CompTIA Cloud+ (CV0-004)SecurityEasy
A cloud operations team discovers unusual outbound network traffic originating from several virtual machines (VMs) that are part of a production application. This traffic is destined for external IP addresses not typically associated with the application's operations. The team suspects a compromise and needs to immediately isolate the affected VMs from the rest of the network while preserving forensic evidence. Which incident response action should they prioritize?
- AContainment
- BEradication
- CRecovery
- DPost-incident analysis
Show answer & explanationAnswer & explanation
Correct answer: A. Containment
Containment is the immediate action taken to prevent an incident from spreading further and minimize its impact. Isolating the affected VMs from the network directly addresses this by stopping the unusual outbound traffic and preventing further compromise, while preserving the VMs for later forensic analysis.
Why the other options are wrong
- B. Eradication focuses on removing the root cause after containment.
- C. Recovery involves restoring systems to normal operation after eradication.
- D. Post-incident analysis occurs after the incident is resolved, for lessons learned.
Incident Response: Containment
The phase of incident response focused on stopping the spread of an incident, limiting its impact, and preventing further damage or compromise.
- Immediate action after detection.
- Aims to stop the attack and isolate affected systems.
- Can involve network segmentation, firewall rules, or system isolation.
- Crucial for minimizing overall damage and preserving evidence.
Memory trick: Don't Come Eat Ramen, Please!