mediumMultiple Choice
Containment of Compromised Service Account for CISSP
During a security incident, the incident response team identifies that an attacker exfiltrated data via a compromised service account. Which of the following is the BEST immediate step to contain the incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the service account's privileges
The best immediate containment step is to revoke the service account's privileges (option C), because disabling or removing the account's permissions stops the attacker from continuing to use it for exfiltration or lateral movement while preserving the account object for forensic review. Containment focuses on cutting off the adversary's access path, and privilege revocation is faster and more decisive than a password change alone, which could still leave the account usable if the attacker has other credential material or persistence. Notifying law enforcement (A) is a later communication step, enabling detailed auditing (B) is a detection/visibility measure rather than containment, and changing the password (D) may not fully stop an active session or token already in the attacker's possession.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement
Why it's wrong here
Notifying law enforcement is an external communication step that neither stops the exfiltration nor removes the attacker's access, and premature disclosure can compromise the investigation. It is tempting because legal notification is a real incident response obligation, and would be correct once containment and evidence preservation are complete.
- ✗
Enable detailed auditing on the account
Why it's wrong here
Enabling detailed auditing only records activity; it does not stop the attacker's ongoing exfiltration through the compromised account. It is tempting because auditing is a legitimate forensic and detection step, and would be correct when gathering evidence after containment rather than during it.
- ✓
Revoke the service account's privileges
Why this is correct
Revoking the compromised service account's privileges immediately stops the attacker using it to access or exfiltrate further data, containing the incident. This severs the active attack path while preserving the account for forensic review, which outright deletion would destroy.
- ✗
Change the password of the service account
Why it's wrong here
Changing the password does not terminate the attacker's existing authenticated session or revoke issued tokens, so exfiltration can continue. It is tempting because credential rotation is a genuine containment action, and would suffice where the account authenticates interactively with no persistent sessions.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.