CompTIA CySA+ (CS0-003)Incident Response and ManagementHard

A security analyst is investigating a suspected data exfiltration incident. The attacker used a compromised user account to log into a critical server and then attempted to transfer a large file to an external IP address. The analyst has identified the compromised account and the external IP. Which of the following actions represents the BEST long-term containment strategy for this specific threat?

  1. AForce a password reset for all user accounts.
  2. BImplement a Data Loss Prevention (DLP) solution.
  3. CDisable the compromised user account immediately.
  4. DBlock the external IP address at the perimeter firewall.
Show answer & explanation

Correct answer: B. Implement a Data Loss Prevention (DLP) solution.

While disabling the account and blocking the IP are immediate containment, a DLP solution offers long-term containment by actively monitoring and preventing unauthorized data transfers, regardless of which account is compromised or which external IP is used, addressing the root problem of data exfiltration attempts.

Why the other options are wrong

  • A. Forcing a password reset for all accounts is a broad measure that might be part of recovery, but not the most targeted long-term containment for data exfiltration itself.
  • C. Disabling the account is crucial for immediate containment but doesn't prevent exfiltration if another account is compromised or a different method is used.
  • D. Blocking the external IP is a short-term containment measure; the attacker could use another IP.

Long-Term Containment

Strategies implemented to prevent recurrence or further spread of an incident over an extended period.

  • Goes beyond immediate isolation.
  • Often involves policy changes, new security controls.
  • Aims to address root causes.

Memory trick: Short-term is 'Block and Isolate', Long-term is 'Build a Wall' (DLP, NAC, Segmentation).

More Incident Response and Management questions