Courseiva
easyMultiple ChoiceObjective-mapped

CS0-003 Practice Question: During an incident response, the team identifies…

During an incident response, the team identifies that a workstation was compromised via a phishing email. Which of the following should be performed immediately after containment?

⚠ Common exam trap

CompTIA often tests the order of the incident response phases (containment, eradication, recovery, lessons learned) and the trap here is that candidates mistakenly choose 'Collect forensic evidence' (Option B) because they confuse the need for evidence with the immediate priority of removing the active threat after containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Eradicate the malware from the workstation.

Immediately after containment, the priority is to eradicate the malware from the workstation to prevent reinfection or lateral movement. Containment isolates the system, but eradication removes the malicious artifacts (e.g., registry keys, scheduled tasks, or malicious binaries) to ensure the system is clean before recovery. This step aligns with the NIST SP 800-61 incident response lifecycle, where eradication follows containment to eliminate the threat's foothold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Notify law enforcement about the phishing campaign.

    Why it's wrong here

    While reporting cybercrimes to law enforcement is important, it is typically not the immediate next technical step after identifying malware on a workstation. Such notification is a management decision, often contingent on legal obligations, the severity of the breach, and the type of data compromised, and usually occurs after initial containment and assessment of the incident's scope. Prioritizing immediate technical remediation to stop the threat is paramount.

  • Collect forensic evidence from the workstation.

    Why it's wrong here

    Forensic evidence collection is a critical step in incident response, but it should ideally occur *before* or *during* the initial phases of containment, and certainly *before* eradication. The goal is to preserve the state of the system and volatile data before any actions are taken that might alter or destroy crucial evidence. If eradication is the next step, it implies that evidence collection should have already been completed to capture the initial compromise state.

  • Conduct a root cause analysis of the phishing email.

    Why it's wrong here

    Root cause analysis (RCA) is a crucial component of the post-incident activities phase, occurring *after* the incident has been fully contained, eradicated, and systems recovered. Its purpose is to understand *why* the incident occurred, identify vulnerabilities, and implement preventative measures to avoid recurrence. It is not an immediate operational step during the active incident response process.

  • Eradicate the malware from the workstation.

    Why this is correct

    Following the identification of malware and subsequent containment (isolating the affected workstation to prevent further spread), the logical and necessary next technical step in the incident response lifecycle is eradication. This involves thoroughly removing the identified malware and any associated malicious components from the compromised system to eliminate the immediate threat and prepare for recovery.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.