CS0-004 CompTIA Cybersecurity Analyst (CySA+) V4 Practice Questions
Prepare for CS0-004 with more than an answer.
Unlock the full exam and previous versions
- v1CompTIA Cybersecurity Analyst (CySA+) V4 150 questions Current
- CS0-002Legacy CompTIA Cybersecurity Analyst (CySA+ v2) 122 questions Locked
- CS0-003Legacy CompTIA Cybersecurity Analyst (CySA+ v3) 271 questions Locked
- Level
- Intermediate
Domains covered on the exam 4
- Security Operations34%
- Vulnerability Management26%
- Incident Response and Management24%
- Reporting and Communication16%
- 1
While investigating an AWS environment compromise, an analyst reviews CloudTrail logs and finds multiple
sts:AssumeRoleevents originating from a compromised EC2 instance's IAM role. The events show the role assuming a higher-privileged administrative role in another account. Which cloud attack technique is being demonstrated?Show answer details
Correct answer: B
Role chaining occurs when an identity uses its permissions to assume another role, which may then assume another role, and so on. Attackers use this to escalate privileges or move laterally across cloud accounts (cross-account access). The
sts:AssumeRoleAPI call is the primary mechanism for this in AWS. While SSRF might have been used initially to steal the instance credentials, the log activity itself represents role chaining. - 2
A vulnerability management team needs to scan a segment of Windows servers to identify missing registry-level security configurations and outdated third-party software versions. Which scanning method is REQUIRED to achieve this level of visibility?
Show answer details
Correct answer: B
A credentialed (authenticated) scan uses administrative credentials to log into the target system. This allows the scanner to read the local registry, check installed software versions, and verify local file configurations. An uncredentialed scan only sees what is exposed over the network (e.g., open ports and banner grabbing) and cannot check registry keys.
- 3
An organization is prioritizing vulnerabilities using the CVSS v4.0 framework. A network-exploitable vulnerability rated Critical is identified on a server. However, in this organization's deployment the server is completely isolated from all networks, so it can only be reached through local physical access. Furthermore, a strict compensating control (application whitelisting) is already in place. Which CVSS metric group should the team adjust to reflect this specific business and architectural context?
Show answer details
Correct answer: C
In CVSS v4.0 (and previous versions), Environmental metrics allow an organization to customize the score for its own environment. The Modified Base metrics let the consumer override Base values to reflect deployment characteristics and mitigations - for example, Modified Attack Vector set to Physical because this server is isolated, with compensating controls such as application allowlisting reflected in the modified exploitability/impact values - while the Security Requirements (CR/IR/AR) express how critical the asset is to the organization. Base metrics describe the intrinsic qualities of the flaw, Threat metrics (formerly Temporal) describe Exploit Maturity, and Supplemental metrics add context without changing the score.
- 4
A security analyst is reviewing a vulnerability scan report for a custom-built web application. The automated scanner flagged a "SQL Injection" vulnerability. Upon manual investigation, the analyst discovers that the application uses parameterized queries for all database interactions and the scanner only flagged the issue because an error message contained the word "syntax". Which TWO actions should the analyst take? (Select TWO)
Show answer details
Correct answer: A, C
Since the application uses parameterized queries (which prevent SQL injection) and the finding was triggered solely by a generic error message keyword, this is a false positive. The analyst must document it as such to prevent wasted remediation efforts. Additionally, suppressing or tuning the scanner rule prevents this false alert from recurring in future scans.
Since the application uses parameterized queries (which prevent SQL injection) and the finding was triggered solely by a generic error message keyword, this is a false positive. The analyst must document it as such to prevent wasted remediation efforts. Additionally, suppressing or tuning the scanner rule prevents this false alert from recurring in future scans.
- 5
A manufacturing company relies on a legacy SCADA system to control its assembly line. A recent vulnerability scan identified a critical, remotely exploitable vulnerability in the SCADA software.
The vendor went out of business five years ago, meaning no patch will ever be released. The system cannot be upgraded because it requires proprietary hardware interfaces that are incompatible with modern operating systems. However, the system must remain operational to generate revenue.
Which of the following is the BEST approach to manage this vulnerability?
graph TD Internet --> CorpNet[Corporate Network] CorpNet --> Router[Core Router] Router --> SCADA[Legacy SCADA System]Show answer details
Correct answer: B
When a system cannot be patched (due to being legacy or unsupported), the standard vulnerability management approach is to implement compensating controls. Network segmentation (isolating it in a VLAN) and restricting access (using a jump-box) mitigate the risk of remote exploitation without requiring a patch. Decommissioning halts revenue, and accepting a critical remote exploit risk without mitigation is negligent.
- 6
A retail organization processes credit card transactions and must comply with PCI DSS. According to standard compliance practices regarding vulnerability management, what is a mandatory requirement for external vulnerability scans?
Show answer details
Correct answer: B
Under PCI DSS compliance requirements, organizations that process cardholder data must conduct external vulnerability scans at least quarterly. Furthermore, these specific external scans must be performed by a PCI SSC Approved Scanning Vendor (ASV). Internal scans do not require an ASV.
- 7
A development team wants to integrate security testing into their CI/CD pipeline. They specifically want a tool that analyzes the application's source code for security flaws before the code is compiled or executed. Which type of tool should the security analyst recommend?
Show answer details
Correct answer: B
Static Application Security Testing (SAST) analyzes application source code, byte code, or binaries for security vulnerabilities without executing the program. It is ideal for early CI/CD integration (shift-left). DAST tests the running application from the outside, while IAST uses instrumentation within the running app.
- 8
A Security Operations Center (SOC) is evaluating a new Generative AI (GenAI) tool to automatically summarize incident tickets and propose remediation steps. The SOC manager is developing the governance framework for this implementation. Which of the following represents the MOST significant operational risk that must be addressed in the governance policy before deployment?
Show answer details
Correct answer: C
When utilizing public or cloud-based GenAI tools, the primary governance risk is data leakage. Submitting proprietary incident data, PII, or internal network architecture details to a public LLM can result in that sensitive data being absorbed into the model's training set and potentially exposed to unauthorized parties. The other options represent technical or workflow issues, but data privacy/leakage is the paramount governance risk.
flowchart TD SOC[SOC Analyst] -->|Pastes alert data| AI[Public GenAI Tool] AI -->|Absorbs data| Model[(Training Model)] Model -.->|Potential Exposure| Ext[External Actors] style Model fill:#f9f,stroke:#333,stroke-width:2px - 9
A senior threat hunter is developing a new methodology for the organization. Instead of waiting for alerts generated by known Indicators of Compromise (IoCs), the hunter decides to assume a breach has occurred and searches for anomalous PowerShell execution bypasses across the fleet. Which of the following BEST describes this approach?
Show answer details
Correct answer: A
Hypothesis-driven threat hunting is a proactive approach where the hunter creates a hypothesis (e.g., "An attacker is bypassing execution policies using PowerShell") based on threat intelligence or knowledge of adversary tactics, and then searches the environment for evidence of that specific behavior, assuming traditional defenses have failed. It relies on behavioral analysis rather than static IoC matching.
- 10
During a routine audit of log sources, a security architect notices that Windows Event ID 4769 (A Kerberos service ticket was requested) is not being forwarded to the centralized SIEM. Which of the following malicious activities would be MOST difficult to detect due to this logging gap?
Show answer details
Correct answer: B
Event ID 4769 is generated every time a Kerberos service ticket (TGS) is requested. In a Kerberoasting attack, an adversary requests TGS tickets for service accounts (which have SPNs) to extract them and crack the service account passwords offline. Without Event ID 4769, detecting the anomalous volume of TGS requests associated with Kerberoasting is highly difficult. Password spraying, LLMNR poisoning, and DCSync are detected via other event IDs or network traffic.
