mediumMultiple Select
CS0-003 Practice Question: Which TWO of the following are essential steps in…
Which TWO of the following are essential steps in the incident response phase of 'Containment, Eradication, and Recovery'? (Choose two.)
⚠ Common exam trap
CompTIA often tests the distinction between 'containment' actions (like isolation) and 'eradication' actions (like removal of artifacts), and the trap here is that candidates confuse 'collecting forensic evidence' (which belongs to the identification phase) with a step in the containment/eradication process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove malicious files and artifacts from affected systems
Removing malicious files and artifacts from affected systems is a core step in the eradication phase, ensuring that the root cause of the incident is eliminated and the system can be safely restored to normal operations. This step directly addresses the removal of malware, persistence mechanisms, and unauthorized changes that were identified during analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage all systems in the environment
Why it's wrong here
Reimaging every system across the entire enterprise is an extreme, disruptive, and often unnecessary measure. While rebuilding systems from known-good baselines is a valid eradication and recovery strategy, it should be targeted only at verified compromised assets to avoid massive operational downtime and resource exhaustion.
- ✗
Disconnect the organization from the internet
Why it's wrong here
Severing the entire organization's internet connectivity is a highly disruptive action that can halt business operations and critical cloud services. This drastic measure is typically reserved for catastrophic, widespread incidents where local containment controls have failed and the threat poses an immediate existential risk to the enterprise.
- ✓
Remove malicious files and artifacts from affected systems
Why this is correct
Removing malicious files, registry keys, and unauthorized user accounts is a core component of the eradication phase. This step ensures that the active threat vectors and persistence mechanisms are completely purged from the compromised hosts before transitioning to the recovery phase.
- ✗
Collect and preserve forensic evidence
Why it's wrong here
While forensic preservation is critical for root-cause analysis and legal compliance, it is primarily an investigative activity rather than a direct containment or eradication action. Performing forensic collection does not actively stop the spread of malware or remove the threat from the environment.
- ✓
Isolate affected systems from the network
Why this is correct
Isolating compromised hosts from the rest of the network is the primary action during the containment phase. By restricting network communication, security analysts prevent lateral movement, stop data exfiltration, and block command-and-control (C2) traffic while preserving the system's volatile memory for analysis.
Go deeper
Related to this question
Learn chapter
Data Breach Incident Response
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.