Courseiva

CS0-003 Incident Response and Management Practice Question

A security analyst receives an alert about a possible ransomware outbreak. Which short-term containment action should be performed FIRST to prevent further spread?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the system from the network

Network isolation (disconnecting the affected system from the network) is a quick short-term containment step that stops the ransomware from communicating with C2 or spreading laterally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the user account

    Why it's wrong here

    While disabling the compromised user account can prevent further authenticated access to network resources, it does not stop an active, automated ransomware process already running on the local host. The malware will continue encrypting local files and scanning the subnet regardless of the account's active directory status.

  • ✗

    Rebuild the system

    Why it's wrong here

    Rebuilding the system from a clean image is an eradication and recovery phase action, not an immediate containment step. Performing a rebuild prematurely destroys volatile memory and forensic evidence crucial for determining the root cause and scope of the ransomware infection.

  • ✗

    Update antivirus signatures

    Why it's wrong here

    Updating antivirus signatures is a proactive or detective control that is ineffective against an active, running ransomware payload. This action does not halt the encryption process or prevent lateral movement, and signature-based tools often fail against zero-day ransomware variants already executing in memory.

  • ✓

    Isolate the system from the network

    Why this is correct

    Isolating the affected host from the network is the primary containment step during a ransomware incident. This action immediately halts the propagation of the malware to other network segments, prevents the encryption of mapped network shares, and severs command-and-control (C2) communications required for key exchange.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.