This CySA+ mock exam is one timed shift: a mixed set weighted like the four CS0-004 domains, a clock set at the real exam's pace, and no verdicts until you close it. The set is shorter than the real exam, so the clock is shorter too; the briefing gives the exact length.
Exam code CS0-004
Tickets 55
Clock 107 min
01The shift beside the real exam
CS0-004 format and this mock, checked October 2026scroll →
Sit it in one go. Stopping to look things up turns a timed rehearsal back into practice, and the CySA+ practice test already does that with a verdict on every ticket.
Ticket 1 / 55
107:00
Shift briefing
55 tickets, 107 minutes on the clock. The clock starts when you press Start.
No verdicts during the shift. You can move between tickets and change a pick until you close it.
When the shift closes (by you or the clock) you get a score per area and every ticket opens with notes on each option.
How the tickets split by areascroll →
Area
Tickets
Architecture and logging
4
Indicators of malicious activity
5
Analysis tools
5
Threat intel and hunting
1
Automation and process
4
Scanning methods
3
Assessment tools
1
Prioritization and mitigation
7
Controls and risk
3
Attack frameworks
1
Incident response process
5
Response techniques
7
Vulnerability reporting
4
Incident communication
5
INC-001Architecture and logging
Events from three sources show timestamps differing by up to eight hours because of mixed time zones. Which normalization step prevents incorrect event ordering during correlation?
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: A
ACorrect: Converting every timestamp to UTC at ingestion puts all sources on one clock so events order correctly, and keeping the original time-zone field preserves the raw evidence.
BKeeping only the first-seen timestamp loses each event's real time, so the ordering stays wrong.
CRounding to the nearest hour destroys the fine-grained ordering that correlation depends on.
DConverting to one analyst's local time is fragile across analysts and daylight-saving changes, and it discards the original zone.
INC-002Architecture and logging
Which SIEM logging fields and controls allow retention of decrypted-flow indicators without storing sensitive plaintext?
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: C
AStoring the full decrypted payload keeps exactly the sensitive plaintext the question wants to avoid, even with role-based access.
BKeeping every metadata field in plaintext logs can still capture sensitive values such as full URLs, and it adds no protection.
CCorrect: The server name (SNI), the JA3 client fingerprint and the certificate fingerprint identify suspicious flows without payload content, and encryption at rest plus access audits protect what is stored.
DThese are the right fields, but without encryption or access auditing the stored indicators are left unprotected.
INC-003Architecture and logging
A security team plans to deploy EDR agents to 800 endpoints including domain controllers and sensitive file servers. Which onboarding and update procedure best minimizes the attack surface introduced by privileged agents?
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: D
AUSB installation does not scale to 800 endpoints, and daily full-privilege updates widen the attack surface instead of shrinking it.
BOne shared admin service account means a single stolen credential exposes every endpoint, including the domain controllers.
CGiving every installer domain admin rights hands out the most powerful credential in the environment during rollout.
DCorrect: Certificate-based enrollment proves each agent's identity, signed updates block tampered packages and least-privilege service accounts limit the damage if an agent is compromised.
INC-004Architecture and logging
Why is the SIEM failing to append geolocation threat intelligence to the ingested firewall log presented in the table below?
Exhibitscroll →
Log Format
Content
Raw Syslog
SRC=192.168.1.50 DST=203.0.113.5
Parsed JSON
{"Message": "SRC=192.168.1.50 DST=203.0.113.5"}
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: A
ACorrect: The parsed JSON leaves both IPs inside one Message string, so the SIEM has no source or destination IP field for the geolocation lookup to use.
BRisk scoring comes after enrichment, so a low score cannot explain missing geolocation data.
CEscalation routing decides who receives an alert; it does nothing to enrich the alert's fields.
DThe raw syslog line was ingested, as the Message field shows; the failure happened later, during parsing.
INC-005Indicators of malicious activity
A table of network flows lists timestamp, source IP, destination IP, protocol, packet length, and TCP flags. Which flow pattern most closely matches C2 beaconing?
Exhibitscroll →
Timestamp
Src IP
Dst IP
Protocol
Length
Flags
10:00:00
192.168.1.10
203.0.113.5
TCP
64
SYN
10:01:02
192.168.1.10
203.0.113.5
TCP
64
SYN
10:02:01
192.168.1.10
203.0.113.5
TCP
64
SYN
10:03:05
192.168.1.10
203.0.113.5
TCP
128
PSH-ACK
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: B
AOnly one packet is larger with PSH-ACK flags; the regular pattern comes from the small, repeated SYN packets.
BCorrect: Small packets of the same size sent to the same destination about once a minute show the regular rhythm of automated beaconing.
CEvery flow goes to the same destination, 203.0.113.5, so random destinations do not fit the data.
DThe table shows small, one-way packets, while this option describes high-volume two-way bursts.
INC-006Indicators of malicious activity
Analyze the cloud authentication logs below. Which identity principal's activity most strongly indicates a compromised federated token or stolen credentials?
Exhibitscroll →
Event ID
Principal
Source IP
MFA
Action
Evt-01
service-automation-role
10.0.5.20
N/A
AssumeRole
Evt-02
user.jdoe@corp.example.com
192.168.1.15
Yes
ConsoleLogin
Evt-03
user.asmith@corp.example.com
203.0.113.88
No
GetSessionToken
Evt-04
app-deployment-role
172.16.0.50
N/A
UpdateFunction
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: B
Aapp-deployment-role updating a function from an internal IP, with MFA not applicable, is normal for a workload role.
BCorrect: user.asmith requested a session token from an external IP without MFA, which fits a stolen password or token being used from outside.
Cuser.jdoe signed in from an internal IP with MFA, which is the expected pattern.
Dservice-automation-role assuming a role from an internal address is routine machine activity.
INC-007Indicators of malicious activity
EDR shows file write spikes to encrypted archives, proxy logs indicate large outbound uploads to rare domains, and DNS exhibits TXT record anomalies. Has exfiltration occurred and what containment is recommended?
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: D
AThe signals do point to exfiltration, but briefing executives before you contain the hosts lets the data keep leaving while people talk.
BScheduled backups do not usually upload to rare domains or produce DNS TXT anomalies, so blaming backups ignores the evidence.
CThree separate data sources already agree, so waiting for more confirmation only gives the attacker more time to move data out.
DCorrect: archive staging on the endpoint, large uploads to rare domains and DNS TXT anomalies back each other up, so treat it as exfiltration, isolate the hosts and block the domains.
INC-008Indicators of malicious activity
A CASB alerts on an anomalous OAuth token grant to a third-party application. To verify if this represents a malicious integration, which investigative sequence should the analyst execute?
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: D
ARegistry and process analysis looks for malware on an endpoint, but a malicious OAuth app works in the cloud with no code on the device.
BOn-premises firewall logs do not see traffic between the third-party app and the SaaS provider.
CRevoking the token may come later, but the question asks how to verify the grant, and isolating the endpoint assumes malware with no evidence.
DCorrect: Matching the grant time against the SaaS provider's own audit logs for bulk data exports or permission changes shows whether the app is actually misusing its access.
INC-009Indicators of malicious activity
Review the following proxy log entries for a workstation. Which pattern most strongly indicates DGA-based C2 beaconing rather than legitimate SaaS traffic?
Exhibitscroll →
Domain
Requests
Timing
update.os-vendor.example
42
Irregular
x7k9p2q.example
38
Every 300s
y8m2r4t.example
37
Every 300s
z3n7s9v.example
39
Every 300s
mail.office-suite.example
55
Irregular
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: B
AThe readable vendor domains show irregular, human-driven timing, which is what legitimate SaaS traffic looks like.
BCorrect: Random-looking domains with the same naming pattern, each contacted every 300 seconds exactly, combine DGA-style names with automated beaconing.
CHeavy traffic to one well-known domain such as mail.office-suite.example is normal SaaS use.
DIrregular timing to popular domains looks like human browsing, the opposite of beaconing.
INC-010Analysis tools
A junior analyst attempts to quickly test a suspicious macro-enabled document by opening it within a corporate Virtual Desktop Infrastructure (VDI) environment. Why does this approach severely violate fundamental malware triage isolation principles?
No verdicts during the shift. Notes on every option open when you close it.
Key and notes on every option
Key: B
AMissing debugging tools would limit the analysis, but the real violation is that the payload runs next to production.
BCorrect: Corporate VDI is connected to the production network and shared resources, so opening the macro there could let malware spread; triage belongs in an isolated sandbox.
CNothing about VDI prevents the macro from reaching its C2 server, and that is part of the danger.
DHashing first is good practice, but skipping it does not break isolation the way running the file on a connected system does.
Shift tally
0 / 0
03After the shift closes
Read the area scores first
The lowest area is where your next study week goes. Each domain's areas are grouped in the study guide index.
Separate changed picks from first picks
A pick you switched and got wrong points to time pressure or doubt. A first pick that was wrong points to a gap in knowledge. They need different fixes.
Rebuild the week
Drop the weak areas into the CySA+ study plan; it packs areas by domain weight and closes on another mock.
Drill, then sit it again
Work the weak areas on their own pages until the notes stop surprising you, then run a fresh shift.
A strong tally is no forecastTrap
CompTIA does not publish how raw answers map onto the 750 cut on its 100–900 scale; see the CySA+ passing score. Use the shift to find weak areas and settle your pacing. What makes the real sitting demanding is covered in is the CySA+ exam hard.
04Testing online? Rehearse the room as well
A single display. Disconnect the second monitor before the shift, the way you will on the day.
Webcam, microphone and speaker working. Headphones are not allowed.
A clear desk and a clear room around you.
A government ID within reach for check-in.
The system test passed before you book, per Pearson VUE's OnVUE requirements page (checked October 2026); failing a requirement on the day cancels the exam and the fee is lost.
Keep the queue going on your phone
Our practice app carries CySA+ questions to your phone, on iPhone and Android.