Construct delegated containment and preservation recommendations
A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.
Try this labAll CS0-004 practice
- Certification
- CS0-004
- Format
- Structured configuration
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 8
The brief
Repair containment-rules.json: hitPolicy unique or first, 1..24 distinct {id,when,then} rules. Inputs: signal uncertain,confirmed,active-egress; target endpoint,identity,essential-service; delegation none,responder,emergency; evidence pending,captured. Category arrays combine by AND; omitted fields are wildcards. then contains recommendation (analyze,seek-authority,isolate-endpoint,block-identity,restrict-service), preservation (ordinary,collect-before-disruption,parallel-volatile,preserved), gate (analysis-required,verification-required). Local policy: uncertain signals always recommend analyze and retain analysis-required; preservation is preserved when evidence is captured, ordinary otherwise. For confirmed/active-egress, delegation none always recommends seek-authority. Responder delegation permits isolate-endpoint for endpoint and block-identity for identity; essential-service still requires seek-authority. Emergency delegation permits those same endpoint/identity recommendations and restrict-service for essential-service. These are conditional permissions, not completed approval or execution. Every confirmed/active-egress context retains verification-required, independent of delegation or preservation. Its preservation is preserved for captured evidence; otherwise active-egress requires parallel-volatile while confirmed requires collect-before-disruption. Urgent harm must not be delayed by a serial collection assumption, and captured evidence must not be mislabeled newly collected. Evaluate all 54 contexts. Unique requires exactly one hit; first can overlap intentionally if specific rules precede their fallback. Cover every input, keep each row reachable, and use only supplied fields/typed values. Distinct rule strategies are valid. Inspect actual authority, collection and future-release consequences; save and repair without Reset. No output proves containment or authorizes release.
What the checks verify
Your work is graded on 8 independent properties, not on matching one reference answer.
- Explicit hit policy and distinct bounded conditional recommendation records remain editable.
- Evidence, authority and target states remain supplied facts with complete typed consequences.
- Every incident context retains a recommendation, preservation route and future gate.
- Every contextual match is resolved by the declared hit policy.
- Each conditional recommendation can actually contribute.
- Actual target and delegated authority determine the conditional containment route.
- Preservation respects captured evidence and ongoing harm without inventing completed collection.
- Future analysis or recovery verification remains unresolved after a correct recommendation.
Where this sits in the CS0-004 blueprint
- Domain
- Incident Response and Management
- Objective
- Incident Response Techniques
- Skill
- Evidence, Containment and Verification
Part of CS0-004 preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.