Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 451–525

701 questions total · 10pages · All types, answers revealed

Page 6

Page 7 of 10

Page 8
451
Multi-Selecthard

Which THREE activities are typically performed during the post-incident activity phase of the incident response lifecycle?

Select 3 answers
A.System restoration from backups.
B.Root cause analysis.
C.Implementation of new security awareness training.
D.Evidence retention for potential legal action.
E.Lessons learned meeting.
AnswersB, D, E

Root cause analysis (RCA) is performed during the post-incident phase to identify the fundamental vulnerability or vector that allowed the compromise to occur. By pinpointing the exact failure point, security teams can implement permanent corrective controls rather than just treating the symptoms of the attack. This prevents future occurrences of the same exploit.

Why this answer

Root cause analysis (B) is performed during the post-incident activity phase to identify the underlying vulnerability or misconfiguration that allowed the incident to occur. This analysis informs remediation steps and helps prevent recurrence, making it a core activity of this phase.

Exam trap

CompTIA often tests the distinction between recovery-phase actions (e.g., system restoration) and post-incident analysis activities, leading candidates to mistakenly include restoration as a post-incident task.

452
MCQhard

During memory analysis of a compromised host, an analyst finds a process that appears to be 'svchost.exe' but with an unusual parent process (not 'services.exe'). The process also has injected code in its memory. What is the most likely explanation?

A.The process is a legitimate svchost.exe but spawned by a different service
B.The svchost.exe is a hollowed process used for malicious purposes
C.The process is a DLL injection into svchost.exe
D.The svchost.exe process is a false positive due to a known Windows bug
AnswerB

Process hollowing is a defense evasion technique where an adversary spawns a legitimate process like svchost.exe in a suspended state, unmaps its memory, and replaces it with a malicious payload. This allows the malware to masquerade as a trusted system process, hiding its true nature from basic process-monitoring tools while executing unauthorized code.

Why this answer

Svchost.exe should always have services.exe as parent. A different parent suggests process hollowing where an attacker replaced the legitimate process memory.

453
Multi-Selectmedium

A security analyst needs to communicate the findings of a penetration test to the IT operations team and the CISO. Which three of the following actions best support effective reporting and communication? (Choose three.)

Select 3 answers
.Customize the level of detail in the report for each audience
.Include raw command outputs and exploit code in the executive summary
.Prioritize findings based on risk to the organization’s mission
.Provide actionable remediation steps with ownership assignments
.Delay the report until all findings are fully verified with no uncertainty
.Submit the report as a confidential document without any verbal briefing

Why this answer

Customizing the level of detail for each audience ensures that technical teams receive the operational depth they need (e.g., raw findings, exploit paths) while executives get a high-level summary focused on business risk and strategic impact. This aligns with the principle of audience-aware reporting in penetration testing, where the CISO requires risk context and the IT operations team needs actionable technical details.

Exam trap

CompTIA often tests the misconception that including all raw technical data in the executive summary is thorough, when in fact it violates audience-specific communication best practices and can overwhelm non-technical readers.

454
MCQhard

A SIEM alert shows one workstation requesting a high number of Kerberos service tickets for many SPNs, followed by no corresponding service access. Which attack should be suspected?

A.Kerberoasting reconnaissance or ticket harvesting
B.DNS cache poisoning
C.Pass-the-hash using NTLM only
D.ARP spoofing
AnswerA

Kerberoasting involves an attacker requesting service tickets (TGS-REQs) for various Service Principal Names (SPNs) registered in Active Directory. These tickets contain a hash of the service account's password, encrypted with the service account's NTLM hash. A high volume of TGS-REQ requests from a single workstation, especially for numerous different service principals, is a strong indicator of an attacker attempting to harvest these tickets offline for brute-forcing the password hashes to gain credentials.

Why this answer

A high volume of Kerberos service ticket requests for many SPNs, followed by no actual service access, is characteristic of Kerberoasting reconnaissance. In this attack, an adversary with valid domain credentials requests TGS tickets for service accounts to extract the NTLM hash embedded in the ticket, which can then be cracked offline. The lack of subsequent service access confirms the tickets were obtained solely for offline brute-force cracking, not legitimate use.

Exam trap

The CS0-004 exam often tests the distinction between reconnaissance (ticket harvesting without access) and actual exploitation; the trap here is confusing Kerberoasting with pass-the-ticket or golden ticket attacks, which involve ticket reuse or forgery rather than offline hash cracking.

How to eliminate wrong answers

Option B is wrong because DNS cache poisoning involves corrupting DNS resolver caches to redirect traffic to malicious IPs, which does not generate Kerberos TGS requests or SPN enumeration. Option C is wrong because pass-the-hash using NTLM only exploits NTLM authentication by reusing captured NTLM hashes to authenticate, not by requesting Kerberos service tickets; the described behavior specifically involves Kerberos AS-REQ/TGS-REQ traffic, not NTLM.

455
MCQhard

A cloud tenant shows an unusual spike in IAM policy changes, access key creation, and failed console logons from a new country. Which telemetry set gives the strongest evidence for control-plane compromise? In the alert triage phase, Which action gives the analyst the clearest next triage step?

A.Endpoint antivirus quarantine reports only
B.Packet captures from user laptops only
C.Cloud audit logs for identity, policy, and key-management API calls
D.Web server access logs from the public website
AnswerC

Cloud audit logs capture control-plane API calls such as IAM policy changes, access key creation and console sign-in attempts, tying each action to an identity and source IP. This directly evidences control-plane compromise, unlike data-plane or endpoint telemetry.

Why this answer

Cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log) capture control-plane API calls such as IAM policy changes, key creation, and authentication failures. These logs directly record the identity and resource management actions that indicate a compromise of the cloud management plane, whereas endpoint or network telemetry only reflects data-plane activity and cannot see API-level administrative actions.

Exam trap

The trap here is that candidates often confuse data-plane telemetry (endpoint AV, packet captures) with control-plane telemetry, failing to recognize that only cloud audit logs can capture administrative API calls like IAM policy changes and key creation.

How to eliminate wrong answers

Option A is wrong because endpoint antivirus quarantine reports only detect malware or file-based threats on individual devices; they cannot capture cloud control-plane API calls like IAM policy changes or access key creation. Option B is wrong because packet captures from user laptops only show network traffic at the data plane (e.g., HTTP, SSH sessions) and cannot log cloud management API requests that occur between the client and the cloud provider's control-plane endpoints.

456
Drag & Dropmedium

Order the steps for deploying a new security patch to a production environment.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Patch deployment involves download/verification, testing, backup, rollout, and monitoring.

457
MCQmedium

During a forensic investigation, an analyst creates a disk image using dd with a SHA256 hash. Later, the analyst needs to verify the integrity of the image before analysis. Which command should the analyst use to compare the original hash with a newly computed hash?

A.md5sum original.dd
B.dd if=image.dd | sha256sum
C.sha256sum image.dd
D.chksum -a sha256 image.dd
AnswerC

Running sha256sum directly against the image file recomputes its SHA256 digest using the same algorithm and tool convention as the original acquisition hash, producing a value the analyst can directly diff against the recorded original hash to confirm bit-for-bit integrity and an unbroken chain of custody before proceeding with analysis.

Why this answer

The analyst needs to recompute the SHA256 hash of the image file and compare it to the original value. The command 'sha256sum image.dd' computes the SHA256 digest of the file directly, which is the standard Linux utility for this purpose and produces output that can be diffed against the original hash.

Exam trap

CS0-004 often tests command syntax and hash algorithm matching — candidates pick md5sum out of habit or choose a non-existent command like 'chksum -a sha256', forgetting that the hash algorithm must match the original baseline exactly.

How to eliminate wrong answers

Option A is wrong because md5sum computes an MD5 hash, not SHA256, so it cannot verify a SHA256 baseline and MD5 is cryptographically broken for integrity assurance. Option B is wrong because piping 'dd if=image.dd | sha256sum' works but is unnecessarily indirect and error-prone; more importantly, it is not the canonical command and introduces an extra process that could mask read errors — the direct sha256sum is preferred. Option D is wrong because 'chksum -a sha256' is not a valid standard Linux command for computing SHA256 digests; the correct tools are sha256sum or openssl dgst -sha256.

458
MCQmedium

A cloud security analyst reviews AWS CloudTrail logs and notices multiple 'RunInstances' API calls from a single IAM user creating EC2 instances with public IP addresses in an unusual region. What is the most likely concern?

A.The user's credentials may be compromised and used for cryptomining
B.The user is performing legitimate scaling operations
C.The user is provisioning resources for a new project
D.The user is testing disaster recovery procedures
AnswerA

When threat actors compromise AWS IAM credentials, they frequently target unused geographical regions to evade detection while spinning up high-performance EC2 instances for illicit cryptocurrency mining. This anomalous behavior is flagged in CloudTrail logs by API calls like RunInstances originating from unfamiliar IPs and targeting non-standard regions, which deviates sharply from established baseline activity.

Why this answer

Multiple RunInstances calls from a single IAM user creating public-IP EC2 instances in an unusual region is a textbook indicator of compromised credentials being used for cryptomining. Attackers favor this pattern because it rapidly provisions compute resources for mining, often in regions the victim doesn't normally use to evade detection and quota monitoring.

Exam trap

CS0-004 often tests whether candidates can distinguish a genuine security incident (compromised credentials, cryptomining) from benign operational explanations (scaling, new projects) by focusing on anomalies like unusual region and public IP exposure.

How to eliminate wrong answers

Option B is wrong because legitimate auto-scaling is typically driven by Auto Scaling Groups with service-linked roles, not a single IAM user making manual RunInstances calls in an unusual region. Option C is wrong because new-project provisioning would normally follow change-management processes and occur in the organization's standard regions, not an anomalous one. Option D is wrong because disaster recovery testing is a planned, documented activity that would not present as repeated ad-hoc RunInstances calls with public IPs from one user.

459
MCQeasy

Which of the following is the primary audience for a strategic threat intelligence report?

A.System administrators
B.SOC analysts
C.Executive leadership
D.Incident responders
AnswerC

Executive leadership is the primary audience for strategic intelligence because it informs high-level decisions about risk tolerance, resource allocation, and business continuity. This type of intelligence is written in non-technical language, summarizing geopolitical threats, industry-level trends, and potential impacts to the enterprise in a way that supports governance and investment choices. It helps the C-suite align cybersecurity with organizational objectives, not with day-to-day tactics.

Why this answer

Strategic intelligence is high-level and intended for executive leadership to inform business decisions.

460
MCQeasy

A vulnerability scan report shows a critical vulnerability on a web server with a CVSS score of 9.8. The IT manager wants to know the risk to the organization. Which of the following factors should the analyst consider FIRST?

A.The asset value and business criticality
B.The vendor's patch release schedule
C.The number of exploit attempts in the logs
D.The number of other vulnerabilities on the server
AnswerA

When assessing a critical vulnerability, the asset's value and its criticality to business operations are paramount. This factor directly determines the potential impact of a successful exploit, which is a core component of risk calculation (Risk = Threat x Vulnerability x Impact). A critical vulnerability on a low-value, non-essential asset poses less overall risk than the same vulnerability on a high-value, mission-critical system, dictating immediate prioritization.

Why this answer

The CVSS score of 9.8 indicates a critical severity vulnerability, but risk is a function of both severity and business context. The analyst must first assess the asset value and business criticality of the web server because a critical vulnerability on a non-essential server poses lower risk than the same vulnerability on a server handling sensitive data or core business processes. Without this context, the organization cannot prioritize remediation effectively.

Exam trap

CompTIA often tests the distinction between vulnerability severity (CVSS) and organizational risk, trapping candidates who confuse a high CVSS score with automatically high risk without considering asset context.

How to eliminate wrong answers

Option B is wrong because the vendor's patch release schedule is an operational consideration for remediation timing, not the primary factor for determining risk; risk assessment must first establish the impact on the organization. Option C is wrong because the number of exploit attempts in logs indicates current threat activity, but risk is evaluated based on potential impact and likelihood, not solely on observed attacks; a vulnerability with no current exploits can still pose high risk if the asset is critical. Option D is wrong because the number of other vulnerabilities on the server is irrelevant to the risk of this specific vulnerability; each vulnerability must be assessed independently based on asset criticality and exposure.

461
Multi-Selectmedium

A vulnerability management analyst is reviewing the results of an authenticated scan. The analyst identifies several medium-severity vulnerabilities that have been present for over a year. Which of the following are the best actions to take? (Choose two.)

Select 2 answers
A.Verify the vulnerabilities are still relevant by re-scanning.
B.Escalate to the asset owner for remediation.
C.Accept the risk if the system is no longer in use.
D.Remove the system from the network.
E.Increase the severity rating to high to ensure remediation.
AnswersA, B

Performing a targeted follow-up scan is the critical first step to validate that the identified vulnerabilities have not already been mitigated by automated patching or configuration changes. This prevents the analyst from wasting organizational resources on false positives or outdated scan data before initiating formal remediation workflows.

Why this answer

Re-scanning verifies whether the vulnerabilities are still present or have been remediated by other means (e.g., patching, configuration changes). Over a year, the environment may have changed, and the original scan results could be stale. An authenticated scan provides deeper visibility, but a fresh scan is the only way to confirm current relevance before taking further action.

Exam trap

CompTIA often tests the misconception that old vulnerabilities should automatically be escalated or reclassified, when in fact the first step is always to re-verify the finding with a current scan to avoid wasting resources on false positives or already-remediated issues.

462
MCQhard

An organization uses a SIEM with a rule that triggers when a user fails to authenticate five times within 10 minutes. Last night, the rule fired for a service account from an internal IP. What should be the first triage step?

A.Disable the service account immediately
B.Block the internal IP address at the firewall
C.Review the account's recent activity and correlate with system logs
D.Reset the service account password
AnswerC

Correlating the service account's authentication history, the source system's process and event logs, and any recent configuration changes lets the analyst distinguish between an expired or rotated credential causing benign failures and genuine credential misuse, which is the necessary evidence-gathering step before any containment decision is made.

Why this answer

The best first triage step. Service accounts often have automated login attempts that may trigger false positives. Reviewing recent activity and correlating with system logs helps determine if the failures are legitimate (e.g., a script using wrong credentials) or indicate compromise.

Disabling the account (A) could disrupt critical services. Blocking the IP (B) might be premature without confirmation. Resetting the password (D) could lock out the legitimate service if the account is not compromised.

463
MCQeasy

Which of the following best describes the purpose of the CISA Known Exploited Vulnerabilities (KEV) catalog in vulnerability management?

A.It lists vulnerabilities that are known to have been exploited in the wild
B.It provides a framework for conducting penetration tests
C.It provides a scoring system for vulnerability severity
D.It offers a database of configuration baselines for operating systems
AnswerA

The CISA KEV catalog's defining criterion is real-world exploitation evidence; CISA adds a CVE only after confirming it has been actively exploited in the wild, which is why federal agencies under Binding Operational Directive 22-01 must remediate KEV-listed vulnerabilities on an accelerated timeline regardless of their CVSS score.

Why this answer

The CISA Known Exploited Vulnerabilities (KEV) catalog is a authoritative list maintained by CISA that enumerates vulnerabilities confirmed to have been exploited in the wild. Its purpose is to help organizations prioritize remediation by focusing on vulnerabilities with active exploitation evidence, not theoretical risk. This makes it a key input for risk-based vulnerability management and for meeting Binding Operational Directive 22-01 requirements for federal agencies.

Exam trap

CS0-004 often tests the distinction between vulnerability scoring (CVSS), exploitation evidence (KEV), and testing frameworks (PTES), so candidates must not confuse the KEV catalog with severity scoring or penetration testing methodologies.

How to eliminate wrong answers

Option B is wrong because penetration testing frameworks are methodologies like PTES, OWASP Testing Guide, or MITRE ATT&CK, not the KEV catalog. Option C is wrong because vulnerability severity scoring is provided by systems like CVSS (Common Vulnerability Scoring System), not KEV. Option D is wrong because configuration baselines are published by CIS Benchmarks, DISA STIGs, or NIST, not the KEV catalog.

464
MCQhard

A security analyst discovers a critical vulnerability in a web application that allows an attacker to trigger server-side requests from the application server. Which OWASP Top 10 category does this vulnerability belong to?

A.Broken Access Control
B.Security Misconfiguration
C.Injection
D.Server-Side Request Forgery (SSRF)
AnswerD

Server-Side Request Forgery (SSRF) occurs when a web application fetches a remote resource without validating the user-supplied URL. This allows an attacker to coerce the vulnerable server into sending crafted requests to internal-only resources, such as loopback interfaces, local databases, or cloud metadata endpoints (like AWS IMDSv1), effectively bypassing perimeter firewalls.

Why this answer

Server-Side Request Forgery (SSRF) is a distinct category in OWASP Top 10 (A10:2021).

465
MCQhard

What is the net effect of the policy shown in the exhibit on requests from an IP address in the 10.0.0.0/8 range?

A.Allows all S3 actions from the 10.0.0.0/8 range and denies from other IPs.
B.Denies all S3 actions from all IP addresses.
C.Denies all S3 actions except GetObject from the 10.0.0.0/8 range.
D.Allows GetObject requests from the 10.0.0.0/8 range and denies all other S3 actions.
AnswerB

This option is correct because the policy contains an explicit Deny statement for all s3:* actions, which lacks any limiting conditions such as aws:SourceIp. According to AWS IAM policy evaluation logic, an explicit Deny always overrides any explicit Allow statements. Consequently, all S3 actions are denied for all principals, regardless of their source IP address, effectively nullifying any Allow rules.

Why this answer

The exhibit shows an AWS S3 bucket policy with a Deny effect for all S3 actions (s3:*) from any IP address (the condition block uses a NotIpAddress condition with the value 10.0.0.0/8, meaning the deny applies to all IPs that are NOT in that range). However, because the policy explicitly denies all actions for all IPs not in 10.0.0.0/8, and there is no corresponding Allow statement for the 10.0.0.0/8 range, the net effect is that all S3 actions are denied from all IP addresses, including those in 10.0.0.0/8. This is because AWS IAM policies default to implicit deny, and an explicit deny overrides any allow, so without an explicit allow for the 10.0.0.0/8 range, the deny applies universally.

Exam trap

CompTIA often tests the misconception that a Deny statement with a NotIpAddress condition effectively allows traffic from the specified IP range, when in reality it only denies traffic from outside that range, and without an explicit Allow, all traffic is denied.

How to eliminate wrong answers

Option A is wrong because the policy does not contain an Allow statement for the 10.0.0.0/8 range; it only has a Deny statement that denies all S3 actions from IPs not in 10.0.0.0/8, which does not implicitly allow actions from that range. Option C is wrong because the policy denies all S3 actions (s3:*) without exception for GetObject, and there is no condition that would allow GetObject from any IP range. Option D is wrong because the policy does not allow GetObject from 10.0.0.0/8; it denies all S3 actions from IPs outside that range, but without an explicit allow, requests from 10.0.0.0/8 are also denied by default.

466
MCQmedium

An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?

A.The organization's risk register
B.Copies of recent vulnerability scan reports and access review logs
C.Email communications about security incidents
D.A summary of security policies and procedures
AnswerB

Vulnerability scan reports and access review logs serve as direct, empirical evidence of technical control implementation and operational effectiveness. These artifacts prove to auditors that vulnerability management processes are actively running and that identity and access management controls are being routinely monitored and enforced. This objective, system-generated data is crucial for validating compliance with frameworks like PCI-DSS, SOC 2, or ISO 27001.

Why this answer

Log exports, configuration reports, vulnerability scans, and access reviews are typical evidence for GDPR audits.

467
MCQhard

A SOC analyst notices a spike in outbound traffic from a server that normally only serves web pages. The signature-based IDS did not alert. What should the analyst do next?

A.Query threat intelligence for the destination IPs
B.Disable the server immediately
C.Check for zero-day vulnerabilities
D.Increase the IDS sensitivity threshold
AnswerA

A spike in outbound traffic from a server is inherently suspicious, necessitating immediate investigation. Querying threat intelligence platforms (TIPs) or open-source intelligence (OSINT) feeds with the destination IPs is a crucial initial step in incident response. This action quickly correlates observed indicators of compromise (IOCs) with known malicious infrastructure, such as command-and-control (C2) servers, botnet nodes, or phishing sites. This provides immediate context on the potential threat actor or malware family involved, allowing the analyst to rapidly assess the severity and nature of the incident without disrupting operations.

Why this answer

Querying threat intelligence for the destination IPs is the correct next step because the spike in outbound traffic from a web server suggests a potential data exfiltration attempt or command-and-control (C2) communication. Since the signature-based IDS did not alert, the traffic may be using non-standard ports or encrypted channels that evade known signatures. Threat intelligence can reveal if the destination IPs are associated with known malicious actors, botnets, or recent threat campaigns, providing context to determine if the traffic is benign or malicious.

Exam trap

CompTIA often tests the misconception that a signature-based IDS failing to alert means the traffic is safe, leading candidates to incorrectly choose increasing IDS sensitivity or checking for zero-days, rather than recognizing that the analyst must pivot to threat intelligence to identify unknown or evasive threats.

How to eliminate wrong answers

Option B is wrong because immediately disabling the server is a drastic, reactive measure that could disrupt legitimate services without first confirming malicious activity; a SOC analyst should investigate and contain, not blindly shut down. Option C is wrong because checking for zero-day vulnerabilities is premature and unrelated to the immediate symptom of outbound traffic spikes; zero-day checks are part of vulnerability management, not real-time traffic analysis. Option D is wrong because increasing the IDS sensitivity threshold would likely generate more false positives and does not address the root cause—the IDS missed the traffic because it was not signature-based, not because of sensitivity settings.

468
Multi-Selectmedium

An analyst is preparing a vulnerability report for management. Which THREE sections should be included to effectively communicate findings and remediation? (Select THREE.)

Select 3 answers
A.Executive summary
B.Incident response procedures
C.Network topology diagram
D.Findings by severity
E.Remediation timeline
AnswersA, D, E

The executive summary is the most critical section for management because it distills the entire vulnerability assessment into a concise, high-level overview of the organization's risk posture. It should highlight the total number of vulnerabilities, the most severe threats, and the recommended strategic actions without overwhelming readers with technical CVSS vectors or exploit details. Management needs this to make informed decisions on resource allocation and risk acceptance, making it a mandatory component of any vulnerability report.

Why this answer

The executive summary (A) is correct because it gives management a concise, non-technical overview of the assessment's scope, key risks, and overall risk posture, which is essential for decision-makers who need the bottom line without deep technical detail. Findings by severity (D) is correct because organizing vulnerabilities by severity ratings (e.g., CVSS scores or Critical/High/Medium/Low categories) lets management prioritize the most dangerous issues and allocate resources accordingly. Remediation timeline (E) is correct because it communicates when fixes will be applied, establishes accountability, and aligns remediation with business risk tolerance and operational constraints.

Incident response procedures (B) do not belong because they are operational playbooks for handling active incidents, not components of a vulnerability report. Network topology diagram (C) is not required because it is supporting technical documentation that may aid context but is not one of the core sections needed to communicate findings and remediation to management.

Exam trap

CS0-004 often tests the confusion between vulnerability report components and incident response documentation, tempting candidates to include IR procedures or topology diagrams that are not part of a standard management report.

469
MCQhard

A container workload unexpectedly starts a shell, mounts the host filesystem, and attempts outbound connections to an unknown IP. Which telemetry is MOST useful? In the evidence source phase, Which evidence source best supports or refutes the detection?

A.Only monthly vulnerability scan summaries
B.Only user password age reports
C.Only physical datacenter access logs
D.Container runtime events, Kubernetes audit logs, and network flow from the pod
AnswerD

Container runtime events, such as those from an agent like Falco or eBPF, directly monitor process execution, file system access, and system calls within the container, immediately flagging an unexpected shell or host mount. Kubernetes audit logs capture API server requests, revealing if the container's configuration was modified or if a privileged pod was created, indicating orchestration-level compromise. Network flow from the pod provides crucial visibility into any attempted exfiltration or command-and-control communication initiated by the compromised container, completing the forensic picture. Together, these telemetry sources offer comprehensive detection and context for container escape attempts.

Why this answer

Container runtime events (e.g., from containerd or CRI-O) capture process spawns like an unexpected shell, Kubernetes audit logs record API calls that could indicate a compromised pod mounting the host filesystem, and network flow logs from the pod (e.g., via eBPF or Calico) reveal outbound connections to an unknown IP. Together, these three telemetry sources provide direct, real-time evidence of the three suspicious behaviors described, making them the most useful for detection and investigation.

Exam trap

CompTIA often tests the distinction between passive, periodic compliance artifacts (vulnerability scans, password reports) and active, real-time telemetry (runtime events, audit logs, network flows) that directly capture the sequence of malicious actions in a containerized environment.

How to eliminate wrong answers

Option A is wrong because monthly vulnerability scan summaries are point-in-time snapshots of known CVEs and cannot detect real-time anomalous behavior like a shell spawn, filesystem mount, or outbound connection. Option B is wrong because user password age reports are identity and access management artifacts unrelated to runtime container activity or network flows. Option C is wrong because physical datacenter access logs track human entry to facilities, not container-level process or network events, and cannot refute or support a workload compromise.

470
MCQmedium

An analyst reviews AWS CloudTrail logs and detects multiple 'CreateNetworkAclEntry' API calls from a user who does not typically perform network administration. What type of activity is this?

A.Cloud misconfiguration
B.Privilege escalation or lateral movement
C.Normal administrative activity
D.Data exfiltration via NACL
AnswerB

When a user account suddenly executes unauthorized API calls to alter network configurations or security groups, it strongly suggests an adversary is attempting privilege escalation or lateral movement. By modifying these boundaries, the attacker aims to establish broader access to sensitive cloud resources or bypass existing security controls.

Why this answer

Creating Network ACL entries is a network administration task. When a user who does not normally perform such actions makes multiple CreateNetworkAclEntry calls, it suggests the user's credentials may have been compromised and are being used to modify network access controls, potentially to enable lateral movement or privilege escalation. This is a classic indicator of compromise in cloud environments.

Exam trap

The trap is labeling suspicious but non-destructive API calls as 'misconfiguration' or 'normal'; candidates must recognize that unusual administrative actions by a non-admin user indicate compromise and potential lateral movement.

How to eliminate wrong answers

Option A is wrong because cloud misconfiguration refers to accidental errors in configuration, not suspicious API calls from an unusual user; the pattern here indicates malicious intent. Option C is wrong because the user does not typically perform network administration, so this is not normal activity for them. Option D is wrong because data exfiltration via NACL is not a standard attack technique; NACLs control traffic, and while they could be used to allow exfiltration, the act of creating entries is more indicative of establishing persistence or lateral movement.

471
MCQmedium

An organization has been experiencing repeated phishing attacks that bypass email filters. The incident response team wants to enhance detection by creating rules based on characteristics of the phishing emails. Which of the following IOCs would be most effective for detecting similar phishing campaigns?

A.Registry keys modified by the payload
B.File hashes of attached malware
C.IP addresses of the phishing servers
D.Email subject lines and sender domain
AnswerD

Email subject lines and sender domains serve as highly effective, static indicators of compromise that can be ingested directly into secure email gateways (SEGs) to block incoming campaigns. By creating transport rules or blocklists based on these specific header elements, security analysts can proactively intercept and neutralize widespread phishing waves before users interact with them.

Why this answer

Email subject lines and sender domains are the most effective IOCs for detecting phishing campaigns that bypass email filters, because these characteristics are directly observable at the email gateway and are commonly reused across a campaign. Attackers often reuse subject line templates and sender domains (or lookalike domains) across many messages, making them reliable detection pivots. Unlike file hashes or registry keys, these IOCs do not require the payload to execute or the attachment to be present, so they catch the phishing attempt at delivery time.

Exam trap

The trap here is confusing host-based IOCs (hashes, registry keys) with network/email-layer IOCs — candidates often pick file hashes because they sound 'technical,' but the question asks about detecting phishing emails at the filter-bypass stage, which requires email-observable indicators.

How to eliminate wrong answers

Option A is wrong because registry keys modified by the payload are host-based IOCs that only appear after the malware has already executed, so they cannot detect phishing emails at the email gateway and are useless for campaigns that bypass filters without executing. Option B is wrong because file hashes of attached malware only detect known, previously seen payloads; phishing campaigns routinely mutate attachments or use unique hashes per recipient, and many phishing emails contain no attachment at all (just links). Option C is wrong because IP addresses of phishing servers are volatile — attackers rotate infrastructure rapidly, use CDNs, and compromise legitimate hosts — so IP-based IOCs have a very short useful lifespan and miss the email-layer characteristics that would catch the campaign earlier.

472
MCQhard

A security analyst is tasked with performing a risk assessment for a new web application. The application will handle sensitive customer data. Which of the following should the analyst do FIRST to identify vulnerabilities specific to the application?

A.Run a network vulnerability scan against the application server.
B.Perform a penetration test on the application.
C.Perform a source code review.
D.Conduct a threat model of the application.
AnswerD

Threat modelling systematically enumerates threats against the application's architecture, data flows and trust boundaries before any testing begins, satisfying the stem's requirement to identify vulnerabilities specific to this application. Unlike vulnerability scanning, which only detects known signatures, it exposes design-level weaknesses such as insecure data handling of sensitive customer information.

Why this answer

Conducting a threat model helps identify potential vulnerabilities early in the development lifecycle, especially for a new application handling sensitive data. Option A is wrong because a network vulnerability scan is too broad and does not focus on application-specific vulnerabilities. Option B is wrong because penetration testing is typically performed later after the application is deployed.

Option C is wrong because source code review is important but threat modeling should be performed first to identify risks at a higher level.

473
MCQmedium

An analyst is creating a compliance dashboard for management. Which of the following is the most relevant metric to include regarding patch management?

A.Number of antivirus alerts
B.Phishing simulation click rate
C.Mean time to detect incidents
D.Patch SLA compliance %
AnswerD

Patch SLA compliance percentage directly measures whether systems are being patched within the timeframes the organization has committed to, for example critical patches within 14 days, which is precisely what a management-facing compliance dashboard needs to show for the patch management program. It ties directly to the process being audited rather than to an adjacent security function.

Why this answer

Patch SLA compliance percentage directly measures how well the organization meets patch deadlines, which is a key compliance metric.

474
Multi-Selecteasy

A security analyst is reviewing IOCs from a threat intelligence feed. The analyst wants to enrich the IOCs using open-source tools. Which THREE tools are commonly used for IOC enrichment? (Select three.)

Select 3 answers
A.WHOIS
B.Wireshark
C.VirusTotal
D.Shodan
E.Nmap
AnswersA, C, D

WHOIS queries domain registration databases, returning registrar, registrant contact, creation and expiration dates, and nameserver records. For an IOC like a known malicious domain, WHOIS enables analysts to pivot on registration metadata, identify shared infrastructure, or detect typosquatting and recently registered domains. It is a read-only lookup service, not a traffic analysis tool, making it a first-line passive enrichment source.

Why this answer

WHOIS (A) is correct because it enriches domain and IP IOCs with registration data such as registrar, creation/expiration dates, name servers, and registrant contact details, which help attribute infrastructure to threat actors. VirusTotal (C) is correct because it aggregates results from dozens of antivirus engines, URL/domain scanners, and sandboxes to provide reputation, detection ratios, and behavioral context for hashes, URLs, domains, and IPs. Shodan (D) is correct because it enriches IP and service IOCs with internet-facing banner data, open ports, service versions, TLS certificates, and geolocation, revealing exposed infrastructure tied to an indicator.

Wireshark (B) is a packet capture and protocol analysis tool used for live traffic inspection, not for querying external reputation or registration data about IOCs. Nmap (E) is a network scanning and host-discovery utility used to probe systems directly, not an open-source enrichment service that correlates IOCs against third-party intelligence.

Exam trap

CS0-004 often tests whether candidates confuse enrichment tools (reputation, registration, exposure data) with analysis or scanning tools (Wireshark, Nmap), so options that are legitimate security tools but not enrichment sources are the trap.

475
Multi-Selectmedium

Which items help make a post-incident report useful for technical teams? (Choose two.)

Select 2 answers
A.Generic motivational slogans
B.Unrelated financial forecasts
C.Root cause and exploited control gaps
D.Specific remediation tasks with owners and validation steps
AnswersC, D

Identifying the precise root cause and the specific security control gaps that were exploited is fundamental to preventing recurrence. This technical detail allows engineering and security teams to understand exactly how the threat actor bypassed existing defenses, enabling them to deploy targeted mitigations, update firewall rules, or patch specific software vulnerabilities.

Why this answer

A post-incident report must include the root cause and exploited control gaps to enable technical teams to implement targeted remediation. Without identifying the specific vulnerability (e.g., unpatched CVE, misconfigured firewall rule, weak authentication mechanism) and the control failure that allowed the exploit, the report lacks actionable intelligence for hardening defenses.

Exam trap

The CS0-004 exam often tests the misconception that a post-incident report should include broad business or motivational content, but the exam expects candidates to recognize that only technical, actionable details (like root cause and control gaps) are useful for remediation teams.

476
MCQmedium

An organization is experiencing a DDoS attack targeting its web servers. Which of the following is the BEST short-term containment strategy?

A.Rebuild the web servers from backups.
B.Implement rate limiting on the firewall.
C.Reroute traffic through a DDoS mitigation service.
D.Disable the web server accounts.
AnswerC

Rerouting traffic to a cloud-based DDoS mitigation or scrubbing service (via DNS or BGP redirection) is the most effective containment strategy. This allows the provider to filter out malicious traffic at the network edge using global scrubbing centers, ensuring that only clean, legitimate traffic reaches the organization's origin servers.

Why this answer

Short-term containment for DDoS often involves rerouting traffic through a scrubbing center or cloud-based DDoS mitigation service that filters malicious traffic.

477
MCQhard

During forensic analysis of a compromised server, the analyst finds that the attacker deleted the system logs. Which data source is most likely to still contain relevant evidence?

A.Memory dump from before the attack
B.Endpoint detection and response (EDR) telemetry
C.Network flow logs
D.Backup tapes
AnswerB

Endpoint Detection and Response (EDR) telemetry provides granular, real-time visibility into system activities, including process execution, file modifications, registry changes, and network connections, often stored off-host in a centralized repository. This rich dataset is crucial for forensic analysis as it allows investigators to reconstruct the attack timeline, identify initial access vectors, track lateral movement, and pinpoint malicious binaries or scripts. EDR's continuous monitoring capabilities ensure that even ephemeral attacker actions are captured and available for post-incident investigation.

Why this answer

EDR telemetry is the most reliable source because it captures process creation, network connections, file modifications, and registry changes in real-time, storing them off-host. Even if an attacker deletes local system logs, the EDR agent's telemetry stream remains intact on the central management server, providing a forensic timeline of the attacker's actions.

Exam trap

CompTIA often tests the misconception that backup tapes are the ultimate forensic source, but the trap here is that attackers often delete logs during the incident, and only real-time, off-host telemetry (like EDR) preserves the sequence of events that occurred on the compromised host.

How to eliminate wrong answers

Option A is wrong because a memory dump from before the attack would not contain evidence of the attack itself; it captures a snapshot of the system state at that earlier time, not the attacker's activities. Option C is wrong because network flow logs (e.g., NetFlow, IPFIX) only record metadata like source/destination IPs, ports, and byte counts, not the actual system-level events (e.g., log deletion, process execution) that occurred on the compromised server. Option D is wrong because backup tapes contain point-in-time copies of files and system state, but they are typically taken on a schedule (e.g., nightly) and may not include the logs that were deleted during the attack window; moreover, restoring from backup is time-consuming and may overwrite current evidence.

478
MCQmedium

An analyst is creating a YARA rule to detect a specific malware family that uses the string 'evil' in its PE file. Which of the following rule structures is correct?

A.rule detect_malware { strings: $a = "evil" condition: $a }
B.rule detect_malware { strings: "evil" condition: $a }
C.rule detect_malware { condition: $a = "evil" }
D.if "evil" in file then alert
AnswerA

This is the correct YARA rule syntax. It defines a rule named detect_malware, declares a string identifier $a assigned to the literal byte sequence "evil" inside the strings section, and then uses that identifier as the condition. The condition $a evaluates to true if the string 'evil' is found anywhere in the scanned file. YARA requires a dollar-sign prefix for string identifiers, an equals sign to bind the literal value, and a condition that references the identifier without quotes or further assignment. This rule compiles and will trigger a match when the file contains the specified string.

Why this answer

A valid YARA rule requires the structure: rule <name> { strings: $var = "pattern" condition: $var }. Option A correctly declares a string variable $a assigned to 'evil' and then references $a in the condition, which is the canonical YARA syntax.

Exam trap

CS0-004 often tests the exact YARA rule skeleton — candidates pick options that omit the $variable assignment in the strings section or use imperative pseudocode instead of the rule/strings/condition block.

How to eliminate wrong answers

Option B is wrong because it omits the variable assignment ($a =) in the strings section, so the condition references an undefined identifier $a — YARA will fail to compile. Option C is wrong because it places the string assignment inside the condition block and leaves the strings section empty, which is invalid syntax. Option D is wrong because 'if ... then alert' is pseudocode, not YARA syntax — YARA rules use the rule/strings/condition block structure, not imperative if-then statements.

479
Multi-Selectmedium

A security team is tuning a SIEM rule that alerts on all outbound connections to IP addresses classified as 'high risk' by threat intelligence. The rule generates many false positives because some legitimate services use these IPs. Which two actions should the analyst take to reduce false positives? (Select TWO.)

Select 2 answers
A.Ignore the false positives and continue
B.Increase the risk score threshold to only alert on very high risk IPs
C.Expand the rule to include all risky IPs
D.Add known legitimate IP addresses to an exclusion list
E.Disable the rule
AnswersB, D

Raising the risk score threshold means only IPs with very high threat-intelligence risk scores trigger alerts, filtering out lower-scored IPs that legitimate services use. This directly reduces the false positives described in the stem while retaining detection of genuinely high-risk connections.

Why this answer

Option B is correct because raising the risk score threshold so the rule only fires on 'very high risk' IPs narrows the alert set to indicators with stronger threat-intelligence confidence, filtering out lower-confidence 'high risk' entries that frequently match legitimate services. Option D is correct because adding the verified legitimate IP addresses to an exclusion list (allowlist) suppresses alerts for known-good destinations while keeping detection coverage for the remaining high-risk IPs. Option A is wrong because ignoring false positives leaves the rule noisy and risks missing true malicious connections.

Option C is wrong because expanding the rule to include all risky IPs would increase, not reduce, false positives. Option E is wrong because disabling the rule eliminates detection entirely, creating a blind spot rather than tuning the rule.

Exam trap

CS0-004 often tests whether candidates choose the 'do nothing' or 'disable' options as shortcuts, when the correct answer is always a targeted tuning action (threshold adjustment or exclusion) that preserves detection while reducing noise.

480
MCQeasy

A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?

A.Publish a press release on the corporate website to demonstrate transparency
B.Identify which regulations apply and their specific notification requirements, including timelines and recipients
C.Send an internal email to all employees describing the breach and instructing them not to discuss it
D.Immediately notify all affected customers via email with the details of the breach
AnswerB

Different regulations, such as GDPR, HIPAA, or state breach laws, have distinct notification triggers, timelines, and recipients. Before communicating, the analyst must determine which laws apply based on data type, location, and affected individuals. This ensures the organization meets its legal obligations and avoids penalties. It is the foundational step in building a compliant communication plan, as it dictates what, when, and to whom notifications must be sent.

Why this answer

When a data breach involves regulated data, the first step is to determine which laws apply and what they require. Notification timelines, recipients, and content vary by regulation. Identifying these obligations ensures the communication plan is legally compliant and avoids premature or inadequate disclosures.

Only after this analysis should customer, public, or internal communications be drafted.

Exam trap

The trap here is rushing to notify affected parties or the public before confirming which regulations apply, which can lead to legal penalties and inconsistent messaging.

481
MCQmedium

A security analyst is using Qualys to perform a vulnerability scan on a public-facing web server. The scan results show that the server is running an outdated version of Apache HTTP Server with multiple known vulnerabilities. The analyst checks the vendor security advisories and finds that a patch was released three months ago. However, the server is in a staging environment and not yet in production. What should the analyst recommend?

A.Only patch if the vulnerability is rated critical.
B.Patch the server immediately because it poses a risk to the staging network.
C.Do not patch because the server is not in production.
D.Wait until the server moves to production to patch.
AnswerB

Staging environments often mirror production configurations and may reside on networks with access to sensitive internal resources or active directory domains. Patching this vulnerability immediately is critical because an attacker could exploit the staging server to establish a foothold and perform lateral movement across the corporate network.

Why this answer

Even in staging, an unpatched public-facing web server with known Apache vulnerabilities is exploitable and can serve as a pivot point into the staging network or be used to attack other environments. Best practice is to patch immediately regardless of environment, because staging often shares credentials, network paths, or data with production. Deferring patching until production migration compounds risk.

Exam trap

CS0-004 often tests the misconception that non-production environments are low risk, when internet-facing staging hosts with known CVEs are prime targets for lateral movement.

How to eliminate wrong answers

Option A is wrong because severity ratings are contextual — a medium-severity flaw on an internet-facing host can still be chained into a critical exploit, and selective patching based only on CVSS ignores exposure. Option C is wrong because 'not in production' does not mean 'not exposed' — staging environments are frequently internet-accessible and hold sensitive test data. Option D is wrong because waiting until production migration means the vulnerable version is promoted into production, exactly when the risk is highest.

482
MCQeasy

A medium-sized company has experienced a ransomware attack that encrypted critical file servers. The incident response team has contained the outbreak and restored data from backups. The CISO has requested a post-incident report. The report must include a timeline, root cause analysis, lessons learned, and recommendations. The security team is currently overwhelmed with recovery tasks. The CISO wants the report delivered in 24 hours. Which of the following is the BEST course of action for the security analyst assigned to write the report?

A.Wait until all recovery tasks are complete to ensure accurate information
B.Delegate the report writing to a junior analyst while focusing on technical recovery
C.Use the incident response playbook template to draft the report immediately, incorporating available information and noting gaps
D.Request an extension from the CISO due to resource constraints
AnswerC

Leveraging an established incident response playbook template for report drafting is a highly effective strategy, especially under time constraints. This approach ensures that critical information fields are addressed systematically, even if initial data is incomplete, and allows for the immediate documentation of known facts, timelines, and current status. By explicitly noting information gaps, the report remains transparent about its current state, facilitates timely communication to stakeholders, and provides a structured framework for subsequent updates and refinements as recovery progresses.

Why this answer

The CISO needs a timely post-incident report within 24 hours, and using the incident response playbook template allows the analyst to immediately draft the report with available information while noting gaps. This approach balances the urgency of the deadline with the need for structured documentation, even though recovery tasks are ongoing. It ensures that critical findings are captured promptly without waiting for full recovery, which could delay lessons learned and recommendations.

Exam trap

CompTIA often tests the tension between thoroughness and timeliness in incident reporting, and the trap here is that candidates may choose to wait for complete data (Option A) or delegate (Option B) instead of using a structured template to meet the deadline while acknowledging information gaps.

How to eliminate wrong answers

Option A is wrong because waiting until all recovery tasks are complete would likely exceed the 24-hour deadline, delaying the CISO's required report and potentially missing the window for actionable recommendations. Option B is wrong because delegating to a junior analyst without proper oversight could introduce inaccuracies in the timeline, root cause analysis, and lessons learned, especially if the junior lacks incident response experience. Option D is wrong because requesting an extension due to resource constraints may not be feasible given the CISO's explicit deadline, and it fails to leverage available templates and existing data to meet the requirement.

483
MCQmedium

A vulnerability scanner reports a finding with a CVSS v3.1 base score of 7.5 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. What does this indicate about the vulnerability?

A.It has high impact on integrity
B.It requires authentication to exploit
C.It has high impact on confidentiality
D.It has high impact on availability
AnswerD

The A component of the CVSS v3.1 vector is H, which is the Availability Impact metric and indicates that the exploit can cause a total loss of availability, such as a denial of service. Unlike the C and I metrics, which are both N, the A metric is the only one rated high, so this option correctly identifies the finding's high impact on availability.

Why this answer

The vector shows high impact to availability (A:H) and no impact to confidentiality or integrity, so the vulnerability primarily affects availability.

484
MCQmedium

A security team is responding to a phishing incident that led to credential compromise. Which of the following is the BEST short-term containment action to prevent further damage?

A.Disable the compromised user account.
B.Rebuild the user's workstation.
C.Block the phishing email's source IP at the firewall.
D.Rotate all domain admin passwords.
AnswerA

Disabling the compromised account is the most immediate and effective containment action to halt active exploitation. It instantly revokes the attacker's access to network resources, cloud services, and email, preventing lateral movement or data exfiltration using those specific credentials. This action buys the incident response team time to investigate the scope of the breach without allowing further unauthorized activity.

Why this answer

Short-term containment aims to stop the attack quickly. Disabling the compromised account prevents the attacker from using the stolen credentials to access resources.

485
MCQmedium

Which of the following is a key component of a vulnerability report that provides a high-level overview for management?

A.Remediation timeline
B.Executive summary
C.Findings by severity
D.Risk acceptance
AnswerB

The executive summary condenses technical findings into business risk and impact language, giving management a high-level overview without operational detail. It satisfies the audience-specific requirement, unlike the technical sections that enumerate vulnerabilities, affected assets, and remediation steps for practitioners.

Why this answer

The executive summary condenses findings for management to quickly understand the state of vulnerabilities.

486
MCQmedium

During a threat hunting exercise, the hunter creates a hypothesis based on recent threat intelligence about a new ransomware variant that uses scheduled tasks for persistence. Which ATT&CK technique should the hunter focus on?

A.T1566.001 (Spearphishing Attachment)
B.T1059.001 (PowerShell)
C.T1053.005 (Scheduled Task)
D.T1547.001 (Registry Run Keys)
AnswerC

Scheduled Tasks (T1053.005) represent a highly common persistence mechanism where adversaries abuse task scheduling utilities, such as Windows Task Scheduler, to execute malicious binaries at specific intervals or system events. This technique directly aligns with the threat hunter's hypothesis of identifying persistent execution methods that survive reboots and user logoffs.

Why this answer

Scheduled tasks are a persistence technique (T1053.005). The hunter should focus on the persistence tactic and the specific technique for scheduled tasks.

487
MCQmedium

A security analyst is using Burp Suite to test an API endpoint. The analyst notices that the API returns detailed error messages when invalid input is provided, revealing database schema information. Which OWASP Top 10 category does this issue primarily relate to?

A.Injection
B.Security Misconfiguration
C.Broken Access Control
D.Cryptographic Failures
AnswerB

Verbose error messages, such as stack traces or database debugging information returned by an API endpoint, represent a classic security misconfiguration. Properly configuring the application server to suppress detailed debugging outputs and return generic error messages prevents attackers from mapping the internal architecture and finding exploitable vectors.

Why this answer

Detailed error messages revealing internal details are a form of security misconfiguration. The OWASP Top 10 category 'Security Misconfiguration' includes verbose error messages that leak information.

488
MCQhard

During a penetration test, a tester successfully exploits a vulnerability in a web application and gains a shell on the backend server. The tester then attempts to pivot to other hosts. Which of the following security controls would be most effective in limiting lateral movement in this scenario?

A.Host-based intrusion prevention system (HIPS)
B.Full disk encryption
C.Network segmentation with strict firewall rules
D.Application whitelisting
AnswerC

Network segmentation logically divides a network into smaller, isolated subnets, significantly limiting direct communication paths between different security zones. When combined with strict firewall rules that enforce a "deny by default" policy and only permit explicitly authorized traffic, this architecture severely restricts an attacker's ability to move laterally from a compromised host in one segment to other critical systems in different segments, thereby containing breaches and hindering further compromise.

Why this answer

Network segmentation with strict firewall rules (C) is the most effective control because it directly restricts the ability of an attacker who has compromised one host to initiate connections to other hosts. By enforcing least-privilege network access between segments (e.g., using VLANs and ACLs), lateral movement techniques such as port scanning, SMB relay, or RDP brute force are blocked at the network layer, regardless of the attacker's shell access.

Exam trap

CompTIA often tests the misconception that endpoint controls like HIPS or application whitelisting are sufficient to stop lateral movement, but the trap here is that once an attacker has a shell, they can often bypass or disable host-based controls, whereas network segmentation is a preventive control that operates independently of the compromised host's state.

How to eliminate wrong answers

Option A is wrong because a host-based intrusion prevention system (HIPS) monitors and blocks malicious behavior on the compromised host itself, but once the attacker has a shell, they can often disable or evade HIPS before pivoting; HIPS does not prevent network-level lateral movement to other hosts. Option B is wrong because full disk encryption protects data at rest on the compromised host's storage, but it does nothing to prevent the attacker from using the host as a pivot point to reach other systems over the network. Option D is wrong because application whitelisting controls which executables can run on the compromised host, but the attacker already has a shell and can use built-in OS tools (e.g., PowerShell, netcat) or living-off-the-land binaries to pivot; whitelisting does not block network connections to other hosts.

489
MCQhard

An analyst suspects a process hollowing attack on an endpoint. Which of the following EDR telemetry findings would best support this hypothesis?

A.A legitimate process (e.g., svchost.exe) created in a suspended state and later resumed with changed memory contents
B.A process with the same name as a Windows system process but running from a temporary directory
C.A process injecting code into a legitimate running process
D.An unknown process making network connections to multiple internal IPs
AnswerA

Process hollowing specifically involves spawning a legitimate system process (like svchost.exe) in a suspended state using the CREATE_SUSPENDED flag, unmapping its original executable code from memory, writing a malicious payload into that hollowed space, and then resuming the thread. This allows the malware to masquerade as a trusted process while executing arbitrary code under its identity.

Why this answer

Process hollowing involves creating a legitimate process in a suspended state, then replacing its memory with malicious code. This leaves the original path unchanged but the process may exhibit unusual child process behavior.

490
MCQeasy

A company uses a cloud-based identity provider (IdP) for single sign-on (SSO) to all applications. The SOC receives an alert that a user's account logged in from an IP address associated with a country where the company has no offices. The user is currently on a planned vacation and is not in that country. The analyst reviews the authentication logs and sees the login used a valid token and correct multi-factor authentication (MFA) method. Which of the following is the BEST initial step to handle this alert?

A.Review the user's recent activity for other anomalies.
B.Add the IP address to the block list.
C.Contact the user to verify if they logged in.
D.Disable the user account immediately.
AnswerC

Quickest way to confirm if it was the user or a compromise.

Why this answer

The best initial step is to contact the user to verify if they logged in. Since the login used a valid token and correct MFA, it could be authorized (e.g., user using a VPN or traveling). Disabling the account or blocking the IP without verification could impact productivity if the login is legitimate.

Reviewing recent activity may be useful but should come after contacting the user to avoid delays.

Exam trap

The trap is to immediately disable the account or block the IP when seeing an anomalous login. However, because the authentication succeeded with MFA, the first step should be verification with the user before taking irreversible actions.

491
Multi-Selecteasy

A security analyst is using a vulnerability scanner to identify missing patches on Windows servers. The scanner uses plugins that reference Common Vulnerabilities and Exposures (CVE) identifiers. Which THREE of the following are components of a CVSS v3.1 base score vector?

Select 3 answers
A.Attack Vector (AV)
B.Confidentiality (C)
C.Privileges Required (PR)
D.Remediation Level (RL)
E.Exploitability (E)
AnswersA, B, C

Attack Vector (AV) is a base metric that describes the context by which a vulnerability can be exploited, such as network, adjacent, local, or physical. This metric directly influences the CVSS exploitability subscore and is fundamental because it determines the remote vs. local nature of the attack. A network attack vector is typically the most severe because it allows exploitation from anywhere on the internet without prior access.

Why this answer

The CVSS v3.1 base score vector is composed of Exploitability metrics (Attack Vector, Attack Complexity, Privileges Required, User Interaction) and Impact metrics (Confidentiality, Integrity, Availability). Option A, Attack Vector (AV), is correct because AV is an Exploitability metric in the base group, with values Network (N), Adjacent (A), Local (L), and Physical (P). Option B, Confidentiality (C), is correct because C is one of the three Impact metrics (C/I/A) in the base score, reflecting the degree of confidentiality loss.

Option C, Privileges Required (PR), is correct because PR is an Exploitability metric in the base group, with values None (N), Low (L), and High (H). Option D, Remediation Level (RL), is incorrect because RL belongs to the Temporal score group, not the base score. Option E, Exploitability (E), is incorrect because E is a Temporal metric (with values Unproven, Proof-of-Concept, Functional, High, Not Defined), not a base metric.

Exam trap

CS0-004 often tests whether candidates can distinguish Base metrics from Temporal metrics, tricking them into selecting Exploitability (E) or Remediation Level (RL) because those sound like core vulnerability characteristics.

492
MCQeasy

A security analyst is preparing a monthly dashboard for the board of directors. Which metric would best demonstrate the effectiveness of the security program in reducing risk?

A.Number of security incidents detected.
B.Mean time to detect (MTTD) and mean time to respond (MTTR).
C.Percentage of employees who completed security awareness training.
D.Number of firewall rules configured.
AnswerB

Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) are crucial operational metrics that directly quantify the efficiency and effectiveness of a security program's incident management lifecycle. MTTD measures the speed at which threats are identified, reflecting the efficacy of monitoring and alerting systems. MTTR assesses the swiftness of containment, eradication, and recovery efforts, indicating the incident response team's proficiency in neutralizing threats and minimizing their impact.

Why this answer

Mean time to detect (MTTD) and mean time to respond (MTTR) directly quantify the security program's operational efficiency in identifying and containing threats, which reduces the window of exposure and potential damage. A lower MTTD/MTTR indicates faster detection and response, directly correlating with reduced risk from incidents. This makes it the best metric for demonstrating risk reduction effectiveness to the board.

Exam trap

CompTIA often tests the misconception that volume or compliance metrics (like incident count or training completion) directly indicate risk reduction, when in fact operational efficiency metrics (MTTD/MTTR) are the true measure of a security program's effectiveness in minimizing impact.

How to eliminate wrong answers

Option A is wrong because the number of security incidents detected is a volume metric that does not indicate how quickly or effectively incidents are handled; a high number could reflect better detection rather than higher risk, and it provides no insight into response quality. Option C is wrong because the percentage of employees who completed security awareness training is a compliance or training metric that measures awareness, not the operational effectiveness of the security program in detecting and responding to active threats. Option D is wrong because the number of firewall rules configured is a configuration metric that does not measure risk reduction; more rules can increase complexity and attack surface without improving security posture.

493
MCQmedium

During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?

A.96 hours
B.72 hours
C.24 hours
D.48 hours
AnswerB

72 hours is the correct timeframe under GDPR Article 33(1), which states that a data breach notification must be made to the competent supervisory authority 'without undue delay' and, where feasible, no later than 72 hours after the controller becomes aware of the breach. This period is a fixed regulatory deadline, and failure to meet it without a documented justification (e.g., complexity of investigation) can result in significant administrative fines.

Why this answer

GDPR Article 33 requires notification of the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is a hard regulatory deadline and applies to breaches involving customer PII. Failure to notify can trigger fines under Article 83.

Exam trap

CS0-004 often tests whether candidates confuse GDPR's 72-hour authority notification with the 'without undue delay' data-subject notification or with shorter sector-specific windows like 24 hours.

How to eliminate wrong answers

Option A is wrong because 96 hours exceeds the GDPR limit—no EU regulation uses a 96-hour breach notification window. Option C is wrong because 24 hours is the timeline used by some other regimes (e.g., certain NIS2 or sector-specific rules) but not GDPR. Option D is wrong because 48 hours is not specified in GDPR; it may be confused with internal escalation SLAs, not the regulatory deadline.

494
Multi-Selecthard

A security analyst is investigating a potential advanced persistent threat (APT) that uses living off the land binaries (LOLBins). The EDR has flagged several processes. Which THREE process behaviors are most indicative of LOLBin abuse? (Choose THREE.)

Select 3 answers
A.mshta.exe executing JavaScript from a remote URL
B.explorer.exe opening the Start menu
C.notepad.exe opening a .txt file in the user's Documents folder
D.wmic.exe creating a process on a remote system
E.certutil.exe downloading an executable from a remote server
AnswersA, D, E

mshta.exe is a Microsoft HTML Application host that runs .hta files containing VBScript or JavaScript. When invoked with a remote URL, it executes attacker-supplied script directly from the internet, bypassing many application control policies and acting as a living-off-the-land binary (LOLBin). This behavior is highly suspicious because legitimate mshta execution is typically local and user-initiated, not a network fetch of script code.

Why this answer

Option A is correct because mshta.exe is a signed Microsoft LOLBin that normally renders HTML applications, so executing JavaScript from a remote URL is a classic abuse pattern for fileless execution and remote payload retrieval. Option D is correct because wmic.exe is a legitimate WMI command-line utility, and using it to create a process on a remote system (e.g., via /node and process call create) is a well-known lateral movement and remote execution technique. Option E is correct because certutil.exe is a built-in certificate utility whose -urlcache or -split options are frequently abused to download executables from remote servers, making it a hallmark LOLBin download cradle.

Option B is not indicative because explorer.exe opening the Start menu is normal user-interface behavior, and Option C is not indicative because notepad.exe opening a local .txt file in the user's Documents folder is ordinary, expected activity with no remote or execution-abuse characteristics.

Exam trap

CS0-004 often tests whether candidates can distinguish normal signed-binary behavior from anomalous LOLBin abuse — the trap is picking benign actions like opening a text file or Start menu because the binary itself is legitimate.

495
MCQeasy

A security analyst is conducting a vulnerability assessment of a web application. The assessment reveals that the application is vulnerable to SQL injection. Which of the following is the MOST effective remediation?

A.Upgrade the web application framework to the latest version
B.Deploy a web application firewall (WAF)
C.Use parameterized queries in the application code
D.Implement client-side input validation
AnswerC

Using parameterized queries directly addresses the root cause of SQL injection by ensuring that user input is treated strictly as data, not as executable code. This method pre-compiles the SQL statement, defining placeholders for input values. When user data is then bound to these parameters, the database engine interprets it literally, preventing malicious characters from altering the query's structure and effectively eliminating SQL injection vulnerabilities.

Why this answer

Parameterized queries (also known as prepared statements) are the most effective remediation for SQL injection because they separate SQL logic from user-supplied data by using placeholders. The database engine treats the input strictly as data, not executable code, which prevents an attacker from altering the query structure. This addresses the root cause at the application layer, unlike other controls that only mitigate or detect the attack.

Exam trap

CompTIA often tests the misconception that a WAF is a sufficient fix for SQL injection, but the trap here is that a WAF is a compensating control, not a remediation—the question asks for the 'most effective remediation,' which must address the root cause in the code.

How to eliminate wrong answers

Option A is wrong because upgrading the web application framework may patch known vulnerabilities but does not fix the insecure coding practice of concatenating user input into SQL statements; the SQL injection flaw remains if the code itself is not changed. Option B is wrong because a web application firewall (WAF) can detect and block some SQL injection payloads, but it is a reactive, signature-based control that can be bypassed with obfuscation or novel attack patterns, and it does not eliminate the underlying vulnerability. Option D is wrong because client-side input validation can be easily bypassed by an attacker using tools like Burp Suite or cURL to send crafted requests directly to the server, and it provides no security against server-side injection.

496
Matchingmedium

Match each regulatory framework to its focus.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Data privacy in EU

Payment card security

Healthcare data protection

Financial reporting controls

Federal information security

Why these pairings

Correct matches: GDPR with data protection, HIPAA with health info, PCI DSS with credit card security, SOX with financial reporting. Common confusions include swapping HIPAA and PCI DSS due to both involving 'security', and confusing GDPR with SOX.

497
MCQmedium

A user receives repeated MFA prompts and eventually approves one they did not initiate. Which behaviour should the analyst classify this as?

A.Password spraying only
B.MFA fatigue or push-bombing attack
C.DNS tunnelling
D.SSL certificate expiry
AnswerB

MFA fatigue, also known as push-bombing, is a social engineering attack where an attacker repeatedly sends multi-factor authentication push notifications to a target user's device after obtaining their primary credentials. The goal is to overwhelm or annoy the user into inadvertently approving one of the prompts, granting the attacker unauthorized access to the account. This tactic exploits human psychology, relying on the user's frustration or distraction to bypass the intended security control.

Why this answer

Repeated MFA prompts that the user eventually approves out of frustration or habit is the hallmark of MFA fatigue (also called push-bombing). The attacker sends a flood of push notifications to the user's device, hoping the user will mistakenly approve one to stop the annoyance. This bypasses the MFA control without needing to compromise the second factor.

Exam trap

The CS0-004 exam often tests the distinction between 'MFA fatigue' and 'password spraying' — candidates mistakenly choose password spraying because they focus on the repeated attempts, but the key is that the attacker already has the password and is abusing the MFA approval process, not guessing passwords.

How to eliminate wrong answers

Option A is wrong because password spraying involves trying a few common passwords against many accounts, not targeting a single user with repeated MFA prompts. Option C is wrong because DNS tunnelling encodes data in DNS queries/responses to exfiltrate data or establish C2, not to overwhelm a user with MFA approval requests.

498
MCQhard

An organization uses OpenSCAP to perform compliance scanning against STIGs for DoD environments. A scan reveals that several systems are non-compliant with STIG ID: V-XXXXX requiring 'The system must disable the guest account.' The configuration drift detection tool shows that the guest account was re-enabled after a recent patch. What is the MOST effective course of action?

A.Update the system baseline to enforce the guest account disabled state via Group Policy.
B.Apply an exception to the STIG requirement for these systems.
C.Re-run the OpenSCAP scan after the next patch cycle.
D.Manually disable the guest account on each non-compliant system.
AnswerA

Updating the Active Directory Group Policy Objects (GPOs) to enforce the disabled state of the guest account ensures centralized, automated remediation across all target systems. This approach establishes a permanent configuration baseline that actively prevents configuration drift, aligning the environment with the required STIG profile validated by OpenSCAP.

Why this answer

Configuration drift indicates that patches or changes are reverting settings. The most effective action is to update the baseline configuration management tool (e.g., Group Policy) to enforce the setting automatically.

499
Multi-Selectmedium

An incident responder is performing containment of a ransomware incident that has encrypted files on several file servers. Which THREE actions are appropriate for long-term containment and recovery? (Select THREE)

Select 3 answers
A.Blocking the ransomware's command-and-control IP at the firewall
B.Patching the vulnerability exploited by the ransomware
C.Rebuilding affected servers from known-good backups
D.Rotating all service account credentials
E.Isolating the affected network segment
AnswersB, C, D

Patching the specific vulnerability that the ransomware exploited is a definitive eradication measure because it closes the door at the root cause, preventing both the current strain and any similar variations from re-entering through the same path. This step, derived from the incident's root cause analysis, is essential for protecting not only the affected hosts but also all other unpatched systems in the environment. Without this patch, even after rebuilding or credential rotation, the same hole remains, leaving the network vulnerable to immediate reinfection.

Why this answer

Patching the exploited vulnerability (B) is correct because it removes the initial access vector, preventing the ransomware from re-infecting systems during long-term containment and recovery. Rebuilding affected servers from known-good backups (C) is correct because encrypted systems cannot be trusted after compromise; restoring from clean backups ensures integrity and enables recovery. Rotating all service account credentials (D) is correct because ransomware often harvests credentials for lateral movement and persistence, so rotating them invalidates stolen secrets and blocks re-entry.

Blocking the C2 IP (A) and isolating the affected segment (E) are valid immediate/short-term containment measures, but they do not address the root cause or restore operations, so they are not the long-term containment and recovery actions requested.

Exam trap

CS0-004 often tests the distinction between short-term containment actions (e.g., blocking IPs, isolating segments) and long-term containment/recovery actions (e.g., patching, rebuilding, rotating credentials), causing candidates to select immediate but temporary measures instead of permanent remediation steps.

500
Multi-Selecthard

A SIEM correlation rule for impossible travel is creating noise from VPN users. Which refinements should improve fidelity? (Choose two.)

Select 2 answers
A.Disable all identity alerts
B.Require a second signal such as new device, failed MFA, or mailbox rule creation
C.Add trusted VPN egress ranges as named/known locations
D.Treat every VPN login as malicious
AnswersB, C

Requiring a second, corroborating signal significantly enhances the fidelity of an impossible travel alert by reducing false positives. For instance, an impossible travel event combined with a new device registration, multiple failed MFA attempts, or the creation of a suspicious mailbox rule strongly indicates a compromised account rather than a legitimate user action. This multi-factor anomaly detection approach leverages contextual information to differentiate between benign user behavior and genuine threats, making the alert more actionable and reliable.

Why this answer

Requiring a second signal—such as a new device, failed MFA, or mailbox rule creation—adds an additional layer of verification that helps confirm the user's identity and intent. This reduces false positives from VPN users whose IP addresses may change rapidly, as the SIEM can now correlate the impossible travel event with other suspicious activities that indicate a genuine compromise rather than a legitimate VPN connection.

Exam trap

The CS0-004 exam often tests the misconception that disabling identity alerts is a valid refinement, but this would eliminate all identity-based detection, whereas the correct approach is to add context (trusted ranges and secondary signals) to reduce noise without losing detection capability.

501
MCQmedium

An organization is implementing a patch management process and wants to track compliance. They deploy patches to a test group of systems before rolling out to the entire environment. After patching the test group, they run a vulnerability scan and find that 95% of the vulnerabilities are resolved. What should the organization do next?

A.Run another scan on the test group in a week to confirm persistence.
B.Immediately deploy the patch to all systems without further testing.
C.Skip full deployment and rely on the test group results.
D.Verify the patch on test systems and then proceed with full deployment through change management.
AnswerD

This option aligns with established security best practices by ensuring the patch is first validated for efficacy and stability on test systems before proceeding. Utilizing the organization's formal change management process ensures that the production rollout is coordinated, scheduled during maintenance windows, documented, and equipped with a rollback plan to minimize operational impact.

Why this answer

After successful testing, the next step is to deploy the patch to the rest of the environment, following change management procedures.

502
MCQhard

A security team discovers a critical vulnerability in a widely used software component. The vulnerability has a CVSS score of 9.0, but there is no known exploit or patch available yet. However, the software vendor has released a workaround. According to the vulnerability management lifecycle, which action should the team prioritize first?

A.Wait for the vendor to release a patch before taking any action
B.Remove the affected component from all systems immediately
C.Increase monitoring of the affected systems but take no other action
D.Apply the workaround as a compensating control
AnswerD

Applying a workaround as a compensating control is the most appropriate immediate action when a critical vulnerability is discovered and a vendor patch is not yet available. A compensating control is an alternative security measure that reduces the risk to an acceptable level until a permanent solution can be implemented. This approach effectively mitigates the immediate threat without causing undue operational disruption, balancing security with business continuity.

Why this answer

Since no patch is available, the team should apply compensating controls to mitigate the risk. Remediation typically involves patching, but if not possible, compensating controls are the next best step.

503
Multi-Selecthard

A security analyst is prioritizing vulnerabilities from a scan. Which TWO factors should be considered to determine the remediation priority? (Select TWO)

Select 2 answers
A.Exploit code availability
B.Vendor patch availability
C.Number of affected systems
D.CVSS base score
E.Age of the vulnerability
AnswersA, C

When functional exploit code is publicly available in repositories like Metasploit or Exploit-DB, the technical barrier to entry for attackers drops significantly. This dramatically increases the likelihood of active exploitation, making it a critical, high-priority factor for immediate remediation over vulnerabilities that remain purely theoretical.

Why this answer

Exploit code availability is a critical factor because if working exploit code is publicly available, the vulnerability is far more likely to be actively exploited, increasing the risk and urgency for remediation. This directly impacts the likelihood of a breach, making it a key priority driver beyond just the CVSS score.

Exam trap

The CS0-004 exam often tests the misconception that CVSS base score alone determines priority, but the exam emphasizes that exploit availability and asset criticality (here, number of affected systems) are more actionable for remediation prioritization.

504
Multi-Selectmedium

Which findings should be included when reporting remediation performance to asset owners? (Choose two.)

Select 2 answers
A.Recently remediated findings awaiting validation
B.Every raw scanner debug line
C.Unrelated physical-access badge failures
D.Open critical findings past SLA by owner
AnswersA, D

Recently remediated findings awaiting validation belong in remediation performance reporting because they show work completed but not yet confirmed, satisfying the stem's requirement to report progress to asset owners. This distinguishes pending verification from open or closed findings, giving owners an accurate picture of outstanding risk exposure.

Why this answer

Option A is correct because recently remediated findings awaiting validation represent the current state of remediation work in progress, showing asset owners what has been fixed but not yet confirmed, which is essential for tracking remediation performance. Option D is correct because open critical findings past SLA by owner directly measures remediation performance against service-level agreements, highlighting overdue high-severity issues that require immediate attention and accountability. Option B is incorrect because raw scanner debug lines are low-level technical noise, not performance metrics relevant to asset owners.

Option C is incorrect because unrelated physical-access badge failures fall outside the scope of remediation performance reporting and belong to a different security domain.

Exam trap

The CS0-004 exam often tests the distinction between operational data (e.g., raw scanner logs) and actionable remediation metrics, tempting candidates to select overly detailed or irrelevant information instead of the concise, status-driven data that asset owners need.

505
Multi-Selectmedium

An organization is implementing security hardening for Kubernetes clusters. Which THREE of the following are common Kubernetes misconfigurations that should be addressed? (Select THREE)

Select 3 answers
A.Using namespaces to isolate workloads
B.Implementing network policies
C.Using hostPath mounts without restrictions
D.Running containers in privileged mode
E.Overly permissive RBAC roles
AnswersC, D, E

HostPath mounts allow a pod to mount an arbitrary path from the underlying node's filesystem directly into the container. Without restrictions such as requiring read-only mounts, allowing only specific directories, or disabling hostPath when possible, a compromised container can read or modify sensitive host files, plant malicious executables, or even achieve full node compromise. This is a critical misconfiguration that directly exposes the host and is absolutely a security risk.

Why this answer

Option C is correct because hostPath mounts without restrictions let a pod access the node's filesystem, enabling container escape, node compromise, and tampering with kubelet or other host files, so they should be limited via Pod Security Admission or OPA/Gatekeeper policies. Option D is correct because privileged containers run with all Linux capabilities and unrestricted device access, effectively granting root on the host and bypassing container isolation, so privileged: true should be disallowed except for tightly controlled system workloads. Option E is correct because overly permissive RBAC roles, such as wildcard verbs/resources or cluster-admin bindings, violate least privilege and let compromised service accounts read secrets, create pods, or escalate across the cluster.

Options A and B are not misconfigurations: using namespaces to isolate workloads and implementing network policies are recommended hardening practices that segment resources and restrict pod-to-pod traffic.

Exam trap

CS0-004 often tests whether candidates can distinguish security best practices (namespaces, network policies) from actual misconfigurations (hostPath, privileged mode, permissive RBAC); selecting a best practice as a misconfiguration is the common error.

506
MCQhard

During a threat hunting engagement, an analyst creates a hypothesis based on a recent threat intelligence report about a new APT group using DLL side-loading for persistence. The analyst decides to search for processes that have loaded a known vulnerable DLL. Which framework is most appropriate to map the TTPs?

A.Diamond Model
B.NIST CSF
C.MITRE ATT&CK
D.Cyber Kill Chain
AnswerC

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides threat hunters with a highly structured, granular matrix to map specific behaviors, identify coverage gaps in telemetry, and systematically formulate hypotheses regarding how advanced persistent threats (APTs) might execute actions within an environment.

Why this answer

MITRE ATT&CK is the most comprehensive framework for mapping adversary TTPs, including persistence techniques like DLL side-loading (T1574.002).

507
Multi-Selecthard

A security team is implementing container security scanning in their CI/CD pipeline. They want to scan container images for vulnerabilities and Kubernetes misconfigurations. Which THREE tools from the following list are best suited for this purpose? (Select THREE)

Select 3 answers
A.Burp Suite
B.Trivy
C.OpenSCAP
D.Clair
E.Snyk
AnswersB, D, E

Trivy is an open-source, fast, and comprehensive vulnerability scanner designed specifically for container images. It scans both OS packages (e.g., Alpine, Debian) and application dependencies (e.g., Python, Node.js) by comparing against a continuously updated CVE database, and it can be easily embedded into CI/CD pipelines with a simple CLI without requiring a separate server. Its low false-positive rate and support for multiple input formats (e.g., Docker, Podman, OCI) make it the most straightforward and effective choice among these options for the security team's container scanning need.

Why this answer

Trivy (B) is a purpose-built container and Kubernetes scanner that detects OS package and language dependency CVEs in images and also checks Kubernetes manifests and cluster configurations for misconfigurations, making it a direct fit for both requirements. Clair (D) is an open-source static analyzer from CoreOS/Quay that inspects container image layers against vulnerability databases, so it is well suited for image vulnerability scanning in a CI/CD pipeline. Snyk (E) provides container image vulnerability scanning plus Kubernetes and IaC misconfiguration detection, and it integrates natively into CI/CD workflows, satisfying both stated goals.

Burp Suite (A) is a web application security testing proxy for runtime HTTP traffic, not a container image or Kubernetes configuration scanner, so it does not belong. OpenSCAP (C) is a compliance and vulnerability scanner based on SCAP for hosts and operating systems, not for container image layers or Kubernetes misconfigurations, so it is not the best fit here.

Exam trap

The trap is selecting general-purpose security tools like Burp Suite or OpenSCAP because they are well-known, but the question specifically requires container image and Kubernetes misconfiguration scanning, which only Trivy, Clair, and Snyk address.

508
MCQhard

An analyst is investigating a suspected data exfiltration via HTTP. The analyst examines a PCAP file and finds a series of HTTP POST requests to an external site with varying 'Content-Length' values. The payloads appear to be base64-encoded strings. Which tool would be most effective for extracting and decoding the payloads for analysis?

A.Wireshark
B.Python with scapy
C.tcpdump
D.NetFlow
AnswerB

Python paired with the Scapy library provides a powerful programmatic environment to parse packet capture (PCAP) files. It allows analysts to write custom scripts that target specific layers, extract HTTP payload data, programmatically decode base64-encoded strings, and automate the identification of exfiltrated data at scale.

Why this answer

Python with scapy allows custom scripting to extract and decode payloads from PCAP files.

509
MCQmedium

During a memory analysis of a potentially compromised host, a security analyst finds a process with an executable image that is not present on disk. Which technique is most likely being observed?

A.Reflective DLL injection
B.Process hollowing
C.API hooking
D.DLL injection
AnswerB

Process hollowing involves spawning a legitimate process in a suspended state, unmapping its original executable image from memory, and replacing it with a malicious payload. Because the process's metadata and path point to a legitimate disk-backed executable while the memory contains unauthorized code, it creates a memory-only execution state that evades standard signature-based detection.

Why this answer

Process hollowing (a form of process replacement) involves creating a legitimate process in a suspended state, unmapping its original executable image from memory, and writing malicious code into that address space before resuming it. The result is a running process whose in-memory image does not correspond to any executable on disk — exactly the artifact described. This is a classic malware evasion technique used by families such as TrickBot and Emotet.

Exam trap

The trap is confusing process hollowing with reflective DLL injection — both involve in-memory code, but only hollowing produces a running process whose primary executable image is absent from disk.

How to eliminate wrong answers

Option A is wrong because reflective DLL injection loads a DLL directly into memory via a reflective loader without touching disk, but the host process's own executable image remains intact and present on disk — the anomaly would be an unbacked DLL module, not a missing primary image. Option C is wrong because API hooking intercepts function calls (e.g., via inline patches or IAT hooks) to redirect execution; it does not remove the process's executable image from disk or memory. Option D is wrong because DLL injection writes a DLL into a target process's address space, but the target's original executable image is still mapped and present on disk — the disk/memory mismatch described is specific to process hollowing.

510
MCQmedium

An analyst is investigating a suspected data breach. The analyst needs to identify which files were exfiltrated and preserve evidence. According to the order of volatility, which of the following should the analyst capture FIRST?

A.Contents of the hard drive
B.Network connections and listening ports
C.CPU registers and cache
D.System logs
AnswerC

CPU registers and L1/L2/L3 caches represent the absolute highest tier of volatility in digital forensics. This data changes nanosecond by nanosecond as the processor executes instructions, and it is completely lost the moment any tool is run or the system state changes. Analysts must capture this ultra-transient data first to preserve the immediate execution state of the system.

Why this answer

Order of volatility prioritizes capturing volatile data first. CPU registers and cache are the most volatile, then RAM, swap, disk, etc.

511
Multi-Selecthard

A legal hold is issued during an investigation. Which actions support it? (Choose two.)

Select 2 answers
A.Preserve relevant logs, mailboxes, images, and tickets
B.Let each team decide informally what to delete
C.Purge audit logs to save storage
D.Suspend routine deletion for in-scope evidence
AnswersA, D

Preserving relevant logs, mailboxes, images, and tickets is a critical action during a legal hold. This involves actively identifying, collecting, and securing all potentially discoverable electronic stored information (ESI) from various sources. These items often contain crucial metadata and content that can serve as evidence in legal proceedings, requiring strict chain of custody protocols to maintain their integrity and admissibility.

Why this answer

A legal hold (litigation hold) requires preservation of all potentially relevant electronically stored information (ESI). Preserving logs, mailboxes, images, and tickets ensures that data is not altered or deleted, maintaining its integrity for forensic analysis and legal proceedings. This action directly supports the hold by preventing spoliation and ensuring compliance with discovery obligations.

Exam trap

The CS0-004 exam often tests the misconception that cost-saving measures (like purging logs) are acceptable during a legal hold, when in fact any deletion—even for legitimate storage management—violates the preservation requirement and can be considered spoliation.

512
MCQmedium

A security analyst is creating a Sigma rule to detect suspicious usage of 'schtasks.exe' to create a scheduled task that runs an encoded PowerShell command. Which log source is most appropriate for this rule?

A.Windows Security Event Log (Event ID 4624)
B.Sysmon Event ID 1 (Process creation)
C.DNS server log
D.Windows PowerShell operational log
AnswerB

Sysmon Event ID 1 provides highly detailed telemetry regarding process creation, including the parent process, command-line arguments, and file hashes. This rich context is essential for Sigma rules designed to detect suspicious command-line flags or anomalous parent-child process relationships.

Why this answer

Sysmon Event ID 1 captures process creation with rich metadata including the full command line, parent process, hashes, and user context — exactly what's needed to detect 'schtasks.exe' spawning with an encoded PowerShell payload. Sigma rules map to log sources that expose these fields, and Sysmon EID 1 is the canonical source for process-creation-based detections. This lets the rule match on Image, CommandLine, and ParentImage to catch the suspicious pattern.

Exam trap

The trap is assuming the PowerShell operational log is the best source because the payload is PowerShell — but the detection target is the schtasks.exe process creation, which only process-creation telemetry captures.

How to eliminate wrong answers

Option A is wrong because Windows Security Event ID 4624 is a logon event, not process creation — it records authentication, not command lines, so it cannot detect schtasks.exe arguments. Option C is wrong because DNS logs only show name resolution queries and would not reveal the process or its encoded PowerShell argument. Option D is wrong because the PowerShell operational log captures PowerShell engine activity (script block logging, module logging) but not the initial schtasks.exe process creation with its command-line arguments — the detection target is the scheduled task creation, not the PowerShell execution itself.

513
Multi-Selecthard

A security analyst is performing an API vulnerability test using OWASP ZAP. The analyst finds several issues. Which THREE of the following are common API vulnerabilities according to OWASP? (Select THREE.)

Select 3 answers
A.Broken Object Level Authorization
B.Excessive Data Exposure
C.SQL Injection
D.Cross-Site Scripting (XSS)
E.Broken Authentication
AnswersA, B, E

Broken Object Level Authorization (BOLA) is the most direct and correct answer because it occurs when an API fails to enforce per-object permissions, allowing an attacker to access, modify, or delete another user's data simply by substituting an object ID in an API request. For example, changing 'GET /api/user/123' to 'GET /api/user/456' can expose another user's private information if the server does not verify that the authenticated principal owns the requested object. This flaw is specifically catalogued as API1:2019 in the OWASP API Top 10 and is a primary focus of API penetration testing.

Why this answer

Broken Object Level Authorization (A) is correct because it is the #1 item on the OWASP API Security Top 10, occurring when an API fails to verify that the requesting user owns or is authorized to access the specific object referenced by an ID in the request (e.g., /api/users/123), allowing horizontal privilege escalation via IDOR-style attacks. Excessive Data Exposure (B) is correct because it is a recognized OWASP API risk where APIs return full objects with sensitive fields (PII, tokens, internal attributes) and rely on the client to filter, exposing data the consumer should never receive. Broken Authentication (E) is correct because it is a core OWASP API Security Top 10 category covering weak credential handling, missing token validation, improper JWT verification, and absent rate limiting on authentication endpoints.

SQL Injection (C) and Cross-Site Scripting (D) are not API-specific OWASP API Top 10 categories; they are classic web application vulnerabilities listed in the OWASP Top 10 for web apps, and while an API could theoretically be affected, they are not among the API-specific vulnerabilities the question asks for.

Exam trap

CS0-004 often tests whether candidates can distinguish the OWASP API Security Top 10 from the classic OWASP Top 10 web application list — SQL Injection and XSS are web-app categories, not API-specific ones, so candidates who select them lose the question.

514
MCQmedium

A server team needs to fix an OpenSSL vulnerability across Linux hosts. What should the technical remediation section include? If the primary audience is technical remediation owner, which content choice is most appropriate?

A.Only a red/yellow/green chart
B.Only the CVE headline
C.Affected assets, package versions, patch commands or vendor guidance, validation method, and rollback notes
D.Only estimated financial loss
AnswerC

This comprehensive report provides the precise, actionable intelligence a server team needs to efficiently and safely remediate vulnerabilities. By detailing affected assets and their exact package versions, it pinpoints the scope of work, while patch commands or vendor guidance offer clear instructions for implementation. Including a validation method ensures the fix is confirmed successful, and rollback notes provide crucial risk mitigation. This holistic approach enables effective patching and minimizes operational disruption.

Why this answer

A technical remediation section must provide actionable steps for the remediation owner. This includes identifying affected assets and package versions, specifying patch commands or vendor guidance, outlining a validation method to confirm the fix, and including rollback notes in case the patch causes issues. Without these details, the remediation owner cannot execute the fix reliably or verify its success.

Exam trap

The CS0-004 exam often tests the distinction between reporting to executives (which uses summary charts) and providing technical remediation details to the remediation owner, leading candidates to mistakenly choose a high-level summary like a chart or CVE headline instead of the actionable, step-by-step content required for the technical audience.

How to eliminate wrong answers

Option A is wrong because a red/yellow/green chart is a status summary for executive reporting, not a technical remediation plan; it lacks the specific commands, versions, and validation steps needed to fix an OpenSSL vulnerability. Option B is wrong because only the CVE headline (e.g., CVE-2024-XXXX) provides no actionable information; the remediation owner needs affected package versions, patch commands, and rollback procedures, not just a vulnerability identifier.

515
MCQmedium

A security analyst is reviewing a SIEM alert indicating a high number of failed authentication attempts from a single IP address against multiple user accounts. The analyst checks the logs and finds the IP belongs to a known vulnerability scanner used by the internal security team. How should the analyst classify this alert?

A.True positive - unauthorized access attempt
B.False positive - authorized activity
C.True positive - lateral movement
D.False negative - missed detection
AnswerB

This is the correct classification because the SIEM generated an alert for behavior that, while anomalous or aggressive in appearance, is actually benign and pre-authorized. Vulnerability scanners frequently trigger brute-force or account-harvesting alerts during routine credentialed checks. Labeling this as a false positive allows analysts to tune the SIEM rules to exclude the scanner's IP address from future alerts.

Why this answer

The alert is triggered by authorized activity from a known internal scanner, so it is a false positive. The SIEM rule should be tuned to exclude this scanner or reduce its severity.

516
MCQmedium

During a security incident, the SOC team identifies indicators of compromise (IoCs) related to a new malware strain. Which type of threat intelligence report should be produced for the SOC team to enhance detection?

A.Tactical intelligence report with IoCs and detection signatures
B.Technical intelligence report on malware code analysis
C.Strategic intelligence report on global threat trends
D.Operational intelligence report on threat actor campaigns
AnswerA

Tactical threat intelligence focuses on the immediate, actionable technical details of an attack, such as IP addresses, file hashes, and specific YARA or Snort detection signatures. During an active security incident, SOC analysts rely on this real-time data to rapidly identify, scope, and contain malicious activity within the network.

Why this answer

Tactical threat intelligence focuses on immediate, actionable indicators such as file hashes, IP addresses, domain names, and YARA rules that SOC analysts can directly load into SIEM, IDS/IPS, or endpoint detection tools to enhance detection. Since the SOC team needs to detect the new malware strain, a tactical report with IoCs and detection signatures provides the specific technical artifacts required for signature-based and anomaly-based detection. This type of intelligence is consumed at the analyst level and is designed for machine-readable consumption, enabling rapid deployment of detection logic.

Exam trap

CS0-004 often tests the distinction between tactical, technical, operational, and strategic intelligence, and candidates frequently confuse tactical (IoCs for detection) with technical (malware analysis) or operational (campaign details) reports.

How to eliminate wrong answers

Option B is wrong because technical intelligence reports delve into malware reverse engineering, code analysis, and capabilities, which are more suited for threat researchers or malware analysts, not for immediate SOC detection enhancement. Option C is wrong because strategic intelligence reports address high-level trends, geopolitical risks, and long-term security posture for executives, lacking the granular IoCs needed for detection. Option D is wrong because operational intelligence reports cover threat actor campaigns, motivations, and upcoming attacks, which inform hunting and response planning but do not provide the direct detection signatures or IoCs that tactical intelligence does.

517
MCQmedium

A vulnerability management team has identified a critical vulnerability with a CVSS score of 9.8. The vulnerability affects a public-facing web server that handles sensitive customer data. The team decides to apply a patch immediately without going through the normal patch testing cycle. What type of patching procedure is this?

A.Rolling patch deployment
B.Patch compliance tracking
C.Emergency patching
D.Standard patch management
AnswerC

Emergency patching is a specialized, expedited process designed to rapidly deploy critical security updates to production systems, often bypassing standard testing and change management protocols due to the severe and immediate risk posed by a newly discovered vulnerability. Its primary objective is to quickly mitigate an active threat or prevent imminent exploitation, prioritizing risk reduction over typical operational considerations like extensive pre-deployment testing or scheduled maintenance windows. This approach is reserved for vulnerabilities deemed critical enough to warrant immediate action.

Why this answer

When a critical vulnerability is actively exploited or poses immediate risk, emergency patching procedures are used to expedite deployment without standard testing.

518
Multi-Selecthard

A security analyst is prioritizing vulnerabilities for remediation. The analyst has the following information: a vulnerability with a CVSS score of 9.0 that affects a public-facing web server, and a vulnerability with a CVSS score of 7.5 that affects an internal database server with sensitive data. Which two factors should the analyst consider when prioritizing? (Choose two.)

Select 2 answers
A.The presence of known exploits in the wild.
B.The vendor's patch release date.
C.The asset's exposure and criticality.
D.The number of open ports on each server.
E.The vulnerability publication date.
AnswersA, C

Vulnerabilities with active, publicly available exploits in the wild pose an immediate threat because the barrier to entry for attackers is significantly lowered. Prioritizing these flaws aligns with threat-intelligence-driven vulnerability management, ensuring that organizations defend against active, real-world campaigns before addressing theoretical risks.

Why this answer

The presence of known exploits in the wild directly impacts the likelihood of a vulnerability being weaponized. Even a high CVSS score (e.g., 9.0) may be less urgent if no exploit exists, while a lower-scored vulnerability (e.g., 7.5) with active exploitation poses an immediate threat. This aligns with the CVSS environmental metrics and threat intelligence integration in vulnerability management.

Exam trap

The CS0-004 exam often tests the misconception that CVSS score alone determines priority, whereas the correct approach combines CVSS with threat intelligence (exploit availability) and asset criticality/exposure.

519
MCQmedium

During a security incident, the SOC analyst determines that the attack is originating from an internal IP address belonging to the finance department. The incident response plan requires escalation to the appropriate team. Which of the following should the analyst contact first?

A.The legal department to handle potential compliance issues.
B.The system administrator for the finance department to isolate the host.
C.The finance department manager to confirm if the activity is authorized.
D.The human resources department for disciplinary action.
AnswerB

Isolating a host in the finance department without confirming the activity's legitimacy is a drastic and potentially disruptive action. Such a measure could severely impact critical business operations, leading to financial losses, operational delays, or an inability to perform essential tasks. Containment actions like isolation should only be executed after confirming malicious intent or unauthorized access, not as a first step during initial analysis.

Why this answer

During an active security incident where an attack is originating from an internal host, the immediate priority under incident response frameworks (such as NIST SP 800-61) is containment. The SOC analyst should contact the system administrator responsible for the system to isolate the host and prevent lateral movement or further damage. Contacting a non-technical department manager to ask if an 'attack' is authorized is incorrect and delays critical containment actions.

Exam trap

Do not confuse suspicious but potentially benign activity (like an authorized vulnerability scan) with an active 'attack'. If the stem specifies that an 'attack' is occurring, containment is the priority, and the technical custodian (system administrator) must be contacted to isolate the host. Do not delay containment by seeking authorization from non-technical managers.

How to eliminate wrong answers

Option A is wrong because legal department involvement is premature at this stage; compliance issues are only considered after unauthorized activity is confirmed, not before verifying authorization. Option B is wrong because isolating the host without first confirming the activity is authorized could disrupt legitimate business operations and violates the containment-first-verify principle; system administrators are contacted after authorization is denied. Option D is wrong because HR disciplinary action is a post-incident response step, only relevant after unauthorized activity is confirmed and attributed to an individual, not during initial triage.

520
Multi-Selectmedium

Which items belong in a vulnerability exception request? (Choose three.)

Select 3 answers
A.Business justification for delayed remediation
B.A request to remove the asset from inventory
C.Expiration or review date
D.Compensating controls
AnswersA, C, D

A robust business justification is paramount for a vulnerability exception request, detailing why immediate remediation is impractical or detrimental to critical business operations. This justification must clearly articulate the operational impact, financial cost, or technical incompatibility that prevents standard vulnerability resolution. It serves as the foundation for management's informed decision to temporarily accept the associated risk, demonstrating due diligence in risk management.

Why this answer

A vulnerability exception request is a formal process to accept the risk of not remediating a vulnerability within the standard timeframe. A business justification for delayed remediation is a core component because it documents the operational, financial, or technical reasons why the fix cannot be applied immediately, which is required for risk acceptance by management. Without this justification, the exception lacks the necessary context for approval and audit compliance.

Exam trap

The CS0-004 exam often tests the distinction between operational risk acceptance (exception request) and asset lifecycle management (decommissioning), leading candidates to incorrectly include asset removal as part of the exception process.

521
MCQmedium

An analyst needs to collect evidence for a compliance audit. Which type of evidence is most appropriate to demonstrate that access reviews are performed regularly?

A.Vulnerability scan reports
B.Access review reports
C.Configuration backups
D.Log exports of user activity
AnswerB

Access review reports provide direct, auditable evidence that an organization regularly evaluates user permissions against the principle of least privilege. These reports document the specific reviewers, the dates of the evaluations, and the formal decisions to approve or revoke access rights, satisfying strict compliance mandates.

Why this answer

Access review reports serve as direct evidence that reviews are conducted, showing dates and outcomes.

522
MCQhard

A security team uses the Common Vulnerability Scoring System (CVSS) v3.1 to prioritize vulnerabilities. They find a vulnerability with a base score of 7.5 and vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. However, the asset is a public-facing web server with no backups. The team also checks the Exploit Prediction Scoring System (EPSS) and sees a score of 0.95 (95% probability of exploitation in the next 30 days). Which action should the team take first based on prioritizing by risk?

A.Expedite patch testing and deployment, and consider emergency change procedures
B.Apply the patch within the next 30 days as part of routine maintenance
C.Implement a network-based intrusion prevention system signature to block exploitation attempts
D.Deploy the patch immediately in the production environment without testing
AnswerA

When a critical asset is affected by a vulnerability with a high Exploit Prediction Scoring System (EPSS) score, the probability of active exploitation is imminent. Expediting patch testing through an accelerated QA process and utilizing emergency change management procedures balances the urgent need to remediate the flaw with the necessity of preventing operational disruption. This approach ensures the vulnerability is closed rapidly without bypassing critical stability checks.

Why this answer

With a CVSS base score of 7.5 (High) affecting a public-facing web server, no backups, and an EPSS score of 0.95 indicating a 95% probability of exploitation within 30 days, the risk is extreme — active exploitation is imminent and recovery would be impossible without backups. The correct first action is to expedite patch testing and deployment while invoking emergency change procedures to compress the normal change-management timeline without abandoning testing. This balances urgency with the operational discipline required to avoid introducing new outages.

Exam trap

CS0-004 often tests whether candidates over-index on a single metric — the trap is choosing 'patch within 30 days' based on the High (not Critical) CVSS score while ignoring the EPSS 0.95 and the no-backup context that together demand emergency action.

How to eliminate wrong answers

Option B is wrong because a 30-day routine maintenance window is far too slow given a 95% EPSS exploitation probability — the server would likely be compromised before the patch lands. Option C is wrong because an IPS signature is a compensating control that may not exist for a zero-day or may be bypassed by obfuscation; it does not remediate the underlying vulnerability and should not be the first action. Option D is wrong because deploying an untested patch to production violates change-management discipline and risks an outage on a critical public-facing server — 'expedite testing' is the key phrase distinguishing A from D.

523
MCQmedium

During the detection and analysis phase of incident response, a security analyst identifies suspicious outbound traffic from a workstation to an external IP address known for command and control (C2) activity. Which classification should the analyst assign to this incident?

A.Insider threat
B.Data breach
C.Phishing
D.Malware
AnswerD

Outbound beaconing or persistent connections to a known command-and-control (C2) IP address are primary indicators of compromise (IoCs) associated with malware infections, such as trojans or botnet agents. Identifying this traffic during the detection and analysis phase allows analysts to confirm the presence of malicious software executing on the workstation.

Why this answer

The suspicious outbound traffic to a known C2 IP indicates that the workstation is likely infected with malware that is beaconing to its command and control server. This is a classic indicator of a malware infection, where the compromised host communicates with an external entity for instructions or data exfiltration. Therefore, the incident should be classified as malware.

Exam trap

CS0-004 often tests the ability to distinguish between incident classifications based on observable indicators; candidates might confuse malware with data breach when seeing outbound traffic, but the key is that C2 communication indicates an active malware infection, not necessarily a confirmed data breach.

How to eliminate wrong answers

Option A is wrong because an insider threat involves a trusted internal user misusing access, not external C2 communication. Option B is wrong because a data breach refers to unauthorized data exfiltration, but the scenario only mentions suspicious traffic, not confirmed data theft. Option C is wrong because phishing is an initial attack vector (e.g., deceptive emails), not the post-compromise C2 activity observed.

524
MCQhard

During a security incident, a SOC analyst identifies that customer PII has been exfiltrated. The company operates in multiple states and processes EU residents' data. Which of the following is the MOST critical immediate communication requirement?

A.Notify law enforcement within 24 hours
B.Notify affected customers within 48 hours
C.Notify the relevant data protection authority within 72 hours
D.Issue a press release within 24 hours
AnswerC

GDPR Article 33 explicitly mandates that in the event of a personal data breach, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights. This is a strict, legally binding timeline tested heavily on the CySA+ exam.

Why this answer

Notifying the relevant data protection authority within 72 hours is the most critical immediate communication requirement because the GDPR mandates that organizations report personal data breaches to the supervisory authority within 72 hours of becoming aware of the breach, especially when EU residents' data is involved. This is a legal obligation with strict timelines. Other notifications may be required but are not as immediately critical or universally mandated within that timeframe.

Exam trap

CS0-004 often tests the specific 72-hour GDPR notification requirement, while candidates may confuse it with other timelines like 24 or 48 hours for different notifications.

How to eliminate wrong answers

Option A is wrong because law enforcement notification is not universally required within 24 hours and varies by jurisdiction; it is not the primary immediate requirement under GDPR. Option B is wrong because notifying affected customers within 48 hours is not a specific GDPR requirement; the regulation requires notification to individuals without undue delay when high risk is present, but the 72-hour deadline applies to the authority. Option D is wrong because issuing a press release within 24 hours is not a legal requirement and could exacerbate the situation.

525
MCQeasy

An incident responder is classifying an incident. The incident involves ransomware encrypting files on multiple workstations, causing significant business disruption. Which severity level should be assigned to this incident?

A.Medium
B.High
C.Informational
D.Low
AnswerB

High-severity incidents involve severe degradation of critical services, widespread compromise, or the encryption of multiple production systems by ransomware. This classification triggers immediate escalation, mobilization of the full incident response team, and containment protocols to prevent catastrophic operational downtime or data loss.

Why this answer

Ransomware affecting multiple workstations causes high impact and likely critical business disruption, so it should be classified as high or critical severity. The highest typical level is 'Critical' (or similar).

Page 6

Page 7 of 10

Page 8

All pages