CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud operations team detects unusual spikes in network egress traffic from several virtual machines (VMs) that are part of a production application. Further investigation reveals that these VMs are communicating with unknown external IP addresses on non-standard ports. The team suspects a potential compromise. Which phase of the incident response lifecycle should the team prioritize next to prevent further damage?

  1. APost-Incident Analysis
  2. BEradication
  3. CRecovery
  4. DContainment
Show answer & explanation

Correct answer: D. Containment

In the incident response lifecycle, after detection, the immediate priority is containment. This involves taking steps to limit the scope and impact of the incident, such as isolating compromised systems or blocking malicious traffic, to prevent further damage or spread.

Why the other options are wrong

  • A. Post-Incident Analysis (or Lessons Learned) is the final phase, occurring after recovery, to review the incident and improve processes.
  • B. Eradication involves removing the root cause of the incident, which comes after containment.
  • C. Recovery involves restoring affected systems and services to normal operation, which follows eradication.

Incident Response: Containment

Containment is the phase of incident response focused on limiting the scope and impact of a security incident, preventing further damage or spread.

  • Immediate action after detection.
  • Tactics include isolating systems, blocking traffic, or shutting down services.
  • Aims to buy time for thorough analysis and eradication.

Memory trick: DR. RECAL: Detect, Respond, Eradicate, Contain, Analyze, Learn.

More Security questions