Free CS0-004 sample questions
Real questions from the CompTIA Cybersecurity Analyst (CySA+) V4 practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A senior threat hunter is developing a new methodology for the organization. Instead of waiting for alerts generated by known Indicators of Compromise (IoCs), the hunter decides to assume a breach has occurred and searches for anomalous PowerShell execution bypasses across the fleet. Which of the following BEST describes this approach?
During a routine audit of log sources, a security architect notices that Windows Event ID 4769 (A Kerberos service ticket was requested) is not being forwarded to the centralized SIEM. Which of the following malicious activities would be MOST difficult to detect due to this logging gap?
A SOC analyst receives an "Impossible Travel" alert from the organization's cloud identity provider. The alert indicates that a user successfully authenticated from New York, USA, and then successfully authenticated from Tokyo, Japan, only 45 minutes later. Which of the following is the MOST likely benign explanation for this alert?
A multinational financial services company is redesigning its enterprise architecture. Historically, the company relied on a perimeter-based security model utilizing robust edge firewalls and a trusted internal flat network. Remote users accessed internal resources via a traditional IPSec VPN. Due to rapid cloud adoption and a highly distributed workforce, the company has experienced several incidents where compromised remote endpoints allowed attackers to move laterally across the internal network unhindered. Leadership has mandated a transition to a Zero Trust Architecture (ZTA). The new architecture must ensure that network location is no longer the primary determinant of trust. Access to corporate applications, whether hosted on-premises or in the cloud, must be dynamically verified for every request. Based on the scenario, which architectural implementation is MOST critical to achieving the core principles of the mandated Zero Trust strategy? graph TD User[Remote User] -->|Identity + Device Posture| Policy[Trust Broker / Policy Engine] Policy -->|Deny| Block[Block Access] Policy -->|Allow| App[Target Application] App -->|Micro-segmented| DB[(Database)]
A SOC team is investigating a potential lateral movement incident. The analyst needs to combine capabilities from both the SIEM and the EDR solution to build a complete timeline of the attacker's actions. Which TWO of the following tasks are BEST suited for the EDR tool rather than the SIEM? (Select TWO)
While reviewing alerts, a junior analyst notices that a user's workstation has triggered multiple antivirus warnings for "Mimikatz" over the last 10 minutes. Which of the following is the MOST immediate risk to the organization based on this specific indicator?
A security analyst is reviewing a packet capture (PCAP) file from a compromised workstation. The analyst observes a high volume of DNS TXT record queries directed to an external IP address that is not the organization's configured DNS server. The TXT responses contain long strings of base64-encoded text. What is the MOST likely explanation for this activity?
During an incident investigation, an analyst discovers that an attacker gained access to multiple SaaS applications without needing the users' passwords. The attacker achieved this by forging an XML-based assertion, signing it with a stolen private key from the organization's Identity Provider (IdP), and presenting it to the Service Providers (SPs). Which identity protocol was abused in this attack?
True or False: When utilizing Artificial Intelligence (AI) and Machine Learning (ML) models for threat hunting, "AI Hallucinations" refer to instances where the model confidently presents false or fabricated data as factual intelligence, which can lead analysts down incorrect investigative paths.
10 more free samples are waiting
Create a free account to unlock the whole CS0-004 sample bank, or get full access to all 150 practice questions in the simulator.