Courseiva
Security Operations →hardMultiple Select

CAS-004 Security Operations Practice Question

During an incident response, a team is prioritizing containment actions. Which THREE of the following actions should be taken to contain the incident effectively?

⚠ Common exam trap

CAS-005 often tests the distinction between containment and other incident response phases, and candidates frequently select evidence collection or legal notification as containment actions when they are actually part of investigation or communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blocking malicious IP addresses at the firewall

Option A is correct because blocking malicious IP addresses at the firewall is a direct, immediate containment action that severs the attacker's command-and-control or exfiltration channel at the network perimeter, preventing further ingress or egress. Option D is correct because isolating affected systems from the network (e.g., VLAN quarantine, disabling switch ports, or pulling the cable) stops lateral movement and prevents the compromised hosts from infecting other assets while preserving their state for later analysis. Option E is correct because disabling compromised user accounts (e.g., resetting credentials and revoking sessions/tokens in Active Directory or the IdP) contains the incident by cutting off the attacker's authenticated access and halting further abuse of those identities. Option B does not belong because notifying law enforcement is an external communication/coordination step, not a technical containment action, and it typically occurs after containment or per legal guidance. Option C does not belong because collecting forensic images is evidence preservation and investigation work that, while important, is not itself a containment measure and is often performed after systems are isolated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Blocking malicious IP addresses at the firewall

    Why this is correct

    Blocking malicious IP addresses at the firewall satisfies the containment constraint by severing the network path attackers use for command-and-control and lateral movement. Perimeter filtering stops inbound exploitation attempts and outbound callbacks immediately, limiting blast radius while forensic investigation continues. This is a standard, reversible containment action that preserves evidence on affected hosts.

  • ✗

    Notifying law enforcement

    Why it's wrong here

    Law enforcement notification is an external communication step, typically deferred until containment is complete and evidence preserved. It is tempting because regulatory or legal duties may require it, but it does not itself halt an active intrusion.

  • ✗

    Collecting forensic images of affected systems

    Why it's wrong here

    Collecting forensic images preserves evidence for later analysis; it does not stop the spread of an active threat, so containment remains unachieved. It is tempting because imaging is central to digital forensics and would be the right choice during evidence-gathering or post-incident investigation, once containment has already isolated affected systems.

  • ✓

    Isolating affected systems from the network

    Why this is correct

    Isolating affected systems from the network severs the attacker's command-and-control and lateral-movement paths, directly satisfying the stem's containment objective. It limits blast radius while preserving volatile evidence for later forensic analysis, unlike eradication or recovery actions that alter state. This makes it a core containment step during active incident response.

  • ✓

    Disabling compromised user accounts

    Why this is correct

    Disabling compromised accounts revokes the attacker's authenticated access, blocking further use of stolen credentials for lateral movement or persistence. This satisfies containment by cutting off an active access path while the team resets credentials and investigates scope.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.