CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is investigating a potential data exfiltration incident. Suspicious network traffic is observed originating from an internal server to an unknown external IP address over an unusual port. The analyst needs to immediately prevent further data loss without disrupting other critical services. Which of the following containment strategies would be MOST appropriate?

  1. ADisabling the network interface of the compromised server.
  2. BImplementing a firewall rule to block the suspicious outbound connection.
  3. CComplete network shutdown of the affected segment.
  4. DIsolating the server into a dedicated forensic VLAN.
Show answer & explanation

Correct answer: B. Implementing a firewall rule to block the suspicious outbound connection.

Implementing a firewall rule to block the specific suspicious outbound connection is a targeted containment strategy that stops data exfiltration without causing widespread disruption to other critical services or completely isolating the server, which might be needed for further investigation or minimal operations.

Why the other options are wrong

  • A. Disabling the server's network interface would prevent all communication, potentially disrupting other critical services running on it.
  • C. A complete network shutdown is too disruptive and not targeted.
  • D. Isolating to a forensic VLAN is a good step but might still allow C2 or require more setup time; a firewall rule offers immediate, precise blocking.

Targeted Containment

A containment strategy that focuses on isolating or stopping only the malicious activity or affected assets, minimizing disruption to legitimate operations.

  • Aims to stop the spread and impact of an incident.
  • Prioritizes minimal business disruption.
  • Often involves firewall rules, ACLs, or process termination.

Memory trick: Containment is like putting a lid on a boiling pot of trouble.

More Incident Response and Management questions