ISC2 CC Security Operations Practice Question
An attacker used stolen credentials from a phishing campaign to authenticate to a cloud email account. The organization's incident response team wants to immediately stop the attacker from continuing to access the mailbox while preserving evidence for investigation. Which action best meets both goals?
⚠ Common exam trap
The trap here is assuming that changing the user's password immediately terminates all active sessions and tokens, when many identity platforms allow existing sessions to persist until explicitly revoked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the account in the identity provider, then export the mailbox audit log and sign-in logs to a secure evidence repository.
The most effective containment combines immediate revocation of access with preservation of forensic data. Disabling the account in the identity provider stops the attacker from authenticating again, while exporting audit and sign-in logs captures evidence before it rotates or is lost. Destructive actions like deleting the mailbox, or partial measures like a password change or IP block, either harm the investigation or fail to reliably stop the attacker.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable the account in the identity provider, then export the mailbox audit log and sign-in logs to a secure evidence repository.
Why this is correct
Disabling the account in the identity provider immediately revokes the attacker's ability to authenticate while leaving the mailbox and logs intact for forensic review. Exporting audit and sign-in logs to a secure repository preserves volatile evidence before it ages out or is altered. This combination contains the threat without destroying data needed to determine scope.
- ✗
Delete the mailbox and recreate it for the legitimate user, then reset the user's password.
Why it's wrong here
Deleting the mailbox destroys the email artifacts, suspicious rules, and sent-item evidence that investigators need to understand what the attacker accessed or exfiltrated. Recreating the mailbox does not preserve logs, and password reset alone does not address the active session. This action is destructive and undermines the investigation.
- ✗
Change the user's password and enable self-service password reset so the user can regain access quickly.
Why it's wrong here
A password change may not immediately invalidate already-issued tokens or active sessions depending on the identity platform, so the attacker could retain access. Enabling self-service reset introduces another path for account takeover and does not preserve evidence. This response is slower and less reliable than directly disabling the account.
- ✗
Add the attacker's IP address to the firewall block list and continue monitoring the mailbox for suspicious activity.
Why it's wrong here
Blocking a single IP address is easily bypassed by an attacker using proxies, VPNs, or residential exit nodes. It also leaves the compromised credentials valid, so the attacker can reconnect from a different address. Passive monitoring does not stop the ongoing unauthorized access or preserve evidence in a controlled way.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.