Courseiva

CS0-003 Incident Response and Management Practice Question

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, a security analyst identifies an alert indicating a high volume of outbound traffic from a critical server to an unknown IP address. Which of the following actions should the analyst perform FIRST?

⚠ Common exam trap

The trap here is conflating urgency with action — candidates often pick 'isolate the server' because it feels like the safest immediate step, but NIST SP 800-61 explicitly places containment after detection and analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Correlate the alert with firewall logs and other security tools.

In the NIST SP 800-61 Detection and Analysis phase, the analyst's first priority is to validate and understand the alert before taking disruptive action. Correlating the alert with firewall logs and other security tools confirms whether the outbound traffic is truly malicious, identifies the destination, and establishes scope — this is the analysis step that precedes containment. Acting on an unverified alert risks unnecessary downtime and destroys evidence needed for the investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Correlate the alert with firewall logs and other security tools.

    Why this is correct

    During the Detection and Analysis phase of NIST SP 800-61 Rev 2, analysts must validate precursors and indicators to confirm if an actual incident has occurred. Correlating the initial alert with complementary data sources, such as firewall logs, DNS queries, and host-based intrusion detection systems, helps establish the scope, reduce false positives, and build a timeline before taking disruptive actions.

  • ✗

    Notify law enforcement immediately.

    Why it's wrong here

    Notifying law enforcement is a sensitive, policy-driven action that typically occurs during the containment, eradication, and recovery phase or post-incident activity, rather than early detection. Prematurely involving external authorities before validating the incident and establishing clear evidence can disrupt business operations and violate internal escalation protocols.

  • ✗

    Isolate the server from the network to prevent data exfiltration.

    Why it's wrong here

    Network isolation is a containment strategy designed to limit the damage of an active attack. Under the NIST incident response framework, containment occurs in the Containment, Eradication, and Recovery phase, which must only be initiated after the detection and analysis phase has successfully confirmed and characterized the threat.

  • ✗

    Rebuild the server from a known good backup.

    Why it's wrong here

    Rebuilding a system from a clean backup is a recovery task performed during the Containment, Eradication, and Recovery phase. Attempting to restore or rebuild a server during the detection and analysis phase is highly premature, as it destroys volatile forensic evidence needed to understand the root cause and ensure the threat actor is fully eradicated.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.