Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 376–450

701 questions total · 10pages · All types, answers revealed

Page 5

Page 6 of 10

Page 7
376
Drag & Dropmedium

Arrange the steps for conducting a security incident response in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Incident response follows the NIST framework: Prepare, Detect & Analyze, Contain/Eradicate/Recover, Post-Incident, and Report.

377
Multi-Selectmedium

During dynamic analysis of a suspicious file in a sandbox environment, which THREE behaviors are considered indicators of compromise (IOCs) that suggest malicious activity? (Choose THREE.)

Select 3 answers
A.Creating a registry run key to achieve persistence.
B.Outbound network connections to a known malicious IP.
C.The file reading its own content.
D.Dropping an executable file in the startup folder.
E.Opening a text file that was already present.
AnswersA, B, D

A registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is an autostart extension point that launches a specified executable at user logon. Malware frequently adds entries here to achieve persistence, ensuring the malicious code runs on every subsequent login. Sandbox analysis treats this as high-risk because legitimate programs rarely modify such keys during a single execution, especially with randomly named or masqueraded values.

Why this answer

Option A is correct because creating a registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run) is a classic persistence mechanism that causes malware to execute automatically at user logon or system startup, making it a strong IOC. Option B is correct because outbound network connections to a known malicious IP indicate command-and-control (C2) communication, data exfiltration, or payload retrieval, which are hallmark malicious behaviors observed during sandbox dynamic analysis. Option D is correct because dropping an executable into the Startup folder (e.g., %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) establishes persistence by launching the file automatically at user logon, another well-known IOC.

Option C is not an IOC because a file reading its own content is common benign behavior (e.g., self-verification, configuration parsing) and does not by itself indicate malicious activity. Option E is not an IOC because opening a pre-existing text file is normal, expected behavior for many legitimate applications and lacks the persistence, network, or payload-dropping characteristics of malicious activity.

Exam trap

The trap is selecting behaviors that seem suspicious but are actually benign, such as a file reading itself; candidates may overestimate the maliciousness of self-referential actions.

378
MCQmedium

During a phishing incident, an analyst extracts a URL from the email body and searches VirusTotal. The URL is associated with a credential harvesting page. Which type of indicator is this URL?

A.Indicator of Compromise (IOC)
B.Indicator of Attack (IOA)
C.Campaign
D.TTP
AnswerA

A malicious URL extracted from a phishing email serves as a classic Indicator of Compromise (IOC). Security analysts use these reactive, static artifacts—such as domain names, IP addresses, and file hashes—to identify systems that have already been breached or targeted. Once identified, IOCs are ingested into security tools like SIEMs and firewalls to block future traffic and scope the extent of the intrusion.

Why this answer

The URL is an observable that indicates malicious activity and can be used to detect and block further phishing attempts, making it an IOC.

379
MCQeasy

A critical vulnerability affected the customer portal, but no evidence of exploitation was found. What should the executive summary emphasize? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?

A.A list of analyst shift times only
B.Every command the scanner executed
C.Business risk, customer impact assessment, remediation status, and remaining exposure
D.Raw packet captures from the scan
AnswerC

This option correctly identifies the essential elements for an executive-level report on a critical vulnerability. Executives require a clear understanding of the business risk posed by the vulnerability, a thorough assessment of its potential customer impact (including legal and privacy implications), the current status of remediation efforts, and the organization's remaining exposure. This strategic information enables informed decision-making regarding resource allocation, risk acceptance, and communication strategies, aligning security posture with business objectives.

Why this answer

The executive summary for legal/privacy stakeholders must focus on business risk, customer impact, remediation status, and remaining exposure. Since no exploitation was found, the summary should communicate the potential regulatory and privacy implications (e.g., GDPR, CCPA) and the steps taken to close the vulnerability, not technical details. This aligns with the CS0-004 objective of tailoring communication to the audience's need for risk-based, non-technical summaries.

Exam trap

The CS0-004 exam often tests the misconception that an executive summary should include all technical findings, but the trap here is that legal/privacy stakeholders require a risk-focused, non-technical summary, not operational or scanner output details.

How to eliminate wrong answers

Option A is wrong because listing analyst shift times is irrelevant to a vulnerability report and provides no value to legal/privacy stakeholders who need risk and compliance context. Option B is wrong because every command the scanner executed is excessive technical detail that would overwhelm non-technical stakeholders and obscure the key message of no exploitation and remediation status.

380
MCQeasy

During a vulnerability assessment, a security analyst uses a tool that identifies missing patches and misconfigurations based on CIS Benchmarks. Which of the following tools is specifically designed for compliance scanning against CIS benchmarks?

A.OpenSCAP
B.Qualys
C.Nessus
D.OpenVAS
AnswerA

OpenSCAP is an open-source security compliance tool designed specifically to audit systems against standardized security baselines, such as the Center for Internet Security (CIS) benchmarks and DISA STIGs. It utilizes the Security Content Automation Protocol (SCAP) to automate configuration compliance checking and vulnerability assessment, making it the ideal choice for verifying adherence to specific security frameworks.

Why this answer

OpenSCAP is an open-source implementation of the Security Content Automation Protocol (SCAP) that natively consumes SCAP content, including CIS Benchmarks delivered as XCCDF/OVAL datastreams. It is specifically designed for compliance scanning and remediation against benchmarks like CIS, PCI DSS, and STIG. Running 'oscap xccdf eval' against a CIS benchmark profile produces a compliance report mapped to the benchmark's controls.

Exam trap

CS0-004 often tests whether candidates can distinguish SCAP-native compliance tools from general vulnerability scanners — the trap is picking a well-known commercial scanner like Nessus or Qualys when the question specifically asks for CIS benchmark compliance scanning.

How to eliminate wrong answers

Option B is wrong because Qualys is a commercial vulnerability management platform that can import CIS content but is not specifically designed for CIS benchmark compliance scanning — its primary focus is vulnerability detection and asset management. Option C is wrong because Nessus is a general-purpose vulnerability scanner; while Tenable provides CIS audit files, Nessus itself is not a SCAP-native compliance engine. Option D is wrong because OpenVAS (Greenbone) is an open-source vulnerability scanner focused on network vulnerability detection, not SCAP/CIS benchmark compliance evaluation.

381
MCQeasy

A security analyst is reviewing the results of a vulnerability scan. The analyst sees a plugin output that includes the CVSS vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. What is the base score of this vulnerability?

A.6.5
B.9.8
C.10.0
D.7.5
AnswerB

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a worst-case scenario where an unauthenticated remote attacker can fully compromise confidentiality, integrity, and availability without user interaction. Because the Scope is Unchanged (S:U), the mathematical formula caps the maximum possible base score at 9.8 rather than 10.0.

Why this answer

The CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H represents a network-exploitable vulnerability with low attack complexity, no privileges or user interaction required, unchanged scope, and high impact to confidentiality, integrity, and availability. This combination yields a base score of 9.8 (Critical), the maximum for an unchanged-scope vulnerability.

Exam trap

CS0-004 often tests the Scope metric — candidates see all-High impacts and pick 10.0, forgetting that 10.0 requires S:C (Changed), while S:U caps the score at 9.8.

How to eliminate wrong answers

Option A (6.5) is wrong because it corresponds to a medium-severity vector such as AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, which requires privileges or has partial impact — not the all-high, no-prerequisite vector shown. Option C (10.0) is wrong because a 10.0 requires Scope:Changed (S:C) in addition to all-high impacts; the vector here has S:U (Unchanged), capping the score at 9.8. Option D (7.5) is wrong because it corresponds to a high-severity but less severe vector, typically with network access but partial impact or required user interaction, not the fully unauthenticated all-high profile shown.

382
Multi-Selecthard

A root-cause analysis finds that an alert fired but was never triaged. Which corrective actions are useful? (Choose two.)

Select 2 answers
A.Blame an individual without process review
B.Delete the alert rule because it was inconvenient
C.Define queue ownership and escalation thresholds
D.Add monitoring for stale or unassigned alerts
AnswersC, D

Defining clear queue ownership ensures that every alert has a designated team or individual responsible for its review and action, preventing alerts from being orphaned or ignored. Establishing specific escalation thresholds, including time limits and conditions for elevating an alert to higher-tier analysts or management, guarantees timely response and prevents critical incidents from languishing unaddressed. This structured approach is fundamental for efficient and effective security operations center (SOC) workflow and incident management.

Why this answer

Defining queue ownership and escalation thresholds ensures that alerts are assigned to a specific team or individual and have a clear path for escalation if not acknowledged within a defined time. This directly addresses the root cause of the alert never being triaged by enforcing accountability and automated follow-up, which is a standard incident response practice per NIST SP 800-61.

Exam trap

The CS0-004 exam often tests the misconception that punitive measures (blaming individuals) or removing inconvenient alerts are valid corrective actions, when the correct approach is always to improve process and automation to prevent recurrence.

383
MCQmedium

A company wants to prioritize vulnerabilities based on exploitability and impact. Which industry standard framework should the analyst use?

A.CVSS v3
B.OWASP Top 10
C.CVE
D.NIST SP 800-53
AnswerA

CVSS v3 (Common Vulnerability Scoring System version 3) is the industry standard for assessing the severity of software vulnerabilities. It provides a quantitative score from 0 to 10, derived from metrics evaluating exploitability, impact, and temporal and environmental factors. This comprehensive scoring allows organizations to prioritize vulnerabilities effectively based on their potential risk and ease of exploitation, directly addressing the need for a prioritization mechanism.

Why this answer

CVSS v3 (Common Vulnerability Scoring System) is the industry-standard framework for prioritizing vulnerabilities based on exploitability and impact. It provides a numerical score (0-10) derived from metrics such as Attack Vector, Attack Complexity, Privileges Required, User Interaction, and Scope, along with Confidentiality, Integrity, and Availability impact. This allows analysts to objectively rank vulnerabilities for remediation.

Exam trap

CompTIA often tests the distinction between a vulnerability scoring system (CVSS) and a vulnerability identification system (CVE), causing candidates to confuse CVE as a prioritization tool.

How to eliminate wrong answers

Option B (OWASP Top 10) is wrong because it is a list of the most critical web application security risks, not a scoring system for individual vulnerabilities; it does not assign exploitability or impact scores. Option C (CVE) is wrong because it is a dictionary of publicly disclosed vulnerabilities with unique identifiers, not a prioritization or scoring framework. Option D (NIST SP 800-53) is wrong because it is a catalog of security controls for federal information systems, not a vulnerability scoring methodology.

384
Multi-Selectmedium

An organization is implementing a new security incident response plan and wants to establish clear communication protocols. Which three of the following are essential components of effective incident communication? (Choose three.)

Select 3 answers
.Defining a single point of contact (POC) for each stakeholder group
.Using only email for all incident updates to maintain a written record
.Establishing pre-approved templates for different incident types
.Including all employees in every incident notification to ensure transparency
.Creating an escalation matrix with authority levels for decision-making
.Automatically releasing incident details to the press within one hour

Why this answer

Defining a single point of contact (POC) for each stakeholder group ensures clear, controlled communication and prevents conflicting information. Pre-approved templates for different incident types enable rapid, consistent, and accurate notifications without needing to craft messages from scratch during a crisis. An escalation matrix with authority levels ensures that decisions are made by the appropriate personnel based on incident severity, preventing delays and unauthorized actions.

Exam trap

CompTIA often tests the distinction between 'transparency' and 'controlled communication' — candidates may incorrectly choose 'include all employees' thinking it promotes transparency, but the exam expects role-based, need-to-know notifications to avoid operational chaos.

385
MCQeasy

Two servers have the same critical vulnerability. One hosts a public payment API; the other is a lab server isolated from production. What changes the remediation priority? For business prioritization, Which recommendation gives the best risk-based order of work?

A.The number of installed fonts
B.The colour of the scanner dashboard
C.Whether the hostname is shorter
D.Asset criticality, exposure, and business impact
AnswerD

Remediation priority shifts because risk combines vulnerability severity with asset criticality and exposure. The public payment API carries direct financial and regulatory impact, while the isolated lab server does not, so ordering work by business impact and internet exposure correctly ranks the API first.

Why this answer

Remediation priority in vulnerability management is determined by asset criticality, exposure, and business impact, not by superficial attributes. The public payment API server has high business impact and exposure to external threats, making it a higher priority than the isolated lab server, even though both share the same vulnerability. This aligns with risk-based prioritization frameworks such as CVSS environmental metrics and FAIR analysis.

Exam trap

The CS0-004 exam often tests the misconception that all vulnerabilities with the same CVSS base score should be remediated with equal urgency, ignoring the critical role of asset context and business impact in risk-based prioritization.

How to eliminate wrong answers

Option A is wrong because the number of installed fonts has no bearing on vulnerability severity, exploitability, or business risk; it is an irrelevant system configuration detail. Option B is wrong because the colour of the scanner dashboard is a cosmetic UI element that does not affect technical risk assessment or prioritization decisions. Option C is wrong because hostname length is arbitrary and does not correlate with asset criticality, exposure, or the likelihood of exploitation; a shorter hostname does not indicate higher risk.

386
Multi-Selectmedium

A security analyst is investigating a phishing incident that resulted in credential theft. Which TWO actions should the analyst take as part of short-term containment? (Choose two.)

Select 2 answers
A.Block the phishing domain at the email gateway
B.Rebuild the affected workstations from a clean image
C.Conduct a full vulnerability scan of the network
D.Change all user passwords in the domain
E.Disable the compromised user accounts
AnswersA, E

Blocking the phishing domain at the email gateway is immediate containment because it prevents subsequent emails carrying the same malicious payload from reaching other recipients, thereby reducing the number of users exposed to the lure. This email gateway control is fast, reversible, and can also block outbound traffic if needed, but it does not remediate credentials that have already been stolen.

Why this answer

Option A is correct because blocking the phishing domain at the email gateway is a short-term containment action that immediately prevents additional phishing emails from the same domain from reaching other users and stops further credential harvesting. Option E is correct because disabling the compromised user accounts is a short-term containment step that stops the attacker from using the stolen credentials to access resources, halting ongoing unauthorized activity. Option B is not appropriate here because rebuilding workstations from a clean image is a longer-term eradication and recovery action, and credential theft does not necessarily require reimaging.

Option C is not a containment action; a full vulnerability scan is a broader assessment activity that does not stop the active incident. Option D is not the best short-term containment step because changing all domain user passwords is a broad, disruptive action, whereas disabling the specific compromised accounts is more targeted and immediate.

Exam trap

CS0-004 often tests the distinction between short-term containment and other incident response phases (e.g., eradication, recovery), causing candidates to select remediation actions like rebuilding systems or changing all passwords instead of immediate, targeted containment steps.

387
Multi-Selecthard

A security analyst is using osquery to hunt for persistence mechanisms on a Windows endpoint. Which THREE Windows artifacts should the analyst query to identify common persistence locations? (Select THREE.)

Select 3 answers
A.Scheduled tasks in the Task Scheduler
B.Windows Event Logs for login events
C.Network connections from the endpoint
D.Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
E.Services listed in the Service Control Manager
AnswersA, D, E

Scheduled tasks allow the operating system to launch specified commands or executables on triggers such as system startup, user logon, or defined intervals. Attackers frequently create scheduled tasks that re-download or re-execute malicious payloads, and these tasks persist across reboots by being stored in the Task Scheduler database. Osquery can enumerate them through the scheduled_tasks table, revealing the task name, path, and schedule, which helps identify malicious creations with autorun capabilities.

Why this answer

Option A is correct because scheduled tasks in the Task Scheduler are a classic persistence mechanism, allowing attackers to execute code at defined times or triggers, and osquery can enumerate them via the scheduled_tasks table. Option D is correct because the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run registry key causes programs to launch automatically at user logon, a well-known autostart location queryable through osquery's registry table. Option E is correct because services registered in the Service Control Manager can be configured to start automatically at boot, providing persistent execution, and osquery exposes them via the services table.

Option B does not belong because Windows Event Logs for login events are useful for auditing authentication activity, not for identifying persistence locations. Option C does not belong because network connections reflect current or recent communications, not a persistence mechanism stored on the endpoint.

Exam trap

CS0-004 often tests the distinction between persistence artifacts (auto-execution locations) and detection telemetry (logs, network connections) — candidates pick Event Logs because they 'show what happened,' but logs are not a persistence mechanism.

388
MCQeasy

During a phishing investigation, an employee reports clicking a link and entering credentials. Which of the following should be the first step?

A.Conduct user awareness training
B.Block the phishing domain
C.Analyze the email headers
D.Reset the employee's password
AnswerD

Resetting the employee's password is the most immediate and effective containment action when there's a strong suspicion of compromised credentials due to a phishing click. This action instantly invalidates any stolen password, preventing an attacker from using it to gain unauthorized access to the employee's account or other systems where those credentials might be reused. It directly mitigates the primary risk associated with credential-harvesting phishing attacks by severing the attacker's access.

Why this answer

The immediate priority after credential compromise is to secure the account and prevent unauthorized access. Resetting the employee's password (Option D) invalidates the stolen credentials, stopping the attacker from using them to log in. This aligns with the NIST Incident Response Framework's containment phase, which must occur before any remediation or analysis steps.

Exam trap

The CS0-004 exam often tests the distinction between containment and remediation; the trap here is that candidates choose 'Analyze the email headers' (Option C) because they confuse forensic analysis with the first step of incident response, but the priority must always be to stop active harm before investigating.

How to eliminate wrong answers

Option A is wrong because user awareness training is a long-term preventive measure, not an immediate containment step; conducting it first would leave the compromised account vulnerable. Option B is wrong because blocking the phishing domain, while useful, does not address the immediate risk of the attacker using the stolen credentials to access the account. Option C is wrong because analyzing email headers is part of the forensic investigation phase, which should follow containment to avoid delaying critical account protection.

389
MCQmedium

A security team is implementing CIS Benchmarks for a Linux server. They need to choose between Level 1 and Level 2 benchmarks. Which of the following best describes Level 1 benchmarks?

A.They are basic security settings that can be implemented with minimal disruption
B.They are mandatory for compliance with DoD STIGs
C.They are the most restrictive settings, suitable for high-security environments
D.They include advanced settings that require extensive testing
AnswerA

Level 1 controls, such as disabling unused filesystems or setting basic password policies, are designed to reduce the attack surface without breaking common applications, making them suitable as a default baseline for nearly any server.

Why this answer

CIS Level 1 benchmarks are defined as basic, essential security settings that can be applied with minimal disruption to functionality and are intended for all systems. They represent a practical baseline that most organizations can implement without extensive testing or performance impact, making them suitable as a starting point for hardening. This matches option A's description of basic settings with minimal disruption.

Exam trap

CS0-004 often tests the confusion between Level 1 and Level 2, where candidates incorrectly associate Level 1 with high-security or mandatory compliance settings rather than its true role as a minimal-disruption baseline.

How to eliminate wrong answers

Option B is wrong because CIS Benchmarks are not mandatory for DoD STIG compliance; STIGs are separate DoD-specific hardening guides, and while they may overlap, CIS Level 1 is not a STIG requirement. Option C is wrong because Level 2, not Level 1, contains the most restrictive settings intended for high-security environments. Option D is wrong because Level 2 benchmarks include advanced settings that require extensive testing and may impact functionality; Level 1 is specifically designed to avoid that.

390
MCQhard

During a web application penetration test using Burp Suite, a security analyst identifies that an API endpoint accepts a URL parameter that is used to fetch data from an external resource. The application does not validate or sanitize the parameter. This is most likely vulnerable to which attack?

A.SQL injection
B.Server-Side Request Forgery (SSRF)
C.Cross-site scripting (XSS)
D.XML External Entity (XXE)
AnswerB

Because the unvalidated URL parameter is used server-side to fetch a resource, an attacker can substitute internal addresses, cloud metadata endpoints, or restricted URLs, forcing the server itself to issue requests it controls, which is the defining behavior of Server-Side Request Forgery.

Why this answer

When an application takes a user-supplied URL parameter and fetches content from it without validation, the server can be tricked into making requests to internal or external resources on the attacker's behalf. This is the classic definition of Server-Side Request Forgery (SSRF). The lack of validation or sanitization of the URL parameter is the key indicator, allowing attackers to reach internal metadata endpoints (e.g., 169.254.169.254) or internal services.

Exam trap

CS0-004 often tests the confusion between SSRF and XXE or SQLi — candidates must recognize that a URL parameter used for server-side fetching without validation is the signature of SSRF, not injection into a database or XML parser.

How to eliminate wrong answers

Option A is wrong because SQL injection involves injecting SQL syntax into database queries, not fetching external resources via URL parameters. Option C is wrong because XSS executes script in a victim's browser, whereas SSRF abuses the server's ability to make outbound requests. Option D is wrong because XXE exploits XML parsers that process external entities, which requires XML input and a vulnerable parser — not a URL fetch parameter.

391
MCQhard

A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?

A.Tactical intelligence
B.Strategic intelligence
C.Technical intelligence
D.Operational intelligence
AnswerA

Tactical threat intelligence focuses on the immediate, real-time indicators of compromise (IoCs) such as malicious IP addresses, domain names, and file hashes. Security analysts ingest this data directly into security information and event management (SIEM) systems and firewalls to automate threat detection and block active attacks.

Why this answer

Tactical intelligence includes IoCs such as IP addresses, domain names, and hashes that can be used for detection and blocking.

392
MCQeasy

Which technology is specifically designed to detect anomalous user behavior that may indicate a compromised account?

A.IDS.
B.UEBA.
C.SIEM.
D.Antivirus.
AnswerB

User and Entity Behavior Analytics (UEBA) is specifically engineered to detect anomalous activities by establishing baselines of normal behavior for users and other entities within an organization's IT environment. It employs machine learning algorithms and statistical analysis to identify deviations from these baselines, such as unusual login times, access to sensitive data, or data exfiltration attempts, which often indicate compromised accounts or insider threats. This makes UEBA the ideal technology for proactive detection of behavioral anomalies.

Why this answer

User and Entity Behavior Analytics (UEBA) is specifically designed to establish baselines of normal user behavior and detect anomalous activities—such as unusual login times, impossible travel, or abnormal data access patterns—that may indicate a compromised account. Unlike signature-based tools, UEBA leverages machine learning and statistical modeling to identify deviations from established norms, making it the correct choice for detecting account compromise.

Exam trap

CompTIA often tests the distinction between correlation-based tools (SIEM) and behavior-based tools (UEBA), and the trap here is that candidates confuse SIEM's log aggregation and rule-based alerting with UEBA's machine learning-driven anomaly detection for user behavior.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) primarily monitors network traffic for known attack signatures or protocol anomalies, not user behavior patterns. Option C is wrong because a Security Information and Event Management (SIEM) system aggregates and correlates logs from multiple sources but relies on predefined rules and signatures rather than behavioral baselining to detect anomalies. Option D is wrong because Antivirus software detects and blocks known malware based on signatures and heuristics, not user behavior or account compromise indicators.

393
MCQmedium

An analyst is investigating a suspicious email attachment. The sandbox analysis shows that the document drops a binary that connects to an external IP on port 4444. Which network analysis tool is best suited to confirm if any internal hosts are communicating on that port?

A.tcpdump
B.nmap
C.Wireshark
D.NetFlow analyzer
AnswerD

A NetFlow analyzer aggregates metadata about network conversations, such as source/destination IPs, ports, and timestamps, without the overhead of full packet payloads. This lightweight data structure allows security analysts to rapidly query months of historical traffic across the entire enterprise to pinpoint which hosts communicated with a malicious external IP.

Why this answer

NetFlow collects metadata about network flows, including destination IP and port, enabling analysts to query for all traffic on a specific port across the network.

394
Multi-Selectmedium

A vulnerability report is going to system owners. Which elements make it actionable? (Choose three.)

Select 3 answers
A.Only a generic statement that risk exists
B.Affected assets and owners
C.Due dates based on severity or SLA
D.Remediation guidance and validation steps
AnswersB, C, D

System owners must be able to immediately identify which specific hosts, IP addresses, or application components are vulnerable. Explicitly mapping affected assets to their designated owners ensures clear accountability and prevents critical remediation tasks from being ignored due to ambiguity in organizational responsibility.

Why this answer

Identifying affected assets and their owners is essential for accountability and remediation. Without this information, system owners cannot determine which systems require patching or configuration changes, making the report non-actionable. This aligns with the NIST SP 800-40 Rev. 4 guidance on vulnerability management, which emphasizes asset ownership as a prerequisite for response.

Exam trap

The CS0-004 exam often tests the misconception that a vulnerability report is actionable if it merely states risk exists, but without asset ownership and due dates, the report lacks the specificity required for system owners to take concrete steps.

395
Multi-Selecthard

A host is suspected of running fileless malware. Which artefacts should be collected quickly? (Choose two.)

Select 2 answers
A.Memory image or live response data
B.Active network connections and running processes
C.A list of cafeteria purchases
D.A printed office map
AnswersA, B

Fileless malware resides primarily in volatile memory (RAM) or executes via legitimate system tools like PowerShell or WMI without writing traditional files to the disk. Capturing a memory image or gathering live response data is critical because rebooting or shutting down the system will destroy this volatile evidence, preventing successful forensic reconstruction.

Why this answer

Fileless malware operates in memory without writing to disk, so capturing a memory image or live response data preserves the malicious code, injected DLLs, and process hollowing artifacts that would vanish on reboot. Active network connections and running processes reveal the malware's C2 communications and its in-memory execution context, which are critical for identifying the infection vector and scope.

Exam trap

The CS0-004 exam often tests the misconception that fileless malware leaves no artifacts at all, leading candidates to overlook memory and live response data, or to choose irrelevant options like cafeteria purchases that seem like a distractor but have no forensic value.

396
MCQeasy

Which of the following vulnerability lifecycle phases involves verifying that a remediation has been successfully applied and that the vulnerability no longer exists?

A.Discovery
B.Prioritization
C.Remediation
D.Verification
AnswerD

Verification is the closing phase of the lifecycle, where the analyst re-scans or otherwise re-tests the previously vulnerable asset to confirm the remediation was applied correctly and the vulnerability no longer exists, closing the loop before the finding can be marked resolved in the tracking system.

Why this answer

Verification is the phase where after remediation, the system is rescanned or checked to confirm the vulnerability is mitigated.

397
MCQmedium

A security operations center (SOC) analyst is investigating an alert from the endpoint detection and response (EDR) system indicating that a process named "svchost.exe" spawned from a parent process "cmd.exe" on a user workstation. The user is a software developer who frequently uses command-line tools. The analyst checks the command line arguments: "cmd.exe /c powershell -EncodedCommand ...". The encoded command decodes to a script that downloads a payload from a remote server and executes it. The analyst also sees that the workstation has established an outbound connection to the same server on port 443. Which of the following is the BEST immediate action?

A.Isolate the workstation from the network.
B.Disable the user account.
C.Kill the svchost.exe process.
D.Block the remote server IP at the firewall.
AnswerA

Network isolation immediately severs all communication pathways for the compromised workstation. This critical containment step prevents the malware from exfiltrating data, receiving further command and control (C2) instructions, or attempting lateral movement to other internal systems. It effectively quarantines the threat, buying crucial time for incident responders to analyze the payload and plan remediation without further risk to the broader network.

Why this answer

Isolating the workstation is the best immediate action because the EDR alert confirms active compromise: a malicious encoded PowerShell command executed via cmd.exe spawned svchost.exe (a process commonly abused for masquerading), and an outbound connection to the same C2 server on port 443 (HTTPS) indicates ongoing data exfiltration or further payload delivery. Network isolation stops all communication with the attacker while preserving forensic evidence on the endpoint, which is critical for containment in a SOC response.

Exam trap

CompTIA often tests the misconception that blocking the remote IP or killing the process is sufficient, but the trap here is that the active outbound connection and running payload require immediate network containment to prevent data exfiltration and lateral movement, not just reactive blocking or process termination.

How to eliminate wrong answers

Option B is wrong because disabling the user account does not stop the already-running malicious process or its outbound C2 connection; the threat persists on the endpoint regardless of authentication status. Option C is wrong because killing svchost.exe may disrupt the malware but does not block the outbound connection already established, and the process could be a legitimate svchost.exe instance that has been injected or hollowed, making termination risky without analysis. Option D is wrong because blocking the remote server IP at the firewall only prevents future connections from that IP but does not stop the current active session or the malware already executing on the workstation, and the attacker can easily switch to a different IP or domain.

398
MCQmedium

During a vulnerability scan, an analyst discovers a high-severity vulnerability on a critical database server. The server is in production and cannot be taken offline. The vendor has released a patch but requires a reboot. Which of the following should the analyst recommend FIRST?

A.Implement a workaround from the vendor.
B.Schedule the patch during the next maintenance window.
C.Apply the patch immediately.
D.Migrate the database to a new server.
AnswerB

Scheduling the patch during the next maintenance window represents the best practice for addressing high-severity vulnerabilities in production environments. This approach allows for proper change management, including testing the patch in a non-production environment, planning for potential rollbacks, and communicating downtime to stakeholders. It effectively balances the need for security remediation with the critical requirement for system availability and operational stability, minimizing unplanned service disruptions.

Why this answer

The database server is in production and cannot be taken offline, so the patch must be applied during a scheduled maintenance window to minimize business disruption. The vulnerability is high-severity, but the vendor requires a reboot, which would cause downtime; therefore, the first step is to plan the patch application at the next available maintenance window, not to apply it immediately or implement a workaround that may not fully mitigate the risk.

Exam trap

CompTIA often tests the candidate's ability to prioritize business continuity over immediate remediation, leading candidates to incorrectly choose 'Apply the patch immediately' (Option C) because they focus solely on the high severity without considering the operational impact of a reboot on a critical production server.

How to eliminate wrong answers

Option A is wrong because implementing a workaround from the vendor is a temporary measure that may not fully address the vulnerability and could introduce additional complexity or performance issues; the analyst should prioritize the patch itself. Option C is wrong because applying the patch immediately would cause an unplanned reboot of a critical production database server, leading to unacceptable downtime and potential data loss or corruption. Option D is wrong because migrating the database to a new server is a drastic, time-consuming, and high-risk operation that is not the first recommendation; it should only be considered if patching is impossible or the server is end-of-life.

399
MCQhard

A vulnerability report is being prepared for an organization's management. Which of the following is the MOST appropriate structure for this report?

A.Charts showing open vulnerability counts over time, without any narrative
B.List of all vulnerabilities sorted by CVSS score, followed by detailed technical descriptions
C.Executive summary, findings by severity, risk acceptance, remediation timeline
D.Network diagram with vulnerability locations, patch status, and compliance checklists
AnswerC

This structure layers an executive summary for quick comprehension, findings grouped by severity for prioritization context, documented risk acceptances for transparency on deferred items, and a remediation timeline for accountability, matching exactly what management-level reporting requires to make informed risk and resourcing decisions without wading through raw technical scan output.

Why this answer

A standard vulnerability report includes an executive summary for high-level decision-makers, findings grouped by severity, risk acceptance decisions, and a remediation timeline.

400
Multi-Selectmedium

Which TWO of the following are best practices for vulnerability scanning in a PCI DSS compliant environment? (Select TWO)

Select 2 answers
A.Perform quarterly scans
B.Scan only external IP ranges
C.Use a single scanning vendor
D.Scan after any significant network change
E.Use authenticated scanning for more accurate results
AnswersA, E

PCI DSS requirement 11.2 mandates quarterly external and internal scans.

Why this answer

Options A and E are correct. PCI DSS Requirement 11.2.1 mandates quarterly internal and external vulnerability scans, so option A is correct. Option E is correct because authenticated scanning provides more accurate results by identifying vulnerabilities visible only to authenticated users.

Option B is incorrect because PCI DSS requires scanning both external and internal IP ranges, not just external. Option C is incorrect because PCI DSS does not require a single scanning vendor; organizations may use multiple vendors. Option D is incorrect because while scanning after significant network changes is a best practice, it is not a specific PCI DSS requirement in this context.

401
Multi-Selecthard

An organization is preparing for a compliance audit. Which TWO of the following are essential pieces of evidence to demonstrate effective vulnerability management?

Select 2 answers
A.Network topology diagrams
B.Employee training logs
C.Vulnerability scan reports
D.Patch management reports
E.Incident response playbooks
AnswersC, D

Vulnerability scan reports are the primary evidence that an organization is actively discovering weaknesses, as they contain the scan timestamp, authenticated or unauthenticated scan type, CVEs, and CVSS severity scores. They allow auditors to correlate the identified vulnerabilities against the organization's asset inventory and check that coverage includes critical systems. A series of scan reports demonstrates the continuous, recurring nature of the program, which is a core requirement of many compliance frameworks.

Why this answer

Vulnerability scan reports (C) are essential evidence because they document the identification of vulnerabilities across the environment, showing when scans were performed, what hosts were assessed, and which CVEs or findings were detected, which is the core proof that a vulnerability management program is actively discovering weaknesses. Patch management reports (D) are equally essential because they demonstrate remediation—showing that identified vulnerabilities were addressed through applied updates, with dates, affected systems, and patch levels (e.g., KB numbers or package versions), closing the loop between detection and resolution. Together, C and D provide the audit trail of find-and-fix that auditors require to verify an effective vulnerability management process.

Network topology diagrams (A) describe architecture but do not evidence scanning or remediation activity. Employee training logs (B) support security awareness compliance, not vulnerability management specifically. Incident response playbooks (E) are documentation for handling incidents and do not demonstrate ongoing vulnerability identification or patching.

Exam trap

CS0-004 often tests whether candidates understand that vulnerability management requires both detection and remediation evidence — picking only scan reports or only patch reports misses half the lifecycle and is a common wrong answer.

402
MCQhard

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the supervisory authority?

A.24 hours
B.7 days
C.48 hours
D.72 hours
AnswerD

The General Data Protection Regulation (GDPR), specifically Article 33, explicitly mandates that organizations must notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This precise timeframe is crucial for enabling authorities to promptly assess the breach's impact and for organizations to initiate appropriate mitigation actions and fulfill their accountability obligations.

Why this answer

GDPR Article 33 requires that data breaches be reported to the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

403
MCQmedium

A SOC analyst receives an alert from the SIEM indicating a high volume of outbound traffic from a single workstation to an external IP address on port 22. Upon investigation, the analyst finds the workstation is used by a developer who frequently transfers large files to a remote server via SCP. What is the most appropriate classification for this alert?

A.True positive
B.True negative
C.False positive
D.False negative
AnswerC

A false positive occurs when a security control incorrectly flags benign, authorized activity as malicious. In this case, the SIEM generated an alert for legitimate SCP transfers, meaning the rule triggered on normal administrative behavior rather than an actual security incident.

Why this answer

The alert is triggered by legitimate administrative activity (SCP file transfer), so it is a false positive. The analyst should tune the SIEM to reduce similar alerts.

404
MCQhard

A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?

A.Explain the potential financial loss and reputational damage.
B.Show the CVSS score and exploit complexity.
C.Recommend immediate patching without details.
D.Describe the vulnerability in technical terms.
AnswerA

Quantifying the unpatched vulnerability in terms of potential financial loss—such as breach response costs, regulatory fines, or lost revenue from downtime—and reputational damage, like customer churn or erosion of brand trust, directly aligns the technical risk with the board's fiduciary responsibilities. This translation reassures executives that their decision allocates resources to protect shareholder value and market standing, not just IT infrastructure.

Why this answer

When communicating risk to a board of directors, the most effective approach is to translate the technical vulnerability into business impact—potential financial loss, regulatory fines, and reputational damage—because executives prioritize strategic and financial consequences over technical detail. This framing enables informed risk acceptance or remediation decisions at the governance level. CVSS scores and technical descriptions, while useful to security teams, do not resonate with non-technical leadership.

Exam trap

CS0-004 often tests audience-appropriate communication, so candidates who default to technical metrics (CVSS, CVE) instead of business impact (financial, reputational) pick the wrong answer for executive audiences.

How to eliminate wrong answers

Option B is wrong because CVSS scores and exploit complexity are technical metrics that mean little to a board; they inform severity but not business consequence. Option C is wrong because recommending immediate patching without context or justification undermines informed decision-making and fails to convey the risk's business impact. Option D is wrong because describing the vulnerability in technical terms (e.g., buffer overflow, CVE details) does not translate to the financial and reputational stakes that boards are accountable for.

405
MCQeasy

During the preparation phase of the NIST SP 800-61 incident response lifecycle, which of the following is the MOST important activity to ensure effective incident response?

A.Using YARA rules to detect malware in the environment
B.Implementing network segmentation to limit lateral movement
C.Conducting a root cause analysis after each incident
D.Creating and training the incident response team
AnswerD

People execute the plan; without a formed, trained team, detection, analysis and containment stall regardless of tooling. Creating and training the incident response team during preparation directly satisfies the stem's requirement for effective response capability before an incident occurs.

Why this answer

The preparation phase of NIST SP 800-61 is about establishing the capability to respond before an incident occurs. The single most critical element is having a trained, organized incident response team with defined roles, responsibilities, and communication channels. Without a competent team, detection tools, segmentation, and post-incident analysis cannot be effectively leveraged.

NIST explicitly lists 'Incident Response Team' as a key preparation component, including team formation, training, and equipping.

Exam trap

CS0-004 often tests the distinction between preparation and other phases, and candidates may confuse preventive controls (like segmentation) or detection tools (like YARA) as preparation activities, when the most critical preparation is the human team and its readiness.

How to eliminate wrong answers

Option A is wrong because YARA rules are a detection mechanism used during detection and analysis, not a preparation activity; they are part of the tooling but not the most important preparatory step. Option B is wrong because network segmentation is a preventive architectural control that supports containment, but it is not the primary preparation activity for incident response; it is a general security measure. Option C is wrong because root cause analysis is performed during post-incident activity (lessons learned), which is the final phase of the lifecycle, not preparation.

406
MCQmedium

Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?

A.72 hours
B.7 days
C.24 hours
D.48 hours
AnswerA

GDPR Article 33(1) sets a hard, maximum deadline of 72 hours after the controller becomes aware of a personal data breach for notifying the supervisory authority, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The obligation is phrased as 'without undue delay and, where feasible, not later than 72 hours,' meaning 72 hours is the outer statutory limit, not a target. If notification is made after 72 hours, the controller must provide the reasons for the delay under Article 33(5). Thus, 72 hours is the correct and canonical compliance reporting requirement.

Why this answer

Under GDPR Article 33, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is a core GDPR compliance requirement. The other timeframes do not match the regulation.

Exam trap

CS0-004 often tests specific regulatory timeframes, so candidates who confuse GDPR's 72-hour rule with shorter windows from other breach notification laws (e.g., 24 hours) or internal SLAs pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because 7 days is not a GDPR notification timeframe; it may be confused with other regulatory or internal reporting periods. Option C is wrong because 24 hours is a common misconception, possibly borrowed from other breach notification regimes, but GDPR specifies 72 hours. Option D is wrong because 48 hours is not specified in GDPR Article 33; the regulation explicitly uses 72 hours.

407
MCQeasy

Which of the following metrics measures the average time it takes to identify a security incident after it occurs?

A.Patch SLA compliance percentage
B.Mean time to remediate (MTTRem)
C.Mean time to respond (MTTR)
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect (MTTD) is the average elapsed time between the actual occurrence of a security incident or malicious activity and the moment it is recognized or flagged as suspicious by telemetry, analytics, or an analyst. It is the definitive metric for measuring detection velocity, because it captures the so-called "dwell time" before discovery, where the adversary may be operating unnoticed. Lower MTTD directly reduces the opportunity for attackers to achieve their objectives by limiting the window of undetected access.

Why this answer

Mean time to detect (MTTD) is the metric that measures the average elapsed time between when a security incident actually occurs and when it is identified/detected by the organization. It is a core SOC efficiency metric.

Exam trap

CS0-004 often tests the confusion between MTTD, MTTR (respond), and MTTRem (remediate) — candidates mix up 'detect' with 'respond' because both are abbreviated MTTR in some frameworks.

How to eliminate wrong answers

Option A is wrong because patch SLA compliance measures the percentage of patches applied within a defined timeframe — it is a vulnerability management metric, not an incident detection metric. Option B is wrong because MTTRem (mean time to remediate) measures how long it takes to fix/contain an incident after detection, not how long detection takes. Option C is wrong because MTTR (mean time to respond) measures the time from detection to response actions — it starts after detection, so it does not capture identification time.

408
MCQhard

A hospital's IT department has been receiving reports from nursing staff that the electronic medical record (EMR) system is responding slowly during peak hours. The network team has verified that the local area network is operating normally and there is no bandwidth congestion. The security analyst reviews the firewall logs and observes repeated outbound connections from the EMR server to an external IP address 198.51.100.23 on TCP port 443 at regular 5-minute intervals. Each connection transfers a small amount of data. The analyst also notes that the EMR server's antivirus software is up to date and no malware has been detected. The hospital's security policy requires that all outbound connections from critical servers be explicitly approved. Further investigation reveals that 198.51.100.23 is associated with a hosting provider in a foreign country. The analyst suspects a data exfiltration. Which of the following actions should the analyst take FIRST?

A.Install a network-based intrusion detection system to monitor the server.
B.Capture and analyze the network traffic between the EMR server and the external IP.
C.Isolate the EMR server from the network and run a full forensic analysis.
D.Block all outbound traffic from the EMR server to the internet immediately.
AnswerB

Capturing and analyzing the network traffic between the EMR server and the external IP address is the most effective immediate step. This action allows security analysts to perform deep packet inspection, revealing the protocols, data payloads, and true intent of the communication. This critical evidence determines whether data exfiltration is occurring, what specific data is being sent, and if the connection is malicious or benign, enabling an informed and targeted response without premature disruption.

Why this answer

The analyst must first confirm whether the outbound connections are actually exfiltrating data or are legitimate (e.g., software updates, license checks). Capturing and analyzing the network traffic (e.g., using tcpdump or Wireshark) allows the analyst to inspect the payload and determine the nature of the data being sent, which is a standard step in incident response before taking more disruptive actions.

Exam trap

CompTIA often tests the principle of 'least disruption first' in incident response, where candidates mistakenly choose an aggressive containment action (like isolation or blocking) before gathering sufficient evidence to confirm the threat.

How to eliminate wrong answers

Option A is wrong because installing a network-based intrusion detection system (NIDS) is a long-term monitoring solution, not an immediate first step to investigate a suspected active exfiltration; it would not provide the specific payload analysis needed now. Option C is wrong because isolating the EMR server and running a full forensic analysis is too disruptive and premature without first confirming that the traffic is malicious; it could halt critical hospital operations unnecessarily. Option D is wrong because immediately blocking all outbound traffic from the EMR server could disrupt legitimate services (e.g., updates, cloud backups) and would destroy evidence of the ongoing communication before it can be analyzed.

409
MCQmedium

A security analyst is configuring a SIEM correlation rule to detect multiple failed login attempts followed by a successful login from the same source IP within a short time window. This pattern suggests a successful brute-force attack. Which of the following correlation types should the analyst use?

A.Thresholding
B.Sequential correlation
C.Aggregation
D.Time-based correlation
AnswerB

Sequential correlation is precisely engineered to identify a specific series of events occurring in a predefined order, often involving the same entity or asset within a specified time window. This type of rule is ideal for detecting complex attack patterns, such as multiple failed login attempts followed by a successful login from the same user or IP address, which could indicate a brute-force attack or credential stuffing. It explicitly requires Event A to happen *before* Event B, and so on, making it perfect for recognizing a 'pattern of failures followed by success.'

Why this answer

Sequential correlation is the correct choice because it detects a specific ordered sequence of events: multiple failed logins followed by a successful login from the same source IP within a defined time window. This pattern is characteristic of a brute-force attack, where an attacker attempts many passwords before succeeding. SIEM tools like Splunk or QRadar use sequential correlation to match event chains where the order matters, not just the count or aggregation of events.

Exam trap

The CS0-004 exam often tests the distinction between sequential correlation and aggregation, where candidates mistakenly choose aggregation because they focus on the 'multiple failed logins' count rather than the required ordered sequence of failures followed by a success.

How to eliminate wrong answers

Option A is wrong because thresholding triggers on a count of events exceeding a threshold (e.g., 10 failed logins) but does not require a subsequent successful login, missing the key pattern of a successful brute-force. Option C is wrong because aggregation groups events by a common attribute (e.g., source IP) but does not enforce an ordered sequence; it would flag any set of failed logins followed by a success even if the success occurred before the failures. Option D is wrong because time-based correlation simply matches events within a time window without requiring a specific order or sequence, so it could match a successful login followed by failed attempts, which is not the brute-force pattern.

410
MCQhard

Your organization has deployed a new web application on a Linux server. The application uses a custom database port (TCP 3307). During a routine vulnerability scan, the scanner reports a critical vulnerability: 'MySQL Server - Unrestricted File Upload (CVE-20XX-XXXX)'. The system administrator confirms that MySQL is not installed; the custom database uses PostgreSQL on port 3307. The scanner likely misidentified the service due to port-based fingerprinting. On further investigation, you find that the scanner's fingerprinting database has an incorrect mapping for port 3307. The PostgreSQL version is current and fully patched. The environment is production and cannot be disrupted. Which of the following is the BEST action to take?

A.Manually update the scanner's database to correct the port mapping.
B.Schedule an immediate patch of the supposed MySQL vulnerability.
C.Apply a workaround to block file upload functionality on port 3307.
D.Mark the vulnerability as a false positive and suppress it for this asset.
AnswerD

This is the correct action because the scanner has mistakenly identified a web application running on port 3307 as a MySQL database, leading to a false positive vulnerability report. Marking it as a false positive and suppressing it for this asset ensures that security teams are not distracted by irrelevant alerts, allowing them to focus on genuine threats and maintain an accurate vulnerability posture.

Why this answer

The vulnerability report is based on a false positive: the scanner misidentified the service on port 3307 as MySQL due to an incorrect port mapping in its fingerprinting database, while the actual service is a fully patched PostgreSQL. Since MySQL is not installed and no actual vulnerability exists, marking the finding as a false positive and suppressing it for this asset is the appropriate response in a production environment that cannot be disrupted.

Exam trap

CompTIA often tests the candidate's ability to distinguish between a true vulnerability and a false positive caused by service misidentification, trapping those who jump to patching or blocking without verifying the actual service running on the port.

How to eliminate wrong answers

Option A is wrong because manually updating the scanner's database is not a standard or recommended remediation action; scanner databases are vendor-managed, and manual edits could cause further inaccuracies or be overwritten on the next update. Option B is wrong because scheduling an immediate patch for a supposed MySQL vulnerability is unnecessary and potentially disruptive, as MySQL is not installed and the PostgreSQL service is fully patched—applying a non-existent patch wastes resources and may introduce risk. Option C is wrong because applying a workaround to block file upload functionality on port 3307 is irrelevant; PostgreSQL does not have an unrestricted file upload vulnerability, and blocking functionality would disrupt legitimate database traffic without addressing the actual scanner misidentification.

411
MCQmedium

After containing a ransomware incident, the incident response team is conducting post-incident activities. Which action is MOST important to prevent a similar attack in the future?

A.Sharing IOCs with other organizations via a threat intelligence platform
B.Reimaging all affected systems
C.Performing a root cause analysis and implementing remediation
D.Updating the incident response plan
AnswerC

Performing a root cause analysis (RCA) allows the incident response team to trace the attack path back to the initial point of entry and understand the vulnerabilities exploited. Implementing targeted remediation based on these findings—such as patching software, disabling unnecessary protocols, or enforcing multi-factor authentication—directly eliminates the security gaps. This is the only action that systematically prevents the same threat actor or campaign from recurring.

Why this answer

Conducting a root cause analysis identifies the underlying vulnerability or weakness that allowed the attack, enabling targeted remediation.

412
MCQhard

A development team wants to find vulnerable open-source libraries before deployment. Which control best fits this stage? For control selection, Which control best addresses the stated weakness without hiding risk?

A.Wireless spectrum analysis
B.Physical badge access reviews
C.Database transaction log backups
D.Software composition analysis in the CI/CD pipeline
AnswerD

Software composition analysis inventories open-source dependencies and their known CVEs, satisfying the requirement to find vulnerable libraries before deployment. Running it in the CI/CD pipeline blocks risky builds at the earliest feasible stage rather than after release.

Why this answer

Software composition analysis (SCA) is the correct control because it automatically scans the project's dependencies against known vulnerability databases (e.g., NVD, GitHub Advisory Database) to identify vulnerable open-source libraries before deployment. Integrating SCA into the CI/CD pipeline ensures that vulnerabilities are caught early in the development lifecycle, aligning with the shift-left security principle without suppressing or masking risk.

Exam trap

CompTIA often tests the distinction between vulnerability scanning (SCA) and other security controls like network monitoring or physical security, so the trap here is confusing a general security practice (e.g., backups or access reviews) with a specific software dependency scanning control that directly addresses the stated weakness.

How to eliminate wrong answers

Option A is wrong because wireless spectrum analysis (e.g., using tools like Wireshark or spectrum analyzers) is used to detect rogue access points or interference in wireless networks, not to identify vulnerable open-source libraries in code. Option B is wrong because physical badge access reviews control physical access to facilities, not software dependencies or code-level vulnerabilities. Option C is wrong because database transaction log backups are a data recovery and integrity control, unrelated to scanning for vulnerable open-source libraries in a development pipeline.

413
MCQhard

A scanner flags TLS 1.0 on a server, but the service owner says TLS 1.0 is disabled. What is the BEST validation method? For tool configuration, Which scanner or pipeline change most directly improves result quality?

A.Change the severity to informational automatically
B.Delete the server from the scan scope
C.Close the finding because the owner disagrees
D.Manually test the service with a TLS client or scanner profile that negotiates protocol versions
AnswerD

Negotiating protocol versions directly with a TLS client or version-aware scanner profile confirms whether TLS 1.0 is genuinely accepted, satisfying the need to validate the conflicting scanner finding. Passive inspection or configuration review cannot prove the listener's actual handshake behaviour.

Why this answer

The most reliable way to validate whether TLS 1.0 is truly disabled is to perform an active, negotiated test using a TLS client (e.g., OpenSSL s_client) or a scanner profile that explicitly attempts to connect using only TLS 1.0. This bypasses any potential misconfiguration in the scanner's service detection or version negotiation logic, and directly confirms whether the server accepts a TLS 1.0 handshake. Relying solely on the scanner's banner grab or the owner's assertion can miss cases where the server still supports the protocol on certain ports or under specific cipher suites.

Exam trap

CompTIA often tests the concept that scanner results must be validated through active, protocol-specific testing rather than relying on configuration assertions or passive detection, and the trap here is assuming that a service owner's claim or a scanner's default detection is sufficient without manual verification.

How to eliminate wrong answers

Option A is wrong because changing severity to informational does not resolve the underlying validation issue; it merely hides the finding and could mask a real vulnerability if TLS 1.0 is actually enabled. Option B is wrong because deleting the server from the scan scope removes all future visibility into that asset, which is an overreaction and prevents ongoing security monitoring. Option C is wrong because closing a finding solely because the owner disagrees violates the principle of independent validation; the scanner's result must be verified through technical means, not dismissed based on opinion.

414
Multi-Selectmedium

A security analyst is evaluating a Kubernetes cluster for misconfigurations. Which TWO of the following are common Kubernetes misconfigurations that increase security risk? (Select the two best answers.)

Select 2 answers
A.Running containers as non-root user
B.Using hostPath mounts
C.Using privileged containers
D.Enabling Role-Based Access Control (RBAC)
E.Implementing network policies to restrict traffic
AnswersB, C

hostPath mounts bind a node's filesystem directory into a pod, breaking container isolation. A compromised pod can then read or write node files, including credentials and the kubelet configuration, escalating beyond its namespace and undermining the cluster's security boundary.

Why this answer

Option B (Using hostPath mounts) is correct because a hostPath volume mounts a file or directory directly from the node's filesystem into the pod, allowing a compromised container to read or write sensitive node paths such as /etc, /var/run/docker.sock, or kubelet credentials, which can lead to node takeover or cluster compromise. Option C (Using privileged containers) is correct because a privileged container runs with essentially all Linux capabilities and full access to host devices and kernel interfaces (equivalent to --privileged), disabling isolation and enabling container escape and host compromise. Option A is not a misconfiguration but a security best practice, since running as non-root reduces privilege.

Option D is not a misconfiguration because enabling RBAC is a recommended access-control hardening measure. Option E is not a misconfiguration because network policies that restrict pod traffic reduce lateral movement and are a security best practice.

415
MCQmedium

A company uses a configuration management tool to enforce CIS Benchmarks on its servers. The security team wants to apply Level 1 benchmarks to all servers to achieve a baseline security posture. Which of the following best describes the difference between CIS Level 1 and Level 2 benchmarks?

A.Level 1 benchmarks are for Linux systems, while Level 2 benchmarks are for Windows systems.
B.Level 1 benchmarks are basic security measures that do not impact system performance, while Level 2 benchmarks are more restrictive and may affect performance or usability.
C.Level 1 benchmarks are for servers, while Level 2 benchmarks are for workstations.
D.Level 1 benchmarks are mandatory, while Level 2 benchmarks are optional.
AnswerB

CIS Benchmarks define Level 1 as the core set of security configurations that can be implemented without significantly degrading system functionality or causing incompatibility, making them suitable for most environments. Level 2 extends these settings with more aggressive hardening, such as disabling legacy protocols or tightening file permissions, which may reduce performance, break existing workflows, or require additional operational overhead. This performance-versus-restriction trade-off is the intended distinction.

Why this answer

CIS Benchmarks define Level 1 as essential, basic security settings that can be applied broadly with minimal impact on functionality or performance, making them suitable as a universal baseline. Level 2 settings are defense-in-depth measures intended for high-security environments; they are more restrictive and may degrade performance or break usability (e.g., disabling legacy protocols or enforcing strict password policies). The question's goal of a baseline posture maps directly to Level 1.

Exam trap

The trap is conflating the Level 1/Level 2 distinction with OS or device-type categories; candidates who haven't read the CIS documentation assume the levels map to platform tiers.

How to eliminate wrong answers

Option A is wrong because CIS Benchmarks are OS- and application-specific (there are separate benchmarks for Linux distros, Windows Server, macOS, etc.), and both Level 1 and Level 2 exist within each benchmark — the levels are not split by operating system. Option C is wrong because the Level 1/Level 2 distinction is about security strictness, not device role; both levels apply to servers and workstations within their respective benchmarks. Option D is wrong because neither level is 'mandatory' in a regulatory sense — they are recommendations, and organizations choose which profile to apply based on risk tolerance and operational constraints.

416
MCQmedium

During a traffic analysis, a security analyst observes repeated outbound connections from an internal workstation to an external IP address on TCP port 53 at irregular intervals. The connections are small and occur every few minutes. Which technique is most likely being used?

A.HTTP smuggling
B.TCP handshake anomaly
C.DNS tunneling
D.Beaconing
AnswerC

DNS tunneling encapsulates non-DNS traffic, such as SSH, HTTP, or proprietary data exfiltration protocols, within DNS queries and responses. While standard DNS queries typically utilize UDP port 53, attackers frequently fall back to or abuse TCP port 53 to bypass standard UDP-based inspection filters and transmit larger payloads or maintain persistent, stateful connection channels.

Why this answer

DNS normally uses UDP, but TCP port 53 can be used for DNS tunneling. The small, irregular connections to a single external IP suggest data exfiltration via DNS tunneling.

417
MCQmedium

A CASB alert indicates that a user downloaded a file containing sensitive data from a cloud app to an unmanaged device. Which action should the analyst take first?

A.Report the incident to law enforcement
B.Reset the user's password
C.Block the user's cloud app access
D.Investigate the alert to confirm the data exfiltration
AnswerD

The first phase of the incident response lifecycle following detection is analysis and validation. Analysts must investigate the CASB alert to rule out false positives, determine the classification of the downloaded file, and verify whether the activity constitutes actual unauthorized data exfiltration before initiating containment or eradication protocols.

Why this answer

The first step is to verify the alert is a true positive by checking the user's activity and the file's sensitivity. Prematurely blocking or reporting may be incorrect if the alert is a false positive.

418
MCQeasy

A security dashboard is being designed for the executive team. Which metric is MOST appropriate to display?

A.Current CPU utilization on firewalls
B.Overall risk posture score with trend over time
C.Patch installation status of all endpoints
D.Number of IDS alerts per hour
AnswerB

This metric offers a high-level, aggregated view of the organization's current security health, synthesizing various underlying security controls and vulnerabilities into a single, comprehensible score. Presenting this score with a trend over time allows executives to quickly grasp whether security efforts are improving or deteriorating, enabling strategic resource allocation and risk management decisions aligned with business objectives. It directly addresses the strategic need for understanding enterprise-wide risk.

Why this answer

The executive team requires a high-level, strategic view of security effectiveness, not granular operational data. The overall risk posture score with trend over time directly communicates the organization's security health and whether it is improving or deteriorating, enabling informed decision-making. This aligns with the Reporting and Communication domain's emphasis on translating technical metrics into business-relevant insights.

Exam trap

CompTIA often tests the distinction between operational metrics (for technical teams) and strategic metrics (for executives), and the trap here is that candidates mistake a detailed, operational metric like patch status or alert counts as appropriate for an executive dashboard, ignoring the need for aggregated, trended risk visibility.

How to eliminate wrong answers

Option A is wrong because current CPU utilization on firewalls is an operational metric relevant to network engineers for troubleshooting performance issues, not a strategic indicator for executives. Option C is wrong because patch installation status of all endpoints is a detailed, tactical metric that belongs in IT operations or vulnerability management dashboards, not an executive summary. Option D is wrong because the number of IDS alerts per hour is a raw, high-volume data point that lacks context and would overwhelm executives; it requires correlation and analysis to be meaningful.

419
MCQmedium

During a web application security assessment using OWASP ZAP, a tester identifies that the application reflects user input in HTTP responses without proper encoding. Which OWASP Top 10 vulnerability category does this finding most likely belong to?

A.Broken Access Control
B.Cryptographic Failures
C.Security Misconfiguration
D.Injection
AnswerD

Injection occurs when untrusted user input is directly interpreted as code by an interpreter. Cross-Site Scripting (XSS) is a specific type of injection vulnerability where malicious scripts are injected into benign and trusted websites. During an OWASP ZAP assessment, the tool identifies this by injecting payload strings and verifying if they execute within the context of the victim's browser session.

Why this answer

Reflected user input in responses without encoding is a classic sign of Cross-Site Scripting (XSS), which falls under injection in OWASP Top 10 (though XSS is specifically listed as a separate category in some versions, but in 2021 it is under injection).

420
Multi-Selectmedium

When briefing legal and privacy teams after a suspected data exposure, which details matter? (Choose two.)

Select 2 answers
A.Data types and jurisdictions potentially affected
B.A complete list of unrelated server patches
C.Speculation about attacker identity without evidence
D.Timeline of discovery, containment, and known access
AnswersA, D

Legal and privacy teams must determine regulatory notification obligations, which are strictly dictated by the specific categories of data compromised (such as PII, PHI, or PCI) and the geographic locations of the affected data subjects. Providing this information allows counsel to accurately assess compliance with frameworks like GDPR, CCPA, or HIPAA.

Why this answer

Data types (e.g., PII, PHI, PCI) and affected jurisdictions determine legal notification obligations under regulations like GDPR, HIPAA, or CCPA. Jurisdictions dictate breach notification timelines and penalties, making this information critical for legal and privacy teams to assess risk and compliance. Without this detail, the response cannot be properly scoped or legally defensible.

Exam trap

The CS0-004 exam often tests the distinction between operational details (like patch lists) and legally relevant information (data types and jurisdictions), trapping candidates who think all technical details are equally important for legal teams.

421
Multi-Selecteasy

A security analyst is reviewing alerts from an IDS. Which TWO indicators are most likely to suggest a successful command and control (C2) communication? (Choose two.)

Select 2 answers
A.An inbound connection from a known malicious IP to the mail server
B.A high volume of outbound traffic to an unusual destination IP on port 443
C.A single large file upload to a cloud storage service
D.An internal host performing a DNS query for a known malicious domain
E.Regular beaconing activity to an external IP with consistent payload sizes
AnswersB, E

A high volume of outbound traffic directed to an unusual or previously unseen external IP address, especially over port 443, is a strong indicator of potential command-and-control (C2) activity or data exfiltration. Attackers frequently use port 443 to masquerade malicious traffic as legitimate HTTPS, blending in with normal web browsing to evade detection. The sheer volume and unusual destination suggest more than typical user activity, pointing towards a compromised internal host communicating with an external controller.

Why this answer

Option B is correct because sustained outbound traffic to an unusual external IP over port 443 is a classic C2 indicator: attackers frequently tunnel C2 over HTTPS (TCP 443) to blend with legitimate web traffic, and the destination being atypical for the environment raises suspicion. Option E is correct because regular beaconing to an external IP with consistent payload sizes reflects the periodic check-in pattern used by implants (e.g., fixed intervals with jitter and uniform packet sizes), which is a hallmark of established C2 channels. Option A does not belong because an inbound connection from a malicious IP to a mail server suggests scanning, exploitation, or spam relay activity rather than an internal host initiating C2.

Option C does not belong because a single large upload to cloud storage is more indicative of data exfiltration than C2, and cloud storage is a legitimate service. Option D does not belong because a DNS query for a malicious domain indicates possible resolution or attempted contact, but a single query alone does not demonstrate the sustained, bidirectional communication characteristic of successful C2.

Exam trap

The CS0-004 exam often tests the distinction between attempted and successful C2 communication, where candidates mistakenly choose indicators like DNS queries or inbound connections as proof of success, but only outbound beaconing or sustained data transfer on unusual ports confirms an established C2 channel.

422
MCQmedium

An organization is implementing a patch management process for servers. Which of the following is a crucial step that should be performed before deploying patches to production servers?

A.Immediately apply the patch to all systems to minimize exposure
B.Review the CVSS score to decide if the patch is necessary
C.Verify patch compliance by checking the vendor's advisory
D.Test the patch in a staging environment that closely mirrors production
AnswerD

Validating the patch in a dedicated staging environment that replicates production configurations allows administrators to identify potential software conflicts, performance degradation, or deployment failures. This isolated testing ensures that the update can be safely applied to production systems without disrupting critical business operations.

Why this answer

Before deploying patches to production servers, the critical step is to test the patch in a staging environment that closely mirrors production, because patches can introduce regressions, break application compatibility, or cause unexpected downtime. Testing in staging validates that the patch works correctly with the organization's specific configurations, dependencies, and workloads before it affects live systems. This is a foundational principle of change management and patch management frameworks.

Exam trap

The trap is the urgency bias — candidates feel pressure to 'patch immediately to reduce exposure' and pick option A, forgetting that untested patches can cause outages that are just as damaging as the vulnerability itself. The exam tests whether you prioritize controlled change management over reflexive urgency.

How to eliminate wrong answers

Option A is wrong because immediately applying patches to all systems without testing is reckless — it maximizes the risk of widespread outages or application failures if the patch is faulty or incompatible, violating change-management best practices. Option B is wrong because reviewing the CVSS score helps prioritize which patches to apply first, but it does not replace the need to test the patch before production deployment — CVSS measures severity, not compatibility. Option C is wrong because verifying patch compliance by checking the vendor's advisory confirms the patch exists and is legitimate, but it does not validate that the patch will function correctly in the organization's environment.

423
MCQmedium

During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?

A.The specific malware used and its technical attributes
B.The names of the IT staff who first detected the incident
C.A step-by-step timeline of the incident response actions taken so far
D.The financial impact, reputational risk, and potential regulatory penalties
AnswerD

For a board of directors, information regarding the financial impact, potential reputational damage, and regulatory penalties is paramount because these directly relate to their fiduciary duties and the long-term strategic health of the organization. Understanding the monetary losses, the erosion of public trust, and the legal ramifications enables the board to assess the overall business risk effectively. This critical information guides their strategic decisions on resource allocation, risk mitigation strategies, and governance improvements to protect shareholder value and ensure compliance.

Why this answer

When communicating with the board of directors during a data breach, the most important aspects are the business impact: financial loss, reputational damage, and potential regulatory fines. Board members are concerned with strategic and financial implications, not technical details. Emphasizing these areas helps them make informed decisions and allocate resources appropriately.

Exam trap

The trap is focusing on technical details instead of business impact. Candidates might think the board wants to know how the breach happened, but they care more about the consequences and mitigation.

How to eliminate wrong answers

Option A is wrong because the specific malware and its technical attributes are too granular for a board-level audience; they need impact, not technical indicators. Option B is wrong because naming IT staff who detected the incident is irrelevant to the board's decision-making and could unfairly assign blame. Option C is wrong because a step-by-step timeline of response actions, while useful for operational reviews, is too detailed for a board communication; they need a high-level summary of impact and response effectiveness.

424
Multi-Selecthard

During a forensic investigation, an analyst must preserve evidence in accordance with forensic sound procedures. Which THREE of the following practices should the analyst follow? (Select THREE.)

Select 3 answers
A.Run a full antivirus scan on the target drive
B.Document all actions taken in a chain of custody form
C.Use a write blocker when imaging a hard drive
D.Create a cryptographic hash of the original media before imaging
E.Boot the system to ensure it is operational
AnswersB, C, D

Maintaining a complete chain of custody form is essential because it documents every interaction with the evidence — who collected it, when, where, and how it was handled, transferred, and secured. In court, opposing counsel will attack a gap in this record as evidence tampering or mishandling. A continuous, written log of all actions taken during acquisition and analysis preserves the integrity narrative and is what makes the forensic evidence legally admissible.

Why this answer

Option B is correct because maintaining a chain of custody form that documents every action, transfer, and access of the evidence is essential for forensic soundness and admissibility in court. Option C is correct because a write blocker prevents any modification to the original hard drive during imaging, preserving the integrity of the evidence. Option D is correct because creating a cryptographic hash (e.g., MD5 or SHA-256) of the original media before imaging provides a verifiable baseline to prove the image is an exact copy and that the original was not altered.

Option A is not appropriate because running an antivirus scan modifies the drive (e.g., quarantining or deleting files), which violates forensic soundness. Option E is not appropriate because booting the system can alter the state of the drive (e.g., changing timestamps, creating temporary files), compromising evidence integrity.

Exam trap

The trap is that options A and E sound like reasonable 'verification' steps, but CompTIA expects candidates to recognize that any action altering the original media — including antivirus scans or booting — violates forensic soundness.

425
MCQeasy

A security analyst receives an alert about a possible ransomware outbreak. Which short-term containment action should be performed FIRST to prevent further spread?

A.Disable the user account
B.Rebuild the system
C.Update antivirus signatures
D.Isolate the system from the network
AnswerD

Isolating the affected host from the network is the primary containment step during a ransomware incident. This action immediately halts the propagation of the malware to other network segments, prevents the encryption of mapped network shares, and severs command-and-control (C2) communications required for key exchange.

Why this answer

Network isolation (disconnecting the affected system from the network) is a quick short-term containment step that stops the ransomware from communicating with C2 or spreading laterally.

426
MCQeasy

A company's IDS generated an alert for a SQL injection attempt against a web server. The web application firewall (WAF) is already in place. What is the best action?

A.Update the WAF rules
B.Block the source IP at the firewall
C.Shut down the web server
D.Verify if the attack succeeded by checking server logs
AnswerD

An IDS only detects; the WAF may have blocked the attempt or it may have succeeded. Checking server and database logs confirms whether the injection actually executed, which determines whether this is a true incident requiring response or a blocked attempt to document.

Why this answer

When an IDS alerts on a SQL injection attempt against a web server that already has a WAF, the WAF may have blocked it — but you cannot assume that. The best next step is to verify whether the attack succeeded by inspecting web server, application, and database logs for evidence of successful injection (e.g., unexpected queries, error messages, data exfiltration). Confirming impact drives the correct response and avoids unnecessary or disruptive actions.

Exam trap

CS0-004 often tests the misconception that the first response to an IDS alert is to block or update defenses — candidates must remember that verifying whether the attack succeeded (impact analysis) precedes containment or rule changes.

How to eliminate wrong answers

Option A is wrong because updating WAF rules is premature — you do not yet know if the existing rules failed or if the attack was blocked; rule changes should follow evidence. Option B is wrong because blocking the source IP at the firewall is a containment action that may be appropriate later, but without confirming the attack succeeded, it could be a false positive and waste effort or block legitimate traffic. Option C is wrong because shutting down the web server is a drastic, service-impacting action that is not justified before confirming a successful compromise.

427
MCQmedium

A cloud posture scan finds a storage bucket with public read access containing customer exports. What should the team do first? For tool configuration, Which scanner or pipeline change most directly improves result quality?

A.Restrict public access and determine whether sensitive data was accessed
B.Wait for the next quarterly review
C.Rotate database administrator passwords only
D.Delete all audit logs to reduce liability
AnswerA

The priority is exposure containment and impact assessment.

Why this answer

The immediate priority is to stop the data leak by restricting public read access to the storage bucket, then investigate whether sensitive data was actually accessed. This aligns with the incident response principle of containment before analysis. In cloud environments like AWS S3 or Azure Blob Storage, a bucket with public read access exposes all objects to the internet, and the first step is to apply a bucket policy or ACL to deny public access.

Exam trap

The CS0-004 exam often tests the misconception that rotating credentials (like database passwords) is a catch-all fix for data exposure, but the trap here is that the vulnerability is a misconfigured storage bucket, not compromised credentials, so the correct first step is to restrict public access and assess exposure.

How to eliminate wrong answers

Option B is wrong because waiting for the next quarterly review leaves sensitive customer data exposed to the internet for an extended period, violating data protection regulations and incident response best practices. Option C is wrong because rotating database administrator passwords does not address the root cause—a misconfigured storage bucket with public read access—and is an irrelevant action for this specific vulnerability.

428
Multi-Selectmedium

Which evidence helps distinguish a true brute-force attack from a misconfigured service account? (Choose two.)

Select 2 answers
A.The number of monitors used by the administrator
B.Source distribution and timing of failed logons
C.Whether one service account repeatedly fails after a password change
D.The brand of the office router only
AnswersB, C

Analyzing the source distribution and timing of failed logons is critical for identifying a brute-force attack. A true brute-force often manifests as numerous failed attempts originating from a single or a small cluster of external IP addresses within a short, rapid timeframe, or from a distributed set of IPs attempting a dictionary attack. Conversely, legitimate user errors typically show fewer attempts, slower timing, and originate from expected internal sources. These patterns help differentiate malicious activity from simple user mistakes or misconfigurations.

Why this answer

A true brute-force attack typically originates from multiple source IP addresses or a single source with a high frequency of failed logons over a short time window, whereas a misconfigured service account usually fails from a consistent source at regular intervals. Analyzing the source distribution and timing of failed logons helps distinguish automated attack patterns from predictable service account behavior, such as retry intervals defined in application configuration.

Exam trap

The CS0-004 exam often tests the misconception that any repeated failed logon after a password change is evidence of an attack, when in fact it is a classic symptom of a misconfigured service account that has not been updated with the new credentials.

429
Multi-Selectmedium

Which three metrics are commonly used to measure the effectiveness of a security operations center (SOC)? (Select THREE.)

Select 3 answers
A.Number of firewall rules
B.Number of employees in the SOC
C.Mean Time to Respond (MTTR)
D.Mean Time to Remediate (MTTRem)
E.Mean Time to Detect (MTTD)
AnswersC, D, E

Mean Time to Respond (MTTR) quantifies how quickly a SOC team takes action to contain an incident after detection. It typically measures the interval between alert triage and the first mitigation step (e.g., isolating a host, blocking a C2 domain), directly reflecting the team's readiness and playbook efficiency. Lower MTTR indicates faster containment, which reduces the attacker's dwell time and prevents lateral movement.

Why this answer

Option C, Mean Time to Respond (MTTR), is correct because it measures how quickly the SOC reacts to a validated incident after detection, directly reflecting operational responsiveness. Option D, Mean Time to Remediate (MTTRem), is correct because it captures how long it takes to fully resolve or contain the threat, showing the SOC's effectiveness in restoring normal operations. Option E, Mean Time to Detect (MTTD), is correct because it measures the time from the initial compromise or event to detection, which is a core indicator of monitoring and detection capability.

Options A and B are not correct: the number of firewall rules is a configuration or hygiene metric rather than a SOC performance measure, and the number of SOC employees is a staffing/resource metric, not an effectiveness outcome.

Exam trap

CS0-004 often tests the confusion between SOC performance metrics (MTTD, MTTR, MTTRem) and vanity metrics (number of rules, staff count), tempting candidates to select operational or staffing counts as effectiveness measures.

430
Multi-Selecthard

Which TWO of the following are indicators of potential data exfiltration via DNS?

Select 2 answers
A.Unusual TLS handshake patterns
B.Traffic to known malicious IPs over HTTP
C.Large number of NXDOMAIN responses
D.High volume of TXT record queries
E.Frequent queries to long subdomains
AnswersD, E

Attackers frequently abuse DNS TXT records because they can hold large, arbitrary strings of text, making them ideal for carrying payload data or receiving commands. A sudden spike in TXT queries, especially to unfamiliar external domains, strongly suggests that an internal host is using these records to bypass traditional firewalls and exfiltrate sensitive data.

Why this answer

TXT records are commonly used in DNS tunneling to encode exfiltrated data. Attackers embed data in TXT record queries or responses, and a high volume of such queries is a strong indicator of data exfiltration via DNS.

Exam trap

CompTIA often tests the distinction between DNS tunneling indicators (TXT record volume and long subdomains) and other DNS anomalies like NXDOMAIN responses, which are more associated with DGA or reconnaissance rather than exfiltration.

431
MCQeasy

In a regulated payment environment, an incident was contained successfully, but delayed escalation allowed the attacker more dwell time. What should the post-incident review produce? During eradication, which decision is most defensible? which action best reduces risk without losing evidence?

A.A generic statement that security is important
B.Deletion of all incident tickets
C.A blame list of individual analysts
D.Specific playbook updates, escalation triggers, owners, and due dates
AnswerD

Lessons learned should translate findings into trackable process improvements. In eradication, responders need action that reduces risk while preserving the investigation record.

Why this answer

It addresses all three aspects implicitly. A post-incident review in a regulated payment environment must produce actionable improvements (specific playbook updates, escalation triggers, owners, due dates) to prevent recurrence and reduce dwell time. During eradication, the most defensible decision is to follow the updated playbook, ensuring actions are documented and repeatable.

The action that reduces risk without losing evidence is to implement defined escalation triggers and owners, ensuring prompt containment while preserving forensic data—avoiding deletion or blame.

Exam trap

The CS0-004 exam often tests the misconception that post-incident reviews are about assigning blame or deleting evidence, rather than focusing on process improvement and evidence preservation.

How to eliminate wrong answers

Option A is wrong because a generic statement that security is important provides no measurable, actionable steps to fix the identified procedural gap, and would fail audit scrutiny in a regulated environment. Option B is wrong because deletion of all incident tickets violates evidence preservation requirements under regulations like PCI DSS and GDPR, and destroys the forensic trail needed for root cause analysis and legal proceedings. Option C is wrong because a blame list of individual analysts creates a punitive culture that discourages reporting and collaboration, and does not address the systemic process failure that allowed delayed escalation.

432
MCQmedium

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a finance workstation to a known malicious IP address at 2:00 AM. The analyst checks the firewall logs and sees a single connection. Which action should the analyst take FIRST according to NIST SP 800-61?

A.Validate the incident by reviewing additional data sources.
B.Run a full antivirus scan on the workstation.
C.Isolate the workstation from the network immediately.
D.Notify law enforcement per the incident response plan.
AnswerA

Validating the incident is the crucial initial step in the detection and analysis phase. This involves corroborating the initial alert by reviewing additional data sources such as logs from firewalls, intrusion detection systems, endpoint detection and response (EDR) tools, and network flow data. This process helps to confirm if the alert represents a true security incident, thereby minimizing false positives and preventing the premature allocation of valuable incident response resources to non-threats.

Why this answer

NIST SP 800-61 emphasizes that during detection and analysis, the first step is to validate the incident as a true positive before escalating or containing. The analyst should confirm the alert is not a false positive by gathering additional evidence.

433
MCQhard

An organization's compliance dashboard shows a control effectiveness score of 85%. Which type of evidence best supports this score?

A.Incident response logs
B.Employee training records
C.Vendor documentation
D.Penetration test results and audit reports
AnswerD

Penetration test results and formal audit reports offer objective, empirical validation of how controls perform under active duress or systematic evaluation. These assessments actively test defenses and verify regulatory compliance, providing the concrete evidence needed to populate a control effectiveness dashboard.

Why this answer

A control effectiveness score of 85% reflects how well implemented controls are actually performing against their intended objectives. Penetration test results and audit reports provide direct, independent evidence of whether controls are functioning as designed—pen tests actively attempt to bypass controls, while audits verify their operational status. These sources offer the most objective and comprehensive validation of control effectiveness, making them the best evidence to support such a score.

Exam trap

CS0-004 often tests the distinction between evidence of control existence versus evidence of control effectiveness, causing candidates to select training records or vendor documentation that only prove a control is in place, not that it works.

How to eliminate wrong answers

Option A is wrong because incident response logs only show events that triggered a response; they do not measure the overall effectiveness of preventive or detective controls across the environment. Option B is wrong because employee training records only indicate completion of awareness training, which is a single administrative control and does not provide evidence of technical or operational control effectiveness. Option C is wrong because vendor documentation describes what a product or service is supposed to do, not whether the organization's implemented controls are actually working effectively.

434
MCQmedium

A security analyst receives an alert from the HIDS indicating that a critical configuration file was modified unexpectedly. What is the best immediate action?

A.Ignore the alert as HIDS false positives are common
B.Immediately revert the file and block any similar changes
C.Check the change management system to see if the change was approved
D.Restore the file from a known good backup
AnswerC

Checking the change management system is the most appropriate initial step because it directly addresses the legitimacy of the HIDS alert. This action allows the analyst to quickly determine if the detected file modification was an authorized, pre-approved change or an unauthorized, potentially malicious event. Validating against a known baseline of approved changes is crucial for efficient and accurate incident triage, preventing unnecessary escalation for legitimate activities.

Why this answer

The best immediate action when a HIDS alerts on a critical configuration file change is to first verify whether the change was authorized through the change management system. This aligns with the incident response process of validation before remediation; reverting or restoring without checking could disrupt approved maintenance or patch deployments. HIDS monitors file integrity via checksums (e.g., SHA-256), but it cannot distinguish approved changes from malicious ones without external context.

Exam trap

The CS0-004 exam often tests the principle that immediate remediation (reverting or restoring) is not the best first step; candidates mistakenly jump to containment actions without validating whether the change was authorized, confusing incident response speed with due diligence.

How to eliminate wrong answers

Option A is wrong because ignoring HIDS alerts on critical configuration files is negligent; while false positives can occur, dismissing them without investigation violates security operations best practices and could allow a breach to go undetected. Option B is wrong because immediately reverting the file and blocking changes is premature and could undo an authorized change (e.g., a scheduled security patch or configuration update), potentially causing service disruption or compliance issues. Option D is wrong because restoring from a known good backup is a remediation step that should only be taken after confirming the change was unauthorized; doing so without checking change management could overwrite legitimate modifications and lose audit trail data.

435
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from an internal IP address to a domain controller at 3:00 AM. The user associated with the account is on vacation. Which classification best describes this alert?

A.False positive
B.False negative
C.True negative
D.True positive
AnswerD

A true positive occurs when a security monitoring tool correctly identifies and alerts on actual malicious or unauthorized activity. In this case, the SIEM alert successfully flagged a genuine security event that requires analyst triage and incident response. Validating true positives is a fundamental step in the incident handling lifecycle before escalating to containment.

Why this answer

The alert is triggered by a real failed login attempt from an internal IP, but the user is on vacation, so it likely indicates a malicious attempt. Since it is a confirmed security incident, it is a true positive.

436
MCQhard

During a threat hunting exercise, an analyst formulates a hypothesis that an attacker may be using DNS tunneling to exfiltrate data. Which data source would provide the best evidence to confirm or deny this hypothesis?

A.Firewall logs showing allowed outbound connections
B.NetFlow records from the border router
C.EndPoint detection and response (EDR) logs showing DNS client activity
D.Deep packet inspection (DPI) of DNS traffic
AnswerD

Deep Packet Inspection (DPI) involves a thorough examination of the entire network packet, including its application-layer payload, not just the header information. When applied to DNS traffic, DPI can analyze the full content of DNS queries and responses, such as unusually long domain names, non-standard record types, or encoded data within these fields. This capability is essential for identifying the subtle anomalies and data patterns indicative of DNS tunneling, where data is covertly embedded.

Why this answer

Deep packet inspection (DPI) of DNS traffic is the best evidence because DNS tunneling works by encoding data within DNS queries and responses, often using non-standard record types (e.g., TXT, NULL) or unusually long domain names. DPI can decode the payload within DNS packets to reveal hidden data, whereas other methods only see metadata or connection summaries. This allows the analyst to directly inspect the content of DNS messages for signs of exfiltration, such as base64-encoded data or anomalous query patterns.

Exam trap

The CS0-004 exam often tests the misconception that NetFlow or firewall logs are sufficient for detecting data exfiltration, when in reality only deep packet inspection can reveal the payload content necessary to confirm DNS tunneling.

How to eliminate wrong answers

Option A is wrong because firewall logs showing allowed outbound connections only indicate that traffic passed through the firewall, not the content or structure of DNS packets; they cannot reveal whether data is being tunneled within DNS. Option B is wrong because NetFlow records from the border router provide metadata such as source/destination IPs, ports, and byte counts, but they lack the payload-level detail needed to detect encoded data inside DNS queries or responses. Option C is wrong because EDR logs showing DNS client activity typically record process-level events (e.g., which process made a DNS query) but do not capture the full DNS packet payload, making them insufficient to identify tunneling without additional deep inspection.

437
MCQmedium

A security analyst is triaging an alert indicating that a user's workstation has been infected with ransomware. The file server shows signs of encryption. The analyst needs to contain the incident. Which action should the analyst take FIRST to minimize damage?

A.Running a full antivirus scan on the workstation
B.Disabling the user's Active Directory account
C.Rebuilding the workstation from a known good image
D.Disconnecting the workstation from the network
AnswerD

Disconnecting the workstation from the network is the most immediate and effective short-term containment action for an active ransomware infection. This action physically isolates the compromised system, preventing the ransomware from communicating with command-and-control servers, exfiltrating data, or attempting to spread laterally to other network resources, shares, or systems. It buys critical time for incident responders to analyze the threat and plan further remediation steps without risking wider network compromise, thus limiting the overall impact of the incident.

Why this answer

Disconnecting the infected workstation from the network stops the ransomware from spreading to other systems via network shares.

438
Multi-Selecthard

Which signals strengthen an alert for Kerberoasting activity? (Choose two.)

Select 2 answers
A.Unusual volume of TGS requests for many service principals
B.Requests from a workstation that does not normally administer services
C.A user changing their desktop wallpaper
D.Successful DHCP lease renewal
AnswersA, B

Kerberoasting relies on requesting Ticket Granting Service (TGS) tickets for Active Directory service accounts to crack their passwords offline. An unusual spike in TGS requests across multiple distinct Service Principal Names (SPNs) from a single user account is a strong indicator of an attacker scanning and harvesting tickets for offline brute-force attacks.

Why this answer

Kerberoasting involves requesting Ticket-Granting Service (TGS) tickets for service principals (SPNs) to crack their passwords offline. An unusual volume of TGS requests for many SPNs is a strong indicator because attackers typically enumerate SPNs and request tickets in bulk, which deviates from normal user behavior.

Exam trap

The CS0-004 exam often tests the distinction between benign user actions (like wallpaper changes) and actual Kerberos-related attack indicators, trapping candidates who confuse general system changes with authentication-specific anomalies.

439
MCQhard

A laptop may contain evidence for a legal investigation. What should the responder document during acquisition? During post-incident improvement, which decision is most defensible?

A.Only the laptop colour
B.Only the ticket priority
C.Only the user's job title
D.Who collected it, when, where, hash values, transfer details, and storage location
AnswerD

Chain of custody records evidence handling and integrity from collection onward. In post-incident improvement, responders need action that reduces risk while preserving the investigation record.

Why this answer

Proper chain of custody documentation is critical for evidence admissibility in legal proceedings. The responder must record who collected the evidence, the exact date and time, the physical location, cryptographic hash values (e.g., SHA-256) to verify integrity, transfer details (e.g., chain-of-custody forms), and the secure storage location. This ensures the evidence is not tampered with and can be defended in court.

For the post-incident improvement phase, the most defensible decision is to formalize and enforce the same comprehensive documentation procedures based on lessons learned, thereby strengthening the overall incident response process and ensuring evidence integrity in future investigations.

Exam trap

The CS0-004 exam often tests the misconception that only superficial details (like colour or job title) are sufficient for documentation, when in fact the full chain of custody—including collector identity, timestamps, hashes, and storage—is mandatory for evidence admissibility.

How to eliminate wrong answers

Option A is wrong because documenting only the laptop colour provides no forensic value—it does not establish chain of custody, integrity, or provenance of the evidence. Option B is wrong because the ticket priority is an administrative metric unrelated to forensic acquisition; it does not help prove the evidence was handled properly or securely. Option C is wrong because the user's job title is irrelevant to the technical acquisition process; it does not record who collected the evidence, when, or how it was preserved.

440
MCQmedium

An incident responder is called to a server room where a critical database server is exhibiting signs of compromise. The responder must preserve evidence while preventing further damage. Which of the following is a short-term containment strategy that also preserves evidence?

A.Reboot the server into safe mode.
B.Disconnect the network cable from the server.
C.Power off the server to freeze the system state.
D.Run a memory dump with WinPmem before any action.
AnswerB

Disconnecting the network cable immediately isolates the compromised server from the network, preventing further malicious activity such as data exfiltration, lateral movement, or command-and-control communication. This crucial containment step preserves the current volatile system state for subsequent forensic acquisition without introducing significant changes, allowing for a more accurate investigation.

Why this answer

Disconnecting the network cable (Option B) is the correct short-term containment strategy because it immediately isolates the compromised database server from the network, preventing further lateral movement or data exfiltration, while preserving the volatile system state (memory, running processes, open network connections) for forensic analysis. This action stops active network-based attacks without altering the contents of RAM or disk, which is critical for evidence integrity.

Exam trap

In the CompTIA CySA+ exam, the trap is that candidates may select Option C (power off) thinking it 'freezes' the state, but this destroys volatile evidence and does not contain the incident if the attacker has remote access. Option D (memory dump) is a forensic step, not containment. Option A (reboot) modifies the system.

Only Option B isolates while preserving volatile data.

How to eliminate wrong answers

Option A is wrong because rebooting into safe mode will overwrite volatile memory (RAM) and modify system logs, destroying critical forensic evidence such as active network connections, running malware processes, and encryption keys. Option C is wrong because powering off the server causes a hard shutdown that erases all volatile memory data and may trigger anti-forensic mechanisms (e.g., self-deleting scripts), losing the most time-sensitive evidence. Option D is wrong because running a memory dump with WinPmem before any containment action is a forensic acquisition step, not a containment strategy; it takes time and does not stop ongoing damage or network-based attacks.

441
MCQeasy

A DAST scan cannot reach authenticated pages of a web application and reports only public content findings. What should be configured? For tool configuration, Which scanner or pipeline change most directly improves result quality?

A.Authenticated scanning with a test account and session handling
B.Reduce the scan to only the landing page
C.Disable all application authentication
D.Treat absence of findings as proof of security
AnswerA

The DAST scanner only crawls unauthenticated content, so it never reaches pages behind login. Configuring authenticated scanning with a test account and session handling lets the scanner maintain a valid session and crawl restricted areas, directly improving coverage and finding quality.

Why this answer

DAST scanners analyze live web applications by sending HTTP requests and inspecting responses. When authentication is required to access protected pages, the scanner must maintain a valid session to reach those endpoints. Configuring authenticated scanning with a test account and proper session handling (e.g., using cookies, tokens, or form-based login) allows the scanner to traverse authenticated pages, ensuring the scan covers the full attack surface and reports findings from restricted areas.

Exam trap

The CS0-004 exam often tests the misconception that disabling authentication or reducing scope is an acceptable workaround, when the correct approach is to configure the scanner to properly handle the existing authentication mechanism.

How to eliminate wrong answers

Option B is wrong because reducing the scan to only the landing page would intentionally ignore all other pages, including authenticated ones, which directly contradicts the goal of improving result quality by reaching more content. Option C is wrong because disabling all application authentication would fundamentally alter the application's security posture, potentially breaking business logic and causing the scanner to test a non-representative environment, rather than properly handling the existing authentication mechanism.

442
MCQeasy

Which of the following is the BEST description of configuration drift?

A.A planned change to a system's configuration
B.The process of reverting a system to its baseline configuration
C.The gradual deviation of a system's configuration from the intended baseline
D.A vulnerability that is patched and then reappears
AnswerC

Configuration drift is the gradual and often unnoticed deviation of a system's current configuration from its intended, documented baseline. It results from incremental changes such as manual edits, emergency fixes, unpatchable workarounds, or inconsistent patch deployments that accumulate over time without change-control approval. This divergence can lead to security weaknesses, compliance violations, and unpredictable behavior, making it a central concern for configuration management.

Why this answer

Configuration drift refers to the gradual change in system configurations over time, causing deviations from the baseline or security standards.

443
MCQeasy

A security analyst is reviewing vulnerability scan results and notices that several critical vulnerabilities have been reported on the same web server for three consecutive months. The server owner states that the patches cannot be applied due to application compatibility issues. Which of the following is the BEST course of action?

A.Escalate the issue to senior management and move on
B.Remove the web server from service until patches are applied
C.Schedule a rescan to verify if the vulnerabilities still exist
D.Implement compensating controls to reduce the risk
AnswerD

Implementing compensating controls is often the most practical and immediate action when direct patching or full remediation of a vulnerability is not immediately feasible due to operational constraints, system stability concerns, or vendor limitations. These alternative security measures, such as deploying a Web Application Firewall (WAF), configuring Intrusion Prevention System (IPS) rules, or segmenting networks, effectively reduce the likelihood or impact of exploitation. This approach allows the organization to reduce risk and maintain business continuity until a permanent solution can be applied.

Why this answer

When a known vulnerability cannot be patched due to application compatibility issues, the standard risk management approach is to implement compensating controls. These controls (e.g., Web Application Firewall rules, network segmentation, or host-based IPS) reduce the likelihood or impact of exploitation without modifying the vulnerable application. This aligns with the NIST SP 800-40 Rev. 4 guidance on vulnerability handling, which explicitly recommends compensating controls when patching is not feasible.

Exam trap

The CS0-004 exam often tests the misconception that rescanning (Option C) is the correct next step, but the trap here is that rescanning does not change the risk posture—it only confirms what is already known, while the question requires a risk-reducing action.

How to eliminate wrong answers

Option A is wrong because simply escalating to senior management without taking any action to reduce risk is a passive approach that leaves the vulnerability exploitable; the analyst must still recommend or implement compensating controls. Option B is wrong because removing the web server from service is an extreme measure that may not be justified if compensating controls can adequately mitigate the risk, and it could cause unnecessary business disruption. Option C is wrong because rescanning will only confirm the same vulnerabilities still exist (since patches were not applied), wasting time without addressing the underlying risk.

444
MCQmedium

During dynamic malware analysis in a sandbox, an analyst observes that the malware attempts to connect to a remote IP address on port 443, modifies the Windows registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and drops a DLL in the system32 folder. Which type of IOC is most indicative of persistence?

A.The registry modification to the Run key
B.The network connection over port 443
C.The remote IP address
D.The dropped DLL file hash
AnswerA

The HKCU\Software\Microsoft\Windows\CurrentVersion\Run key causes the referenced program to execute automatically at user logon, establishing persistence across reboots. The outbound port 443 connection indicates command-and-control, and the dropped system32 DLL is a payload artefact, but only the Run key modification ensures the malware survives restarts.

Why this answer

The registry modification to HKCU\Software\Microsoft\Windows\CurrentVersion\Run is the most indicative of persistence because this specific key is designed to automatically launch programs when a user logs in. By adding a value here, the malware ensures it executes on every system startup, which is the definition of persistence. In contrast, network connections and file drops are common during execution but do not inherently guarantee re-execution after a reboot.

Exam trap

CompTIA CySA+ often tests the distinction between indicators of activity (network connections, file drops) and indicators of persistence (registry Run keys, scheduled tasks, services), and the trap here is that candidates confuse a common malware behavior (like connecting to a C2 server) with a mechanism that ensures the malware runs again after reboot.

How to eliminate wrong answers

Option B is wrong because a network connection over port 443 (HTTPS) indicates command-and-control communication or data exfiltration, not a mechanism to survive a reboot. Option C is wrong because the remote IP address is merely a destination for network activity and provides no information about automatic re-execution. Option D is wrong because the dropped DLL file hash is a file-based indicator of compromise (IOC) that identifies the malware sample, but the file alone does not ensure it will be loaded again after a restart without a persistence mechanism like a Run key or service.

445
MCQmedium

A security analyst is configuring a vulnerability scanner for a new deployment. The scanner must be able to authenticate to targets to perform deep configuration audits against CIS Benchmarks. Which type of scan should the analyst configure?

A.Credentialed scan
B.Unauthenticated scan
C.Passive scan
D.External scan
AnswerA

Credentialed scans utilize valid administrative or user credentials to log directly into target systems, enabling the scanner to inspect local registries, installed software versions, and configuration files. This deep visibility allows for the identification of missing patches and misconfigurations that are invisible from the network perspective, minimizing false positives and negatives.

Why this answer

A credentialed scan supplies valid credentials (e.g., SSH keys, SMB accounts, or API tokens) to the scanner, allowing it to log into targets and inspect local configuration, registry settings, file permissions, and patch levels. This deep access is required to audit against CIS Benchmarks, which specify OS and application configuration hardening checks that cannot be assessed externally.

Exam trap

CS0-004 often tests the confusion between credentialed vs. external scans — candidates pick 'external' thinking it implies deep access, when external describes vantage point and credentialed describes authentication depth required for CIS Benchmark audits.

How to eliminate wrong answers

Option B is wrong because an unauthenticated scan only probes externally visible services and banners, missing local configuration details needed for CIS Benchmark audits. Option C is wrong because a passive scan observes network traffic without actively querying targets, so it cannot authenticate or enumerate configuration settings. Option D is wrong because an external scan is defined by its vantage point (outside the network) rather than its authentication method — an external scan can be credentialed or not, and the question specifically requires authentication for deep configuration audits.

446
MCQmedium

An incident report includes a section that details the sequence of events from initial compromise to containment. Which component of the incident report does this describe?

A.Impact assessment
B.Root cause
C.Lessons learned
D.Timeline
AnswerD

A timeline is a chronological, time-stamped listing of events, actions, observations, and findings that occurred during an incident. It is a foundational component of incident documentation because it establishes the order and timing of events, supporting correlation of security events and response actions. In an incident report, the section 'detailing the sequence' directly maps to the timeline's purpose of recording events in sequence.

Why this answer

The timeline component of an incident report provides a chronological record of events, from the initial compromise through detection, response, and containment. It answers the 'when' and 'in what order' questions, which is exactly what the question describes. Other components like impact assessment, root cause, and lessons learned focus on consequences, underlying reasons, and improvements, respectively.

Exam trap

CS0-004 often tests the distinction between incident report components by using similar-sounding descriptions; candidates may confuse 'sequence of events' with 'root cause' or 'lessons learned' if they do not carefully map the definition to the component.

How to eliminate wrong answers

Option A is wrong because an impact assessment quantifies the damage or business effect (e.g., data loss, downtime cost), not the sequence of events. Option B is wrong because root cause analysis identifies the fundamental vulnerability or failure that allowed the incident, not the chronological progression. Option C is wrong because lessons learned capture recommendations and improvements after the incident, not the event sequence itself.

447
MCQhard

A large e-commerce site is under a DDoS attack targeting its web servers. The incident response team is activated. Which goal should receive the HIGHEST priority during the response?

A.Maintain availability of the service.
B.Implement attribution.
C.Identify the attacker's identity.
D.Quantify the financial loss.
AnswerA

Maintaining availability of the service is the paramount objective during an active Distributed Denial of Service (DDoS) attack. The primary goal of a DDoS attack is to overwhelm an organization's resources, preventing legitimate users from accessing critical services. Therefore, the immediate and most critical response is to implement measures that ensure the e-commerce site remains accessible and functional for its customers, directly countering the attack's intent and preserving business continuity.

Why this answer

During a DDoS attack targeting web servers, the highest priority is maintaining availability of the service because the primary goal of incident response in this scenario is to preserve business continuity and minimize disruption to legitimate users. The incident response team must first focus on mitigating the attack (e.g., rate-limiting, blackholing traffic, or scaling resources) before any forensic or attribution steps, as service downtime directly impacts revenue and customer trust.

Exam trap

The CS0-004 exam often tests the principle that during an active incident, the priority is containment and recovery (availability) over forensic activities like attribution or identification, which are handled in later phases of the incident response lifecycle.

How to eliminate wrong answers

Option B is wrong because attribution (identifying the source of the attack) is a secondary goal that typically occurs after the immediate threat is contained; focusing on attribution during the active attack can delay mitigation and prolong downtime. Option C is wrong because identifying the attacker's identity is a forensic objective that is rarely achievable in real-time during a DDoS attack (attackers often use spoofed IPs, botnets, or reflection techniques), and it does not help restore service availability. Option D is wrong because quantifying financial loss is a post-incident activity that should be performed after the attack is mitigated; prioritizing it during the response would divert resources from stopping the attack and restoring service.

448
MCQmedium

During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch causes a regression in a key business application. Which of the following should the analyst do next?

A.Apply the patch to production but roll back if issues occur
B.Skip the patch and accept the risk
C.Deploy the patch to production and monitor for issues
D.Report the regression to the vendor and wait for a fixed patch
AnswerD

The standard operating procedure when finding a regression during patch testing is to document the defect and report it to the software vendor. This allows the vendor to refactor the code and release an updated, stable patch. While waiting, the organization should implement compensating controls to mitigate the underlying vulnerability without breaking production systems.

Why this answer

Reporting the regression to the vendor and waiting for a fixed patch is correct because the patch introduces a functional regression in a key business application, meaning it cannot be safely deployed. The proper patch management lifecycle requires that failed patches be documented, communicated to the vendor, and re-tested once a corrected version is available. This preserves both security and business continuity without accepting unmanaged risk.

Exam trap

CS0-004 often tests whether candidates confuse 'accepting risk' or 'deploying anyway' with proper remediation — the trap is choosing an action that bypasses the vendor feedback loop or violates change control.

How to eliminate wrong answers

Option A is wrong because applying a patch known to cause regressions to production violates change management principles and risks business disruption — 'roll back if issues occur' is reactive, not proactive. Option B is wrong because skipping the patch and accepting the risk leaves the known vulnerability unmitigated, which is unacceptable for a critical security patch without formal risk acceptance. Option C is wrong because deploying a patch already proven to break a key application to production is reckless and contradicts the purpose of staging tests.

449
MCQhard

Based on the scan output, which vulnerability should be prioritized first for remediation?

A.CVE-2019-16905
B.CVE-2020-15778
C.CVE-2020-12060
D.Both A and B equally.
AnswerB

Highest CVSS score (9.8).

Why this answer

CVE-2020-15778 is a critical command injection vulnerability in OpenSSH's scp utility that allows an unauthenticated remote attacker to execute arbitrary commands on the target system by crafting a malicious scp source path. This vulnerability has a CVSS score of 9.8 (Critical) and is remotely exploitable without authentication, making it the highest priority for remediation over the other listed CVEs.

Exam trap

CompTIA often tests the principle that remote code execution (RCE) vulnerabilities with no authentication requirement should always be prioritized over local privilege escalation or denial-of-service vulnerabilities, even if the latter have higher CVSS scores in some categories.

How to eliminate wrong answers

Option A is wrong because CVE-2019-16905 is a privilege escalation vulnerability in the Linux kernel's eBPF subsystem (bpf_skb_change_head) that requires local access to exploit, making it less critical than a remotely exploitable command injection. Option C is wrong because CVE-2020-12060 is a denial-of-service (DoS) vulnerability in the Linux kernel's NFSv4.2 implementation that requires specific conditions and only causes a system crash, not remote code execution. Option D is wrong because both A and C are not equally critical; CVE-2020-15778 is the only one that allows unauthenticated remote command execution, which is a higher severity and should be prioritized first.

450
MCQeasy

Which of the following tools is specifically designed for compliance scanning against security benchmarks such as CIS and STIG?

A.OpenVAS
B.Nessus
C.OpenSCAP
D.Trivy
AnswerC

Correct. OpenSCAP is built specifically around SCAP standards, consuming XCCDF checklists and OVAL definitions to evaluate a system's actual configuration against CIS Benchmarks or DISA STIGs and producing pass/fail compliance results, which is its primary design purpose.

Why this answer

OpenSCAP is an open-source tool specifically designed for compliance scanning against security benchmarks like CIS and STIG. It uses SCAP (Security Content Automation Protocol) standards to automate vulnerability management and compliance checking. It can evaluate systems against predefined policies and generate reports.

Exam trap

CS0-004 often tests the difference between vulnerability scanners and compliance scanners; candidates may pick Nessus or OpenVAS due to familiarity, but OpenSCAP is the specialized tool for CIS/STIG.

How to eliminate wrong answers

Option A is wrong because OpenVAS is a vulnerability scanner, not specifically for compliance benchmarks like CIS/STIG; it focuses on detecting vulnerabilities. Option B is wrong because Nessus is a commercial vulnerability scanner that can perform compliance checks but is not specifically designed for CIS/STIG; it requires plugins and is not open-source. Option D is wrong because Trivy is a vulnerability scanner for containers and other artifacts, not for compliance scanning against CIS/STIG benchmarks.

Page 5

Page 6 of 10

Page 7

All pages