easyMultiple Select
CS0-003 Practice Question: Which THREE of the following are common…
Which THREE of the following are common containment techniques used during incident response?
⚠ Common exam trap
CompTIA often tests the distinction between containment, eradication, and recovery phases, so the trap here is confusing actions like shutting down or reimaging (which belong to later phases) with true containment techniques that isolate the threat without destroying evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the network cable
Disconnecting the network cable is a common containment technique because it immediately isolates the affected system from the network, preventing the spread of malware or unauthorized access. This physical disconnection ensures that no further network-based communication can occur, which is critical for containing incidents like ransomware or data exfiltration. It is a rapid, low-level action that does not rely on software or OS controls, making it effective even if the system is compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the network cable
Why this is correct
Physically disconnecting the network interface card or disabling the switch port provides immediate physical-layer isolation. This action instantly halts lateral movement and command-and-control traffic without altering the volatile memory of the compromised host, preserving crucial forensic evidence.
- ✗
Shut down the system
Why it's wrong here
Powering down or shutting down an infected machine destroys volatile data stored in RAM, such as running processes, active network connections, and unencrypted cryptographic keys. While it stops the attack, it severely compromises subsequent forensic investigations and malware analysis.
- ✗
Reimage the system
Why it's wrong here
Reimaging involves wiping the storage media and deploying a clean operating system template, which is a core activity of the eradication and recovery phases. Performing this step during containment is premature, as it destroys all forensic evidence before the incident scope is fully understood.
- ✓
Block IP addresses at the firewall
Why this is correct
Implementing egress or ingress filters at the perimeter firewall to block known malicious IP addresses effectively disrupts command-and-control channels. This containment technique prevents further data exfiltration and blocks external threat actors from interacting with compromised internal assets.
- ✓
Change passwords for compromised accounts
Why this is correct
Revoking active sessions and forcing a password reset for compromised user or service accounts immediately invalidates the attacker's active credentials. This containment measure stops unauthorized lateral movement and privilege escalation across the domain while security teams remediate the affected systems.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.