FlashGenius Logo FlashGenius
Login Sign Up

CYSA-004 Practice Questions: Reporting and Communication Domain

Test your CYSA-004 knowledge with 10 practice questions from the Reporting and Communication domain. Includes detailed explanations and answers.

CYSA-004 Practice Questions

Master the Reporting and Communication Domain

Test your knowledge in the Reporting and Communication domain with these 10 practice questions. Each question is designed to help you prepare for the CYSA-004 certification exam with detailed explanations to reinforce your learning.

Question 1

A SOC analyst uses an internal AI assistant to draft a customer-facing incident summary. The draft says: "Confirmed attacker access to all production databases for approximately 6 hours. Customer records were likely exfiltrated." Case notes actually show: - Access confirmed to one reporting database - Access window currently estimated between 45 and 70 minutes - Exfiltration is still under investigation with no confirmation yet What is the BEST next step?

A) Send the draft after adding a note that it was AI-generated, since the customer needs a fast update.

B) Validate and correct the summary against case evidence before any external distribution.

C) Delete the draft and avoid using AI for any internal security tasks in the future.

D) Send the draft only to executives first, because technical inaccuracies matter less in an early business update.

Show Answer & Explanation

Correct Answer: B

Explanation:

Correct answer (B): AI-assisted summaries can be useful, but they must be validated before being shared because they can overstate scope, confidence, or impact. In this scenario, the draft materially misrepresents affected systems, duration, and exfiltration status. The analyst must correct it against the case evidence before external communication.

Why the other options are wrong:
- Option A: Noting that AI was used does not fix factual errors. Sending an inaccurate external statement can create trust, legal, and communication problems.
- Option C: This is an overreaction. The issue is lack of validation, not the existence of AI assistance itself.
- Option D: Inaccuracies matter to every audience. Executives also need correct scope and confidence, and unsupported claims should not be circulated internally or externally.

Question 2

A SOC analyst used an internal AI tool to draft an executive update. AI-generated excerpt: - The incident began with a phishing email sent to user tpatel - No data left the environment - The attacker used the granted OAuth app only to read calendar items Case facts available to the analyst: - Suspicious OAuth consent was confirmed for user tpatel - Mail gateway logs are inconclusive - Proxy retention expired for part of the investigation window - Scope of data access is still being validated What should the analyst do BEFORE sending the update?

A) Validate the claims against available evidence and remove any unsupported statements about initial access, exfiltration, or scope

B) Send the summary with a note that it was AI-generated so leadership knows some details may be inaccurate

C) Ask the AI tool to make the summary more confident so the incident commander can make faster decisions

D) Add raw authentication logs and OAuth token details so the unsupported conclusions appear more technically complete

Show Answer & Explanation

Correct Answer: A

Explanation:

Correct answer (A): AI-generated reporting can speed drafting, but analysts must validate conclusions before distribution. Here, the tool makes unsupported claims about initial access, exfiltration, and scope that are not established by the evidence. The analyst should remove or rewrite those statements so the report clearly separates confirmed facts from unknowns.

Why the other options are wrong:
- Option B: A disclaimer does not fix inaccurate content. Executives may still act on false statements.
- Option C: Incorrect because more confident wording would make uncertain claims more dangerous, not more useful.
- Option D: Incorrect because extra raw detail does not validate unsupported conclusions and also makes the executive update less audience-appropriate.

Question 3

A detection engineer is sharing a short threat intelligence update with the SOC. Artifact: Observed TTPs: password spraying against VPN, use of newly registered domains, archive creation before outbound transfer Indicators: 198.51.100.24, login failures against svc_backup, domain update-check[.]site What addition would make this report MOST useful to internal defenders?

A) A recommendation to search VPN authentication logs for repeated failures, review outbound archive creation on critical servers, and update detections for the listed indicators and behaviors.

B) A full copy of the external intelligence article so analysts can decide individually whether anything matters.

C) A confidence statement that the activity is definitely linked to a named threat group even though attribution is still being assessed.

D) A request for the SOC to wait for more indicators before taking any action to avoid extra alert volume.

Show Answer & Explanation

Correct Answer: A

Explanation:

Correct answer (A): Internal threat intelligence reporting is most valuable when it converts indicators and TTPs into concrete defensive actions. Option A gives immediate hunt targets, detection updates, and investigative direction, which makes the intelligence operationally useful.

Why the other options are wrong:
- Option B: Source material may add context, but it does not tell defenders what to do next.
- Option C: Unconfirmed attribution can mislead responders and does not improve defensive action.
- Option D: Waiting for more indicators delays useful hunts and tuning that can be performed now.

Question 4

A SOC analyst is ending a shift during an active identity-based incident. Current handover note: - 14 alerts for impossible travel - User: jdiaz - MFA challenge failures observed - Ticket INC-4471 opened - Investigating cloud admin console activity Which additional item is MOST important to add before handoff?

A) A full export of every raw authentication log generated during the shift

B) The analyst's opinion that the user was probably careless with a password

C) Actions completed, pending tasks, assigned owner, and the 02:00 lockout review deadline

D) A list of all other medium-severity alerts seen in the environment today

Show Answer & Explanation

Correct Answer: C

Explanation:

Correct answer (C): A good handover note lets the next analyst continue work without losing time. That requires current status, what has already been done, what still needs to be done, who owns it, and any deadlines. Option C adds the operational details missing from the note and is far more useful than raw log volume or speculation.

Why the other options are wrong:
- Option A: Raw logs may be valuable evidence, but they do not replace a concise handoff that explains status and next actions.
- Option B: Speculation about user behavior is not an appropriate substitute for actionable handoff information and can bias the investigation.
- Option D: This adds noise rather than helping the incoming analyst understand the active incident's current status and priorities.

Question 5

An analyst is ending the night shift and must hand off an active incident to the day team. Artifact: INC-4472 | Severity: High - Possible lateral movement from WS-244 to FILE-09 - WS-244 isolated at 21:10 - Need to review FILE-09 access logs - Phishing email sample attached to case Which addition is MOST important before the analyst signs off?

A) The likely threat actor attribution based on the source IP geolocation

B) The owner of the pending log review and the location of the collected evidence and case notes

C) A list of all open helpdesk tickets created during the shift

D) The hardware purchase date and warranty status of FILE-09

Show Answer & Explanation

Correct Answer: B

Explanation:

Correct answer (B): Shift handover documentation should include pending actions, assigned owners, and where evidence or case artifacts are stored. Without those details, the next shift may duplicate work, miss deadlines, or fail to continue the investigation smoothly. Attribution guesses, helpdesk noise, and asset procurement details are not the priority here.

Why the other options are wrong:
- Option A: Threat attribution based only on IP geolocation is weak and does not help the day team continue confirmed investigative steps.
- Option C: This adds unrelated operational noise and does not improve the incident handoff.
- Option D: Asset lifecycle information is not the most important missing detail for an active high-severity investigation.

Question 6

A vulnerability analyst is building the weekly remediation report for infrastructure leadership. Artifact: 1) Internet-facing payment API: CVSS 8.2, EPSS 0.94, active exploitation reported in the wild, age 18 days, SLA 14 days, no compensating control 2) Internal dev file server: CVSS 9.8, EPSS 0.07, not internet-facing, age 2 days, SLA 30 days 3) HR workstation image package: CVSS 7.5, EPSS 0.61, affects 130 endpoints, age 6 days, patch available, EDR blocks known exploit chain 4) Legacy print server: CVSS 8.8, EPSS 0.22, segmented VLAN, age 11 days, SLA 14 days, service disabled outside business hours Which finding should be emphasized as the HIGHEST priority in the report?

A) The internal dev file server because it has the highest CVSS score.

B) The internet-facing payment API because it is exposed, likely to be exploited, and already beyond SLA.

C) The HR workstation image package because it affects the largest number of assets.

D) The legacy print server because it is close to the SLA deadline and still has a high CVSS score.

Show Answer & Explanation

Correct Answer: B

Explanation:

Correct answer (B): Strong vulnerability reporting uses more than CVSS alone. The payment API is internet-facing, tied to a critical business service, has very high exploit likelihood, has active exploitation reported in the wild, lacks compensating controls, and is already beyond SLA. That combination makes it the clearest top priority for leadership attention.

Why the other options are wrong:
- Option A: High CVSS alone does not make this the top reporting priority. The server is internal, newer, and has much lower exploit-likelihood context.
- Option C: Asset count matters, but the stem shows an EDR control already blocks the known exploit chain, reducing immediate urgency compared with the exposed payment API.
- Option D: This is a valid concern, but segmentation and reduced service availability are compensating controls, and the overall risk is lower than the exposed payment API.

Question 7

An analyst must summarize newly received threat intelligence for the SOC detection team. Artifact: Threat intelligence snippet: - Source confidence: medium - Campaign targets SAML-based SSO portals with adversary-in-the-middle phishing kits - Common signs: impossible travel after MFA, new device enrollment, abnormal token reuse - Internal environment: the company uses an internet-facing SAML identity provider for remote access Which report excerpt is the BEST one to send internally?

A) Threat actors may target identity systems. The team should stay alert for anything unusual this week.

B) A high-confidence nation-state intrusion is underway against our company, so block all foreign IP addresses immediately.

C) This campaign is relevant because we use an internet-facing SAML identity provider; monitor for impossible travel, new device enrollment, and token reuse, and increase review of MFA-resistant phishing detections. Confidence is medium based on current reporting.

D) Because the intelligence does not name our company directly, no internal reporting or tuning changes are warranted.

Show Answer & Explanation

Correct Answer: C

Explanation:

Correct answer (C): Strong internal threat intelligence reporting includes relevance to the environment, confidence level, likely behaviors, and recommended detection or mitigation actions. Option C ties the threat to the organization's SAML exposure, preserves the medium-confidence assessment, and gives the SOC concrete monitoring actions. The other options are either too vague, too certain, or dismissive.

Why the other options are wrong:
- Option A: This is too generic to be useful. It does not explain why the intelligence matters to the environment or what defenders should monitor.
- Option B: This overstates the intelligence, claims high confidence when the source is only medium confidence, and recommends a broad action not justified by the stem.
- Option D: Threat intelligence can still be operationally relevant even when it does not specifically name the company, especially when the organization uses the targeted technology.

Question 8

A Tier 1 analyst leaves the following handover note for the next shift: Handover note: - INC-2441 - Severity: High - Investigated unusual OAuth consent grants - Disabled user mlee - See ticket for details What information is MOST important to add for an effective shift handover?

A) The current validated scope, actions already taken, pending tasks, and who owns the next step

B) A full copy of every authentication log related to the user account from the last seven days

C) A summary of the analyst's certifications and previous experience with OAuth abuse cases

D) A screenshot of the ticket queue so the next analyst can confirm the incident still exists

Show Answer & Explanation

Correct Answer: A

Explanation:

Correct answer (A): Good handovers preserve continuity. The next analyst needs to know the confirmed scope, what has already been done, what remains to be done, any deadlines or urgency, and who owns the next action. Ticket numbers alone do not provide enough operational context for a fast-moving incident.

Why the other options are wrong:
- Option B: Too much raw detail and not a replacement for a concise status handoff.
- Option C: Irrelevant to incident continuity and next-step execution.
- Option D: A queue screenshot does not explain scope, response status, or pending actions.

Question 9

A SOC analyst is preparing an update for the CIO and COO during an ongoing incident. Artifact: Audience: Executive leadership Current status: FIN-APP-02 isolated at 09:42, payroll API unavailable to 42 users, investigation continues Draft excerpt: "EDR detected powershell.exe -enc ..., SHA256=7d1c..., outbound 185.77.2.19:443, persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run" Which revision is the BEST replacement for the draft excerpt?

A) A host on the finance network executed a suspicious PowerShell command and contacted an external IP. Full IOC and hash details are attached for review.

B) A finance application server was isolated after suspicious activity was detected. Payroll API access is currently disrupted for 42 users, containment is in progress, and leadership will be updated at 11:00 if recovery approval is needed.

C) The server showed registry persistence and encoded PowerShell activity. Network traffic and process-tree details confirm likely hands-on-keyboard activity.

D) The activity likely indicates a ransomware affiliate, and the organization should assume large-scale data theft until proven otherwise.

Show Answer & Explanation

Correct Answer: B

Explanation:

Correct answer (B): Executive updates should emphasize business impact, affected service, current containment status, and any pending leadership decisions rather than raw IOCs or forensic detail. Option B communicates the disruption, current action, and next update point without speculation.

Why the other options are wrong:
- Option A: Still too technical for an executive audience. Raw IOCs and hashes may help responders, but they do not center business impact or decision support.
- Option C: Appropriate for a technical team, not executive leadership. It emphasizes forensic detail instead of operational impact.
- Option D: Speculative attribution and impact inflation should be avoided in active incident communication.

Question 10

A SOC analyst used an AI assistant to draft an incident update. Artifact: AI-generated draft: - "No customer data was exposed." - "Attackers accessed only one host." - Includes internal hostnames and usernames - Current case notes say exfiltration is unconfirmed and scope is still under investigation What is the BEST next step before distributing the report?

A) Send it as written because speed matters more than wording during an incident.

B) Validate each claim against the case evidence, remove unsupported conclusions, and confirm the recipients are authorized to receive the included details.

C) Replace the draft with the AI model's confidence score and send that to leadership instead.

D) Ask the AI assistant to send the summary directly to all department heads for faster awareness.

Show Answer & Explanation

Correct Answer: B

Explanation:

Correct answer (B): AI-assisted drafting can improve speed, but analysts still own accuracy and handling of sensitive information. Here, the draft contains unsupported conclusions and potentially sensitive identifiers, so the analyst must validate claims against evidence, remove unsupported statements, and confirm recipient authorization before distribution.

Why the other options are wrong:
- Option A: Speed does not justify sending inaccurate or overconfident incident reporting.
- Option C: A model confidence score is not a substitute for analyst verification and does not fix the exposure of sensitive details.
- Option D: Broad automatic distribution increases the risk of unnecessary or unauthorized disclosure.

Ready to Accelerate Your CYSA-004 Preparation?

Join thousands of professionals who are advancing their careers through expert certification preparation with FlashGenius.

  • ✅ Unlimited practice questions across all CYSA-004 domains
  • ✅ Full-length exam simulations with real-time scoring
  • ✅ AI-powered performance tracking and weak area identification
  • ✅ Personalized study plans with adaptive learning
  • ✅ Mobile-friendly platform for studying anywhere, anytime
  • ✅ Expert explanations and study resources
Start Free Practice Now

Already have an account? Sign in here

About CYSA-004 Certification

The CYSA-004 certification validates your expertise in reporting and communication and other critical domains. Our comprehensive practice questions are carefully crafted to mirror the actual exam experience and help you identify knowledge gaps before test day.