Triage BoardGet the app

Domain 1 · Security Operations

System and network architecture for security operations

Logging and system architecture decide what a security operations center (SOC) can see and how far it can trust what it sees. CS0-004 objective 1.1 covers both, from log integrity and time sync to hardening, cloud telemetry, ZTNA and SASE, identity, encryption and OT. The questions describe an environment and ask which design produces usable evidence or protects it.

  • Exam code CS0-004
  • Domain weight 34%
  • Tickets here 15

What objective 1.1 expects of an analyst

The CS0-004 exam objectives (version 2.0, checked October 2026) run 1.1 from logging through operating-system hardening, cloud and containers, endpoint management, network access models, identity, encryption and data protection, and finally operational technology. CS0-004 names zero trust network access (ZTNA) where CS0-003 said “zero trust”; secure access service edge (SASE) was already on the CS0-003 list.

1.1 is worded as a concepts objective. The scenario-heavy objectives come next, in 1.2 and 1.3, so this part tends toward multiple-choice items that test a design decision. That is our reading of the objective verbs; CompTIA does not say which objectives feed which question types.

The eight parts at a glance

Objective 1.1 broken into parts, with the angle the exam takes on each
PartWhat to knowHow it is askedWhere candidates slip
LoggingIngestion, configuration, integrity, time sync, retentionWhich source holds the evidenceAssuming a collected log is a trustworthy log
OS hardeningBaselines, critical files, normal processesWhich change on a host mattersTreating a hardened image as a monitored one
Cloud and containersControl plane vs workload telemetry, APIsWhich log answers a cloud questionForgetting that short-lived workloads take local logs with them
Endpoint and mobile managementEnrollment, compliance state, remote wipeWhich tool enforces a device ruleExpecting a management console to detect attacks
ZTNA, SASE, hybrid cloudPer-application access vs network accessWhich model fits remote staff or branchesCalling SASE a single product
Identity and accessPAM, authentication vs authorization, secretsWhich control limits privileged useMixing up proving identity with granting rights
Encryption and data protectionData at rest, in transit, in use; key handlingWhere the keys liveForgetting encryption also blinds your own sensors
OT, ICS, SCADASafety and uptime first, long-lived devicesWhich monitoring is safe on a plant networkScanning controllers like office laptops

Part names are our grouping of the CS0-004 objective text, written in our own words.

Logging, the part everything else depends on

Ingestion and configuration

A source that is never forwarded does not exist for the SIEM (security information and event management). Know the common sources by layer: Windows event logs (EVTX), Linux syslog and journald, firewall, proxy and DNS logs, the cloud provider's audit trail, and application logs. Configuration sets the depth: a web server that records only errors will not show the requests that led up to one.

Integrity

Logs are evidence, and an intruder with administrator rights can clear a host's local copy. Windows records that act itself as event ID 1102 in the Security log, which is why a clearing event is a finding on its own. Hash exported log files the way you would any other evidence; the page on chain of custody and evidence integrity covers the handling rules.

Time synchronization

Correlation is a sort by timestamp, so a drifting clock reorders the story. NTP keeps hosts on one reference. When a reconstructed sequence shows an effect before its cause, check the clocks before you build a theory around the attacker.

Retention

Retention is set by policy, by regulation and by how long intrusions stay hidden. A short searchable window is cheap, but an intrusion found weeks later needs older data, so expect questions that weigh hot, searchable storage against cheaper archive tiers.

Hosts, cloud, endpoints and identity

Hardening, critical files and processes

Hardening removes what a system does not need (services, default accounts, open ports) and fixes a baseline such as a CIS Benchmark. For an analyst the baseline matters twice: it shrinks the attack surface, and it gives you something to compare against. Know the places attackers edit: scheduled tasks, services and the hosts file on Windows; /etc/passwd, /etc/shadow, cron and SSH authorized_keys on Linux. Know normal process lineage too: svchost.exe under C:\Windows\System32 is expected, while the same name in a user's Temp folder is a lead.

Cloud, virtualization, containers and APIs

Cloud telemetry comes in two layers. The control plane records who created, changed or deleted resources; the workload layer records what the virtual machine, function or container did. Containers add a lifecycle problem: one image runs as many short-lived instances, so logs have to be shipped off the instance while it runs. APIs are both attack surface and data source, since a gateway can log the caller, the key used and the request rate.

Endpoints and mobile devices

Endpoint and mobile management covers enrollment, configuration profiles, compliance status and remote lock or wipe. Exam options often pair it with endpoint detection and response (EDR): management pushes settings, while EDR records process, file and network events and can isolate a host. The differences between EDR, XDR and SIEM are laid out in SIEM vs SOAR vs EDR.

Identity and access

Authentication proves who someone is; authorization decides what they may do. Privileged access management (PAM) vaults administrator credentials and issues them only for a task. Secrets management does the same for machine credentials (API keys, tokens, database passwords) so they stop living in scripts and code repositories. MFA, single sign-on and federation through SAML or OAuth/OpenID Connect are the methods to recognize.

Encryption and data protection

Match each control to the state of the data: TLS in transit, disk or database encryption at rest, data loss prevention (DLP) watching data in motion. Key handling decides the real protection, because whoever can export a key can read everything it protects.

VPN, ZTNA and SASE

Three remote-access models from objective 1.1, compared row by row
PointVPNZTNASASE
What the user reachesA network segmentOne application at a timeNetwork and security services delivered from the cloud
When trust is checkedAt connection timeOn every request, using identity and device stateThrough its ZTNA component for private apps
Typical partsTunnel and concentratorBroker plus identity and device checksSD-WAN, secure web gateway, CASB, ZTNA, firewall as a service
What a stolen session exposesEverything the segment exposesOnly the apps that identity is allowedWhatever its access policy allows

Zero trust principles are defined in NIST SP 800-207 (checked October 2026). SASE is a bundle of services; an answer that names it as one appliance is usually wrong.

Operational technology is not an office networkTrap

  • In operational technology (OT), meaning industrial control systems (ICS) and SCADA, physical safety and uptime outrank confidentiality. Aggressive active scans can stall programmable logic controllers, and many controllers cannot be patched on an IT schedule.
  • Answers that fit OT favor passive monitoring, strict segmentation and documented compensating controls when you cannot patch.

Drill: architecture and logging

Read what the environment in the stem has to protect and log before you weigh the designs.

Ticket 1 / 15

0 right

INC-001

Logs show different timezones and NTP drift. What produces the accurate incident timeline?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ARebooting does not fix timestamps already written to the logs, and it destroys volatile evidence.
  2. BIgnoring known clock drift leaves events in the wrong order.
  3. CComparing local times from different time zones is exactly what scrambles the timeline.
  4. DCorrect: Converting every timestamp to UTC and correcting for each source's recorded clock offset puts events from all systems on one accurate timeline.

INC-002

Which metadata schema best preserves original device timestamps for forensic correlation while supporting efficient SIEM queries?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AWithout a delay field or a normalized UTC time, events cannot be ordered across sources or checked for late arrival.
  2. BConverting to the server's local time at ingestion discards the original device timestamp that forensics needs.
  3. CCorrect: Keeping the original device timestamp, the ingestion timestamp, the delay between them and a normalized UTC field preserves the evidence while letting the SIEM query on one consistent clock.
  4. DA device timestamp with only a time zone string forces conversion at query time and omits the ingestion details.

INC-003

Based on the telemetry source comparison matrix, which forensic evidence is permanently lost if an organization relies solely on on-premises firewall logs during a cloud incident?

Exhibit

Log SourceEvent VisibilityNetwork ContextManagement Context
On-Premise FirewallTraffic Permitted/DeniedSource/Dest IPsNone
Cloud Control PlaneAPI InvocationsSource IPResource Alterations

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Only the cloud control plane records management activity such as IAM policy changes and resource modifications, and the firewall logs show no management context at all.
  2. BNeither source in the table records payload volume, so this is not what relying on the firewall loses; the gap unique to the cloud source is management activity.
  3. CThe firewall logs include source and destination IPs, so outbound destinations are still visible.
  4. DFirewalls record permitted and denied traffic for inbound flows, so this connection data is still available.

INC-004

An organization suspects that advanced threat actors have compromised high-level cloud administrative credentials. How can the security team best architect the environment to prevent the attackers from deleting the control-plane audit trails?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Shipping logs to a separate account with immutable (write-once) storage puts them out of reach of the compromised admin credentials, so the attackers cannot delete them.
  2. BA customer-managed key protects confidentiality, but an admin who controls the account can still delete the logs or the key.
  3. CIAM read restrictions do not stop a high-level administrator from deleting logs or changing the policies.
  4. DThe hypervisor belongs to the cloud provider and is not a place customers can send logs, and syslog forwarding does not capture control-plane audit trails.

INC-005

A SOC must retain security artifacts from ephemeral container workloads while controlling storage costs. Which retention policy best meets both goals?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ASampling 1 percent of events throws away almost all evidence, including the rare events investigations depend on.
  2. BSeven days is too short for most investigations, which often start weeks after the compromise.
  3. CCorrect: Keeping high-value records such as authentication events and privileged API calls for 90 days while sampling low-value, high-volume events such as image pulls balances forensic value against storage cost.
  4. DKeeping every log for a year with no sampling preserves evidence but ignores the cost goal.

INC-006

An organization runs both long-lived virtual machines and short-lived serverless functions. Which observability approach provides the best balance of visibility, cost, and performance?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ATracing every invocation adds cost and latency to functions that may run millions of times.
  2. BTurning off instrumentation leaves serverless workloads with no visibility at all.
  3. CCorrect: Short-lived functions suit lightweight, function-level tracing, while long-running VMs can carry full agents, so each workload gets visibility at a reasonable cost.
  4. DServerless platforms often cannot host full agents, and where they can, agents slow startup and add cost.

INC-007

An organization experiences frequent client certificate errors after enabling blanket TLS inspection. Which policy change best preserves detection value while minimizing operational and compliance risk?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AInspecting only internal servers leaves outbound traffic, where most threats arrive, unexamined.
  2. BCorrect: Decrypting only high-risk categories while exempting regulated traffic, such as health or banking sites, keeps detection where it matters and avoids compliance problems and broken connections.
  3. CAccepting certificate errors disrupts users and teaches them to click through warnings.
  4. DDisabling all inspection removes visibility into threats hidden in encrypted traffic.

INC-008

A TLS interception deployment uses one pre-generated certificate across all inspection points. Which cryptographic failure is most likely to occur?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA larger revocation list is an operational detail, not the main cryptographic risk of a shared key.
  2. BCorrect: If one certificate and private key serve every inspection point, disclosing that key lets an attacker impersonate or decrypt traffic everywhere, so a single leak becomes a systemic compromise.
  3. CSharing a certificate does not reduce validation errors, and fewer errors would not be a failure anyway.
  4. DReusing one certificate does not improve forward secrecy, which depends on ephemeral key exchange.

INC-009

Which security mechanism utilizes a hash of executable files and stores them in a Trusted Platform Module (TPM) instead of employing digital certificates?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Measured boot hashes each boot component and records the values in the TPM so they can be checked later, rather than relying on digital signatures.
  2. BAttestation reports the TPM's measurements to a verifier; it uses the hashes but is not the mechanism that records them.
  3. CSecure boot checks digital signatures on boot components against trusted certificates, which is the approach the question rules out.
  4. DAn HSM is a dedicated device for managing keys, not a boot-integrity mechanism built on the TPM.

INC-010

An organization wants to ensure that only compliant devices can access its internal cloud services. What solution should be implemented to check device compliance before granting access?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: NAC checks a device's posture, such as patch level and security settings, before allowing it to connect.
  2. BA firewall filters traffic by rules but does not assess whether a device is compliant.
  3. CA VPN encrypts the connection but does not check device health on its own.
  4. DAn IDS detects suspicious traffic and does not grant or deny access based on device compliance.

INC-011

After identifying multiple security breaches, an organization decides to implement a solution to control and manage all mobile devices used by employees. This helps ensure that these devices comply with security policies and have the latest security updates. What is this an example of?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAn IDS watches for attacks on the network and does not manage device settings or updates.
  2. BCorrect: MDM enrolls employee mobile devices and enforces security policies, updates and remote actions such as lock or wipe.
  3. CEncryption protects data on the device but does not manage policies or updates.
  4. DFirewall management controls network rule sets and has no say over mobile devices.

INC-012

As an information security analyst, what tool would you use to monitor and manage security policies across different cloud environments?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ASDN separates network control from traffic forwarding; it is not a tool for enforcing security policy across cloud services.
  2. BA VPN creates encrypted tunnels but does not monitor or enforce policy across cloud providers.
  3. CA VPC is an isolated network inside a single cloud provider; it is no policy tool that spans several providers.
  4. DCorrect: A CASB sits between users and cloud services and enforces security policies, such as access rules and DLP, while giving visibility across many cloud environments.

INC-013

Which approach is most effective for monitoring privileged user activities in a security operations environment?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Recording and analyzing privileged sessions captures exactly what administrators did, which is what monitoring privileged activity requires.
  2. BPeriodic access reviews confirm who holds privileges but do not show what those users do with them.
  3. CPassword rotation reduces credential risk but does not monitor activity.
  4. DAwareness training changes behavior over time but provides no monitoring.

INC-014

In your organization, you currently utilize DLP solutions for protecting data in use. Your CISO wants to explore a hardware-based approach for securing cryptographic keys. Which solution involves using a dedicated hardware device to manage and protect keys?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AA self-encrypting drive encrypts its own data but is not a general device for managing keys.
  2. BA TPM is a chip built into one device that protects that device's keys; it is not a dedicated key-management device.
  3. CA TEE is an isolated area inside the processor for running sensitive code, whereas a separate hardware device for managing keys is an HSM.
  4. DCorrect: An HSM is a dedicated, tamper-resistant hardware device built to generate, store and manage cryptographic keys.

INC-015

To ensure compliance with privacy regulations during data collection, organizations should implement a principle that restricts the collection of personal data to what is necessary for the intended purpose. What is this practice called?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. APurpose limitation means data is used only for the purpose it was collected for; limiting how much is collected in the first place is minimization.
  2. BCorrect: Data minimization means collecting only the personal data needed for the stated purpose, a principle written into privacy laws such as the GDPR.
  3. CData masking hides sensitive values, for example in test data, but does not limit what is collected.
  4. DData sovereignty means data is subject to the laws of the country where it is stored.

Shift tally

0 / 0

Carry forward

  • Ask of every log source: is it collected, is it trustworthy, are its clocks right, and is it kept long enough.
  • Cloud questions turn on the difference between control-plane and workload telemetry.
  • ZTNA grants applications, a VPN grants networks, and SASE packages ZTNA with other cloud-delivered services.
  • Next in the domain: indicators of malicious activity, which asks what this telemetry looks like when something is wrong. Machine-assisted analysis of the same data is the subject of AI in security operations.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.