Construct delegated containment and preservation recommendations

A hands-on CS0-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll CS0-004 practice

Certification
CS0-004
Format
Structured configuration
Difficulty
hard
Estimated time
35 min
Automated checks
8

The brief

Repair containment-rules.json: hitPolicy unique or first, 1..24 distinct {id,when,then} rules. Inputs: signal uncertain,confirmed,active-egress; target endpoint,identity,essential-service; delegation none,responder,emergency; evidence pending,captured. Category arrays combine by AND; omitted fields are wildcards. then contains recommendation (analyze,seek-authority,isolate-endpoint,block-identity,restrict-service), preservation (ordinary,collect-before-disruption,parallel-volatile,preserved), gate (analysis-required,verification-required). Local policy: uncertain signals always recommend analyze and retain analysis-required; preservation is preserved when evidence is captured, ordinary otherwise. For confirmed/active-egress, delegation none always recommends seek-authority. Responder delegation permits isolate-endpoint for endpoint and block-identity for identity; essential-service still requires seek-authority. Emergency delegation permits those same endpoint/identity recommendations and restrict-service for essential-service. These are conditional permissions, not completed approval or execution. Every confirmed/active-egress context retains verification-required, independent of delegation or preservation. Its preservation is preserved for captured evidence; otherwise active-egress requires parallel-volatile while confirmed requires collect-before-disruption. Urgent harm must not be delayed by a serial collection assumption, and captured evidence must not be mislabeled newly collected. Evaluate all 54 contexts. Unique requires exactly one hit; first can overlap intentionally if specific rules precede their fallback. Cover every input, keep each row reachable, and use only supplied fields/typed values. Distinct rule strategies are valid. Inspect actual authority, collection and future-release consequences; save and repair without Reset. No output proves containment or authorizes release.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • Explicit hit policy and distinct bounded conditional recommendation records remain editable.
  • Evidence, authority and target states remain supplied facts with complete typed consequences.
  • Every incident context retains a recommendation, preservation route and future gate.
  • Every contextual match is resolved by the declared hit policy.
  • Each conditional recommendation can actually contribute.
  • Actual target and delegated authority determine the conditional containment route.
  • Preservation respects captured evidence and ongoing harm without inventing completed collection.
  • Future analysis or recovery verification remains unresolved after a correct recommendation.

Where this sits in the CS0-004 blueprint

Domain
Incident Response and Management
Objective
Incident Response Techniques
Skill
Evidence, Containment and Verification

Part of CS0-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.