hardMultiple Choice
CS0-003 Practice Question: During a post-compromise review, a company wants…
During a post-compromise review, a company wants to test whether legal, PR, IT, and executives understand their roles during a ransomware incident without touching production systems. What exercise is best? During post-incident improvement, which decision is most defensible? which action should be prioritized before closure?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between testing the plan (tabletop) versus testing the technology (simulation or live-fire), and the trap here is assuming that any security improvement (like a new SIEM) inherently validates stakeholder roles, when in fact it only addresses detection capability without testing human decision-making.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tabletop exercise using a realistic ransomware scenario
A tabletop exercise is the best choice for the first question because it allows legal, PR, IT, and executives to discuss and validate their roles during a ransomware scenario without impacting production systems, aligning with NIST SP 800-61 Rev. 2 guidance. For the second question, during post-incident improvement, conducting a tabletop exercise is the most defensible decision as it tests the updated incident response plan in a low-risk environment, providing objective evidence of readiness before committing to changes. For the third question, before closure, prioritizing the scheduling of a tabletop exercise ensures that lessons learned are incorporated and stakeholders are retrained, making it a critical action to formally close the incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tabletop exercise using a realistic ransomware scenario
Why this is correct
Tabletops validate decision paths and communication without operational disruption. In post-incident improvement, responders need action that reduces risk while preserving the investigation record.
- ✗
Purchasing a new SIEM without testing procedures
Why it's wrong here
Tools alone do not validate roles and decisions.
- ✗
Annual password reset only
Why it's wrong here
Password resets do not test cross-functional incident response.
- ✗
Full destructive malware detonation in production
Why it's wrong here
Testing with real malware in production is unsafe.
Go deeper
Related to this question
Learn chapter
Lessons Learned and Post-Incident Activities
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.