100-160 Question 221
Single answerA company’s IT team detects unusual outbound traffic from a server in the network. As part of the incident handling process, what should be the first action taken to contain the threat?
- A
Disconnect the affected server from the network immediately.
- B
Perform a complete forensic analysis on the server.
- C
Notify all employees about the incident to raise awareness.
- D
Restore the server from the most recent backup.
Show answer and explanation
Correct answer: A
Explanation
In incident handling, containment is the first priority to prevent further harm to the organization. Disconnecting the affected server from the network stops the immediate threat, such as malware spreading or data being exfiltrated, which allows the team to proceed with other steps like forensic analysis and recovery in a controlled environment.
- A. Correct.
Disconnecting the affected server from the network immediately is the correct first step in containing the threat. This action prevents further damage and stops potential data exfiltration or the spread of malware.
- B. Incorrect.
Performing a complete forensic analysis is important but should happen after the immediate containment of the threat. Forensics is usually part of the analysis phase, not the initial containment.
- C. Incorrect.
Notifying all employees about the incident is not an immediate containment action and could lead to unnecessary panic. Employee awareness is part of incident response communication but not the first step.
- D. Incorrect.
Restoring the server from a backup may be necessary later in the recovery process but is not a containment action. It does not address the immediate threat and could potentially overwrite critical evidence.