CS0-004 · Intermediate
CompTIA Cybersecurity Analyst (CySA+)
Investigate security evidence, prioritize vulnerabilities and coordinate defensible incident response and reporting.
Your free account includes a full CS0-004 practice exam.
ExamNova practice
Your first session
- Questions
- 85
- Time limit
- 165 min
- Coverage
- 4 domains
Practise, review your answers and see where to focus next.
Is CS0-004 your next step?
Explore the coverage below to see how this certification fits your study goals.
What you’ll study
Your CS0-004 practice covers every domain on the exam.
- Security Operations
- Vulnerability Management
- Incident Response and Management
- Reporting and Communication
Consult the official guide for the vendor’s current exam outline.
Put it into practice.
Explore hands-on tasks connected to CS0-004. These are real Labs from the catalogue.
Construct AI triage input and evidence gates
Repair ai-triage-rules.json using hitPolicy unique or first and 1..24 distinct {id,when,then} rows. Inputs: data public,internal,restricted; purpose triage,model-training; provider approved,unreviewed; grounding corroborated,unsupported,injected. when nonempty category arrays combine by AND; omitted fields are wildcards. then must contain input (proceed,minimize,withhold), handling (purpose-review,provider-review,private-route,quarantine-output,analyst-review,verify-evidence), autonomy (boolean true or false). Apply this local policy in precedence order: model-training always yields withhold/purpose-review. For triage, unreviewed provider always yields withhold/provider-review. Triage at an approved provider with restricted data always yields withhold/private-route. For approved triage with public/internal data, injected grounding always yields withhold/quarantine-output. Remaining public data may proceed; remaining internal data must minimize. For both, corroborated grounding requires analyst-review; unsupported grounding requires verify-evidence. Earlier permission gates determine the handling reason even when grounding is injected; an input permission failure cannot be bypassed by a grounded-looking result. Autonomy is false for EVERY context. No row authorizes model-driven containment, incident closure or evidence deletion, including corroborated public input. A model-training opt-out or provider label cannot replace permitted purpose/classification. Evaluate all 36 contexts. Unique requires exactly one matching row. First permits deliberate overlap when earlier permission gates precede later evidence fallbacks. Every context needs exact outputs; every row must contribute. Use only supplied fields, typed values and meaningful reachable priority. Disjoint gates or ordered broad fallbacks are valid. Run tests, inspect actual input/handling/authority mismatches, save and repair without Reset.
hard · About 35 min
LabReconcile an authenticated assessment coverage ledger
Repair coverage.sql. Return exactly asset_id, owner, coverage_status, attempt_id, assessed_second, high_findings, with one row per inventory asset; repeated identical imported rows must not multiply the ledger. Preserve the inventory owner, including an unknown NULL owner. scope_state excluded means EXCLUDED; pending means AUTHORIZATION_PENDING. Both retain NULL attempt/time and zero findings, even if old scan records exist. Never silently remove an unassessed or excluded inventory asset. For approved assets, assessment evidence is eligible only when outcome='complete', authenticated=1 and inventory_collected=1. At the fixed observation second 1000, finished must be in the inclusive 700..1000 window. Select the newest eligible finished value; a later failed attempt does not erase an earlier still-current successful assessment. If times tie, select the lexicographically greatest attempt_id. Missing eligible evidence means NOT_ASSESSED, NULL attempt/time and zero findings; otherwise report ASSESSED with that actual attempt and finished time. Zero findings from failed credentials or missing inventory must not become an assessed result. high_findings counts distinct finding_id values only for that selected attempt AND that asset, with confirmed=1 and severity>=7. Imported duplicates, another asset's records and older scan findings must not inflate it. The threshold is this team's policy, not an exploitation verdict. A window-ranked eligible-attempt query or an equivalent correlated/anti-join selection is valid. Inspect actual inventory status, chosen attempt and finding counts; repair a newly visible stale or duplicate-evidence error without Reset.
hard · About 35 min
Make CS0-004 your next step.
Create your free account. Start practising.
Start Free