CS0-003 Incident Response and Management Practice Question
A security analyst is responding to a potential data exfiltration incident. As part of the containment strategy, the analyst must preserve evidence. Which TWO actions should the analyst take before containment? (Select two.)
⚠ Common exam trap
CS0-004 often tests the sequence of incident response phases, and candidates confuse containment actions (disconnecting, killing processes, changing passwords) with evidence preservation, picking a containment step that destroys the very evidence the question asks them to save.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture a forensic image of the affected systems
Option A is correct because capturing a forensic image of the affected systems creates a bit-for-bit copy of volatile and non-volatile data (using tools like dd, FTK Imager, or EnCase) that preserves evidence in its original state before any containment actions alter the system. Option D is correct because recording current active network connections (e.g., via netstat, ss, or Get-NetTCPConnection) captures volatile evidence such as established sessions, remote IP addresses, and ports that would be lost once the system is isolated or processes are terminated. Option B is not appropriate because changing passwords modifies system state and can destroy evidence of credential compromise or attacker persistence. Option C is a containment action itself, not an evidence-preservation step, and would eliminate live network artifacts. Option E is also a containment/remediation action that destroys volatile memory evidence such as running processes and their associated network connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Capture a forensic image of the affected systems
Why this is correct
Capturing a forensic image of affected systems is the correct first step because it creates a bit-for-bit copy of the storage media while preserving file slack, unallocated space, and metadata. Using a hardware write-blocker and cryptographic hashing ensures the evidence remains intact and tamper-proof for later analysis. This action is essential for identifying how the data exfiltration occurred, which files were accessed, and what remnants remain, all without altering the original source.
- ✗
Change passwords for affected accounts
Why it's wrong here
Changing passwords for affected accounts is a containment and recovery measure, not an evidence preservation step. Password resets modify authentication logs and Kerberos/Authentication tokens, potentially destroying the very artifacts needed to trace an attacker's lateral movement or account hijacking. In incident response, credential rotation should be performed only after forensic data is captured, so that the evidence of the compromise remains pristine for legal or investigative review.
- ✗
Disconnect the system from the network
Why it's wrong here
Disconnecting the system from the network is a vital containment action to stop ongoing data exfiltration, but it is not the immediate priority in the preservation phase. Network isolation abruptly terminates live connections, causing volatile evidence such as active TCP/UDP sessions, ephemeral ports, and in-memory network buffers to be lost forever. It may also trigger remote kill-switches or anti-forensic routines, so it should be executed only after volatile data and forensic images have been collected.
- ✓
Record current active network connections
Why this is correct
Recording current active network connections is a critical evidence preservation technique because this volatile data disappears the moment the system is rebooted, disconnected, or the attacker cleans up. Documenting netstat output, established connections, remote IPs, ports, and associated process IDs provides a snapshot of potential command-and-control or exfiltration channels. This is a low-impact, non-destructive step that must occur before any containment action that would disrupt the network stack.
- ✗
Kill malicious processes
Why it's wrong here
Killing malicious processes is a classic mistake because it destroys the volatile memory footprint of the malware, including injected code, decrypted payloads, API calls, and encryption keys. Terminating a process may also trigger self-deletion or anti-forensic mechanisms, erasing the very evidence needed to determine how data was exfiltrated. Instead, a memory dump should be collected first; only after forensic preservation should the process be safely stopped as part of containment.
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Containment strategy
A containment strategy is a set of actions taken during a security incident to stop the threat from spreading or causing further damage while preserving evidence for analysis.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.