Courseiva

CS0-003 Incident Response and Management Practice Question

An incident responder is classifying an incident. The incident involves ransomware encrypting files on multiple workstations, causing significant business disruption. Which severity level should be assigned to this incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High

Ransomware affecting multiple workstations causes high impact and likely critical business disruption, so it should be classified as high or critical severity. The highest typical level is 'Critical' (or similar).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Medium

    Why it's wrong here

    A medium-severity classification is reserved for incidents that cause moderate, localized disruption to non-critical systems or business functions. Because ransomware spreading across multiple systems threatens core operations and data integrity, it far exceeds the threshold of a medium-severity event, which typically allows for normal operations to continue with minor workarounds.

  • ✓

    High

    Why this is correct

    High-severity incidents involve severe degradation of critical services, widespread compromise, or the encryption of multiple production systems by ransomware. This classification triggers immediate escalation, mobilization of the full incident response team, and containment protocols to prevent catastrophic operational downtime or data loss.

  • ✗

    Informational

    Why it's wrong here

    Informational events represent standard, non-threatening log entries, such as successful user logins or routine system updates, that do not indicate unauthorized activity. Classifying an active, multi-system ransomware attack as informational would dangerously ignore a critical security breach that requires immediate containment and eradication.

  • ✗

    Low

    Why it's wrong here

    Low-severity incidents involve near-zero operational impact, such as a single user experiencing adware or a minor policy violation that does not threaten the broader network. Active ransomware spreading across multiple systems represents a systemic threat that cannot be mitigated through standard, low-priority helpdesk ticketing workflows.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.