CS0-004 Exam Questions & Answers
CompTIA Cybersecurity Analyst CySA+ V4 (New Version) • CompTIA
100% money-back guarantee
Sample CS0-004 Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
A cybersecurity analyst is reviewing static application security testing scan results and notices a finding for hard-coded credentials.
Which of the following should the analyst recommend to the application team to resolve this concern?
The correct remediation is to integrate a secrets-management solution and remove credentials from application source code. Hard-coded passwords, API keys, access tokens, certificates, and similar secrets create serious exposure because anyone who obtains the source repository, package, build artifact, backup, or configuration may recover the credential.
OWASP specifically identifies hard-coded secrets in source code and configuration files as a secrets-management problem and recommends centralized controls for securely storing, retrieving, rotating, auditing, and managing secrets throughout their lifecycle.
A secrets-management platform allows applications to retrieve sensitive values securely during execution instead of embedding them directly in code. Proper implementation also supports rotation and revocation when credentials are exposed.
PAM primarily governs privileged human or service access and is not the most direct application-code remediation. Single sign-on reduces repeated user authentication but does not remove embedded application credentials. Obfuscation is inadequate because an application that needs an API key must ultimately be capable of recovering and using it; attackers can often reverse that transformation.
The correct secure-development principle is therefore separation of secrets from application code.
Study Guide Reference: Vulnerability Management SAST Hard-Coded Credentials Secrets Management API Keys Credential Rotation Secure Software Development.
Which of the following occurs during the analysis phase of the incident response process?
Triage occurs during the analysis phase because responders must determine what an alert represents, how serious it is, which assets are affected, and what response priority should be assigned before taking broader containment or recovery actions.
Triage typically involves validating the alert, gathering supporting telemetry, establishing whether the event is a true positive, determining scope and impact, identifying affected identities or systems, correlating indicators, and assigning severity. The outcome provides the evidence required to decide whether an event should be escalated into formal incident handling and what subsequent actions are justified. NIST incident-handling guidance has historically emphasized analyzing incident-related information in order to determine the appropriate response, while the current NIST framework continues to emphasize efficient incident detection, response, and recovery.
Isolation belongs to containment because it restricts the compromised asset's ability to communicate or spread malicious activity. Reimaging normally occurs during recovery after the environment has been contained and malicious persistence addressed. Alert writing is part of detection engineering or security-monitoring operations rather than a defining incident-analysis activity.
The sequence is therefore important: detect analyze/triage contain eradicate recover conduct post-incident activities.
Study Guide Reference: Incident Response and Management Incident Response Process Detection Analysis/Triage Containment Eradication Recovery.
Which of the following is the most likely reason an organization might implement compensating controls?
Compensating controls are appropriate when the preferred remediation cannot currently be implemented but the organization must still reduce exposure. A mission-critical system with an unpatched vulnerability for which no vendor patch exists is a classic example. The system cannot simply be removed from service because the business requires it, and conventional patching is unavailable.
The organization may therefore deploy alternative controls such as network segmentation, restrictive firewall rules, application allowlisting, disabling unnecessary services, enhanced monitoring, IPS signatures, access restrictions, or isolation of affected functionality. These measures do not eliminate the underlying defect; instead, they reduce the probability or impact of exploitation while a permanent solution is developed.
NIST's control framework is designed to allow security controls to be selected and tailored according to organizational mission requirements and risk, supporting the broader principle that organizations may apply appropriate alternative safeguards when operational constraints exist.
Option B requires no compensating control because remediation has already occurred. Option C describes a vulnerability that is not applicable to the organization's systems. Option D represents a false positive and therefore does not constitute an actual exposure requiring mitigation.
Study Guide Reference: Vulnerability Management Mitigation Compensating Controls Patch Availability Mission-Critical Systems Segmentation and Monitoring.
Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?
Residual risk is the risk that remains after security controls, safeguards, or mitigation measures have been implemented. No practical security program can eliminate every threat or vulnerability completely, so organizations evaluate the remaining exposure to determine whether additional treatment is required or whether management can formally accept it.
The distinction from inherent risk is particularly important. Inherent risk represents the level of exposure before controls are applied. For example, an internet-facing application containing sensitive information may have substantial inherent risk. After implementing strong authentication, patching, a web application firewall, monitoring, secure coding controls, and segmentation, its probability and impact of compromise may be reduced---but not eliminated. The remaining exposure is residual risk.
''Acceptable risk'' describes risk that falls within an organization's approved tolerance or appetite; residual risk may or may not be acceptable. If the remaining exposure still exceeds tolerance, further controls, avoidance, transfer, or other treatment may be necessary. ''Appropriate'' is not a formal risk category in this context.
Risk management therefore follows a continuous cycle of identifying inherent exposure, applying controls, measuring the remaining residual exposure, and comparing that level with organizational risk tolerance.
Study Guide Reference: Vulnerability Management Risk Analysis Inherent Risk Mitigating Controls Residual Risk Risk Acceptance Risk Appetite and Tolerance.
Your incident response team has just contained a malware outbreak affecting multiple endpoints. During the eradication phase, you need to ensure that forensic evidence is preserved while removing the threat. What is the formal term for the sequence of handling and documenting evidence to maintain its integrity and legal admissibility throughout the incident lifecycle?
The term 'chain of custody' refers to the documented record of who has handled evidence, when, and how it was handled. In incident response, maintaining a strict chain of custody is critical for both technical investigations and potential legal proceedings. This ensures evidence integrity and admissibility if the incident results in disciplinary action, litigation, or law enforcement involvement. The CySA+ exam requires candidates to understand key incident response techniques including evidence handling, which is a foundational practice in the eradication and recovery phases of the incident response process. This question tests knowledge of formal incident response procedures and terminology used in professional security operations.
Get access to all 82 verified questions with detailed answers.
Unlock All CS0-004 Questions