CS0-004: CompTIA CySA+ V4 — Free Practice Questions
10 free sample questions from a bank of 470, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?
TTP provides useful insights on the hash values and internet protocol addresses attributed to an attacker.
TTP provides useful insights on an attacker's indicators of compromise.
TTP provides useful insights on the tools used by an attacker.
TTP provides useful insights on the strategy and behavior of an attacker.
Answer: D
2Which of the following is the best reason to heavily segment business-critical assets from within the network?
Legacy systems
Degraded functionality
Asset obfuscation
Proprietary server
Answer: A
3A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses. Which of the following is the best tool to accomplish this task?
CyberChef
Wireshark
Zeek
Open Cyber Threat Intelligence (OpenCTI)
Answer: A
4Which of the following best describes why operational technology (OT) devices use compensating controls?
Industrial control systems use significant network bandwidth.
Outage windows are usually scheduled.
Traditional IT security solutions may not be compatible.
OT devices are typically not encrypted.
Answer: C
5The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:
Which of the following is the best action to improve overall security operations efficiency?
Leverage a cloud security posture management tool to add asset context to alerts.
Analyze and tune the detections that are causing non-actionable alerts.
Implement playbooks for the junior analysts to use during investigations.
Perform internal incident training on the most common alerts from security information and event management (SIEM).
Answer: B
6A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed. Which of the following techniques should be used until a patch is available?
Sinkholing
Eradication techniques
Continuous monitoring
Evidence acquisition
Answer: C
7The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment. Which of the following concepts best describes this practice?
Secure access service edge
Next-generation firewall
Zero Trust
Privileged access management
Answer: C
8Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?
Usage policies
Prompt engineering
Non-disclosure agreement
Incident response policy
Answer: A
9A security operations center analyst is using the command line to display specific traffic. The analyst uses the following command:
$tshark -r file.pcap -Y "http or udp"
Which of the following will the command line display?
Encrypted web requests and Domain Name System (DNS) traffic
Unencrypted web requests and DNS traffic
Neither encrypted nor unencrypted web and DNS traffic
Both encrypted and unencrypted web and DNS traffic
Answer: B
10Which of the following network architectures would best implement a perimeter-less network topology?