8 real CS0-004 flashcards, sampled from all 4 domains the exam tests, heaviest first. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.
The full deck has 356 flashcards, and a free account opens 40 of them across every domain. For a domain-by-domain breakdown and a study plan, read the CS0-004 study guide.
schoolConceptSecurity Operations
Why must an analyst validate a machine-learning detection flag against underlying evidence before treating it as an actionable finding?
arrow_downward
ML detections are probabilistic and can produce false positives, so a low-confidence flag with no corroborating signature must be confirmed against the raw telemetry before escalation or containment.
errorMisconceptionSecurity Operations
Is a classifier passing malware because of an unvalidated feed injecting mislabelled entries best described as model drift?
arrow_downward
No. Both cause degraded accuracy over time, but drift is natural change in real data, not deliberate corruption of the training labels.
schoolConceptVulnerability Management
What does the CVSS v3.1 Environmental metric group let an analyst do that the Base group cannot?
arrow_downward
It applies modified base metrics plus confidentiality, integrity and availability requirement weightings, so the final score represents risk to the specific deployment rather than the flaw in the abstract.
errorMisconceptionVulnerability Management
Is EPSS a confirmed list of exploited flaws while CVSS predicts which will be exploited next?
arrow_downward
No. A confirmed exploited-in-the-wild catalogue describes CISA KEV, not EPSS, and the CVSS base score makes no exploitation prediction at all.
schoolConceptIncident Response and Management
How do you correctly map the abuse of a trusted, signed system binary such as rundll32 to an ATT&CK technique?
arrow_downward
System binary proxy execution (T1218) abuses a signed, allowlisted OS binary such as rundll32 to run attacker code, which evades controls that trust the parent process. A load-and-execute chain from such a binary matches this technique rather than delivery, exfiltration, or persistence.
errorMisconceptionIncident Response and Management
A non-system process accessing LSASS confirms lateral movement is complete, because reading LSASS always yields usable credentials.
arrow_downward
The event shows an access attempt, not a successful dump, decryption, or any subsequent remote logon. The absolute claim overreaches what one artefact can establish.
schoolConceptReporting and Communication
What triggers the external regulatory notification clock after a confirmed data breach?
arrow_downward
The classification of the data exposed, not timeline metrics or infrastructure details. Cardholder data pulls the incident into PCI DSS and jurisdictional breach-notification regimes, each with its own reporting clock, so the data type governs the deadline rather than dwell time or destination.
errorMisconceptionReporting and Communication
Is the root-cause narrative the chronological sequence of alerts and analyst actions taken during the response?
arrow_downward
No. Timelines are central to reporting, but that describes the incident timeline; a sequence of events is not the same as the reason those events were possible.
Examworthy is not affiliated with or endorsed by CompTIA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CS0-004 and related marks belong to their respective owners.