easyMultiple Choice
CS0-003 Practice Question: An organization's incident response playbook…
An organization's incident response playbook specifies that after a confirmed malware infection, the infected system should be isolated from the network. Which action best achieves isolation?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between 'isolation' (stopping network communication while preserving the system) and 'eradication' (removing the malware or rebuilding the system), leading candidates to confuse reimaging or power-off actions with proper isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the network interface card (NIC) via software.
Disabling the network interface card (NIC) via software immediately stops all network traffic to and from the infected system, effectively isolating it from the network while preserving the system's state for forensic analysis. This action aligns with the incident response playbook's requirement for network isolation without destroying volatile data or evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Uninstall the operating system and reimage.
Why it's wrong here
Uninstalling the operating system and reimaging an infected system is a highly destructive action that eradicates critical forensic evidence necessary for root cause analysis and threat intelligence gathering. This step is typically performed much later in the incident response lifecycle, during recovery, after proper containment and evidence collection have occurred. Furthermore, it does not immediately isolate the system from the network if the OS is still running during the uninstallation process.
- ✓
Disable the network interface card (NIC) via software.
Why this is correct
Disabling the network interface card (NIC) via software, such as through the operating system's network settings or command-line tools, immediately severs the system's network connectivity. This action effectively contains the threat by preventing further propagation or data exfiltration while preserving the system's volatile memory and disk state for subsequent forensic analysis. It is a controlled and reversible method for initial containment.
- ✗
Pull the power cord from the infected system.
Why it's wrong here
Pulling the power cord from an infected system results in an uncontrolled shutdown, leading to the immediate loss of all volatile data residing in RAM, which is crucial for forensic investigation. This abrupt power loss can also corrupt file systems or operating system files, hindering subsequent analysis and recovery efforts. While it isolates, it does so at a significant cost to evidence integrity.
- ✗
Delete the infected user's account.
Why it's wrong here
Deleting an infected user's account primarily revokes that user's access privileges but does not inherently disconnect the compromised system from the network or stop malicious processes already running under other contexts. The malware may persist, operate under a different account, or leverage system-level privileges, rendering account deletion ineffective for immediate network containment. This action also removes potential audit trails associated with the account.
Go deeper
Related to this question
Learn chapter
DDoS Attack Incident Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.