nerdexam
GIAC

GCFA · Question #25

Adam works as an Incident Handler for Umbrella Inc. He is informed by the senior authorities that the server of the marketing department has been affected by a malicious hacking attack. Supervisors…

The correct answer is D. Containment. Adam has already identified the incident and is now isolating the network and collecting volatile evidence, which are core containment activities.

Advanced Incident Response & Digital Forensics Fundamentals

Question

Adam works as an Incident Handler for Umbrella Inc. He is informed by the senior authorities that the server of the marketing department has been affected by a malicious hacking attack. Supervisors are also claiming that some sensitive data are also stolen. Adam immediately arrived to the server room of the marketing department and identified the event as an incident. He isolated the infected network from the remaining part of the network and started preparing to image the entire system. He captures volatile data, such as running process, ram, and network connections. Which of the following steps of the incident handling process is being performed by Adam?

Options

  • ARecovery
  • BEradication
  • CIdentification
  • DContainment

How the community answered

(58 responses)
  • A
    9% (5)
  • B
    3% (2)
  • C
    5% (3)
  • D
    83% (48)

Why each option

Adam has already identified the incident and is now isolating the network and collecting volatile evidence, which are core containment activities.

ARecovery

Recovery involves restoring systems to normal operations after eradication has been completed, which has not yet occurred.

BEradication

Eradication involves removing the root cause of the incident such as deleting malware or patching vulnerabilities, which Adam has not yet begun.

CIdentification

Identification was already completed - Adam confirmed the event as an incident before taking the actions described in the question.

DContainmentCorrect

Containment is the phase where the incident handler isolates the affected system or network segment to prevent further spread of the attack. Capturing volatile data such as RAM, running processes, and network connections while the system is isolated is a standard containment-phase activity performed before any eradication or full imaging steps begin.

Concept tested: Incident handling containment phase activities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response phases#containment#volatile data capture#CSIRT procedures

Community Discussion

No community discussion yet for this question.

Full GCFA Practice