SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationEasy

A security analyst is investigating a suspected malware infection on a critical server. The analyst needs to quickly isolate the server from the network to prevent further spread while ensuring that forensic data can still be collected. Which of the following actions is the MOST appropriate initial step?

  1. AReboot the server into safe mode with networking.
  2. BChange the server's IP address to an unused range.
  3. CUnplug the server's power cable immediately.
  4. DDisable the network interface card (NIC) on the server.
Show answer & explanation

Correct answer: D. Disable the network interface card (NIC) on the server.

Disabling the network interface card (NIC) effectively isolates the server from the network, preventing malware propagation, while keeping the system powered on for forensic data collection. This is a common and effective containment strategy.

Why the other options are wrong

  • A. Rebooting into safe mode with networking might still allow some network communication, defeating the isolation purpose.
  • B. Changing the IP address might not immediately disconnect established connections and could complicate forensic tracking.
  • C. Unplugging the power cable would lead to loss of volatile data, which is crucial for forensic investigation.

Incident Containment

Incident containment is the process of limiting the scope and impact of a cybersecurity incident by isolating affected systems or networks.

  • Aims to prevent further damage or spread.
  • Requires quick decision-making.
  • Often involves network segmentation or disabling network access.

Memory trick: Contain the wildfire before it spreads, but don't douse the evidence.

More Security Operations and Administration questions