CompTIA Security+ (SY0-701)Security OperationsHard

During an active ransomware incident, the incident response team has identified the affected systems and confirmed the attack vector. According to standard incident response process, what should the team do NEXT?

  1. AContain the affected systems to prevent further spread
  2. BConduct a full lessons-learned review with executive leadership
  3. CImmediately restore all systems from the most recent backups
  4. DClose the incident ticket and resume normal operations
Show answer & explanation

Correct answer: A. Contain the affected systems to prevent further spread

The standard incident response lifecycle is preparation, identification, containment, eradication, recovery, and lessons learned. After identification confirms the affected systems and attack vector, the next step is containment to stop further spread before eradication and recovery occur.

Why the other options are wrong

  • B. Lessons learned occurs after the incident is fully resolved, not during active response.
  • C. Restoring from backups (recovery) happens after containment and eradication, not immediately after identification.
  • D. Closing the ticket prematurely risks further compromise since eradication/recovery haven't occurred.

Incident Response Lifecycle

A structured process for handling security incidents consisting of preparation, identification, containment, eradication, recovery, and lessons learned.

  • Preparation: policies, tools, training in place beforehand
  • Identification: detect and confirm the incident
  • Containment: isolate affected systems to stop spread
  • Eradication/Recovery: remove threat, restore systems
  • Lessons learned: post-incident review to improve future response

Memory trick: Prepare, ID, Contain, Eradicate, Recover, Learn.

More Security Operations questions