ExamDumpster

Free CS0-004 sample questions

Real questions from the CompTIA Cybersecurity Analyst (CySA+) V4 practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A Security Operations Center (SOC) is evaluating a new Generative AI (GenAI) tool to automatically summarize incident tickets and propose remediation steps. The SOC manager is developing the governance framework for this implementation. Which of the following represents the MOST significant operational risk that must be addressed in the governance policy before deployment?

Question 2Choose one

A senior threat hunter is developing a new methodology for the organization. Instead of waiting for alerts generated by known Indicators of Compromise (IoCs), the hunter decides to assume a breach has occurred and searches for anomalous PowerShell execution bypasses across the fleet. Which of the following BEST describes this approach?

Question 3Choose one

During a routine audit of log sources, a security architect notices that Windows Event ID 4769 (A Kerberos service ticket was requested) is not being forwarded to the centralized SIEM. Which of the following malicious activities would be MOST difficult to detect due to this logging gap?

Question 4Choose one

A SOC analyst receives an "Impossible Travel" alert from the organization's cloud identity provider. The alert indicates that a user successfully authenticated from New York, USA, and then successfully authenticated from Tokyo, Japan, only 45 minutes later. Which of the following is the MOST likely benign explanation for this alert?

Question 5Choose one

A multinational financial services company is redesigning its enterprise architecture. Historically, the company relied on a perimeter-based security model utilizing robust edge firewalls and a trusted internal flat network. Remote users accessed internal resources via a traditional IPSec VPN. Due to rapid cloud adoption and a highly distributed workforce, the company has experienced several incidents where compromised remote endpoints allowed attackers to move laterally across the internal network unhindered. Leadership has mandated a transition to a Zero Trust Architecture (ZTA). The new architecture must ensure that network location is no longer the primary determinant of trust. Access to corporate applications, whether hosted on-premises or in the cloud, must be dynamically verified for every request. Based on the scenario, which architectural implementation is MOST critical to achieving the core principles of the mandated Zero Trust strategy? graph TD User[Remote User] -->|Identity + Device Posture| Policy[Trust Broker / Policy Engine] Policy -->|Deny| Block[Block Access] Policy -->|Allow| App[Target Application] App -->|Micro-segmented| DB[(Database)]

Question 6Choose 2

A SOC team is investigating a potential lateral movement incident. The analyst needs to combine capabilities from both the SIEM and the EDR solution to build a complete timeline of the attacker's actions. Which TWO of the following tasks are BEST suited for the EDR tool rather than the SIEM? (Select TWO)

Question 7Choose one

While reviewing alerts, a junior analyst notices that a user's workstation has triggered multiple antivirus warnings for "Mimikatz" over the last 10 minutes. Which of the following is the MOST immediate risk to the organization based on this specific indicator?

Question 8Choose one

A security analyst is reviewing a packet capture (PCAP) file from a compromised workstation. The analyst observes a high volume of DNS TXT record queries directed to an external IP address that is not the organization's configured DNS server. The TXT responses contain long strings of base64-encoded text. What is the MOST likely explanation for this activity?

Question 9Choose one

During an incident investigation, an analyst discovers that an attacker gained access to multiple SaaS applications without needing the users' passwords. The attacker achieved this by forging an XML-based assertion, signing it with a stolen private key from the organization's Identity Provider (IdP), and presenting it to the Service Providers (SPs). Which identity protocol was abused in this attack?

Question 10Choose one

True or False: When utilizing Artificial Intelligence (AI) and Machine Learning (ML) models for threat hunting, "AI Hallucinations" refer to instances where the model confidently presents false or fabricated data as factual intelligence, which can lead analysts down incorrect investigative paths.

10 more free samples are waiting

Create a free account to unlock the whole CS0-004 sample bank, or get full access to all 150 practice questions in the simulator.

Create account