CompTIA CySA+ (CS0-004) cheat sheet
CompTIA
Free to share. Examworthy is not affiliated with or endorsed by CompTIA; CS0-004 and related marks belong to their respective owners.
At a glance
Format: Multiple choice and performance-based, at Pearson VUE testing center or online proctored
Domain weight map
Heaviest first - spend your time hereHow this exam thinks
CS0-004 rewards what a defender does with the evidence in front of them, triage, interpret, prioritise, contain, report, not how to design the system or exploit it.
Spot the trap
Tempting wrong answers, and why they failTempting but wrong
Is a classifier passing malware because of an unvalidated feed injecting mislabelled entries best described as model drift?
Why it fails
No. Both cause degraded accuracy over time, but drift is natural change in real data, not deliberate corruption of the training labels.
Security Operations
Tempting but wrong
Is EPSS a confirmed list of exploited flaws while CVSS predicts which will be exploited next?
Why it fails
No. A confirmed exploited-in-the-wild catalogue describes CISA KEV, not EPSS, and the CVSS base score makes no exploitation prediction at all.
Vulnerability Management
Tempting but wrong
A non-system process accessing LSASS confirms lateral movement is complete, because reading LSASS always yields usable credentials.
Why it fails
The event shows an access attempt, not a successful dump, decryption, or any subsequent remote logon. The absolute claim overreaches what one artefact can establish.
Incident Response and Management
Tempting but wrong
Is the root-cause narrative the chronological sequence of alerts and analyst actions taken during the response?
Why it fails
No. Timelines are central to reporting, but that describes the incident timeline; a sequence of events is not the same as the reason those events were possible.
Reporting and Communication
Tempting but wrong
Is corrupting a model's training feedback with mislabelled samples an example of model inversion?
Why it fails
No. Model inversion extracts private training data by querying a deployed model; it does not corrupt training data, so it does not explain a rising false-negative rate.
Security Operations
Tempting but wrong
Should the finding with the highest CVSS base score (10.0) automatically be the top priority?
Why it fails
No. That finding is an isolated lab workstation with negligible EPSS and no KEV entry, posing little practical risk, so base score alone must not drive the decision.
Vulnerability Management
Tempting but wrong
The four core features of a Diamond Model event are reconnaissance, weaponisation, delivery, and exploitation in a fixed sequence.
Why it fails
These are Cyber Kill Chain phases, which are ordered stages rather than the Diamond's vertices. The Diamond's features are adversary, capability, infrastructure, and victim.
Incident Response and Management
Tempting but wrong
Does MTTD measure how long until an incident is resolved while MTTR measures how long until it is first detected?
Why it fails
No. It uses the right vocabulary but reverses the two definitions; detection precedes response, not the other way around.
Reporting and Communication
Key terms
Exam-day rules
- Read the last line of the question first. It tells you what the analyst is actually being asked to do, so you can read the scenario looking for the answer rather than memorising detail.
- Choose the analyst's next action, not the architect's redesign or the pentester's exploit. Several options may be true; the exam wants the correct defensive move for the situation as written.
- Check the incident response phase before you answer. Contain before eradicate, eradicate before recover; an action that is right in general is wrong if it is premature for the phase.
- On prioritisation questions, look past the CVSS number to exploitability, active exploitation, asset criticality, and compensating controls. The highest score is not always the first fix.
- Ask what the named data source can actually prove. If an option asks NetFlow to show content or email headers to prove intent, it is reaching beyond the source and is likely the distractor.
Revision schedule
- Day 1Confirm you are studying V4 and set a date
- Weeks 1-2Build the security operations foundation
- Weeks 2-3Master vulnerability prioritisation, not just scanning
- Weeks 3-4Lock the incident response lifecycle order
- Week 4Practise reporting and stakeholder communication