nerdexam
EC-Council

312-50V11 · Question #75

It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it…

The correct answer is C. Containment. Isolating a compromised system by disconnecting it from the network and powering it down to limit further damage represents the Containment phase of incident response.

Information Security and Ethical Hacking Fundamentals

Question

It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it down. What step in incident handling did you just complete?

Options

  • ADiscovery
  • BRecovery
  • CContainment
  • DEradication

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    94% (46)

Why each option

Isolating a compromised system by disconnecting it from the network and powering it down to limit further damage represents the Containment phase of incident response.

ADiscovery

Discovery (Detection and Analysis) refers to the phase where the incident is first identified and analyzed, not where physical isolation actions are taken.

BRecovery

Recovery is the phase where affected systems are restored to normal operation after the threat has been removed, which occurs after containment and eradication.

CContainmentCorrect

Containment is the incident response phase in which responders take immediate action to limit the scope and impact of an incident, such as isolating the affected system by removing network access and shutting it down. According to NIST SP 800-61, containment strategies are applied after an incident is identified to prevent further damage or data loss before eradication and recovery begin. The actions described - network disconnection, peripheral removal, and power-down - are classic short-term containment techniques.

DEradication

Eradication involves removing the root cause of the incident such as deleting malware or patching vulnerabilities, which has not yet occurred in this scenario.

Concept tested: Incident response containment phase actions

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident handling#containment#incident response#information spillage

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice