easyMultiple ChoiceObjective-mapped
CS0-003 Practice Question: During an incident response, the team identifies…
During an incident response, the team identifies that a workstation was compromised via a phishing email. Which of the following should be performed immediately after containment?
⚠ Common exam trap
CompTIA often tests the order of the incident response phases (containment, eradication, recovery, lessons learned) and the trap here is that candidates mistakenly choose 'Collect forensic evidence' (Option B) because they confuse the need for evidence with the immediate priority of removing the active threat after containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eradicate the malware from the workstation.
Immediately after containment, the priority is to eradicate the malware from the workstation to prevent reinfection or lateral movement. Containment isolates the system, but eradication removes the malicious artifacts (e.g., registry keys, scheduled tasks, or malicious binaries) to ensure the system is clean before recovery. This step aligns with the NIST SP 800-61 incident response lifecycle, where eradication follows containment to eliminate the threat's foothold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement about the phishing campaign.
Why it's wrong here
While reporting cybercrimes to law enforcement is important, it is typically not the immediate next technical step after identifying malware on a workstation. Such notification is a management decision, often contingent on legal obligations, the severity of the breach, and the type of data compromised, and usually occurs after initial containment and assessment of the incident's scope. Prioritizing immediate technical remediation to stop the threat is paramount.
- ✗
Collect forensic evidence from the workstation.
Why it's wrong here
Forensic evidence collection is a critical step in incident response, but it should ideally occur *before* or *during* the initial phases of containment, and certainly *before* eradication. The goal is to preserve the state of the system and volatile data before any actions are taken that might alter or destroy crucial evidence. If eradication is the next step, it implies that evidence collection should have already been completed to capture the initial compromise state.
- ✗
Conduct a root cause analysis of the phishing email.
Why it's wrong here
Root cause analysis (RCA) is a crucial component of the post-incident activities phase, occurring *after* the incident has been fully contained, eradicated, and systems recovered. Its purpose is to understand *why* the incident occurred, identify vulnerabilities, and implement preventative measures to avoid recurrence. It is not an immediate operational step during the active incident response process.
- ✓
Eradicate the malware from the workstation.
Why this is correct
Following the identification of malware and subsequent containment (isolating the affected workstation to prevent further spread), the logical and necessary next technical step in the incident response lifecycle is eradication. This involves thoroughly removing the identified malware and any associated malicious components from the compromised system to eliminate the immediate threat and prepare for recovery.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.