Courseiva
← Back to CompTIA CySA+ CS0-004 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise CompTIA CySA+ CS0-004 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

6
scenario questions
CS0-004
exam code
CompTIA
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CS0-004 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit. An analyst reviews the output from a netstat command on a server. Which connection is MOST likely indicative of command and control (C2) activity?

Exhibit

The following output is from a compromised server:
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 10.0.0.5:3389           192.168.1.10:54321     TIME_WAIT
tcp        0      0 10.0.0.5:54321          198.51.100.20:4444     ESTABLISHED
tcp        0      0 10.0.0.5:22             10.0.0.1:50001        ESTABLISHED
Question 2mediummultiple choice
Full question →

Refer to the exhibit. An analyst sees this alert in the SIEM console: Suricata alert: ET MALWARE Ransomware activity detected from 10.0.0.5 to 10.0.0.1 over SMB. What is the best immediate action?

Exhibit

Dec  5 10:15:30 192.168.1.1 suricata: [1:2000001:1] ET TROJAN Possible Metasploit Payload Detected [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 10.0.0.5:4444 -> 10.0.0.1:80
Question 3mediummultiple choice
Full question →

Refer to the exhibit. A security analyst is reviewing SIEM logs and notices repeated entries from the same source IP. Which of the following actions should the analyst take NEXT?

Exhibit

2025-02-15 08:23:45 | src=192.168.2.10 | dst=10.0.0.5 | port=443 | action=blocked | signature=ET TROJAN Suspicious Outbound Connection
Question 4easymultiple choice
Full question →

Refer to the exhibit. The output is from a Linux system running `netstat -an`. Which of the following ports is likely being used for remote command-and-control communication?

Exhibit

Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State      
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN     
tcp        0      0 10.0.0.5:54321         198.51.100.20:443        ESTABLISHED
tcp        0      0 192.168.1.10:80         0.0.0.0:*               LISTEN     
udp        0      0 0.0.0.0:53              0.0.0.0:*
Question 5hardmultiple choice
Full question →

Refer to the exhibit. A security auditor finds this IAM policy attached to a user account. Which of the following describes the primary security concern?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:*",
      "Resource": "*"
    }
  ]
}
Question 6mediummultiple choice
Full question →

An analyst runs the above command on a server. Based on the exhibit, which of the following is the MOST likely scenario?

Exhibit

Refer to the exhibit.

Exhibit:
```
netstat -an | grep 4444
tcp        0      0 0.0.0.0:4444            0.0.0.0:*               LISTEN
tcp        0      0 192.168.1.50:4444       10.0.0.100:56789        ESTABLISHED
```

These CS0-004 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style CS0-004 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.