Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

An incident response team is handling a ransomware incident. The team has successfully contained the threat and is now in the eradication phase. Which THREE actions are appropriate for the eradication phase? (Select THREE.)

⚠ Common exam trap

CAS-005 often tests the confusion between eradication and recovery phases, where candidates incorrectly select recovery actions like restoring from backups as part of eradication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply security patches to the vulnerability that allowed initial access

In the eradication phase, the goal is to remove the threat and close the attack vector, so option B is correct because applying security patches to the vulnerability that allowed initial access eliminates the root cause and prevents reinfection. Option C is correct because revoking and resetting all compromised user and service accounts removes adversary persistence and stops further unauthorized access using stolen credentials. Option D is correct because deleting all infected files and registry keys associated with the ransomware removes malicious artifacts and persistence mechanisms from affected systems. Option A is not appropriate here because restoring systems from clean backups is a recovery-phase action performed after eradication, and option E is not appropriate because conducting a lessons learned meeting occurs in the post-incident activity phase after recovery is complete.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore systems from clean backups

    Why it's wrong here

    Restoring from clean backups is a recovery-phase activity that returns production services, whereas eradication removes malware, closes the initial access vector and hardens systems before restoration begins. It is tempting because clean backups are essential to ransomware response, and it would be correct once eradication is verified complete.

  • ✓

    Apply security patches to the vulnerability that allowed initial access

    Why this is correct

    Patching the exploited vulnerability removes the initial access vector, preventing re-compromise during recovery. Eradication requires eliminating the root cause, so remediation of the flaw that permitted entry is a core action, distinct from containment or recovery tasks.

  • ✓

    Revoke and reset all compromised user and service accounts

    Why this is correct

    Resetting compromised credentials removes the attacker's persistent access, a core eradication goal after containment. Revoking sessions and rotating service account secrets eliminates the foothold the ransomware operator retains, preventing reinfection during recovery and satisfying the requirement to eliminate adversary presence from the environment.

  • ✓

    Delete all infected files and registry keys associated with the ransomware

    Why this is correct

    Removing infected files and associated registry keys eliminates the ransomware's persistence mechanisms and malicious artefacts from affected hosts. This directly fulfils eradication's objective of deleting the threat's components so it cannot execute again, rather than merely isolating systems as containment would.

  • ✗

    Conduct a lessons learned meeting

    Why it's wrong here

    A lessons learned meeting belongs to the post-incident review phase, after recovery is complete, so holding it during eradication misorders the lifecycle. It is tempting because documenting findings feels valuable throughout, and it would be correct once systems are restored and the incident is formally closed.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.