Courseiva
Security Operations →mediumMultiple Select

CAS-004 Security Operations Practice Question

A company's incident response team is developing a playbook for ransomware incidents. The playbook should cover the preparation phase. Which THREE of the following are appropriate preparation activities? (Choose THREE.)

⚠ Common exam trap

CAS-005 often tests the distinction between preparation and other incident response phases, and candidates may incorrectly classify containment or detection activities as preparation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Train employees on how to recognize and report phishing attempts

Option A is correct because user awareness training on recognizing and reporting phishing is a foundational preparation activity, since phishing is a leading initial access vector for ransomware and trained employees enable earlier detection and response. Option B is correct because regular backup testing and maintaining offline, immutable backups are essential preparation steps that ensure data can be restored without paying a ransom and that backups are not encrypted or deleted by the malware. Option D is correct because establishing communication procedures with legal, PR, and other stakeholders before an incident occurs is a preparation-phase task that supports coordinated, compliant crisis communication during an actual ransomware event. Option C is not a preparation activity but a containment action performed during the detection/response phase after an infection is identified. Option E is not a preparation activity in this context; threat hunting is an ongoing detection operation conducted during normal security monitoring rather than a preparatory step in a ransomware playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Train employees on how to recognize and report phishing attempts

    Why this is correct

    Phishing remains the primary initial access vector for ransomware, so training employees to recognise and report suspicious messages directly reduces the likelihood of successful compromise. This satisfies the preparation phase's requirement to build preventive human controls before an incident occurs, complementing technical safeguards such as email filtering and endpoint detection.

  • ✓

    Conduct regular backup testing and ensure offline backups are available

    Why this is correct

    Regular backup testing with offline copies directly satisfies ransomware resilience: immutable or air-gapped backups cannot be encrypted by the attacker, so restoration remains possible without paying. Testing verifies recovery point and recovery time objectives actually work, converting a documented plan into proven capability during the preparation phase.

  • ✗

    Isolate infected systems from the network immediately after detection

    Why it's wrong here

    Isolation is a containment action executed during detection and analysis, after an incident is confirmed, so it belongs to the response phase rather than preparation. It is the correct answer when the question asks how to stop lateral spread from a system already known to be compromised.

  • ✓

    Develop communication procedures, including legal and PR contacts

    Why this is correct

    Ransomware preparation demands pre-agreed escalation paths, since legal, regulatory notification and PR response decisions must be made under pressure. Documenting contacts and procedures before an incident removes delay and ambiguity, satisfying the playbook's requirement to cover the preparation phase rather than detection or recovery.

  • ✗

    Perform threat hunting in the network to identify potential threats

    Why it's wrong here

    Threat hunting is a continuous detection activity performed during normal operations, not a preparation-phase task defined for a ransomware playbook. It would be correct where the question asks how to proactively uncover existing intrusions that evaded automated detection tooling.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.