Courseiva
Incident Response and ManagementeasyMultiple SelectObjective-mapped

CS0-003 Incident Response and Management Practice Question

An incident response team is conducting post-incident activities after containing a malware outbreak. Which TWO activities should be included in the lessons learned phase? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conducting a root cause analysis.

Lessons learned involves analyzing the incident to improve future response. Updating detection rules based on IOCs and conducting a root cause analysis are key activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deleting all logs from the incident.

    Why it's wrong here

    Deleting all logs from the incident is destructive and counterproductive. Logs are the forensic backbone for understanding the attack vector, timeline, and compromised systems; removing them destroys evidence needed for root cause analysis and legal proceedings. Moreover, regulatory frameworks such as PCI-DSS, HIPAA, and GDPR often mandate log retention, and deliberate deletion could be considered spoliation of evidence, exposing the organization to fines or liability.

  • Conducting a root cause analysis.

    Why this is correct

    Conducting a root cause analysis is the central activity of the lessons-learned phase, as it systematically identifies the underlying human, technical, or procedural factors that allowed the incident. Using structured methods like "5 Whys" or fault tree analysis, the team traces the chain of events back to initial conditions, distinguishing the immediate trigger from the deeper vulnerabilities or gaps. This analysis drives targeted remediation—such as revised hardening standards or additional training—so that similar incidents are less likely to recur.

  • Rewriting the organization's security policy from scratch.

    Why it's wrong here

    Rewriting the entire security policy from scratch is an overreaction that often introduces unnecessary risk and operational disruption. Lessons-learned reviews typically identify specific gaps in existing policy, procedure, or control execution, which are best addressed through focused revisions to the relevant sections (e.g., access control or incident response) rather than a full rewrite. Abandoning established policy also can create confusion and dilute effective controls that were already working, and the time spent on wholesale rewriting delays more impactful improvements.

  • Updating detection rules based on IOCs.

    Why this is correct

    Updating detection rules based on Indicators of Compromise is a proactive step that directly improves future detection and reduces dwell time. By incorporating observed IOCs—such as malicious IPs, domain names, file hashes, or behavioral TTPs—into SIEM correlation rules, EDR signatures, and threat intelligence feeds, the organization can identify similar activity early in the kill chain. This is a concrete, measurable outcome of the lessons-learned phase and is often automated to ensure shared context across the security stack.

  • Patching all systems immediately.

    Why it's wrong here

    Patching all systems immediately is an action more suited to the containment or eradication phase, not the lessons-learned phase. A blanket, untested patch deployment during post-incident review can introduce system instability, break business-critical applications, and consume IT resources that should instead be focused on understanding why the patching process failed to prevent the incident. In lessons learned, the appropriate activity is to evaluate patch management procedures, prioritization criteria, and change controls to close the vulnerability systematically, not to rush a mass update.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.