mediumMultiple ChoiceObjective-mapped
First Step in Incident Response: Containment for CASP+
A security analyst discovers that an employee has been using a personal USB drive to transfer sensitive customer data from a workstation to a home computer. This violates the company's data handling policy. According to the company's incident response plan, which of the following is the FIRST step the analyst should take?
Quick Answer
The answer is to isolate the workstation from the network. This is the correct first step because incident response first step containment prioritizes stopping the immediate threat before any other action, such as investigation or evidence collection. By disconnecting the workstation, you prevent further data exfiltration via the personal USB drive and block any potential lateral movement if the drive introduced malware, directly aligning with the containment phase of the NIST SP 800-61 lifecycle. On the CompTIA SecurityX CAS-004 exam, this scenario tests your ability to prioritize containment over eradication or recovery, a common trap where students mistakenly choose to confiscate the drive or interview the employee first. Remember, in incident response, you must contain before you collect. A simple memory tip: “Contain the pain before you explain the stain.”
⚠ Common exam trap
CompTIA often tests the candidate's ability to prioritize containment over investigation or notification, trapping those who confuse the order of the incident response phases (e.g., jumping to forensic analysis or legal escalation before stopping the bleeding).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network
The first priority in any incident response is containment to prevent further data loss or network propagation. Isolating the workstation from the network (Option B) immediately stops the employee from exfiltrating additional data and prevents any potential lateral movement by malware that might be on the USB drive. This aligns with the NIST SP 800-61 incident response lifecycle, where containment precedes eradication and recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a forensic analysis of the workstation
Why it's wrong here
Forensics should follow containment to preserve evidence.
- ✓
Isolate the workstation from the network
Why this is correct
Isolation contains the incident and prevents further data transfer.
- ✗
Escalate the incident to the data protection officer (DPO)
Why it's wrong here
Escalation is important, but containment should come first.
- ✗
Notify law enforcement
Why it's wrong here
Law enforcement notification is not the first step.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CAS-005
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. A security analyst reviews the firewall logs and sees traffic from 192.168.1.200 to the database server 10.0.0.10 on TCP port 1433. 192.168.1.200 is not in the approved IP list for database access. What is the BEST immediate action?
medium- A.Investigate the source host for malware
- B.Disable the database server
- C.Review the database access rules
- ✓ D.Block the source IP on the firewall
Why D: The immediate priority is to stop the unauthorized access attempt. Blocking the source IP (192.168.1.200) on the firewall is the fastest and most effective way to prevent further traffic to the database server on TCP port 1433 (Microsoft SQL Server). This action directly enforces the access control policy without disrupting legitimate services or requiring a lengthy investigation first.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.