CAS-004 Security Operations Practice Question
During an incident response, a team is prioritizing containment actions. Which THREE of the following actions should be taken to contain the incident effectively?
⚠ Common exam trap
CAS-005 often tests the distinction between containment and other incident response phases, and candidates frequently select evidence collection or legal notification as containment actions when they are actually part of investigation or communication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Blocking malicious IP addresses at the firewall
Option A is correct because blocking malicious IP addresses at the firewall is a direct, immediate containment action that severs the attacker's command-and-control or exfiltration channel at the network perimeter, preventing further ingress or egress. Option D is correct because isolating affected systems from the network (e.g., VLAN quarantine, disabling switch ports, or pulling the cable) stops lateral movement and prevents the compromised hosts from infecting other assets while preserving their state for later analysis. Option E is correct because disabling compromised user accounts (e.g., resetting credentials and revoking sessions/tokens in Active Directory or the IdP) contains the incident by cutting off the attacker's authenticated access and halting further abuse of those identities. Option B does not belong because notifying law enforcement is an external communication/coordination step, not a technical containment action, and it typically occurs after containment or per legal guidance. Option C does not belong because collecting forensic images is evidence preservation and investigation work that, while important, is not itself a containment measure and is often performed after systems are isolated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Blocking malicious IP addresses at the firewall
Why this is correct
Blocking malicious IP addresses at the firewall satisfies the containment constraint by severing the network path attackers use for command-and-control and lateral movement. Perimeter filtering stops inbound exploitation attempts and outbound callbacks immediately, limiting blast radius while forensic investigation continues. This is a standard, reversible containment action that preserves evidence on affected hosts.
- ✗
Notifying law enforcement
Why it's wrong here
Law enforcement notification is an external communication step, typically deferred until containment is complete and evidence preserved. It is tempting because regulatory or legal duties may require it, but it does not itself halt an active intrusion.
- ✗
Collecting forensic images of affected systems
Why it's wrong here
Collecting forensic images preserves evidence for later analysis; it does not stop the spread of an active threat, so containment remains unachieved. It is tempting because imaging is central to digital forensics and would be the right choice during evidence-gathering or post-incident investigation, once containment has already isolated affected systems.
- ✓
Isolating affected systems from the network
Why this is correct
Isolating affected systems from the network severs the attacker's command-and-control and lateral-movement paths, directly satisfying the stem's containment objective. It limits blast radius while preserving volatile evidence for later forensic analysis, unlike eradication or recovery actions that alter state. This makes it a core containment step during active incident response.
- ✓
Disabling compromised user accounts
Why this is correct
Disabling compromised accounts revokes the attacker's authenticated access, blocking further use of stolen credentials for lateral movement or persistence. This satisfies containment by cutting off an active access path while the team resets credentials and investigates scope.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.