CS0-003 Incident Response and Management Practice Question
A security analyst receives an alert about a possible ransomware outbreak. Which short-term containment action should be performed FIRST to prevent further spread?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the system from the network
Network isolation (disconnecting the affected system from the network) is a quick short-term containment step that stops the ransomware from communicating with C2 or spreading laterally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account
Why it's wrong here
While disabling the compromised user account can prevent further authenticated access to network resources, it does not stop an active, automated ransomware process already running on the local host. The malware will continue encrypting local files and scanning the subnet regardless of the account's active directory status.
- ✗
Rebuild the system
Why it's wrong here
Rebuilding the system from a clean image is an eradication and recovery phase action, not an immediate containment step. Performing a rebuild prematurely destroys volatile memory and forensic evidence crucial for determining the root cause and scope of the ransomware infection.
- ✗
Update antivirus signatures
Why it's wrong here
Updating antivirus signatures is a proactive or detective control that is ineffective against an active, running ransomware payload. This action does not halt the encryption process or prevent lateral movement, and signature-based tools often fail against zero-day ransomware variants already executing in memory.
- ✓
Isolate the system from the network
Why this is correct
Isolating the affected host from the network is the primary containment step during a ransomware incident. This action immediately halts the propagation of the malware to other network segments, prevents the encryption of mapped network shares, and severs command-and-control (C2) communications required for key exchange.
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.