Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?
Determine the final root cause of the incident.
Remove all instances of the incident from the network.
Mitigate exploited vulnerabilities to prevent future incidents.
Isolate affected systems to prevent the spread of damage.
Isolating affected systems limits the damage and prevents the incident from impacting other parts of the organization.
“During containment, the primary objective is to isolate affected systems to prevent further damage.”
— CISM Review Manual 15th Edition, Chapter 4: Incident Management, Section: Incident Response Process*
Submit