CompTIA Cybersecurity Analyst (CySA+) V4 Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions CS0-002 122 Questions CS0-003 271 Questions.

Try Simulator

CS0-004 Sample Questions

  1. Question 1

    Q1

    A Security Operations Center (SOC) is evaluating a new Generative AI (GenAI) tool to automatically summarize incident tickets and propose remediation steps. The SOC manager is developing the governance framework for this implementation. Which of the following represents the MOST significant operational risk that must be addressed in the governance policy before deployment?

    Show answer & explanation

    Correct answer: C

    When utilizing public or cloud-based GenAI tools, the primary governance risk is data leakage. Submitting proprietary incident data, PII, or internal network architecture details to a public LLM can result in that sensitive data being absorbed into the model's training set and potentially exposed to unauthorized parties. The other options represent technical or workflow issues, but data privacy/leakage is the paramount governance risk.

    flowchart TD SOC[SOC Analyst] -->|Pastes alert data| AI[Public GenAI Tool] AI -->|Absorbs data| Model[(Training Model)] Model -.->|Potential Exposure| Ext[External Actors] style Model fill:#f9f,stroke:#333,stroke-width:2px
  2. Question 2

    Q2

    A senior threat hunter is developing a new methodology for the organization. Instead of waiting for alerts generated by known Indicators of Compromise (IoCs), the hunter decides to assume a breach has occurred and searches for anomalous PowerShell execution bypasses across the fleet. Which of the following BEST describes this approach?

    Show answer & explanation

    Correct answer: A

    Hypothesis-driven threat hunting is a proactive approach where the hunter creates a hypothesis (e.g., "An attacker is bypassing execution policies using PowerShell") based on threat intelligence or knowledge of adversary tactics, and then searches the environment for evidence of that specific behavior, assuming traditional defenses have failed. It relies on behavioral analysis rather than static IoC matching.

  3. Question 3

    Q3

    During a routine audit of log sources, a security architect notices that Windows Event ID 4769 (A Kerberos service ticket was requested) is not being forwarded to the centralized SIEM. Which of the following malicious activities would be MOST difficult to detect due to this logging gap?

    Show answer & explanation

    Correct answer: B

    Event ID 4769 is generated every time a Kerberos service ticket (TGS) is requested. In a Kerberoasting attack, an adversary requests TGS tickets for service accounts (which have SPNs) to extract them and crack the service account passwords offline. Without Event ID 4769, detecting the anomalous volume of TGS requests associated with Kerberoasting is highly difficult. Password spraying, LLMNR poisoning, and DCSync are detected via other event IDs or network traffic.

  4. Question 4

    Q4

    A SOC analyst receives an "Impossible Travel" alert from the organization's cloud identity provider. The alert indicates that a user successfully authenticated from New York, USA, and then successfully authenticated from Tokyo, Japan, only 45 minutes later. Which of the following is the MOST likely benign explanation for this alert?

    Show answer & explanation

    Correct answer: B

    Impossible travel alerts trigger when the physical distance between two authentication source IP addresses cannot be traversed in the time elapsed. A common benign cause (false positive) is a user connecting to a VPN routing traffic through an exit node in another country, making their IP appear to be in Tokyo while they are physically in New York.

  5. Question 5

    Q5

    A multinational financial services company is redesigning its enterprise architecture. Historically, the company relied on a perimeter-based security model utilizing robust edge firewalls and a trusted internal flat network. Remote users accessed internal resources via a traditional IPSec VPN.

    Due to rapid cloud adoption and a highly distributed workforce, the company has experienced several incidents where compromised remote endpoints allowed attackers to move laterally across the internal network unhindered. Leadership has mandated a transition to a Zero Trust Architecture (ZTA).

    The new architecture must ensure that network location is no longer the primary determinant of trust. Access to corporate applications, whether hosted on-premises or in the cloud, must be dynamically verified for every request.

    Based on the scenario, which architectural implementation is MOST critical to achieving the core principles of the mandated Zero Trust strategy?

    graph TD User[Remote User] -->|Identity + Device Posture| Policy[Trust Broker / Policy Engine] Policy -->|Deny| Block[Block Access] Policy -->|Allow| App[Target Application] App -->|Micro-segmented| DB[(Database)]
    Show answer & explanation

    Correct answer: B

    Zero Trust Architecture (ZTA) shifts the security perimeter from the network edge to identity and context. Deploying identity-aware proxies ensures that every access request is authenticated and authorized based on user identity and device posture, regardless of network location. Microsegmentation prevents lateral movement by isolating workloads. Upgrading firewalls or deploying NIDS still relies on network-centric boundaries, which contradicts the core mandate of ZTA.

  6. Question 6

    Q6Multiple answers

    A SOC team is investigating a potential lateral movement incident. The analyst needs to combine capabilities from both the SIEM and the EDR solution to build a complete timeline of the attacker's actions. Which TWO of the following tasks are BEST suited for the EDR tool rather than the SIEM? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    Endpoint Detection and Response (EDR) solutions are designed to monitor endpoint behavior at a deep level, including memory analysis, process trees, and registry modifications. Analyzing memory for DLL injection and isolating the endpoint from the network are core EDR capabilities. SIEMs are used for log aggregation and correlation across disparate systems (like firewalls and badge readers) and evaluating cloud identity logs.

  7. Question 7

    Q7

    While reviewing alerts, a junior analyst notices that a user's workstation has triggered multiple antivirus warnings for "Mimikatz" over the last 10 minutes. Which of the following is the MOST immediate risk to the organization based on this specific indicator?

    Show answer & explanation

    Correct answer: B

    Mimikatz is a well-known credential dumping tool used to extract plaintext passwords, hashes, PINs, and Kerberos tickets from memory (specifically the LSASS process in Windows). The immediate risk is credential theft, which facilitates privilege escalation and lateral movement. It is not used for DoS, ransomware encryption, or SQL injection.

  8. Question 8

    Q8

    A security analyst is reviewing a packet capture (PCAP) file from a compromised workstation. The analyst observes a high volume of DNS TXT record queries directed to an external IP address that is not the organization's configured DNS server. The TXT responses contain long strings of base64-encoded text. What is the MOST likely explanation for this activity?

    Show answer & explanation

    Correct answer: B

    DNS tunneling abuses the DNS protocol to bypass firewalls and proxy restrictions. Attackers often use TXT records because they allow for larger payloads of arbitrary text. The presence of base64-encoded strings in TXT responses from a non-standard external IP is a classic indicator of a Command and Control (C2) channel or data exfiltration via DNS tunneling.

    sequenceDiagram participant W as Compromised Workstation participant F as Firewall participant C as Attacker C2 (Rogue DNS) W->>F: DNS Query (TXT) encoded_data.evil.com F->>C: Forwards DNS Query (Port 53 allowed) C-->>F: DNS Response (TXT) Base64_C2_Command F-->>W: Delivers Command
  9. Question 9

    Q9

    During an incident investigation, an analyst discovers that an attacker gained access to multiple SaaS applications without needing the users' passwords. The attacker achieved this by forging an XML-based assertion, signing it with a stolen private key from the organization's Identity Provider (IdP), and presenting it to the Service Providers (SPs). Which identity protocol was abused in this attack?

    Show answer & explanation

    Correct answer: C

    Security Assertion Markup Language (SAML) 2.0 is an XML-based standard in which an Identity Provider (IdP) issues signed assertions that Service Providers (SPs) trust for web SSO. The attack described is a 'Golden SAML' attack: with the IdP's token-signing private key, the attacker forges valid signed XML assertions for any user and bypasses authentication entirely. OpenID Connect uses JSON-based JWT ID tokens, OAuth 2.0 is an authorization framework whose tokens are not XML assertions, and RADIUS is a network AAA protocol.

  10. Question 10

    Q10

    True or False: When utilizing Artificial Intelligence (AI) and Machine Learning (ML) models for threat hunting, "AI Hallucinations" refer to instances where the model confidently presents false or fabricated data as factual intelligence, which can lead analysts down incorrect investigative paths.

    Show answer & explanation

    Correct answer: A

    True. AI Hallucinations occur when a Generative AI model generates output that sounds plausible and confident but is entirely fabricated or factually incorrect. In security operations, this is a significant risk as it can result in false positives, misattribution of threats, or wasted time during incident response.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the CS0-004 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 543 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon