Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CompTIA Cybersecurity Analyst CySA+ V4 (New Version) CS0-004 Exam Questions

Page: 1 / 9 Total 82 questions

Want more questions? Get Premium Access.

Question 1

A security architect works with a client on security operations center (SOC) capabilities. The security architect wants to ensure the log correlation and investigation activities are accurate across the infrastructure.

Which of the following is the best for the client to implement?

Correct Answer: A. Network Time Protocol (NTP)
Explanation:

Accurate time synchronization is essential for reliable log correlation, making Network Time Protocol the best answer. Security investigations routinely combine events from endpoints, servers, authentication infrastructure, firewalls, cloud services, intrusion-detection systems, and other platforms. If those systems maintain inconsistent clocks, the apparent order of events may be incorrect, making it difficult to reconstruct an attack timeline or correlate activity across multiple sources.

NTP is specifically designed to synchronize computer clocks across distributed systems. RFC 5905 defines NTPv4 as a protocol used to synchronize clocks across internet-connected systems. Synchronized timestamps enable the SOC to determine whether events occurring on separate systems actually belong to the same sequence---for example, authentication followed by process execution, lateral movement, and a subsequent network connection.

ZTNA controls access according to Zero Trust principles but does not synchronize timestamps. Account federation addresses identity interoperability. SASE combines network and security services for distributed environments. APIs can integrate tools and exchange information, but integrated data remains difficult to correlate accurately if each system's timestamps are inconsistent.

For forensic and operational analysis, a consistent time reference is therefore foundational to timeline reconstruction, event sequencing, SIEM correlation, and evidentiary accuracy.

Study Guide Reference: Security Operations Logging and Monitoring Time Synchronization NTP SIEM Correlation Timeline Analysis.


Question 2

Which of the following best explains why sensitive data should be encrypted at rest on laptops?

Correct Answer: B. To protect disclosure of information if physical devices are stolen
Explanation:

Encryption at rest primarily protects the confidentiality of stored information when an unauthorized party obtains physical or logical access to the storage medium. This is particularly important for laptops because portable devices can be lost or stolen, giving an attacker possession of the disk outside the organization's normal network and endpoint protections.

NIST guidance on storage encryption specifically addresses laptops and other end-user devices and explains that storage encryption combines encryption and authentication to restrict unauthorized access to stored information. NIST further notes that threats involving lost or stolen end-user devices can expose information to unauthorized parties.

Encryption does not inherently prevent an authenticated and authorized user from copying information while the system is unlocked; data loss prevention controls are more directly suited to that objective. Regulatory requirements may mandate encryption in some environments, but compliance is an external requirement rather than the fundamental security reason encryption at rest exists. Option D confuses confidentiality with integrity and network protection. Encryption of data stored on a laptop is not primarily intended to validate whether network data has been modified.

The examination concept is the CIA triad: encryption primarily supports confidentiality, especially when physical possession of the storage device is lost.

Study Guide Reference: Security Operations Data Protection Encryption at Rest Full-Disk Encryption Confidentiality Lost/Stolen Endpoint Protection.


Question 3

A team lead asks an analyst to integrate multiple security tools to provide an enhanced view into data that is not readily available in the tool console.

Which of the following will best meet this requirement?

Correct Answer: A. Utilizing application programming interfaces
Explanation:

Application programming interfaces (APIs) provide the most direct mechanism for retrieving, exchanging, and integrating information between separate security technologies. A product console normally exposes only the information and workflows chosen by the vendor for its graphical interface. An API can provide programmatic access to underlying alerts, events, asset information, telemetry, configuration objects, or investigation data, allowing an analyst to combine information from multiple systems into a richer analytical view.

CISA describes security-analysis workflows in which integration enables defenders to connect existing analytical tools and automate data-handling processes, while modern security platforms commonly expose APIs specifically to ingest or exchange telemetry.

SOAR can certainly integrate multiple tools, but its primary purpose is orchestration and automation of security workflows. If the requirement is specifically to access and combine information not readily exposed in individual consoles, APIs are the underlying capability most directly suited to retrieving that data. Infrastructure as code defines and provisions infrastructure through machine-readable templates; it does not primarily aggregate security telemetry. Playbooks establish standardized investigation or response procedures but do not themselves provide interfaces into external product data.

The key phrase is ''enhanced view into data.'' This requires programmatic access and integration rather than merely workflow documentation or automation.

Study Guide Reference: Security Operations Security Tool Integration APIs Data Enrichment Automation/Orchestration SOC Process Improvement.


Question 4

An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only.

The analyst scans with the following command:

$sudo nmap -Pn 10.203.10.0/24

The analyst then receives the following output:

Which of the following hosts should the analyst prioritize for patching?

Correct Answer: A. 10.203.10.11
Explanation:

The analyst should prioritize 10.203.10.11 because the scan output identifies that host as presenting the Windows SMB exposure relevant to the critical vulnerability. Vulnerability prioritization requires matching the vulnerability's technical prerequisites against the characteristics discovered on each host rather than simply patching every responding system indiscriminately.

Modern SMB services commonly use TCP port 445. Microsoft documents TCP 445 as a required port for SMB-based file services, with port 139 associated with older NetBIOS-based implementations. Therefore, a Windows host exposing the affected SMB service satisfies an essential condition for applicability and should be prioritized when the vulnerability specifically targets open SMB ports.

The -Pn option is also significant operationally because it instructs Nmap to treat targets as online without relying on normal host-discovery probes. The analyst can consequently inspect reachable service ports even when systems do not respond to standard discovery methods.

The remaining hosts either do not expose the vulnerable SMB service or do not match the required Windows/service profile described by the scenario. Priority should follow confirmed applicability, exposure, severity, and exploitability.

Study Guide Reference: Vulnerability Management Nmap Port Scanning SMB TCP 445/139 Vulnerability Applicability Remediation Prioritization.


Question 5

An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)

Correct Answer: A. Host ws-57 is performing a network scan against dc-1.; D. Host ws-57 is communicating on a service using a non-standard port.
Explanation:

The log relationships support two conclusions: ws-57 is scanning dc-1, and ws-57 is communicating with a service through a non-standard port. Network scanning is normally identified when one source system attempts connections against multiple ports or services on another host over a short period. Here, the directionality of the recorded communications identifies ws-57 as the initiating host and dc-1 as the target, supporting option A rather than B.

Port numbers then need to be interpreted in context. Standard service-port mappings provide useful baselines, but a service can technically operate on a port different from its conventional assignment. Detection logic therefore needs to consider both the actual port number and the protocol or service identified in the traffic. Nmap, for example, classifies scanned ports according to states and attempts to associate ports with known services during network reconnaissance.

The entries do not provide sufficient behavioral evidence for phishing delivery or ransomware infection. Those conclusions would require additional indicators such as SMTP message evidence, malicious attachments, encryption activity, process execution, or endpoint telemetry.

The correct analytical approach is to determine source, destination, connection pattern, and port/service relationship before assigning malicious intent.

Study Guide Reference: Security Operations Network Log Analysis Scanning/Enumeration Source/Destination Interpretation Ports and Protocols Non-standard Service Ports.


Question 6

Which of the following best describes why operational technology (OT) devices use compensating controls?

Correct Answer: C. Traditional IT security solutions may not be compatible.
Explanation:

Operational technology environments frequently contain specialized controllers, industrial control systems, supervisory control and data acquisition equipment, embedded operating systems, and vendor-specific devices that were designed primarily for availability, safety, deterministic operation, and long service life. Traditional enterprise security controls---such as endpoint detection agents, vulnerability scanners, host-based firewalls, aggressive patching mechanisms, or modern authentication software---may not be supported and can potentially interfere with operational processes.

For this reason, organizations often implement compensating controls around OT assets when the preferred security control cannot be deployed directly. Examples include network segmentation, tightly controlled firewall rules, protocol allowlisting, passive monitoring, secure jump servers, access restrictions, enhanced logging, and additional physical controls. These measures reduce risk without requiring unsupported software to be installed on sensitive industrial devices.

High network bandwidth consumption is not the defining reason for compensating controls. Scheduled outage windows can actually facilitate maintenance rather than explain why alternative controls are required. Likewise, lack of encryption may be a weakness in some environments, but it does not explain the broader compatibility problem.

CS0-004 specifically places OT, ICS, and SCADA under critical-infrastructure concepts in Security Operations and separately recognizes compensating controls as a formal vulnerability mitigation strategy.

Study Guide Reference: Security Operations Critical Infrastructure OT/ICS/SCADA Security Architecture Compatibility Constraints and Compensating Controls.


Question 7

A cybersecurity analyst requests a paid subscription to a threat intelligence feed relevant to a company's industry.

Which of the following best describes this type of feed?

Correct Answer: D. Closed-source intelligence
Explanation:

A paid, subscription-based threat intelligence service is best classified as closed-source intelligence because access is restricted to authorized subscribers rather than being freely available to the public. Commercial threat-intelligence providers typically collect, analyze, correlate, and curate indicators and adversary information before distributing that intelligence through authenticated portals, APIs, or feeds.

NIST identifies several external intelligence-source categories, including open-source repositories, commercial threat feeds, and external information-sharing partners. A commercial feed relevant to a company's specific industry may provide higher-context intelligence regarding threat actors, infrastructure, malware, vulnerabilities, campaigns, and indicators affecting that vertical.

OSINT, by contrast, originates from publicly accessible sources and normally does not require restricted subscription access. Threat mapping is the activity of associating adversary behavior or intelligence with infrastructure, campaigns, frameworks, or organizational assets. Threat modeling is a structured process used to identify potential threats and weaknesses in systems or applications; it is not an intelligence-source classification.

The examination clue is ''paid subscription.'' Restricted commercial access distinguishes the feed from publicly obtainable OSINT.

Study Guide Reference: Security Operations Threat Intelligence Intelligence Sources Open-Source Intelligence Closed/Commercial Intelligence Industry-Specific Threat Feeds.


Question 8

A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the 10.213.4.27 file server.

This file server is under investigation due to concerns about potential data exfiltration using Domain Name System (DNS) traffic.

Which of the following commands should the analyst use to extract any potentially leaked data from the suspicious.pcap file?

Correct Answer: D. tcpdump -r suspicious.pcap port 53 and host 10.213.4.27
Explanation:

Option D applies the correct packet-filtering logic to isolate DNS-related traffic associated with the suspected server. The -r suspicious.pcap option directs tcpdump to read packets from the existing PCAP rather than capture live traffic. The expression port 53 and host 10.213.4.27 then limits output to packets involving the specified system and DNS's conventional port 53.

This is directly relevant to suspected DNS exfiltration. Attackers can encode data within DNS queries or responses, including unusually long subdomains or other manipulated DNS fields. Isolating the target's port 53 traffic dramatically reduces the dataset and allows the analyst to examine relevant queries and responses for encoded or anomalous information.

strings suspicious.pcap | grep treats the capture primarily as raw printable data and does not accurately perform protocol-aware packet filtering. The Zeek option searches file.log, which is focused on files observed in network traffic and is not the most direct location for DNS-query analysis. The Snort syntax shown is also inappropriate for the required extraction workflow.

The essential skill is translating an investigative hypothesis---possible DNS exfiltration by a known host---into a precise PCAP filter.

Study Guide Reference: Security Operations Network Traffic Analysis Full Packet Capture tcpdump BPF Filters DNS Analysis Data Exfiltration Detection.


Question 9

Which of the following is commonly used after an incident has been resolved to identify efficiencies and corrective actions related to activities performed during the incident response process?

Correct Answer: A. Lessons learned
Explanation:

A lessons learned review evaluates how the incident was handled and identifies improvements that should be incorporated into future response activities. It examines what worked well, what created delays, where communications or escalation failed, whether tools and playbooks were effective, and which corrective actions should be assigned to reduce the likelihood or impact of similar incidents.

NIST's current incident-response guidance places strong emphasis on continuous improvement. It states that lessons identified during incident-response activities should feed into organizational improvement so policies, processes, practices, and security capabilities can be adjusted as necessary. NIST also notes that traditional post-incident activities identify required improvements and return them to preparation and broader cybersecurity risk management.

KPIs quantify operational performance but do not themselves provide the qualitative review necessary to identify process efficiencies and corrective actions. An executive summary communicates major incident facts and outcomes to leadership. Root cause analysis focuses on identifying the fundamental technical or organizational cause of the incident; it can contribute to lessons learned but is narrower in scope.

Therefore, the broader mechanism for reviewing the entire response process and developing improvement actions is the lessons-learned process.

Study Guide Reference: Reporting and Communication Post-Incident Reporting Lessons Learned Corrective Actions Process Improvement Stakeholder Feedback.


Question 10

Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?

Correct Answer: A. Residual
Explanation:

Residual risk is the risk that remains after security controls, safeguards, or mitigation measures have been implemented. No practical security program can eliminate every threat or vulnerability completely, so organizations evaluate the remaining exposure to determine whether additional treatment is required or whether management can formally accept it.

The distinction from inherent risk is particularly important. Inherent risk represents the level of exposure before controls are applied. For example, an internet-facing application containing sensitive information may have substantial inherent risk. After implementing strong authentication, patching, a web application firewall, monitoring, secure coding controls, and segmentation, its probability and impact of compromise may be reduced---but not eliminated. The remaining exposure is residual risk.

''Acceptable risk'' describes risk that falls within an organization's approved tolerance or appetite; residual risk may or may not be acceptable. If the remaining exposure still exceeds tolerance, further controls, avoidance, transfer, or other treatment may be necessary. ''Appropriate'' is not a formal risk category in this context.

Risk management therefore follows a continuous cycle of identifying inherent exposure, applying controls, measuring the remaining residual exposure, and comparing that level with organizational risk tolerance.

Study Guide Reference: Vulnerability Management Risk Analysis Inherent Risk Mitigating Controls Residual Risk Risk Acceptance Risk Appetite and Tolerance.