Examworthyexamworthy.com

CompTIA CySA+ (CS0-004) cheat sheet

CompTIA

Exam version V4Reviewed 2026-08-12

Free to share. Examworthy is not affiliated with or endorsed by CompTIA; CS0-004 and related marks belong to their respective owners.

At a glance

Maximum of 85
Questions
165 min
Time allowed
750 on a scale of 100 to 900
Pass mark
$439
Cost (USD)

Format: Multiple choice and performance-based, at Pearson VUE testing center or online proctored

Domain weight map

Heaviest first - spend your time here
Security Operations34% · 99 Q
Vulnerability Management26% · 81 Q
Incident Response and Management24% · 61 Q
Reporting and Communication16% · 48 Q

How this exam thinks

CS0-004 rewards what a defender does with the evidence in front of them, triage, interpret, prioritise, contain, report, not how to design the system or exploit it.

Spot the trap

Tempting wrong answers, and why they fail

Tempting but wrong

Is a classifier passing malware because of an unvalidated feed injecting mislabelled entries best described as model drift?

Why it fails

No. Both cause degraded accuracy over time, but drift is natural change in real data, not deliberate corruption of the training labels.

Security Operations

Tempting but wrong

Is EPSS a confirmed list of exploited flaws while CVSS predicts which will be exploited next?

Why it fails

No. A confirmed exploited-in-the-wild catalogue describes CISA KEV, not EPSS, and the CVSS base score makes no exploitation prediction at all.

Vulnerability Management

Tempting but wrong

A non-system process accessing LSASS confirms lateral movement is complete, because reading LSASS always yields usable credentials.

Why it fails

The event shows an access attempt, not a successful dump, decryption, or any subsequent remote logon. The absolute claim overreaches what one artefact can establish.

Incident Response and Management

Tempting but wrong

Is the root-cause narrative the chronological sequence of alerts and analyst actions taken during the response?

Why it fails

No. Timelines are central to reporting, but that describes the incident timeline; a sequence of events is not the same as the reason those events were possible.

Reporting and Communication

Tempting but wrong

Is corrupting a model's training feedback with mislabelled samples an example of model inversion?

Why it fails

No. Model inversion extracts private training data by querying a deployed model; it does not corrupt training data, so it does not explain a rising false-negative rate.

Security Operations

Tempting but wrong

Should the finding with the highest CVSS base score (10.0) automatically be the top priority?

Why it fails

No. That finding is an isolated lab workstation with negligible EPSS and no KEV entry, posing little practical risk, so base score alone must not drive the decision.

Vulnerability Management

Tempting but wrong

The four core features of a Diamond Model event are reconnaissance, weaponisation, delivery, and exploitation in a fixed sequence.

Why it fails

These are Cyber Kill Chain phases, which are ordered stages rather than the Diamond's vertices. The Diamond's features are adversary, capability, infrastructure, and victim.

Incident Response and Management

Tempting but wrong

Does MTTD measure how long until an incident is resolved while MTTR measures how long until it is first detected?

Why it fails

No. It uses the right vocabulary but reverses the two definitions; detection precedes response, not the other way around.

Reporting and Communication

Key terms

network segmentationzero trustcloud and hybrid architecturecontainerisation and virtualisationlogging and telemetry sourcesindicators of compromisenetwork vs host indicatorsbeaconing and C2true positive vs false positiveauthentication anomaliesSIEM correlationpacket capture and protocol analysisendpoint and log analysis toolssandboxing and detonationfile and hash reputationthreat intelligence sources

Exam-day rules

  • Read the last line of the question first. It tells you what the analyst is actually being asked to do, so you can read the scenario looking for the answer rather than memorising detail.
  • Choose the analyst's next action, not the architect's redesign or the pentester's exploit. Several options may be true; the exam wants the correct defensive move for the situation as written.
  • Check the incident response phase before you answer. Contain before eradicate, eradicate before recover; an action that is right in general is wrong if it is premature for the phase.
  • On prioritisation questions, look past the CVSS number to exploitability, active exploitation, asset criticality, and compensating controls. The highest score is not always the first fix.
  • Ask what the named data source can actually prove. If an option asks NetFlow to show content or email headers to prove intent, it is reaching beyond the source and is likely the distractor.

Revision schedule

  1. Day 1
    Confirm you are studying V4 and set a date
  2. Weeks 1-2
    Build the security operations foundation
  3. Weeks 2-3
    Master vulnerability prioritisation, not just scanning
  4. Weeks 3-4
    Lock the incident response lifecycle order
  5. Week 4
    Practise reporting and stakeholder communication

Practise CS0-004 free

Every question explains why the right answer is right and why each wrong one is rationale. No sign-up.

356 audited flashcards in this deck.

Practise CS0-004 free
Examworthy - CompTIA CySA+ (CS0-004) cheat sheet. Free to share.examworthy.com