Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: certbig75

CS0-004 Exam Dumps - CompTIA CySA+ Questions and Answers

Question # 4

An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)

Options:

A.

Host ws-57 is performing a network scan against dc-1.

B.

Domain Controller dc-1 is performing a network scan against ws-57.

C.

Host ws-57 delivered a phishing email via Simple Mail Transfer Protocol.

D.

Host ws-57 is communicating on a service using a non-standard port.

E.

Domain Controller dc-1 is infected with ransomware and initiating connections with ws-57.

F.

Domain Controller dc-1 is communicating using a non-standard port.

Buy Now
Question # 5

A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.

Which of the following is the best way to help mitigate the risk for this level of access?

Options:

A.

Enabling single sign-on for all administrators

B.

Integrating token-based authentication using a privileged access management (PAM) solution

C.

Using temporary, one-time passwords as part of the login process

D.

Configuring agentless scanning for critical targets

Buy Now
Question # 6

Which of the following is the main concept behind the use of an attack methodology framework?

Options:

A.

Implementing continuous monitoring and rapid deployment of system fixes over the traditional patch, test, and deploy approach

B.

Prioritizing vulnerabilities that can be exploited based on risk calculations and using the consequences and likelihood of the exploits to determine where resources should be allocated

C.

Approaching cybersecurity from the perspective of a threat actor and using their common behaviors and motivations to identify secure solutions

D.

Applying a Zero Trust environment by assuming networks and systems are vulnerable to malicious actions by both external, hostile adversaries and insider threats

Buy Now
Question # 7

An analyst executes the top command on a Linux system for an unresponsive application and observes the following output:

Which of the following is the most likely cause of this issue?

Options:

A.

Service disruption

B.

Unauthorized software

C.

Resource exhaustion

D.

Filesystem changes

Buy Now
Question # 8

Which of the following will inhibit remediation when attempting to resolve a vulnerability?

Options:

A.

Controlled systems

B.

Legacy systems

C.

Shared systems

D.

Closed systems

Buy Now
Question # 9

An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts.

INSTRUCTIONS

Click on each workstation and server to review outputs and a log file.

Identify the compromised host and executable, and determine an appropriate remediation for the issue.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Options:

Buy Now
Question # 10

An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only.

The analyst scans with the following command:

$sudo nmap -Pn 10.203.10.0/24

The analyst then receives the following output:

Which of the following hosts should the analyst prioritize for patching?

Options:

A.

10.203.10.11

B.

10.203.10.12

C.

10.203.10.13

D.

10.203.10.16

Buy Now
Question # 11

A vulnerability scanner shows discrepancies between the number of Internet Protocol (IP) addresses across the sites being scanned and the number of systems reporting into the patching system.

Which of the following actions will resolve this issue?

Options:

A.

Enable verbose logging in the scanner and check for failures.

B.

Rebuild the vulnerability report selection criteria to account for all sites.

C.

Request the infrastructure team rerun patching deployments.

D.

Conduct a comprehensive asset inventory with the infrastructure team.

Buy Now
Question # 12

The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:

Which of the following is the best action to improve overall security operations efficiency?

Options:

A.

Leverage a cloud security posture management tool to add asset context to alerts.

B.

Analyze and tune the detections that are causing non-actionable alerts.

C.

Implement playbooks for the junior analysts to use during investigations.

D.

Perform internal incident training on the most common alerts from security information and event management (SIEM).

Buy Now
Question # 13

Which of the following is the most important component to include in the preparation phase of an incident response plan?

Options:

A.

Roles and responsibilities

B.

After action reports

C.

Data integrity validation

D.

Chain of custody

Buy Now
Exam Code: CS0-004
Exam Name: CompTIA Cybersecurity Analyst CySA+ V4 (New Version)
Last Update: Aug 22, 2026
Questions: 82
CS0-004 pdf

CS0-004 PDF

$21.25  $84.99
CS0-004 Engine

CS0-004 Testing Engine

$23.75  $94.99
CS0-004 PDF + Engine

CS0-004 PDF + Testing Engine

$33.75  $134.99