CompTIA Cloud+ (CV0-004)SecurityMedium
A cloud security architect is designing an incident response plan for a critical application hosted in a public cloud. The initial detection phase has identified a potential compromise. The next immediate step is to limit the scope of the incident and prevent further damage. Which phase of the incident response process does this describe?
- APreparation
- BEradication
- CContainment
- DRecovery
Show answer & explanationAnswer & explanation
Correct answer: C. Containment
Containment is the phase of incident response focused on limiting the scope of the incident, preventing further spread, and minimizing damage. This often involves isolating affected systems, blocking malicious IP addresses, or temporarily shutting down compromised services.
Why the other options are wrong
- A. Preparation involves setting up tools, policies, and teams before an incident occurs.
- B. Eradication focuses on removing the root cause of the incident and all remnants of the attacker's presence.
- D. Recovery involves restoring affected systems and services to full operation after an incident.
Incident Response: Containment
The phase of the incident response process aimed at limiting the scope and impact of a security incident, preventing further damage, and isolating affected systems.
- Occurs immediately after identification/analysis.
- Focuses on stopping the spread of the incident.
- Examples: isolating networks, disabling accounts, stopping services.
Memory trick: Don't let the fire spread; put up a firewall!