Describe the general approach to containment during an incident.

Enhance your cyber defense skills with the Security Blue Team Level 1 Test. Prepare with flashcards, multiple choice questions, and detailed explanations to ace your exam!

Multiple Choice

Describe the general approach to containment during an incident.

Explanation:
Containment is about stopping the attack from spreading while preserving evidence for later analysis. To do this, you act quickly to isolate affected systems, preventing further access or lateral movement, and you implement temporary blocks and revoke compromised credentials to cut off attacker access. Preserving evidence—like logs and volatile data—while you contain is also crucial for later investigation and eradication. After containment, you can move to eradication and recovery. The other options don’t fit containment: restoring from backups is a recovery step, not stopping ongoing activity; notifying customers is about communication, not containment; and delaying action to investigate first allows more damage and makes containment harder.

Containment is about stopping the attack from spreading while preserving evidence for later analysis. To do this, you act quickly to isolate affected systems, preventing further access or lateral movement, and you implement temporary blocks and revoke compromised credentials to cut off attacker access. Preserving evidence—like logs and volatile data—while you contain is also crucial for later investigation and eradication. After containment, you can move to eradication and recovery. The other options don’t fit containment: restoring from backups is a recovery step, not stopping ongoing activity; notifying customers is about communication, not containment; and delaying action to investigate first allows more damage and makes containment harder.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy