CS0-004 · Intermediate

CompTIA Cybersecurity Analyst (CySA+)

Investigate security evidence, prioritize vulnerabilities and coordinate defensible incident response and reporting.

Start Free

Your free account includes a full CS0-004 practice exam.

ExamNova practice

Your first session

Questions
85
Time limit
165 min
Coverage
4 domains

Practise, review your answers and see where to focus next.

Is CS0-004 your next step?

Explore the coverage below to see how this certification fits your study goals.

What you’ll study

Your CS0-004 practice covers every domain on the exam.

  1. Security Operations
  2. Vulnerability Management
  3. Incident Response and Management
  4. Reporting and Communication

Consult the official guide for the vendor’s current exam outline.

Put it into practice.

Explore hands-on tasks connected to CS0-004. These are real Labs from the catalogue.

Lab

Construct AI triage input and evidence gates

Repair ai-triage-rules.json using hitPolicy unique or first and 1..24 distinct {id,when,then} rows. Inputs: data public,internal,restricted; purpose triage,model-training; provider approved,unreviewed; grounding corroborated,unsupported,injected. when nonempty category arrays combine by AND; omitted fields are wildcards. then must contain input (proceed,minimize,withhold), handling (purpose-review,provider-review,private-route,quarantine-output,analyst-review,verify-evidence), autonomy (boolean true or false). Apply this local policy in precedence order: model-training always yields withhold/purpose-review. For triage, unreviewed provider always yields withhold/provider-review. Triage at an approved provider with restricted data always yields withhold/private-route. For approved triage with public/internal data, injected grounding always yields withhold/quarantine-output. Remaining public data may proceed; remaining internal data must minimize. For both, corroborated grounding requires analyst-review; unsupported grounding requires verify-evidence. Earlier permission gates determine the handling reason even when grounding is injected; an input permission failure cannot be bypassed by a grounded-looking result. Autonomy is false for EVERY context. No row authorizes model-driven containment, incident closure or evidence deletion, including corroborated public input. A model-training opt-out or provider label cannot replace permitted purpose/classification. Evaluate all 36 contexts. Unique requires exactly one matching row. First permits deliberate overlap when earlier permission gates precede later evidence fallbacks. Every context needs exact outputs; every row must contribute. Use only supplied fields, typed values and meaningful reachable priority. Disjoint gates or ordered broad fallbacks are valid. Run tests, inspect actual input/handling/authority mismatches, save and repair without Reset.

hard · About 35 min

Lab

Reconcile an authenticated assessment coverage ledger

Repair coverage.sql. Return exactly asset_id, owner, coverage_status, attempt_id, assessed_second, high_findings, with one row per inventory asset; repeated identical imported rows must not multiply the ledger. Preserve the inventory owner, including an unknown NULL owner. scope_state excluded means EXCLUDED; pending means AUTHORIZATION_PENDING. Both retain NULL attempt/time and zero findings, even if old scan records exist. Never silently remove an unassessed or excluded inventory asset. For approved assets, assessment evidence is eligible only when outcome='complete', authenticated=1 and inventory_collected=1. At the fixed observation second 1000, finished must be in the inclusive 700..1000 window. Select the newest eligible finished value; a later failed attempt does not erase an earlier still-current successful assessment. If times tie, select the lexicographically greatest attempt_id. Missing eligible evidence means NOT_ASSESSED, NULL attempt/time and zero findings; otherwise report ASSESSED with that actual attempt and finished time. Zero findings from failed credentials or missing inventory must not become an assessed result. high_findings counts distinct finding_id values only for that selected attempt AND that asset, with confirmed=1 and severity>=7. Imported duplicates, another asset's records and older scan findings must not inflate it. The threshold is this team's policy, not an exploitation verdict. A window-ranked eligible-attempt query or an equivalent correlated/anti-join selection is valid. Inspect actual inventory status, chosen attempt and finding counts; repair a newly visible stale or duplicate-evidence error without Reset.

hard · About 35 min

Make CS0-004 your next step.

Create your free account. Start practising.

Start Free