CompTIA CySA+ CS0-004 Certification Exam

CompTIA Cybersecurity Analyst (CySA+) CS0-004

The CompTIA CySA+ CS0-004 certification validates the skills security analysts use to detect, analyze and respond to threats through continuous security monitoring. The exam covers four domains: security operations, vulnerability management, incident response and management, and reporting and communication. Candidates analyze logs and exhibits from SIEM, EDR and packet-capture tools, correlate indicators of malicious activity, manage the vulnerability lifecycle and prioritize remediation, apply the incident response process, and communicate findings to technical and business stakeholders. It also introduces the use of AI and automation in security operations. The exam has a maximum of 85 questions over 165 minutes.

Certification Overview

  • Exam name: CySA+ CS0-004
  • Vendor: CompTIA
  • Exam code: CS0-004
  • Duration: 165 minutes
  • Total questions: 85
  • Passing score: 75%

Who Should Take This Exam?

Security Analyst, SOC Analyst, Threat Intelligence Analyst, Vulnerability Management Analyst, Incident Response Analyst, SOC Engineer, Threat Hunter

Prerequisites

No formal prerequisite. CompTIA recommends Network+ and Security+ or equivalent knowledge, plus about four years of hands-on cybersecurity experience.

Topics Covered

  • Security Operations
  • Vulnerability Management
  • Incident Response and Management
  • Reporting and Communication

Question Types

  • Multiple Choice (Single Answer)
  • Multiple Choice (Multiple Answers)
  • Drag and Drop
  • Scenario-Based

CySA+ CS0-004 Practice Questions

Our question bank contains 654+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.

Security Operations

Which Windows event log records authentication activity such as successful and failed logons?
  • Security
  • Setup
  • Application
  • System
Which principle is central to a zero trust architecture?
  • Grant broad access once a device passes initial authentication
  • Trust traffic that originates from inside the corporate LAN
  • Place all critical assets behind a single hardened perimeter firewall
  • Verify every access request explicitly, regardless of network location
Which network behavior is most characteristic of command-and-control beaconing?
  • Bursts of outbound HTTPS to a cloud storage provider during nightly backups
  • Small outbound connections to one external host at near-identical intervals
  • Large inbound transfers from a software vendor's update servers each month
  • Repeated internal DNS queries for the domain controller at user logon

Vulnerability Management

Which type of scan logs in to a target with valid credentials to inspect its configuration and installed software?
  • Non-credentialed scan
  • Passive scan
  • Credentialed scan
  • Discovery scan
Which tool is widely used for host discovery and port scanning?
  • Ettercap
  • Hydra
  • Nmap
  • Nikto
Which testing method analyzes application source code without executing the program?
  • Penetration testing
  • Static application security testing
  • Fuzz testing, which feeds malformed input to a running program to trigger crashes
  • Dynamic application security testing

Incident Response and Management

Which model describes seven stages of an intrusion, beginning with reconnaissance and ending with actions on objectives?
  • Diamond Model
  • STRIDE model
  • OWASP Top 10
  • Cyber Kill Chain
In the Cyber Kill Chain, which stage comes immediately after weaponization?
  • Exploitation
  • Command and control
  • Installation
  • Delivery
Which MITRE ATT&CK tactic covers an adversary keeping their foothold across restarts and credential changes?
  • Collection
  • Impact
  • Discovery
  • Persistence

Reporting and Communication

Which report gives executives a high-level view of security risk and trends?
  • Raw scanner export
  • Executive summary dashboard
  • Packet capture log
  • Firewall rule dump
Which details should a vulnerability report give remediation teams for each finding?
  • Only the total number of findings
  • Affected asset, severity and recommended fix
  • Only the CVE publication date
  • Only the scanner name and scan date
What is the main purpose of a vulnerability management dashboard?
  • Store the raw packet captures from every scan
  • Grant scanner access to new analysts
  • Show the current state and trends of vulnerabilities
  • Replace the vulnerability management policy

Frequently Asked Questions

How many questions are on the exam?

The CySA+ CS0-004 exam contains 85 questions.

What is the passing score?

You need 75% to pass.

How long is the exam?

You have 165 minutes to complete the exam.

More CompTIA Practice Exams

Practice with realistic mock exams to prepare for your CompTIA certification.