Courseiva

GSEC Incident Handling and Response Practice Question

During an investigation, an analyst finds that a compromised host has an outbound connection to a known command-and-control IP every 60 seconds. The host is on a production VLAN with other servers. Which containment strategy best limits the adversary's access while preserving evidence for later analysis?

⚠ Common exam trap

The trap here is thinking that blocking a single C2 IP is sufficient containment, when the adversary can pivot to fallback infrastructure and continue operating on the live host.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the host using network access control or an EDR network containment feature, keeping it powered on for memory capture.

Effective containment must both stop the adversary's access and preserve evidence for later analysis. Isolating the host through NAC or EDR network containment severs the C2 channel and prevents lateral movement across the production VLAN while leaving the system powered on, so volatile memory and active connections can still be captured. This balances operational risk with forensic integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately power off the host to sever the C2 channel and prevent further data exfiltration.

    Why it's wrong here

    Powering off severs the channel but destroys volatile memory, active connections, and in-memory malware, severely degrading the investigation. It may also trigger dead-man switches or encrypted payloads that activate on reboot. Because the scenario explicitly values preserving evidence, an immediate power-off is too destructive and forfeits valuable forensic artifacts.

  • ✗

    Change the host's IP address and update DNS records to redirect the adversary to a honeypot.

    Why it's wrong here

    Redirecting traffic to a honeypot can be useful for threat intelligence but does not reliably contain the adversary, who may detect the change or use other channels. It also risks alerting the attacker and causing them to accelerate their objectives. This approach is more deception than containment and does not preserve the host's state for evidence collection.

  • ✗

    Block the C2 IP at the perimeter firewall and leave the host online to observe further adversary behavior.

    Why it's wrong here

    Blocking only the known C2 IP may stop one channel but leaves the host online, allowing the adversary to use alternate infrastructure or fallback domains. It also risks continued lateral movement within the VLAN. While it preserves evidence, it fails to adequately limit the adversary's access, which is the primary containment goal in this scenario.

  • ✓

    Isolate the host using network access control or an EDR network containment feature, keeping it powered on for memory capture.

    Why this is correct

    Network isolation via NAC or EDR containment severs the adversary's access while keeping the host running, so volatile memory and active connections remain available for capture. This limits spread to other production servers and preserves evidence, satisfying both containment and forensic requirements. It is the most balanced strategy for a live compromised host on a shared VLAN.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.