200-201 Question 404
Select 2An organization detects unauthorized access to a critical server and immediately initiates their incident response plan. The team observes that the attacker is actively exfiltrating data. Which of the following actions should the team prioritize to minimize the impact of the attack? (Choose two.)
- A
Isolate the affected server from the network to stop further data exfiltration.
- B
Analyze the attacker's tools and techniques before taking action.
- C
Disable user accounts suspected of being compromised.
- D
Notify external stakeholders about the breach immediately.
- E
Preserve forensic evidence while containing the attack.
Show answer and explanation
Correct answers: A, E
Explanation
In incident response, containment is a high-priority action to limit the damage caused by an active attack. Isolating the affected server prevents further exfiltration, and preserving forensic evidence ensures that the organization can analyze the breach post-containment without losing critical information. These actions align with minimizing the time to respond and control the situation effectively.
- A. Correct.
Isolating the affected server immediately helps contain the attack and prevents further exfiltration of sensitive data, which is a critical response step.
- B. Incorrect.
While analyzing the attacker's tools and techniques is important, it should not take priority over containing the attack in real-time to minimize the damage.
- C. Incorrect.
Disabling user accounts could be part of the response but is not as immediate or impactful as isolating the compromised server during active data exfiltration.
- D. Incorrect.
Notifying external stakeholders is important but is part of the later stages of incident response (e.g., communication and recovery), not the containment phase.
- E. Correct.
Preserving forensic evidence while containing the attack ensures that the organization can investigate the breach without compromising the response effort.