CS0-003 Incident Response and Management Practice Question
A security analyst is investigating a phishing incident that resulted in credential theft. Which TWO actions should the analyst take as part of short-term containment? (Choose two.)
⚠ Common exam trap
CS0-004 often tests the distinction between short-term containment and other incident response phases (e.g., eradication, recovery), causing candidates to select remediation actions like rebuilding systems or changing all passwords instead of immediate, targeted containment steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the phishing domain at the email gateway
Option A is correct because blocking the phishing domain at the email gateway is a short-term containment action that immediately prevents additional phishing emails from the same domain from reaching other users and stops further credential harvesting. Option E is correct because disabling the compromised user accounts is a short-term containment step that stops the attacker from using the stolen credentials to access resources, halting ongoing unauthorized activity. Option B is not appropriate here because rebuilding workstations from a clean image is a longer-term eradication and recovery action, and credential theft does not necessarily require reimaging. Option C is not a containment action; a full vulnerability scan is a broader assessment activity that does not stop the active incident. Option D is not the best short-term containment step because changing all domain user passwords is a broad, disruptive action, whereas disabling the specific compromised accounts is more targeted and immediate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block the phishing domain at the email gateway
Why this is correct
Blocking the phishing domain at the email gateway is immediate containment because it prevents subsequent emails carrying the same malicious payload from reaching other recipients, thereby reducing the number of users exposed to the lure. This email gateway control is fast, reversible, and can also block outbound traffic if needed, but it does not remediate credentials that have already been stolen.
- ✗
Rebuild the affected workstations from a clean image
Why it's wrong here
Rebuilding the affected workstations from a clean image is long-term remediation, not immediate containment, because it requires confirming which machines are actually compromised and can take significant time to reimage and reconfigure, leaving users without access. During the acute phase of a phishing incident, the priority is to halt the email campaign and disable compromised accounts, not to rebuild endpoints whose infection status may still be uncertain. This action might become appropriate later for systems that were definitely impacted.
- ✗
Conduct a full vulnerability scan of the network
Why it's wrong here
A full vulnerability scan of the network is an important proactive security measure, but it is not an immediate containment action for an active phishing attack. It identifies missing patch levels and configuration weaknesses without blocking the phishing emails or preventing users from clicking on them, and it does not cut off an attacker already using stolen credentials. Running a large scan could also create network congestion that distracts from the urgent investigation.
- ✗
Change all user passwords in the domain
Why it's wrong here
Forcing a password reset for every user in the domain is too broad for the containment stage because it can lock out unrelated users and may not be necessary if only a small set of accounts are compromised, while it also does not stop additional phishing emails from arriving. Immediate containment should focus on the accounts known to be affected, with a full password reset potentially included later during eradication to ensure no unauthorized sessions persist. This is a broader action that you might take after the initial attack is contained.
- ✓
Disable the compromised user accounts
Why this is correct
Disabling the specific compromised user accounts denies the attacker continued authentication with valid credentials and blocks any active sessions from being reused, cutting off lateral movement and data exfiltration while the investigation proceeds. This targeted control minimizes disruption to the rest of the organization and preserves the account's domain-joined state for forensic analysis. It is a correct and immediate containment step.
Go deeper
Related to this question
Learn chapter
SOC Tier 1, Tier 2, and Tier 3 Analyst Roles
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.