200-201 Question 403
Single answerA cybersecurity analyst in a Security Operations Center (SOC) detects suspicious activity on a critical server. The analyst follows the incident response process and prioritizes actions to minimize damage. Which step should the SOC analyst take first to effectively manage the incident and reduce the time to control?
- A
Isolate the affected server from the network to prevent further spread
- B
Conduct a forensic analysis to identify the root cause of the attack
- C
Notify senior management and provide detailed incident reports
- D
Restore the affected server from the latest known good backup
Show answer and explanation
Correct answer: A
Explanation
Containment is the top priority in responding to a cybersecurity incident to minimize damage and reduce the time to control. Isolating the affected server effectively stops the attack from spreading, allowing the SOC team to focus on investigating, mitigating, and recovering without risking further harm to the environment.
- A. Correct.
Isolating the affected server is critical to containing the threat and preventing further damage to the network. This step reduces the time to control the incident and limits its spread.
- B. Incorrect.
Conducting forensic analysis is important but should be performed after the threat is contained to avoid allowing the attack to propagate further.
- C. Incorrect.
Notifying senior management is necessary, but it is not the immediate priority during the containment phase of an active incident.
- D. Incorrect.
Restoring the affected server is part of the recovery phase, not the containment phase. This action should occur after the threat is neutralized and prevented from recurring.