Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free CompTIA Cybersecurity Analyst CySA+ V4 (New Version) Practice Questions

Exams4sure Dumps

Exam style questions across every CS0-004 domain

Last Update 2 days ago
Total Questions : 82

Start with our free CS0-004 practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real CompTIA CySA+ exam. Each CS0-004 exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your CompTIA weak domains, see where you're losing marks, and build a focused study plan in minutes.

CS0-004 PDF

CS0-004 PDF (Printable)
$54.25
$154.99

CS0-004 Testing Engine

CS0-004 PDF (Printable)
$59.5
$169.99

CS0-004 PDF + Testing Engine

CS0-004 PDF (Printable)
$74.55
$212.99
Question # 11

A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Question # 11

Which of the following actions should the analyst take first?

Options:

A.  

Perform log correlation.

B.  

Reset user credentials.

C.  

Restore files from backup.

D.  

Establish a timeline.

E.  

Establish a legal hold.

Discussion 0
Question # 12

A security analyst responds to an alert regarding identity and access management activity within the cloud environment. The attacker is currently trying to gain access from one isolated cloud subscription to another via a compromised user role.

Which of the following aspects of the MITRE ATT & CK framework is the attacker trying to perform?

Options:

A.  

Privilege escalation

B.  

Lateral movement

C.  

Persistence

D.  

Execution

E.  

Credential access

Discussion 0
Question # 13

A security analyst analyzes the output of a web application access log for a company based in the United States.

Given the following output:

Question # 13

Which of the following users should be investigated first?

Options:

A.  

jschott

B.  

dmann

C.  

mschultz

D.  

tlindy

Discussion 0
Question # 14

Which of the following best explains the purpose of the Pyramid of Pain in threat intelligence?

Options:

A.  

To show that changing to different types of indicators and behaviors is difficult for an adversary

B.  

To measure how much operational damage a threat actor can cause before detection occurs

C.  

To compare open-source intelligence (OSINT) with closed-source intelligence based on collection cost

D.  

To organize attack activity into categories such as spoofing, tampering, and repudiation

Discussion 0
Question # 15

A security analyst reruns infrastructure as code (IaC) to tear down and rebuild a new environment after a ransomware attack.

Which of the following describes this phase?

Options:

A.  

Analysis

B.  

Post-incident

C.  

Detection

D.  

Containment

E.  

Recovery

Discussion 0
Question # 16

Which of the following contains stakeholder contact information for incident response reporting?

Options:

A.  

The company organization chart

B.  

The communication plan

C.  

The last incident report

D.  

The standard operating procedures

Discussion 0
Question # 17

Which of the following network architectures would best implement a perimeter-less network topology?

Options:

A.  

Hybrid cloud networks

B.  

Secure access service edge

C.  

Cloud-native computing

D.  

Content delivery networks

Discussion 0
Question # 18

Which of the following phases of the incident response process will permanently remove an attacker’s access to corporate resources?

Options:

A.  

Eradication

B.  

Containment

C.  

Denial of service

D.  

Detection

Discussion 0
Question # 19

A security operations center analyst is using the command line to display specific traffic.

The analyst uses the following command:

$tshark -r file.pcap -Y "http or udp"

Which of the following will the command line display?

Options:

A.  

Encrypted web requests and Domain Name System (DNS) traffic

B.  

Unencrypted web requests and DNS traffic

C.  

Neither encrypted nor unencrypted web and DNS traffic

D.  

Both encrypted and unencrypted web and DNS traffic

Discussion 0
Question # 20

A new security operations center (SOC) manager joins a team that struggles to meet service-level agreements (SLAs). The alert backlog continues to increase daily.

Which of the following will the manager most likely need to do?

Options:

A.  

Automate escalation.

B.  

Improve the triage processes.

C.  

Upgrade threat intelligence.

D.  

Enhance the customer service response.

Discussion 0

Free Exams Sample Questions