Courseiva
mediumMultiple Choice

CS0-003 Practice Question: During incident response, the team identifies…

During incident response, the team identifies that an attacker used a compromised third-party vendor account to access the network. Which of the following should the team do first?

⚠ Common exam trap

CompTIA often tests the 'containment before eradication' principle, and the trap here is that candidates choose forensic analysis (C) first, mistakenly thinking evidence preservation is more urgent than stopping the active attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke the vendor's access

The immediate priority is to contain the breach by revoking the compromised third-party vendor's access. This stops the attacker from using the valid session or credentials to move laterally or exfiltrate data. Changing all system passwords (A) is too broad and time-consuming, while forensic analysis (C) and law enforcement notification (D) are secondary steps that occur after containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change all system passwords

    Why it's wrong here

    Changing all system passwords across the enterprise is an overly broad, disruptive administrative action that does not immediately isolate the specific compromised vector. While password rotation is a useful recovery step, it delays targeted containment and can cause widespread operational disruption during an active incident.

  • ✓

    Revoke the vendor's access

    Why this is correct

    Revoking the compromised vendor account's access is the most immediate and effective containment action. This step instantly terminates active sessions and prevents the attacker from leveraging the established credentials to move laterally or exfiltrate sensitive data, aligning with the containment phase of the incident response lifecycle.

  • ✗

    Conduct forensic analysis on the vendor's account

    Why it's wrong here

    Conducting forensic analysis is a critical step in the eradication and post-incident phases, but it must not precede containment. Attempting to analyze the account while the attacker still has active access risks tipping off the adversary and allows them to continue damaging systems or altering log files.

  • ✗

    Notify law enforcement

    Why it's wrong here

    Notifying law enforcement is an external reporting requirement that typically occurs during the post-incident or eradication phases, depending on regulatory and organizational policies. Initiating this contact prematurely diverts valuable security resources away from active containment efforts, which must always remain the primary focus during the initial response.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.