nerdexam
CompTIA

CS0-003 · Question #618

A security analyst is performing a malware analysis on a device and receives the following instructions: - Reduce the blast radius of the potential threat. - Preserve forensic data for post-incident…

The correct answer is A. Configure an EDR agent to isolate the network with authorized exceptions to the NOC VLAN. Using the EDR’s network‑isolation feature contains the infected host (shrinking its blast radius) while still permitting controlled access from a management or NOC VLAN for live analysis and forensic collection. This meets all three objectives without destroying data or cutting…

Submitted by mateo_ar· Mar 6, 2026Incident Response and Management

Question

A security analyst is performing a malware analysis on a device and receives the following instructions:

  • Reduce the blast radius of the potential threat.
  • Preserve forensic data for post-incident analysis.
  • If securely possible, preserve connectivity for live analysis.

Which of the following will best help the analyst during the investigation?

Options

  • AConfigure an EDR agent to isolate the network with authorized exceptions to the NOC VLAN.
  • BExecute a SOAR playbook to trigger a malware scan on the company's assets.
  • CUse file integrity monitoring to determine if the suspicious file was modified.
  • DCollect the suspicious file using SFTP and reimage the device.

How the community answered

(34 responses)
  • A
    85% (29)
  • B
    3% (1)
  • C
    3% (1)
  • D
    9% (3)

Explanation

Using the EDR’s network‑isolation feature contains the infected host (shrinking its blast radius) while still permitting controlled access from a management or NOC VLAN for live analysis and forensic collection. This meets all three objectives without destroying data or cutting off analysis.

Topics

#malware analysis#EDR#containment#forensics

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice