Courseiva
mediumMultiple Choice

CS0-003 Practice Question: A security analyst receives an alert from the…

A security analyst receives an alert from the HIDS indicating that a critical configuration file was modified unexpectedly. What is the best immediate action?

⚠ Common exam trap

The CS0-004 exam often tests the principle that immediate remediation (reverting or restoring) is not the best first step; candidates mistakenly jump to containment actions without validating whether the change was authorized, confusing incident response speed with due diligence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the change management system to see if the change was approved

The best immediate action when a HIDS alerts on a critical configuration file change is to first verify whether the change was authorized through the change management system. This aligns with the incident response process of validation before remediation; reverting or restoring without checking could disrupt approved maintenance or patch deployments. HIDS monitors file integrity via checksums (e.g., SHA-256), but it cannot distinguish approved changes from malicious ones without external context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ignore the alert as HIDS false positives are common

    Why it's wrong here

    Ignoring HIDS alerts, even those with a high false positive rate, is a critical security lapse that can lead to severe consequences. While HIDS can be noisy, dismissing an alert without proper investigation risks overlooking a genuine compromise, allowing an attacker to persist or escalate privileges undetected within the environment. A robust incident response methodology mandates investigation of all security alerts to determine their true nature and potential impact.

  • ✗

    Immediately revert the file and block any similar changes

    Why it's wrong here

    Immediately reverting a file and blocking similar changes without prior investigation is an overly aggressive and potentially disruptive action. Such a premature response could undo legitimate system updates, authorized configuration changes, or even critical application modifications, causing operational outages or data integrity issues. Proper incident response prioritizes validation and impact assessment before implementing remediation to avoid unintended consequences and maintain business continuity.

  • ✓

    Check the change management system to see if the change was approved

    Why this is correct

    Checking the change management system is the most appropriate initial step because it directly addresses the legitimacy of the HIDS alert. This action allows the analyst to quickly determine if the detected file modification was an authorized, pre-approved change or an unauthorized, potentially malicious event. Validating against a known baseline of approved changes is crucial for efficient and accurate incident triage, preventing unnecessary escalation for legitimate activities.

  • ✗

    Restore the file from a known good backup

    Why it's wrong here

    Restoring a file from a known good backup prematurely, without first verifying the nature of the change, carries significant risks and can exacerbate issues. This action could inadvertently overwrite legitimate system updates, configuration changes, or user data that were properly approved through the change management process. Such an irreversible step should only be taken after confirming malicious intent, assessing the full impact of the restoration, and ensuring no authorized work is undone.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.