Courseiva
easyMultiple Choice

Incident Response Containment: Isolate and Preserve Evidence

A SOC analyst receives an alert indicating that a workstation has been making outbound connections to a known command-and-control (C2) IP address. The analyst initiates the incident response process. Which of the following should be the FIRST action taken?

⚠ Common exam trap

CAS-005 often tests the distinction between containment and eradication/detection steps in the incident response lifecycle — candidates frequently choose 'run a scan' or 'delete files' because those feel like active remediation, but the FIRST action against an actively communicating C2 host is always isolation to stop the bleeding and preserve evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the workstation from the network.

The FIRST action in incident response when a host is confirmed to be communicating with a known C2 server is containment — specifically, network isolation of the affected workstation. Isolating the host immediately stops the active exfiltration channel and prevents lateral movement or further C2 tasking, while preserving volatile evidence (memory, running processes, network connections) for later forensic analysis. Running scans, deleting files, or notifying management are subsequent steps that either destroy evidence or waste time while the attacker retains an active foothold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the affected workstation.

    Why it's wrong here

    A full antivirus scan is time-consuming and does not immediately sever the active C2 channel; the host continues beaconing throughout. Scanning suits post-containment verification and eradication checks, but the first action must isolate the workstation from the network to stop data exfiltration and further attacker instruction.

  • ✗

    Notify the organization's management and legal team.

    Why it's wrong here

    Notification is a communication step that follows containment and evidence preservation, not the immediate technical response to an active C2 channel. Escalation to management and legal is appropriate once the incident is confirmed and scoped, for example when assessing regulatory breach obligations, but acting on it first leaves the compromised host communicating with the attacker.

  • ✗

    Delete the suspicious files identified by the antivirus.

    Why it's wrong here

    Deleting files destroys volatile and forensic evidence before the incident is scoped, and the C2 connection persists regardless. File removal belongs to the eradication phase after containment and analysis. The immediate priority is isolating the workstation to cut the active C2 channel while preserving artefacts for investigation.

  • ✓

    Isolate the workstation from the network.

    Why this is correct

    Isolating the workstation severs the active C2 channel, preventing further command execution, data exfiltration and lateral movement while evidence remains intact on the host. Containment precedes eradication and recovery in the incident response lifecycle, satisfying the stem's requirement for the first action against a confirmed beaconing endpoint.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.