Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard
A security analyst discovers that an attacker has gained unauthorized access to a critical database server by exploiting a known vulnerability. The organization's incident response plan outlines immediate steps to isolate the compromised server from the network. This action is primarily aimed at preventing the attacker from moving laterally to other systems or exfiltrating more data. Which incident response phase does this isolation strategy represent?
- ADetection and Analysis
- BRecovery
- CContainment
- DEradication
Show answer & explanationAnswer & explanation
Correct answer: C. Containment
Isolating the compromised server to prevent further damage or spread is a direct action taken during the Containment phase of incident response.
Why the other options are wrong
- A. Detection and Analysis is about identifying and understanding the incident, not taking action to stop its spread.
- B. Recovery is about restoring systems to normal operation after the threat is removed.
- D. Eradication involves removing the root cause of the incident, not limiting its immediate spread.
Incident Containment
The incident response phase focused on limiting the scope and impact of a security incident to prevent further damage or spread.
- Involves actions like isolating systems, blocking IPs, or disabling accounts.
- Aims to stop the attack from progressing.
- Requires quick decision-making and precise execution.
Memory trick: PREDICT and C.E.R.P. for incidents: Preparation, Detection, Containment, Eradication, Recovery, Post-Incident.