Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save75geek

CS0-004 CompTIA Cybersecurity Analyst CySA+ V4 (New Version) Questions and Answers

Questions 4

A security analyst runs an Nmap scan against a host with multiple open ports using the following command:

nmap 10.10.10.1 -p-

The following output is obtained after the scan:

Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-15 15:55 UTC

Note: Host seems down.

Nmap done: 1 IP address (0 hosts up) scanned in 3.16 seconds

Which of the following is the most accurate way to scan the target IP for open ports?

Options:

A.

nmap 10.10.10.1 -p80, 443, 445, 9999, 135, 22, 21 -b --traceroute

B.

nmap -sn -p- 10.10.10.1

C.

nmap -p- -Pn 10.10.10.1

D.

nmap 10.10.10.1/24 -p- -R -O --script=ssl-enum-ciphers

Buy Now
Questions 5

An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts.

INSTRUCTIONS

Click on each workstation and server to review outputs and a log file.

Identify the compromised host and executable, and determine an appropriate remediation for the issue.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Options:

Buy Now
Questions 6

An analyst performs Nmap scans to determine which hosts may need to be targeted to deploy a critical Windows patch. The patch for the vulnerability is to address a critical security flaw that targets open Server Message Block (SMB) ports on Windows systems only.

The analyst scans with the following command:

$sudo nmap -Pn 10.203.10.0/24

The analyst then receives the following output:

Which of the following hosts should the analyst prioritize for patching?

Options:

A.

10.203.10.11

B.

10.203.10.12

C.

10.203.10.13

D.

10.203.10.16

Buy Now
Questions 7

Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?

Options:

A.

Usage policies

B.

Prompt engineering

C.

Non-disclosure agreement

D.

Incident response policy

Buy Now
Questions 8

Which of the following is the most important component to include in the preparation phase of an incident response plan?

Options:

A.

Roles and responsibilities

B.

After action reports

C.

Data integrity validation

D.

Chain of custody

Buy Now
Questions 9

An analyst must provide a visualization of data received from threat intelligence sources. The data includes the Internet Protocols, services, and tools used by threat actors.

Which of the following is the best framework for the analyst to follow to display this data?

Options:

A.

Diamond Model of Intrusion Analysis

B.

Exploit Prediction Scoring System

C.

Cyber Kill Chain

D.

MITRE Adversarial Tactics, Techniques, and Common Knowledge and Detection, Denial, and Disruption Framework Empowering Network Defense

Buy Now
Questions 10

A vulnerability scanner shows discrepancies between the number of Internet Protocol (IP) addresses across the sites being scanned and the number of systems reporting into the patching system.

Which of the following actions will resolve this issue?

Options:

A.

Enable verbose logging in the scanner and check for failures.

B.

Rebuild the vulnerability report selection criteria to account for all sites.

C.

Request the infrastructure team rerun patching deployments.

D.

Conduct a comprehensive asset inventory with the infrastructure team.

Buy Now
Questions 11

Which of the following actions should an incident response analyst take during the recovery phase of the incident response process?

Options:

A.

Verify that malicious activity has occurred.

B.

Reimage the disk.

C.

Take the system offline.

D.

Write the final report.

Buy Now
Questions 12

An analyst uses an AI platform to help correlate events. The AI output contains events that did not happen. This results in inaccurate correlations.

Which of the following best describes what has occurred?

Options:

A.

Hallucinations

B.

Data exposure

C.

Malicious prompts

D.

Model poisoning

Buy Now
Questions 13

Based on recent alerts, a security analyst thinks a web application server was compromised. The analyst reviews the following server output:

Which of the following best describes what has occurred?

Options:

A.

An initiated unauthorized session

B.

Too many users logged in at the same time

C.

High resource consumption

D.

Abnormal idle times for each user

Buy Now
Questions 14

An incident response team investigates a possible data leak. Various IT systems collect evidence.

Which of the following processes is required to ensure that evidentiary artifacts are properly recorded?

Options:

A.

Packaging and labeling

B.

Chain of custody

C.

Post incident reporting

D.

Storage and containment

Buy Now
Questions 15

A vulnerability analyst must perform a security assessment on an edge device running various services.

The analyst runs an Nmap port scan and sees the following output:

Which of the following should the analyst do next to validate the discovered remote access service is secure?

Options:

A.

Verify that the web server certificate is added to certificate store.

B.

Verify that the Border Gateway Protocol (BGP) route has been published.

C.

Verify that the virtual private network (VPN) service is utilizing Main Mode.

D.

Verify that the web server can be pinged.

Buy Now
Questions 16

An analyst is configuring a security information and event management system to capture fileless malware execution events.

Which of the following log files requires additional configuration to accomplish this task?

Options:

A.

Microsoft-Windows-Crypto-DPAPI/Operational

B.

Microsoft-Windows-PowerShell/Operational

C.

Microsoft-Windows-UserPnp/DeviceInstall

D.

Microsoft-Windows-TerminalServices-LocalSessionManager/Operational

Buy Now
Questions 17

A security architect works with a client on security operations center (SOC) capabilities. The security architect wants to ensure the log correlation and investigation activities are accurate across the infrastructure.

Which of the following is the best for the client to implement?

Options:

A.

Network Time Protocol (NTP)

B.

Zero Trust Network Access (ZTNA)

C.

Account federation

D.

Secure access service edge (SASE)

E.

Application programming interfaces (APIs)

Buy Now
Questions 18

Which of the following is the most comprehensive type of report associated with a closed incident?

Options:

A.

Lessons-learned

B.

Situation

C.

Root cause analysis

D.

After action

Buy Now
Questions 19

Which of the following is the most likely reason an organization might implement compensating controls?

Options:

A.

A vulnerability does not have a patch, and the system is mission critical.

B.

A vulnerability has been fixed, tested, and deployed to production.

C.

A vulnerability is being actively exploited in the wild, but the organization does not use the affected system.

D.

A vulnerability was detected, but the organization has determined the result is a false positive.

Buy Now
Questions 20

Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?

Options:

A.

Residual

B.

Acceptable

C.

Inherent

D.

Appropriate

Buy Now
Questions 21

Which of the following is the main concept behind the use of an attack methodology framework?

Options:

A.

Implementing continuous monitoring and rapid deployment of system fixes over the traditional patch, test, and deploy approach

B.

Prioritizing vulnerabilities that can be exploited based on risk calculations and using the consequences and likelihood of the exploits to determine where resources should be allocated

C.

Approaching cybersecurity from the perspective of a threat actor and using their common behaviors and motivations to identify secure solutions

D.

Applying a Zero Trust environment by assuming networks and systems are vulnerable to malicious actions by both external, hostile adversaries and insider threats

Buy Now
Questions 22

A security operations center analyst is using the command line to display specific traffic.

The analyst uses the following command:

$tshark -r file.pcap -Y "http or udp"

Which of the following will the command line display?

Options:

A.

Encrypted web requests and Domain Name System (DNS) traffic

B.

Unencrypted web requests and DNS traffic

C.

Neither encrypted nor unencrypted web and DNS traffic

D.

Both encrypted and unencrypted web and DNS traffic

Buy Now
Questions 23

A vulnerability analyst conducts a security assessment on the Remote Desktop Protocol (RDP) security posture within the environment.

The analyst issues the following command for the assessment: nmap -p 3389 --script rdp* 10.0.0.0/24 The analyst receives responses, which are divided into one of the two categories, from 13 out of the 254 hosts:

Which of the following conclusions can the analyst make about the output on Category 2?

Options:

A.

The systems are joined to an Active Directory domain and using New Technology LAN Manager (NTLM) as an authentication method.

B.

The systems are not joined to an Active Directory domain and are using Kerberos as an authentication method.

C.

The systems are not joined to an Active Directory domain and are using NTLM as an authentication method.

D.

The systems are joined to an Active Directory domain and are using Kerberos as an authentication method.

Buy Now
Questions 24

A security analyst reruns infrastructure as code (IaC) to tear down and rebuild a new environment after a ransomware attack.

Which of the following describes this phase?

Options:

A.

Analysis

B.

Post-incident

C.

Detection

D.

Containment

E.

Recovery

Buy Now
Exam Code: CS0-004
Exam Name: CompTIA Cybersecurity Analyst CySA+ V4 (New Version)
Last Update: Aug 22, 2026
Questions: 82
CS0-004 pdf

CS0-004 PDF

$21.25  $84.99
CS0-004 Engine

CS0-004 Testing Engine

$25  $99.99
CS0-004 PDF + Engine

CS0-004 PDF + Testing Engine

$33.75  $134.99