CS0-003 Incident Response and Management Practice Question
A security operations center (SOC) analyst receives an alert about a potential ransomware infection on a critical server. The incident response team needs to contain the threat quickly. Which of the following should be performed FIRST as a short-term containment measure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the affected network segment
Short-term containment focuses on immediate isolation to prevent further damage. Isolating the affected network segment stops the ransomware from spreading to other systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account associated with the alert
Why it's wrong here
While disabling the compromised user account can prevent further unauthorized authentication attempts, it does not stop active, automated malware processes already running on the server. If ransomware is actively encrypting files or spreading via local system privileges, disabling the user account will fail to halt the immediate threat. Network isolation must take precedence to contain the active payload.
- ✗
Run a full antivirus scan on the server
Why it's wrong here
Running an antivirus scan is a diagnostic and detective measure rather than an active containment strategy. Furthermore, modern ransomware often employs evasion techniques, such as living-off-the-land binaries or memory-only execution, which standard signature-based antivirus tools may fail to detect. Initiating a scan during an active outbreak wastes critical response time while the malware continues to propagate.
- ✓
Isolate the affected network segment
Why this is correct
Isolating the affected network segment is the most effective short-term containment action to prevent the lateral movement of ransomware to other critical systems. By restricting network traffic at the switch, router, or firewall level, the analyst halts the spread of the infection while preserving the volatile memory of the affected server for subsequent forensic analysis.
- ✗
Rebuild the server from a clean backup
Why it's wrong here
Rebuilding the server from a known-good backup is a recovery phase activity, not an immediate containment action. Attempting to restore systems before the threat has been fully contained and the root cause identified can lead to reinfection if the malware is still active on the network. Additionally, premature rebuilding destroys volatile forensic evidence needed to understand the attack vector.
Go deeper
Related to this question
Learn chapter
Geolocation Analysis in Threat Hunting
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.