CISSP Security Operations Practice Question
A hospital's security operations center receives an alert that a nurse's workstation is communicating with a known command-and-control IP address. The analyst confirms the workstation is infected with malware that is beaconing every sixty seconds. Following the incident response process, which action should the analyst take FIRST?
⚠ Common exam trap
The trap here is equating containment with shutting the machine down, when powering off destroys volatile memory evidence and can break disk encryption, making later forensics far harder.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network while preserving its state for investigation.
With an active beacon to attacker infrastructure, the immediate priority in the incident response lifecycle is containment. Isolating the workstation at the network layer halts command-and-control and limits lateral movement while preserving volatile and non-volatile evidence. Powering off, deleting files, or relying on user cooperation all either destroy evidence or leave the compromised host communicating with the adversary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the workstation from the network while preserving its state for investigation.
Why this is correct
Containment is the priority once an active compromise is confirmed, because the host is beaconing to attacker infrastructure and could enable lateral movement. Network isolation stops command-and-control and spread while keeping memory and disk intact, so the subsequent investigation can determine how the malware arrived and what data was touched.
- ✗
Power off the workstation immediately to stop the malware from spreading.
Why it's wrong here
Cutting power destroys volatile evidence such as running processes, network connections, and encryption keys in memory, and it may leave the disk encrypted or corrupted. Containment should stop the threat without needlessly destroying the forensic artifacts that investigators need to determine scope and root cause.
- ✗
Run a full antivirus scan and delete any detected files before escalating.
Why it's wrong here
Deleting detected files destroys indicators of compromise and may tip off the attacker, and a scan can take hours while the beacon continues. Remediation comes after containment and evidence collection; eradicating first risks losing the very artifacts needed to understand the intrusion's scope and to prove whether patient data was affected.
- ✗
Notify the affected nurse and ask them to stop using the workstation until further notice.
Why it's wrong here
Verbal notification does not stop the malware from beaconing or moving laterally, so the threat remains active while the analyst waits. Human communication is important, but it is not containment; the host must be technically isolated first, and user notification can occur in parallel without delaying the technical response.
Go deeper
Related to this question
Learn chapter
Security Operations Foundations
Key term
Security operations center
A Security Operations Center (SOC) is a centralized team and facility that monitors, detects, analyzes, and responds to cybersecurity incidents across an organization's IT environment 24/7.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.