CS0-003 Incident Response and Management Practice Question
After a phishing incident, the security team wants to improve detection of similar attacks in the future. Which THREE actions should the team take as part of post-incident activity? (Choose THREE.)
⚠ Common exam trap
CS0-004 often tests the confusion between containment/recovery actions (disabling accounts, reimaging hosts) and true post-incident improvement activities (lessons learned, detection tuning, intel sharing).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Updating email filtering rules and detection signatures
Option B is correct because updating email filtering rules and detection signatures directly operationalizes the lessons from the phishing incident, enabling future similar messages to be blocked or flagged based on the observed sender, subject, URL, or attachment characteristics. Option C is correct because sharing indicators of compromise (IOCs) such as malicious domains, IP addresses, and file hashes through a threat intelligence platform helps other organizations detect the same campaign and can yield reciprocal intelligence that improves the team's own defenses. Option D is correct because a lessons learned meeting is a core post-incident activity that reviews the timeline, root cause, and response effectiveness to identify concrete process, tooling, and training improvements. Option A is not a post-incident improvement action; disabling accounts is a containment step during the incident, and it does not by itself enhance future detection. Option E is also not a detection improvement; reimaging workstations is an eradication/recovery action for affected hosts and does not build capability to detect similar attacks later.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disabling user accounts that clicked the phishing link
Why it's wrong here
Disabling user accounts immediately after a phishing click is an incident containment measure, not a post-incident improvement. It limits the attacker's potential access and prevents further lateral movement, but it does not modify the underlying email security controls or address the root cause of the phishing delivery. While necessary, this action is reactive and tactical; improvement requires analyzing why the email bypassed existing controls and implementing changes to reduce future risk.
- ✓
Updating email filtering rules and detection signatures
Why this is correct
Updating email filtering rules and detection signatures is a direct, preventive improvement that uses indicators from the phishing campaign (such as sender domain, subject line patterns, and payload hashes) to enhance the email security gateway. This action hardens the environment against similar attacks by proactively blocking malicious emails before they reach users. It is a classic post-incident activity because it closes the specific vulnerability that allowed the phishing email to be delivered, reducing the likelihood of recurrence.
- ✓
Sharing indicators of compromise with other organizations via a threat intelligence platform
Why this is correct
Sharing indicators of compromise (IOCs) via a threat intelligence platform, such as MISP or an ISAC, is a post-incident improvement that expands the security community's collective defense. By publishing the malicious URLs, file hashes, and sender infrastructure, other organizations can update their own detection mechanisms, and in turn, the sharing organization may receive contextual intelligence about the threat actor's tactics, techniques, and procedures (TTPs). This collaborative approach benefits all parties and aligns with post-incident goals of improving resilience against broader campaigns.
- ✓
Conducting a lessons learned meeting to identify process improvements
Why this is correct
Conducting a lessons learned meeting is a structured post-incident review that examines the entire response lifecycle to identify what worked, what did not, and where processes, playbooks, or training need refinement. It goes beyond technical fixes by addressing human factors, procedural gaps, and communication breakdowns that contributed to the incident's impact. This meeting ensures that findings are documented and actionable, directly feeding into the continuous improvement of the incident response plan and security posture.
- ✗
Reimaging all affected workstations
Why it's wrong here
Reimaging affected workstations is an eradication and recovery action that restores systems to a known-good state, but it does not improve the organization's ability to prevent or detect future phishing attacks. This step is essential for removing malware and ensuring the integrity of endpoints, but it is a corrective measure for the current incident, not a forward-looking improvement. The distinction is critical: recovery restores operations, while improvement enhances security controls, which is why reimaging does not address the root cause or update defenses.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.