mediumMultiple Choice
CS0-003 Practice Question: During incident response, the team identifies…
During incident response, the team identifies that an attacker used a compromised third-party vendor account to access the network. Which of the following should the team do first?
⚠ Common exam trap
CompTIA often tests the 'containment before eradication' principle, and the trap here is that candidates choose forensic analysis (C) first, mistakenly thinking evidence preservation is more urgent than stopping the active attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the vendor's access
The immediate priority is to contain the breach by revoking the compromised third-party vendor's access. This stops the attacker from using the valid session or credentials to move laterally or exfiltrate data. Changing all system passwords (A) is too broad and time-consuming, while forensic analysis (C) and law enforcement notification (D) are secondary steps that occur after containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change all system passwords
Why it's wrong here
Changing all system passwords across the enterprise is an overly broad, disruptive administrative action that does not immediately isolate the specific compromised vector. While password rotation is a useful recovery step, it delays targeted containment and can cause widespread operational disruption during an active incident.
- ✓
Revoke the vendor's access
Why this is correct
Revoking the compromised vendor account's access is the most immediate and effective containment action. This step instantly terminates active sessions and prevents the attacker from leveraging the established credentials to move laterally or exfiltrate sensitive data, aligning with the containment phase of the incident response lifecycle.
- ✗
Conduct forensic analysis on the vendor's account
Why it's wrong here
Conducting forensic analysis is a critical step in the eradication and post-incident phases, but it must not precede containment. Attempting to analyze the account while the attacker still has active access risks tipping off the adversary and allows them to continue damaging systems or altering log files.
- ✗
Notify law enforcement
Why it's wrong here
Notifying law enforcement is an external reporting requirement that typically occurs during the post-incident or eradication phases, depending on regulatory and organizational policies. Initiating this contact prematurely diverts valuable security resources away from active containment efforts, which must always remain the primary focus during the initial response.
Go deeper
Related to this question
Learn chapter
Legal Considerations in Incident Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.