Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

Exhibit

Refer to the exhibit.

---
Incident #1023 - Malware Infection
Detection: Antivirus alert on workstation WKS-045
Time: 2024-03-15 14:22 UTC
Actions:
  14:25 - Isolated WKS-045 from network
  14:30 - Scanned system, detected Trojan.Downloader
  14:35 - Escalated to incident handler
  14:45 - Removed malware via AV
  15:00 - System back online
---

Based on the incident log, at which step did the incident response team contain the threat?

⚠ Common exam trap

ISC2 often tests the distinction between containment and eradication, where candidates mistakenly choose removal (Option B) as containment, but containment must stop the spread before any cleanup occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

14:25 - Isolated WKS-045 from network

Containment is the immediate step to prevent the threat from spreading, and isolating WKS-045 from the network at 14:25 achieves this by cutting off its network connectivity. This aligns with the NIST SP 800-61 incident response lifecycle, where containment is prioritized before eradication or recovery. The log shows isolation occurred before scanning or removal, making it the correct containment action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    14:30 - Scanned system, detected Trojan.Downloader

    Why it's wrong here

    Scanning and detecting the Trojan is identification, not containment; the threat is still active on the system. Containment means isolating or stopping the spread, such as disconnecting the host from the network. Detection is a tempting answer because it is the first active step in the response lifecycle, but it precedes containment.

  • ✗

    14:45 - Removed malware via AV

    Why it's wrong here

    Removing malware via antivirus is eradication, eliminating the threat from the host, not containment, which limits spread. It is tempting because both occur early in the response lifecycle, and it would be correct if the step instead isolated affected systems or segmented the network.

  • ✓

    14:25 - Isolated WKS-045 from network

    Why this is correct

    Isolating WKS-045 at 14:25 satisfies the containment requirement by severing the compromised endpoint's network connectivity, preventing lateral movement and further command-and-control communication. Containment means limiting spread, not eradication or recovery, so this action directly matches the incident response phase the question asks about.

  • ✗

    14:35 - Escalated to incident handler

    Why it's wrong here

    Escalating to an incident handler is notification and triage, not containment; the malware remains active while the handler is alerted. Containment requires isolating the affected system or blocking the threat. Escalation is tempting because it is a required response step, but it merely transfers responsibility for containing the incident.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.