mediumMultiple Select
CS0-003 A phishing incident led to credential theft Practice Question
A phishing incident led to credential theft. Which containment actions are appropriate? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between 'containment' (stopping the attack) and 'eradication' (removing the root cause), and the trap here is that candidates may choose overly aggressive actions like deleting mailboxes or disabling DNS, mistaking brute-force disruption for precise containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset affected credentials and revoke active sessions
Immediately resetting compromised credentials and revoking active sessions (e.g., via Microsoft Entra ID 'Revoke-AzureADUserAllRefreshToken' or Active Directory 'Reset-ADAccountPassword' combined with 'Revoke-AuthenticationTokens') invalidates the attacker's access tokens and session cookies, preventing further lateral movement or data exfiltration. This aligns with the NIST SP 800-61 containment phase, which prioritizes cutting off attacker access while preserving forensic evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reset affected credentials and revoke active sessions
Why this is correct
Resetting the compromised user's password prevents the attacker from authenticating again using the stolen credentials. Crucially, revoking active sessions, such as OAuth refresh tokens or active web sessions, invalidates any existing session cookies and immediately ejects the threat actor from the environment. Without session revocation, the attacker could maintain access despite the password change.
- ✗
Delete all user mailboxes
Why it's wrong here
Deleting all user mailboxes is an extreme, destructive action that causes massive business disruption and permanently destroys critical forensic evidence needed for the incident investigation. Incident responders must preserve mailbox data, logs, and headers to trace the scope of the phishing campaign rather than deleting the infrastructure.
- ✗
Disable DNS for the entire company indefinitely
Why it's wrong here
Disabling DNS for the entire organization is a highly disproportionate response that completely halts business operations and internet connectivity. While isolating specific compromised hosts or blocking malicious domains is standard containment, a blanket, indefinite DNS shutdown causes self-inflicted denial of service without addressing the root credential theft.
- ✓
Search for mailbox rules or OAuth grants created after compromise
Why this is correct
Threat actors frequently establish persistence by creating inbox forwarding rules to exfiltrate data or by authorizing malicious OAuth applications to bypass future password resets. Auditing and removing these post-compromise configurations is a vital containment step to ensure the attacker cannot silently maintain access or continue harvesting emails after credentials are secured.
Go deeper
Related to this question
Learn chapter
Phishing Email Analysis Techniques
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.