CS0-003 Incident Response and Management Practice Question
During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies an alert indicating a high volume of outbound traffic from a critical server to an unknown IP address. Which of the following actions should the analyst perform FIRST?
⚠ Common exam trap
The trap here is conflating urgency with action — candidates often pick 'isolate the server' because it feels like the safest immediate step, but NIST SP 800-61 explicitly places containment after detection and analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate the alert with firewall logs and other security tools.
In the NIST SP 800-61 Detection and Analysis phase, the analyst's first priority is to validate and understand the alert before taking disruptive action. Correlating the alert with firewall logs and other security tools confirms whether the outbound traffic is truly malicious, identifies the destination, and establishes scope — this is the analysis step that precedes containment. Acting on an unverified alert risks unnecessary downtime and destroys evidence needed for the investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Correlate the alert with firewall logs and other security tools.
Why this is correct
During the Detection and Analysis phase of NIST SP 800-61 Rev 2, analysts must validate precursors and indicators to confirm if an actual incident has occurred. Correlating the initial alert with complementary data sources, such as firewall logs, DNS queries, and host-based intrusion detection systems, helps establish the scope, reduce false positives, and build a timeline before taking disruptive actions.
- ✗
Notify law enforcement immediately.
Why it's wrong here
Notifying law enforcement is a sensitive, policy-driven action that typically occurs during the containment, eradication, and recovery phase or post-incident activity, rather than early detection. Prematurely involving external authorities before validating the incident and establishing clear evidence can disrupt business operations and violate internal escalation protocols.
- ✗
Isolate the server from the network to prevent data exfiltration.
Why it's wrong here
Network isolation is a containment strategy designed to limit the damage of an active attack. Under the NIST incident response framework, containment occurs in the Containment, Eradication, and Recovery phase, which must only be initiated after the detection and analysis phase has successfully confirmed and characterized the threat.
- ✗
Rebuild the server from a known good backup.
Why it's wrong here
Rebuilding a system from a clean backup is a recovery task performed during the Containment, Eradication, and Recovery phase. Attempting to restore or rebuild a server during the detection and analysis phase is highly premature, as it destroys volatile forensic evidence needed to understand the root cause and ensure the threat actor is fully eradicated.
Go deeper
Related to this question
Learn chapter
SIGMA and YARA Detection Rules
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.