GSEC Incident Handling and Response Practice Question
An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?
⚠ Common exam trap
It's easy for candidates to confuse containment with eradication; isolation limits spread but does not remove the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Containment
The correct answer is containment because isolating a compromised server is a direct step to limit the incident's spread and impact. Containment actions are taken immediately after detection to prevent further damage, while eradication and recovery come later. Preparation is pre-incident, and recovery restores normal operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Containment
Why this is correct
Containment aims to limit the scope and impact of an incident. Isolating the server prevents further lateral movement and stops the attacker from exfiltrating data or causing more damage. This is a classic containment action, as it separates the affected system from the rest of the network while allowing forensic analysis to continue.
- ✗
Preparation
Why it's wrong here
Preparation involves establishing policies, tools, and training before an incident occurs. Isolating a compromised server is a reactive step taken during an active incident, not part of pre-incident readiness. Preparation would include having an isolation playbook ready, but the act of isolating is not preparation itself.
- ✗
Recovery
Why it's wrong here
Recovery focuses on restoring normal operations, such as bringing the server back online after it has been cleaned and verified. Isolating the server is the opposite of recovery; it takes the system out of production to prevent further harm. Recovery would happen later in the incident lifecycle.
- ✗
Eradication
Why it's wrong here
Eradication involves removing the threat, such as deleting malware or closing vulnerabilities. Isolation does not remove the attacker or the malware; it only restricts their ability to communicate. Eradication would occur after containment, when the analyst cleans the system or rebuilds it.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.