ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsMedium

A security analyst is reviewing logs from a web application firewall (WAF) and notices a high volume of requests originating from a single IP address attempting to access non-existent pages with various SQL injection payloads. The analyst determines this is an active attack and needs to contain it immediately. Which of the following is the MOST appropriate next step according to a typical incident response plan?

  1. ANotify law enforcement and legal counsel.
  2. BPerform a detailed forensic analysis of the WAF logs.
  3. CBlock the source IP address at the perimeter firewall.
  4. DUpdate the web application's intrusion detection system (IDS) signatures.
Show answer & explanation

Correct answer: C. Block the source IP address at the perimeter firewall.

In the containment phase of incident response, the primary goal is to stop the attack and prevent further damage. Blocking the source IP at the perimeter firewall is an immediate and effective technical control to achieve this.

Why the other options are wrong

  • A. Notification of external parties typically occurs after containment and eradication, once the scope and impact are better understood.
  • B. Forensic analysis is part of the eradication and post-incident phases, not the immediate containment phase.
  • D. Updating IDS signatures is a preventative measure for future attacks, not an immediate containment action for an active one.

Incident Containment

Incident containment is the phase of incident response focused on limiting the scope and impact of an ongoing security incident. It prevents further damage and unauthorized access.

  • Aims to stop the spread of an incident.
  • Can involve technical controls like blocking IPs or isolating systems.
  • Should be executed quickly to minimize impact.

Memory trick: PICERL: Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned.

More Security Operations questions