Courseiva

CS0-003 Incident Response and Management Practice Question

An organization's incident response team is handling a ransomware incident where critical servers have been encrypted. The team has identified the ransomware variant and determined that decryption is not possible. Which of the following is the BEST post-incident activity to prevent recurrence?

⚠ Common exam trap

CS0-004 often tests the confusion between recovery actions (reimage, restore) and preventive actions (RCA, control changes), tempting candidates to pick the most visible operational step instead of the one that stops recurrence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a root cause analysis to determine the initial infection vector.

A root cause analysis identifies how the ransomware actually entered — phishing email, exposed RDP, unpatched VPN, supply chain — which is the only way to close the specific gap that allowed the incident. Without knowing the initial infection vector, any remediation is guesswork and the same attack can recur. Post-incident activities in NIST SP 800-61 and CompTIA's IR lifecycle explicitly call for lessons-learned/root-cause work to drive preventive controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the frequency of vulnerability scans.

    Why it's wrong here

    While increasing the frequency of vulnerability scans helps identify unpatched software or misconfigurations over time, it is a proactive assessment measure rather than a targeted post-incident action. It does not identify how the specific ransomware bypassed existing controls or address the precise entry point used by the attacker.

  • ✗

    Share IOCs with the industry ISAC.

    Why it's wrong here

    Sharing Indicators of Compromise (IOCs) with an Information Sharing and Analysis Center (ISAC) is a vital threat intelligence practice that helps secure the broader community. However, this external sharing does not remediate the internal vulnerabilities or structural weaknesses that allowed the ransomware to compromise the organization's own network.

  • ✓

    Conduct a root cause analysis to determine the initial infection vector.

    Why this is correct

    Conducting a root cause analysis (RCA) is the critical post-incident activity required to pinpoint the exact initial infection vector, such as a phishing email, compromised credential, or unpatched edge device. Identifying this entry point allows the incident response team to implement targeted, permanent security controls to prevent the same exploit from being used in future attacks.

  • ✗

    Reimage all affected servers from backups.

    Why it's wrong here

    Reimaging affected servers from clean backups is a fundamental step in the eradication and recovery phases of incident response to restore operational state. However, if the underlying vulnerability or compromised credential that allowed the initial intrusion is not identified and remediated first, restoring the servers will simply leave them vulnerable to immediate reinfection by the same threat actor.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.