CS0-003 Incident Response and Management Practice Question
During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement additional network monitoring sensors.
Updating detection rules, integrating threat intelligence, and improving monitoring coverage directly reduce detection time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement additional network monitoring sensors.
Why this is correct
Deploying additional network monitoring sensors at segmentation boundaries and critical ingress/egress points eliminates the blind spots that allowed this incident to go undetected. These sensors capture full packet data, NetFlow metadata, or IDS/IPS alerts, enabling analysts to detect lateral movement and command-and-control activity that passive host-based tools might miss. This is a direct corrective action to improve visibility and reduce time-to-detection for future attacks.
- ✓
Enhance SIEM correlation rules based on current threat intelligence.
Why this is correct
Enhancing SIEM correlation rules by integrating current threat intelligence, such as indicators of compromise and MITRE ATT&CK techniques, allows the platform to automatically match raw security events to known adversarial patterns. This shortens the gap between initial compromise and alert generation, because previously missed sequences of behavior now trigger alerts. Without this tuning, the SIEM remains configured only for historical signatures, leaving the organization blind to evolving attack methods.
- ✓
Subscribe to threat intelligence feeds to enrich alerts.
Why this is correct
Subscribing to threat intelligence feeds enriches SIEM alerts with contextual data such as malicious IP addresses, domain reputation, and file hashes, enabling analysts to triage faster and prioritize high-risk events. Enrichment turns raw indicators into actionable intelligence, reducing the manual research load during investigations and revealing connections to broader campaigns. This is a forward-looking improvement that directly addresses the threat landscape encountered during the incident.
- ✗
Increase the frequency of vulnerability scans.
Why it's wrong here
Increasing vulnerability scan frequency only identifies known weaknesses in systems, not signs of an active compromise or the attacker's current actions. After an incident, the goal is to detect, contain, and eradicate adversarial activity; vulnerability management is a separate continuous process. Relying on scans for this purpose fails because they are point-in-time assessments and do not provide real-time detection of malicious behavior.
- ✗
Reduce the retention period for logs.
Why it's wrong here
Reducing log retention periods systematically erases the historical evidence that incident responders need to reconstruct the attack timeline and determine the full scope of a breach. It also removes the data required for future threat hunting and anomaly detection, since baseline behaviors are lost. This decision undermines both post-incident forensics and long-term security visibility, making it the opposite of an effective remediation.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.