100-160 Question 262
Select 2Your organization recently experienced a ransomware attack. As part of the incident response, the security team is reviewing the actions taken during the containment stage. Which of the following tasks are MOST relevant to the containment stage of the NIST Incident Response Lifecycle?
- A
Isolating affected systems from the network to prevent further spread of the ransomware.
- B
Analyzing logs to identify the initial point of compromise.
- C
Developing a communication plan to notify stakeholders about the incident.
- D
Deploying backups to restore affected systems after the ransomware is removed.
- E
Establishing temporary fixes to prevent further exploitation while a long-term solution is developed.
Show answer and explanation
Correct answers: A, E
Explanation
The containment stage of the NIST Incident Response Lifecycle focuses on limiting the impact and spread of the incident. Tasks like isolating affected systems and implementing temporary fixes are directly associated with this stage, as they aim to control the damage and prevent further escalation until the incident can be fully resolved.
- A. Correct.
Isolating affected systems is a key task during the containment stage to prevent the ransomware from spreading further within the network.
- B. Incorrect.
Analyzing logs to identify the initial point of compromise is part of the identification stage, not containment.
- C. Incorrect.
Developing a communication plan is part of the preparation or recovery stage, but it is not directly relevant to containment.
- D. Incorrect.
Deploying backups to restore systems is a task performed during the eradication or recovery stage, not containment.
- E. Correct.
Establishing temporary fixes to prevent further exploitation is a critical part of containment to stop the immediate threat while a long-term solution is being implemented.