mediumMultiple Select
CS0-003 Practice Question: What should be included in incident scoping for…
What should be included in incident scoping for ransomware? (Choose three.)
⚠ Common exam trap
The CS0-004 exam often tests the ability to filter out irrelevant physical or administrative details (like office chairs) that distract from the core technical scoping steps required in incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initial infected host and user context
Identifying the initial infected host and user context is critical for understanding the attack vector, containing the threat, and preventing further spread. In ransomware incidents, the first compromised system often reveals the entry point (e.g., phishing email, RDP brute force) and the user account used, which helps scope the blast radius and prioritize remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Initial infected host and user context
Why this is correct
Identifying patient zero (the initial infected host) and the associated user context is critical during ransomware scoping. This allows analysts to pinpoint the entry vector, such as a phishing email or drive-by download, and determine the privilege level of the compromised account to predict potential lateral movement.
- ✗
The brand of office chairs near the server room
Why it's wrong here
Physical assets like office furniture have no bearing on logical network security, malware execution, or data encryption. Incident scoping must focus strictly on digital assets, network segments, and user accounts that could be impacted by the ransomware payload.
- ✓
Backup integrity and last known clean restore point
Why this is correct
Determining the status of backups is a vital scoping step because modern ransomware actively targets shadow copies and network-attached backup repositories. Verifying backup integrity and locating the last known clean, unencrypted restore point dictates whether the organization can recover without paying a ransom.
- ✓
Shares or systems touched by the compromised account
Why this is correct
Mapping the network shares, databases, and directory services accessed by the compromised credentials reveals the blast radius of the attack. Since ransomware typically encrypts any writeable network path accessible to the user, tracking these connections is essential to contain the spread and identify encrypted files.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Geolocation Analysis in Threat Hunting
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.