CAS-004 Security Operations Practice Question
An incident response team is handling a ransomware incident. The team has successfully contained the threat and is now in the eradication phase. Which THREE actions are appropriate for the eradication phase? (Select THREE.)
⚠ Common exam trap
CAS-005 often tests the confusion between eradication and recovery phases, where candidates incorrectly select recovery actions like restoring from backups as part of eradication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply security patches to the vulnerability that allowed initial access
In the eradication phase, the goal is to remove the threat and close the attack vector, so option B is correct because applying security patches to the vulnerability that allowed initial access eliminates the root cause and prevents reinfection. Option C is correct because revoking and resetting all compromised user and service accounts removes adversary persistence and stops further unauthorized access using stolen credentials. Option D is correct because deleting all infected files and registry keys associated with the ransomware removes malicious artifacts and persistence mechanisms from affected systems. Option A is not appropriate here because restoring systems from clean backups is a recovery-phase action performed after eradication, and option E is not appropriate because conducting a lessons learned meeting occurs in the post-incident activity phase after recovery is complete.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore systems from clean backups
Why it's wrong here
Restoring from clean backups is a recovery-phase activity that returns production services, whereas eradication removes malware, closes the initial access vector and hardens systems before restoration begins. It is tempting because clean backups are essential to ransomware response, and it would be correct once eradication is verified complete.
- ✓
Apply security patches to the vulnerability that allowed initial access
Why this is correct
Patching the exploited vulnerability removes the initial access vector, preventing re-compromise during recovery. Eradication requires eliminating the root cause, so remediation of the flaw that permitted entry is a core action, distinct from containment or recovery tasks.
- ✓
Revoke and reset all compromised user and service accounts
Why this is correct
Resetting compromised credentials removes the attacker's persistent access, a core eradication goal after containment. Revoking sessions and rotating service account secrets eliminates the foothold the ransomware operator retains, preventing reinfection during recovery and satisfying the requirement to eliminate adversary presence from the environment.
- ✓
Delete all infected files and registry keys associated with the ransomware
Why this is correct
Removing infected files and associated registry keys eliminates the ransomware's persistence mechanisms and malicious artefacts from affected hosts. This directly fulfils eradication's objective of deleting the threat's components so it cannot execute again, rather than merely isolating systems as containment would.
- ✗
Conduct a lessons learned meeting
Why it's wrong here
A lessons learned meeting belongs to the post-incident review phase, after recovery is complete, so holding it during eradication misorders the lifecycle. It is tempting because documenting findings feels valuable throughout, and it would be correct once systems are restored and the incident is formally closed.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.