nerdexam
EC-Council

212-82 · Question #139

A global financial Institution experienced a sophisticated cyber-attack where attackers gained access to the internal network and exfiltrated sensitive data over several months. The attack was…

The correct answer is C. Isolating affected systems to prevent further data exfiltration and analyzing network traffic for. In a sophisticated cyber-attack involving data exfiltration, the primary initial focus for an incident response team is immediate containment to stop ongoing damage and investigate the attack's scope.

Submitted by katya_ua· Mar 6, 2026Cloud Security Operations & Incident Response

Question

A global financial Institution experienced a sophisticated cyber-attack where attackers gained access to the internal network and exfiltrated sensitive data over several months. The attack was complex, involving a mix of phishing, malware, and exploitation of system vulnerabilities. Once discovered, the institution initiated its incident response process. Considering the nature and severity of the incident, what should be the primary focus of the incident response team's initial efforts?

Options

  • AImplementing a communication plan to manage public relations and customer communication
  • BNotifying law enforcement and regulatory bodies immediately to comply with legal and regulatory
  • CIsolating affected systems to prevent further data exfiltration and analyzing network traffic for
  • DConducting a comprehensive system audit to identify all vulnerabilities and patch them

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    7% (3)
  • C
    68% (28)
  • D
    20% (8)

Why each option

In a sophisticated cyber-attack involving data exfiltration, the primary initial focus for an incident response team is immediate containment to stop ongoing damage and investigate the attack's scope.

AImplementing a communication plan to manage public relations and customer communication

Implementing a communication plan is important for stakeholder management but follows initial technical containment and assessment, as accurate information about the breach is required for public relations.

BNotifying law enforcement and regulatory bodies immediately to comply with legal and regulatory

Notifying law enforcement and regulatory bodies is a vital legal and compliance step, but it typically occurs once the incident is contained and its immediate impact is understood, not as the very first technical response.

CIsolating affected systems to prevent further data exfiltration and analyzing network traffic forCorrect

Isolating affected systems is a critical containment step that immediately prevents further data exfiltration and limits the attacker's reach, while analyzing network traffic helps understand the attack's scope and methods for effective eradication.

DConducting a comprehensive system audit to identify all vulnerabilities and patch them

Conducting a comprehensive system audit to identify and patch all vulnerabilities is part of the post-incident recovery and improvement phase, not the immediate containment phase when an active attack is still ongoing.

Concept tested: Incident response phases (Containment)

Source: learn.microsoft.com/en-us/security/compass/incident-response-technical-guidance#contain-the-incident

Topics

#Incident response#Containment#Data exfiltration#Cyber-attack

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice