Courseiva
mediumMultiple Choice

Containment of Compromised Service Account for CISSP

During a security incident, the incident response team identifies that an attacker exfiltrated data via a compromised service account. Which of the following is the BEST immediate step to contain the incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revoke the service account's privileges

The best immediate containment step is to revoke the service account's privileges (option C), because disabling or removing the account's permissions stops the attacker from continuing to use it for exfiltration or lateral movement while preserving the account object for forensic review. Containment focuses on cutting off the adversary's access path, and privilege revocation is faster and more decisive than a password change alone, which could still leave the account usable if the attacker has other credential material or persistence. Notifying law enforcement (A) is a later communication step, enabling detailed auditing (B) is a detection/visibility measure rather than containment, and changing the password (D) may not fully stop an active session or token already in the attacker's possession.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify law enforcement

    Why it's wrong here

    Notifying law enforcement is an external communication step that neither stops the exfiltration nor removes the attacker's access, and premature disclosure can compromise the investigation. It is tempting because legal notification is a real incident response obligation, and would be correct once containment and evidence preservation are complete.

  • ✗

    Enable detailed auditing on the account

    Why it's wrong here

    Enabling detailed auditing only records activity; it does not stop the attacker's ongoing exfiltration through the compromised account. It is tempting because auditing is a legitimate forensic and detection step, and would be correct when gathering evidence after containment rather than during it.

  • ✓

    Revoke the service account's privileges

    Why this is correct

    Revoking the compromised service account's privileges immediately stops the attacker using it to access or exfiltrate further data, containing the incident. This severs the active attack path while preserving the account for forensic review, which outright deletion would destroy.

  • ✗

    Change the password of the service account

    Why it's wrong here

    Changing the password does not terminate the attacker's existing authenticated session or revoke issued tokens, so exfiltration can continue. It is tempting because credential rotation is a genuine containment action, and would suffice where the account authenticates interactively with no persistent sessions.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.