nerdexam
EC-Council

312-50V9 · Question #332

It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it…

The correct answer is A. Containment. Isolating an affected system by disconnecting it from the network and powering it down is the Containment phase of the incident response lifecycle, which limits further damage or spread of the incident.

Introduction to Ethical Hacking

Question

It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove the keyboard and mouse, and power it down. What step in incident handling did you just complete?

Options

  • AContainment
  • BEradication
  • CRecovery
  • DDiscovery

How the community answered

(48 responses)
  • A
    94% (45)
  • B
    2% (1)
  • D
    4% (2)

Why each option

Isolating an affected system by disconnecting it from the network and powering it down is the Containment phase of the incident response lifecycle, which limits further damage or spread of the incident.

AContainmentCorrect

Containment is the incident response phase focused on limiting the scope and impact of an incident by preventing it from spreading to other systems or causing further harm. Actions such as disconnecting from the network, removing input devices, and powering down the machine are all classic containment techniques described in NIST SP 800-61. This phase occurs after the incident has been identified and before eradication begins.

BEradication

Eradication involves removing the root cause of the incident, such as deleting malware or closing vulnerabilities, which has not yet occurred here.

CRecovery

Recovery involves restoring the system to normal operation and returning it to production, which is a later phase that follows eradication.

DDiscovery

Discovery (Identification) is the phase where the incident is first detected and reported, which already occurred before the responder arrived at the computer.

Concept tested: Incident response lifecycle - containment phase

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident handling#containment#incident response#information security

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice