hardMultiple Choice
CS0-003 Practice Question: After a data breach involving customer PII, the…
After a data breach involving customer PII, the incident response team has contained the incident and eradicated the malware. What is the NEXT step in the remediation process?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Close the vulnerability that was exploited.
After containment and eradication, the next step in the remediation process is to close the vulnerability that was exploited. This prevents the attacker from re-entering through the same vector. Conducting a root cause analysis (C) is part of the post-incident review, not the immediate next step. Notifying affected customers (D) is a legal/compliance step that occurs later in the process. Restoring systems from clean backups (B) is part of the recovery phase, which typically occurs after closing the vulnerability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Close the vulnerability that was exploited.
Why this is correct
During the eradication phase of incident response, the primary objective is to eliminate the root components of the threat. Patching or closing the exploited vulnerability must occur before system restoration to prevent attackers from immediately re-entering the network. This ensures the environment is secure before returning to normal operations.
- ✗
Restore systems from clean backups.
Why it's wrong here
Restoring systems from backups is a recovery phase activity that should only occur after eradication is complete. If systems are restored while the vulnerability remains unpatched, the threat actor can easily compromise the newly restored systems again. Therefore, this step must be deferred until the entry vector is fully secured.
- ✗
Conduct a root cause analysis.
Why it's wrong here
Conducting a root cause analysis (RCA) is a critical component of the post-incident activity (lessons learned) phase. While highly valuable for long-term security posture improvement, it is performed after the threat has been fully eradicated and systems are recovered. It is not an immediate containment or eradication action.
- ✗
Notify all affected customers.
Why it's wrong here
Customer notification is a regulatory and compliance requirement that occurs during the post-incident phase, once the scope of the breach is fully understood. Initiating notifications prematurely, before the vulnerability is closed and the incident is contained, can lead to inaccurate disclosures and further reputational damage.
Go deeper
Related to this question
Learn chapter
Zero-Day Vulnerability Response
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.