CS0-003 Incident Response and Management Practice Question
An organization's security team receives an alert about a potential ransomware infection on a critical server. The severity classification is 'high' because the server supports a production database. According to the incident response plan, which containment action should be taken first to minimize data loss?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the server from the network.
Isolating the network connection prevents lateral movement and further encryption while preserving evidence for forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the server to clear the ransomware from memory.
Why it's wrong here
Rebooting a compromised system destroys critical volatile evidence stored in RAM, such as encryption keys, active network connections, and running malware processes. Furthermore, many modern ransomware strains configure themselves to persist across reboots, meaning the system may resume encryption immediately upon startup, potentially with elevated privileges or in safe mode.
- ✓
Disconnect the server from the network.
Why this is correct
Disconnecting the server from the network is the most effective immediate containment action because it halts lateral movement to other network segments and prevents the ransomware from communicating with its command-and-control (C2) server. This isolation stops the spread of the infection and prevents the exfiltration of sensitive data while preserving the system's volatile memory for subsequent forensic analysis.
- ✗
Kill the ransomware process using task manager.
Why it's wrong here
Attempting to manually terminate the ransomware process via Task Manager is highly unreliable because sophisticated malware often employs watchdog processes that immediately restart the malicious thread. Additionally, some ransomware variants are designed with anti-tampering mechanisms that trigger immediate, destructive payloads or mass file deletion if their primary process is abruptly terminated.
- ✗
Create a full disk image of the server before any action.
Why it's wrong here
While acquiring a forensic disk image is a critical step in the preservation phase of incident response, performing it before containment allows the active ransomware to continue encrypting files and spreading across the network. Because disk imaging is a time-consuming process that can take hours, containment must always take priority over evidence collection to minimize ongoing operational damage.
Go deeper
Related to this question
Learn chapter
OWASP Top 10 for Security Analysts
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.