CS0-003 Incident Response and Management Practice Question
An organization's incident response team is classifying an incident based on severity and priority. Which TWO factors should the team consider when determining the priority of an incident? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The potential business impact of the incident.
Priority is often based on the criticality of the affected assets and the potential business impact, as these determine how quickly the incident needs to be addressed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of users reporting the issue.
Why it's wrong here
The number of users reporting the issue is a symptom of scope, not a determinant of priority. User reports can be sparse or duplicated, and a single incident affecting a highly privileged account can be far more urgent than a large number of low-impact user complaints. Priority classification should derive from the incident's potential impact, asset criticality, and urgency, not from the volume of helpdesk tickets.
- ✓
The potential business impact of the incident.
Why this is correct
The potential business impact of an incident drives its priority because the goal of incident management is to minimize harm to the organization. Impact includes financial loss, operational disruption, regulatory fines, reputational damage, and customer trust. A high-impact incident, such as a ransomware attack on a core revenue system, necessitates immediate escalation regardless of other factors.
- ✓
The criticality of the affected systems or data.
Why this is correct
System and data criticality determines how severely an incident affects the organization if confidentiality, integrity, or availability is compromised. Assets supporting core business processes, sensitive customer data, or regulated information have a higher criticality rating, and incidents involving them are automatically prioritized above those affecting nonessential systems. This asset-based measure provides an objective foundation for triage decisions.
- ✗
The time of day the incident occurred.
Why it's wrong here
The time of day an incident occurs has no bearing on its priority classification because the clock does not change the underlying impact or criticality. Whether ransomware strikes at 3 a.m. or 3 p.m., the damage to the organization's operations and data is the same. Time of day may influence response staffing or service-level agreements, but it is not a classification criterion for priority.
- ✗
The type of threat actor involved.
Why it's wrong here
The type of threat actor involved is useful for threat intelligence and response strategy, but it does not directly define the priority of an incident. An unsophisticated attacker can still cause severe business damage through stolen credentials, while a nation-state reconnaissance scan on a low-value system may warrant routine handling. Priority is predicated on the potential harm to the organization, not the adversary's sophistication.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.