Sign In
Home/CompTIA/CS0-004: CompTIA CySA+ V4/Free questions

CS0-004: CompTIA CySA+ V4 — Free Practice Questions

10 free sample questions from a bank of 470, with the correct answers and explanations. No signup required — start practising right now.

1Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?
  • TTP provides useful insights on the hash values and internet protocol addresses attributed to an attacker.
  • TTP provides useful insights on an attacker's indicators of compromise.
  • TTP provides useful insights on the tools used by an attacker.
  • TTP provides useful insights on the strategy and behavior of an attacker.
Answer: D
2Which of the following is the best reason to heavily segment business-critical assets from within the network?
  • Legacy systems
  • Degraded functionality
  • Asset obfuscation
  • Proprietary server
Answer: A
3A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses. Which of the following is the best tool to accomplish this task?
  • CyberChef
  • Wireshark
  • Zeek
  • Open Cyber Threat Intelligence (OpenCTI)
Answer: A
4Which of the following best describes why operational technology (OT) devices use compensating controls?
  • Industrial control systems use significant network bandwidth.
  • Outage windows are usually scheduled.
  • Traditional IT security solutions may not be compatible.
  • OT devices are typically not encrypted.
Answer: C
5The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month: Which of the following is the best action to improve overall security operations efficiency?
CS0-004: CompTIA CySA+ V4 question 5
  • Leverage a cloud security posture management tool to add asset context to alerts.
  • Analyze and tune the detections that are causing non-actionable alerts.
  • Implement playbooks for the junior analysts to use during investigations.
  • Perform internal incident training on the most common alerts from security information and event management (SIEM).
Answer: B
6A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed. Which of the following techniques should be used until a patch is available?
  • Sinkholing
  • Eradication techniques
  • Continuous monitoring
  • Evidence acquisition
Answer: C
7The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment. Which of the following concepts best describes this practice?
  • Secure access service edge
  • Next-generation firewall
  • Zero Trust
  • Privileged access management
Answer: C
8Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?
  • Usage policies
  • Prompt engineering
  • Non-disclosure agreement
  • Incident response policy
Answer: A
9A security operations center analyst is using the command line to display specific traffic. The analyst uses the following command: $tshark -r file.pcap -Y "http or udp" Which of the following will the command line display?
  • Encrypted web requests and Domain Name System (DNS) traffic
  • Unencrypted web requests and DNS traffic
  • Neither encrypted nor unencrypted web and DNS traffic
  • Both encrypted and unencrypted web and DNS traffic
Answer: B
10Which of the following network architectures would best implement a perimeter-less network topology?
  • Hybrid cloud networks
  • Secure access service edge
  • Cloud-native computing
  • Content delivery networks
Answer: B

Want the full bank of 470 questions for CS0-004: CompTIA CySA+ V4? See all practice exams.