CS0-004 Sample Questions & Answers
System and network architecture concepts for security operations carry the top weight, alongside scanning for and mitigating vulnerabilities, attack-methodology frameworks and the incident-response lifecycle, and security reporting.
Launch the full CS0-004 simulator →Showing 10 of 20 free samples.
- Question 1IntermediateSelect 2
Security Operations · Use tools to determine malicious activity
A SOC team is investigating a potential lateral movement incident. The analyst needs to combine capabilities from both the SIEM and the EDR solution to build a complete timeline of the attacker's actions. Which TWO of the following tasks are BEST suited for the EDR tool rather than the SIEM? (Select TWO)
Show answer & explanation
Correct answers: B, E
Endpoint Detection and Response (EDR) solutions are designed to monitor endpoint behavior at a deep level, including memory analysis, process trees, and registry modifications. Analyzing memory for DLL injection and isolating the endpoint from the network are core EDR capabilities. SIEMs are used for log aggregation and correlation across disparate systems (like firewalls and badge readers) and evaluating cloud identity logs.
Endpoint Detection and Response (EDR) solutions are designed to monitor endpoint behavior at a deep level, including memory analysis, process trees, and registry modifications. Analyzing memory for DLL injection and isolating the endpoint from the network are core EDR capabilities. SIEMs are used for log aggregation and correlation across disparate systems (like firewalls and badge readers) and evaluating cloud identity logs.
- Question 2Beginner
Security Operations · Analyze indicators of potential malicious activity
While reviewing alerts, a junior analyst notices that a user's workstation has triggered multiple antivirus warnings for "Mimikatz" over the last 10 minutes. Which of the following is the MOST immediate risk to the organization based on this specific indicator?
Show answer & explanation
Correct answer: C
Mimikatz is a well-known credential dumping tool used to extract plaintext passwords, hashes, PINs, and Kerberos tickets from memory (specifically the LSASS process in Windows). The immediate risk is credential theft, which facilitates privilege escalation and lateral movement. It is not used for DoS, ransomware encryption, or SQL injection.
- Question 3Advanced
Security Operations · Use tools to determine malicious activity
A security analyst is reviewing a packet capture (PCAP) file from a compromised workstation. The analyst observes a high volume of DNS TXT record queries directed to an external IP address that is not the organization's configured DNS server. The TXT responses contain long strings of base64-encoded text. What is the MOST likely explanation for this activity?
Show answer & explanation
Correct answer: C
DNS tunneling abuses the DNS protocol to bypass firewalls and proxy restrictions. Attackers often use TXT records because they allow for larger payloads of arbitrary text. The presence of base64-encoded strings in TXT responses from a non-standard external IP is a classic indicator of a Command and Control (C2) channel or data exfiltration via DNS tunneling.
sequenceDiagram participant W as Compromised Workstation participant F as Firewall participant C as Attacker C2 (Rogue DNS) W->>F: DNS Query (TXT) encoded_data.evil.com F->>C: Forwards DNS Query (Port 53 allowed) C-->>F: DNS Response (TXT) Base64_C2_Command F-->>W: Delivers Command - Question 4Intermediate
Security Operations · Explain system and network architecture concepts in security operations
During an incident investigation, an analyst discovers that an attacker gained access to multiple SaaS applications without needing the users' passwords. The attacker achieved this by forging an XML-based assertion, signing it with a stolen private key from the organization's Identity Provider (IdP), and presenting it to the Service Providers (SPs). Which identity protocol was abused in this attack?
Show answer & explanation
Correct answer: A
Security Assertion Markup Language (SAML) 2.0 is an XML-based standard in which an Identity Provider (IdP) issues signed assertions that Service Providers (SPs) trust for web SSO. The attack described is a 'Golden SAML' attack: with the IdP's token-signing private key, the attacker forges valid signed XML assertions for any user and bypasses authentication entirely. OpenID Connect uses JSON-based JWT ID tokens, OAuth 2.0 is an authorization framework whose tokens are not XML assertions, and RADIUS is a network AAA protocol.
- Question 5Beginner
Security Operations · Summarize concepts related to the use of AI in security operations
True or False: When utilizing Artificial Intelligence (AI) and Machine Learning (ML) models for threat hunting, "AI Hallucinations" refer to instances where the model confidently presents false or fabricated data as factual intelligence, which can lead analysts down incorrect investigative paths.
Show answer & explanation
Correct answer: A
True. AI Hallucinations occur when a Generative AI model generates output that sounds plausible and confident but is entirely fabricated or factually incorrect. In security operations, this is a significant risk as it can result in false positives, misattribution of threats, or wasted time during incident response.
- Question 6Intermediate
Security Operations · Explain threat intelligence and threat-hunting concepts
A cybersecurity team is integrating a new Threat Intelligence Platform (TIP) with their existing SIEM. They want to ensure that threat indicators are shared using a standardized, machine-readable language and transported securely over HTTPS. Which combination of frameworks is the industry standard for this requirement?
Show answer & explanation
Correct answer: A
Structured Threat Information Expression (STIX) is a standardized XML/JSON language for describing cyber threat information. Trusted Automated eXchange of Indicator Information (TAXII) is the transport protocol used to exchange STIX data over HTTPS. Together, they form the industry standard for automated threat intelligence sharing.
- Question 7Intermediate
Security Operations · Describe efficiency and process improvement in security operations
A SOC manager notes that analysts are spending an average of 45 minutes manually querying Active Directory, firewall logs, and endpoint logs just to gather context for every single phishing alert. To improve operational efficiency and reduce alert triage time and the Mean Time To Respond (MTTR), which technology should the manager implement?
Show answer & explanation
Correct answer: B
SOAR platforms are specifically designed to improve SOC efficiency by automating repetitive tasks such as data enrichment. A SOAR playbook can trigger automatically when a phishing alert arrives, query AD, firewalls and endpoints, and present the consolidated context to the analyst immediately. This drastically cuts manual triage effort and the time to respond (MTTR). DLP, NDR and XDR generate or correlate detections but do not orchestrate this enrichment workflow.
- Question 8Advanced
Security Operations · Analyze indicators of potential malicious activity
An analyst is reviewing network traffic logs and notices a repeating pattern from an internal server to an unknown external IP address on port 443. The connections occur exactly every 300 seconds, with a variance of no more than 2 seconds, and transfer approximately 5 KB of data each time. What type of malicious behavior does this pattern MOST strongly indicate?
graph LR Server[Internal Server] -- 00:00:00 (5KB) --> Ext[External IP] Server -- 00:05:01 (5KB) --> Ext Server -- 00:10:00 (5KB) --> Ext Server -- 00:15:02 (5KB) --> ExtShow answer & explanation
Correct answer: D
Beaconing is a behavior where malware periodically "phones home" to a Command and Control (C2) server to check for new instructions. It is characterized by regular, rhythmic connection intervals (e.g., every 5 minutes) and small, consistent payload sizes. Advanced attackers may introduce "jitter" (slight random timing variances, like +/- 2 seconds) to evade basic detection, but the rhythmic pattern remains a strong indicator of C2 beaconing.
- Question 9Intermediate
Security Operations · Analyze indicators of potential malicious activity
While investigating an AWS environment compromise, an analyst reviews CloudTrail logs and finds multiple
sts:AssumeRoleevents originating from a compromised EC2 instance's IAM role. The events show the role assuming a higher-privileged administrative role in another account. Which cloud attack technique is being demonstrated?Show answer & explanation
Correct answer: B
Role chaining occurs when an identity uses its permissions to assume another role, which may then assume another role, and so on. Attackers use this to escalate privileges or move laterally across cloud accounts (cross-account access). The
sts:AssumeRoleAPI call is the primary mechanism for this in AWS. While SSRF might have been used initially to steal the instance credentials, the log activity itself represents role chaining. - Question 10Beginner
Vulnerability Management · Implement the appropriate vulnerability scanning method
A vulnerability management team needs to scan a segment of Windows servers to identify missing registry-level security configurations and outdated third-party software versions. Which scanning method is REQUIRED to achieve this level of visibility?
Show answer & explanation
Correct answer: C
A credentialed (authenticated) scan uses administrative credentials to log into the target system. This allows the scanner to read the local registry, check installed software versions, and verify local file configurations. An uncredentialed scan only sees what is exposed over the network (e.g., open ports and banner grabbing) and cannot check registry keys.
Ready for the real thing?
The full CS0-004 simulator has every exam-style question, timed mode, and instant scoring.