Courseiva
Incident Response and ManagementmediumMultiple SelectObjective-mapped

CS0-003 Incident Response and Management Practice Question

After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Updating email filtering rules and detection signatures

Post-incident activities include updating detection rules, sharing IOCs, and conducting lessons learned to improve processes. Reimaging is recovery, and disabling accounts is containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disabling user accounts that clicked the phishing link

    Why it's wrong here

    Disabling user accounts immediately after a phishing click is an incident containment measure, not a post-incident improvement. It limits the attacker's potential access and prevents further lateral movement, but it does not modify the underlying email security controls or address the root cause of the phishing delivery. While necessary, this action is reactive and tactical; improvement requires analyzing why the email bypassed existing controls and implementing changes to reduce future risk.

  • Updating email filtering rules and detection signatures

    Why this is correct

    Updating email filtering rules and detection signatures is a direct, preventive improvement that uses indicators from the phishing campaign (such as sender domain, subject line patterns, and payload hashes) to enhance the email security gateway. This action hardens the environment against similar attacks by proactively blocking malicious emails before they reach users. It is a classic post-incident activity because it closes the specific vulnerability that allowed the phishing email to be delivered, reducing the likelihood of recurrence.

  • Sharing indicators of compromise with other organizations via a threat intelligence platform

    Why this is correct

    Sharing indicators of compromise (IOCs) via a threat intelligence platform, such as MISP or an ISAC, is a post-incident improvement that expands the security community's collective defense. By publishing the malicious URLs, file hashes, and sender infrastructure, other organizations can update their own detection mechanisms, and in turn, the sharing organization may receive contextual intelligence about the threat actor's tactics, techniques, and procedures (TTPs). This collaborative approach benefits all parties and aligns with post-incident goals of improving resilience against broader campaigns.

  • Conducting a lessons learned meeting to identify process improvements

    Why this is correct

    Conducting a lessons learned meeting is a structured post-incident review that examines the entire response lifecycle to identify what worked, what did not, and where processes, playbooks, or training need refinement. It goes beyond technical fixes by addressing human factors, procedural gaps, and communication breakdowns that contributed to the incident's impact. This meeting ensures that findings are documented and actionable, directly feeding into the continuous improvement of the incident response plan and security posture.

  • Reimaging all affected workstations

    Why it's wrong here

    Reimaging affected workstations is an eradication and recovery action that restores systems to a known-good state, but it does not improve the organization's ability to prevent or detect future phishing attacks. This step is essential for removing malware and ensuring the integrity of endpoints, but it is a corrective measure for the current incident, not a forward-looking improvement. The distinction is critical: recovery restores operations, while improvement enhances security controls, which is why reimaging does not address the root cause or update defenses.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.