hardMultiple Select
CV0-004 Practice Question: A cloud security team is investigating a…
A cloud security team is investigating a potential data breach. Which THREE actions should be taken immediately?
⚠ Common exam trap
CompTIA often tests the misconception that deleting logs or notifying all users immediately is a valid first response, when in fact containment and evidence preservation are the top priorities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the affected systems from the network
Option B is correct because isolating the affected systems from the network (e.g., by disabling NICs, changing security group rules, or moving instances to a quarantine VLAN) contains the breach and prevents lateral movement or further data exfiltration. Option C is correct because capturing a forensic snapshot of the affected storage preserves volatile and non-volatile evidence in a forensically sound manner, enabling later analysis without altering the original media. Option E is correct because preserving logs and system state (memory dumps, running processes, audit trails) maintains the chain of custody and provides the evidence needed for root-cause analysis and potential legal proceedings. Option A is wrong because deleting logs destroys evidence and may violate legal/regulatory retention requirements. Option D is wrong because mass-emailing all users immediately can tip off the attacker, cause panic, and is not a containment or evidence-preservation step; notifications should follow incident response and legal guidance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete all logs to prevent further evidence exposure
Why it's wrong here
Deleting logs destroys critical forensic evidence.
- ✓
Isolate the affected systems from the network
Why this is correct
Isolation halts ongoing exfiltration and lateral movement, containing the breach before eradication. It satisfies the immediate containment constraint, since live systems must be severed from the network while evidence is still volatile and the attacker may retain access.
- ✓
Capture a forensic snapshot of the affected storage
Why this is correct
A snapshot captures the storage volume's exact state, including deleted files and artefacts, without altering the running system. It satisfies evidence preservation for later forensic analysis, which is impossible once the instance is rebuilt or data overwritten.
- ✗
Notify all users via email
Why it's wrong here
Notification should come after investigation and legal review.
- ✓
Preserve logs and system state
Why this is correct
Logs and volatile system state hold the attacker's activity trail, including authentication events and process artefacts. Preserving them satisfies the evidence-retention constraint, preventing loss through log rotation, instance termination or attacker anti-forensics before the investigation concludes.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.