nerdexam
GIAC

GCIH · Question #180

Adam works as an Incident Handler for Umbrella Inc. He is informed by the senior authorities that the server of the marketing department has been affected by a malicious hacking attack. Supervisors…

The correct answer is D. Containment. The Containment phase of incident handling involves isolating the affected system to prevent further spread and collecting volatile evidence before the environment is altered. Adam's actions of network isolation and volatile data capture match this phase exactly.

Incident Response & Cyber Kill Chain

Question

Adam works as an Incident Handler for Umbrella Inc. He is informed by the senior authorities that the server of the marketing department has been affected by a malicious hacking attack. Supervisors are also claiming that some sensitive data are also stolen. Adam immediately arrived to the server room of the marketing department and identified the event as an incident. He isolated the infected network from the remaining part of the network and started preparing to image the entire system. He captures volatile data, such as running process, ram, and network connections. Which of the following steps of the incident handling process is being performed by Adam?

Options

  • ARecovery
  • BEradication
  • CIdentification
  • DContainment

How the community answered

(28 responses)
  • B
    7% (2)
  • C
    4% (1)
  • D
    89% (25)

Why each option

The Containment phase of incident handling involves isolating the affected system to prevent further spread and collecting volatile evidence before the environment is altered. Adam's actions of network isolation and volatile data capture match this phase exactly.

ARecovery

Recovery is the phase where systems are restored to normal operations after the threat has been fully removed, which has not yet occurred in this scenario.

BEradication

Eradication involves removing the malware, closing vulnerabilities, and eliminating the root cause of the incident, which comes after containment and evidence collection.

CIdentification

Identification was already completed - Adam received the report, arrived on-site, and confirmed the event as an incident before taking any of the actions described in the scenario.

DContainmentCorrect

Containment is the incident handling phase where responders limit the scope and impact of an incident after it has been identified. Isolating the infected network segment stops lateral movement or continued data exfiltration, and capturing volatile artifacts such as RAM contents, running processes, and active network connections preserves evidence that would be lost upon shutdown. These are both canonical containment activities as defined in NIST SP 800-61.

Concept tested: Incident handling containment phase activities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#IR phases#containment#volatile data collection#incident response process

Community Discussion

No community discussion yet for this question.

Full GCIH Practice