Courseiva
← Back to CompTIA CySA+ CS0-004 questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise CompTIA CySA+ CS0-004 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CS0-004
exam code
CompTIA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CS0-004 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

A security analyst is evaluating a Kubernetes cluster for misconfigurations. Which TWO of the following are common Kubernetes misconfigurations that increase security risk? (Select the two best answers.)

Question 2hardmulti select
Full question →

A cybersecurity analyst is presenting risk findings to the board of directors. Which THREE types of impact should be emphasized to effectively communicate business risk? (Select THREE.)

Question 3easymulti select
Full question →

A security analyst is reviewing alerts from an IDS. Which TWO indicators are most likely to suggest a successful command and control (C2) communication? (Choose two.)

Question 4hardmulti select
Full question →

A root-cause analysis finds that an alert fired but was never triaged. Which corrective actions are useful? (Choose two.)

Question 5hardmulti select
Full question →

A cloud security posture tool reports public access on object storage. Which follow-up checks matter? (Choose two.)

Question 6mediummulti select
Full question →

A security analyst suspects an insider threat based on unusual data access patterns by an employee. According to best practices, which TWO actions should the analyst take FIRST?

Question 7hardmulti select
Full question →

After a data breach incident, a post-incident review team is collecting lessons learned. Which THREE items should be included in the lessons learned documentation?

Question 8hardmulti select
Full question →

An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)

Question 9hardmulti select
Read the full DNS explanation →

An analyst suspects DNS tunnelling but wants to avoid over-escalating normal CDN behaviour. Which comparisons help? (Choose two.)

Question 10mediummulti select
Full question →

A vulnerability report is going to system owners. Which elements make it actionable? (Choose three.)

Question 11mediummulti select
Full question →

Which TWO methods help ensure the accuracy of security metrics reported to management?

Question 12mediummulti select
Full question →

A Security Operations Center (SOC) analyst is tuning a SIEM rule to reduce false positives. Which three of the following are valid approaches to improve the signal-to-noise ratio of a detection rule? (Choose three.)

Question 13mediummulti select
Full question →

A SOC is onboarding endpoint logs into a SIEM. Which fields are most important for process-chain investigations? (Choose three.)

Question 14hardmulti select
Full question →

A SIEM receives endpoint, firewall, identity, and cloud logs for the same incident, but timestamps do not align across sources. Which actions should the analyst take before finalizing the timeline? (Choose two.)

Question 15mediummulti select
Full question →

Which items belong in a vulnerability exception request? (Choose three.)

Question 16hardmulti select
Full question →

A regulator asks for incident evidence after a data exposure. Which items should be coordinated before disclosure? (Choose two.)

Question 17hardmulti select
Full question →

A remediation report shows repeated SLA breaches by one business unit. Which recommendations are appropriate? (Choose two.)

Question 18mediummulti select
Full question →

Which items help make a post-incident report useful for technical teams? (Choose two.)

Question 19hardmulti select
Full question →

An application has a high CVSS vulnerability, but a WAF rule blocks known exploit payloads. What should the team still do? (Choose two.)

Question 20mediummulti select
Full question →

When briefing legal and privacy teams after a suspected data exposure, which details matter? (Choose two.)

These CS0-004 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style CS0-004 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.