CAS-004 Security Operations Practice Question
A security operations team is developing a SOAR playbook to automate response to a detected ransomware outbreak. The team wants to ensure the playbook can contain the threat quickly while minimizing business disruption. Which TWO actions should the playbook include as automated responses? (Select TWO.)
⚠ Common exam trap
Many exam-takers confuse containment with eradication or recovery — candidates pick 'run antivirus' or 'restore backups' because those sound like fixing the problem, but the question asks for immediate containment actions that stop spread without destroying evidence or availability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block outbound traffic to known malicious IP addresses and domains
Option D is correct because blocking outbound traffic to known malicious IP addresses and domains (e.g., via firewall, proxy, or DNS sinkhole rules) severs command-and-control (C2) and exfiltration channels, which is a fast, low-disruption containment action that prevents the ransomware from receiving instructions or leaking data. Option E is correct because isolating affected endpoints from the network (for example, via EDR network containment or switch port/VLAN quarantine) stops lateral movement and further encryption or spread while leaving the hosts powered on for forensic memory capture and recovery. Option A is not appropriate as an automated containment response because a full antivirus scan is slow, resource-intensive, and does not stop an active outbreak. Option B is not appropriate because automatically restoring all systems from backup can overwrite forensic evidence, reintroduce malware if the backup is compromised, and cause major business disruption before the threat is contained. Option C is not appropriate because powering off affected servers immediately destroys volatile memory evidence, can corrupt encrypted or in-flight data, and may disrupt critical services more than isolation would.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on all systems
Why it's wrong here
A full antivirus scan is slow, consumes endpoint resources and does not contain an active ransomware outbreak, so it fails the rapid-containment requirement. It is tempting because scanning is a familiar remediation step, and it would be correct for routine hygiene checks, but the playbook needs immediate isolation and credential revocation.
- ✗
Restore all systems from the latest backup automatically
Why it's wrong here
Restoring from backup before the ransomware is fully eradicated risks reinfection and overwrites forensic evidence, and the stem requires containment first. It is tempting because recovery is the eventual goal, and automated restore is valid after containment and validation, but it is not an initial containment action.
- ✗
Power off all affected servers immediately
Why it's wrong here
Powering off servers destroys volatile memory evidence and halts production workloads, causing the business disruption the playbook must minimise. It is tempting because immediate shutdown feels like decisive containment, and it would suit an isolated lab host, but the correct actions isolate network segments and disable compromised accounts instead.
- ✓
Block outbound traffic to known malicious IP addresses and domains
Why this is correct
Blocking outbound traffic to known malicious IPs and domains via firewall or DNS sinkhole rules halts command-and-control communication and data exfiltration, directly satisfying the containment requirement while leaving internal business services untouched. This limits ransomware spread without disrupting legitimate user access, unlike broad network isolation.
- ✓
Isolate the affected endpoints from the network
Why this is correct
Network isolation severs the ransomware's command-and-control and lateral-movement paths, containing the outbreak before encryption spreads. It satisfies the stem's demand for rapid containment while limiting disruption, since only affected endpoints are cut off rather than halting wider business services.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.