nerdexam
Cisco

300-740 · Question #68

When an application is compromised, the first response action is typically to:

The correct answer is B. Contain the breach to prevent further unauthorized access. Containing the breach (B) is the correct first response because incident response prioritizes limiting damage - stopping an attacker's access prevents further data exfiltration, lateral movement, or system destruction before investigation begins. A (Amplify the breach) is the…

Threat Response

Question

When an application is compromised, the first response action is typically to:

Options

  • AAmplify the breach
  • BContain the breach to prevent further unauthorized access
  • CImmediately notify the public
  • DIncrease user privileges

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    88% (22)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Containing the breach (B) is the correct first response because incident response prioritizes limiting damage - stopping an attacker's access prevents further data exfiltration, lateral movement, or system destruction before investigation begins.

  • A (Amplify the breach) is the opposite of sound incident response; amplifying an attack increases harm and liability.
  • C (Notify the public) comes later in the process, after containment and proper assessment - premature disclosure can cause panic and may violate legal notification requirements that specify timelines.
  • D (Increase user privileges) is counterproductive; during a compromise, privileges should typically be reduced or revoked to limit attacker reach.

Memory tip: Think of incident response like a house fire - you contain the fire first (close doors, pull the alarm) before calling the news crew. The acronym C-I-R (Contain → Investigate → Recover) reinforces that containment is always step one.

Topics

#Incident Response#Application Compromise#Breach Containment#First Response

Community Discussion

No community discussion yet for this question.

Full 300-740 Practice