300-215 Question 203
Single answerA security analyst is responding to a ransomware incident in a corporate network. During the incident, the analyst decides to isolate affected systems from the network to prevent further spread of the ransomware. Which step of the incident response process is the analyst performing?
- A
Identification
- B
Containment
- C
Eradication
- D
Recovery
Show answer and explanation
Correct answer: B
Explanation
The containment phase of the incident response process is critical for limiting the impact of a security incident. In this scenario, isolating affected systems from the network helps prevent further spread of the ransomware, which is a typical containment activity.
- A. Incorrect.
Identification involves detecting and confirming the occurrence of a security incident. While the analyst is aware of the ransomware, the step described is about taking action, not identifying the incident.
- B. Correct.
Containment focuses on limiting the spread and impact of an incident. The analyst's decision to isolate affected systems from the network is clearly an action that falls under containment.
- C. Incorrect.
Eradication involves removing the root cause or malicious elements of the incident, such as deleting malware or closing vulnerabilities. The scenario does not describe removing the ransomware, only isolating the affected systems.
- D. Incorrect.
Recovery involves restoring normal operations and ensuring systems are no longer vulnerable. The analyst’s action in this scenario does not involve restoring systems but rather preventing further damage.