300-740 · Question #68
When an application is compromised, the first response action is typically to:
The correct answer is B. Contain the breach to prevent further unauthorized access. Containing the breach (B) is the correct first response because incident response prioritizes limiting damage - stopping an attacker's access prevents further data exfiltration, lateral movement, or system destruction before investigation begins. A (Amplify the breach) is the…
Question
When an application is compromised, the first response action is typically to:
Options
- AAmplify the breach
- BContain the breach to prevent further unauthorized access
- CImmediately notify the public
- DIncrease user privileges
How the community answered
(25 responses)- A4% (1)
- B88% (22)
- C4% (1)
- D4% (1)
Explanation
Containing the breach (B) is the correct first response because incident response prioritizes limiting damage - stopping an attacker's access prevents further data exfiltration, lateral movement, or system destruction before investigation begins.
- A (Amplify the breach) is the opposite of sound incident response; amplifying an attack increases harm and liability.
- C (Notify the public) comes later in the process, after containment and proper assessment - premature disclosure can cause panic and may violate legal notification requirements that specify timelines.
- D (Increase user privileges) is counterproductive; during a compromise, privileges should typically be reduced or revoked to limit attacker reach.
Memory tip: Think of incident response like a house fire - you contain the fire first (close doors, pull the alarm) before calling the news crew. The acronym C-I-R (Contain → Investigate → Recover) reinforces that containment is always step one.
Topics
Community Discussion
No community discussion yet for this question.