CompTIA CS0-004 Exam Prep
CompTIA CySA+ V4 (Page 3 )

Updated On: 22-Aug-2026

Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?

  1. TTP provides useful insights on the hash values and internet protocol addresses attributed to an attacker.
  2. TTP provides useful insights on an attacker's indicators of compromise.
  3. TTP provides useful insights on the tools used by an attacker.
  4. TTP provides useful insights on the strategy and behavior of an attacker.

Answer(s): D

Explanation:

TTPs describe how an adversary operates. These behavioral patterns are generally more durable and strategically useful for detection and defense than easily changed indicators such as IP addresses, hashes, or tools.



Which of the following is the best reason to heavily segment business-critical assets from within the network?

  1. Legacy systems
  2. Degraded functionality
  3. Asset obfuscation
  4. Proprietary server

Answer(s): A

Explanation:

Legacy systems may be unsupported or unable to receive security patches. Strong network segmentation limits their exposure and prevents attackers from easily reaching them through lateral movement.



A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses.
Which of the following is the best tool to accomplish this task?

  1. CyberChef
  2. Wireshark
  3. Zeek
  4. Open Cyber Threat Intelligence (OpenCTI)

Answer(s): A

Explanation:

CyberChef can parse unstructured text and extract IPv4 addresses using built-in extraction and regular-expression operations. Wireshark and Zeek analyze network traffic, while OpenCTI manages threat intelligence.



Which of the following best describes why operational technology (OT) devices use compensating controls?

  1. Industrial control systems use significant network bandwidth.
  2. Outage windows are usually scheduled.
  3. Traditional IT security solutions may not be compatible.
  4. OT devices are typically not encrypted.

Answer(s): C

Explanation:

OT systems often use specialized, legacy, or availability-sensitive equipment that cannot support conventional security tools or patches. Compensating controls provide alternative protection without disrupting operations.



The Chief Information Security Officer (CISO) reviews the following security operations metrics from the last month:

Which of the following is the best action to improve overall security operations efficiency?

  1. Leverage a cloud security posture management tool to add asset context to alerts.
  2. Analyze and tune the detections that are causing non-actionable alerts.
  3. Implement playbooks for the junior analysts to use during investigations.
    -D. Perform internal incident training on the most common alerts from security information and event management (SIEM).
    -

Answer(s): B

Explanation:

The large number of alerts and investigations compared with only five confirmed incidents indicates excessive non-actionable alerts. Tuning detection rules reduces false positives and unnecessary analyst workload.



A public threat intelligence report includes indicators of compromise (IoCs) for threat actors. The threat actors are exploiting a zero-day vulnerability that the vendor has not fixed.
Which of the following techniques should be used until a patch is available?

  1. Sinkholing
  2. Eradication techniques
  3. Continuous monitoring
  4. Evidence acquisition

Answer(s): C

Explanation:

Until a patch is available, the organization should continuously monitor systems and network activity for the reported IoCs to detect attempted or successful exploitation quickly.



The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment.
Which of the following concepts best describes this practice?

  1. Secure access service edge
  2. Next-generation firewall
  3. Zero Trust
  4. Privileged access management

Answer(s): C

Explanation:

Zero Trust follows the principle of “never trust, always verify,” continuously validating users, devices, and access requests rather than trusting them based on network location.



Which of the following allows an organization to leverage AI in various forms while protecting business objectives and data?

  1. Usage policies
  2. Prompt engineering
  3. Non-disclosure agreement
  4. Incident response policy

Answer(s): A

Explanation:

AI usage policies define approved tools, permitted data, acceptable use, and security requirements, enabling AI adoption while protecting organizational information and objectives.



Viewing page 3 of 12
Viewing questions 17 - 24 out of 83 questions


Post your Comments and Discuss CompTIA CS0-004 exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!