Defensive cybersecurity analyst certification covering security operations, vulnerability management, incident response, and reporting for the CompTIA CySA+ CS0-004 (V4) exam.
Exam domains and weighting
The CS0-004 blueprint is split across 4 domains. See the official exam guide for the authoritative breakdown.
Free sample questions
No account needed. Every question explains why every answer is right or wrong, just like the full bank.
lock_openFree sampleVulnerability Managementhard
Within the CVSS version 3.1 framework, what does the Environmental metric group allow an analyst to do that the Base metric group alone cannot?
- AAdjust the score to reflect the security requirements and modified characteristics of the analyst's own deployment.check_circle Correct
- BReflect the current maturity of available exploit code and the state of official remediation.
- CExpress the intrinsic severity of the flaw independent of any particular organisation or time.
- DPredict the probability that the vulnerability will be exploited in the wild within thirty days.
Distinguish the CVSS Environmental metric group as the mechanism for tailoring a base score to local asset context and security requirements. The Environmental group applies modified base metrics and confidentiality, integrity and availability requirement weightings so the final score represents risk to the specific environment rather than the flaw in the abstract.
Why A is correct: Correct: the Environmental group re-weights confidentiality, integrity and availability requirements and lets the analyst override base metrics to match how the asset is actually deployed.
Why B is wrong: Tempting because these do adjust a score over time, but exploit maturity and remediation level belong to the Temporal metric group, not the Environmental group.
Why C is wrong: This describes the purpose of the Base metric group itself, which is the fixed starting point the Environmental group is meant to tailor.
Why D is wrong: Exploitation probability is what EPSS estimates; CVSS environmental scoring measures contextual impact, not likelihood of attack over a time window.
lock_openFree sampleReporting and Communicationmedium
During a ransomware incident, your executive sponsor sends this email at 09:15: "Board call at 10:00. Give me the current business impact and what we are doing, in plain terms." You have technical findings but the eradication is still in progress. What should your update to the sponsor prioritise?
- AWhich services are down, the current containment status, and the expected next milestone in plain business languagecheck_circle Correct
- BA packet-level breakdown of the C2 beacon intervals and the malware's registry persistence keys
- CA request that the board approve purchasing a new EDR platform before the call begins
- DThe full indicator-of-compromise list so the board can forward it to peer organisations
Tailor incident communications to the audience: executives need business impact, status, and next steps in plain language, not raw technical artefacts. Stakeholder communication effectiveness depends on matching content to the audience's decisions. Executives make resourcing and disclosure calls, so they need impact, containment status, and milestones framed in business terms rather than low-level indicators they cannot use.
Why A is correct: An executive update should translate technical status into business impact and next steps, matching the audience and the decision they must support.
Why B is wrong: This is accurate technical detail, but a board-facing sponsor needs business impact and status, not indicators they cannot act on.
Why C is wrong: Procurement decisions belong in the lessons-learned phase, not a mid-incident status update, and pre-empting them derails the sponsor's immediate need.
Why D is wrong: Sharing raw IOCs with a board is the wrong audience and risks premature disclosure; the sponsor asked for impact and actions in plain terms.
lock_openFree sampleIncident Response and Managementmedium
During triage you review an EDR alert on a finance workstation: 'rundll32.exe loaded a signed but unusual DLL from C:\Users\Public, then spawned a connection to a known content delivery domain'. Your team maps every observation to MITRE ATT&CK. Which mapping BEST fits the rundll32 behaviour observed here?
- AInitial Access via T1566 Phishing, because the workstation belongs to a finance user who is a common phishing target
- BExfiltration via T1041 Exfiltration Over C2 Channel, because a network connection to an external domain was observed
- CDefense Evasion via T1218 System Binary Proxy Execution, because a trusted signed Windows binary is being abused to run the payloadcheck_circle Correct
- DPersistence via T1547 Boot or Logon Autostart Execution, because the DLL was loaded from a public writable folder
Map abuse of a trusted signed system binary to the correct ATT&CK technique rather than to an unproven adjacent tactic. System binary proxy execution abuses a signed, allowlisted OS binary such as rundll32 to run attacker code, which evades controls that trust the parent process; the observed load-and-execute chain matches this technique rather than delivery, exfiltration, or persistence.
Why A is wrong: Tempting because finance users are phished often, but the evidence shows post-execution binary abuse, not a delivery vector, so mapping to phishing invents a tactic the artefact does not establish.
Why B is wrong: Tempting because an outbound connection is present, but a single connection to a CDN domain is not evidence that data left the host, so keying exfiltration overreads the artefact.
Why C is correct: Correct: rundll32 is a legitimate signed system binary abused to proxy execution of an attacker DLL, which is exactly the living-off-the-land pattern ATT&CK catalogues under T1218.
Why D is wrong: Tempting because a writable path suggests staging, but nothing shows a run key, service, or startup entry, so persistence is a technique the evidence does not support.
More free CS0-004 practice questions, every answer explainedFrequently asked questions
- How many questions are on the CompTIA CySA+ certification exam?
- The CompTIA CySA+ (CS0-004) exam has Maximum of 85 questions and runs for 165 minutes. The format is multiple choice and performance-based, at pearson vue testing center or online proctored.
- What score do I need to pass CompTIA CySA+ certification?
- The pass mark is 750 on a scale of 100 to 900. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the CompTIA CySA+ certification exam cost?
- The exam costs 439 USD to sit. Practising on Examworthy is free to start, and every answer is explained, right and wrong.
- Is there a CompTIA CySA+ certification practice exam?
- Yes. Examworthy's exam mode runs a timed CompTIA CySA+ certification practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand. Timed mocks are free with an account.
- How does Examworthy help me prepare for CompTIA CySA+ certification?
- Every practice question explains why the right answer is right and why each wrong one is wrong, mapped to the official blueprint domains. You learn the reasoning, not just the letter.
- Is Examworthy affiliated with CompTIA?
- No. Examworthy is not affiliated with or endorsed by CompTIA. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by CompTIA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CS0-004 and related marks belong to their respective owners.