Incident Containment

5 minutes 5 Questions

Incident Containment is the process of limiting the compromise, restricting the intruder's access, and preventing further damage to the system or data during a security incident. It aims to prevent propagation of the threat, preserve the evidence, and restore parts of the network not affected by th…

Test mode:
CompTIA Security+ - Incident Containment Example Questions

Test your knowledge of Incident Containment

Question 1

A user in your organization reports that their computer is running slow, and they suspect a virus. What is the best containment step to minimize the risk of spreading the virus?

Question 2

Your organization has detected unauthorized network traffic to an external IP address, suggesting data exfiltration. As the lead security analyst, which incident containment step should you choose?

Question 3

Your company recently suffered a malware attack. The primary server has been compromised, and you suspect data exfiltration. As the IT administrator, which immediate action should you take for incident containment?

More Incident Containment questions
2 questions (total)