Free CompTIA CS0-004 Practice Test Questions and Answers (2026)
Last Update Check
Q: 1
A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the
10.213.4.27 file server.
This file server is under investigation due to concerns about potential data exfiltration using Domain Name
System (DNS) traffic.
Which of the following commands should the analyst use to extract any potentially leaked data from the
suspicious.pcap file?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which of the following allows an organization to leverage AI in various forms while protecting business
objectives and data?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
An incident response team identifies a malicious uniform resource locator (URL) associated with a required
business process and performs the following activities:
* Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security
Group rules.
* Additional monitoring has been enabled for traffic related to that site and the allowed users.
* All application servers that need to access that site have been patched with the latest security and
software updates.
* Application owners have been notified of the severity and need to remediate this reported issue.
Which of the following best describes the overall mitigation the security team is performing?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
A vulnerability analyst runs a credentialed vulnerability scan covering all addressable enterprise assets. After
running the scan, the analyst discovers a large number of critical vulnerabilities that cannot be immediately
remediated.
Which of the following are the most likely reasons why the vulnerabilities cannot be immediately addressed?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
An analyst receives the following output:
Which of the following is the correct number of discovered systems that are allowing unencrypted traffic?
Which of the following is the correct number of discovered systems that are allowing unencrypted traffic?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
FILL IN THE BLANK
Your vulnerability management team completes a network scan and identifies 450 vulnerabilities across
various systems. Using the CVSS v3.1 scoring system, you find that 12 vulnerabilities have a base score of
9.8, 45 have scores between 7.0 and 8.9, and 393 have scores below 7.0. However, two of the critical-
scoring vulnerabilities (9.8) exist only on a non-internet-facing internal development system that has no
access to sensitive data or production systems.
According to risk-based vulnerability prioritization principles, which CVSS severity category should these two
low-contextual-risk vulnerabilities be treated as for remediation purposes?
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The
proxy server is supposed to handle all web page requests from all internal hosts.
INSTRUCTIONS
Click on each workstation and server to review outputs and a log file.
Identify the compromised host and executable, and determine an appropriate remediation for the issue.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
QUESTION IMAGE:

QUESTION IMAGE:

Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
FILL IN THE BLANK
Your SOC has observed a spike in failed login attempts targeting privileged accounts, followed by successful
logins from unusual geographic locations and times. You correlate this with lateral movement detected via
EDR on several servers, and unusual data access patterns from those accounts in your cloud storage audit
logs. To frame your investigation using a structured attack methodology, you decide to map these indicators
to _____________, a widely adopted framework that organizes adversary tactics and techniques by kill
chain phase, enabling better threat intelligence sharing and detection engineering.
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A systems administrator is reviewing the output of a vulnerability scan.
INSTRUCTIONS -
Review the information in each tab.
Based on the organization's environment architecture and remediation standards, select the server to be
patched within 14 days and select the appropriate technique and mitigation.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
QUESTION IMAGE:

QUESTION IMAGE:

Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
FILL IN THE BLANK
Your incident response team has just contained a malware outbreak affecting multiple endpoints. During the
eradication phase, you need to ensure that forensic evidence is preserved while removing the threat. What is
the formal term for the sequence of handling and documenting evidence to maintain its integrity and legal
admissibility throughout the incident lifecycle?
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20