Courseiva
easyMultiple Select

CS0-003 Practice Question: Which THREE of the following are common…

Which THREE of the following are common containment techniques used during incident response?

⚠ Common exam trap

CompTIA often tests the distinction between containment, eradication, and recovery phases, so the trap here is confusing actions like shutting down or reimaging (which belong to later phases) with true containment techniques that isolate the threat without destroying evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the network cable

Disconnecting the network cable is a common containment technique because it immediately isolates the affected system from the network, preventing the spread of malware or unauthorized access. This physical disconnection ensures that no further network-based communication can occur, which is critical for containing incidents like ransomware or data exfiltration. It is a rapid, low-level action that does not rely on software or OS controls, making it effective even if the system is compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disconnect the network cable

    Why this is correct

    Physically disconnecting the network interface card or disabling the switch port provides immediate physical-layer isolation. This action instantly halts lateral movement and command-and-control traffic without altering the volatile memory of the compromised host, preserving crucial forensic evidence.

  • ✗

    Shut down the system

    Why it's wrong here

    Powering down or shutting down an infected machine destroys volatile data stored in RAM, such as running processes, active network connections, and unencrypted cryptographic keys. While it stops the attack, it severely compromises subsequent forensic investigations and malware analysis.

  • ✗

    Reimage the system

    Why it's wrong here

    Reimaging involves wiping the storage media and deploying a clean operating system template, which is a core activity of the eradication and recovery phases. Performing this step during containment is premature, as it destroys all forensic evidence before the incident scope is fully understood.

  • ✓

    Block IP addresses at the firewall

    Why this is correct

    Implementing egress or ingress filters at the perimeter firewall to block known malicious IP addresses effectively disrupts command-and-control channels. This containment technique prevents further data exfiltration and blocks external threat actors from interacting with compromised internal assets.

  • ✓

    Change passwords for compromised accounts

    Why this is correct

    Revoking active sessions and forcing a password reset for compromised user or service accounts immediately invalidates the attacker's active credentials. This containment measure stops unauthorized lateral movement and privilege escalation across the domain while security teams remediate the affected systems.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.