CompTIA CySA+ (CS0-003)Incident Response and ManagementEasy

A security analyst is investigating an alert from an Endpoint Detection and Response (EDR) system indicating suspicious activity on a user's workstation. The alert details show a process named 'updater.exe' initiating an outbound connection to a known malicious IP address over a non-standard port (TCP 4444). Further investigation reveals that 'updater.exe' is not a legitimate system process and was launched from a temporary directory. Which of the following incident response phases should the analyst prioritize NEXT after confirming the malicious activity?

  1. AContainment
  2. BEradication
  3. CRecovery
  4. DPost-incident activity
Show answer & explanation

Correct answer: A. Containment

After confirming malicious activity, the immediate priority is to stop the spread and impact of the incident. Containment measures are designed to limit the scope and prevent further damage.

Why the other options are wrong

  • B. Eradication involves removing the threat and is performed after containment.
  • C. Recovery involves restoring systems to normal operation and comes after eradication.
  • D. Post-incident activity, including lessons learned, is the final phase of the incident response lifecycle.

Containment (Incident Response)

The phase of incident response focused on limiting the scope and impact of a security incident to prevent further damage or spread.

  • Occurs after detection and analysis, before eradication.
  • Aims to isolate affected systems or networks.
  • Can involve temporary or long-term measures.

Memory trick: Did Clint Eat Rotten Apples Regularly?

More Incident Response and Management questions