Courseiva
mediumMultiple Select

CS0-003 Practice Question: What should be included in incident scoping for…

What should be included in incident scoping for ransomware? (Choose three.)

⚠ Common exam trap

The CS0-004 exam often tests the ability to filter out irrelevant physical or administrative details (like office chairs) that distract from the core technical scoping steps required in incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Initial infected host and user context

Identifying the initial infected host and user context is critical for understanding the attack vector, containing the threat, and preventing further spread. In ransomware incidents, the first compromised system often reveals the entry point (e.g., phishing email, RDP brute force) and the user account used, which helps scope the blast radius and prioritize remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Initial infected host and user context

    Why this is correct

    Identifying patient zero (the initial infected host) and the associated user context is critical during ransomware scoping. This allows analysts to pinpoint the entry vector, such as a phishing email or drive-by download, and determine the privilege level of the compromised account to predict potential lateral movement.

  • ✗

    The brand of office chairs near the server room

    Why it's wrong here

    Physical assets like office furniture have no bearing on logical network security, malware execution, or data encryption. Incident scoping must focus strictly on digital assets, network segments, and user accounts that could be impacted by the ransomware payload.

  • ✓

    Backup integrity and last known clean restore point

    Why this is correct

    Determining the status of backups is a vital scoping step because modern ransomware actively targets shadow copies and network-attached backup repositories. Verifying backup integrity and locating the last known clean, unencrypted restore point dictates whether the organization can recover without paying a ransom.

  • ✓

    Shares or systems touched by the compromised account

    Why this is correct

    Mapping the network shares, databases, and directory services accessed by the compromised credentials reveals the blast radius of the attack. Since ransomware typically encrypts any writeable network path accessible to the user, tracking these connections is essential to contain the spread and identify encrypted files.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.