Free CompTIA CS0-004 Practice Test Questions and Answers (2026)

Last Update Check
View Mode
Q: 1
A security analyst uses a full pcap solution to extract all traffic from the last two days associated with the 10.213.4.27 file server. This file server is under investigation due to concerns about potential data exfiltration using Domain Name System (DNS) traffic. Which of the following commands should the analyst use to extract any potentially leaked data from the suspicious.pcap file?
Options
Q: 2
Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?
Options
Q: 3
An incident response team identifies a malicious uniform resource locator (URL) associated with a required business process and performs the following activities: * Access to the URL has been restricted only to the necessary users through firewall rules and Cloud Security Group rules. * Additional monitoring has been enabled for traffic related to that site and the allowed users. * All application servers that need to access that site have been patched with the latest security and software updates. * Application owners have been notified of the severity and need to remediate this reported issue. Which of the following best describes the overall mitigation the security team is performing?
Options
Q: 4
A vulnerability analyst runs a credentialed vulnerability scan covering all addressable enterprise assets. After running the scan, the analyst discovers a large number of critical vulnerabilities that cannot be immediately remediated. Which of the following are the most likely reasons why the vulnerabilities cannot be immediately addressed?
Options
Q: 5
An analyst receives the following output: Comptia CS0 004 question Which of the following is the correct number of discovered systems that are allowing unencrypted traffic?
Options
Q: 6
FILL IN THE BLANK Your vulnerability management team completes a network scan and identifies 450 vulnerabilities across various systems. Using the CVSS v3.1 scoring system, you find that 12 vulnerabilities have a base score of 9.8, 45 have scores between 7.0 and 8.9, and 393 have scores below 7.0. However, two of the critical- scoring vulnerabilities (9.8) exist only on a non-internet-facing internal development system that has no access to sensitive data or production systems. According to risk-based vulnerability prioritization principles, which CVSS severity category should these two low-contextual-risk vulnerabilities be treated as for remediation purposes?
Your Answer
Q: 7
An organization receives an indication that one of its hosts is part of a DDoS attack against a victim. The proxy server is supposed to handle all web page requests from all internal hosts. INSTRUCTIONS Click on each workstation and server to review outputs and a log file. Identify the compromised host and executable, and determine an appropriate remediation for the issue. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question QUESTION IMAGE: Comptia CS0 004 question
Your Answer
Q: 8
FILL IN THE BLANK Your SOC has observed a spike in failed login attempts targeting privileged accounts, followed by successful logins from unusual geographic locations and times. You correlate this with lateral movement detected via EDR on several servers, and unusual data access patterns from those accounts in your cloud storage audit logs. To frame your investigation using a structured attack methodology, you decide to map these indicators to _____________, a widely adopted framework that organizes adversary tactics and techniques by kill chain phase, enabling better threat intelligence sharing and detection engineering.
Your Answer
Q: 9
A systems administrator is reviewing the output of a vulnerability scan. INSTRUCTIONS - Review the information in each tab. Based on the organization's environment architecture and remediation standards, select the server to be patched within 14 days and select the appropriate technique and mitigation. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Comptia CS0 004 question Comptia CS0 004 question Comptia CS0 004 question QUESTION IMAGE: Comptia CS0 004 question
Your Answer
Q: 10
FILL IN THE BLANK Your incident response team has just contained a malware outbreak affecting multiple endpoints. During the eradication phase, you need to ensure that forensic evidence is preserved while removing the threat. What is the formal term for the sequence of handling and documenting evidence to maintain its integrity and legal admissibility throughout the incident lifecycle?
Your Answer
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top