CS0-003 Incident Response and Management Practice Question
After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Updating email filtering rules and detection signatures
Post-incident activities include updating detection rules, sharing IOCs, and conducting lessons learned to improve processes. Reimaging is recovery, and disabling accounts is containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disabling user accounts that clicked the phishing link
Why it's wrong here
Disabling user accounts immediately after a phishing click is an incident containment measure, not a post-incident improvement. It limits the attacker's potential access and prevents further lateral movement, but it does not modify the underlying email security controls or address the root cause of the phishing delivery. While necessary, this action is reactive and tactical; improvement requires analyzing why the email bypassed existing controls and implementing changes to reduce future risk.
- ✓
Updating email filtering rules and detection signatures
Why this is correct
Updating email filtering rules and detection signatures is a direct, preventive improvement that uses indicators from the phishing campaign (such as sender domain, subject line patterns, and payload hashes) to enhance the email security gateway. This action hardens the environment against similar attacks by proactively blocking malicious emails before they reach users. It is a classic post-incident activity because it closes the specific vulnerability that allowed the phishing email to be delivered, reducing the likelihood of recurrence.
- ✓
Sharing indicators of compromise with other organizations via a threat intelligence platform
Why this is correct
Sharing indicators of compromise (IOCs) via a threat intelligence platform, such as MISP or an ISAC, is a post-incident improvement that expands the security community's collective defense. By publishing the malicious URLs, file hashes, and sender infrastructure, other organizations can update their own detection mechanisms, and in turn, the sharing organization may receive contextual intelligence about the threat actor's tactics, techniques, and procedures (TTPs). This collaborative approach benefits all parties and aligns with post-incident goals of improving resilience against broader campaigns.
- ✓
Conducting a lessons learned meeting to identify process improvements
Why this is correct
Conducting a lessons learned meeting is a structured post-incident review that examines the entire response lifecycle to identify what worked, what did not, and where processes, playbooks, or training need refinement. It goes beyond technical fixes by addressing human factors, procedural gaps, and communication breakdowns that contributed to the incident's impact. This meeting ensures that findings are documented and actionable, directly feeding into the continuous improvement of the incident response plan and security posture.
- ✗
Reimaging all affected workstations
Why it's wrong here
Reimaging affected workstations is an eradication and recovery action that restores systems to a known-good state, but it does not improve the organization's ability to prevent or detect future phishing attacks. This step is essential for removing malware and ensuring the integrity of endpoints, but it is a corrective measure for the current incident, not a forward-looking improvement. The distinction is critical: recovery restores operations, while improvement enhances security controls, which is why reimaging does not address the root cause or update defenses.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.