CompTIA - Big Savings Alert – Don’t Miss This Deal - Ends In 1d 00h 00m 00s Coupon code: 26Y30OFF
  1. Home
  2. CompTIA
  3. CS0-004 Exam
  4. Free CS0-004 Questions

Free Practice Questions for CompTIA CS0-004 Exam

Pass4Future also provide interactive practice exam software for preparing CompTIA Cybersecurity Analyst CySA+ V4 (New Version) (CS0-004) Exam effectively. You are welcome to explore sample free CompTIA CS0-004 Exam questions below and also try CompTIA CS0-004 Exam practice test software.

Page:    1 / 14   
Total 82 questions

Question 1

Despite removing malware from some of the affected hosts, several of an organization's internal resources are still unavailable two weeks after the discovery of a major incident.

Which of the following best describes this phase?



Answer : A

The organization remains in the eradication phase because malicious artifacts are still being removed from affected systems and the environment has not yet reached a trusted state suitable for complete restoration. The phrase ''removing malware from some of the affected hosts'' indicates that responders are actively eliminating the threat across the compromised estate rather than merely observing or documenting it.

Eradication addresses malware, attacker persistence, exploited vulnerabilities, unauthorized accounts, malicious configurations, compromised credentials, and other mechanisms that could permit reinfection or renewed access. Only after responders have sufficiently eliminated those causes should affected resources progress fully into recovery and return to normal operation. NIST's current incident-response model identifies containment, eradication, and recovery as related but distinct activities and emphasizes restoring assets only after appropriate incident handling has occurred.

Detection would have occurred when the incident was initially discovered. Analysis determines scope, cause, and impact. Preparation takes place before incidents by establishing plans, tools, procedures, and capabilities. Post-incident activities occur after response and restoration and focus on organizational improvement.

The two-week duration does not determine the phase. The activity being performed does: continued removal of malware indicates eradication.

Study Guide Reference: Incident Response and Management Containment Eradication Malware Removal Persistence Removal System Validation Recovery.


Question 2

Which of the following is the most comprehensive type of report associated with a closed incident?



Answer : D

An after-action report (AAR) is the most comprehensive document associated with a closed incident because it consolidates the incident itself, the response activities performed, recovery actions, outcomes, deficiencies, and lessons identified during the event. NIST Cybersecurity Framework guidance specifically calls for preparing an after-action report that documents the incident, response and recovery activities, and lessons learned.

A lessons-learned document focuses primarily on what worked, what failed, and what should be improved. Those observations are important, but they represent only one component of a complete post-incident record. Root cause analysis has a narrower technical purpose: determining the fundamental condition that permitted the incident to occur or progress. A situation report is generally produced while an incident is ongoing to communicate current status, impact, actions, and outstanding issues.

An AAR is broader because it can incorporate the timeline, technical findings, containment and eradication actions, recovery results, stakeholder performance, root cause, lessons learned, and assigned corrective actions. NIST exercise guidance likewise treats lessons learned as information that becomes part of an after-action report.

Study Guide Reference: Reporting and Communication Post-Incident Reporting After-Action Reports Lessons Learned Root Cause Analysis Corrective Actions.


Question 3

Which of the following occurs during the analysis phase of the incident response process?



Answer : A

Triage occurs during the analysis phase because responders must determine what an alert represents, how serious it is, which assets are affected, and what response priority should be assigned before taking broader containment or recovery actions.

Triage typically involves validating the alert, gathering supporting telemetry, establishing whether the event is a true positive, determining scope and impact, identifying affected identities or systems, correlating indicators, and assigning severity. The outcome provides the evidence required to decide whether an event should be escalated into formal incident handling and what subsequent actions are justified. NIST incident-handling guidance has historically emphasized analyzing incident-related information in order to determine the appropriate response, while the current NIST framework continues to emphasize efficient incident detection, response, and recovery.

Isolation belongs to containment because it restricts the compromised asset's ability to communicate or spread malicious activity. Reimaging normally occurs during recovery after the environment has been contained and malicious persistence addressed. Alert writing is part of detection engineering or security-monitoring operations rather than a defining incident-analysis activity.

The sequence is therefore important: detect analyze/triage contain eradicate recover conduct post-incident activities.

Study Guide Reference: Incident Response and Management Incident Response Process Detection Analysis/Triage Containment Eradication Recovery.


Question 4

Which of the following is commonly used after an incident has been resolved to identify efficiencies and corrective actions related to activities performed during the incident response process?



Answer : A

A lessons learned review evaluates how the incident was handled and identifies improvements that should be incorporated into future response activities. It examines what worked well, what created delays, where communications or escalation failed, whether tools and playbooks were effective, and which corrective actions should be assigned to reduce the likelihood or impact of similar incidents.

NIST's current incident-response guidance places strong emphasis on continuous improvement. It states that lessons identified during incident-response activities should feed into organizational improvement so policies, processes, practices, and security capabilities can be adjusted as necessary. NIST also notes that traditional post-incident activities identify required improvements and return them to preparation and broader cybersecurity risk management.

KPIs quantify operational performance but do not themselves provide the qualitative review necessary to identify process efficiencies and corrective actions. An executive summary communicates major incident facts and outcomes to leadership. Root cause analysis focuses on identifying the fundamental technical or organizational cause of the incident; it can contribute to lessons learned but is narrower in scope.

Therefore, the broader mechanism for reviewing the entire response process and developing improvement actions is the lessons-learned process.

Study Guide Reference: Reporting and Communication Post-Incident Reporting Lessons Learned Corrective Actions Process Improvement Stakeholder Feedback.


Question 5

An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors.

Which of the following is the best framework for the analyst to follow to display this data?



Answer : A

The Diamond Model of Intrusion Analysis is specifically suited to visually representing relationships between a threat actor, the infrastructure used during an intrusion, the actor's capabilities, and the victim. Its four principal vertices are adversary, infrastructure, capability, and victim. IP addresses and network services naturally map to infrastructure, while malware and attack tools map to capability.

The original Diamond Model describes an intrusion event through these four interconnected features and uses their relationships to support documentation, correlation, and analysis of malicious activity. This makes it particularly useful when the analyst wants to visualize intelligence rather than simply place activity into chronological stages.

EPSS predicts the probability that a vulnerability will be exploited and therefore does not model threat-actor infrastructure. The Cyber Kill Chain represents progressive stages of an intrusion, making it useful for understanding attack progression but less suitable for relational visualization. MITRE ATT&CK provides detailed behavioral information on adversary tactics and techniques; MITRE itself notes that ATT&CK and the Diamond Model are complementary, with the Diamond Model particularly useful for clustering and relating intrusion information.

Study Guide Reference: Security Operations Threat Intelligence Diamond Model Adversary Infrastructure Capability Victim Threat Visualization.


Page:    1 / 14   
Total 82 questions