Courseiva

GSEC Incident Handling and Response Practice Question

An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?

⚠ Common exam trap

It's easy for candidates to confuse containment with eradication; isolation limits spread but does not remove the threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Containment

The correct answer is containment because isolating a compromised server is a direct step to limit the incident's spread and impact. Containment actions are taken immediately after detection to prevent further damage, while eradication and recovery come later. Preparation is pre-incident, and recovery restores normal operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Containment

    Why this is correct

    Containment aims to limit the scope and impact of an incident. Isolating the server prevents further lateral movement and stops the attacker from exfiltrating data or causing more damage. This is a classic containment action, as it separates the affected system from the rest of the network while allowing forensic analysis to continue.

  • ✗

    Preparation

    Why it's wrong here

    Preparation involves establishing policies, tools, and training before an incident occurs. Isolating a compromised server is a reactive step taken during an active incident, not part of pre-incident readiness. Preparation would include having an isolation playbook ready, but the act of isolating is not preparation itself.

  • ✗

    Recovery

    Why it's wrong here

    Recovery focuses on restoring normal operations, such as bringing the server back online after it has been cleaned and verified. Isolating the server is the opposite of recovery; it takes the system out of production to prevent further harm. Recovery would happen later in the incident lifecycle.

  • ✗

    Eradication

    Why it's wrong here

    Eradication involves removing the threat, such as deleting malware or closing vulnerabilities. Isolation does not remove the attacker or the malware; it only restricts their ability to communicate. Eradication would occur after containment, when the analyst cleans the system or rebuilds it.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.