nerdexam
EC-Council

312-49V11 · Question #58

During a routine network audit, the cybersecurity team at a large organization detects unusual network traffic patterns and unauthorized access attempts to sensitive systems, indicating a potential…

The correct answer is A. Containment. According to the CHFI v11 Procedures and Methodology domain, the Incident Response Process Flow follows a structured sequence to ensure incidents are handled efficiently, lawfully, and with minimal impact. Once an incident is detected and stakeholders such as management…

Computer Forensics Investigation Process

Question

During a routine network audit, the cybersecurity team at a large organization detects unusual network traffic patterns and unauthorized access attempts to sensitive systems, indicating a potential security breach. In accordance with the Incident Response Process Flow, what should be the immediate priority for the cybersecurity team after various third-party vendors and clients are informed of the incident?

Options

  • AContainment
  • BEradication
  • CIncident Triage
  • DIncident Recording and Assignment

How the community answered

(30 responses)
  • A
    77% (23)
  • B
    13% (4)
  • C
    7% (2)
  • D
    3% (1)

Explanation

According to the CHFI v11 Procedures and Methodology domain, the Incident Response Process Flow follows a structured sequence to ensure incidents are handled efficiently, lawfully, and with minimal impact. Once an incident is detected and stakeholders such as management, third-party vendors, and affected clients are informed, the next immediate priority is containment. Containment focuses on limiting the scope and impact of the incident to prevent further damage, data loss, or lateral movement by the attacker. This may include isolating affected systems, blocking malicious IP addresses, disabling compromised accounts, segmenting networks, or applying temporary firewall rules. CHFI v11 emphasizes that containment must be executed swiftly to preserve evidence while stopping the ongoing threat.

Topics

#incident response#containment#IR process flow#security breach

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice