Triage BoardGet the app

Practice queue · mixed areas

CySA+ practice test

This CySA+ practice test mixes tickets from all four CS0-004 domains and gives a verdict the moment you choose, with a note on why each option is right or wrong. Use the area chips to drill one part of the exam, or work the whole queue in order.

  • Exam code CS0-004
  • Tickets 45

The open queue

Answer, then read every note, including the ones on options you ruled out early: that is where a half-learned distinction shows up.

Ticket 1 / 45

0 right

INC-001Architecture and logging

Analysts observe events from devices in different timezones appearing out of chronological order after normalization. What corrective action restores accurate timelines?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AKeeping only device-local times is what put the events out of order in the first place, because local clocks in different zones cannot be compared directly.
  2. BConverting to the analyst's local zone is still one shared reference, but it breaks for analysts in other zones and around daylight-saving changes; UTC is the standard reference.
  3. CCorrect: correlate on a single UTC timeline so the order is right, and keep each device's original time zone so analysts can still read local times and the original evidence stays intact.
  4. DApplying daylight-saving offsets to every stored timestamp adds errors for devices and dates where DST does not apply and still leaves mixed zones.

INC-002Architecture and logging

SIEM metadata shows several encrypted flows. Which entry should be prioritized for decryption inspection?

Exhibit

Src IPJA3Cert FPSNIBytes
10.1.2.3Known benignTrustedapi.example.com1.2 MB
10.4.5.6Rare fingerprintSelf-signedupdate.bad-cdn.example4.8 MB
10.7.8.9CommonKnown CAcdn.vendor.example850 KB
10.0.1.1StandardWildcardmail.corp.example.com2.1 MB

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AA common JA3 fingerprint, a certificate from a known CA and a recognized vendor CDN all match normal traffic, so this flow is low priority.
  2. BA JA3 fingerprint already classed as benign with a trusted certificate is the least suspicious entry in the table.
  3. CMail to the company's own domain over a wildcard certificate is expected business traffic, and its size alone is not an indicator.
  4. DCorrect: a rare JA3 fingerprint plus a self-signed certificate and a suspicious SNI are the strongest malicious-TLS signals here, so this flow earns the costly decryption first.

INC-003Architecture and logging

Given the asset inventory, which telemetry source should receive highest collection priority for the public-facing database server?

Exhibit

assetroleexposurecriticality
Public DBCustomer data storeInternet-facingCritical
Internal AppBusiness logicInternal onlyHigh
Dev WorkstationDevelopmentIsolatedLow

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AThe asset is a database server, so cloud object storage access logs say nothing about how it would be attacked.
  2. BCorrect: an internet-facing critical data store needs authentication logs to catch credential abuse and EDR process telemetry to catch host compromise.
  3. CWorkstation EDR would watch the low-criticality dev workstation while the public database that needs priority stays uncovered.
  4. DApplication performance metrics track availability and speed; they record no security events such as logins or malicious processes.

INC-004Indicators of malicious activity

Review the DNS query log. Which host exhibits low-and-slow beaconing behavior?

Exhibit

TimestampHostQueryTTLResponse
10:00:01HostAupdate.example.com300NOERROR
10:01:01HostAupdate.example.com300NOERROR
10:02:01HostAupdate.example.com300NOERROR
10:00:05HostBcdn.legit.example60NOERROR
10:05:12HostBapi.legit.example60NOERROR

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AHostB queries two different domains at irregular times, which looks like ordinary client activity rather than a timed callback.
  2. BCorrect: HostA queries the same domain at exact 60-second intervals and ignores its own 300-second TTL cache, a regular cadence typical of beaconing.
  3. COnly HostA shows periodic timing; HostB has no fixed interval or repeated destination.
  4. DHostA's fixed interval to one domain is a clear beaconing pattern, so saying neither host is suspicious misses it.

INC-005Indicators of malicious activity

Analyze the cross-account assume-role events below. The Prod_Admin trust policy requires MFA for external accounts. Which event indicates an unauthorized bypass of the intended IAM trust relationship?

Exhibit

Event IDSource AccountActionTarget RoleMFA Present
Evt_1Dev_AcctAssumeRoleProd_AdminFalse
Evt_2Sec_AcctAssumeRoleAudit_ReadTrue
Evt_3Ops_AcctAssumeRoleNet_AdminTrue

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ANo database reader role appears in the log, and a trust policy is a configuration setting that cannot by itself show a bypass happened.
  2. BEvt_2 used MFA and targets a read-only audit role, which matches the intended trust relationship.
  3. CEvt_3 also presented MFA, so nothing in the log shows the trust policy being bypassed.
  4. DCorrect: Evt_1 shows an external account assuming Prod_Admin with no MFA, which violates the policy that requires MFA for external accounts.

INC-006Indicators of malicious activity

Examine the proxy logs below. Which observation most indicates covert data exfiltration using cookie manipulation?

Exhibit

TimeURICookieBytes Out
10:01:22/uploadsess=abc123;id=11240
10:04:19/syncsess=abc123;id=21180
10:07:31/uploadsess=abc123;id=31310
10:10:45/syncsess=abc123;id=41225

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AActivity confined to business hours is normal, and nothing in the log ties time of day to exfiltration.
  2. BRandom endpoints with widely varying sizes do not match the log, which shows two fixed URIs and similar byte counts.
  3. CThe log contains no user-agent field, and changing user agents point to scraping or evasion rather than cookie-based exfiltration.
  4. DCorrect: a fixed session value with a steadily incrementing ID and near-identical upload sizes suggests data is being sent out in sequenced chunks.

INC-007Indicators of malicious activity

Three authentication logs lack canonical host identifiers or timezones. Which entry most indicates lateral movement despite normalization gaps?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: an SSH login from an internal subnet never seen before, at 2 a.m., fits a host-to-host pivot and is suspicious even without canonical host fields.
  2. BAn Okta login through the corporate VPN in the morning is the normal remote-work pattern and shows no movement between internal hosts.
  3. CA login from the headquarters IP during business hours is the expected baseline for that user.
  4. DSSH from a known jump host during the day is the sanctioned administrative path, so it does not indicate lateral movement.

INC-008Analysis tools

An analyst reviews a network traffic capture generated during the dynamic detonation of a suspicious executable. Based on the provided sandbox network log, which entry represents the most likely indicator of a malicious command and control (C2) callback?

Exhibit

TimestampSource IPDestination IPPortDNS Query / Protocol
10:01:02192.168.1.10198.51.100.10443www.search-portal.example
10:01:05192.168.1.10198.51.100.2080connectcheck.os-vendor.example
10:01:15192.168.1.10198.51.100.30443code-hosting.example
10:01:22192.168.1.10203.0.113.778080update.local-srv.example

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AA public code-hosting site over 443 is a common, reputable destination and typical background traffic for a sandboxed machine.
  2. BA well-known search portal over 443 is ordinary browser or operating-system background traffic in a sandbox capture.
  3. CThe operating system's connectivity check over port 80 runs on every boot, so it is expected noise.
  4. DCorrect: an unfamiliar update host that belongs to no known vendor, on a nonstandard port (8080) and contacted right after detonation, is the classic profile of a C2 callback.

INC-009Analysis tools

An analyst receives an alert for a sudden spike in cross-region S3 bucket access originating from an internal cloud IP. Which action should the analyst take to triage this anomaly?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ABlocking the internal IP before checking for a legitimate cause can break production workflows, including replication itself.
  2. BTreating the spike as malicious without validation skips triage and risks declaring an incident over a false positive.
  3. CCorrect: confirming whether native cross-region replication explains the traffic rules out a common benign cause before escalating.
  4. DIsolating the buckets is a disruptive containment step; it belongs after confirmation, and triage still has to happen first.

INC-010Analysis tools

By comparing the SIEM alert timestamps with the approved change control schedule, which host alert most likely requires escalation?

Exhibit

HostTimestampAlert EventMaintenance Window
H-1102:15Service Stop02:00 to 04:00
H-101:45Config Edit03:00 to 05:00
H-1303:10Service Stop03:00 to 05:00
H-1402:50Config Edit02:00 to 04:00

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: H-1's configuration edit at 01:45 falls outside its approved 03:00–05:00 window, so it is unapproved and needs escalation.
  2. BH-11's service stop at 02:15 falls inside its 02:00–04:00 maintenance window, so it matches approved change.
  3. CH-13's service stop at 03:10 falls inside its 03:00–05:00 window, so it is expected.
  4. DH-14's configuration edit at 02:50 falls inside its 02:00–04:00 window, so it is expected.

Shift tally

0 / 0

Working the queue domain by domain

The chips follow the CS0-004 objectives, so every chip leads back to a page in the CySA+ study guide. Domain weights below are from the CS0-004 exam objectives (version 2.0, checked October 2026).

Security Operations, 34%

The widest domain: logging, indicators, tools, threat intelligence and automation. Tickets here hand you a symptom, such as a binary running from a user's temp folder or a sign-in from two countries within the hour, and ask what it means. The trap is answering with a tool when the stem wants a conclusion. Work indicators of malicious activity first, since it feeds the rest of the domain.

Vulnerability Management, 26%

Scan design, scanner output and fix order. When a ticket shows a finding list and asks what goes first, the highest base score is rarely the whole answer once exposure, asset value and active exploitation come in. Read prioritizing vulnerabilities before you drill this chip.

Incident Response and Management, 24%

Expect sequence: which step comes first, which action belongs to containment and which to eradication. CS0-004 lists seven steps from preparation to post-incident, and answering from the older four-phase NIST cycle costs points. The incident response process page sets out the order.

Reporting and Communication, 16%

The smallest domain, and easy to underprepare for that reason. Tickets ask who hears what and when, and they test metric names that differ by one word. The incident reporting and communication guide covers both.

Objective 1.6, AI in security operations, is new in CS0-004 and has no chip here; its drill is on the AI in security operations page.

Your tally is a raw countRule

The queue counts right answers. CS0-004 reports a scaled score with a pass mark of 750 on a 100–900 scale (CompTIA CS0-004 page, checked October 2026), and CompTIA publishes no conversion between the two. The CySA+ passing score page explains what the scale does and does not tell you.

Stem words that change the answer

BEST
More than one option would work. Pick the one that fixes the stated problem with the widest coverage or the fewest side effects.
FIRST or NEXT
A sequence ticket. Place the scenario in the response steps or the scanning workflow before you read the options.
MOST likely
Choose the explanation the evidence in the stem supports, even when a worse case is possible.
Exhibit
A table under the stem. It stands in for the tool output a performance-based question (PBQ) asks you to work through; see CySA+ performance-based questions.

Asked before the first ticket

Am I practicing on real CySA+ exam questions?

They are written against the CS0-004 objectives and are never recalled from a sitting. The CS0-004 objectives document warns that CompTIA can revoke the certification of candidates who use unauthorized brain-dump material (checked October 2026).

Which exam version am I practicing for?

Each ticket is tagged to a CS0-004 objective. Some began in a CS0-003-era bank and stayed only where the topic carries over; the version differences are on CS0-004 vs CS0-003.

How long will my real exam be?

CS0-004 runs 165 minutes and caps the count at 85, mixing multiple-choice and performance-based items (CompTIA CS0-004 page, checked October 2026). The format is broken down on how many questions are on the CySA+ exam.

When should I move on to the mock exam?

When the chips stop turning up surprises. The timed CySA+ mock exam holds every verdict until the end, which tests pacing as well as recall. Keep the CySA+ flashcards for the acronyms the stems assume you know.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.