312-50V10 · Question #75
It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it…
The correct answer is C. Containment. Disconnecting a compromised system from the network and powering it down are classic containment actions - limiting the spread or impact of an incident without yet removing the threat or restoring operations.
Question
It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it down. What step in incident handling did you just complete?
Options
- ADiscovery
- BRecovery
- CContainment
- DEradication
How the community answered
(42 responses)- A2% (1)
- C93% (39)
- D5% (2)
Why each option
Disconnecting a compromised system from the network and powering it down are classic containment actions - limiting the spread or impact of an incident without yet removing the threat or restoring operations.
Discovery is the phase where the incident is first identified or reported, which had already occurred before these actions were taken.
Recovery involves restoring systems to normal operation after the threat has been removed, not isolating the affected machine.
Containment is the incident handling phase where responders isolate the affected system to prevent further damage or spread. Disconnecting from the network removes lateral movement risk, while powering down stops active processes - both actions limit scope without yet addressing the root cause or restoring service.
Eradication is the phase where the root cause (malware, unauthorized account, etc.) is actively removed from the environment.
Concept tested: Incident response containment phase
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.