Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium

During the containment phase of an incident, a security team discovers that a compromised server is still actively communicating with an external command-and-control (C2) server. To prevent further data exfiltration and control, they decide to block the C2 server's IP address at the perimeter firewall and isolate the compromised server from the network. What is the primary goal of these actions?

  1. ATo collect forensic evidence without interruption.
  2. BTo restore affected services to full operation.
  3. CTo facilitate eradication of the malware from the system.
  4. DTo limit the scope and damage of the ongoing incident.
Show answer & explanation

Correct answer: D. To limit the scope and damage of the ongoing incident.

Blocking C2 communication and isolating the server are direct actions taken to stop the spread and ongoing harm of an incident. This aligns perfectly with the primary objective of the containment phase.

Why the other options are wrong

  • A. Forensic collection is typically done carefully and might be impacted by containment actions, but it's not the primary goal here.
  • B. Restoration is part of the recovery phase, which comes after containment.
  • C. Eradication removes the threat; containment focuses on stopping its immediate impact.

Containment

The incident response phase focused on limiting the scope and impact of an incident, preventing further damage or spread of the attack.

  • Involves isolating compromised systems.
  • May include blocking malicious traffic or accounts.
  • Aims to stop the immediate threat from expanding.

Memory trick: Containment is like putting a STOP sign on the incident's spread.

More Incident Handling questions