Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium

An organization is experiencing a distributed denial-of-service (DDoS) attack targeting its web application hosted on a public cloud. The security operations team needs to quickly identify the source and nature of the attack, filter malicious traffic, and restore normal service without disrupting legitimate users. Which of the following incident response steps should be prioritized immediately after detection to mitigate the ongoing attack?

  1. AConducting a detailed forensic analysis of compromised systems to identify the attacker's TTPs.
  2. BNotifying all affected customers about the service disruption and potential data breach.
  3. CEngaging legal counsel and law enforcement to report the cybercrime.
  4. DImplementing traffic filtering rules and activating DDoS mitigation services provided by the cloud provider.
Show answer & explanation

Correct answer: D. Implementing traffic filtering rules and activating DDoS mitigation services provided by the cloud provider.

During an active DDoS attack, the immediate priority is containment and eradication to stop the attack and restore service. Implementing traffic filtering and leveraging cloud provider DDoS mitigation services are direct actions to achieve this, preventing further impact on legitimate users.

Why the other options are wrong

  • A. Forensic analysis is part of post-incident activity (eradication/recovery) and not the immediate priority during an active DDoS attack.
  • B. Customer notification is part of the communication plan, which occurs after initial mitigation efforts have stabilized the situation.
  • C. Legal and law enforcement engagement is important but follows immediate technical mitigation in the incident response process.

Incident Response - Containment

The phase of incident response focused on limiting the scope and impact of an incident, preventing further damage.

  • Aims to stop the attack and isolate affected systems.
  • Often involves immediate technical actions like blocking traffic or isolating networks.
  • Must be executed quickly to minimize business disruption.

Memory trick: When the 'Flood' hits, build the 'Dam' first!

More Cloud Security Operations questions