CompTIA Server+ (SK0-005)Security and Disaster RecoveryHard
A server administrator discovers that a critical application server has been compromised by an unknown vulnerability. To prevent further damage and analyze the attack, the administrator immediately isolates the server from the network. Which phase of the incident response process does this action primarily fall under?
- AIdentification
- BContainment
- CPreparation
- DRecovery
Show answer & explanationAnswer & explanation
Correct answer: B. Containment
Isolating the compromised server from the network is a containment action. The goal of containment is to stop the spread of the incident and limit further damage to the organization's systems and data. This occurs after an incident has been identified.
Why the other options are wrong
- A. Identification involves detecting and confirming that an incident has taken place.
- C. Preparation involves planning and setting up tools before an incident occurs.
- D. Recovery involves restoring systems and data to normal operations after the incident is contained.
Incident Response: Containment
The phase of incident response focused on stopping the spread of an attack, limiting its impact, and preventing further damage to systems and data.
- Follows the identification phase.
- Involves isolating affected systems, segmenting networks.
- Aims to prevent escalation and further compromise.
Memory trick: Prepare, Identify, Contain, Eradicate, Recover, Lessons.