CS0-003 Incident Response and Management Practice Question
A security analyst receives an alert that a workstation is communicating with a known C2 server over DNS. The analyst wants to quickly isolate the endpoint from the network but keep it powered on for later memory capture. Which of the following actions should the analyst take FIRST?
⚠ Common exam trap
The trap here is assuming that physically unplugging the network cable is always the best first containment step, when a switch port shutdown is often faster and more auditable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Administratively disable the switch port to which the workstation is connected.
Administratively disabling the switch port is the fastest, most controlled way to isolate the endpoint while preserving volatile memory. It stops C2 communication without powering off the system, allowing the analyst to capture RAM and running processes. Physical disconnection or shutdown may lose evidence or be less auditable, and antivirus scanning does not contain the threat. Containment should always precede eradication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Administratively disable the switch port to which the workstation is connected.
Why this is correct
Administratively disabling the switch port immediately stops all network communication from the endpoint while keeping it powered on for memory capture. This method is reversible, logged, and does not require physical access. It also prevents the malware from communicating with the C2 server without alerting the attacker via a full shutdown. This is the most appropriate first containment step.
- ✗
Disconnect the workstation's network cable from the switch port.
Why it's wrong here
Physically disconnecting the cable isolates the endpoint from the network, but it is not the FIRST action if a switch port can be administratively disabled. Physical disconnection may also be slower and less documented than a controlled port shutdown. Additionally, it does not preserve the switch port security logs that could aid in tracing the C2 traffic. The analyst should prefer a network-based containment method that is reversible and logged.
- ✗
Run a full antivirus scan on the workstation to remove the malware.
Why it's wrong here
Running an antivirus scan does not isolate the endpoint from the network, so the C2 communication continues. It also may alter or delete volatile evidence before memory capture. The priority in incident response is to contain the threat before eradication. Scanning is an eradication step, not a containment step, and should occur only after the endpoint is isolated and evidence is preserved.
- ✗
Shut down the workstation to prevent further data exfiltration.
Why it's wrong here
Shutting down the workstation destroys volatile memory, including running processes, network connections, and encryption keys that are critical for forensic analysis. It also may trigger anti-forensic mechanisms in the malware. The goal is to contain without losing evidence, so the endpoint should remain powered on while network-isolated. Shutdown is not appropriate when memory capture is planned.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Memory capture
Memory capture is the process of preserving the contents of a computer's volatile memory (RAM) for forensic analysis during incident response.
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.