CISM · Question #781
Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?
The correct answer is D. Isolate affected systems to prevent the spread of damage. Isolating affected systems (D) is the hallmark action of the containment phase - the goal at this stage is to stop the bleeding by limiting how far the incident can spread, not to fix or fully understand it yet. A is wrong because root cause analysis belongs to the…
Question
Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?
Options
- ADetermine the final root cause of the incident.
- BRemove all instances of the incident from the network.
- CMitigate exploited vulnerabilities to prevent future incidents.
- DIsolate affected systems to prevent the spread of damage.
How the community answered
(40 responses)- B3% (1)
- C3% (1)
- D95% (38)
Explanation
Isolating affected systems (D) is the hallmark action of the containment phase - the goal at this stage is to stop the bleeding by limiting how far the incident can spread, not to fix or fully understand it yet.
- A is wrong because root cause analysis belongs to the post-incident/lessons learned phase, after the threat has been neutralized.
- B is wrong because fully removing all instances of malware or attacker presence is the eradication phase, which comes after containment.
- C is wrong because patching and mitigating vulnerabilities to prevent recurrence is part of the recovery/remediation phase, not containment.
Memory tip: Think of incident response phases as PICERL (Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned). Containment = contain the blast radius first, everything else comes later. If you see "isolate," "segment," or "disconnect," that's containment.
Topics
Community Discussion
No community discussion yet for this question.