mediumMultiple Choice
CS0-003 Practice Question: Refer to the exhibit
Exhibit
Dec 5 10:15:30 192.168.1.1 suricata: [1:2000001:1] ET TROJAN Possible Metasploit Payload Detected [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 10.0.0.5:4444 -> 10.0.0.1:80Refer to the exhibit. An analyst sees this alert in the SIEM console: Suricata alert: ET MALWARE Ransomware activity detected from 10.0.0.5 to 10.0.0.1 over SMB. What is the best immediate action?
⚠ Common exam trap
CompTIA CySA+ frequently tests containment actions. If an analyst has clear evidence of a compromised host actively attacking the network, the correct immediate action is containment (e.g., isolating the host) rather than escalating and delaying action, unless the analyst lacks the authority or the system is a critical production server where isolation would cause unacceptable downtime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the source host 10.0.0.5 from the network.
The alert indicates active ransomware activity from an internal source host. The best immediate action is containment: isolate source host 10.0.0.5 from the network to prevent the malware from spreading. Updating a signature and running an antivirus scan are not immediate containment actions, and escalation should not delay containment once a high-severity active threat is confirmed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the Suricata signature to block the traffic.
Why it's wrong here
Updating Suricata signatures to block traffic is a proactive measure typically undertaken by security engineers or threat hunters after a new, persistent threat pattern has been thoroughly analyzed and validated. For a single, immediate alert indicating a potential exploit, the priority is incident response and investigation, not the time-consuming process of signature development and deployment, which could also lead to false positives if not carefully crafted.
- ✗
Run a full antivirus scan on destination host 10.0.0.1.
Why it's wrong here
Running a full antivirus scan on the destination host (10.0.0.1) is generally not the most effective immediate response for a potential web-based exploit. Antivirus software primarily detects known file-based malware, whereas this alert likely indicates an attempt to exploit a vulnerability in a web application or server, which may not involve dropping or executing traditional malware files. Furthermore, a full scan on a production web server can introduce performance degradation.
- ✓
Isolate the source host 10.0.0.5 from the network.
Why this is correct
Isolating the source host (10.0.0.5) from the network is a significant containment action that should only be performed after initial analysis confirms it is genuinely compromised or malicious, and after proper coordination with stakeholders. Premature isolation without sufficient evidence or communication could disrupt legitimate business operations if the source is a critical internal system or if the alert proves to be a false positive, hindering the overall incident response process.
- ✗
Escalate the alert to the incident response team.
Why it's wrong here
Escalating the alert to the incident response (IR) team is the most appropriate immediate action for a high-severity SIEM alert indicating a potential exploit. This ensures that trained specialists with defined roles and established procedures can promptly investigate the potential compromise, determine its scope, and initiate the necessary containment, eradication, and recovery efforts. A structured, coordinated response is crucial for effective incident management.
Go deeper
Related to this question
Learn chapter
Network Baseline and Anomaly Detection
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.