SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy
A security team is developing an incident response plan. They are currently defining procedures for containing an incident once it has been detected and analyzed. Which of the following actions is a primary objective during the containment phase?
- AEradicating the root cause of the incident.
- BLimiting the scope and impact of the incident.
- CDocumenting lessons learned for future improvement.
- DRestoring affected systems to normal operation.
Show answer & explanationAnswer & explanation
Correct answer: B. Limiting the scope and impact of the incident.
The primary objective of the containment phase in incident response is to limit the scope and impact of the incident, preventing further damage or spread while preparing for eradication and recovery.
Why the other options are wrong
- A. Eradication happens after containment, focusing on removing the cause.
- C. Lessons learned is part of post-incident review, occurring much later.
- D. Recovery occurs after eradication, aiming to restore systems.
Incident Containment
Incident containment is a phase in incident response aimed at stopping the spread of an attack, limiting its impact, and preventing further damage or compromise of systems and data, typically after detection and analysis.
- Follows detection and analysis.
- Precedes eradication and recovery.
- Focuses on isolating affected systems or networks.
- Can involve temporary shutdowns, firewall rules, or system segmentation.
Memory trick: DIPER: Detect, Isolate, Patch, Eradicate, Recover.