nerdexam
CompTIA

CS0-003 · Question #406

An attacker recently gained unauthorized access to a financial institution's database, which contains confidential information. The attacker exfiltrated a large amount of data before being detected…

The correct answer is C. Review the log files that record all events related to client applications and user access. In a root cause analysis following unauthorized access, the initial step is usually to review relevant log files. These logs can provide critical information about how and when the attacker The first step in a root cause analysis after a data breach is typically to review the…

Submitted by saadiq_pk· Mar 6, 2026Incident Response and Management

Question

An attacker recently gained unauthorized access to a financial institution's database, which contains confidential information. The attacker exfiltrated a large amount of data before being detected and blocked. A security analyst needs to complete a root cause analysis to determine how the attacker was able to gain access. Which of the following should the analyst perform first?

Options

  • ADocument the incident and any findings related to the attack for future reference.
  • BInterview employees responsible for managing the affected systems.
  • CReview the log files that record all events related to client applications and user access.
  • DIdentify the immediate actions that need to be taken to contain the incident and minimize damage.

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    3% (1)
  • C
    76% (22)
  • D
    7% (2)

Explanation

In a root cause analysis following unauthorized access, the initial step is usually to review relevant log files. These logs can provide critical information about how and when the attacker The first step in a root cause analysis after a data breach is typically to review the logs. This helps the analyst understand how the attacker gained access by providing a detailed record of all events, including unauthorized or abnormal activities. Documenting the incident, interviewing employees, and identifying immediate containment actions are important steps, but they usually follow the initial log review.

Topics

#Root cause analysis#Log analysis#Incident response steps#Data exfiltration

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice