trap is that candidates pick firewall logs because DNS uses port 53, but firewalls log connections, not query contents — only DNS logs contain the query names and payloads needed to detect tunneling.

How to eliminate wrong answers

Option B is wrong because firewall logs typically record connection 5-tuples and may log DNS to port 53, but they do not capture the query name or payload contents needed to identify tunneling. Option C is wrong because authentication logs record logon events and credential use, which are unrelated to DNS exfiltration channels. Option D is wrong because EDR logs capture process, file, and network activity on endpoints; while EDR may see a process making DNS calls, it does not log the DNS query strings or response payloads that reveal tunneling.

306
MCQeasy

A critical vulnerability affected the customer portal, but no evidence of exploitation was found. What should the executive summary emphasize? If the primary audience is executive leadership, which content choice is most appropriate?

A.Raw packet captures from the scan
B.A list of analyst shift times only
C.Every command the scanner executed
D.Business risk, customer impact assessment, remediation status, and remaining exposure
AnswerD

Executives need decision-oriented context, not technical exploit detail. Framing the vulnerability around business risk, customer impact, remediation status and residual exposure satisfies the executive-audience constraint, enabling leadership to prioritise resources and accept or mitigate remaining exposure.

Why this answer

Executive leadership requires a high-level summary that translates technical findings into business impact. The executive summary should focus on business risk, customer impact assessment, remediation status, and remaining exposure, as these directly inform strategic decisions without overwhelming non-technical stakeholders with raw data.

Exam trap

The CS0-004 exam often tests the distinction between technical detail and executive-level communication, trapping candidates who think more data (e.g., packet captures or command logs) is always better, when in fact leadership needs concise, risk-focused summaries.

How to eliminate wrong answers

Option A is wrong because raw packet captures are low-level network data that require deep technical analysis and are irrelevant for an executive audience; they belong in a technical report for security analysts. Option B is wrong because a list of analyst shift times provides no insight into the vulnerability, its impact, or remediation, and is operationally irrelevant to the executive summary. Option C is wrong because listing every command the scanner executed is excessive technical detail that does not convey the severity, business risk, or remediation progress, and would confuse rather than inform leadership.

307
MCQmedium

An analyst detects a process named 'powershell.exe' executing a base64-encoded command. Which type of analysis is most appropriate to decode and understand the command?

A.Process analysis
B.Memory analysis
C.Registry analysis
D.Network traffic analysis
AnswerA

Process analysis is the correct first step because it allows the analyst to inspect the process metadata, parent-child relationships, and command-line arguments. By examining the command line of the running powershell.exe process, the analyst can extract and decode obfuscated or Base64-encoded scripts directly to understand the payload's intent.

Why this answer

Process analysis is the most appropriate because it focuses on the live execution context of a running process, including its command-line arguments, loaded modules, and parent-child relationships. In this case, the base64-encoded command is part of the process's command line, which can be decoded to reveal the actual PowerShell script or commands being executed. Tools like Process Explorer, Process Monitor, or PowerShell's own logging (e.g., Script Block Logging) can capture and decode this information.

This directly addresses the need to understand what the process is doing.

Exam trap

CS0-004 often tests the distinction between process analysis and memory analysis, as candidates may confuse the two when dealing with encoded commands; the trap is assuming that memory analysis is needed to decode command-line arguments, when in fact process analysis captures the command line directly.

How to eliminate wrong answers

Option B is wrong because memory analysis examines the contents of RAM for artifacts like injected code or credentials, but it does not directly decode command-line arguments; while it can capture process memory, the base64 string is typically in the command line, not necessarily in memory as plaintext. Option C is wrong because registry analysis focuses on configuration and persistence mechanisms stored in the Windows Registry, not on decoding runtime process arguments. Option D is wrong because network traffic analysis inspects packets for malicious communications, but the base64-encoded command is local to the process and not necessarily transmitted over the network.

308
MCQmedium

Refer to the exhibit. An analyst reviews the output from a netstat command on a server. Which connection is MOST likely indicative of command and control (C2) activity?

A.10.0.0.5:22 to 10.0.0.1:50001
B.10.0.0.5:54321 to 198.51.100.20:4444
C.All connections are normal.
D.10.0.0.5:3389 to 192.168.1.10:54321
AnswerB

This connection is highly suspicious and a strong indicator of compromise. An internal host (10.0.0.5) is initiating an outbound connection from an ephemeral port (54321) to an external, non-RFC1918 IP address (198.51.100.20) on a non-standard port (4444). Port 4444 is not commonly used for legitimate services and is frequently associated with reverse shells or command and control (C2) communication by malware, making it a critical security alert.

Why this answer

The connection from a high ephemeral port (54321) on the server to an external IP (198.51.100.20) on port 4444 is a classic indicator of C2 activity. Port 4444 is commonly associated with Metasploit's default reverse shell listener and other malware frameworks, while the use of a non-standard high source port and an external destination suggests outbound beaconing or command reception.

Exam trap

CompTIA often tests the candidate's ability to recognize that not all high-port connections are malicious; the trap here is that options A and D use high ephemeral ports but are normal internal administrative traffic, leading candidates to incorrectly flag them as suspicious instead of focusing on the external destination and the specific C2-associated port 4444.

How to eliminate wrong answers

Option A is wrong because SSH (port 22) from the server to an internal IP on a high ephemeral port is a normal administrative connection within the local network, not indicative of C2. Option C is wrong because not all connections are normal; option B clearly shows suspicious characteristics. Option D is wrong because RDP (port 3389) from the server to an internal IP on a high ephemeral port is a standard remote desktop session within the local subnet, not C2 traffic.

309
Multi-Selecteasy

Which THREE of the following are common challenges in vulnerability management? (Select THREE)

Select 3 answers
A.Inability to scan all systems
B.Lack of asset inventory
C.Too many false positives
D.Excessive budget
E.Patch compatibility issues
AnswersB, C, E

A comprehensive and accurate asset inventory is the foundation of any vulnerability management program. Without knowing which hardware, software, and cloud resources exist on the network, security teams cannot perform targeted scans, leaving critical blind spots that attackers can easily exploit.

Why this answer

Without a complete and accurate asset inventory, vulnerability management cannot identify which systems require scanning or patching. An asset inventory provides the foundational data for vulnerability scanning scope, and its absence leads to blind spots where unmanaged systems remain unpatched and vulnerable.

Exam trap

CompTIA often tests the distinction between operational difficulties (like scanning all systems) and foundational management challenges (like lack of asset inventory), tempting candidates to select 'Inability to scan all systems' as a core challenge when it is actually a downstream effect.

310
MCQeasy

An analyst runs a command to check active network connections on a Linux host and sees many ESTABLISHED connections to an external IP on port 443. Which command was most likely used?

A.netstat -anp
B.ipconfig /all
C.nmap -sT
D.tcpdump -i eth0
AnswerA

netstat -anp lists all sockets numerically (-n), showing every connection state including ESTABLISHED (-a) and the owning process (-p). This matches the observed output of many established connections to an external IP on port 443.

Why this answer

The `netstat -anp` command displays all active network connections (`-a`), shows numeric addresses and port numbers (`-n`), and includes the process ID and program name (`-p`). This makes it the correct tool for an analyst to quickly identify established TCP connections to an external IP on port 443, as it directly lists the state (ESTABLISHED), remote address, and associated process.

Exam trap

The CS0-004 exam often tests the distinction between commands that *show* current connections (like `netstat`) versus commands that *probe* or *capture* network traffic (like `nmap` or `tcpdump`), leading candidates to confuse scanning tools with monitoring tools.

How to eliminate wrong answers

Option B is wrong because `ipconfig /all` is a Windows command that displays network interface configuration (IP address, MAC, DHCP, DNS), not active network connections or their states. Option C is wrong because `nmap -sT` performs a TCP connect scan to probe open ports on a target, but it does not show the host's own current active connections; it is a scanning tool, not a connection monitoring tool. Option D is wrong because `tcpdump -i eth0` captures raw packets on the specified interface, which can show traffic to port 443, but it does not summarize established connections in a human-readable list; it requires further analysis to identify connection states.

311
Multi-Selecthard

After a data breach incident, a post-incident review team is collecting lessons learned. Which THREE items should be included in the lessons learned documentation?

Select 3 answers
A.Individual performance evaluations of team members
B.Timeline of events during the incident
C.Legal liability of the organization
D.Root cause analysis of the breach
E.Recommendations for process improvements
AnswersB, D, E

Creating a detailed timeline of events is a critical component of a post-incident review. This chronological reconstruction helps the team understand the exact sequence of actions taken, when key decisions were made, and the duration of various incident phases. It is essential for identifying delays, missed detection points, and opportunities for earlier containment or eradication, providing a factual basis for subsequent analysis.

Why this answer

The timeline of events is a critical component of lessons learned documentation. It provides a chronological sequence of actions, detections, and responses during the incident, which is essential for identifying gaps in detection, delays in response, and opportunities for improvement. Without a precise timeline, the team cannot accurately assess the effectiveness of their incident response procedures or the speed of containment.

Exam trap

CompTIA often tests the distinction between operational improvement items (timeline, root cause, recommendations) and administrative or legal items (performance reviews, liability) to see if candidates understand that lessons learned focus on process, not blame or legal exposure.

312
MCQhard

An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?

A.48 hours
B.7 days
C.24 hours
D.72 hours
AnswerD

GDPR Article 33(1) mandates that a data controller notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours" after becoming aware of it. This 72-hour window is the exact compliance threshold explicitly written into the regulation, and failing to meet it without documented justification is a violation. The notification must include the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed to mitigate harm.

Why this answer

GDPR Article 33 mandates that a controller notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is the maximum; earlier notification is encouraged. If notification is not made within 72 hours, it must be accompanied by reasons for the delay.

Exam trap

CS0-004 often tests the 72-hour GDPR window against the 24-hour or 48-hour figures borrowed from other regulations; candidates who memorize 'fast notification' pick the shortest number.

How to eliminate wrong answers

Option A (48 hours) is wrong because it is not a GDPR-mandated timeframe — it may be confused with other regulatory deadlines or internal SLAs. Option B (7 days) is wrong because it reflects a common misconception that breach notification follows a weekly cycle; no GDPR provision allows a week. Option C (24 hours) is wrong because it is the stricter timeline used by some sector-specific regulations (e.g., certain NIS2 or financial rules) but not the GDPR baseline — candidates often conflate the two.

313
Multi-Selecthard

A security analyst is investigating a potential data exfiltration incident. The analyst captures memory from a Windows system and finds a process that is injecting code into other processes. Which THREE indicators from the memory analysis would MOST strongly suggest malicious activity? (Select THREE.)

Select 3 answers
A.The process has memory regions with RWX permissions.
B.The process is hidden from the task manager.
C.The process is making calls to WriteProcessMemory and CreateRemoteThread.
D.The process name is a known Windows system process.
E.The process has a valid digital signature.
AnswersA, B, C

RWX (read-write-execute) memory pages in a process are a high-confidence indicator of injected shellcode because modern operating systems enforce W^X (write XOR execute) policies; legitimate code typically resides in read-only executable regions or uses explicit VirtualProtect transitions. While some Just-In-Time (JIT) engines may briefly allocate RWX, persistent regions outside known JIT heaps warrant immediate investigation.

Why this answer

Option A is correct because memory regions marked RWX (read-write-execute) are a strong indicator of code injection, since legitimate code typically resides in RX (read-execute) or read-only pages, and RWX allows an attacker to write and then execute shellcode in the same region. Option B is correct because a process hidden from Task Manager indicates an attempt to evade user and analyst detection, which is characteristic of rootkits or injected/hooked processes used in exfiltration tooling. Option C is correct because WriteProcessMemory followed by CreateRemoteThread is the canonical Windows API sequence for process injection, letting an attacker place code in a remote process and start a thread to run it, which strongly suggests malicious activity.

Option D is not correct on its own because malware frequently masquerades as a known Windows system process (e.g., svchost.exe), so a familiar name alone is not a reliable malicious indicator. Option E is not correct because a valid digital signature generally indicates trusted, unmodified software and argues against malicious tampering, not for it.

Exam trap

CS0-004 often tests whether candidates over-weight superficial indicators like process names or digital signatures, when the strongest malicious indicators are behavioral and memory-permission anomalies.

314
MCQhard

An incident responder is collecting evidence from a compromised Linux server. The server is still running. Which order of collection adheres to the order of volatility?

A.Memory → network connections → disk → swap space.
B.Disk → memory → network connections → swap space.
C.Memory → network connections → swap space → disk.
D.Network connections → memory → disk → swap space.
AnswerC

This sequence correctly adheres to the standard order of volatility for digital forensic evidence collection, ensuring the most ephemeral data is captured first. Memory (RAM) is the most volatile, holding active process data that is lost upon power loss. Network connections represent active communication states, followed by swap space, which contains spilled-over memory pages. Finally, persistent disk storage is the least volatile, preserving data even after power cycles.

Why this answer

The order of volatility (OOV) dictates that the most volatile data (memory/registers) must be collected first, followed by network connections, then swap space, and finally disk. Memory contains running processes and encryption keys that vanish on power loss; network connections change rapidly; swap space persists longer but is still more volatile than disk. This sequence ensures maximum preservation of ephemeral evidence before it is lost.

Exam trap

The CS0-004 exam often tests the misconception that swap space is less volatile than disk because it is on disk, but swap is actually more volatile due to frequent overwriting by the kernel's paging mechanism.

How to eliminate wrong answers

Option A is wrong because it places disk before swap space, but swap space is more volatile than disk (swap is a temporary extension of RAM and may contain residual data that is overwritten quickly). Option B is wrong because it starts with disk, which is the least volatile, violating the OOV principle that the most volatile (memory) must be collected first. Option D is wrong because it collects network connections before memory, but memory (RAM) is more volatile than network connection state (which can be re-queried) and must be captured first to avoid losing critical in-memory artifacts.

315
MCQeasy

During a vulnerability scan, a security analyst identifies a critical vulnerability with a CVSS v3.1 base score of 9.8. The attack vector is network, attack complexity is low, privileges required are none, user interaction is none, and the impact to confidentiality, integrity, and availability is high. Which CVSS vector string represents this vulnerability?

A.CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
B.CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
C.CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
D.CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AnswerA

Every metric matches the scenario exactly: AV:N reflects remote network exploitability, AC:L means no special conditions are needed, PR:N and UI:N confirm no authentication or victim action is required, and C:H/I:H/A:H capture the total loss of confidentiality, integrity, and availability, which together drive the 9.8 critical base score.

Why this answer

The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a vulnerability with network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability. This matches the description and yields a base score of 9.8 (Critical).

Exam trap

CS0-004 often tests the ability to map a description to the correct CVSS vector; candidates may confuse AC:L with AC:H or PR:N with PR:L, so they must read the description carefully.

How to eliminate wrong answers

Option B is wrong because it has AC:H (High attack complexity), which would lower the score and does not match the 'low' complexity described. Option C is wrong because it has PR:L (Low privileges required), but the description states 'privileges required are none'. Option D is wrong because it has AV:A (Adjacent network), but the description states 'attack vector is network'.

316
MCQmedium

A security analyst is reviewing a vulnerability scan report and notices a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and the scope impact?

A.Attack vector: Network; Scope: Unchanged
B.Attack vector: Network; Scope: Changed
C.Attack vector: Local; Scope: Changed
D.Attack vector: Adjacent; Scope: Unchanged
AnswerA

Correct. AV:N indicates the vulnerability is exploitable remotely over a network without requiring physical or adjacent access, and S:U means the exploited component's impact stays confined within its own security scope rather than affecting resources managed by a different authority.

Why this answer

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H decodes as Attack Vector: Network (AV:N) and Scope: Unchanged (S:U). AV:N means the vulnerability is exploitable remotely over a network, and S:U means a successful exploit affects only the vulnerable component's security authority, not other components. The 9.8 base score is consistent with a network-exploitable, no-privilege, no-interaction, high-impact vulnerability with unchanged scope.

Exam trap

CS0-004 often tests CVSS vector decoding — candidates confuse AV:N with AV:A or misread S:U as S:C, especially when the high 9.8 score suggests 'changed scope' intuitively.

How to eliminate wrong answers

Option B is wrong because the vector contains S:U (Scope: Unchanged), not S:C — a changed scope would require S:C and typically a different impact profile. Option C is wrong because AV:L (Local) would require local access, but the vector specifies AV:N (Network); also scope is Unchanged, not Changed. Option D is wrong because AV:A (Adjacent) would mean the attacker must be on the same logical network segment, but the vector specifies AV:N; scope is correctly Unchanged but the attack vector is misread.

317
Multi-Selecteasy

Which TWO of the following are common indicators of compromise (IOCs) that can be identified through log analysis?

Select 2 answers
A.Unexpected changes to file hashes
B.Expired SSL certificates
C.Scheduled backup completion logs
D.Use of strong passwords
E.Unusual outbound network connections
AnswersA, E

File integrity monitoring (FIM) tools track cryptographic hashes, such as SHA-256, of critical system files. An unexpected change in these hashes indicates that a file has been modified, potentially replaced by malware or tampered with by an attacker to establish persistence or escalate privileges.

Why this answer

Unexpected changes to file hashes (A) are a key indicator of compromise because they suggest that a file has been modified, potentially by malware or an attacker. Log analysis can detect these changes by comparing current file hashes against a known-good baseline, revealing unauthorized alterations that may indicate a security breach.

Exam trap

CompTIA often tests the distinction between operational anomalies (like expired certificates) and true security indicators (like hash changes), expecting candidates to recognize that only events directly tied to unauthorized access or malicious modification qualify as IOCs.

318
Multi-Selecthard

During a memory forensics investigation, a security analyst identifies a process that appears to have code injected into it. The process is 'explorer.exe' and its memory contains sections that are not part of the original executable. Which TWO memory analysis techniques should the analyst use to confirm code injection?

Select 2 answers
A.List the process's open handles
B.Examine the process's environment variables
C.Check the process's parent process
D.Scan for executable memory pages not backed by a file on disk
E.Compare the loaded DLL list with known good baselines
AnswersD, E

A definitive sign of code injection is the presence of an executable memory region that is not backed by an on-disk file. Malicious shellcode is often allocated with VirtualAllocEx and written via WriteProcessMemory, producing a private, executable page that does not map to any section object. Memory forensics tools like Volatility's malfind enumerate the Virtual Address Descriptor (VAD) tree to identify such executable pages without a backing file, making this technique a core method for detecting fileless injection.

Why this answer

Option D is correct because injected code typically resides in memory regions that are executable but have no corresponding file on disk; tools like Volatility's malfind or PE-sieve flag such RWX/VAD regions as strong indicators of injection. Option E is correct because comparing the loaded module/DLL list against a known-good baseline reveals unexpected or unsigned DLLs loaded into explorer.exe, which is a classic sign of DLL injection or reflective loading. Option A is not specific to code injection, since open handles (files, registry keys, mutexes) are normal for explorer.exe and do not prove injected code.

Option B is not relevant, as environment variables are process metadata and are not used to detect injected executable memory. Option C is also not diagnostic, because the parent process (typically userinit.exe or winlogon.exe) only shows process lineage, not memory-resident code injection.

Exam trap

CS0-004 often tests whether candidates can distinguish memory-injection indicators (unbacked executable pages, anomalous DLLs) from general process metadata like handles, environment variables, and parentage, which do not confirm injection.

319
MCQhard

A security analyst is reviewing a vulnerability scan of a Kubernetes cluster. The scan reports that a container is running with privileged mode enabled. Which CIS Kubernetes Benchmark recommendation does this violation relate to?

A.Ensure that containers are not running with privileged access
B.Ensure that the cluster-admin role is not used
C.Ensure that the API server is not exposed to the internet
D.Ensure that etcd is configured with TLS
AnswerA

Running containers with privileged access essentially grants them the same capabilities as the host root user, bypassing container isolation boundaries. CIS Kubernetes benchmarks strongly recommend disabling privileged containers to prevent container breakout attacks, where an attacker compromises a container and escalates privileges to compromise the underlying node.

Why this answer

The CIS Kubernetes Benchmark includes a recommendation to avoid running containers with privileged access, as it increases security risks. This is a common misconfiguration.

320
MCQeasy

A security analyst is classifying an incident where an employee's workstation is infected with ransomware that encrypts files and displays a ransom note. Which incident category and severity level best describe this scenario?

A.DDoS, low
B.Malware, moderate
C.Data breach, high
D.Insider threat, high
AnswerB

Ransomware is malware, so the category is straightforward. Moderate severity fits because a single infected workstation is contained, not spreading enterprise-wide, yet file encryption and a ransom demand still disrupt business operations and require remediation.

Why this answer

Ransomware is a specific subtype of malware that encrypts files and demands payment, making 'Malware' the appropriate incident category. The severity is 'moderate' because while the infection impacts a single workstation and causes data loss, it does not immediately compromise the entire network or expose sensitive data at scale, aligning with typical moderate-severity criteria for isolated malware incidents.

Exam trap

In the CompTIA CySA+ exam, a common trap is confusing 'Malware' with 'Data breach' when ransomware is involved. Ransomware typically encrypts files but does not necessarily exfiltrate them; thus classification as 'Malware' is more appropriate than 'Data breach' unless there is evidence of data exfiltration. Additionally, severity is 'moderate' for a single workstation incident, not 'high', which would require broader organizational impact.

How to eliminate wrong answers

Option A is wrong because a DDoS (Distributed Denial of Service) attack involves overwhelming a network or server with traffic to disrupt availability, not encrypting files on a single workstation; ransomware does not cause network-level flooding. Option C is wrong because a data breach requires unauthorized access or exfiltration of sensitive data, whereas ransomware here only encrypts local files without evidence of data theft or exposure. Option D is wrong because an insider threat involves malicious or negligent actions by an authorized user, but the scenario describes an external malware infection (ransomware) with no indication of employee intent or privilege misuse.

321
MCQmedium

A security analyst is creating a risk register. Which of the following is the most important element to include for each risk?

A.Likelihood and impact rating
B.The exact date the risk was identified
C.The name of the person who discovered the risk
D.The CVSS score of related vulnerabilities
AnswerA

A risk register must prioritize threats to allocate mitigation resources effectively. Calculating the likelihood of occurrence alongside the potential business impact allows analysts to derive a qualitative or quantitative risk rating, which is the foundational metric for risk-based decision-making.

Why this answer

A risk register should include risk owner, likelihood, impact, and mitigation status. Likelihood and impact help prioritize risks.

322
MCQhard

A security analyst needs to share threat intelligence data with a partner organization as part of an information sharing agreement. Which of the following is the most critical consideration before sharing the data?

A.The volume of data being shared
B.The classification level and handling restrictions
C.The data format (e.g., STIX, TAXII)
D.The geographic location of the partner
AnswerB

The classification level and handling restrictions are paramount because they directly dictate who is authorized to receive the intelligence and what protective measures must be applied. Protocols like the Traffic Light Protocol (TLP) explicitly define these boundaries, ensuring sensitive information is not inadvertently exposed, sources are protected, and legal or ethical obligations are met. Adhering to these restrictions is critical for maintaining trust within intelligence-sharing communities and preventing compromise of sensitive data.

Why this answer

The classification level and handling restrictions are the most critical consideration because threat intelligence often contains sensitive information such as indicators of compromise (IOCs) that may be classified or subject to legal handling requirements (e.g., TLP markings). Sharing data without verifying classification could violate security policies, breach confidentiality agreements, or expose critical vulnerabilities to unauthorized parties, undermining the trust and legality of the information-sharing agreement.

Exam trap

CompTIA often tests the misconception that technical interoperability (e.g., STIX/TAXII format) is the primary concern, when in reality classification and handling restrictions are the non-negotiable first step to ensure legal and policy compliance.

How to eliminate wrong answers

Option A is wrong because the volume of data being shared is a logistical concern (e.g., bandwidth or storage), not a security or compliance priority; classification and handling restrictions take precedence regardless of size. Option C is wrong because the data format (e.g., STIX/TAXII) is a technical interoperability choice that facilitates automated sharing but does not address the fundamental requirement to protect sensitive data from unauthorized disclosure. Option D is wrong because the geographic location of the partner is relevant to jurisdictional legal considerations (e.g., GDPR, data sovereignty) but is secondary to ensuring the data's classification and handling restrictions are properly enforced before any sharing occurs.

323
MCQmedium

During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch is intended to fix a remote code execution vulnerability in a widely used application. What is the MOST important step before deploying to production?

A.Check the patch's CVSS score
B.Verify the patch's digital signature
C.Automatically deploy to all production servers immediately
D.Perform regression testing to ensure no breakage
AnswerD

During the testing phase of patch management, regression testing is essential to confirm that the newly applied software update does not break or degrade existing system functionalities, APIs, or custom integrations. This systematic validation ensures that while the security vulnerability is successfully mitigated, the operational stability of the application or operating system remains fully intact before deployment.

Why this answer

Regression testing is the most important step because a patch that fixes a remote code execution vulnerability can still introduce functional regressions or break dependent applications in production. Testing in staging validates that the patch resolves the vulnerability without breaking existing functionality, integrations, or workflows. This aligns with change management best practices where validation precedes production deployment.

Exam trap

CS0-004 often tests the distinction between vulnerability severity (CVSS) and patch safety, tricking candidates into choosing the 'most urgent' action rather than the 'most important' validation step.

How to eliminate wrong answers

Option A is wrong because checking the CVSS score only tells you the severity of the vulnerability being patched, not whether the patch itself is safe to deploy. Option B is wrong because verifying the digital signature confirms authenticity and integrity of the patch package, but does not validate that the patch will not break production systems. Option C is wrong because automatically deploying to all production servers without testing violates change management and can cause widespread outages if the patch is faulty.

324
MCQeasy

A vulnerability scan identifies a critical unauthenticated remote-code-execution flaw on an internet-facing VPN appliance that is actively exploited in the wild. Several internal-only medium vulnerabilities are also present. What should be remediated first? For business prioritization, Which recommendation gives the best risk-based order of work?

A.Patch or mitigate the VPN appliance immediately and verify exposure is removed
B.Defer all remediation until the monthly patch window
C.Start with the oldest medium vulnerability
D.Remediate only low-risk internal findings to improve closure rate
AnswerA

The VPN flaw is unauthenticated remote code execution, internet-facing and actively exploited, so it carries far greater likelihood and impact than the internal medium findings. Patching it first and verifying exposure is removed reflects genuine risk-based prioritisation.

Why this answer

The VPN appliance with a critical unauthenticated remote-code-execution flaw that is actively exploited in the wild represents an immediate and severe risk to the organization's security posture. An internet-facing device with such a vulnerability can be compromised by any attacker on the internet without authentication, leading to full system compromise and potential lateral movement into the internal network. Prioritizing remediation of this flaw over internal-only medium vulnerabilities aligns with risk-based vulnerability management principles, as the likelihood and impact of exploitation are far higher.

Exam trap

The CS0-004 exam often tests the misconception that all vulnerabilities should be patched in order of severity score or age, rather than considering the business context of internet exposure and active exploitation, leading candidates to choose a technically correct but risk-ignorant option like 'start with the oldest medium vulnerability'.

How to eliminate wrong answers

Option B is wrong because deferring remediation until the monthly patch window ignores the active exploitation of a critical vulnerability, leaving the organization exposed to immediate compromise; vulnerability management requires expedited handling of actively exploited flaws outside of regular patching cycles. Option C is wrong because starting with the oldest medium vulnerability disregards the severity and exploitability of the critical flaw; age alone does not determine risk, and a medium internal vulnerability poses far less immediate danger than an internet-facing critical RCE. Option D is wrong because remediating only low-risk internal findings to improve closure rate is a metric-driven approach that sacrifices security; it fails to address the most urgent threat and could lead to a false sense of security while the critical flaw remains unpatched.

325
MCQeasy

A security engineer needs to implement a baseline configuration for all new Linux servers. Which of the following should be included in the baseline to reduce the attack surface?

A.Enable strong password policies for all users.
B.Enable comprehensive audit logging.
C.Disable all unnecessary services and daemons.
D.Configure disk encryption for all data volumes.
AnswerC

Disabling services and daemons that are not essential for the system's intended function directly reduces the attack surface. Each active service typically listens on specific network ports or exposes APIs, creating potential entry points and increasing the likelihood of discovering exploitable vulnerabilities. By removing these unneeded components, an organization eliminates potential vectors for compromise, adhering to the principle of least functionality.

Why this answer

Disabling all unnecessary services and daemons directly reduces the attack surface by eliminating potential entry points for exploitation. Each running service represents a vector for attacks, such as buffer overflows or misconfigurations, and removing them minimizes the number of listening ports and active processes. This aligns with the principle of least functionality, a core security baseline for Linux servers.

Exam trap

CompTIA often tests the distinction between preventive controls (reducing attack surface) and detective or corrective controls (logging, encryption), leading candidates to choose strong password policies or audit logging as the primary method to reduce attack surface.

How to eliminate wrong answers

Option A is wrong because enabling strong password policies, while important for user authentication, does not reduce the attack surface of the server itself; it addresses credential security but not the number of exploitable services. Option B is wrong because comprehensive audit logging is a detective control that helps identify incidents after they occur, not a preventive measure that reduces the attack surface. Option D is wrong because configuring disk encryption protects data at rest from physical theft, but it does not reduce the number of running services or network-accessible ports, which is the primary goal of attack surface reduction.

326
MCQmedium

A security analyst is investigating an alert from the EDR tool indicating that a process named 'powershell.exe' was launched with a parent process 'winword.exe'. The user's workstation had received a phishing email earlier that day. Which type of attack does this likely indicate?

A.Process hollowing
B.Living off the land binary (LOLBin) abuse
C.Injection of code into explorer.exe
D.Scheduled task creation
AnswerB

This alert highlights Living off the Land Binary (LOLBin) abuse, where attackers leverage trusted, pre-installed system utilities like PowerShell to execute malicious commands. When a productivity application like Microsoft Word spawns a command-line interpreter, it strongly indicates a macro-based initial access vector exploiting native binaries to bypass traditional application whitelisting.

Why this answer

The parent-child relationship of winword.exe spawning powershell.exe is a classic indicator of a malicious macro executing PowerShell code, often used in phishing attacks.

327
MCQmedium

A cloud security analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address. The instance is part of an auto-scaling group. What is the best immediate action?

A.Isolate the instance by modifying its security group to deny all traffic.
B.Terminate the instance immediately to stop the threat.
C.Ignore the alert because auto-scaling groups are ephemeral.
D.Update the GuardDuty threat list to ignore that IP.
AnswerA

Modifying the instance's security group to deny all inbound and outbound traffic effectively isolates it from the network. This containment strategy immediately stops any ongoing malicious activity from spreading or exfiltrating data, while crucially preserving the instance's current state, memory, and disk for subsequent forensic analysis. This allows security analysts to investigate the root cause, understand the attack vector, and gather evidence without destroying critical information.

Why this answer

Isolating the instance by removing it from the security group or using a quarantine VPC prevents further communication while preserving forensic data.

328
MCQmedium

An organization uses a DAST tool to test a web application for vulnerabilities. The tool sends specially crafted requests and analyzes responses. Which of the following vulnerabilities is a DAST tool most effective at identifying?

A.Outdated library versions in code
B.Insecure cryptographic algorithms in code
C.Hardcoded credentials in source code
D.SQL injection
AnswerD

SQL injection is a runtime vulnerability that DAST tools are highly effective at identifying. By actively injecting malicious payloads into input fields, query parameters, and headers, the DAST scanner analyzes the application's HTTP responses and database error messages to confirm the vulnerability. This black-box testing closely mimics the behavior of an external attacker.

Why this answer

DAST tools are effective at finding runtime vulnerabilities like SQL injection, XSS, and other injection flaws by simulating attacks on the running application.

329
Multi-Selectmedium

A security analyst is selecting Key Performance Indicators (KPIs) for a security operations dashboard. Which THREE metrics are most relevant for measuring incident response effectiveness? (Select THREE.)

Select 3 answers
A.Number of employees
B.Mean time to detect (MTTD)
C.Mean time to remediate (MTTRem)
D.Revenue growth
E.Mean time to respond (MTTR)
AnswersB, C, E

Mean time to detect measures the average duration between when an incident or attack first occurs and when the security team actually becomes aware of it. A lower MTTD indicates stronger monitoring, alerting, and threat-hunting capabilities, allowing the organization to minimize the window in which attackers can operate undetected. It is specifically focused on the detection phase of the incident response lifecycle.

Why this answer

Option B, Mean time to detect (MTTD), is correct because it directly measures how quickly the security operations team identifies a potential incident from the moment it occurs, which is a core indicator of detection capability and monitoring effectiveness. Option C, Mean time to remediate (MTTRem), is correct because it quantifies the time required to fully resolve or contain an incident after detection, reflecting the team's ability to restore normal operations and limit business impact. Option E, Mean time to respond (MTTR), is correct because it measures the elapsed time from detection to the start of active response actions, showing how promptly analysts engage with and begin handling a confirmed incident.

Option A, Number of employees, is not a security operations performance metric and does not reflect incident response effectiveness. Option D, Revenue growth, is a business financial metric unrelated to the speed or quality of incident detection, response, or remediation.

Exam trap

The trap is selecting business or HR metrics (number of employees, revenue growth) because they appear on executive dashboards — but the question specifically asks for incident response effectiveness KPIs, which are time-based detection and remediation metrics.

330
MCQmedium

A security analyst is using OpenSCAP to perform a compliance scan against a set of RHEL servers. The analyst wants to ensure the servers comply with the CIS Benchmark Level 1 for Red Hat Enterprise Linux. What does Level 1 typically indicate?

A.A custom profile defined by the organization
B.A set of security controls that are considered best practices with minimal impact on functionality
C.The most secure configuration possible
D.Configuration settings that are required for DoD environments
AnswerB

The CIS Level 1 profile is specifically designed to provide a basic, highly effective reduction of an organization's attack surface while minimizing disruption to business operations and system utility. These consensus-based recommendations can be rapidly implemented across an enterprise without causing significant compatibility issues or administrative overhead.

Why this answer

CIS Benchmarks define Level 1 as basic security requirements that can be implemented with minimal impact on functionality, while Level 2 includes more stringent controls.

331
MCQmedium

A vulnerability management team is evaluating whether to apply a patch immediately or implement a compensating control. The patch is for a vulnerability in a legacy system that cannot be taken offline during business hours. The compensating control would involve restricting network access to the system. Which decision is MOST appropriate?

A.Ignore the vulnerability since it affects a legacy system
B.Remove the system from the network
C.Implement a compensating control and schedule patching during a maintenance window
D.Apply the patch immediately despite the outage risk
AnswerC

This approach aligns with best-practice vulnerability management by balancing the need for security against operational availability. A compensating control, such as an internal network access control list (ACL) or an updated intrusion prevention system (IPS) signature, reduces the likelihood or impact of exploitation until the patch can be installed during a scheduled maintenance window. This ensures that the system remains functional and that the patch is tested and deployed in a controlled manner, minimizing downtime and the risk of unexpected failures. It is the correct decision because it addresses the vulnerability without disproportionate disruption to the business.

Why this answer

If the system cannot be patched immediately, implementing a compensating control (network restriction) reduces risk while waiting for a maintenance window.

332
MCQeasy

An organization uses CIS Benchmarks to secure its Linux servers. The security team applies Level 1 benchmarks. Which of the following best describes Level 1 CIS benchmarks?

A.Advanced security settings that may reduce functionality
B.Required for all internet-facing systems
C.Basic security configurations with minimal operational impact
D.Only applicable to DoD environments
AnswerC

CIS Level 1 benchmarks are meticulously designed to establish a foundational security posture across various systems without significantly disrupting business operations or demanding extensive resources. These basic security configurations focus on essential hardening steps that are broadly applicable and easy to implement, ensuring a robust security baseline can be achieved with minimal risk of system instability or performance degradation. This approach makes them highly practical for widespread adoption.

Why this answer

CIS Benchmarks Level 1 profiles consist of basic security configurations that are essential for any system and have minimal impact on functionality. They are considered the minimum baseline and are safe to apply to most systems without disrupting operations.

Exam trap

CS0-004 often tests the distinction between Level 1 and Level 2 CIS Benchmarks, where candidates might confuse Level 1 with advanced settings or think it is only for specific environments.

How to eliminate wrong answers

Option A is wrong because advanced security settings that may reduce functionality are characteristic of Level 2 benchmarks, not Level 1. Option B is wrong because while Level 1 is recommended for all systems, it is not specifically 'required' for internet-facing systems; that is a misinterpretation. Option D is wrong because CIS Benchmarks are not only applicable to DoD environments; they are widely used across industries and government agencies, but not exclusively DoD.

333
MCQmedium

An analyst is investigating an alert from AWS GuardDuty that indicates an EC2 instance is communicating with a known malicious IP address. The analyst checks the VPC Flow Logs and confirms the communication. What is the next best step in the investigation?

A.Run a vulnerability scan on the instance.
B.Ignore the alert because GuardDuty often produces false positives.
C.Isolate the EC2 instance from the network.
D.Delete the EC2 instance immediately.
AnswerC

Isolating the EC2 instance by modifying its security groups to block all inbound and outbound traffic is the primary containment step. This action immediately halts malicious command-and-control (C2) communication or data exfiltration. Crucially, network isolation preserves the volatile memory (RAM) and disk state of the running instance for subsequent forensic analysis.

Why this answer

Since the EC2 instance is compromised, isolating it (e.g., by modifying security groups or stopping the instance) prevents further malicious activity while preserving evidence.

334
MCQeasy

A security analyst is reviewing indicators of compromise (IOCs) from a recent phishing campaign. Which of the following is an example of an email-related IOC?

A.Domain name in the URL
B.Suspicious sender email address
C.IP address of the sender's mail server
D.File hash of an attachment
AnswerB

The sender's email address is a primary, direct email indicator of compromise found within the SMTP envelope or mail headers (such as the "From:" field). Analysts use this specific attribute to create mail transport rules, blocklists, and search mailboxes for phishing campaigns targeting the organization.

Why this answer

A suspicious sender email address is an email-header-level artifact — it appears in the From, Reply-To, or Return-Path fields and is directly tied to the phishing email itself. That makes it an email-related IOC, unlike network or file artifacts.

Exam trap

CS0-004 often tests IOC categorization — candidates pick C or D because they are 'from the email,' but the exam distinguishes email-header IOCs from network and file IOCs, and only the sender address lives in the email header.

How to eliminate wrong answers

Option A is wrong because a domain name in a URL is a web/network indicator extracted from the link, not from the email header itself. Option C is wrong because the sender's mail server IP is a network-layer indicator (often found in Received headers or DNS lookups), categorized as a network IOC rather than an email IOC. Option D is wrong because a file hash of an attachment is a host/file indicator used for endpoint detection, not an email-header artifact.

335
MCQeasy

Which SIEM component is responsible for centralizing and correlating logs from multiple sources?

A.Data retention system
B.Aggregation tier
C.Normalization component
D.Correlation engine
AnswerD

The correlation engine is the central analytical component of a SIEM that applies pre-defined rules and machine learning algorithms to normalized data. By analyzing relationships between disparate events across multiple sources in real time, it identifies complex security incidents that would otherwise appear as isolated, benign activities.

Why this answer

The correlation engine is the SIEM component specifically designed to centralize and analyze logs from multiple sources, applying rules and statistical analysis to identify relationships and patterns indicative of security incidents. It ingests normalized data from the aggregation tier and uses correlation rules to detect complex threats like multi-stage attacks or lateral movement across different systems.

Exam trap

The trap here is that candidates confuse the aggregation tier (which centralizes logs) with the correlation engine (which analyzes them), leading them to pick Option B because they focus on the word 'centralizing' without recognizing that correlation is the key function for identifying relationships.

How to eliminate wrong answers

Option A is wrong because the data retention system is responsible for storing historical log data for compliance and forensic analysis, not for centralizing or correlating logs in real-time. Option B is wrong because the aggregation tier collects and consolidates logs from various sources into a central location, but it does not perform the analysis or correlation to identify relationships between events. Option C is wrong because the normalization component converts disparate log formats into a common schema (e.g., CEF or LEEF) to enable consistent processing, but it does not centralize or correlate logs across sources.

336
Multi-Selecthard

A security analyst has identified a critical vulnerability that affects multiple systems. The analyst needs to report the vulnerability to management. Which THREE elements should be included in the vulnerability report? (Choose three.)

Select 3 answers
A.Number of affected systems and their criticality
B.Specific patch installation dates for each system
C.Organizational risk appetite
D.Recommended remediation steps and timeline
E.CVSS score and vector string
AnswersA, D, E

Reporting how many systems are affected and how business-critical they are gives management the scope needed to weigh urgency, because a critical flaw on 50 domain controllers demands immediate emergency change approval, while the identical CVE on a handful of low-value test machines can reasonably wait for the next scheduled maintenance window.

Why this answer

A vulnerability report must convey the scope and business impact of the issue. Including the number of affected systems and their criticality (e.g., system classification, data sensitivity, or role in the network) allows management to prioritize remediation based on risk exposure. Without this context, management cannot assess the urgency or allocate resources effectively.

Exam trap

CompTIA often tests the distinction between management-level reporting and technical operational details, causing candidates to mistakenly include granular patch dates (Option B) instead of focusing on the elements that drive decision-making.

337
MCQmedium

A security analyst is prioritizing vulnerabilities for remediation. One vulnerability has a CVSS v3.1 score of 7.5, an EPSS score of 0.02, and is not in the CISA KEV catalog. Another vulnerability has a CVSS score of 5.0, an EPSS score of 0.85, and is listed in the KEV catalog. Which vulnerability should be prioritized FIRST?

A.The vulnerability with CVSS 7.5
B.Both should be prioritized equally
C.Neither should be prioritized until a full risk assessment is done
D.The vulnerability with CVSS 5.0
AnswerD

The vulnerability with a CVSS score of 5.0 should be prioritized because its high EPSS score and inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog indicate active, real-world exploitation. Remediation efforts must focus on vulnerabilities with proven threat actor activity, as they represent an immediate entry point, regardless of a moderate base severity score.

Why this answer

EPSS and KEV catalog provide real-world exploit intelligence. The vulnerability with high EPSS and KEV is more likely to be exploited, so it should be prioritized despite lower CVSS.

338
MCQhard

An analyst views the above SIEM logs from a Linux server. Which of the following attacks is MOST likely occurring?

A.Man-in-the-middle attack intercepting credentials
B.SQL injection through the web application
C.Brute force attack leading to credential compromise and malware installation
D.Denial of service attack against the SSH service
AnswerC

The SIEM logs clearly depict a classic brute-force progression, starting with a rapid succession of failed SSH login attempts from an external IP address. Once a password is successfully guessed, the attacker establishes a session and immediately executes commands to download and run an external payload, confirming both compromise and malware installation.

Why this answer

The SIEM logs show repeated failed SSH login attempts from multiple IP addresses, followed by a successful login and then a wget command to download a suspicious file, indicating a brute force attack that succeeded, leading to credential compromise and subsequent malware installation. This pattern matches the typical lifecycle of a brute force attack against SSH services, where an attacker gains access and then stages malware.

Exam trap

CompTIA often tests the distinction between a brute force attack and a denial of service attack by including a successful login event, which eliminates DoS as the answer since DoS does not involve credential compromise or post-exploitation activity.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack intercepting credentials would typically involve ARP spoofing or SSL stripping, not repeated SSH login attempts from diverse IPs followed by a file download. Option B is wrong because SQL injection attacks target web application parameters (e.g., HTTP GET/POST) and would not generate SSH authentication logs or wget commands. Option D is wrong because a denial of service attack against SSH would flood the service with connection requests to exhaust resources, not result in a single successful login and subsequent file download.

339
Matchingmedium

Match each threat intelligence source to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Publicly available information

Sector-specific sharing community

Structured language for cyber threat intelligence

Protocol for exchanging threat intelligence

Open-source threat intelligence platform

Why these pairings

The correct matches are: OSINT with open-source intelligence, ISAC with sector-specific sharing, TAXII with protocol, STIX with language. Common confusion occurs between TAXII and STIX, and between OSINT and ISAC.

340
MCQmedium

A security analyst notices repeated alerts for 'DNS query to known malicious domain' from multiple internal hosts. Upon investigation, the analyst finds that the domain is legitimate and used by a third-party service. What should the analyst do to reduce false positives?

A.Add the domain to a whitelist in the SIEM
B.Disable the alert rule for DNS queries
C.Increase the severity of the alert
D.Block the domain on the firewall
AnswerA

Adding a known-safe, high-volume domain to an exclusion list or whitelist within the SIEM suppresses repetitive false positive alerts without degrading overall detection capabilities. This tuning process optimizes analyst workflow by reducing alert fatigue while preserving the integrity of the underlying correlation rule for other unverified domains.

Why this answer

Adding the domain to a whitelist ensures that legitimate traffic is not flagged, reducing false positives without disabling the rule entirely.

341
MCQhard

An analyst is investigating a potential compromise on a Windows endpoint. EDR telemetry shows that 'powershell.exe' was launched by 'svchost.exe', which in turn was spawned by 'services.exe'. The analyst observes that 'powershell.exe' then executed a script that downloaded an executable. What should the analyst be most concerned about?

A.Services.exe spawning svchost.exe is a sign of malware infection
B.Powershell.exe downloading an executable is a false positive from Windows Update
C.This indicates a potential LOLBin attack using svchost.exe to launch powershell.exe
D.Svchost.exe spawning powershell.exe is a normal Windows operation
AnswerC

This chain matches a living-off-the-land binary (LOLBin) technique in which an adversary abuses the trusted svchost.exe process, often via a hijacked or malicious service DLL, to spawn powershell.exe and execute a downloader script while evading signature-based detection. Because svchost.exe is inherently trusted and its child processes are rarely scrutinized, this parent-child anomaly combined with the subsequent executable download is a strong indicator of active compromise requiring immediate isolation and deeper forensic review.

Why this answer

Svchost.exe hosting a child process like powershell.exe is unusual. This parent-child relationship suggests a LOLBin (living off the land) attack, where an attacker abuses legitimate Windows binaries to execute malicious code. The script download further indicates compromise.

342
MCQmedium

Refer to the exhibit. An analyst sees this alert in the SIEM console: Suricata alert: ET MALWARE Ransomware activity detected from 10.0.0.5 to 10.0.0.1 over SMB. What is the best immediate action?

A.Update the Suricata signature to block the traffic.
B.Run a full antivirus scan on destination host 10.0.0.1.
C.Isolate the source host 10.0.0.5 from the network.
D.Escalate the alert to the incident response team.
AnswerC

Isolating the source host (10.0.0.5) from the network is a significant containment action that should only be performed after initial analysis confirms it is genuinely compromised or malicious, and after proper coordination with stakeholders. Premature isolation without sufficient evidence or communication could disrupt legitimate business operations if the source is a critical internal system or if the alert proves to be a false positive, hindering the overall incident response process.

Why this answer

The alert indicates active ransomware activity from an internal source host. The best immediate action is containment: isolate source host 10.0.0.5 from the network to prevent the malware from spreading. Updating a signature and running an antivirus scan are not immediate containment actions, and escalation should not delay containment once a high-severity active threat is confirmed.

Exam trap

CompTIA CySA+ frequently tests containment actions. If an analyst has clear evidence of a compromised host actively attacking the network, the correct immediate action is containment (e.g., isolating the host) rather than escalating and delaying action, unless the analyst lacks the authority or the system is a critical production server where isolation would cause unacceptable downtime.

How to eliminate wrong answers

Option A is wrong because updating a Suricata signature to block traffic is a reactive, long-term tuning action that should only be performed after the incident is fully analyzed and confirmed; it does not address the immediate need to investigate the alert. Option B is wrong because running a full antivirus scan on the destination host (10.0.0.1) is a secondary step that may be part of remediation, but it is not the best immediate action—the source host (10.0.0.5) is the likely origin of the threat, and scanning alone cannot stop an active attack. Option C is wrong because isolating the source host (10.0.0.5) from the network is a containment action that should be directed by the incident response team after proper analysis, not taken unilaterally by the analyst without understanding the full context, as it could disrupt business operations or alert the attacker.

343
MCQmedium

During a vulnerability scan of an internal web server, the scanner reports a critical vulnerability with a CVSS score of 9.8. The server is behind a WAF that blocks the attack vector. The system owner states the vulnerability is not exploitable due to the compensating control. Which of the following is the best next step?

A.Re-run the scan with a non-credentialed profile
B.Document the finding and accept the risk with the compensating control
C.Ignore the vulnerability and close the finding
D.Immediately patch the server during business hours
AnswerB

When an active security control, such as a Web Application Firewall, successfully mitigates a vulnerability, formalizing this state through documented risk acceptance is the correct protocol. Security analysts must record the compensating control's details and the residual risk in the risk register to maintain compliance and operational awareness.

Why this answer

The best next step is to document the finding and accept the risk with the compensating control because the WAF blocks the attack vector, making the vulnerability not exploitable. This aligns with risk management principles: compensating controls can reduce risk to an acceptable level, and acceptance should be documented.

Exam trap

CS0-004 often tests the misconception that a high CVSS score mandates immediate patching, ignoring the impact of compensating controls and the need for documented risk acceptance.

How to eliminate wrong answers

Option A is wrong because re-running the scan with a non-credentialed profile does not address the finding or the compensating control; it may provide different results but does not resolve the risk decision. Option C is wrong because ignoring and closing the finding without documentation is not acceptable; risk acceptance must be formalized. Option D is wrong because immediately patching during business hours could cause disruption and may not be necessary given the compensating control; patching should follow change management.

344
Multi-Selecthard

A malware alert shows a signed binary performing suspicious actions. Which facts help decide whether it is living-off-the-land abuse? (Choose two.)

Select 2 answers
A.The binary is normally administrative but launched from an unusual parent process
B.The command line performs download, encode, dump, or remote-execution behaviour
C.The binary has a familiar vendor name only
D.The endpoint wallpaper is unchanged
AnswersA, B

Legitimate administrative binaries, such as PowerShell or wmic, are frequently abused by attackers in Living off the Land (LotL) attacks. When a trusted, signed binary is spawned by an anomalous parent process like a web server (w3wp.exe) or a document viewer, it strongly indicates a compromise or exploit execution rather than normal administrative activity.

Why this answer

Living-off-the-land (LotL) abuse often involves legitimate administrative binaries (e.g., PowerShell, certutil, wmic) being executed from an unexpected parent process, such as a Microsoft Office application or a script host. This deviation from the normal process tree (e.g., cmd.exe or explorer.exe spawning the binary) is a strong indicator of malicious intent, as attackers leverage trusted tools to evade detection.

Exam trap

The CS0-004 exam often tests the misconception that a signed binary from a trusted vendor is inherently safe, but the trap here is that LotL abuse specifically exploits the trust in signed administrative tools, so candidates must focus on behavioral anomalies (parent process, command-line actions) rather than the binary's signature or vendor name.

345
Multi-Selectmedium

A security analyst must prepare a report on a recent intrusion for a technical audience (IT staff and security engineers). Which TWO elements should be included?

Select 2 answers
A.Estimated financial cost of the incident
B.Indicators of compromise (IoCs)
C.Mitigation steps and remediation actions taken
D.Full exploit code used in the attack
E.Executive summary explaining business impact
AnswersB, C

Indicators of compromise such as malicious IP addresses, file hashes, registry keys, and C2 domains give engineers concrete, actionable artifacts they can load into SIEM correlation rules, EDR block lists, or YARA signatures to hunt for the same threat elsewhere in the environment and confirm the intrusion has been fully eradicated.

Why this answer

Indicators of Compromise (IoCs) are essential for a technical audience because they provide the forensic artifacts—such as IP addresses, file hashes, registry keys, and domain names—that security engineers need to detect, contain, and eradicate the intrusion. Including IoCs enables the IT staff to update detection signatures, block malicious infrastructure, and perform host-based threat hunting, directly supporting incident response and future prevention.

Exam trap

CompTIA often tests the distinction between audience-appropriate content, where candidates mistakenly include business impact or exploit code for a technical audience, overlooking that technical staff need actionable forensic data like IoCs and clear remediation steps.

346
Multi-Selecteasy

A security analyst is tuning a SIEM correlation rule that triggers on failed login attempts. The rule is generating a high number of alerts from a specific user who frequently mistypes passwords. The analyst wants to reduce false positives while maintaining detection of brute-force attacks. Which TWO actions should the analyst take?

Select 2 answers
A.Delete the correlation rule and create a new one from scratch
B.Exclude the specific user account from the rule
C.Increase the threshold of failed attempts within a time window
D.Change the rule to alert on every single failed login
E.Increase the severity of the rule to trigger an immediate response
AnswersB, C

By adding an exception or exclusion filter for the specific, known user account within the SIEM correlation logic, the analyst prevents benign, repetitive authentication failures from triggering the alert. This targeted approach directly eliminates false positives generated by this specific user's predictable behavior without degrading the rule's ability to detect brute-force attacks on other accounts.

Why this answer

Increasing the threshold to require more failed attempts in the time window helps ignore simple mistypes, and excluding the specific user account from the rule prevents alerts for that benign behavior.

347
MCQmedium

An incident responder needs to collect forensic evidence from a server that was attacked. The evidence includes network connections, running processes, memory contents, and disk data. According to the order of volatility, which piece of evidence should the responder collect FIRST?

A.Memory contents
B.Network connections
C.Running processes
D.Disk data
AnswerB

Active network connections, routing tables, and ARP caches are extremely transient and can terminate or change in milliseconds as sessions close. Capturing these live state metrics first is critical before any local tools are run that might alter the network socket state or terminate active connections.

Why this answer

The order of volatility dictates that the most volatile data (e.g., CPU registers, network connections) should be collected first. Network connections change rapidly.

348
MCQeasy

During the preparation phase of the NIST SP 800-61 incident response lifecycle, a security analyst is tasked with ensuring the team has the necessary tools and resources. Which of the following is the MOST important activity to perform during this phase?

A.Sharing indicators of compromise with threat intel platforms
B.Developing and testing incident response playbooks
C.Conducting root cause analysis of past incidents
D.Analyzing malware samples in a sandbox
AnswerB

Developing, documenting, and testing incident response playbooks through tabletop exercises or simulations is a fundamental task of the Preparation phase. This proactive step ensures that the incident response team has validated, repeatable procedures to follow when an active threat is detected. It establishes the necessary operational readiness before any actual security incident occurs.

Why this answer

In the NIST SP 800-61 preparation phase, the most important activity is establishing the capability to respond before an incident occurs, which centers on developing, documenting, and testing incident response playbooks. Playbooks codify roles, communication paths, and step-by-step procedures so the team can act consistently under pressure. Testing them (tabletop exercises, simulations) validates that tools, contacts, and escalation paths actually work.

Exam trap

CS0-004 often tests phase mapping — candidates see a security activity that sounds important (sharing IOCs, sandboxing malware) and pick it without checking whether it belongs to the preparation phase versus detection, analysis, or post-incident activity.

How to eliminate wrong answers

Option A is wrong because sharing indicators of compromise with threat intel platforms is an information-sharing activity that typically occurs during detection, analysis, or post-incident phases, not as the core preparation deliverable. Option C is wrong because root cause analysis is a post-incident activity performed after an incident is contained and eradicated, not during preparation. Option D is wrong because analyzing malware samples in a sandbox is a detection/analysis-phase task that occurs once a sample is in hand, not a preparation-phase priority.

349
Multi-Selecthard

A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)

Select 3 answers
A.Employee training attendance records
B.Access review documentation
C.Log exports from critical systems
D.Vulnerability scan reports
E.Marketing brochures
AnswersB, C, D

Access review documentation is primary audit evidence because it shows a periodic recertification of user entitlements against role definitions, least privilege, and separation of duties. It provides an auditable trail of who reviewed critical systems, what discrepancies were detected, and how they were remediated, directly satisfying access control compliance requirements. Auditors frequently cite missing or outdated access reviews as a material finding, so this documentation is a cornerstone of evidence collection.

Why this answer

Access review documentation (B) is required because compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 mandate periodic attestation that user access rights are appropriate and least-privilege, providing auditable proof of authorization control. Log exports from critical systems (C) are essential evidence because they demonstrate continuous monitoring, traceability of user and system activity, and support incident investigation and retention requirements under regulations like PCI DSS Req. 10 and HIPAA §164.312(b). Vulnerability scan reports (D) are required to prove that the organization identifies, tracks, and remediates technical weaknesses on a recurring basis, satisfying requirements such as PCI DSS Req. 11.2 and NIST SP 800-53 RA-5.

Employee training attendance records (A) are useful for awareness programs but are not one of the three evidence types typically demanded in this audit context, and marketing brochures (E) are promotional materials with no evidentiary value for compliance.

Exam trap

CS0-004 often tests the distinction between governance/awareness artifacts (training records) and technical/operational evidence (access reviews, logs, scan reports) — candidates over-select training records because they sound compliance-related but are not among the three required technical evidence types.

350
MCQhard

A scanner flags TLS 1.0 on a server, but the service owner says TLS 1.0 is disabled. What is the BEST validation method? For validation, Which action should be taken before closing or downgrading the finding?

A.Change the severity to informational automatically
B.Close the finding because the owner disagrees
C.Delete the server from the scan scope
D.Manually test the service with a TLS client or scanner profile that negotiates protocol versions
AnswerD

Negotiating protocol versions directly with the service confirms what the endpoint actually accepts, rather than relying on the owner's configuration claim. A TLS client or scanner profile that offers TLS 1.0 will reveal whether the handshake succeeds, providing evidence before the finding is closed or downgraded.

Why this answer

The only way to definitively resolve a discrepancy between a scanner finding and a service owner's claim is to perform an independent, manual test. Using a TLS client (e.g., OpenSSL s_client) or a scanner profile that specifically negotiates protocol versions allows you to directly verify whether the server actually accepts TLS 1.0 connections, eliminating false positives or misconfigurations.

Exam trap

The CS0-004 exam often tests the trap that candidates will trust the service owner's assertion over the scanner's evidence, leading them to close the finding without independent verification, which violates the principle of validate-before-remediate.

How to eliminate wrong answers

Option A is wrong because automatically changing severity to informational bypasses the need for validation and could hide a real vulnerability. Option B is wrong because closing a finding solely because the owner disagrees ignores the scanner's evidence and violates due diligence in vulnerability management. Option C is wrong because deleting the server from the scan scope removes it from future assessments, which could mask a genuine security issue and is not a valid remediation step.

351
Multi-Selectmedium

A security analyst is reviewing the results of a recent vulnerability scan. The analyst needs to prioritize remediation efforts effectively. Which four of the following factors should the analyst consider when prioritizing vulnerabilities? (Choose four.)

Select 4 answers
.The Common Vulnerability Scoring System (CVSS) base score
.The age of the vulnerability since its public disclosure
.The number of times a vendor has released a patch for the vulnerability
.The existence of publicly available exploit code
.The asset's criticality to the organization's mission
.The color of the vulnerability in the scan report

Why this answer

The Common Vulnerability Scoring System (CVSS) base score provides a standardized numerical rating (0-10) of a vulnerability's severity, factoring in exploitability and impact metrics. This score helps analysts compare vulnerabilities across different systems and prioritize those with higher potential damage. It is a foundational input for risk-based prioritization, not the sole deciding factor.

Exam trap

CompTIA often tests that candidates confuse the number of patches or visual indicators (like color) with actual risk factors, leading them to select those distractors instead of focusing on exploitability, asset value, and standardized scoring.

352
MCQeasy

An organization uses MISP as its threat intelligence platform. After a security incident, the team wants to share IOCs with other trusted organizations. Which standard should they use to package and exchange the threat intelligence?

A.SNMP
B.NetFlow
C.SMTP
D.STIX/TAXII
AnswerD

Structured Threat Information Expression (STIX) provides a standardized XML/JSON schema to represent cyber threat intelligence, while Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol used to securely route this data. MISP natively supports STIX/TAXII to enable automated, machine-to-machine sharing of indicators of compromise (IoCs) and threat actor profiles across diverse security tools.

Why this answer

STIX (Structured Threat Information Expression) is the standard for describing threat intelligence, and TAXII is the protocol for sharing it.

353
MCQhard

A security analyst is prioritizing vulnerabilities for remediation. The following vulnerabilities have been identified: Vulnerability A: CVSS v3.1 Base Score 9.8 (Critical), no known exploit, affects internet-facing web server. Vulnerability B: CVSS v3.1 Base Score 7.5 (High), exploit available, affects internal database server. Vulnerability C: CVSS v3.1 Base Score 6.1 (Medium), exploit available, affects internal file server. Vulnerability D: CVSS v3.1 Base Score 4.0 (Medium), no known exploit, affects internal workstation. Which vulnerability should be remediated FIRST?

A.Vulnerability D
B.Vulnerability C
C.Vulnerability B
D.Vulnerability A
AnswerD

Vulnerability A represents the highest immediate risk due to its critical severity rating and presence on an internet-facing system. This combination means it is highly susceptible to exploitation by external threat actors, potentially leading to severe data breaches, system compromise, or service disruption without requiring prior internal access. Remediation of such a vulnerability must be the absolute top priority to mitigate the most significant and accessible threat to the organization.

Why this answer

Vulnerability A has a CVSS v3.1 Base Score of 9.8 (Critical) and affects an internet-facing web server, which is directly exposed to external threats. Even though no known exploit exists, the high severity and exposure mean that a zero-day or future exploit could cause severe impact, making it the highest priority for remediation according to risk-based prioritization frameworks like CVSS and NIST SP 800-40.

Exam trap

The CS0-004 exam often tests the misconception that an available exploit always outweighs a higher CVSS score, but the correct prioritization must consider both severity and exposure, especially for internet-facing systems with Critical scores.

How to eliminate wrong answers

Option A (Vulnerability D) is wrong because it has a low CVSS score of 4.0, no known exploit, and affects an internal workstation, which poses minimal risk compared to internet-facing systems. Option B (Vulnerability C) is wrong because although it has an available exploit, its CVSS score is 6.1 (Medium) and it affects an internal file server, which is less critical than an internet-facing web server with a Critical score. Option C (Vulnerability B) is wrong because while it has an exploit available and a High score of 7.5, it affects an internal database server, which is not directly exposed to the internet, whereas Vulnerability A is internet-facing and has a higher severity score.

354
MCQeasy

A small business with 50 employees has been hit by ransomware. All files on the file server and local workstations are encrypted, and the ransom note demands $5,000 in Bitcoin for the decryption key. The CEO is panicking and wants to know the impact on operations and how to proceed. The security analyst has been tasked with preparing a report for the CEO. The company does not have cyber insurance, has minimal IT staff, and relies heavily on email and shared drives for daily operations. The analyst has identified that there is a one-week-old backup but is unsure of its integrity. The analyst must consider that the CEO has limited technical knowledge and that the report will form the basis for critical business decisions. The company's reputation and customer trust are at stake. The analyst must balance transparency with clear, actionable guidance. Which of the following is the BEST approach for the analyst to take in communicating with the CEO?

A.Provide a detailed technical timeline of the ransomware infection, including the malware variant and encryption algorithm used.
B.Tell the CEO that the incident is being handled and not to worry, then proceed with recovery without further updates.
C.Summarize the situation in non-technical terms, explain the business impact (e.g., inability to access customer data, potential revenue loss), outline recovery options (e.g., restore from backups or pay ransom with risks), and recommend immediate steps.
D.Immediately contact law enforcement and advise the CEO to wait for their instructions without providing additional information.
AnswerC

Effective incident response requires translating technical findings into business impacts to facilitate rapid executive decision-making. By outlining clear recovery paths, such as restoring from offline backups versus the legal and financial risks of paying a ransom, the security team empowers the CEO to make informed risk-management choices.

Why this answer

The best approach is to communicate in business terms the CEO can understand: summarize the incident, explain operational and financial impact, present recovery options with risks, and recommend immediate actions. This balances transparency with actionable guidance, enabling informed decision-making.

Exam trap

CS0-004 often tests whether candidates can tailor communication to a non-technical audience, and many choose technically detailed answers that fail to address business impact and decision-making needs.

How to eliminate wrong answers

Option A is wrong because a detailed technical timeline with malware variant and encryption algorithm is inappropriate for a non-technical CEO and does not support business decisions. Option B is wrong because withholding information and avoiding updates undermines transparency and the CEO's ability to make critical decisions. Option D is wrong because contacting law enforcement is important but not the sole action; the CEO still needs a clear business-impact summary and recovery options, and waiting passively is not actionable.

355
MCQhard

An analyst is reviewing a YARA rule that triggers on a specific string pattern in memory. The rule has a high false positive rate. Which of the following actions would best reduce false positives while maintaining detection capability?

A.Add a condition that requires the string to appear with another indicator
B.Convert the rule to a Sigma rule
C.Remove the rule from active use
D.Increase the string length in the rule
AnswerA

Adding logical conditions, such as requiring the presence of an auxiliary malicious string or a specific file header, increases the rule's specificity. This multi-indicator approach significantly reduces false positives by ensuring the rule only triggers when a combination of unique threat characteristics is met, rather than a single, potentially benign string.

Why this answer

YARA false positives occur when a single string pattern is too generic and matches benign files. Adding a condition that requires the string to co-occur with another indicator (for example, using 'and' or proximity operators like '2 of them' or 'all of them') increases specificity while preserving the ability to detect the malicious pattern. This is the standard YARA tuning technique because it raises the rule's precision without discarding the detection logic.

Exam trap

The trap here is assuming that any change to the rule (converting format, lengthening strings, or disabling it) will reduce false positives, when only adding a logical co-occurrence condition preserves detection while improving precision.

How to eliminate wrong answers

Option B is wrong because converting a YARA rule to Sigma changes the detection format and target platform (Sigma targets log/SIEM data, not memory/file scanning) — it does not reduce false positives and may not even be applicable to memory scanning. Option C is wrong because removing the rule eliminates detection entirely, which fails the requirement to maintain detection capability. Option D is wrong because simply increasing string length is a blunt approach that can miss variants and does not guarantee reduced false positives; it may also break detection of the actual threat if the longer string is not present in all samples.

356
Multi-Selectmedium

An incident response team is conducting post-incident activities after a ransomware attack. The team wants to improve detection and response for future incidents. Which TWO actions are most appropriate for updating detection rules? (Select TWO.)

Select 2 answers
A.Conduct a tabletop exercise for the incident response team.
B.Increase the frequency of vulnerability scans.
C.Create YARA rules to identify the ransomware file hashes and patterns.
D.Share IOCs with external threat intelligence platforms.
E.Update the SIEM correlation rules to detect the TTPs observed.
AnswersC, E

YARA rules are highly effective for endpoint detection of a known ransomware strain because they can match on multiple characteristics beyond simple hashes—such as unique strings, mutex names, byte patterns, PE section anomalies, and file metadata. By creating a rule that evaluates file content and structure, the team can identify the malicious payload regardless of filename or hash mutation (e.g., hash-busting variants), enabling rapid triage on forensic images and live systems. This directly addresses the immediate need to recognize the specific ransomware artifacts that were observed during the incident.

Why this answer

Option C is correct because YARA rules are specifically designed to identify malware based on file hashes, byte patterns, and strings, so creating them from the ransomware samples observed during the incident directly improves future detection of that malware. Option E is correct because updating SIEM correlation rules to detect the observed TTPs (tactics, techniques, and procedures) enables the organization to alert on the attacker's behavior, not just static indicators, which strengthens detection and response for future incidents. Option A is not appropriate here because a tabletop exercise tests response processes and decision-making rather than updating detection rules.

Option B does not belong because increasing vulnerability scan frequency addresses vulnerability management, not detection rule improvement. Option D is also not the best fit because sharing IOCs with external platforms contributes to threat intelligence sharing and community defense, but it does not itself update the organization's detection rules.

Exam trap

The trap is choosing activities that improve overall security posture (tabletop exercises, more scans, IOC sharing) instead of the two actions that specifically update detection rules—YARA and SIEM correlation.

357
MCQeasy

Which tool is specifically designed to check Linux systems for compliance with security best practices and can be used for configuration auditing?

A.Burp Suite
B.OpenVAS
C.Nessus
D.Lynis
AnswerD

Lynis is an open-source, battle-tested security auditing tool specifically designed for Unix-like operating systems, including Linux and macOS. It runs locally on the host to perform deep scans of system configurations, bootloaders, kernel parameters, and installed packages, providing actionable hardening recommendations to improve overall system defense.

Why this answer

Lynis is a security auditing tool for Linux/Unix systems that performs compliance checks and configuration reviews.

358
MCQmedium

A security analyst notices that a firewall log shows outbound traffic from an internal server to an external IP address on TCP port 443, but the server is not configured to make any outbound connections. The analyst checks previous logs and finds similar connections every 60 minutes. What type of activity is most likely occurring?

A.Beaconing to a command-and-control server
B.Normal software update check
C.DNS tunneling
D.Data exfiltration via FTP
AnswerA

This behavior is characteristic of malware beaconing, where a compromised host establishes periodic, scheduled outbound connections to a command-and-control (C2) server to receive instructions. Utilizing port 443 allows this malicious traffic to blend seamlessly with legitimate, encrypted HTTPS web traffic, bypassing basic firewall inspection.

Why this answer

Regular outbound connections every 60 minutes to an external IP on port 443 from a server that should not make outbound connections is a textbook beaconing pattern. Malware uses periodic callbacks to a command-and-control (C2) server to receive instructions and exfiltrate data, often disguising traffic as HTTPS to evade detection. The fixed interval and unexpected destination strongly indicate C2 beaconing.

Exam trap

CS0-004 often tests the assumption that any HTTPS traffic is benign — candidates pick 'software update' because port 443 looks legitimate, missing the unexpected source and fixed interval that signal C2 beaconing.

How to eliminate wrong answers

Option B is wrong because a legitimate software update check would typically come from a known vendor domain and be configured or documented — an unconfigured server making regular external connections is not normal update behavior. Option C is wrong because DNS tunneling uses DNS queries (port 53) to exfiltrate data, not TCP port 443 to an external IP. Option D is wrong because FTP uses ports 20/21, not 443, and exfiltration via FTP would not typically present as regular 60-minute beacons on HTTPS.

359
MCQmedium

An analyst is investigating a potential data exfiltration via DNS. Which tool would best help identify DNS tunnelling by analyzing packet payloads and query patterns?

A.Wireshark
B.tcpdump
C.nmap
D.NetFlow
AnswerA

Wireshark is a graphical packet analyzer that allows analysts to perform deep packet inspection on captured network traffic. By reconstructing TCP streams and dissecting application-layer payloads, it enables the precise identification of sensitive data being exfiltrated. This granular visibility is crucial for verifying the exact contents of suspicious transmissions.

Why this answer

Wireshark can capture and analyze DNS packets in detail, including payload and query patterns, making it suitable for detecting DNS tunnelling.

360
MCQhard

A cloud tenant shows an unusual spike in IAM policy changes, access key creation, and failed console logons from a new country. Which telemetry set gives the strongest evidence for control-plane compromise? In the evidence source phase, Which evidence source best supports or refutes the detection?

A.Packet captures from user laptops only
B.Cloud audit logs for identity, policy, and key-management API calls
C.Web server access logs from the public website
D.Endpoint antivirus quarantine reports only
AnswerB

Cloud audit logs record control-plane API activity, capturing IAM policy changes, access key creation and console authentication events. These identity and key-management entries directly evidence or refute compromise of the tenant's management plane, unlike data-plane or host telemetry.

Why this answer

Control-plane operations in cloud environments are managed through APIs for identity (IAM), policy, and key management. Cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log) capture every API call to these services, including who made the call, from which IP address, and what changes were made. The spike in IAM policy changes, access key creation, and failed console logons from a new country is directly recorded in these logs, making them the strongest evidence for a control-plane compromise.

Exam trap

The CS0-004 exam often tests the distinction between control-plane and data-plane telemetry, and the trap here is that candidates mistakenly think packet captures or web logs can reveal cloud API activity, when in fact only cloud audit logs provide the necessary API-level detail for identity and policy changes.

How to eliminate wrong answers

Option A is wrong because packet captures from user laptops only show network-layer traffic (e.g., HTTP/HTTPS packets) and cannot capture cloud control-plane API calls made to the cloud provider's endpoints, as those calls are encrypted and the cloud provider's internal audit logs are the authoritative source. Option C is wrong because web server access logs from the public website record only HTTP requests to the tenant's web application (e.g., GET, POST), not IAM policy changes, access key creation, or console logons, which are control-plane operations managed by the cloud provider's identity service.

361
MCQhard

A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?

A.Provide a list of all current vulnerabilities
B.Present the CVSS score and affected systems
C.Describe the potential financial loss, reputational damage, and regulatory fines
D.Explain the technical details of the exploit chain
AnswerC

Describing potential financial loss, reputational damage, and regulatory fines directly maps the risk onto the board's fiduciary duties, giving them the essential information needed for risk tolerance and resource allocation. This approach quantifies or estimates impact in the same units executives use to evaluate business decisions, such as ERM frameworks and insurance. It lets the CISO argue for security investment as a business trade-off, which is the only frame that produces meaningful discussion and sign-off.

Why this answer

Board members focus on business impact, so describing potential financial loss, reputational damage, and regulatory fines translates the technical risk into terms they understand and care about. This aligns with risk communication best practices for non-technical executives. It enables informed decision-making on risk acceptance or mitigation funding.

Exam trap

CS0-004 often tests the confusion between technical and business communication — candidates may pick CVSS scores thinking they are objective, but boards need business impact.

How to eliminate wrong answers

Option A is wrong because a list of all vulnerabilities is overwhelming and lacks prioritization or business context. Option B is wrong because CVSS scores and affected systems are technical metrics that may not convey business impact to a non-technical board. Option D is wrong because explaining the exploit chain is too technical and irrelevant to board-level decision-making.

362
MCQeasy

Which of the following tools is specifically designed for compliance scanning against security benchmarks on Linux systems?

A.OpenVAS
B.Nessus
C.Lynis
D.Qualys
AnswerC

Lynis is an open-source, host-based security auditing tool specifically engineered for Unix, Linux, and macOS systems. It conducts deep local scans to evaluate system hardening, detect configuration flaws, and verify compliance with frameworks like PCI-DSS and ISO 27001. Unlike network scanners, it runs directly on the target operating system to inspect local configuration files and system parameters.

Why this answer

Lynis is an open-source security auditing tool specifically designed for Linux systems, performing compliance scans against benchmarks like CIS, HIPAA, and PCI-DSS. It checks system hardening, kernel parameters, file permissions, and installed software. OpenVAS, Nessus, and Qualys are general vulnerability scanners, not Linux-specific compliance benchmark tools.

Exam trap

CS0-004 often tests confusion between vulnerability scanners (Nessus, OpenVAS, Qualys) and compliance/hardening tools (Lynis), where candidates pick a well-known scanner instead of the Linux-specific benchmark tool.

How to eliminate wrong answers

Option A is wrong because OpenVAS is a general-purpose vulnerability scanner (part of Greenbone) that scans networks and hosts for CVEs, not a Linux compliance benchmark tool. Option B is wrong because Nessus is a commercial vulnerability scanner for broad vulnerability assessment, not specifically for Linux compliance benchmarks. Option D is wrong because Qualys is a cloud-based vulnerability management and compliance platform, broader than Linux-specific benchmark scanning.

363
MCQeasy

A user opens an invoice document and shortly afterward the endpoint runs wscript.exe from the user's profile. Which detection logic is most relevant?

A.Office document spawning a script interpreter from a user context
B.A password expiry warning
C.High CPU usage on the print server
D.Successful DHCP renewal
AnswerA

When a user opens a malicious Office document, embedded macros or OLE objects can trigger the execution of code. This often involves the Office application (e.g., Word, Excel) launching a script interpreter like PowerShell, cmd.exe, or wscript.exe under the user's security context. This process chain (Office app spawning a script interpreter) is a classic initial access vector for malware, allowing attackers to download further payloads or establish persistence on the compromised system.

Why this answer

The correct detection logic is 'Office document spawning a script interpreter from a user context' because the scenario describes a classic phishing attack where a malicious macro or embedded script in an invoice document launches wscript.exe (a Windows Script Host interpreter) from the user's profile directory. This behavior is a strong indicator of script-based malware execution, as legitimate Office documents rarely spawn script interpreters directly from user-writable paths. The detection logic specifically targets the parent-child process relationship between an Office application (e.g., WINWORD.EXE, EXCEL.EXE) and wscript.exe, which is a common technique used by attackers to bypass application whitelisting and execute arbitrary code.

Exam trap

The CS0-004 exam often tests the distinction between process execution anomalies and unrelated system events, so the trap here is that candidates may confuse a script interpreter launch with generic system performance issues or authentication events, missing the critical parent-child process chain that defines the attack vector.

How to eliminate wrong answers

Option B is wrong because a password expiry warning is an authentication-related event (typically logged as Event ID 4738 or 4724 in Windows Security logs) and has no relevance to the process execution chain of an Office document spawning wscript.exe. Option C is wrong because high CPU usage on the print server is a performance metric unrelated to endpoint process behavior; it does not involve user-context script execution or document-based attacks, and would be monitored by system health tools, not security detection logic.

364
MCQhard

During an incident, the security team needs to preserve evidence for potential litigation. Which of the following actions is most critical to ensure the admissibility of digital evidence?

A.Creating a bit-for-bit forensic image of affected systems
B.Immediately notifying law enforcement
C.Establishing and maintaining a chain of custody for all evidence
D.Encrypting all evidence files
AnswerC

Establishing a rigorous chain of custody is the foundational requirement for ensuring the integrity and legal admissibility of any collected evidence. This process meticulously documents who collected, accessed, transferred, and secured the evidence at every stage of the incident lifecycle. Without this continuous paper trail, the evidence can be easily challenged as tainted or manipulated.

Why this answer

Preserving the chain of custody is essential for evidence admissibility, as it documents who handled the evidence and when.

365
MCQhard

An analyst is investigating a possible data exfiltration incident. The analyst has acquired a memory dump from the compromised system. Which of the following would be the BEST approach to extract evidence of exfiltration?

A.Calculating the MD5 hash of the memory dump and comparing it to known good hashes
B.Using a memory analysis framework like Volatility to analyze network connections and process memory
C.Searching the memory dump for strings containing 'password'
D.Rebooting the system and capturing a new memory dump
AnswerB

Utilizing an advanced memory forensics tool like Volatility allows an analyst to reconstruct active network sockets, identify rogue processes, and extract unencrypted payloads from RAM. This deep-dive analysis can reveal active TCP/UDP connections to external command-and-control (C2) servers or identify the specific buffers used to stage exfiltrated data.

Why this answer

Memory analysis tools like Volatility can extract network connections, process memory, and other artifacts that may show exfiltration activity.

366
MCQmedium

A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on an internal web server. The server is not internet-facing and is protected by a compensating control: a web application firewall (WAF) that blocks the attack vector. What should the analyst recommend?

A.Schedule an immediate emergency patch
B.Remove the WAF to ensure the vulnerability is addressed
C.Document the compensating control and reduce the risk rating
D.Ignore the finding because it is a false positive
AnswerC

Proper risk management requires documenting the active compensating control, such as a WAF rule blocking the specific exploit vector, within the risk register. Because this control significantly reduces the likelihood of successful exploitation, the risk rating should be adjusted downward to reflect the actual residual risk. This ensures accurate reporting and prioritization for the security team.

Why this answer

The vulnerability has a high CVSS score, but the compensating control (WAF) reduces the risk. The analyst should document the control and adjust the risk rating rather than patching immediately if patching would cause downtime.

367
MCQhard

You are a senior incident responder for a large technology company. During a routine threat hunting exercise, you detect unusual network traffic from a Linux web server to an external IP address that is known to be associated with an advanced persistent threat (APT) group. The web server runs a custom PHP application and is not in the DMZ; instead, it's on the internal network serving a management dashboard. You have captured a memory dump of the web server and analyzed it with volatility. The output shows a suspicious process running with the name 'apache2' but with an invalid parent process (PID 1 is 'apache2' itself). Additionally, you find a kernel module loaded called 'hideproc.ko' that is not part of the standard kernel. The network connections show a reverse shell to the external IP. You need to determine the most effective containment and eradication strategy that minimizes data loss and maintains business continuity while preserving evidence for law enforcement involvement.

A.Revert the web server to a previous snapshot from before the suspected compromise date, then run a full antivirus scan on the restored system.
B.Perform a live forensic analysis of the PHP application logs and database to identify the specific vulnerability used, then apply a hotfix to the application code.
C.Isolate the web server from the network immediately, capture a full disk and memory image, then reimage the server from a trusted backup or OS image, and restore application data from a known clean backup.
D.Block the external IP address at the firewall and block all outbound traffic from the web server except to specific internal IPs, then continue monitoring for other compromised hosts.
AnswerC

Immediately isolating the web server is crucial for containment, stopping the active reverse shell and preventing lateral movement. Capturing full disk and memory images preserves all forensic evidence, including the kernel rootkit and attacker activities, for post-incident analysis. Reimaging the server from a trusted source and restoring known clean application data ensures complete eradication of all malicious components and persistence mechanisms, preventing re-infection and ensuring system integrity.

Why this answer

The presence of a kernel rootkit ('hideproc.ko') and a reverse shell indicates deep, persistent compromise that cannot be cleaned by patching or scanning. Isolating the server preserves volatile evidence (memory, disk) for law enforcement, while reimaging from a trusted backup ensures complete removal of the attacker's foothold, minimizing data loss and restoring business continuity.

Exam trap

The trap here is that candidates may choose a containment-only option (D) or a patch-only option (B) because they underestimate the persistence of kernel-level rootkits, failing to recognize that eradication requires complete reimaging from a trusted source.

How to eliminate wrong answers

Option A is wrong because reverting to a snapshot does not guarantee the snapshot itself is clean (the APT may have persisted before the snapshot date), and a full antivirus scan cannot detect or remove a kernel-mode rootkit like 'hideproc.ko'. Option B is wrong because live forensic analysis of logs and applying a hotfix addresses the vulnerability but does not remove the already-loaded kernel rootkit or the active reverse shell, leaving the attacker with persistent access. Option D is wrong because blocking the external IP and restricting outbound traffic only contains the immediate C2 channel; the kernel rootkit and backdoor remain on the server, allowing the attacker to pivot or establish alternative egress paths.

368
MCQhard

An analyst is reviewing a packet capture and observes a series of TCP SYN packets sent to a server, each followed by a SYN-ACK from the server, but no ACK from the client. The source IP is spoofed. What type of attack is most likely occurring?

A.Man-in-the-middle attack
B.DNS amplification attack
C.TCP SYN flood attack
D.TCP reset attack
AnswerC

This pattern of sending SYN packets, receiving SYN-ACK responses, and intentionally withholding the final ACK packet is the hallmark of a TCP SYN flood. By leaving these connections half-open, the attacker rapidly exhausts the target's connection queue (backlog queue), rendering the service unavailable to legitimate users.

Why this answer

The scenario describes a TCP SYN flood attack, where an attacker sends a series of TCP SYN packets with spoofed source IPs to a server. The server responds with SYN-ACK to the spoofed IP, but the client never sends the final ACK, leaving half-open connections that exhaust the server's connection table. This is a classic denial-of-service attack.

Exam trap

CompTIA CySA+ often tests the ability to distinguish between different network attacks based on packet patterns; candidates may confuse SYN flood with other TCP-based attacks like reset attacks or session hijacking.

How to eliminate wrong answers

Option A is wrong because a man-in-the-middle attack involves intercepting and possibly altering communication between two parties, not flooding with SYN packets. Option B is wrong because a DNS amplification attack uses DNS queries with spoofed source IPs to overwhelm a target with large responses, not TCP SYN packets. Option D is wrong because a TCP reset attack involves sending forged TCP RST packets to terminate connections, not SYN packets that initiate half-open connections.

369
Drag & Dropmedium

Order the steps for proper forensic acquisition of a hard drive.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Forensic acquisition requires documentation, write-blocked imaging, hash verification, secure storage, and image hash verification.

370
MCQhard

A business owner accepts delayed remediation for a production system. What must the report include? If the primary audience is SOC manager, which content choice is most appropriate?

A.Only the analyst's personal opinion
B.A permanent exception with no review
C.No mention of the accepted risk
D.Risk owner, reason, compensating controls, review date, and expiry
AnswerD

A documented risk acceptance must record the risk owner, justification, compensating controls, review date and expiry so the SOC manager can track accountability and ensure the deferral is revisited. This satisfies the requirement that delayed remediation be formally governed rather than silently ignored.

Why this answer

When a business owner accepts delayed remediation for a production system, the report must formally document the risk acceptance. This includes the risk owner, the reason for acceptance, any compensating controls in place, a scheduled review date, and an expiry date for the exception. This ensures traceability, accountability, and that the risk is not forgotten, aligning with governance frameworks like NIST SP 800-37 or ISO 27001.

Exam trap

CompTIA often tests the misconception that risk acceptance can be a one-time, permanent decision without ongoing review, leading candidates to choose Option B, but the correct approach requires a defined expiry and review cycle to maintain accountability.

How to eliminate wrong answers

Option A is wrong because including only the analyst's personal opinion violates the requirement for objective, evidence-based reporting; risk acceptance decisions must be documented with business context, not subjective views. Option B is wrong because a permanent exception with no review bypasses the need for periodic reassessment, which is a key control in risk management frameworks to ensure the risk is still acceptable over time. Option C is wrong because omitting the accepted risk from the report hides critical information from the SOC manager, undermining the purpose of the report to provide full visibility into the system's risk posture.

371
MCQmedium

An organization wants to prioritize vulnerabilities based on the likelihood of exploitation. Which of the following sources provides a data-driven probability score for exploitation?

A.CVSS v3.1
B.EPSS
C.CIS Benchmarks
D.OWASP Top 10
AnswerB

The Exploit Prediction Scoring System (EPSS) is a data-driven model that estimates the probability that a specific vulnerability will be exploited in the wild within the next 30 days. By integrating real-time threat intelligence and historical exploit data, EPSS allows security analysts to prioritize remediation efforts based on actual threat activity rather than theoretical severity alone.

Why this answer

EPSS uses real-world data to predict the probability of exploitation, aiding in prioritization.

372
MCQhard

During a security assessment, you discover that an organization's web application is vulnerable to SQL injection because it concatenates user input directly into SQL queries. Which of the following is the BEST remediation strategy?

A.Encode all output data.
B.Deploy a web application firewall (WAF).
C.Use parameterized queries or prepared statements.
D.Implement input validation using a whitelist.
AnswerC

Parameterized queries, also known as prepared statements, are the most effective defense against SQL injection because they fundamentally separate the SQL code from user-supplied data. The database engine first compiles the query structure, then binds user input as literal data values, ensuring that any special characters in the input are treated as data, not executable SQL commands. This prevents attackers from altering the query's intent by injecting malicious SQL syntax.

Why this answer

Parameterized queries (prepared statements) separate SQL logic from user data by using placeholders, ensuring that user input is always treated as data, not executable code. This directly prevents SQL injection by eliminating the ability to alter the query structure, regardless of the input content.

Exam trap

The CS0-004 exam often tests the misconception that input validation or a WAF is sufficient to prevent SQL injection, but the exam expects you to recognize that only parameterized queries/prepared statements address the root cause by enforcing data vs. code separation.

How to eliminate wrong answers

Option A is wrong because output encoding (e.g., HTML entity encoding) addresses cross-site scripting (XSS), not SQL injection, which occurs at the database layer before output is generated. Option B is wrong because a web application firewall (WAF) is a reactive, bypassable control that can be evaded with crafted payloads; it does not fix the root cause of insecure code. Option D is wrong because input validation using a whitelist is insufficient as a primary defense—attackers can bypass whitelists with encoding or alternative characters, and it does not guarantee that all malicious input is blocked, whereas parameterized queries provide a deterministic, structural fix.

373
MCQmedium

During post-incident activities, the security team reviews metrics. Which metric measures the average time taken to detect an incident?

A.MTTR
B.SLA
C.RTO
D.MTTD
AnswerD

Mean Time to Detect is the primary security metric used to calculate the average elapsed time between the initial occurrence of a security compromise and its formal identification by security tools or analysts. Reviewing MTTD during post-incident activities helps organizations evaluate the effectiveness of their monitoring controls, SIEM correlation rules, and threat hunting capabilities.

Why this answer

MTTD (Mean Time to Detect) is the metric that measures the average time between when an incident actually occurs and when it is detected by the security team. It is a core SOC effectiveness metric used in post-incident reviews to evaluate detection capability.

Exam trap

CS0-004 often tests the family of incident metrics (MTTD, MTTA, MTTR, RTO, RPO) — the trap is confusing 'detect' with 'respond' or 'recover', so candidates pick MTTR when the question explicitly says detection.

How to eliminate wrong answers

Option A is wrong because MTTR (Mean Time to Repair/Resolve) measures the average time to remediate an incident after detection, not to detect it. Option B is wrong because SLA (Service Level Agreement) is a contractual commitment, not a detection metric. Option C is wrong because RTO (Recovery Time Objective) is the maximum acceptable downtime defined in business continuity planning, not an average detection time.

374
MCQeasy

A security analyst has identified a critical vulnerability in a customer-facing web application. The analyst needs to communicate this to senior management. Which of the following is the best approach for this communication?

A.Send a brief email stating that a critical vulnerability exists and ask management to schedule a meeting.
B.Notify the development team only and have them fix it before informing management.
C.Provide a detailed technical analysis of the vulnerability, including exploit code.
D.Summarize the vulnerability in terms of business risk, potential financial impact, and recommended mitigation timeline.
AnswerD

Summarizing the vulnerability in terms of its business risk, potential financial impact, and a recommended mitigation timeline is the most effective communication strategy for management. This approach translates complex technical issues into terms that resonate with their strategic priorities, such as potential revenue loss, regulatory fines, or reputational damage. Providing a clear action plan and timeline empowers them to understand the urgency, allocate necessary resources, and make informed decisions regarding risk acceptance or mitigation.

Why this answer

Communicating a critical vulnerability to senior management requires translating technical risk into business impact. Security analysts must present findings in terms of potential financial loss, regulatory consequences, and a clear mitigation timeline, enabling informed decision-making without requiring deep technical expertise.

Exam trap

CompTIA often tests the distinction between technical reporting (for engineers) and business-risk communication (for management), trapping candidates who overemphasize technical detail or assume management needs exploit-level information.

How to eliminate wrong answers

Option A is wrong because a brief email with no context fails to convey urgency or actionable details, and asking management to schedule a meeting delays response to a critical vulnerability. Option B is wrong because bypassing management violates incident response protocols and could lead to uncoordinated fixes, legal liability, or non-compliance with disclosure requirements. Option C is wrong because providing exploit code and deep technical analysis to non-technical senior management is inappropriate; it risks information overload and potential misuse, and does not address the business risk they need to evaluate.

375
MCQmedium

A security analyst is triaging a SIEM alert for 'Multiple failed logins followed by a successful login from a remote IP'. The successful login occurs after 10 failed attempts. What is the most likely classification?

A.True positive for a brute-force attack
B.False positive due to a misconfigured application
C.False positive due to user error
D.True positive for a password spraying attack
AnswerA

This scenario represents a classic true positive for a brute-force attack, where an attacker systematically attempts numerous credential combinations against a single account from a single source IP until succeeding. The sequence of multiple rapid authentication failures followed immediately by a successful login is a high-fidelity indicator of compromise (IoC) that confirms the attack was successful.

Why this answer

The pattern of multiple failures followed by a success strongly indicates a successful brute-force attack, which is a true positive.

Page 4

Page 5 of 10

Page 6

All pages