Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

CompTIA Cybersecurity Analyst CySA+ V4 (New Version)

Last Update 8 hours ago Total Questions : 82

The CompTIA Cybersecurity Analyst CySA+ V4 (New Version) content is now fully updated, with all current exam questions added 8 hours ago. Deciding to include CS0-004 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CS0-004 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CS0-004 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any CompTIA Cybersecurity Analyst CySA+ V4 (New Version) practice test comfortably within the allotted time.

Question # 1

Which of the following network architectures would best implement a perimeter-less network topology?

A.

Hybrid cloud networks

B.

Secure access service edge

C.

Cloud-native computing

D.

Content delivery networks

Question # 2

An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts.

INSTRUCTIONS

Click on each workstation and server to review outputs and a log file.

Identify the compromised host and executable, and determine an appropriate remediation for the issue.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question # 3

Which of the following does a phishing campaign click rate measure?

A.

The effectiveness of an organization's email filters

B.

The false-positive rate of data leakage prevention behavior

C.

The employees' security awareness

D.

The speed of responding to a social engineering attack

Question # 4

The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:

Which of the following is the best action to improve overall security operations efficiency?

A.

Leverage a cloud security posture management tool to add asset context to alerts.

B.

Analyze and tune the detections that are causing non-actionable alerts.

C.

Implement playbooks for the junior analysts to use during investigations.

D.

Perform internal incident training on the most common alerts from security information and event management (SIEM).

Question # 5

Which of the following actions should an incident response analyst take during the recovery phase of the incident response process?

A.

Verify that malicious activity has occurred.

B.

Reimage the disk.

C.

Take the system offline.

D.

Write the final report.

Question # 6

A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?

A.

Perform log correlation.

B.

Reset user credentials.

C.

Restore files from backup.

D.

Establish a timeline.

E.

Establish a legal hold.

Question # 7

A security team deploys a new scanning solution that requires root, domain administrator, and local server administrator permissions on all systems.

Which of the following is the best way to help mitigate the risk for this level of access?

A.

Enabling single sign-on for all administrators

B.

Integrating token-based authentication using a privileged access management (PAM) solution

C.

Using temporary, one-time passwords as part of the login process

D.

Configuring agentless scanning for critical targets

Question # 8

Multiple users report unexpected mouse movements and terminal windows opening.

An analyst reviewing the network traffic logs observes the following:

Which of the following is the most likely reason for the reported symptoms?

A.

Activity is on an internally addressable network.

B.

A reverse tunnel is being used to send commands.

C.

Remote Desktop Protocol (RDP) is being used to remotely control the impacted computers.

D.

Virtual Network Computing is being used to connect to systems.

Question # 9

A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.

Which of the following techniques should be used until a patch is available?

A.

Sinkholing

B.

Eradication techniques

C.

Continuous monitoring

D.

Evidence acquisition

Question # 10

An analyst reviews the following log entries:

Which of the following conclusions should the analyst reach? (Choose two.)

A.

Host ws-57 is performing a network scan against dc-1.

B.

Domain Controller dc-1 is performing a network scan against ws-57.

C.

Host ws-57 delivered a phishing email via Simple Mail Transfer Protocol.

D.

Host ws-57 is communicating on a service using a non-standard port.

E.

Domain Controller dc-1 is infected with ransomware and initiating connections with ws-57.

F.

Domain Controller dc-1 is communicating using a non-standard port.

Go to page: