CS0-003 Incident Response and Management Practice Question
An incident responder is classifying an incident. The incident involves ransomware encrypting files on multiple workstations, causing significant business disruption. Which severity level should be assigned to this incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High
Ransomware affecting multiple workstations causes high impact and likely critical business disruption, so it should be classified as high or critical severity. The highest typical level is 'Critical' (or similar).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Medium
Why it's wrong here
A medium-severity classification is reserved for incidents that cause moderate, localized disruption to non-critical systems or business functions. Because ransomware spreading across multiple systems threatens core operations and data integrity, it far exceeds the threshold of a medium-severity event, which typically allows for normal operations to continue with minor workarounds.
- ✓
High
Why this is correct
High-severity incidents involve severe degradation of critical services, widespread compromise, or the encryption of multiple production systems by ransomware. This classification triggers immediate escalation, mobilization of the full incident response team, and containment protocols to prevent catastrophic operational downtime or data loss.
- ✗
Informational
Why it's wrong here
Informational events represent standard, non-threatening log entries, such as successful user logins or routine system updates, that do not indicate unauthorized activity. Classifying an active, multi-system ransomware attack as informational would dangerously ignore a critical security breach that requires immediate containment and eradication.
- ✗
Low
Why it's wrong here
Low-severity incidents involve near-zero operational impact, such as a single user experiencing adware or a minor policy violation that does not threaten the broader network. Active ransomware spreading across multiple systems represents a systemic threat that cannot be mitigated through standard, low-priority helpdesk ticketing workflows.
Go deeper
Related to this question
Learn chapter
Ransomware Incident Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.