ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsMedium

A cybersecurity analyst is investigating a suspected malware infection across several endpoints. After confirming the infection, their immediate priority is to isolate the affected systems to prevent further spread of the malware. Which phase of incident handling is the analyst currently executing?

  1. AIdentification
  2. BEradication
  3. CContainment
  4. DRecovery
Show answer & explanation

Correct answer: C. Containment

Containment is the phase of incident handling where the primary goal is to limit the scope and impact of the incident. Isolating affected systems to prevent further spread of malware is a classic example of a containment strategy.

Why the other options are wrong

  • A. Identification involves detecting and analyzing the incident, which has already occurred ('confirming the infection').
  • B. Eradication involves removing the malware and its root cause, which comes after containment.
  • D. Recovery involves restoring systems to normal operation, which happens after eradication.

Incident Handling: Containment Phase

The phase of incident handling focused on limiting the scope and impact of a security incident by preventing further damage, spread, or compromise.

  • Involves actions like isolating systems, disconnecting networks, or stopping services.
  • Aims to reduce the immediate threat.
  • Often involves short-term, medium-term, and long-term strategies.

Memory trick: Containment: Like a 'container', keeping the bad stuff from spreading.

More Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts questions