Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A security operations center (SOC) analyst receives an alert indicating a successful brute-force attack against a critical administrative portal. The immediate next step, according to standard incident response procedures, should focus on preventing further compromise while gathering initial information. Which of the following actions is the most appropriate next step?
- ABegin a detailed forensic analysis of all network traffic logs.
- BDisable the compromised user account and block the attacking IP address.
- CNotify legal counsel and public relations immediately.
- DInitiate a full system reimage of the compromised server.
Show answer & explanationAnswer & explanation
Correct answer: B. Disable the compromised user account and block the attacking IP address.
The immediate priority after detecting a successful brute-force attack is containment and initial mitigation. Disabling the compromised account prevents further unauthorized access, and blocking the attacking IP addresses stops ongoing attempts, fulfilling the 'preventing further compromise' requirement.
Why the other options are wrong
- A. Detailed forensic analysis comes after initial containment, to understand the full scope.
- C. Legal/PR notification is typically a later step, after initial containment and assessment.
- D. Reimaging is part of eradication/recovery and is premature before containment.
Initial Containment
The immediate actions taken to limit the scope and impact of an incident, often involving isolation or blocking measures.
- Focuses on stopping the immediate threat.
- May involve disabling accounts, blocking IPs, or isolating systems.
- Precedes detailed analysis or full eradication.
Memory trick: Don't Panic, Plan, Contain, Eradicate, Recover, Learn.