Courseiva
hardMultiple ChoiceObjective-mapped

Immediate Containment for C2 Incidents — Isolate Host Before Investigation

Exhibit

Refer to the exhibit.
[Threat Intelligence Feed]
Indicator: 203.0.113.5
Type: IP
Confidence: High
Tags: C2, Malware
[Proxy Log]
src=10.0.1.50 dst=203.0.113.5 port=443 action=ALLOWED

The SIEM alerts on this traffic. What should the incident analyst do FIRST?

Quick Answer

Isolate the host for investigation is the correct first action because when threat intelligence indicates command-and-control (C2) traffic, the priority is immediate containment to sever the attacker’s communication channel and prevent further data exfiltration or lateral movement. This step aligns with the NIST incident response framework’s containment phase, which must precede any deep forensic analysis or evidence gathering. On the Certified Information Security Manager CISM exam, this scenario tests your understanding of the incident response lifecycle and the critical distinction between containment and investigation—a common trap is jumping to log review or threat hunting before stopping the active threat. Remember the memory tip: “C2 means cut the cord first,” reinforcing that isolation halts the attacker’s control before you dig into the details.

⚠ Common exam trap

ISACA CISM emphasizes that containment (isolating the host) must precede any investigative or remediation steps like blocking IPs or verifying destinations, as candidates may mistakenly prioritize analysis over immediate action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the host for investigation.

The SIEM alert indicates suspicious traffic, and the first priority in incident response is containment to prevent further damage or lateral movement. Isolating the host (Option A) immediately stops the potential threat from communicating with the network, allowing for a safe forensic investigation. This aligns with the NIST SP 800-61 incident response lifecycle, where containment is prioritized before eradication or recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Isolate the host for investigation.

    Why this is correct

    Isolating the host is the first step in incident response to contain the threat and prevent further compromise. This aligns with the containment phase of the NIST SP 800-61 lifecycle.

  • Accept the traffic as normal.

    Why it's wrong here

    Accepting the traffic as normal would ignore the alert and could lead to missing a security incident. Investigation is needed before acceptance.

  • Block the IP at the firewall.

    Why it's wrong here

    Blocking the IP at the firewall may be a later step, but the immediate priority is to contain the affected host to prevent lateral movement. Also, the source IP might be spoofed.

  • Check if the destination is a legitimate CDN.

    Why it's wrong here

    Checking if the destination is a legitimate CDN is a valid analysis step, but containment of the host should occur first to minimize risk during investigation.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst receives an alert from the SIEM indicating a high number of failed login attempts from a single external IP address targeting a public-facing web server. The analyst checks the logs and sees that the attempts are using common usernames. What is the MOST appropriate immediate response?

easy
  • A.Block the IP address at the firewall.
  • B.Ignore the alert as it is likely a false positive.
  • C.Disable the web server.
  • D.Notify law enforcement.

Why A: The immediate response to a brute-force attack from a single external IP is to block that IP at the firewall. This stops the attack at the network perimeter, preventing further authentication attempts without affecting legitimate users (assuming the IP is not a known legitimate source). Delaying action could allow the attacker to compromise an account via password guessing, especially since common usernames are being targeted.

Variation 2. A security analyst detects a potential data exfiltration from a critical server. According to incident response best practices, what is the first action the analyst should take?

easy
  • A.Disconnect the server from the network immediately.
  • B.Notify the incident response manager.
  • C.Review firewall logs to confirm the exfiltration.
  • D.Take a forensic image of the server.

Why C: When a potential data exfiltration is detected but not confirmed, incident response best practices prioritize verification before containment. Immediate disconnection (Option A) could cause unnecessary disruption, alert the attacker, or destroy evidence. The first step is to review firewall logs (Option C) to determine if exfiltration is actually occurring, then proceed with containment and other actions accordingly.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.