Courseiva
hardMultiple Choice

CS0-003 Practice Question: After a data breach involving customer PII, the…

After a data breach involving customer PII, the incident response team has contained the incident and eradicated the malware. What is the NEXT step in the remediation process?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Close the vulnerability that was exploited.

After containment and eradication, the next step in the remediation process is to close the vulnerability that was exploited. This prevents the attacker from re-entering through the same vector. Conducting a root cause analysis (C) is part of the post-incident review, not the immediate next step. Notifying affected customers (D) is a legal/compliance step that occurs later in the process. Restoring systems from clean backups (B) is part of the recovery phase, which typically occurs after closing the vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Close the vulnerability that was exploited.

    Why this is correct

    During the eradication phase of incident response, the primary objective is to eliminate the root components of the threat. Patching or closing the exploited vulnerability must occur before system restoration to prevent attackers from immediately re-entering the network. This ensures the environment is secure before returning to normal operations.

  • ✗

    Restore systems from clean backups.

    Why it's wrong here

    Restoring systems from backups is a recovery phase activity that should only occur after eradication is complete. If systems are restored while the vulnerability remains unpatched, the threat actor can easily compromise the newly restored systems again. Therefore, this step must be deferred until the entry vector is fully secured.

  • ✗

    Conduct a root cause analysis.

    Why it's wrong here

    Conducting a root cause analysis (RCA) is a critical component of the post-incident activity (lessons learned) phase. While highly valuable for long-term security posture improvement, it is performed after the threat has been fully eradicated and systems are recovered. It is not an immediate containment or eradication action.

  • ✗

    Notify all affected customers.

    Why it's wrong here

    Customer notification is a regulatory and compliance requirement that occurs during the post-incident phase, once the scope of the breach is fully understood. Initiating notifications prematurely, before the vulnerability is closed and the incident is contained, can lead to inaccurate disclosures and further reputational damage.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.