mediumMultiple Choice
CS0-003 Practice Question: A security analyst receives an alert from the…
A security analyst receives an alert from the HIDS indicating that a critical configuration file was modified unexpectedly. What is the best immediate action?
⚠ Common exam trap
The CS0-004 exam often tests the principle that immediate remediation (reverting or restoring) is not the best first step; candidates mistakenly jump to containment actions without validating whether the change was authorized, confusing incident response speed with due diligence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the change management system to see if the change was approved
The best immediate action when a HIDS alerts on a critical configuration file change is to first verify whether the change was authorized through the change management system. This aligns with the incident response process of validation before remediation; reverting or restoring without checking could disrupt approved maintenance or patch deployments. HIDS monitors file integrity via checksums (e.g., SHA-256), but it cannot distinguish approved changes from malicious ones without external context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the alert as HIDS false positives are common
Why it's wrong here
Ignoring HIDS alerts, even those with a high false positive rate, is a critical security lapse that can lead to severe consequences. While HIDS can be noisy, dismissing an alert without proper investigation risks overlooking a genuine compromise, allowing an attacker to persist or escalate privileges undetected within the environment. A robust incident response methodology mandates investigation of all security alerts to determine their true nature and potential impact.
- ✗
Immediately revert the file and block any similar changes
Why it's wrong here
Immediately reverting a file and blocking similar changes without prior investigation is an overly aggressive and potentially disruptive action. Such a premature response could undo legitimate system updates, authorized configuration changes, or even critical application modifications, causing operational outages or data integrity issues. Proper incident response prioritizes validation and impact assessment before implementing remediation to avoid unintended consequences and maintain business continuity.
- ✓
Check the change management system to see if the change was approved
Why this is correct
Checking the change management system is the most appropriate initial step because it directly addresses the legitimacy of the HIDS alert. This action allows the analyst to quickly determine if the detected file modification was an authorized, pre-approved change or an unauthorized, potentially malicious event. Validating against a known baseline of approved changes is crucial for efficient and accurate incident triage, preventing unnecessary escalation for legitimate activities.
- ✗
Restore the file from a known good backup
Why it's wrong here
Restoring a file from a known good backup prematurely, without first verifying the nature of the change, carries significant risks and can exacerbate issues. This action could inadvertently overwrite legitimate system updates, configuration changes, or user data that were properly approved through the change management process. Such an irreversible step should only be taken after confirming malicious intent, assessing the full impact of the restoration, and ensuring no authorized work is undone.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.