Courseiva

CS0-003 Incident Response and Management Practice Question

During the detection and analysis phase of the NIST SP 800-61 incident response lifecycle, an analyst identifies suspicious network traffic from an internal host to a known malicious IP address. Which step should the analyst perform next to validate the alert?

⚠ Common exam trap

A common pitfall in the CySA+ exam is assuming that external threat intelligence (e.g., VirusTotal, Shodan) alone is sufficient for alert validation. The NIST framework emphasizes correlating internal logs (firewall, DNS, EDR) to confirm malicious activity before proceeding to containment or escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Correlate the alert with other logs and endpoint data to confirm malicious activity.

During the detection and analysis phase, the primary goal is to validate the alert by correlating it with additional data sources (e.g., firewall logs, DNS logs, endpoint detection and response (EDR) telemetry) to confirm whether the traffic is truly malicious or a false positive. Simply searching external threat intelligence (Option A) provides context but does not confirm activity on the host; escalation (Option C) and containment (Option D) are premature without validated evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Search for the IP address on VirusTotal and Shodan.

    Why it's wrong here

    VirusTotal and Shodan are external reputation lookups; they cannot confirm whether this internal host actually communicated with the address, nor reveal the internal context (process, user, payload) that SIEM correlation, endpoint telemetry and log analysis provide. Reputation checks suit proactive threat intelligence enrichment, not validating a live internal alert.

  • ✓

    Correlate the alert with other logs and endpoint data to confirm malicious activity.

    Why this is correct

    Correlating the network alert with logs and endpoint telemetry confirms whether the internal host is genuinely compromised or the traffic is benign. This validation step distinguishes true malicious activity from false positives before escalating within the detection and analysis phase.

  • ✗

    Escalate the alert to the incident response team for containment.

    Why it's wrong here

    Escalation for containment jumps ahead of validation; NIST SP 800-61 requires analysis to confirm the alert before response actions. Escalating to the incident response team is correct after triage confirms a genuine incident requiring coordinated handling, not while the alert remains unverified.

  • ✗

    Contain the host immediately by disconnecting it from the network.

    Why it's wrong here

    Containment belongs to the containment, eradication and recovery phase; isolating during detection and analysis destroys volatile evidence and may tip off an attacker. Immediate disconnection is correct once an incident is confirmed and active exfiltration or lateral movement is underway.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.