Courseiva

CompTIA CySA+ CS0-004 (CS0-004) — Questions 601–675

701 questions total · 10pages · All types, answers revealed

Page 8

Page 9 of 10

Page 10
601
MCQhard

A security analyst is performing memory acquisition on a compromised Linux server using LiME. The analyst needs to capture the memory image with minimal impact on the system. Which of the following parameters should the analyst use to ensure the output is forensically sound?

A.Use the --digest option to calculate a SHA256 hash during acquisition
B.Specify a format that compresses the output to reduce size
C.Ensure the output path is on a write-blocked device
D.Use the --reload option to reload the original kernel module after acquisition
AnswerC

Directing the acquired memory image to a write-blocked destination device is a critical forensic practice that prevents accidental overwriting, modification, or contamination of the evidence. This ensures that the captured volatile data remains in an untampered state from the exact moment of acquisition through the entire chain of custody.

Why this answer

Using a write blocker ensures the memory capture does not alter the storage media, preserving forensic integrity.

602
MCQhard

A security team is implementing a patch management process for a large enterprise. They must ensure that patches are tested before deployment to production. The team has a staging environment that mirrors production. During patch testing, they discover that a critical security patch for a database server causes a performance degradation of 30% in a key application. What should the team do next?

A.Skip the patch and rely on existing security controls.
B.Apply the patch to production immediately because it fixes a critical vulnerability.
C.Contact the vendor for a fix or workaround, and implement compensating controls in the meantime.
D.Deploy the patch to a subset of production servers to test performance.
AnswerC

Engaging the vendor for a hotfix or documented workaround while layering compensating controls, such as WAF rules, enhanced monitoring, or restricted access, addresses the vulnerability's risk in the interim without forcing the team to accept either the security exposure or the measured performance degradation.

Why this answer

The patch is critical but causes performance issues. The best approach is to work with the vendor for a resolution or apply compensating controls until a fix is available. Applying the patch blindly may disrupt operations, while skipping it leaves the vulnerability unaddressed.

603
Multi-Selectmedium

Which THREE of the following are essential tools and technologies used in a Security Operations Center (SOC) for monitoring and detection?

Select 3 answers
A.Firewall
B.Endpoint Detection and Response (EDR)
C.Intrusion Detection/Prevention System (IDS/IPS)
D.Security Information and Event Management (SIEM) system
E.Vulnerability scanner
AnswersB, C, D

EDR solutions provide continuous monitoring and threat detection directly on host devices, such as workstations and servers. By analyzing endpoint behavior, running processes, and system files in real-time, EDR allows analysts to identify and rapidly respond to advanced persistent threats that bypass traditional perimeter defenses.

Why this answer

Endpoint Detection and Response (EDR) is essential in a SOC because it provides continuous monitoring and analysis of endpoint activities, enabling detection of advanced threats such as fileless malware and ransomware. EDR tools collect telemetry data from endpoints, correlate it with threat intelligence, and allow for automated response actions, which are critical for real-time incident detection and investigation.

Exam trap

CompTIA often tests the distinction between tools that provide continuous monitoring and detection (SIEM, EDR, IDS/IPS) versus tools that are preventive or periodic (firewall, vulnerability scanner), leading candidates to incorrectly include the latter as essential SOC monitoring technologies.

604
Multi-Selectmedium

An organization is experiencing a distributed denial-of-service (DDoS) attack targeting its web servers. The incident response team is implementing containment strategies. Which TWO actions are appropriate for short-term containment of a DDoS attack? (Choose TWO.)

Select 2 answers
A.Rerouting traffic through a DDoS mitigation service or scrubbing center
B.Disabling the accounts of the attackers
C.Applying a security patch to the web server software
D.Rebuilding the web servers from clean images
E.Blocking the attacking IP addresses at the firewall
AnswersA, E

Rerouting traffic through a DDoS mitigation service or scrubbing center is the most effective response because these services employ specialized filtering, rate limiting, and behavioral analysis to distinguish legitimate user requests from malicious traffic, forwarding only clean traffic to the origin. This approach is well-suited for both volumetric floods and application-layer attacks, and it can be activated quickly by updating DNS or BGP to redirect traffic.

Why this answer

Option A is correct because rerouting traffic through a DDoS mitigation service or scrubbing center filters and absorbs malicious volumetric traffic before it reaches the web servers, providing immediate short-term relief during an active attack. Option E is correct because blocking the attacking IP addresses at the firewall quickly drops traffic from known malicious sources, reducing the immediate impact on the targeted web servers. Option B is not appropriate because DDoS attacks typically originate from botnets or spoofed sources, so disabling attacker accounts is neither feasible nor effective for containment.

Option C is incorrect because applying a security patch addresses a software vulnerability, not an ongoing traffic-flooding attack, and would not stop the DDoS. Option D is incorrect because rebuilding web servers from clean images is a recovery action, not a short-term containment measure, and does nothing to stop the incoming attack traffic.

Exam trap

The trap is confusing containment with eradication or recovery; candidates pick patching or rebuilding because they sound like fixes, but the question asks specifically for short-term containment of an active DDoS.

605
MCQhard

During a forensic investigation, an analyst finds a suspicious registry key that runs a program at startup. What is the best way to determine if the program is malicious?

A.Search the startup folder for the file
B.Compute the hash of the executable and query threat intelligence
C.Execute the program in a sandbox and observe behavior
D.Check the file's last modified timestamp
AnswerB

Generating a cryptographic hash (such as SHA-256) of the suspicious file and querying threat intelligence databases allows the analyst to quickly identify known malware. This passive analysis technique is safe, efficient, and leverages global threat data without risking exposure or executing the payload.

Why this answer

Computing the hash of the executable and querying threat intelligence (e.g., VirusTotal, AlienVault OTX) provides a definitive, objective indicator of known maliciousness by comparing the file's cryptographic fingerprint against global threat databases. This is the fastest and most reliable method to determine if the program is malicious without risking execution or relying on circumstantial evidence.

Exam trap

The CS0-004 exam often tests the distinction between 'best first step' and 'thorough analysis'—candidates mistakenly choose sandbox execution (Option C) because it seems more comprehensive, but the exam prioritizes speed and safety via hash-based threat intelligence queries.

How to eliminate wrong answers

Option A is wrong because searching the startup folder only confirms the file's location, not its maliciousness; legitimate programs also reside there. Option C is wrong because executing the program in a sandbox, while useful for behavioral analysis, is time-consuming and could still expose the system to risk if the sandbox is misconfigured; it is not the 'best' first step. Option D is wrong because the last modified timestamp is metadata that can be easily altered (timestomping) and provides no indication of malicious intent.

606
MCQeasy

A security analyst is reviewing NetFlow data and notices a significant amount of traffic from an internal host to a known malicious IP address on port 443. What tool would be most effective for further analyzing the payload of this traffic?

A.Nikto
B.Wireshark
C.Nmap
D.tcpdump
AnswerB

Wireshark captures and decodes packets in real time or from a saved capture file, reassembling TCP streams and, where the session is unencrypted or keys are available, rendering application-layer payload content, protocol fields, and TLS handshake metadata needed to determine what data is actually being exchanged with the malicious IP.

Why this answer

Wireshark captures and analyzes packet payloads, which is necessary for examining the content of encrypted or unencrypted traffic.

607
Multi-Selectmedium

What should be included in incident scoping for ransomware? (Choose three.)

Select 3 answers
A.Initial infected host and user context
B.The brand of office chairs near the server room
C.Backup integrity and last known clean restore point
D.Shares or systems touched by the compromised account
AnswersA, C, D

Identifying patient zero (the initial infected host) and the associated user context is critical during ransomware scoping. This allows analysts to pinpoint the entry vector, such as a phishing email or drive-by download, and determine the privilege level of the compromised account to predict potential lateral movement.

Why this answer

Identifying the initial infected host and user context is critical for understanding the attack vector, containing the threat, and preventing further spread. In ransomware incidents, the first compromised system often reveals the entry point (e.g., phishing email, RDP brute force) and the user account used, which helps scope the blast radius and prioritize remediation.

Exam trap

The CS0-004 exam often tests the ability to filter out irrelevant physical or administrative details (like office chairs) that distract from the core technical scoping steps required in incident response.

608
MCQeasy

Which of the following is the primary purpose of log normalisation in a SIEM?

A.Encrypt logs to protect confidentiality
B.Reduce storage space by compressing log data
C.Remove false positives from log entries
D.Convert logs into a standardised format for correlation and analysis
AnswerD

The primary objective of log normalization is to ingest disparate log formats from various vendors—such as firewalls, operating systems, and databases—and map them to a common schema, such as mapping "src_ip", "source", and "src" all to "source_ip". This standardization is essential for SIEM correlation engines to accurately analyze cross-platform events and detect complex attack patterns.

Why this answer

Log normalisation converts logs from different sources into a common, structured format so that the SIEM can correlate and analyse them uniformly.

609
MCQhard

A security analyst uses Wireshark to capture traffic and notices an unusually high number of DNS queries for random-looking subdomains under a single domain, such as 'a1b2c3.malicious.com'. The TTL values are very low. The analyst suspects DNS tunneling. Which of the following additional indicators would most strongly support this hypothesis?

A.Large number of NXDOMAIN responses
B.DNS queries with unusually large TXT record response sizes
C.High number of A record queries
D.Queries originating from a DNS server
AnswerB

DNS tunneling protocols frequently abuse TXT records because they can carry arbitrary, unstructured text payloads up to 65,535 bytes in size. When an analyst observes unusually large TXT record responses, it strongly indicates that an external server is sending encapsulated payload data or command-and-control instructions back to a compromised internal host.

Why this answer

DNS tunneling often uses TXT records to encode data, and the packet sizes can be larger than normal DNS queries.

610
Matchingmedium

Match each attack type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Deceptive email to steal credentials

Malware that encrypts data for ransom

Overwhelming a service with traffic

Injecting malicious SQL queries

Intercepting communication between parties

Why these pairings

Correct matches: Phishing (mass email), Spear phishing (targeted email), Whaling (targeting executives). Common confusions: Vishing is voice, Smishing is SMS.

611
Multi-Selecthard

An organization has identified a ransomware outbreak on several workstations. Which TWO actions should the incident response team take immediately?

Select 2 answers
A.Pay the ransom to recover data quickly.
B.Disconnect all network shares to prevent encryption.
C.Contact law enforcement for guidance.
D.Reimage all affected systems immediately.
E.Isolate the affected workstations from the network.
AnswersB, E

Disconnecting all network shares is a critical containment step because modern ransomware actively scans for mapped drives and open SMB shares, which it can encrypt just like local disks after compromising a single endpoint. By severing access to shared folders, you eliminate a large portion of the attack surface and prevent the ransomware from quickly encrypting centralized file servers and backup repositories. This action directly limits the blast radius while you deploy more comprehensive containment measures.

Why this answer

Option B is correct because disconnecting or disabling network shares (e.g., SMB/CIFS shares) immediately limits the ransomware's ability to propagate laterally and encrypt files on shared network resources, which is a critical containment step during an active outbreak. Option E is correct because isolating the affected workstations from the network (e.g., unplugging the Ethernet cable, disabling Wi-Fi, or placing them in a quarantine VLAN) prevents the malware from spreading to other systems and stops further command-and-control communication. Option A is not appropriate because paying the ransom is discouraged, does not guarantee data recovery, and may fund criminal activity.

Option C, while often advisable, is not an immediate technical containment action and typically follows initial isolation. Option D is not immediate because reimaging should occur only after containment, eradication, and forensic evidence preservation, not as a first response.

Exam trap

CS0-004 often tests the difference between containment and recovery actions, and candidates may confuse 'contact law enforcement' as an immediate step when it is actually a notification step that follows containment.

612
MCQmedium

A scan of Windows servers reports few findings, but the scanner used no credentials. The security manager suspects missing patch data. What should be changed? For tool configuration, Which scanner or pipeline change most directly improves result quality?

A.Increase only the port range
B.Trust the unauthenticated result as complete
C.Run authenticated scans using least-privilege scanner credentials
D.Disable host firewalls permanently
AnswerC

Running authenticated scans allows the vulnerability scanner to log into the target Windows servers using provided credentials, gaining internal access to query the operating system directly. This enables the scanner to accurately identify installed software, verify patch levels against known vulnerabilities, and assess local security configurations, providing a significantly more comprehensive and precise vulnerability report. Employing least-privilege credentials for the scanner account is crucial to minimize the potential impact should those credentials ever be compromised, adhering to security best practices.

Why this answer

Unauthenticated scans rely on network-visible services and banners, which miss registry-level patch data, OS configuration details, and installed updates. Authenticated scans with least-privilege credentials (e.g., using WMI, WinRM, or the Windows Update API) provide deep visibility into missing patches by querying the actual patch database (e.g., via the Microsoft Update Catalog or WSUS). This directly addresses the security manager's suspicion of missing patch data, making option C the correct choice.

Exam trap

The CS0-004 exam often tests the misconception that increasing scan scope (ports, protocols) or disabling firewalls can substitute for proper authentication, when in fact only credentialed scanning provides the access needed to assess patch levels accurately.

How to eliminate wrong answers

Option A is wrong because increasing the port range only expands the number of ports scanned for open services; it does not enable credential-based access to patch information, so missing patch data remains invisible. Option B is wrong because trusting unauthenticated results as complete ignores the fundamental limitation that unauthenticated scans cannot access registry, file system, or WMI data needed to verify patch levels, leading to false negatives. Option D is wrong because disabling host firewalls permanently is an insecure and drastic measure that does not grant the scanner the necessary privileges to read patch data; it only removes network-level access controls, not the authentication requirement.

613
Multi-Selectmedium

Which three of the following are effective techniques for prioritizing vulnerabilities for remediation in a vulnerability management program? (Choose three.)

Select 3 answers
.Applying the Common Vulnerability Scoring System (CVSS) base score as the sole prioritization metric
.Correlating vulnerabilities with active exploit campaigns and threat intelligence feeds
.Using asset criticality ratings derived from business impact analysis (BIA)
.Prioritizing vulnerabilities based solely on the age of the CVE
.Incorporating compensating controls that may reduce the effective risk of a vulnerability
.Focusing remediation efforts exclusively on vulnerabilities with a CVSS score of 9.0 or higher

Why this answer

Correlating vulnerabilities with active exploit campaigns and threat intelligence feeds is effective because it prioritizes vulnerabilities that are currently being exploited in the wild, which directly reduces the risk of a breach. This approach aligns remediation with real-world attacker behavior rather than theoretical severity.

Exam trap

CompTIA often tests the misconception that CVSS base scores alone are sufficient for prioritization, when in fact they must be combined with asset criticality, threat context, and compensating controls to reflect true organizational risk.

614
MCQhard

A security analyst is investigating a containerized environment. A scan using Trivy has identified a critical vulnerability in a container image. The container is running in a Kubernetes cluster with a Pod Security Policy that disallows privileged containers. Which additional concern should the analyst address?

A.The vulnerability is not exploitable due to the Pod Security Policy
B.The vulnerability is automatically mitigated because the container is not privileged
C.The analyst should ignore the vulnerability because the container is not privileged
D.The analyst should immediately patch the image, but also verify that the Pod Security Policy prevents privilege escalation
AnswerD

Because the Pod Security Policy reduces but does not eliminate the vulnerability's potential impact, the correct approach layers remediation with verification: patch the base image to remove the underlying flaw while also confirming the policy's privilege-escalation controls are properly enforced, ensuring both the root cause and the compensating control are addressed rather than relying on either alone.

Why this answer

A critical vulnerability in a container image remains a real risk even if the container is not privileged, because the vulnerability could still be exploited for data exfiltration, denial of service, or lateral movement within the cluster. The analyst should patch the image and also verify that the Pod Security Policy actually prevents privilege escalation, since misconfigurations or policy gaps could allow an attacker to escalate privileges after exploiting the vulnerability.

Exam trap

CS0-004 often tests the misconception that a Pod Security Policy or non-privileged container automatically neutralizes all vulnerabilities, when in fact it only blocks one specific escalation vector.

How to eliminate wrong answers

Option A is wrong because a Pod Security Policy disallowing privileged containers does not make a vulnerability non-exploitable; it only limits one escalation path. Option B is wrong because automatic mitigation is not guaranteed — the vulnerability may still be exploited through other vectors such as application-level flaws or container escape techniques that do not require privileged mode. Option C is wrong because ignoring a critical vulnerability is never acceptable; the policy reduces risk but does not eliminate it.

615
Multi-Selecthard

A vulnerability management analyst is prioritizing vulnerabilities for remediation. The analyst has the following information for three vulnerabilities: CVE-2023-1: CVSS 9.8, EPSS 0.9, asset criticality high; CVE-2023-2: CVSS 7.5, EPSS 0.01, asset criticality low; CVE-2023-3: CVSS 5.0, EPSS 0.8, asset criticality medium. According to best practices, which THREE factors should the analyst consider when prioritizing? (Select THREE)

Select 3 answers
A.CVSS score
B.CVE publication date
C.Asset criticality
D.EPSS score
E.Number of vendors affected
AnswersA, C, D

CVSS is a standardized severity score that synthesizes exploitability characteristics (attack vector, attack complexity, privileges required, user interaction) and impact metrics (confidentiality, integrity, availability) into a 0–10 score. In v3.x, this score provides the critical first filter for triage, allowing an analyst to quickly separate low-severity flaws from those that demand immediate attention. However, it is only a measure of intrinsic severity, not a guarantee of real-world exploitation, so it must be combined with threat likelihood and business impact. As a severity benchmark, it remains the primary initial factor in any prioritization workflow.

Why this answer

Option A (CVSS score) is correct because CVSS provides the standardized severity rating of a vulnerability's technical impact, and in this scenario the analyst is explicitly comparing scores such as 9.8, 7.5, and 5.0 to gauge relative severity. Option C (Asset criticality) is correct because the business value and exposure of the affected asset determine the real-world risk; a high-criticality asset raises the urgency of remediation regardless of raw severity. Option D (EPSS score) is correct because EPSS estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, so values like 0.9 versus 0.01 strongly influence prioritization beyond CVSS alone.

Option B (CVE publication date) is not a standard prioritization factor, since age alone does not indicate exploitability or business impact. Option E (Number of vendors affected) is not a recognized risk-scoring input for prioritizing a specific vulnerability in a given environment.

Exam trap

CS0-004 often tests whether candidates default to CVSS alone — the trap is ignoring EPSS and asset criticality, which are essential for risk-based prioritization.

616
MCQmedium

A legacy system cannot be patched because the vendor no longer supports the application. What should the vulnerability manager request? For control selection, Which control best addresses the stated weakness without hiding risk?

A.Mark the vulnerability as fixed
B.Documented risk acceptance with compensating controls and a migration/remediation plan
C.Remove the system from future reports
D.Give all users local admin rights
AnswerB

Because the vendor no longer supports the application, patching is impossible, so the residual risk must be formally owned. Documented risk acceptance records that decision, compensating controls reduce likelihood or impact, and the migration plan provides a route off the unsupported system.

Why this answer

When a legacy system cannot be patched due to vendor end-of-life, the vulnerability manager must formally document the risk acceptance, implement compensating controls (e.g., network segmentation, host-based firewall rules, or application whitelisting), and create a migration or remediation plan to eventually retire or replace the system. This approach transparently acknowledges the residual risk rather than hiding it, aligning with the principle of risk treatment as defined in NIST SP 800-53 and ISO 27005.

Exam trap

The CS0-004 exam often tests the misconception that removing a system from reports or marking it as fixed is an acceptable shortcut, when in fact the correct process requires formal risk acceptance with compensating controls and a documented plan.

How to eliminate wrong answers

Option A is wrong because marking a vulnerability as 'fixed' when no patch has been applied is a false status that misrepresents the actual risk posture and violates vulnerability management policy. Option C is wrong because removing the system from future reports hides the risk from stakeholders and bypasses the necessary risk acceptance process, which is a security governance failure. Option D is wrong because granting all users local admin rights would increase the attack surface and privilege escalation risk, directly contradicting the principle of least privilege and making the system even more vulnerable.

617
Multi-Selecthard

A SOC team is tuning a SIEM to reduce false positives. Which THREE of the following metrics should the team consider when evaluating detection effectiveness? (Choose THREE)

Select 3 answers
A.False Positive Rate
B.Number of detected events
C.Precision
D.Mean Time to Detect (MTTD)
E.True Positive Rate (Recall)
AnswersA, C, E

This metric directly quantifies the ratio of benign events that are incorrectly flagged as malicious alerts out of all truly benign events. When tuning a SIEM to minimize noise, tracking the False Positive Rate allows analysts to verify that rule modifications are successfully reducing erroneous alerts without compromising detection capabilities.

Why this answer

A is correct because False Positive Rate (FPR) measures the proportion of benign events incorrectly flagged as malicious, directly indicating how much noise the SIEM generates. Reducing FPR is a primary goal when tuning detection rules to minimize analyst fatigue and improve alert fidelity.

Exam trap

CompTIA often tests the distinction between metrics that measure detection accuracy (FPR, Precision, Recall) versus metrics that measure operational efficiency (MTTD, event volume), leading candidates to mistakenly include MTTD or raw event counts as effectiveness metrics.

618
Multi-Selectmedium

Which pipeline controls help prevent vulnerable dependencies reaching production? (Choose two.)

Select 2 answers
A.SBOM generation and review for released builds
B.Manual badge checks at the office door
C.Software composition analysis with policy gates
D.DNS MX record rotation
AnswersA, C

Generating a Software Bill of Materials (SBOM) provides a comprehensive, machine-readable inventory of all third-party components, libraries, and dependencies within a software build. Reviewing these manifests allows security teams to track downstream risks, identify newly disclosed vulnerabilities in existing deployments, and ensure compliance with licensing and security standards.

Why this answer

A is correct because SBOM (Software Bill of Materials) generation and review provides a detailed inventory of all components in a build, enabling teams to identify and block vulnerable dependencies before release. This aligns with supply chain security best practices, as SBOMs allow automated comparison against vulnerability databases (e.g., NVD) to enforce policy gates early in the pipeline.

Exam trap

The CS0-004 exam often tests the distinction between pipeline-level controls (automated, code-focused) and physical or administrative controls, so candidates may mistakenly select a non-technical option like badge checks because they confuse 'pipeline' with general security procedures.

619
Multi-Selecthard

A security analyst is reviewing an alert from Azure Sentinel that indicates a possible privilege escalation attempt. The alert is based on a correlation rule that detects unusual usage of the 'Add-AzKeyVaultKey' cmdlet by a user who has never used it before. The analyst needs to validate the alert and determine if the activity is malicious. Which THREE actions should the analyst take?

Select 3 answers
A.Check the user's role assignments and permissions
B.Run a vulnerability scan on the user's workstation
C.Review the Key Vault's diagnostic logs for any key retrieval after the cmdlet
D.Disable the user account immediately
E.Verify the user's identity by checking Azure AD sign-in logs
AnswersA, C, E

Checking the user's RBAC role assignments against Key Vault establishes whether Add-AzKeyVaultKey was actually within that person's authorized scope of duties, since a first-time use of a cmdlet by someone who legitimately holds a Key Vault Contributor or Crypto Officer role is far less suspicious than the same call from an account with no assigned Key Vault permissions.

Why this answer

Checking Azure AD logs for the authentication context, reviewing the user's recent activity history, and examining the Key Vault audit logs for any subsequent access are all relevant steps.

620
MCQmedium

A threat hunter is creating a hypothesis based on the MITRE ATT&CK framework. The hunter wants to detect adversaries using PowerShell to download files from remote servers. Which ATT&CK technique should the hunter focus on?

A.T1078 (Valid Accounts)
B.T1053.005 (Scheduled Task)
C.T1047 (WMI)
D.T1059.001 (PowerShell)
AnswerD

PowerShell (T1059.001) is a sub-technique under Command and Scripting Interpreter that allows adversaries to execute commands, run scripts, and interact directly with the operating system. Threat hunters look for PowerShell commands utilizing cmdlets like 'Invoke-WebRequest' or 'Start-BitsTransfer' because they are commonly abused to download and execute malicious payloads directly into memory.

Why this answer

T1059.001 is PowerShell, which is commonly used for file downloads. The hunter should create detection rules for PowerShell download cradles.

621
MCQmedium

An organization uses MISP (Malware Information Sharing Platform) to share threat intelligence with trusted partners. Which of the following standards is commonly used by MISP to structure and exchange threat intelligence data?

A.NetFlow
B.SNMP
C.STIX/TAXII
D.Syslog
AnswerC

STIX provides a structured language for describing threat indicators, while TAXII defines the transport protocol for exchanging that data between platforms. MISP natively supports both, satisfying the requirement to structure and exchange threat intelligence with trusted partners. OpenIOC and PDF are unrelated formats, and Microsoft Entra ID governs identity, not intelligence sharing.

Why this answer

STIX (Structured Threat Information Expression) and TAXII (Trusted Automated Exchange of Indicator Information) are standards for exchanging cyber threat intelligence. MISP supports STIX and TAXII for sharing.

622
MCQeasy

After a high-priority SOC escalation, file shares show rapid encryption and ransom-note creation from one workstation. What is the best immediate containment action?

A.Run vulnerability scans on every subnet first
B.Restore backups before isolating the host
C.Email all users the ransom note
D.Isolate the workstation and disable its active sessions to file servers
AnswerD

Containment should stop encryption spread while preserving evidence for analysis. In containment, responders need action that reduces risk while preserving the investigation record.

Why this answer

Isolating the workstation and disabling its active sessions to file servers is the best immediate containment action. This stops the encryption and lateral spread, follows NIST SP 800-61 and standard incident response procedures, and prioritizes containment before investigation or remediation.

Exam trap

The CS0-004 exam often tests the misconception that you should run scans, restore backups, or notify users first, but the trap is that immediate containment (isolation) is always the priority to stop the spread, not investigation or recovery.

How to eliminate wrong answers

Option A is wrong because running vulnerability scans on every subnet first wastes critical time during an active ransomware outbreak; scanning does not stop ongoing encryption and is a post-containment step. Option B is wrong because restoring backups before isolating the host would allow the ransomware to continue encrypting newly restored files, and backups should only be used after containment to ensure a clean restore point. Option C is wrong because emailing all users the ransom note is not a containment action; it may cause panic, spread misinformation, and does not stop the encryption process.

623
MCQhard

A threat hunter is creating a Sigma rule to detect a specific TTP where an attacker uses reg.exe to create a Run key for persistence. Which of the following Sigma rule event selectors would best detect this activity?

A.EventID: 4688 (Process Creation) AND ParentImage: '*reg.exe*'
B.EventID: 13 (Registry Value Set) AND TargetObject: '*\CurrentVersion\Run*'
C.EventID: 4657 (Registry modification) AND ObjectName: '*\RunOnce*'
D.EventID: 1 (Process Creation) AND CommandLine: '*reg.exe*'
AnswerB

Sysmon Event ID 13 specifically monitors registry value modifications, making it highly effective for tracking persistence mechanisms. By targeting the \\CurrentVersion\\Run key path within the TargetObject field, this rule directly alerts on attempts to establish autostart execution points, regardless of the process initiating the change.

Why this answer

Registry persistence via Run keys is commonly achieved by modifying HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Sigma rules targeting registry add/modify events with that path will detect it.

624
MCQhard

A company's incident response team is handling a ransomware incident that has encrypted all files on the file server and spread to several workstations. The team has isolated the affected systems and obtained memory dumps and disk images. The CEO demands immediate restoration of operations and suggests paying the ransom to decrypt files quickly. The company has recent backups but they are stored on a network share that was also encrypted. The CISO wants to ensure that the root cause is identified before restoration. As the lead incident responder, which of the following actions should you take NEXT?

A.Pay the ransom and then restore from the decrypted files
B.Restore the backups to a clean environment and then reimage the affected systems
C.Immediately reimage all affected systems and restore from the most recent clean backups
D.Analyze the memory dumps to identify the infection vector and check for persistence mechanisms
AnswerD

Memory dumps preserve volatile evidence such as running processes, injected code and persistence mechanisms that identify the infection vector. Analysing them before restoration satisfies the CISO's requirement to establish root cause, preventing re-infection once systems are rebuilt from backups.

Why this answer

Analyzing the memory dumps will help identify the initial infection vector (e.g., phishing email, exploited vulnerability) and any persistence mechanisms. This information is critical to prevent reinfection after restoration. Options A, B, and C skip root cause analysis, risking reinfection.

Option A is ill-advised and may not work. Option B involves restoring to a clean environment but still requires root cause analysis to ensure the environment is secure. Option C is premature as it does not identify the root cause.

625
MCQmedium

A security analyst is reviewing a vulnerability scan report from Rapid7 InsightVM. The report shows that a Tomcat server has a plugin finding indicating that the 'Server' header is set to 'Apache-Coyote/1.1', which reveals the server version. Which type of vulnerability does this represent?

A.Broken access control
B.Injection vulnerability
C.Security misconfiguration
D.Cryptographic failure
AnswerC

Exposing detailed server version banners is a classic security misconfiguration that leaks valuable reconnaissance data to potential attackers. By failing to disable verbose headers or default error pages, administrators inadvertently assist adversaries in mapping out specific, exploitable vulnerabilities associated with that software version.

Why this answer

The 'Server' header revealing the server version is a security misconfiguration because it exposes unnecessary information that could aid attackers in targeting known vulnerabilities. This falls under the OWASP Top 10 category of Security Misconfiguration. It is not a direct vulnerability but a configuration weakness that should be remediated by suppressing version details.

Exam trap

CS0-004 often tests the classification of information disclosure as a security misconfiguration, where candidates might incorrectly label it as broken access control or injection.

How to eliminate wrong answers

Option A is wrong because broken access control involves unauthorized access to resources, not information disclosure via headers. Option B is wrong because injection vulnerabilities involve untrusted data being executed as code, not header information leakage. Option D is wrong because cryptographic failures involve weak encryption or key management, not server banner disclosure.

626
MCQeasy

A security analyst needs to verify that a critical patch was successfully applied to all endpoints in the organization after an emergency patch deployment. Which phase of the vulnerability lifecycle is the analyst performing?

A.Remediation
B.Prioritization
C.Discovery
D.Verification
AnswerD

Verification is the final, critical step in the vulnerability management lifecycle where analysts perform follow-up scans or manual checks to ensure the patch was correctly installed and the vulnerability is fully mitigated. This step prevents false positives and confirms that the remediation efforts were effective in reducing the organization's attack surface.

Why this answer

Verification ensures that remediation (patch application) was effective. It occurs after the fix is applied.

627
MCQmedium

An analyst receives an alert that a user's workstation contacted a known command-and-control (C2) IP address. The analyst checks the EDR logs and finds that the process 'svchost.exe' initiated the connection. What should the analyst do next to determine if this is a true positive?

A.Check the parent process of svchost.exe
B.Verify the IP address with threat intelligence feeds
C.Search for other workstations contacting the same IP
D.Isolate the workstation from the network immediately
AnswerA

In a legitimate Windows environment, svchost.exe (Service Host) is always spawned by the Services Control Manager (services.exe). If the parent process is anything else, such as a web browser, user-space application, or command shell, it strongly indicates process hollowing, DLL injection, or malicious Living off the Land (LotL) activity. Verifying this lineage is the most effective way to confirm whether the process has been hijacked to establish the outbound C2 connection.

Why this answer

Checking the parent process of svchost.exe helps identify if it was spawned by a malicious process like a service or scheduled task, indicating compromise.

628
MCQeasy

A security analyst is reviewing a vulnerability scan report and sees a critical finding with a CVSS v3.1 base score of 9.8. The vector string is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector component (AV:N)?

A.The attacker can exploit the vulnerability over a network from a remote system
B.The attacker must be on the same physical network segment
C.The attacker requires local access to the target system
D.The attacker must be physically present at the device
AnswerA

In the Common Vulnerability Scoring System (CVSS), an Attack Vector of Network (AV:N) means the vulnerability is exploitable from any remote system that can reach the target over a network connection. This includes sending specially crafted IP packets, protocol-specific requests, or application-layer payloads without requiring any prior authentication or local access. The attacker does not need to be co-located on the target's local subnet, merely capable of network connectivity.

Why this answer

In CVSS v3.1, the Attack Vector (AV) metric describes how the vulnerability is exploited. AV:N (Network) means the vulnerable component is reachable over a network layer (e.g., the internet or a LAN) and the attacker does not need local or physical access. This is the most severe AV value and contributes to the high base score of 9.8 in the given vector.

Exam trap

CS0-004 often tests the confusion between AV:N and AV:A, so candidates who read 'network' as 'same LAN segment' pick the adjacent value instead of the true network value.

How to eliminate wrong answers

Option B is wrong because 'same physical network segment' describes AV:A (Adjacent), which requires the attacker to be on the same shared network (e.g., same subnet or Bluetooth range), not AV:N. Option C is wrong because local access is AV:L (Local), where the attacker must execute code on the target or have a local shell. Option D is wrong because physical presence is AV:P (Physical), the least severe AV value, requiring hands-on access to the device.

629
Multi-Selectmedium

A security analyst is investigating a reported vulnerability in a web application. The team uses Burp Suite for DAST scanning. Which TWO of the following findings would be classified as injection vulnerabilities according to OWASP Top 10?

Select 2 answers
A.Use of a component with known vulnerabilities
B.Broken access control allowing privilege escalation
C.Stored XSS in the comment section
D.Security misconfiguration exposing directory listing
E.SQL injection in the login form
AnswersC, E

Stored XSS in the comment section is an injection vulnerability because the attacker injects executable client-side script (e.g., JavaScript) that is persisted on the server and later rendered in other users' browsers. Unlike SQL injection, which targets the database layer with structured query language, XSS targets the interpretation context of HTML/JavaScript in the victim's browser. The comment field fails to sanitize or encode user input, enabling script execution that can steal session cookies, deface pages, or perform actions on behalf of the target user.

Why this answer

Option C (Stored XSS in the comment section) is correct because cross-site scripting is classified under OWASP Top 10 A03:2021 Injection, where untrusted user input is interpreted as code (HTML/JavaScript) by the browser, and the stored variant persists the payload in the application's database. Option E (SQL injection in the login form) is correct because SQLi is the canonical injection flaw, where attacker-supplied input alters the structure of a SQL query executed by the backend database, also falling under A03:2021 Injection. Option A does not belong because using a component with known vulnerabilities maps to A06:2021 Vulnerable and Outdated Components, not injection.

Option B does not belong because broken access control is its own category, A01:2021, involving authorization failures rather than input being interpreted as code or commands. Option D does not belong because security misconfiguration maps to A05:2021 and concerns improper hardening (such as exposed directory listings), not injection.

Exam trap

The trap here is confusing other OWASP Top 10 categories (like broken access control or vulnerable components) with injection, because candidates may not recall that XSS is classified under injection in the 2021 list.

630
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a single failed login attempt from a known internal IP address to a file server. The user authenticated successfully on the next attempt. Which classification best describes this alert?

A.True negative
B.True positive
C.False negative
D.False positive
AnswerD

This is a false positive because the alert fired on a single failed login from a known, trusted internal IP that was immediately followed by successful authentication, a pattern far more consistent with a routine typo than malicious activity; the detection rule's threshold for triggering on just one failed attempt is overly sensitive and should likely be tuned to require multiple failures before alerting.

Why this answer

The alert is a false positive because a single failed login followed by success is normal user behavior and not indicative of malicious activity.

631
MCQeasy

A security analyst is reviewing a SIEM alert that triggered on a known malicious IP address communicating with an internal server. The analyst checks the threat intelligence feed and confirms the IP is associated with a command-and-control server. What type of alert is this?

A.False negative
B.True positive
C.False positive
D.True negative
AnswerB

A true positive represents a successful detection where the SIEM security analytics engine correctly flags actual malicious behavior or policy violations. When an analyst validates that the triggered alert corresponds to genuine adversary activity, such as an active brute-force attack or unauthorized data exfiltration, it confirms a true positive state. This validation initiates the incident response lifecycle.

Why this answer

A true positive means the alert correctly identified a real malicious event. Here the SIEM flagged communication with a known C2 IP, threat intel confirmed the IP is malicious, and the internal server is genuinely talking to it — so the detection is accurate and the incident is real. This is the textbook definition of a true positive in alert triage.

Exam trap

The trap is overthinking the classification — candidates sometimes pick 'false positive' because they assume any alert needs further validation, but confirmed malicious activity with a fired alert is unambiguously a true positive.

How to eliminate wrong answers

Option A is wrong because a false negative is a missed detection — malicious activity that occurred but produced no alert, which is the opposite of what happened here. Option C is wrong because a false positive is an alert on benign activity that was incorrectly flagged; here the activity is confirmed malicious, so it's not benign. Option D is wrong because a true negative is the correct absence of an alert on benign activity — no alert fired and nothing malicious occurred, which doesn't match a triggered alert on confirmed C2 traffic.

632
MCQmedium

A SOC analyst is triaging a SIEM alert for a registry modification on a workstation. The alert indicates a new Run key was added under HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Which of the following is the most likely purpose of this modification?

A.To change the desktop wallpaper
B.To establish persistence
C.To disable Windows Defender
D.To update the system time
AnswerB

Threat actors frequently target registry Run and RunOnce keys located within HKLM or HKCU to ensure their malicious payloads execute automatically upon system boot or user logon. This mechanism allows the malware to survive system reboots and maintain a continuous presence within the compromised environment. Consequently, detecting unauthorized modifications to these specific registry paths is a high-fidelity indicator of a persistence establishment attempt.

Why this answer

Run keys are a common persistence mechanism used by malware to ensure execution at user logon.

633
MCQhard

During a vulnerability scan, the scanner reports a high number of open ports on a server that is supposed to be a hardened web server. The analyst investigates and finds that the server is running unnecessary services. Which of the following is the MOST effective long-term solution?

A.Implement a configuration management baseline and enforce it
B.Disable the unnecessary services manually
C.Increase the frequency of vulnerability scans
D.Install a host-based firewall to block the ports
AnswerA

Implementing and enforcing a configuration management baseline directly addresses the root cause of a high number of open ports. Configuration management tools define the desired secure state for systems, specifying exactly which services should run and which ports should be open. By continuously monitoring and automatically remediating any deviations from this established baseline, it ensures consistent hardening, prevents configuration drift, and proactively closes unnecessary ports across the entire environment, significantly improving the security posture.

Why this answer

Implementing a configuration management baseline and enforcing it (Option A) is the most effective long-term solution because it ensures that the server is consistently provisioned with only the necessary services and configurations. This approach uses tools like Ansible, Puppet, or Chef to automatically remediate drift, preventing unnecessary services from reappearing after manual changes or reboots. It addresses the root cause by codifying the desired state, rather than relying on ad-hoc fixes.

Exam trap

CompTIA often tests the distinction between detection (scanning) and remediation (configuration management), and the trap here is that candidates choose a reactive control like a firewall or manual disabling instead of the proactive, automated enforcement that prevents the issue from recurring.

How to eliminate wrong answers

Option B is wrong because manually disabling unnecessary services is a temporary, non-scalable fix that does not prevent the services from being re-enabled during updates or reboots, and it lacks auditability and enforcement. Option C is wrong because increasing the frequency of vulnerability scans only detects the problem more often; it does not remediate the root cause of unnecessary services running. Option D is wrong because installing a host-based firewall to block ports only masks the vulnerability by hiding the open ports from scans, but the unnecessary services remain running and could still be exploited via local access or other attack vectors.

634
Multi-Selecthard

A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)

Select 2 answers
A.Board of directors
B.SOC analysts
C.Executive leadership
D.Incident responders
E.Network engineers
AnswersB, D

SOC analysts are the primary consumers for a report consisting of technical IoCs, as they operationalize these indicators into detection logic such as SIEM signatures and alert rules. The report should be structured to support correlation with telemetry, enabling prioritization and investigation of matching events. For the SOC, IoCs serve as the foundational input for proactive threat detection and ongoing security monitoring.

Why this answer

SOC analysts (B) are a primary consumer of tactical IoCs because they monitor SIEM alerts, tune detection rules, and hunt for the listed IP addresses, domains, and file hashes in day-to-day security operations. Incident responders (D) also need these atomic indicators to scope and contain active compromises, for example by searching endpoints for the specified file hashes or blocking the malicious domains and IPs at the perimeter. Both roles operate at the tactical level where concrete, machine-readable indicators drive immediate detection and response actions.

By contrast, the board of directors (A) and executive leadership (C) consume strategic intelligence such as risk trends, business impact, and threat landscape summaries, not raw IoCs. Network engineers (E) focus on routing, switching, and infrastructure availability, so while they may implement blocks, they are not a primary audience for interpreting threat intelligence reports.

Exam trap

CS0-004 often tests the confusion between tactical and strategic intelligence audiences, tempting candidates to select 'executive leadership' or 'board' because those roles sound authoritative, when in fact they consume strategic, not atomic, intelligence.

635
MCQhard

A security analyst is reviewing the results of a container image scan using Trivy. The scan reports a critical vulnerability in a base image layer. The development team states that the vulnerability is not exploitable because the affected library is not used in the application. According to vulnerability management best practices, what should the analyst do?

A.Accept the risk and close the finding.
B.Request that the development team remove the unused library and rebuild the image.
C.Ignore the finding since it is not exploitable.
D.Apply a compensating control at the network level to block exploitation.
AnswerB

The most effective remediation strategy for container security is to minimize the attack surface by practicing container hygiene. Requesting that the development team remove the unnecessary library and rebuild the base image permanently eliminates the vulnerability at the source, preventing it from being deployed into production environments.

Why this answer

Even if the library is not used, it is best practice to rebuild the image with a patched base image to eliminate the vulnerability and ensure compliance.

636
MCQhard

During a vulnerability assessment of a Kubernetes cluster, a security analyst finds that a container is running with privileged mode enabled and has a hostPath mount that grants write access to the host's /var/log directory. Which of the following is the most significant security risk associated with this configuration?

A.Data leakage through unrestricted storage access
B.Excessive network permissions allowing lateral movement
C.Potential for container escape and host node compromise
D.Increased attack surface due to unnecessary services running in the container
AnswerC

Running a container in privileged mode eliminates the isolation boundaries enforced by namespaces and cgroups, granting the container near-root access to the host. When combined with a hostPath mount, an attacker can easily access the host's filesystem, manipulate system binaries, interact with the host's container runtime socket, and achieve full container escape to compromise the underlying node.

Why this answer

A container running in privileged mode with a hostPath mount that grants write access to the host's /var/log directory poses a significant risk of container escape and host node compromise. Privileged mode gives the container almost all capabilities of the host, and the hostPath mount allows direct write access to host files, enabling an attacker to modify system logs, plant malware, or escalate privileges to the host.

Exam trap

CS0-004 often tests container security risks. Candidates might focus on data leakage or network permissions, but the combination of privileged mode and hostPath write access is a classic container escape vector leading to host compromise.

How to eliminate wrong answers

Option A is wrong because while data leakage is a concern, the write access to /var/log is more about integrity and potential code execution than just leakage. Option B is wrong because excessive network permissions are not indicated by privileged mode and hostPath mount; the risk is host compromise, not lateral movement. Option D is wrong because increased attack surface due to unnecessary services is a general risk, but the specific configuration of privileged mode and hostPath write access is far more severe, directly enabling host takeover.

637
MCQmedium

During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?

A.Root cause analysis
B.Impact assessment
C.Lessons learned
D.Timeline
AnswerD

A timeline is a critical incident response artifact that chronologically documents the exact sequence of events, including initial vector detection, lateral movement, containment actions, and system restoration. Maintaining an accurate timeline is essential for correlating disparate log sources, establishing a clear chain of custody, and providing a structured narrative for forensic analysis, legal compliance, and stakeholder reporting.

Why this answer

The correct answer is D because the timeline component of an incident report details the chronological sequence of events from initial compromise to containment, including the phishing email, credential theft, and lateral movement. This provides a clear narrative for understanding the incident's progression. The timeline is specifically designed to capture the sequence of events.

Exam trap

CS0-004 often tests the confusion between timeline and root cause analysis; candidates may think root cause analysis includes the sequence of events, but the timeline is the component that details the chronological progression.

How to eliminate wrong answers

Option A is wrong because root cause analysis identifies the underlying cause of the incident, not the sequence of events; it answers 'why' rather than 'when' and 'what happened next.' Option B is wrong because impact assessment quantifies the damage or business impact, such as data loss or downtime, not the chronological sequence. Option C is wrong because lessons learned focuses on improvements and recommendations for future prevention, not the detailed sequence of events.

638
Drag & Dropmedium

Arrange the steps for configuring a firewall rule set in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Firewall rule configuration involves identifying traffic, creating rules, applying to interface, testing, and monitoring.

639
MCQeasy

A security analyst needs to share threat intelligence with other organizations in a standardized format. Which of the following standards should the analyst use?

A.REST
B.STIX/TAXII
C.SOAP
D.SNMP
AnswerB

Structured Threat Information Expression (STIX) is a standardized serialization format used to model and represent structured cyber threat intelligence. Trusted Automated Exchange of Intelligence Information (TAXII) is the application-layer protocol specifically designed to securely route and exchange these STIX-formatted threat feeds over HTTPS, making them the industry standard for automated threat sharing.

Why this answer

STIX (Structured Threat Information Expression) is a standardized language for describing cyber threat intelligence, and TAXII (Trusted Automated Exchange of Intelligence Information) is the protocol for exchanging that intelligence over HTTPS. Together, they provide a standardized format and transport mechanism for sharing threat intel between organizations, as required by the question.

Exam trap

CS0-004 often tests the confusion between general web protocols (REST, SOAP) and specialized threat intelligence standards, tricking candidates into choosing REST because it's commonly used for APIs.

How to eliminate wrong answers

Option A is wrong because REST is a general architectural style for web services, not a specific threat intelligence standard. Option C is wrong because SOAP is a messaging protocol for web services, not a threat intelligence sharing standard. Option D is wrong because SNMP is used for network management, not threat intelligence exchange.

640
MCQhard

During a forensic investigation, an analyst needs to acquire memory from a Linux server. Which tool is specifically designed for this purpose?

A.dd
B.LiME
C.FTK Imager
D.WinPmem
AnswerB

LiME (Linux Memory Extractor) is a kernel-space tool designed specifically for acquiring volatile memory from Linux-based systems. It operates as a Loadable Kernel Module (LKM), allowing it to bypass user-space limitations and capture a full, uncorrupted dump of physical RAM, including volatile artifacts, while minimizing its footprint on the host system.

Why this answer

LiME (Linux Memory Extractor) is a loadable kernel module specifically designed to acquire volatile memory from Linux systems in a forensically sound manner. It captures RAM contents and outputs them in formats like raw or lime, which can then be analyzed with tools such as Volatility. This makes it the correct answer for Linux memory acquisition.

Exam trap

CS0-004 often tests the confusion between general-purpose tools (dd) and purpose-built forensic memory acquisition tools (LiME for Linux, WinPmem for Windows), catching candidates who pick dd for Linux memory capture.

How to eliminate wrong answers

Option A is wrong because dd is a general-purpose disk/device copy utility; while it can read /dev/mem, that approach is unreliable on modern kernels with restricted /dev/mem access and does not produce a forensically validated memory image. Option C is wrong because FTK Imager is primarily a Windows disk/memory imaging tool (with limited Linux support) and is not the standard Linux memory acquisition tool. Option D is wrong because WinPmem is a Windows memory acquisition tool, not a Linux one.

641
MCQhard

During a post-incident activity, the CSIRT performs a root cause analysis for a data breach. They discover that the breach originated from a misconfigured S3 bucket that allowed public read access. Which of the following actions should be included in the lessons learned to prevent recurrence?

A.Rotate all access keys for the affected account
B.Disable public access to all S3 buckets permanently
C.Conduct a penetration test on the cloud environment
D.Implement automated compliance checks for cloud storage configurations
AnswerD

Implementing automated compliance checks, such as Cloud Security Posture Management (CSPM) tools, directly addresses the root cause by continuously auditing resource configurations against security baselines. These tools provide real-time detection and automated remediation of drift, ensuring that unauthorized public access is blocked immediately upon misconfiguration.

Why this answer

Implementing automated compliance checks using tools like AWS Config ensures that storage configurations are continuously monitored and misconfigurations are flagged or corrected.

642
MCQmedium

A security analyst is reviewing a vulnerability scan report and finds a critical vulnerability with a CVSS v3.1 base score of 9.8. The vector string is: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack vector and impact of this vulnerability?

A.Adjacent attack vector, high impact on availability only
B.Network attack vector, high impact on confidentiality, integrity, and availability
C.Physical attack vector, medium impact on confidentiality
D.Local attack vector, low impact on confidentiality
AnswerB

This option accurately reflects a CVSS v3 vector string where the Attack Vector is Network, meaning the vulnerability can be exploited remotely over the internet. It also correctly identifies that the exploit results in a High impact rating for confidentiality, integrity, and availability, indicating total compromise of the affected system.

Why this answer

AV:N indicates network-based attack vector, meaning the vulnerability can be exploited remotely over the network. The CIA impact ratings are all High, indicating complete compromise of confidentiality, integrity, and availability.

643
MCQhard

A threat hunter wants a portable detection for suspicious rundll32 execution that can be converted for multiple SIEM platforms. Which artefact format best fits this goal?

A.CVSS vector string
B.Sigma rule
C.YARA rule
D.OpenIOC package only
AnswerB

Sigma is designed as a generic detection-rule format that can be translated into SIEM-specific queries.

Why this answer

Sigma rules are the correct choice because they are designed as a generic, open-source signature format for log events, making them portable across multiple SIEM platforms (e.g., Splunk, Elastic, QRadar) without vendor lock-in. For suspicious rundll32 execution, a Sigma rule can describe the specific event log patterns (e.g., Event ID 4688 with CommandLine containing 'rundll32.exe') that can be converted into each SIEM's native query language. This portability directly meets the threat hunter's goal of creating a detection that can be reused across different environments.

Exam trap

The CS0-004 exam often tests the distinction between detection artefacts (Sigma, YARA) and vulnerability scoring (CVSS), and the trap here is that candidates may confuse YARA's file-scanning capability with log-based SIEM detection, forgetting that YARA rules cannot be directly converted to SIEM queries without significant rework.

How to eliminate wrong answers

Option A is wrong because a CVSS vector string is a standardized score for vulnerability severity (e.g., CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), not a detection artefact for identifying suspicious process execution like rundll32; it describes risk, not a pattern to match in logs. Option C is wrong because YARA rules are primarily designed for file-based pattern matching (e.g., identifying malware binaries by byte sequences or strings), not for parsing Windows Event Logs or SIEM log streams; while YARA can be used for memory analysis, it is not natively portable to SIEM platforms for log-based detection.

644
MCQeasy

Which of the following is the best data source for detecting DNS tunneling activity?

A.Firewall logs
B.DNS logs
C.EDR telemetry
D.NetFlow data
AnswerB

DNS logs capture the complete transaction details, including the requested domain names, query types (such as TXT, MX, or CNAME), and the corresponding server responses. This granular payload visibility is essential for identifying the high-frequency, anomalously long, or encoded subdomains characteristic of DNS tunneling and data exfiltration techniques.

Why this answer

DNS logs contain the queries and responses; analyzing them for unusual domain patterns, large query volumes, or odd record types can reveal tunneling.

645
MCQmedium

A security analyst is tuning a SIEM correlation rule that generates alerts when a single user logs into more than 10 workstations within 5 minutes. The rule is producing excessive false positives due to service accounts performing automated tasks. Which of the following is the best tuning approach to reduce false positives while still detecting potential lateral movement?

A.Change the time window to 10 minutes
B.Increase the threshold to 20 workstations
C.Add an exception for known service account names
D.Disable the rule and rely on manual log review
AnswerC

Creating a whitelist or exception within the SIEM correlation rule for validated, non-interactive service accounts is the most effective tuning strategy. This approach eliminates high-volume false positives generated by legitimate automated processes while maintaining strict, low-threshold monitoring for standard user accounts. It ensures that any anomalous lateral movement by human adversaries remains highly visible to the security operations center.

Why this answer

Excluding known service accounts from the rule reduces false positives while still detecting lateral movement by user accounts.

646
MCQhard

An analyst is reviewing a memory dump of a compromised system and notices that the memory of a legitimate process (e.g., notepad.exe) contains a PE header and executable code that is not part of the original binary. Which technique is most likely being used?

A.A reflective DLL loader
B.Process hollowing
C.DLL injection
D.API hooking
AnswerB

Process hollowing launches a legitimate process in a suspended state, unmaps its original executable image from memory, and writes malicious code and a new PE header into that same memory space before resuming execution, which is exactly why memory forensics reveals a legitimate process name like notepad.exe containing a PE header and code that does not match its original binary on disk.

Why this answer

Process hollowing involves replacing the legitimate code of a running process with malicious code, but the PE header and executable code in memory indicate code injection, specifically hollowing.

647
MCQmedium

An analyst is performing static analysis on a suspicious executable file. Which of the following would be MOST useful to identify potential malicious behavior without executing the file?

A.Running the file in a sandbox.
B.Monitoring network connections during execution.
C.Analyzing the import table.
D.Checking the file's digital signature.
AnswerC

The import table lists external functions and libraries the executable calls, revealing capabilities such as network access, file manipulation, or process injection without running the code. This static inspection satisfies the no-execution constraint while exposing likely malicious behaviour.

Why this answer

Static analysis involves examining the file without executing it. The import table shows which Windows API functions the executable uses, which can indicate capabilities such as network communication, file operations, or registry modifications.

648
MCQmedium

A company has implemented a vulnerability management program. The security team needs to ensure that all critical vulnerabilities are remediated within 30 days. Which of the following metrics would BEST measure the effectiveness of this goal?

A.Number of critical vulnerabilities detected per month
B.Number of rescan results showing vulnerability closure
C.Percentage of systems with up-to-date patches
D.Mean time to remediate critical vulnerabilities
AnswerD

Mean time to remediate (MTTR) critical vulnerabilities directly quantifies the average duration from the initial detection of a critical vulnerability to its verified resolution. This metric is precisely designed to assess the efficiency and effectiveness of the remediation process against a specific service level agreement or internal goal, such as a 30-day target. By tracking this average time, the company can accurately determine if its remediation efforts consistently meet or exceed the desired timeframe for its most severe security findings.

Why this answer

The goal is to ensure all critical vulnerabilities are remediated within 30 days. Mean time to remediate (MTTR) directly measures the average time taken to fix critical vulnerabilities, making it the best metric to assess compliance with the 30-day remediation window. Other metrics, such as detection counts or patch levels, do not capture the timeliness of remediation.

Exam trap

The CS0-004 exam often tests the distinction between measuring remediation activity (e.g., number of closures) versus measuring remediation timeliness (e.g., MTTR), leading candidates to pick Option B because they confuse 'closure count' with 'time to closure.'

How to eliminate wrong answers

Option A is wrong because the number of critical vulnerabilities detected per month measures the volume of new findings, not how quickly or effectively they are fixed; a high detection count could coexist with slow remediation. Option B is wrong because the number of rescan results showing vulnerability closure indicates that some fixes have been applied, but it does not measure the time taken to achieve closure, so it cannot verify the 30-day deadline. Option C is wrong because the percentage of systems with up-to-date patches is a broad compliance metric that may include non-critical patches and does not specifically track the remediation timeline for critical vulnerabilities.

649
MCQmedium

An analyst runs the above command on a server. Based on the exhibit, which of the following is the MOST likely scenario?

A.The server may be compromised with a remote access trojan listening on port 4444
B.The server is running a legitimate SSH service on port 4444
C.The server is hosting a web service on a non-standard port
D.The server is being used as a proxy for internal clients
AnswerA

Port 4444 is the default listening port for the Metasploit Framework's popular payload, Meterpreter, and is frequently associated with Remote Access Trojans (RATs) and reverse shells. Finding an active listener on this port without a documented business justification strongly suggests a malicious compromise where an attacker has established a persistent backdoor.

Why this answer

The command output shows a listening service on port 4444, which is not a standard port for any common service. Port 4444 is commonly associated with remote access trojans (RATs) such as Metasploit's Meterpreter or other malware, making a compromise the most likely scenario. The analyst should investigate further to confirm malicious activity.

Exam trap

CompTIA often tests the association of non-standard ports with common malware or trojans, and the trap here is that candidates may assume any open port is legitimate or overlook the significance of port 4444's known malicious use.

How to eliminate wrong answers

Option B is wrong because SSH runs on port 22 by default (per IANA assignment), and while it could be configured on a non-standard port, there is no evidence of SSH protocol behavior or authentication in the output. Option C is wrong because web services typically use ports 80 (HTTP) or 443 (HTTPS), and port 4444 is not a registered alternative for HTTP/HTTPS. Option D is wrong because proxy services for internal clients commonly use ports like 3128 (Squid) or 8080, and port 4444 is not a standard proxy port.

650
Multi-Selecthard

A SOC wants to measure whether alert enrichment is improving operations. Which metrics are useful? (Choose two.)

Select 2 answers
A.Reduction in analyst triage time for enriched alerts
B.Percentage of enriched alerts with asset owner and criticality populated
C.Amount of storage used by desktop screenshots
D.Number of unused browser bookmarks
AnswersA, B

A primary objective of alert enrichment is to accelerate the incident response lifecycle by automatically appending contextual data, such as threat intelligence or host details, to incoming alerts. Measuring a decrease in the mean time to triage (MTTT) directly quantifies the operational efficiency gained from this automated enrichment process, proving that analysts can make faster, more informed decisions.

Why this answer

A primary goal of alert enrichment is to reduce the time analysts spend investigating alerts. By automatically populating context such as asset owner, criticality, and vulnerability data, enrichment eliminates manual lookup steps, directly lowering mean time to triage (MTTT). This metric quantifies operational efficiency gains from enrichment.

Exam trap

The CS0-004 exam often tests the distinction between metrics that measure operational improvement (e.g., triage time reduction) versus metrics that measure data completeness (e.g., enrichment field population), and candidates may mistakenly choose a storage-related metric that seems tangentially related to operations but is irrelevant to enrichment effectiveness.

651
Multi-Selecthard

A security analyst is conducting a dynamic application security testing (DAST) scan of a REST API. The scanner reports a potential Server-Side Request Forgery (SSRF) vulnerability. The analyst needs to confirm the finding manually. Which TWO of the following techniques are most appropriate for validating SSRF?

Select 2 answers
A.Submit a payload that triggers the server to send a request to an attacker-controlled external server (e.g., Burp Collaborator)
B.Craft a request that causes the server to make a request to an internal IP address (e.g., 127.0.0.1) and observe the response
C.Inject malicious SQL queries into input fields to see if they are executed
D.Attempt to upload a malicious file to the server
E.Modify HTTP headers to test for cross-site scripting
AnswersA, B

An out-of-band (OAST) SSRF test uses an external callback server like Burp Collaborator to detect when the application fetches an attacker-specified URL. If a DNS lookup or HTTP hit is received, it proves the server-side component is making the request as the victim, even when the response body is not reflected to the tester. This technique is essential for blind SSRF, where the application processes the response internally without echoing it back. It also confirms the vulnerability independently of any firewall or filtering on the inbound path.

Why this answer

Option A is correct because SSRF validation classically uses an out-of-band channel: submitting a payload that makes the vulnerable server issue a request to an attacker-controlled host such as Burp Collaborator, and then confirming the inbound DNS/HTTP interaction proves the server-side request was actually made. Option B is correct because SSRF is fundamentally about the server reaching resources the attacker cannot, so crafting input that causes the server to request an internal address like 127.0.0.1 (or 169.254.169.254 for cloud metadata) and observing a response or timing/error difference confirms the server is fetching attacker-influenced URLs. Option C is not appropriate because injecting SQL queries tests for SQL injection, a different vulnerability class, not server-side request forgery.

Option D is not appropriate because uploading a malicious file tests unrestricted file upload, not SSRF. Option E is not appropriate because modifying HTTP headers to test for cross-site scripting targets XSS, which is a client-side injection issue unrelated to SSRF.

Exam trap

CompTIA CS0-004 often tests whether candidates can distinguish SSRF validation (out-of-band callbacks, internal IP probing) from unrelated vulnerability tests like SQLi, file upload, or XSS that appear in the same option list.

652
Multi-Selectmedium

An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)

Select 3 answers
A.The technical vulnerability exploited
B.The number of records affected
C.The name of the employee who clicked the phishing email
D.Human factors, such as lack of training
E.Process failures that allowed the vulnerability to exist
AnswersA, D, E

Documenting the technical vulnerability exploited is central to root cause analysis because it identifies the specific weakness—such as an unpatched CVE, SQL injection, or misconfigured S3 bucket—that allowed the initial compromise. Without this technical detail, the response team cannot prescribe a targeted fix (e.g., patch, configuration change, or WAF rule) to prevent recurrence. The root cause is inseparable from the exact flaw that made the attack viable.

Why this answer

Option A is correct because the root cause analysis must identify the specific technical vulnerability that was exploited, such as an unpatched CVE, misconfigured service, or weak authentication mechanism, since this is the direct technical weakness enabling the breach. Option D is correct because human factors like insufficient security awareness training or failure to follow procedures are legitimate root causes that explain why the initial compromise succeeded. Option E is correct because process failures, such as missing patch management, inadequate access reviews, or absent change control, describe the systemic conditions that allowed the vulnerability to persist and are central to root cause analysis.

Option B is not part of root cause analysis; the number of records affected is an impact or scope metric reported elsewhere in the incident report. Option C is not essential to root cause analysis; naming the specific employee who clicked the phishing email assigns individual blame rather than identifying the underlying human-factor or process cause, and may raise privacy concerns.

Exam trap

CS0-004 often tests the distinction between impact metrics (records affected) and causal factors — candidates pick 'number of records affected' because it feels important, but RCA is about why, not how much.

653
MCQeasy

An organization uses OpenSCAP for compliance scanning. What is the primary purpose of OpenSCAP?

A.Vulnerability scanning
B.Intrusion detection
C.Penetration testing
D.Compliance scanning and configuration assessment
AnswerD

OpenSCAP evaluates systems against security baselines such as SCAP content and STIG profiles, checking configuration settings and reporting compliance deviations. This directly satisfies the scenario's compliance scanning purpose by automating configuration assessment against defined standards.

Why this answer

OpenSCAP is a tool for automated compliance checking against security policies like SCAP content.

654
Multi-Selectmedium

A security analyst suspects an insider threat based on unusual data access patterns by an employee. According to best practices, which TWO actions should the analyst take FIRST?

Select 2 answers
A.Restrict the employee's access to sensitive data.
B.Suspend the employee's accounts outright.
C.Immediately notify law enforcement.
D.Collect additional evidence without alerting the employee.
E.Confront the employee about the behavior.
AnswersA, D

Restricting an employee's access to sensitive data is a critical, immediate containment measure during an insider threat investigation. This action adheres to the principle of least privilege, mitigating potential data exfiltration or damage without prematurely alerting the suspect. It allows the security team to safely conduct further investigation and evidence collection while minimizing ongoing risk to organizational assets.

Why this answer

Restricting the employee's access to sensitive data (A) is a correct first action because it immediately reduces the risk of further data exfiltration or damage while preserving the ability to investigate. Collecting additional evidence without alerting the employee (D) is also correct because it allows the analyst to build a forensic case covertly, preventing the insider from destroying evidence or altering behavior. Both actions align with the incident response principle of containment before eradication and the need to avoid tipping off a potential adversary.

Exam trap

CompTIA often tests the distinction between 'immediate containment' and 'overreaction' — the trap here is that candidates confuse 'suspending accounts' (a disruptive, all-or-nothing action) with 'restricting access' (a precise, reversible control), leading them to choose B instead of A.

655
Multi-Selectmedium

A security analyst is reviewing a suspicious email attachment. Which THREE of the following are safe analysis techniques? (Choose THREE)

Select 3 answers
A.Open the attachment on a production machine
B.Submit the file to a public online scanner
C.Extract and examine the source code of the attachment
D.Use an automated malware analysis tool
E.Open the attachment in a sandbox environment
AnswersB, D, E

Uploading the suspicious file to a public multi-engine scanner like VirusTotal allows the analyst to quickly cross-reference the file's hash against dozens of antivirus databases. This provides rapid, low-risk detection intelligence without executing the payload locally, though analysts must remain cautious about leaking sensitive or proprietary data contained within the file.

Why this answer

Submitting a suspicious file to a public online scanner (e.g., VirusTotal) allows the analyst to check the file against multiple antivirus engines and threat intelligence feeds without executing it on a live system. This technique is safe as it avoids direct exposure of the production environment to potential malware while leveraging community-sourced detection data.

Exam trap

The CS0-004 exam often tests the distinction between 'safe' and 'unsafe' analysis techniques, where candidates mistakenly think examining source code (Option C) is always safe, but it can still trigger execution if the file is opened in an unsecured environment (e.g., enabling macros in Office documents).

656
MCQhard

During a penetration test, an analyst successfully exploits a privilege escalation vulnerability to gain root access on a Linux server. The server is used for application development. Which of the following remediation actions would be MOST effective in preventing similar attacks?

A.Deploy a host intrusion detection system
B.Harden the kernel using sysctl parameters
C.Implement application whitelisting
D.Apply the principle of least privilege to user accounts
AnswerD

Applying the principle of least privilege to user accounts is the most direct and effective countermeasure against privilege escalation. This principle ensures that users and processes are granted only the minimum necessary permissions to perform their legitimate functions, and no more. By limiting the initial access an attacker gains, even if they compromise a user account, their ability to escalate privileges to administrative or system-level access is severely restricted, significantly reducing the potential impact of a successful exploit.

Why this answer

The principle of least privilege ensures that users and processes have only the minimum permissions necessary to perform their tasks. By applying this to user accounts, the attack surface for privilege escalation is reduced because even if an account is compromised, the attacker cannot easily escalate to root. This directly addresses the root cause of the vulnerability exploited in the scenario.

Exam trap

CompTIA often tests the distinction between detection (HIDS), system hardening (sysctl), execution control (whitelisting), and access control (least privilege), expecting candidates to recognize that preventing privilege escalation requires limiting permissions rather than just monitoring or restricting specific binaries.

How to eliminate wrong answers

Option A is wrong because a host intrusion detection system (HIDS) can detect suspicious activity after the fact but does not prevent the privilege escalation vulnerability from being exploited. Option B is wrong because hardening the kernel with sysctl parameters (e.g., disabling core dumps or restricting kernel module loading) does not address the underlying misconfiguration or weak permissions that allowed the escalation. Option C is wrong because application whitelisting controls which executables can run, but it does not prevent an attacker from abusing legitimate tools or scripts to escalate privileges once they have a foothold.

657
Multi-Selecthard

A financial services organization experienced a ransomware incident that encrypted several file servers. The CISO must deliver a post-incident report to the board of directors and the audit committee. The report must communicate both the business impact and the effectiveness of the response. Which of the following should be included in this executive-level report? (Choose two.)

Select 2 answers
A.The complete raw packet capture from the initial compromise vector
B.A timeline of key response actions and the measured effectiveness of containment, eradication, and recovery
C.A quantified estimate of financial loss, including downtime, recovery costs, and regulatory exposure
D.The full malware binary hash list and YARA rule syntax used during triage
E.A detailed list of every file that was encrypted, including full directory paths
AnswersB, C

An executive report should demonstrate how well the organization responded and where improvements are needed. A concise timeline with effectiveness metrics for containment, eradication, and recovery shows whether controls worked and where gaps exist. This helps leadership assess resilience and prioritize investments. It is a standard component of post-incident reporting for senior stakeholders.

Why this answer

Executive-level post-incident reports must translate technical events into business language. Quantifying financial loss and presenting a timeline with response effectiveness give the board the information they need to evaluate risk, resilience, and investment priorities. Technical artifacts like packet captures, hashes, and file lists belong in operational reports, not board communications.

Exam trap

The trap here is assuming that more technical detail always makes a report more credible, when executive audiences actually need summarized business impact and response effectiveness.

658
MCQhard

A forensic analyst is investigating a suspected data breach involving a compromised workstation. The analyst wants to collect volatile data in accordance with the order of volatility. Which sequence of data collection is correct?

A.Disk → RAM → Swap → CPU registers → Network connections → Archived media
B.CPU registers → RAM → Swap → Network connections → Disk → Archived media
C.Network connections → CPU registers → RAM → Swap → Disk → Archived media
D.CPU registers → RAM → Swap → Disk → Network connections → Archived media
AnswerB

Correct: RAM (most volatile) first, then CPU registers, then swap, then network connections, then disk, then archived media. This follows the standard order of volatility.

Why this answer

The correct order of volatility is CPU registers, RAM, swap, network connections, disk, archived media. This sequence captures the most volatile data first: CPU registers are the most volatile, followed by RAM, then swap, then network connections, then disk, and finally archived media.

Exam trap

Many candidates incorrectly place network connections after disk, assuming they are less volatile. However, network connections are more volatile than disk because they represent active communications that can be lost quickly.

659
Drag & Dropmedium

Order the steps for a typical patch management process.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Patch management includes identification, testing, approval, deployment, and verification.

660
MCQmedium

During a network traffic analysis, a security analyst notices a host communicating with an external IP address over TCP port 443 using a self-signed certificate. The traffic flows are consistent in size and occur every 60 seconds. The external IP is not on any threat intelligence feeds. What does this pattern most likely indicate?

A.Lateral movement attempt
B.Data exfiltration via DNS tunneling
C.Command and control beaconing
D.Normal web browsing
AnswerC

Command and control (C2) beaconing is characterized by compromised internal hosts making periodic, highly consistent outbound connections to external malicious infrastructure to check for instructions. These regular intervals, often referred to as heartbeat signals, are designed to maintain persistence and bypass standard firewalls by masquerading as legitimate outbound HTTPS traffic.

Why this answer

Regular, periodic connections of consistent size to an external host over HTTPS suggest beaconing, often used by malware for command and control.

661
MCQmedium

A security analyst is triaging an alert from the EDR that shows the process 'powershell.exe' with a parent process of 'winword.exe'. The user recently opened a document from an email. What is the most likely explanation?

A.The user double-clicked a PowerShell script attached to the email
B.The document contains a malicious macro that spawned PowerShell to execute commands
C.A scheduled task started PowerShell that initiated Word
D.The user is running a legitimate PowerShell script from within a Word document
AnswerB

Malicious VBA macros embedded in Office documents commonly use the Shell function or WScript.Shell object to launch powershell.exe directly as a child process of winword.exe, often passing obfuscated, base64-encoded, or download-cradle commands as arguments to retrieve a second-stage payload, which produces exactly the winword.exe-to-powershell.exe parent-child relationship seen in this alert and matches the well-documented email-delivered macro attack pattern.

Why this answer

When winword.exe (Microsoft Word) is the parent of powershell.exe, it almost always indicates a malicious macro in the document spawned a shell to execute commands. This parent-child relationship is a classic indicator of macro-based malware delivery, especially when the document arrived via email and the user opened it. Legitimate Word documents rarely spawn PowerShell directly.

Exam trap

CS0-004 often tests parent-child process lineage — candidates pick the 'user double-clicked a script' option, missing that the parent process would be explorer.exe, not winword.exe, which is the key forensic clue.

How to eliminate wrong answers

Option A is wrong because double-clicking a PowerShell script attachment would make explorer.exe or the mail client the parent process, not winword.exe. Option C is wrong because a scheduled task starting PowerShell would show taskeng.exe or svchost.exe as the parent, and it would not explain Word being the parent. Option D is wrong because legitimate PowerShell execution from within Word is extremely rare and would still be unusual; the email-delivered document context strongly points to malicious macro activity rather than a benign script.

662
MCQmedium

A SOC analyst is reviewing logs from a web server and sees the following request: GET /../../etc/passwd HTTP/1.1. Which type of web attack is this?

A.SQL injection
B.Cross-site request forgery (CSRF)
C.Directory traversal
D.Cross-site scripting (XSS)
AnswerC

The log entries clearly display dot-dot-slash (../) sequences, or their URL-encoded equivalents like %2e%2e%2f, which are classic signatures of a directory traversal attack. This exploit attempts to escape the web root directory to access restricted system files, such as /etc/passwd or boot configuration files.

Why this answer

The request GET /../../etc/passwd HTTP/1.1 uses '../' sequences to traverse directories outside the web root, attempting to read the /etc/passwd file. This is the classic signature of a directory traversal (path traversal) attack, which exploits insufficient input validation to access unauthorized files on the server.

Exam trap

CompTIA often tests the distinction between directory traversal and file inclusion; the trap here is confusing the '../' path manipulation with SQL injection or XSS because the request looks like a simple GET, but the attack vector is purely about file system access, not database or script injection.

How to eliminate wrong answers

Option A is wrong because SQL injection involves injecting SQL commands into input fields to manipulate a database, not path manipulation in HTTP requests. Option B is wrong because CSRF tricks a user's browser into executing unwanted actions on a trusted site, not directly requesting files via path traversal. Option D is wrong because XSS injects client-side scripts into web pages viewed by others, not server-side file access via directory traversal.

663
MCQmedium

A security analyst is using a container image scanner to identify vulnerabilities in a Kubernetes deployment. Which of the following tools is specifically designed for container image scanning?

A.Trivy
B.OpenVAS
C.Nessus
D.Burp Suite
AnswerA

Trivy is an open-source vulnerability scanner specifically designed for containers, Kubernetes, and IaC templates. It excels at detecting vulnerabilities in OS packages and application dependencies within container images, making it ideal for integration into CI/CD pipelines.

Why this answer

Trivy is a popular open-source tool for scanning container images for vulnerabilities.

664
MCQmedium

A security analyst reviews a Nessus scan result for a web server. The plugin output indicates a critical vulnerability with CVSS v3.1 base score 9.8. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Which of the following best describes the attack complexity?

A.Low
B.Critical
C.Medium
D.High
AnswerA

The CVSS vector string 'AC:L' explicitly denotes a Low Attack Complexity. This means that a successful attack does not require specialized conditions beyond the attacker's control, nor does it demand extensive preparation or specific timing. Attackers can typically exploit such vulnerabilities with readily available techniques and resources, making the attack relatively straightforward and increasing its likelihood.

Why this answer

In the CVSS vector, AC:L means Attack Complexity is Low, indicating no special conditions are required for exploitation.

665
MCQeasy

What is the primary purpose of performing credentialed vulnerability scans?

A.Eliminate the need for patch management
B.Reduce network bandwidth usage
C.Avoid detection by the target system
D.Provide deeper insight into the system configuration
AnswerD

By authenticating to the target, the scanner can query installed software versions, registry settings, running services, and local configuration files directly from the operating system, producing far more accurate and complete vulnerability data than an external, unauthenticated scan could infer from network responses alone.

Why this answer

Credentialed scans authenticate to the target system, allowing deeper inspection (e.g., registry, installed software) for a more accurate assessment.

666
MCQmedium

A security analyst is configuring a vulnerability scanner to perform a scan of a network segment. The analyst wants to minimize the risk of disrupting critical production systems during the scan. Which of the following scanner settings should the analyst adjust?

A.Scan schedule
B.Scan intensity
C.Credentialed scanning
D.Plugin updates
AnswerB

Scan intensity controls the aggressiveness of the scan, including the number of concurrent connections and payloads sent. Lowering intensity reduces the risk of overwhelming production systems, which could cause outages. The analyst should set a lower intensity to avoid disruption while still identifying vulnerabilities. This setting directly addresses the need to balance thoroughness with system stability.

Why this answer

Scan intensity determines how aggressively the scanner probes systems, including the rate of connections and the types of checks performed. Lowering intensity reduces the chance of causing performance issues or crashes on production systems. While scheduling and credentialed scanning have their place, adjusting intensity is the most direct way to minimize disruption.

Plugin updates are unrelated to scan impact.

Exam trap

The trap here is assuming that scheduling the scan during off-peak hours is sufficient to prevent disruption, when the scan's intensity is the primary factor affecting system load.

667
MCQhard

During a configuration compliance scan using OpenSCAP, a security analyst finds that several Windows servers have the 'Network access: Do not allow anonymous enumeration of SAM accounts' setting set to 'Disabled'. This finding corresponds to a CIS Benchmark recommendation. Which of the following describes the most appropriate remediation step for this finding?

A.Disable the Guest account on all servers.
B.Apply a registry key to disable anonymous enumeration.
C.Restrict anonymous access using IPsec rules.
D.Enable the policy 'Network access: Do not allow anonymous enumeration of SAM accounts' via Group Policy.
AnswerD

This Group Policy setting directly addresses the OpenSCAP finding by preventing unauthenticated users from enumerating domain or local account names and shares. Enabling this policy enforces the recommended CIS benchmark control, securing the SAM database against reconnaissance techniques like null session enumeration without disrupting legitimate system operations.

Why this answer

The setting should be enabled to prevent anonymous enumeration of SAM accounts. The remediation is to change the policy setting via Group Policy or local security policy.

668
MCQeasy

A security analyst reviews a SIEM alert that fired when a user successfully logged into a server from a remote IP address at 3 AM. The user is a system administrator who often works late. What is the most appropriate initial classification of this alert?

A.False positive
B.True positive
C.True negative
D.False negative
AnswerA

This scenario represents a false positive because the SIEM's correlation rules triggered an alert on benign, authorized user activity. The system incorrectly classified a legitimate login attempt as a security threat, requiring the analyst to investigate and potentially tune the rule to prevent future noise.

Why this answer

The alert is a false positive because the SIEM rule triggered on a legitimate login that matches the pattern of an authorized after-hours admin session. The user is a system administrator who often works late, so the activity is expected and benign. A true positive would require the login to be malicious or unauthorized, which is not the case here.

Since the alert fired but the underlying activity is not a security incident, it is correctly classified as a false positive.

Exam trap

CS0-004 often tests the distinction between alert classification terms, and the trap is confusing 'false positive' with 'true positive' by assuming any alert that fires is a true positive, or misinterpreting 'true negative' as a correct non-alert.

How to eliminate wrong answers

Option B is wrong because a true positive means the alert correctly identified malicious or unauthorized activity, but the login was legitimate. Option C is wrong because a true negative refers to no alert firing when no malicious activity occurs, which is not the scenario here since an alert did fire. Option D is wrong because a false negative means malicious activity occurred but no alert was generated, whereas here an alert was generated for benign activity.

669
MCQmedium

A security analyst is reviewing a vulnerability scan report and notices that a plugin output indicates a potential misconfiguration in a web server that allows directory listing. The analyst wants to verify this finding manually. Which of the following tools would be most appropriate to confirm the vulnerability?

A.Burp Suite
B.Metasploit
C.Wireshark
D.Nmap
AnswerA

Burp Suite is an intercepting proxy designed specifically for web application security testing. It allows an analyst to intercept, modify, and replay HTTP/HTTPS requests to manually inspect the web server's responses. This makes it the ideal tool to safely and directly verify if directory listing is enabled on a specific web directory.

Why this answer

Burp Suite is a web application security testing tool that can be used to manually verify web vulnerabilities like directory listing by intercepting and modifying requests.

670
MCQeasy

A security analyst is using a DAST tool to test a web application. Which of the following vulnerabilities would the tool most likely identify?

A.Hardcoded credentials in source code
B.SQL injection
C.Outdated library versions
D.Insecure cryptographic algorithms in configuration
AnswerB

DAST tools excel at identifying input validation flaws like SQL injection by actively sending malicious payloads to application entry points and analyzing the HTTP responses. If the application returns database error messages or exhibits unexpected behavior, the tool flags the vulnerability in real-time.

Why this answer

DAST tools interact with the running application and can detect vulnerabilities like SQL injection by sending malicious inputs and observing responses.

671
MCQeasy

A company has a policy to remediate vulnerabilities within 30 days. A critical vulnerability is discovered on a database server. The patch requires a reboot, and the database cannot be taken offline during business hours. Which of the following is the BEST approach?

A.Implement a compensating control
B.Apply a hotfix without reboot
C.Schedule the patch during the next maintenance window
D.Extend the remediation deadline
AnswerC

Scheduling the patch for the next maintenance window, especially if it's more than 30 days away, directly violates the company's established remediation policy. This approach leaves the vulnerability unaddressed and the system exposed for an extended period, significantly increasing the risk of exploitation. It prioritizes operational convenience over security policy adherence and immediate risk mitigation.

Why this answer

Since the database cannot be taken offline during business hours, the standard and best practice is to schedule the installation and reboot during the next scheduled maintenance window (which occurs outside of business hours). This allows the vulnerability to be fully remediated (patched) within the 30-day policy limit without violating operational SLAs. Compensating controls are typically reserved for situations where a patch cannot be applied at all or must be delayed significantly beyond policy limits.

Exam trap

CompTIA often tests the balance between security and operations. Students often think that critical vulnerabilities must be patched immediately (even if it violates SLAs) or that compensating controls are the first choice. However, if a maintenance window is available outside of business hours, scheduling the patch is the correct and standard procedure to achieve actual remediation.

How to eliminate wrong answers

Option B is wrong because applying a hotfix without reboot is not feasible for a patch that explicitly requires a reboot to complete installation; a hotfix that does not require a reboot would need to be specifically designed for that purpose, and the scenario does not indicate such a hotfix exists. Option C is wrong because scheduling the patch during the next maintenance window may exceed the 30-day remediation deadline if the window falls outside that timeframe, and the policy requires remediation within 30 days, not merely scheduling. Option D is wrong because extending the remediation deadline violates the company's explicit policy to remediate vulnerabilities within 30 days, and it does not actively reduce risk during the extension period.

672
MCQmedium

A security analyst is configuring a vulnerability scanner for internal network scanning. The analyst wants to ensure the scanner can identify missing patches and software configurations that require administrative privileges to read. Which scan type should the analyst configure?

A.Non-credentialed scan
B.Credentialed scan
C.External scan
D.Passive scan
AnswerB

A credentialed scan utilizes provided administrative or user credentials to log directly into the target operating system. This allows the scanner to perform deep local inspections, such as querying the registry, checking package manager databases, and auditing configuration files. Consequently, it provides a highly accurate assessment of missing patches and misconfigurations with minimal false positives.

Why this answer

Credentialed scans use administrative credentials to access systems and retrieve detailed configuration information, including missing patches.

673
Multi-Selectmedium

A security analyst is reviewing network traffic and suspects a host is infected with malware that uses a domain generation algorithm (DGA) for C2 communication. Which two of the following indicators are most consistent with DGA activity?

Select 2 answers
A.All DNS queries are to internal DNS servers
B.Frequent DNS queries to domains with random-looking, long subdomains
C.DNS queries to domains with a high Alexa ranking
D.High volume of DNS queries resulting in NXDOMAIN responses
E.Consistent DNS query intervals to a single IP
AnswersB, D

Frequent queries to domains with random-looking, long subdomains are a hallmark of Domain Generation Algorithms (DGAs). Malware uses DGAs to generate pseudorandom domain names as rendezvous points with command-and-control (C2) servers, often producing long, alphanumeric subdomains that appear nonsensical. The high query rate to such domains is a strong indicator of compromise because legitimate users rarely make repeated queries to random subdomains.

Why this answer

Option B is correct because DGA malware generates large numbers of pseudo-random domain names (often long, high-entropy subdomains) and the infected host repeatedly queries them while attempting to locate its C2 server. Option D is correct because most algorithmically generated domains are unregistered, so the resolver typically returns NXDOMAIN for the vast majority of these queries, producing a distinctive high-volume NXDOMAIN pattern. Option A is not indicative of DGA activity, since using internal DNS resolvers is normal enterprise behavior and says nothing about the queried domain names.

Option C is not indicative because DGA domains are newly generated and unregistered, so they would not have a high Alexa ranking. Option E is not indicative because consistent intervals to a single IP suggest beaconing to a fixed C2, whereas DGA relies on constantly changing domain names.

Exam trap

CS0-004 often tests the confusion between DGA indicators (random domains, NXDOMAIN floods) and fixed-C2 beaconing (consistent intervals to one IP), so candidates pick the beaconing pattern as DGA.

674
MCQmedium

A security analyst is reviewing a DAST scan report for a web application. The report indicates a vulnerability where the application fails to properly validate user-supplied data before using it in a database query. This is most likely which type of vulnerability?

A.Cross-site scripting (XSS)
B.Security misconfiguration
C.Injection
D.Broken access control
AnswerC

Injection vulnerabilities occur when an application passes unfiltered, user-supplied input directly to an interpreter, such as a SQL database or system shell. This allows an attacker to manipulate the structure of the intended command, leading to unauthorized data access, modification, or arbitrary remote code execution on the host system.

Why this answer

Failure to validate user input before using in a database query is classic SQL injection (injection flaw).

675
MCQeasy

A CI pipeline blocks a container image because the base layer contains a critical OpenSSL CVE. The application team says the vulnerable binary is not used. What is the BEST next step? For business prioritization, Which recommendation gives the best risk-based order of work?

A.Ignore all base-image vulnerabilities
B.Only rename the image tag
C.Validate exploitability and rebuild from a patched base image where feasible
D.Ship the image and document nothing
AnswerC

Validating exploitability is a crucial first step to prioritize remediation efforts by determining if a vulnerability is reachable and impactful within the specific container context. Subsequently, rebuilding the image from a patched base image directly addresses the root cause of the vulnerability at its foundational layer. This proactive approach significantly reduces the inherited risk, ensures the deployment of secure artifacts, and aligns with best practices for maintaining a robust software supply chain.

Why this answer

The best next step is to validate whether the vulnerable OpenSSL binary is actually reachable or exploitable in the running container, and then rebuild from a patched base image if feasible. This balances security with business priorities by avoiding unnecessary rebuilds for non-exploitable vulnerabilities while ensuring that truly exploitable CVEs are remediated. Simply ignoring or renaming the tag does not address the underlying risk and violates secure CI/CD practices.

Exam trap

The CS0-004 exam often tests the misconception that a vulnerability can be safely ignored if the application team claims the binary is unused, but the trap is that without validation (e.g., runtime reachability analysis), the claim may be false due to transitive dependencies or dynamic loading.

How to eliminate wrong answers

Option A is wrong because ignoring all base-image vulnerabilities would leave the organization exposed to known critical CVEs, violating vulnerability management policies and potentially leading to compliance failures. Option B is wrong because renaming the image tag does not remove or patch the vulnerable binary; it only obscures the issue, and the vulnerable layer remains in the image, which could still be exploited if the binary is reachable.

Page 8

Page 9 of 10

Page 10

All pages