ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsEasy

A cybersecurity team is conducting an initial assessment after detecting suspicious network activity. They have isolated the affected systems to prevent further spread of potential malware. Which phase of the incident response process are they currently executing?

  1. ARecovery
  2. BEradication
  3. CDetection and Analysis
  4. DContainment
Show answer & explanation

Correct answer: D. Containment

The isolation of affected systems to prevent further spread is a hallmark activity of the Containment phase in incident response. This phase focuses on limiting the damage and stopping the incident from escalating.

Why the other options are wrong

  • A. Recovery involves restoring systems to normal operations, which comes after eradication.
  • B. Eradication involves removing the cause of the incident, which comes after containment.
  • C. Detection and Analysis involves identifying and analyzing the incident, not isolating systems.

Incident Response: Containment Phase

The phase of incident response focused on limiting the scope and impact of an incident by isolating affected systems and preventing further damage.

  • Objective: Stop the spread of the incident
  • Actions: Isolate systems, disconnect networks, change firewall rules
  • Precedes eradication and recovery

Memory trick: Preparation, Detection, Containment, Eradication, Recovery, Post-Incident.

More Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts questions