Incident Containment

5 minutes 5 Questions

Incident Containment is the process of limiting the compromise, restricting the intruder's access, and preventing further damage to the system or data during a security incident. It aims to prevent propagation of the threat, preserve the evidence, and restore parts of the network not affected by th…

Test mode:
CompTIA Security+ - Incident Containment Example Questions

Test your knowledge of Incident Containment

Question 1

Your company recently suffered a malware attack. The primary server has been compromised, and you suspect data exfiltration. As the IT administrator, which immediate action should you take for incident containment?

Question 2

A user in your organization reports that their computer is running slow, and they suspect a virus. What is the best containment step to minimize the risk of spreading the virus?

Question 3

Your organization has detected unauthorized network traffic to an external IP address, suggesting data exfiltration. As the lead security analyst, which incident containment step should you choose?

More Incident Containment questions
2 questions (total)