Free practice + study guide

CompTIA CySA+ (CS0-004)

  • 24 free practice questions, every one explained · no signup
  • Timed mock exam (24 questions, 165 minutes) — free
  • Study guide: free to read online
Practice free 24 questions · explanations · no signup
01

Test what you know · free, all of it

Four ways to practise.

The same 24 questions, dealt four ways. Pick the one that fits the time you have.

02

Learn what the questions test

Practice · free
24
questions, each explained — finds what you don't know yet
Learn · free
4
chapters, free to read online

The four chapters, free online

every chapter free online
  1. 1Security Operations34% of the exam — the largest sectionRead free →
  2. 2Vulnerability Management26%Read free →
  3. 3Incident Response & Management24%Read free →
  4. 4Reporting & Communication16%Read free →
03

Before you sit

Know the exam you're walking into.

04

See the questions first

Two from the bank, answered.

Real items, with the answer marked and the reason written out — the same format as all 24.

Security Operations

An analyst reviewing SIEM alerts wants to reduce noise by suppressing repeated benign events from a known vulnerability scanner. Which action best preserves detection capability while cutting alert volume?

  1. ADisable the correlation rule entirely across all hosts
  2. BCreate a tuning rule that excludes traffic from the scanner's known IP for that specific signatureCorrect
  3. CDelete all log sources associated with the scanner's subnet
  4. DLower the SIEM's overall logging retention to 7 days

Why: Tuning to exclude a known-good source for one signature removes false positives without blinding the SIEM to real threats. Deleting log sources or disabling the rule globally would create blind spots, and shortening retention harms investigations. Targeted allow-listing keeps fidelity high while reducing analyst fatigue.

Vulnerability Management

An analyst must prioritize remediation for a vulnerability with a CVSS base score of 9.8. Before escalating, which additional factor most improves prioritization accuracy?

  1. AEnvironmental and threat context such as asset exposure and active exploitationCorrect
  2. BThe vendor's marketing severity label only
  3. CThe alphabetical order of the affected hostname
  4. DThe number of characters in the CVE identifier

Why: A CVSS base score reflects intrinsic severity but ignores your environment; adding environmental metrics and threat intelligence (like known active exploitation) sharpens real-world risk. A 9.8 on an isolated, non-critical asset may rank below a 7.0 on an internet-facing crown-jewel system. Context-driven prioritization prevents wasting effort on theoretically severe but practically low-risk findings.

Read all 24 questions with answers →

06

The exam itself

CompTIA CySA+ (CS0-004), by the numbers.

Questions85
Time165 minutes
SectionsSecurity Operations · Vulnerability Management · Incident Response & Management · Reporting & Communication
Passing score750 / 900
Our bank24 questions · updated August 2026Written from CompTIA
LanguagesEnglish
SourceCompTIA
09

Questions

Asked before starting.

Is the practice really free, or does it stop after a few questions?

All 24 questions, the timed mock and the report are free with no sign-up. A free account only adds saving your progress.

Is your mock the same as the real CompTIA CySA+ (CS0-004)?

No. Ours is 24 questions in 165 minutes; the real exam is 85 questions in 165 minutes. Use the mock for stamina and section timing, not as a score predictor.

What score do I need?

750 / 900 — as published by CompTIA. Confirm the current rule with them before your exam date.

Practice questions are AI-assisted study material written from CompTIA and reviewed by PrepPass — for practice only, not official exam questions. Bank updated August 2026. PrepPass is an independent study resource and is not affiliated with, endorsed by, or approved by CompTIA. Always confirm current exam details with CompTIA.
Report