CS0-003 Incident Response and Management Practice Question
An incident response team is conducting post-incident activities after containing a malware outbreak. Which TWO activities should be included in the lessons learned phase? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a root cause analysis.
Lessons learned involves analyzing the incident to improve future response. Updating detection rules based on IOCs and conducting a root cause analysis are key activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deleting all logs from the incident.
Why it's wrong here
Deleting all logs from the incident is destructive and counterproductive. Logs are the forensic backbone for understanding the attack vector, timeline, and compromised systems; removing them destroys evidence needed for root cause analysis and legal proceedings. Moreover, regulatory frameworks such as PCI-DSS, HIPAA, and GDPR often mandate log retention, and deliberate deletion could be considered spoliation of evidence, exposing the organization to fines or liability.
- ✓
Conducting a root cause analysis.
Why this is correct
Conducting a root cause analysis is the central activity of the lessons-learned phase, as it systematically identifies the underlying human, technical, or procedural factors that allowed the incident. Using structured methods like "5 Whys" or fault tree analysis, the team traces the chain of events back to initial conditions, distinguishing the immediate trigger from the deeper vulnerabilities or gaps. This analysis drives targeted remediation—such as revised hardening standards or additional training—so that similar incidents are less likely to recur.
- ✗
Rewriting the organization's security policy from scratch.
Why it's wrong here
Rewriting the entire security policy from scratch is an overreaction that often introduces unnecessary risk and operational disruption. Lessons-learned reviews typically identify specific gaps in existing policy, procedure, or control execution, which are best addressed through focused revisions to the relevant sections (e.g., access control or incident response) rather than a full rewrite. Abandoning established policy also can create confusion and dilute effective controls that were already working, and the time spent on wholesale rewriting delays more impactful improvements.
- ✓
Updating detection rules based on IOCs.
Why this is correct
Updating detection rules based on Indicators of Compromise is a proactive step that directly improves future detection and reduces dwell time. By incorporating observed IOCs—such as malicious IPs, domain names, file hashes, or behavioral TTPs—into SIEM correlation rules, EDR signatures, and threat intelligence feeds, the organization can identify similar activity early in the kill chain. This is a concrete, measurable outcome of the lessons-learned phase and is often automated to ensure shared context across the security stack.
- ✗
Patching all systems immediately.
Why it's wrong here
Patching all systems immediately is an action more suited to the containment or eradication phase, not the lessons-learned phase. A blanket, untested patch deployment during post-incident review can introduce system instability, break business-critical applications, and consume IT resources that should instead be focused on understanding why the patching process failed to prevent the incident. In lessons learned, the appropriate activity is to evaluate patch management procedures, prioritization criteria, and change controls to close the vulnerability systematically, not to rush a mass update.
Go deeper
Related to this question
Learn chapter
SIEM Log Analysis
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.