100-160 Question 224
Single answerA company has detected unusual outbound traffic from a workstation, indicating a possible data exfiltration attempt. As the first responder, what is the most appropriate initial step to take in handling this incident?
- A
Disconnect the workstation from the network to contain the threat.
- B
Immediately delete the suspicious files to prevent further damage.
- C
Perform a full system scan and wait for the results before taking action.
- D
Notify the incident response team and document the details of the event.
Show answer and explanation
Correct answer: A
Explanation
In incident handling, the priority is to contain the threat to prevent further damage or spread. Disconnecting the affected workstation from the network isolates it, stopping the potential data exfiltration or malicious activity. Other actions, like notifying the incident response team or analyzing the system, should happen after immediate containment to ensure the threat is neutralized as quickly as possible.
- A. Correct.
Disconnecting the workstation from the network is the correct first step in containing the threat and preventing further potential damage or data exfiltration.
- B. Incorrect.
Deleting suspicious files without proper analysis can destroy critical evidence needed for investigation and may not fully contain the threat.
- C. Incorrect.
Performing a full system scan and waiting for results delays containment efforts, allowing the potential threat to continue affecting the system or network.
- D. Incorrect.
While notifying the incident response team is important, it should be done after immediate containment actions, such as disconnecting the device, have been taken.