Triage BoardGet the app

Timed mock shift

CySA+ mock exam: one timed shift

This CySA+ mock exam is one timed shift: a mixed set weighted like the four CS0-004 domains, a clock set at the real exam's pace, and no verdicts until you close it. The set is shorter than the real exam, so the clock is shorter too; the briefing gives the exact length.

  • Exam code CS0-004
  • Tickets 55
  • Clock 107 min

The shift beside the real exam

CS0-004 format and this mock, checked October 2026
PointCS0-004 examThis mock
LengthUp to 85A shorter set, see the briefing
Time165 minutesScaled to the same pace
Question typesMultiple choice and performance-basedMultiple choice, some with table exhibits
Domain mix34 / 26 / 24 / 16%Within a point or two of that split
ResultScaled score, 750 to pass on 100–900Raw tally per area, then notes

Exam figures from the CompTIA CS0-004 page and the CS0-004 exam objectives, checked October 2026. The full format is on how many questions are on the CySA+ exam.

Your timed shift

Sit it in one go. Stopping to look things up turns a timed rehearsal back into practice, and the CySA+ practice test already does that with a verdict on every ticket.

Ticket 1 / 55

107:00

Shift briefing

  • 55 tickets, 107 minutes on the clock. The clock starts when you press Start.
  • No verdicts during the shift. You can move between tickets and change a pick until you close it.
  • When the shift closes (by you or the clock) you get a score per area and every ticket opens with notes on each option.
How the tickets split by area
AreaTickets
Architecture and logging4
Indicators of malicious activity5
Analysis tools5
Threat intel and hunting1
Automation and process4
Scanning methods3
Assessment tools1
Prioritization and mitigation7
Controls and risk3
Attack frameworks1
Incident response process5
Response techniques7
Vulnerability reporting4
Incident communication5

INC-001Architecture and logging

Events from three sources show timestamps differing by up to eight hours because of mixed time zones. Which normalization step prevents incorrect event ordering during correlation?

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: A

  1. ACorrect: Converting every timestamp to UTC at ingestion puts all sources on one clock so events order correctly, and keeping the original time-zone field preserves the raw evidence.
  2. BKeeping only the first-seen timestamp loses each event's real time, so the ordering stays wrong.
  3. CRounding to the nearest hour destroys the fine-grained ordering that correlation depends on.
  4. DConverting to one analyst's local time is fragile across analysts and daylight-saving changes, and it discards the original zone.

INC-002Architecture and logging

Which SIEM logging fields and controls allow retention of decrypted-flow indicators without storing sensitive plaintext?

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: C

  1. AStoring the full decrypted payload keeps exactly the sensitive plaintext the question wants to avoid, even with role-based access.
  2. BKeeping every metadata field in plaintext logs can still capture sensitive values such as full URLs, and it adds no protection.
  3. CCorrect: The server name (SNI), the JA3 client fingerprint and the certificate fingerprint identify suspicious flows without payload content, and encryption at rest plus access audits protect what is stored.
  4. DThese are the right fields, but without encryption or access auditing the stored indicators are left unprotected.

INC-003Architecture and logging

A security team plans to deploy EDR agents to 800 endpoints including domain controllers and sensitive file servers. Which onboarding and update procedure best minimizes the attack surface introduced by privileged agents?

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: D

  1. AUSB installation does not scale to 800 endpoints, and daily full-privilege updates widen the attack surface instead of shrinking it.
  2. BOne shared admin service account means a single stolen credential exposes every endpoint, including the domain controllers.
  3. CGiving every installer domain admin rights hands out the most powerful credential in the environment during rollout.
  4. DCorrect: Certificate-based enrollment proves each agent's identity, signed updates block tampered packages and least-privilege service accounts limit the damage if an agent is compromised.

INC-004Architecture and logging

Why is the SIEM failing to append geolocation threat intelligence to the ingested firewall log presented in the table below?

Exhibit

Log FormatContent
Raw SyslogSRC=192.168.1.50 DST=203.0.113.5
Parsed JSON{"Message": "SRC=192.168.1.50 DST=203.0.113.5"}

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: A

  1. ACorrect: The parsed JSON leaves both IPs inside one Message string, so the SIEM has no source or destination IP field for the geolocation lookup to use.
  2. BRisk scoring comes after enrichment, so a low score cannot explain missing geolocation data.
  3. CEscalation routing decides who receives an alert; it does nothing to enrich the alert's fields.
  4. DThe raw syslog line was ingested, as the Message field shows; the failure happened later, during parsing.

INC-005Indicators of malicious activity

A table of network flows lists timestamp, source IP, destination IP, protocol, packet length, and TCP flags. Which flow pattern most closely matches C2 beaconing?

Exhibit

TimestampSrc IPDst IPProtocolLengthFlags
10:00:00192.168.1.10203.0.113.5TCP64SYN
10:01:02192.168.1.10203.0.113.5TCP64SYN
10:02:01192.168.1.10203.0.113.5TCP64SYN
10:03:05192.168.1.10203.0.113.5TCP128PSH-ACK

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: B

  1. AOnly one packet is larger with PSH-ACK flags; the regular pattern comes from the small, repeated SYN packets.
  2. BCorrect: Small packets of the same size sent to the same destination about once a minute show the regular rhythm of automated beaconing.
  3. CEvery flow goes to the same destination, 203.0.113.5, so random destinations do not fit the data.
  4. DThe table shows small, one-way packets, while this option describes high-volume two-way bursts.

INC-006Indicators of malicious activity

Analyze the cloud authentication logs below. Which identity principal's activity most strongly indicates a compromised federated token or stolen credentials?

Exhibit

Event IDPrincipalSource IPMFAAction
Evt-01service-automation-role10.0.5.20N/AAssumeRole
Evt-02user.jdoe@corp.example.com192.168.1.15YesConsoleLogin
Evt-03user.asmith@corp.example.com203.0.113.88NoGetSessionToken
Evt-04app-deployment-role172.16.0.50N/AUpdateFunction

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: B

  1. Aapp-deployment-role updating a function from an internal IP, with MFA not applicable, is normal for a workload role.
  2. BCorrect: user.asmith requested a session token from an external IP without MFA, which fits a stolen password or token being used from outside.
  3. Cuser.jdoe signed in from an internal IP with MFA, which is the expected pattern.
  4. Dservice-automation-role assuming a role from an internal address is routine machine activity.

INC-007Indicators of malicious activity

EDR shows file write spikes to encrypted archives, proxy logs indicate large outbound uploads to rare domains, and DNS exhibits TXT record anomalies. Has exfiltration occurred and what containment is recommended?

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: D

  1. AThe signals do point to exfiltration, but briefing executives before you contain the hosts lets the data keep leaving while people talk.
  2. BScheduled backups do not usually upload to rare domains or produce DNS TXT anomalies, so blaming backups ignores the evidence.
  3. CThree separate data sources already agree, so waiting for more confirmation only gives the attacker more time to move data out.
  4. DCorrect: archive staging on the endpoint, large uploads to rare domains and DNS TXT anomalies back each other up, so treat it as exfiltration, isolate the hosts and block the domains.

INC-008Indicators of malicious activity

A CASB alerts on an anomalous OAuth token grant to a third-party application. To verify if this represents a malicious integration, which investigative sequence should the analyst execute?

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: D

  1. ARegistry and process analysis looks for malware on an endpoint, but a malicious OAuth app works in the cloud with no code on the device.
  2. BOn-premises firewall logs do not see traffic between the third-party app and the SaaS provider.
  3. CRevoking the token may come later, but the question asks how to verify the grant, and isolating the endpoint assumes malware with no evidence.
  4. DCorrect: Matching the grant time against the SaaS provider's own audit logs for bulk data exports or permission changes shows whether the app is actually misusing its access.

INC-009Indicators of malicious activity

Review the following proxy log entries for a workstation. Which pattern most strongly indicates DGA-based C2 beaconing rather than legitimate SaaS traffic?

Exhibit

DomainRequestsTiming
update.os-vendor.example42Irregular
x7k9p2q.example38Every 300s
y8m2r4t.example37Every 300s
z3n7s9v.example39Every 300s
mail.office-suite.example55Irregular

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: B

  1. AThe readable vendor domains show irregular, human-driven timing, which is what legitimate SaaS traffic looks like.
  2. BCorrect: Random-looking domains with the same naming pattern, each contacted every 300 seconds exactly, combine DGA-style names with automated beaconing.
  3. CHeavy traffic to one well-known domain such as mail.office-suite.example is normal SaaS use.
  4. DIrregular timing to popular domains looks like human browsing, the opposite of beaconing.

INC-010Analysis tools

A junior analyst attempts to quickly test a suspicious macro-enabled document by opening it within a corporate Virtual Desktop Infrastructure (VDI) environment. Why does this approach severely violate fundamental malware triage isolation principles?

No verdicts during the shift. Notes on every option open when you close it.

Key and notes on every option

Key: B

  1. AMissing debugging tools would limit the analysis, but the real violation is that the payload runs next to production.
  2. BCorrect: Corporate VDI is connected to the production network and shared resources, so opening the macro there could let malware spread; triage belongs in an isolated sandbox.
  3. CNothing about VDI prevents the macro from reaching its C2 server, and that is part of the danger.
  4. DHashing first is good practice, but skipping it does not break isolation the way running the file on a connected system does.

Shift tally

0 / 0

After the shift closes

  1. Read the area scores first

    The lowest area is where your next study week goes. Each domain's areas are grouped in the study guide index.

  2. Separate changed picks from first picks

    A pick you switched and got wrong points to time pressure or doubt. A first pick that was wrong points to a gap in knowledge. They need different fixes.

  3. Rebuild the week

    Drop the weak areas into the CySA+ study plan; it packs areas by domain weight and closes on another mock.

  4. Drill, then sit it again

    Work the weak areas on their own pages until the notes stop surprising you, then run a fresh shift.

A strong tally is no forecastTrap

CompTIA does not publish how raw answers map onto the 750 cut on its 100–900 scale; see the CySA+ passing score. Use the shift to find weak areas and settle your pacing. What makes the real sitting demanding is covered in is the CySA+ exam hard.

Testing online? Rehearse the room as well

  • A single display. Disconnect the second monitor before the shift, the way you will on the day.
  • Webcam, microphone and speaker working. Headphones are not allowed.
  • A clear desk and a clear room around you.
  • A government ID within reach for check-in.
  • The system test passed before you book, per Pearson VUE's OnVUE requirements page (checked October 2026); failing a requirement on the day cancels the exam and the fee is lost.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.