Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A security analyst receives a notice about a possible data breach. The report identifies unapproved, current access dates for files found in the following personnel archives:

Which of the following actions should the analyst take first?
The analyst should first establish a legal hold because the suspected breach involves personnel records and evidence that may become relevant to regulatory, disciplinary, civil, or other legal proceedings. A legal hold prevents potentially relevant information from being deleted, overwritten, modified, rotated out under normal retention schedules, or otherwise destroyed before the organization's legal and investigative obligations are understood.
Preservation must precede destructive or potentially evidence-altering actions. NIST describes digital forensics as retrieving, storing, and analyzing electronic information while ensuring that evidence is captured reliably without alteration. RFC 3227 similarly emphasizes preserving evidence, following proper collection procedures, documenting handling, and maintaining chain of custody.
Log correlation and timeline construction are important investigative activities, but they should occur after preservation requirements have been established. Resetting credentials may subsequently be required for containment, but the scenario first raises an evidence-preservation obligation. Restoring files from backup would be especially premature because it could alter timestamps, overwrite artifacts, or otherwise complicate forensic analysis.
The examination principle is therefore preserve first when legal implications are reasonably foreseeable; analyze and remediate afterward under controlled procedures.
Study Guide Reference: Incident Response and Management Evidence Acquisition Legal Hold Evidence Preservation Chain of Custody Timeline Analysis Regulatory/Legal Considerations.
A security operations center analyst is using the command line to display specific traffic.
The analyst uses the following command:
$tshark -r file.pcap -Y "http or udp"
Which of the following will the command line display?
The -r file.pcap argument instructs TShark to read packets from the specified capture file, while -Y applies a Wireshark display filter. The expression 'http or udp' therefore displays packets recognized as HTTP or packets using UDP.
Traditional HTTP traffic is unencrypted and can be dissected directly as HTTP. HTTPS normally carries HTTP inside TLS encryption and therefore is not displayed merely because the filter specifies http. DNS commonly operates over UDP, particularly for standard queries and responses, so ordinary DNS traffic satisfies the udp portion of the expression. Consequently, B is the best answer in the context of the available choices.
A technical distinction is important: the expression does not mean ''HTTP or DNS specifically.'' The udp portion matches UDP traffic generally, which can include protocols other than DNS. Nevertheless, within the examination scenario, the intended comparison is plaintext HTTP versus encrypted HTTPS together with standard UDP-based DNS.
Wireshark's documentation distinguishes display filters from capture filters, and TShark is the command-line network traffic analyzer within the Wireshark suite. CS0-004 places packet-analysis capabilities within Security Operations.
Study Guide Reference: Security Operations Packet Analysis Wireshark/TShark PCAP Analysis Display Filters HTTP, UDP, and DNS.
The Chief Information Security Officer wants to improve internal security measures by continuously validating and verifying access to the production environment.
Which of the following concepts best describes this practice?
Zero Trust is based on the principle that access should not be implicitly trusted merely because a user, workload, or device has already entered the enterprise environment. Access decisions are continuously evaluated using identity, authentication state, device posture, authorization, contextual information, and resource sensitivity. The scenario's emphasis on continuously validating and verifying access therefore directly describes Zero Trust.
Traditional perimeter-oriented models tend to treat internal network position as a degree of trust. Zero Trust removes that assumption and requires explicit verification before granting access to protected resources. It also supports least privilege, granular authorization, segmentation, and ongoing assessment of sessions or identities.
Secure access service edge combines networking and security capabilities delivered through a distributed service architecture and can support Zero Trust implementations, but SASE itself is not the fundamental principle described. A next-generation firewall provides application-aware traffic inspection and policy enforcement but does not by itself establish continuous identity-centric verification. Privileged access management specifically controls elevated or administrative accounts; it is an important component of access security but addresses a narrower scope than Zero Trust.
The CS0-004 objectives explicitly identify Zero Trust Network Architecture, SASE, hybrid cloud, IAM, PAM, authentication, and authorization as Security Operations architecture concepts.
Study Guide Reference: Security Operations Network Architecture Zero Trust Network Architecture IAM Authentication and Authorization Least Privilege.
An analyst needs to perform a baseline security evaluation of the company's cloud infrastructure.
Which of the following tools is most appropriate for this task?
ScoutSuite is specifically designed for security posture assessment of cloud environments, making it the best tool for establishing a cloud-security baseline. NCC Group describes ScoutSuite as an open-source, multi-cloud security-auditing tool that uses cloud-provider APIs to collect configuration information and identify risk areas across cloud environments.
This capability is fundamentally different from conventional host or web vulnerability scanning. A cloud baseline requires evaluation of configurations such as identity permissions, storage exposure, network controls, encryption settings, logging, cloud-native security services, and resource policies. ScoutSuite queries the cloud control plane and produces an organized view of configuration weaknesses that can be compared with security expectations.
OpenVAS is primarily a general-purpose vulnerability-assessment scanner for systems and network services. Nikto concentrates on web-server weaknesses and dangerous configurations. Metasploit is primarily an exploitation and penetration-testing framework. Although each has legitimate assessment uses, none is as directly suited to broad cloud configuration posture assessment as ScoutSuite.
The critical examination distinction is cloud configuration auditing versus traditional vulnerability scanning or exploitation.
Study Guide Reference: Vulnerability Management Cloud Vulnerability Assessment Configuration Baselines ScoutSuite Cloud APIs Security Posture Assessment Misconfiguration Identification.
A cybersecurity analyst receives an unstructured text document that contains advanced persistent threat (APT)-related indicators of compromise (IoCs). The analyst needs to extract the IPv4 addresses.
Which of the following is the best tool to accomplish this task?
CyberChef is the most appropriate option because the task involves parsing and extracting structured indicators from unstructured text, rather than inspecting network traffic or managing a threat-intelligence repository. CyberChef provides operations for text manipulation, pattern matching, regular expressions, decoding, extraction, and transformation. An analyst can therefore feed the document into CyberChef and identify IPv4 address patterns without manually reviewing potentially thousands of characters.
Wireshark is primarily a packet-analysis platform. It would be appropriate if the analyst needed to inspect packets from a PCAP or live network capture, but the scenario provides a text document. Zeek is a network security monitoring and traffic-analysis framework that converts network activity into structured logs; it is similarly unnecessary for static textual extraction. OpenCTI is a threat-intelligence platform designed to organize, correlate, and manage intelligence objects and relationships. It could store the resulting IoCs after extraction, but it is not the most efficient tool for extracting IPv4 strings from raw text.
The official CS0-004 objectives identify CyberChef under decoding/parsing tools, while Wireshark and Zeek are classified under packet analysis and OpenCTI under threat-intelligence platforms.
Study Guide Reference: Security Operations Tools for Malicious-Activity Analysis Decoding/Parsing CyberChef Pattern Recognition/Regular Expressions IoC Analysis.
Which of the following occurs during the analysis phase of the incident response process?
Triage occurs during the analysis phase because responders must determine what an alert represents, how serious it is, which assets are affected, and what response priority should be assigned before taking broader containment or recovery actions.
Triage typically involves validating the alert, gathering supporting telemetry, establishing whether the event is a true positive, determining scope and impact, identifying affected identities or systems, correlating indicators, and assigning severity. The outcome provides the evidence required to decide whether an event should be escalated into formal incident handling and what subsequent actions are justified. NIST incident-handling guidance has historically emphasized analyzing incident-related information in order to determine the appropriate response, while the current NIST framework continues to emphasize efficient incident detection, response, and recovery.
Isolation belongs to containment because it restricts the compromised asset's ability to communicate or spread malicious activity. Reimaging normally occurs during recovery after the environment has been contained and malicious persistence addressed. Alert writing is part of detection engineering or security-monitoring operations rather than a defining incident-analysis activity.
The sequence is therefore important: detect analyze/triage contain eradicate recover conduct post-incident activities.
Study Guide Reference: Incident Response and Management Incident Response Process Detection Analysis/Triage Containment Eradication Recovery.
Exam domains verified against: Official CompTIA CS0-004 exam guide, last checked October 2026.
Explain system and network architecture concepts that support secure environments, including security architecture components, identity concepts, and logging practices. Analyze indicators of potential malicious activity across networks, endpoints, cloud, and identity systems using tools like SIEM and EDR platforms.
Sample question from this domain above: Q3
Implement vulnerability scanning methods across systems, networks, and applications to identify security gaps. Prioritize and mitigate vulnerabilities using risk-based approaches, scoring systems, and business context to determine remediation order.
Outline the incident response process including preparation, detection, analysis, containment, eradication, and recovery phases. Implement triage, evidence handling, escalation, remediation, and root cause analysis to resolve security events.
Sample question from this domain above: Q2
Produce vulnerability management reports and dashboards that communicate findings to stakeholders and support escalation during security events. Document incidents, conduct post-incident reviews, and track metrics such as detection time, response time, and remediation effectiveness.
Common questions about the exam itself