CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is reviewing a system after a reported security incident. During the initial investigation, the analyst discovers a suspicious process running under a privileged account that is not part of the normal baseline. The process is communicating with an external IP address over an unusual port. The analyst needs to prevent further damage and data exfiltration while preserving evidence. Which of the following actions should the analyst prioritize NEXT?

  1. ANotify law enforcement and legal counsel immediately.
  2. BIsolate the compromised system from the network.
  3. CInitiate a full forensic image of the affected system's hard drive.
  4. DReimage the system with a clean operating system installation.
Show answer & explanation

Correct answer: B. Isolate the compromised system from the network.

Isolating the compromised system from the network is the most critical immediate step to prevent further damage, data exfiltration, and lateral movement, aligning with the containment phase of incident response.

Why the other options are wrong

  • A. Notification to external parties is part of the communication plan but does not directly address the immediate technical threat or containment.
  • C. While important for evidence preservation, forensic imaging can be time-consuming and should typically follow initial containment to prevent ongoing harm.
  • D. Reimaging the system destroys volatile evidence and should only be done after proper containment, evidence collection, and eradication planning.

Containment

The phase of incident response focused on stopping the incident from spreading and causing further damage.

  • Prevents further compromise.
  • Limits the scope of the incident.
  • Can be short-term or long-term.

Memory trick: Prepare and Detect, then Respond with Containment, Eradication, Recovery, and Post-Incident Review.

More Incident Response and Management questions