Courseiva
Free · No account needed · No credit card

CompTIA CySA+ CS0-004 Practice Test

236 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 165 min
Pass mark: 750%

The vendor is retiring this exam on December 22, 2026.

You can still schedule and take CS0-004 until that date. See CompTIA CySA+ V4 (the successor version)

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

A SOC analyst reviews DNS telemetry and sees a workstation resolving hundreds of algorithmically generated domains at fixed intervals, with most responses returning NXDOMAIN. What evidence should the analyst prioritize to validate command-and-control beaconing? In the evidence source phase, Which evidence source best supports or refutes the detection?

ASearch only for successful HTTP 200 responses
BDelete the host from the SIEM asset inventory
CBlock all DNS traffic from the subnet
Correlate DNS query logs with endpoint process and network connection telemetryCorrect

Correlating DNS query logs with endpoint process and network connection telemetry (Option D) provides direct evidence of command-and-control (C2) beaconing by linking the algorithmically generated domain (AGD) queries to a specific process initiating outbound connections. This cr…Read full explanation

A container workload unexpectedly starts a shell, mounts the host filesystem, and attempts outbound connections to an unknown IP. Which telemetry is MOST useful? In the evidence source phase, Which evidence source best supports or refutes the detection?

AOnly monthly vulnerability scan summaries
BOnly user password age reports
COnly physical datacenter access logs
Container runtime events, Kubernetes audit logs, and network flow from the podCorrect

Container runtime events (e.g., from containerd or CRI-O) capture process spawns like an unexpected shell, Kubernetes audit logs record API calls that could indicate a compromised pod mounting the host filesystem, and network flow logs from the pod (e.g., via eBPF or Calico) reve…Read full explanation

A vendor shares indicators marked TLP:AMBER+STRICT. How should the SOC handle them? In the alert triage phase, Which action gives the analyst the clearest next triage step?

AIgnore the indicators because TLP markings are optional
BPublish the indicators on a public GitHub repository
CSend the indicators to all customers
Use them internally with only people who need to know and avoid wider redistributionCorrect

TLP:AMBER+STRICT restricts sharing to individuals within the organization who have a specific need to know, and prohibits any wider redistribution. In the alert triage phase, using the indicators internally ensures the SOC can investigate and respond without violating the informa…Read full explanation

What's covered

Questions are tagged by exam domain. Practice a specific domain or mix them all.

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All CS0-004 questionsCS0-004 exam guideStudy guidePractice by domain