Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingHard

A security analyst is investigating a suspected insider threat incident. The analyst has identified an employee who accessed highly sensitive financial records outside of their normal work hours and then attempted to delete system logs. The company policy dictates that such activity requires immediate isolation of the employee's network access and workstation. Which type of containment strategy is being applied?

  1. ASegmentation Containment
  2. BBlackhole Containment
  3. CIsolation Containment
  4. DReconfiguration Containment
Show answer & explanation

Correct answer: C. Isolation Containment

Isolation containment involves completely disconnecting a compromised or suspicious system/user from the network to prevent further malicious activity. This directly matches the action of immediately isolating the employee's network access and workstation.

Why the other options are wrong

  • A. Segmentation Containment involves restricting access to specific network segments, not full isolation.
  • B. Blackhole Containment redirects malicious traffic to a null route, typically for known bad IPs, not for an internal user/workstation.
  • D. Reconfiguration Containment involves changing system configurations (e.g., firewall rules) to block specific traffic, but not necessarily full isolation.

Isolation Containment

A containment strategy that involves completely disconnecting a compromised or suspicious system, user, or segment from the network to prevent further damage or spread.

  • Often a rapid, aggressive containment method.
  • Can disrupt legitimate business operations temporarily.
  • Used when the immediate threat outweighs the impact of disconnection.

Memory trick: Containment is like putting a physical barrier around the problem.

More Incident Handling questions