Courseiva
hardMultiple Choice

CS0-003 Practice Question: A company's incident response team is handling a…

A company's incident response team is handling a ransomware incident that has encrypted all files on the file server and spread to several workstations. The team has isolated the affected systems and obtained memory dumps and disk images. The CEO demands immediate restoration of operations and suggests paying the ransom to decrypt files quickly. The company has recent backups but they are stored on a network share that was also encrypted. The CISO wants to ensure that the root cause is identified before restoration. As the lead incident responder, which of the following actions should you take NEXT?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyze the memory dumps to identify the infection vector and check for persistence mechanisms

Analyzing the memory dumps will help identify the initial infection vector (e.g., phishing email, exploited vulnerability) and any persistence mechanisms. This information is critical to prevent reinfection after restoration. Options A, B, and C skip root cause analysis, risking reinfection. Option A is ill-advised and may not work. Option B involves restoring to a clean environment but still requires root cause analysis to ensure the environment is secure. Option C is premature as it does not identify the root cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pay the ransom and then restore from the decrypted files

    Why it's wrong here

    Paying the ransom funds criminals, does not guarantee decryption keys, and skips the root-cause analysis the CISO mandated. It is tempting because it appears to restore operations fastest under CEO pressure, and it would only be considered when no viable backups or decryption options exist and legal guidance permits it.

  • ✗

    Restore the backups to a clean environment and then reimage the affected systems

    Why it's wrong here

    Restoring backups now skips root-cause analysis, which the CISO requires before restoration; the encrypted network share also means those backups may be unusable or compromised. This suits recovery once the initial access vector is confirmed and eradicated, not containment-stage investigation.

  • ✗

    Immediately reimage all affected systems and restore from the most recent clean backups

    Why it's wrong here

    Reimaging and restoring immediately destroys volatile evidence and bypasses the root-cause identification the CISO demanded, risking reinfection from the same vector. It is tempting because it is standard recovery practice, and it would be correct after containment, eradication and root-cause analysis are complete.

  • ✓

    Analyze the memory dumps to identify the infection vector and check for persistence mechanisms

    Why this is correct

    Memory dumps preserve volatile evidence such as running processes, injected code and persistence mechanisms that identify the infection vector. Analysing them before restoration satisfies the CISO's requirement to establish root cause, preventing re-infection once systems are rebuilt from backups.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.