Courseiva

CS0-003 Incident Response and Management Practice Question

A security operations center (SOC) analyst receives an alert about a potential ransomware infection on a critical server. The incident response team needs to contain the threat quickly. Which of the following should be performed FIRST as a short-term containment measure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the affected network segment

Short-term containment focuses on immediate isolation to prevent further damage. Isolating the affected network segment stops the ransomware from spreading to other systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the user account associated with the alert

    Why it's wrong here

    While disabling the compromised user account can prevent further unauthorized authentication attempts, it does not stop active, automated malware processes already running on the server. If ransomware is actively encrypting files or spreading via local system privileges, disabling the user account will fail to halt the immediate threat. Network isolation must take precedence to contain the active payload.

  • ✗

    Run a full antivirus scan on the server

    Why it's wrong here

    Running an antivirus scan is a diagnostic and detective measure rather than an active containment strategy. Furthermore, modern ransomware often employs evasion techniques, such as living-off-the-land binaries or memory-only execution, which standard signature-based antivirus tools may fail to detect. Initiating a scan during an active outbreak wastes critical response time while the malware continues to propagate.

  • ✓

    Isolate the affected network segment

    Why this is correct

    Isolating the affected network segment is the most effective short-term containment action to prevent the lateral movement of ransomware to other critical systems. By restricting network traffic at the switch, router, or firewall level, the analyst halts the spread of the infection while preserving the volatile memory of the affected server for subsequent forensic analysis.

  • ✗

    Rebuild the server from a clean backup

    Why it's wrong here

    Rebuilding the server from a known-good backup is a recovery phase activity, not an immediate containment action. Attempting to restore systems before the threat has been fully contained and the root cause identified can lead to reinfection if the malware is still active on the network. Additionally, premature rebuilding destroys volatile forensic evidence needed to understand the attack vector.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.