Courseiva
Incident Response and ManagementeasyMultiple SelectObjective-mapped

CS0-003 Incident Response and Management Practice Question

During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement additional network monitoring sensors.

Updating detection rules, integrating threat intelligence, and improving monitoring coverage directly reduce detection time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement additional network monitoring sensors.

    Why this is correct

    Deploying additional network monitoring sensors at segmentation boundaries and critical ingress/egress points eliminates the blind spots that allowed this incident to go undetected. These sensors capture full packet data, NetFlow metadata, or IDS/IPS alerts, enabling analysts to detect lateral movement and command-and-control activity that passive host-based tools might miss. This is a direct corrective action to improve visibility and reduce time-to-detection for future attacks.

  • Enhance SIEM correlation rules based on current threat intelligence.

    Why this is correct

    Enhancing SIEM correlation rules by integrating current threat intelligence, such as indicators of compromise and MITRE ATT&CK techniques, allows the platform to automatically match raw security events to known adversarial patterns. This shortens the gap between initial compromise and alert generation, because previously missed sequences of behavior now trigger alerts. Without this tuning, the SIEM remains configured only for historical signatures, leaving the organization blind to evolving attack methods.

  • Subscribe to threat intelligence feeds to enrich alerts.

    Why this is correct

    Subscribing to threat intelligence feeds enriches SIEM alerts with contextual data such as malicious IP addresses, domain reputation, and file hashes, enabling analysts to triage faster and prioritize high-risk events. Enrichment turns raw indicators into actionable intelligence, reducing the manual research load during investigations and revealing connections to broader campaigns. This is a forward-looking improvement that directly addresses the threat landscape encountered during the incident.

  • Increase the frequency of vulnerability scans.

    Why it's wrong here

    Increasing vulnerability scan frequency only identifies known weaknesses in systems, not signs of an active compromise or the attacker's current actions. After an incident, the goal is to detect, contain, and eradicate adversarial activity; vulnerability management is a separate continuous process. Relying on scans for this purpose fails because they are point-in-time assessments and do not provide real-time detection of malicious behavior.

  • Reduce the retention period for logs.

    Why it's wrong here

    Reducing log retention periods systematically erases the historical evidence that incident responders need to reconstruct the attack timeline and determine the full scope of a breach. It also removes the data required for future threat hunting and anomaly detection, since baseline behaviors are lost. This decision undermines both post-incident forensics and long-term security visibility, making it the opposite of an effective remediation.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.