Courseiva
mediumMultiple Select

CS0-003 Practice Question: Which TWO of the following are essential steps in…

Which TWO of the following are essential steps in the incident response phase of 'Containment, Eradication, and Recovery'? (Choose two.)

⚠ Common exam trap

CompTIA often tests the distinction between 'containment' actions (like isolation) and 'eradication' actions (like removal of artifacts), and the trap here is that candidates confuse 'collecting forensic evidence' (which belongs to the identification phase) with a step in the containment/eradication process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove malicious files and artifacts from affected systems

Removing malicious files and artifacts from affected systems is a core step in the eradication phase, ensuring that the root cause of the incident is eliminated and the system can be safely restored to normal operations. This step directly addresses the removal of malware, persistence mechanisms, and unauthorized changes that were identified during analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reimage all systems in the environment

    Why it's wrong here

    Reimaging every system across the entire enterprise is an extreme, disruptive, and often unnecessary measure. While rebuilding systems from known-good baselines is a valid eradication and recovery strategy, it should be targeted only at verified compromised assets to avoid massive operational downtime and resource exhaustion.

  • ✗

    Disconnect the organization from the internet

    Why it's wrong here

    Severing the entire organization's internet connectivity is a highly disruptive action that can halt business operations and critical cloud services. This drastic measure is typically reserved for catastrophic, widespread incidents where local containment controls have failed and the threat poses an immediate existential risk to the enterprise.

  • ✓

    Remove malicious files and artifacts from affected systems

    Why this is correct

    Removing malicious files, registry keys, and unauthorized user accounts is a core component of the eradication phase. This step ensures that the active threat vectors and persistence mechanisms are completely purged from the compromised hosts before transitioning to the recovery phase.

  • ✗

    Collect and preserve forensic evidence

    Why it's wrong here

    While forensic preservation is critical for root-cause analysis and legal compliance, it is primarily an investigative activity rather than a direct containment or eradication action. Performing forensic collection does not actively stop the spread of malware or remove the threat from the environment.

  • ✓

    Isolate affected systems from the network

    Why this is correct

    Isolating compromised hosts from the rest of the network is the primary action during the containment phase. By restricting network communication, security analysts prevent lateral movement, stop data exfiltration, and block command-and-control (C2) traffic while preserving the system's volatile memory for analysis.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.