ISC2 CISSP (Certified Information Systems Security Professional)Security OperationsEasy

A security analyst is investigating a series of failed login attempts originating from an external IP address. The attempts are targeting a critical internal application. What is the MOST appropriate immediate action to take after verifying the legitimacy of the threat?

  1. APerform a vulnerability scan on the targeted application.
  2. BInitiate a full forensic investigation of the affected application server.
  3. CNotify law enforcement about the ongoing attack.
  4. DBlock the source IP address at the perimeter firewall.
Show answer & explanation

Correct answer: D. Block the source IP address at the perimeter firewall.

After verifying a legitimate threat involving external unauthorized access attempts, the most immediate and effective action is to contain the threat by blocking the source IP address. This prevents further attempts while allowing time for a more thorough investigation.

Why the other options are wrong

  • A. A vulnerability scan is a preventative measure or a later step in remediation, not an immediate response to an active attack.
  • B. A full forensic investigation is a later step, not the immediate containment action.
  • C. Notifying law enforcement is typically done after containment and initial analysis, unless it's a critical infrastructure or highly sensitive target.

Incident Response - Containment

Containment in incident response refers to the actions taken to stop an incident from spreading or causing further damage, thereby limiting its scope and impact.

  • Aims to prevent further damage.
  • Often involves isolating affected systems or blocking malicious traffic.
  • Is a critical phase before eradication and recovery.

Memory trick: PICERL: Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned.

More Security Operations questions