Courseiva
mediumMultiple Select

CS0-003 A phishing incident led to credential theft Practice Question

A phishing incident led to credential theft. Which containment actions are appropriate? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between 'containment' (stopping the attack) and 'eradication' (removing the root cause), and the trap here is that candidates may choose overly aggressive actions like deleting mailboxes or disabling DNS, mistaking brute-force disruption for precise containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reset affected credentials and revoke active sessions

Immediately resetting compromised credentials and revoking active sessions (e.g., via Microsoft Entra ID 'Revoke-AzureADUserAllRefreshToken' or Active Directory 'Reset-ADAccountPassword' combined with 'Revoke-AuthenticationTokens') invalidates the attacker's access tokens and session cookies, preventing further lateral movement or data exfiltration. This aligns with the NIST SP 800-61 containment phase, which prioritizes cutting off attacker access while preserving forensic evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reset affected credentials and revoke active sessions

    Why this is correct

    Resetting the compromised user's password prevents the attacker from authenticating again using the stolen credentials. Crucially, revoking active sessions, such as OAuth refresh tokens or active web sessions, invalidates any existing session cookies and immediately ejects the threat actor from the environment. Without session revocation, the attacker could maintain access despite the password change.

  • ✗

    Delete all user mailboxes

    Why it's wrong here

    Deleting all user mailboxes is an extreme, destructive action that causes massive business disruption and permanently destroys critical forensic evidence needed for the incident investigation. Incident responders must preserve mailbox data, logs, and headers to trace the scope of the phishing campaign rather than deleting the infrastructure.

  • ✗

    Disable DNS for the entire company indefinitely

    Why it's wrong here

    Disabling DNS for the entire organization is a highly disproportionate response that completely halts business operations and internet connectivity. While isolating specific compromised hosts or blocking malicious domains is standard containment, a blanket, indefinite DNS shutdown causes self-inflicted denial of service without addressing the root credential theft.

  • ✓

    Search for mailbox rules or OAuth grants created after compromise

    Why this is correct

    Threat actors frequently establish persistence by creating inbox forwarding rules to exfiltrate data or by authorizing malicious OAuth applications to bypass future password resets. Auditing and removing these post-compromise configurations is a vital containment step to ensure the attacker cannot silently maintain access or continue harvesting emails after credentials are secured.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.