CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium
A security incident response team discovers that an unauthorized third party has gained access to a critical server hosting customer data. The immediate priority is to prevent further compromise and data exfiltration. Which of the following incident response phases should the team primarily focus on at this stage?
- AContainment
- BRecovery
- CEradication
- DPost-incident activity
Show answer & explanationAnswer & explanation
Correct answer: A. Containment
Containment is the phase focused on limiting the scope and impact of the incident, such as isolating compromised systems or blocking malicious traffic, to prevent further damage or data exfiltration. This is the immediate priority after detection.
Why the other options are wrong
- B. Recovery (restoring systems to normal operation) comes after containment and eradication.
- C. Eradication (removing the cause of the incident) comes after containment.
- D. Post-incident activity (lessons learned, reporting) occurs after the incident is resolved.
Containment (Incident Response)
The phase of incident response focused on limiting the scope and impact of a security incident by isolating affected systems and preventing further damage or spread.
- Immediate priority after detection and analysis.
- Aims to stop the bleeding.
- Can involve network segmentation, system shutdown, or service disabling.
Memory trick: Prep, Detect, Contain, Eradicate, Recover, Post-mortem.