Courseiva
hardMultiple Choice

CS0-003 Practice Question: During a post-compromise review, a company wants…

During a post-compromise review, a company wants to test whether legal, PR, IT, and executives understand their roles during a ransomware incident without touching production systems. What exercise is best? During post-incident improvement, which decision is most defensible? which action should be prioritized before closure?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between testing the plan (tabletop) versus testing the technology (simulation or live-fire), and the trap here is assuming that any security improvement (like a new SIEM) inherently validates stakeholder roles, when in fact it only addresses detection capability without testing human decision-making.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tabletop exercise using a realistic ransomware scenario

A tabletop exercise is the best choice for the first question because it allows legal, PR, IT, and executives to discuss and validate their roles during a ransomware scenario without impacting production systems, aligning with NIST SP 800-61 Rev. 2 guidance. For the second question, during post-incident improvement, conducting a tabletop exercise is the most defensible decision as it tests the updated incident response plan in a low-risk environment, providing objective evidence of readiness before committing to changes. For the third question, before closure, prioritizing the scheduling of a tabletop exercise ensures that lessons learned are incorporated and stakeholders are retrained, making it a critical action to formally close the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tabletop exercise using a realistic ransomware scenario

    Why this is correct

    Tabletops validate decision paths and communication without operational disruption. In post-incident improvement, responders need action that reduces risk while preserving the investigation record.

  • ✗

    Purchasing a new SIEM without testing procedures

    Why it's wrong here

    Tools alone do not validate roles and decisions.

  • ✗

    Annual password reset only

    Why it's wrong here

    Password resets do not test cross-functional incident response.

  • ✗

    Full destructive malware detonation in production

    Why it's wrong here

    Testing with real malware in production is unsafe.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.