hardMultiple Choice
CS0-003 Practice Question: A company's incident response team is handling a…
A company's incident response team is handling a ransomware incident that has encrypted all files on the file server and spread to several workstations. The team has isolated the affected systems and obtained memory dumps and disk images. The CEO demands immediate restoration of operations and suggests paying the ransom to decrypt files quickly. The company has recent backups but they are stored on a network share that was also encrypted. The CISO wants to ensure that the root cause is identified before restoration. As the lead incident responder, which of the following actions should you take NEXT?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the memory dumps to identify the infection vector and check for persistence mechanisms
Analyzing the memory dumps will help identify the initial infection vector (e.g., phishing email, exploited vulnerability) and any persistence mechanisms. This information is critical to prevent reinfection after restoration. Options A, B, and C skip root cause analysis, risking reinfection. Option A is ill-advised and may not work. Option B involves restoring to a clean environment but still requires root cause analysis to ensure the environment is secure. Option C is premature as it does not identify the root cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom and then restore from the decrypted files
Why it's wrong here
Paying the ransom funds criminals, does not guarantee decryption keys, and skips the root-cause analysis the CISO mandated. It is tempting because it appears to restore operations fastest under CEO pressure, and it would only be considered when no viable backups or decryption options exist and legal guidance permits it.
- ✗
Restore the backups to a clean environment and then reimage the affected systems
Why it's wrong here
Restoring backups now skips root-cause analysis, which the CISO requires before restoration; the encrypted network share also means those backups may be unusable or compromised. This suits recovery once the initial access vector is confirmed and eradicated, not containment-stage investigation.
- ✗
Immediately reimage all affected systems and restore from the most recent clean backups
Why it's wrong here
Reimaging and restoring immediately destroys volatile evidence and bypasses the root-cause identification the CISO demanded, risking reinfection from the same vector. It is tempting because it is standard recovery practice, and it would be correct after containment, eradication and root-cause analysis are complete.
- ✓
Analyze the memory dumps to identify the infection vector and check for persistence mechanisms
Why this is correct
Memory dumps preserve volatile evidence such as running processes, injected code and persistence mechanisms that identify the infection vector. Analysing them before restoration satisfies the CISO's requirement to establish root cause, preventing re-infection once systems are rebuilt from backups.
Go deeper
Related to this question
Learn chapter
Web Application Vulnerability Scanning
Key term
Root cause analysis
Root cause analysis is a systematic process used to identify the fundamental underlying cause of a problem, rather than just treating its symptoms.
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.