CS0-004
CompTIA CySA+ CS0-004
The natural step after Security+: SOC analyst work — detection, log and SIEM analysis, vulnerability management, incident response.
- Questions
- max 85
- Time
- 165 min
- Pass
- 750/900
- Reading
- ~6 hrs
Security Operations
34% of exam- 1.1Explain system and network architecture concepts in security operations26m
Logging, operating systems, infrastructure, network architecture, identity and access management, encryption, and how each shapes what a SOC can actually see.
- 1.2Analyze indicators of potential malicious activity34m
Network, host, and application indicators — reading symptoms and naming the attack. The heaviest analysis objective on the exam.
- 1.3Use tools to determine malicious activity30m
Wireshark, packet capture, log analysis, endpoint and email tooling, sandboxing, and the common file/hash analysis utilities.
- 1.4Explain threat intelligence and threat-hunting concepts26m
Intelligence sources and confidence levels, threat actors and TTPs, indicators of compromise, and proactively hunting what no alert has flagged.
- 1.5Describe efficiency and process improvement in security operations18m
Standardising processes, orchestrating and automating with SOAR playbooks, integrations and APIs, and where automation earns its complexity.
- 1.6Summarize concepts related to the use of AI in security operations20m
New in V4: using AI for analysis and enrichment, the risks it introduces, and recognising AI-enabled threats.
Vulnerability Management
26% of exam- 2.1Implement the appropriate vulnerability scanning method24m
Asset discovery, scan types and timing, credentialed vs non-credentialed, agent vs agentless, and scanning fragile systems safely.
- 2.2Analyze output from vulnerability assessment tools28m
Reading real scanner, web application, and infrastructure tool output, and separating true findings from noise.
- 2.3Prioritize and mitigate vulnerabilities28m
CVSS scoring in depth, context and exploitability, validation, compensating controls, and handling inhibitors to remediation.
- 2.4Explain concepts related to control types, risks, and vulnerability management22m
Control types, risk management principles, secure coding, and the frameworks and standards that govern the programme.
Incident Response and Management
24% of exam- 3.1Summarize concepts related to attack methodology frameworks24m
Cyber Kill Chain, Diamond Model, MITRE ATT&CK, and OSSTMM — mapping observed activity onto a model to predict what comes next.
- 3.2Outline the incident response process26m
Preparation through lessons learned, with the detection, analysis, containment, eradication and recovery sequence in order.
- 3.3Implement incident response techniques26m
Containment, eradication and recovery in practice — isolation, segmentation, reimaging, patching, and validating the fix held.
Reporting and Communication
16% of exam- 4.1Explain vulnerability management reporting and communication20m
Compliance and action plans, inhibitors to remediation, metrics and KPIs, stakeholder identification, and reporting that drives decisions.
- 4.2Describe security operations, incident response reporting, and communication20m
Incident declaration and escalation, communicating with legal, regulators and executives, root cause analysis, and lessons learned.