CS0-003 Incident Response and Management Practice Question
During a post-incident review, a security analyst identifies that the mean time to detect (MTTD) for incidents is significantly higher than the industry benchmark. Which THREE actions should the analyst recommend to improve detection capabilities?
⚠ Common exam trap
CompTIA often tests whether candidates confuse detection improvement with prevention or hygiene activities; vulnerability scanning and log reduction sound security-related but do not reduce MTTD.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement additional network monitoring sensors.
Option A is correct because deploying additional network monitoring sensors (e.g., IDS/IPS or network TAP/SPAN-based collectors) increases visibility across network segments, allowing malicious traffic and anomalies to be observed sooner and thereby lowering MTTD. Option B is correct because tuning and expanding SIEM correlation rules with current threat intelligence lets the platform detect multi-event attack patterns and known adversary techniques faster, directly reducing the time between compromise and alerting. Option C is correct because subscribing to threat intelligence feeds enriches alerts with indicators of compromise (IOCs) and contextual data, enabling analysts to recognize and prioritize malicious activity more quickly. Option D is not appropriate because vulnerability scans identify unpatched weaknesses on a scheduled basis and do not provide real-time detection of active intrusions, so they do not materially improve MTTD. Option E is not appropriate because reducing log retention removes historical evidence needed for correlation and forensic analysis, which would likely degrade detection and investigation capabilities rather than improve them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement additional network monitoring sensors.
Why this is correct
Deploying additional network monitoring sensors at segmentation boundaries and critical ingress/egress points eliminates the blind spots that allowed this incident to go undetected. These sensors capture full packet data, NetFlow metadata, or IDS/IPS alerts, enabling analysts to detect lateral movement and command-and-control activity that passive host-based tools might miss. This is a direct corrective action to improve visibility and reduce time-to-detection for future attacks.
- ✓
Enhance SIEM correlation rules based on current threat intelligence.
Why this is correct
Enhancing SIEM correlation rules by integrating current threat intelligence, such as indicators of compromise and MITRE ATT&CK techniques, allows the platform to automatically match raw security events to known adversarial patterns. This shortens the gap between initial compromise and alert generation, because previously missed sequences of behavior now trigger alerts. Without this tuning, the SIEM remains configured only for historical signatures, leaving the organization blind to evolving attack methods.
- ✓
Subscribe to threat intelligence feeds to enrich alerts.
Why this is correct
Subscribing to threat intelligence feeds enriches SIEM alerts with contextual data such as malicious IP addresses, domain reputation, and file hashes, enabling analysts to triage faster and prioritize high-risk events. Enrichment turns raw indicators into actionable intelligence, reducing the manual research load during investigations and revealing connections to broader campaigns. This is a forward-looking improvement that directly addresses the threat landscape encountered during the incident.
- ✗
Increase the frequency of vulnerability scans.
Why it's wrong here
Increasing vulnerability scan frequency only identifies known weaknesses in systems, not signs of an active compromise or the attacker's current actions. After an incident, the goal is to detect, contain, and eradicate adversarial activity; vulnerability management is a separate continuous process. Relying on scans for this purpose fails because they are point-in-time assessments and do not provide real-time detection of malicious behavior.
- ✗
Reduce the retention period for logs.
Why it's wrong here
Reducing log retention periods systematically erases the historical evidence that incident responders need to reconstruct the attack timeline and determine the full scope of a breach. It also removes the data required for future threat hunting and anomaly detection, since baseline behaviors are lost. This decision undermines both post-incident forensics and long-term security visibility, making it the opposite of an effective remediation.
Go deeper
Related to this question
Learn chapter
DDoS Attack Incident Response
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Event
An event is any identifiable occurrence or action in a computer system, network, or application that can be logged, monitored, or analyzed for security or operational purposes.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.