Courseiva

CS0-003 Incident Response and Management Practice Question

A security analyst is responding to a potential data exfiltration incident. As part of the containment strategy, the analyst must preserve evidence. Which TWO actions should the analyst take before containment? (Select two.)

⚠ Common exam trap

CS0-004 often tests the sequence of incident response phases, and candidates confuse containment actions (disconnecting, killing processes, changing passwords) with evidence preservation, picking a containment step that destroys the very evidence the question asks them to save.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture a forensic image of the affected systems

Option A is correct because capturing a forensic image of the affected systems creates a bit-for-bit copy of volatile and non-volatile data (using tools like dd, FTK Imager, or EnCase) that preserves evidence in its original state before any containment actions alter the system. Option D is correct because recording current active network connections (e.g., via netstat, ss, or Get-NetTCPConnection) captures volatile evidence such as established sessions, remote IP addresses, and ports that would be lost once the system is isolated or processes are terminated. Option B is not appropriate because changing passwords modifies system state and can destroy evidence of credential compromise or attacker persistence. Option C is a containment action itself, not an evidence-preservation step, and would eliminate live network artifacts. Option E is also a containment/remediation action that destroys volatile memory evidence such as running processes and their associated network connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Capture a forensic image of the affected systems

    Why this is correct

    Capturing a forensic image of affected systems is the correct first step because it creates a bit-for-bit copy of the storage media while preserving file slack, unallocated space, and metadata. Using a hardware write-blocker and cryptographic hashing ensures the evidence remains intact and tamper-proof for later analysis. This action is essential for identifying how the data exfiltration occurred, which files were accessed, and what remnants remain, all without altering the original source.

  • ✗

    Change passwords for affected accounts

    Why it's wrong here

    Changing passwords for affected accounts is a containment and recovery measure, not an evidence preservation step. Password resets modify authentication logs and Kerberos/Authentication tokens, potentially destroying the very artifacts needed to trace an attacker's lateral movement or account hijacking. In incident response, credential rotation should be performed only after forensic data is captured, so that the evidence of the compromise remains pristine for legal or investigative review.

  • ✗

    Disconnect the system from the network

    Why it's wrong here

    Disconnecting the system from the network is a vital containment action to stop ongoing data exfiltration, but it is not the immediate priority in the preservation phase. Network isolation abruptly terminates live connections, causing volatile evidence such as active TCP/UDP sessions, ephemeral ports, and in-memory network buffers to be lost forever. It may also trigger remote kill-switches or anti-forensic routines, so it should be executed only after volatile data and forensic images have been collected.

  • ✓

    Record current active network connections

    Why this is correct

    Recording current active network connections is a critical evidence preservation technique because this volatile data disappears the moment the system is rebooted, disconnected, or the attacker cleans up. Documenting netstat output, established connections, remote IPs, ports, and associated process IDs provides a snapshot of potential command-and-control or exfiltration channels. This is a low-impact, non-destructive step that must occur before any containment action that would disrupt the network stack.

  • ✗

    Kill malicious processes

    Why it's wrong here

    Killing malicious processes is a classic mistake because it destroys the volatile memory footprint of the malware, including injected code, decrypted payloads, API calls, and encryption keys. Terminating a process may also trigger self-deletion or anti-forensic mechanisms, erasing the very evidence needed to determine how data was exfiltrated. Instead, a memory dump should be collected first; only after forensic preservation should the process be safely stopped as part of containment.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.