Skip to content
CS0-003
Incident Response Management
medium
Question 10 of 20

An incident has been detected where an attacker accessed an administrative account using stolen credentials. After containing the incident, what is the correct next step in the incident response lifecycle?

AEradication — removing the threat, changing compromised credentials, and closing the access vector
BRecovery — restoring the affected systems from backup immediately
CLessons learned — documenting what happened for future improvements
DPreparation — updating the incident response plan

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion