hardMultiple Choice
SSCP Practice Question: A company uses a Cloud Workload Protection…
A company uses a Cloud Workload Protection Platform (CWPP) to secure IaaS workloads. They discover that a virtual machine (VM) is communicating with a known command-and-control server. What is the FIRST action the security team should take?
⚠ Common exam trap
SSCP often tests the order of incident response steps — candidates may choose 'analyze logs' or 'run antivirus' first, but containment (isolation) must precede eradication and analysis to stop active harm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately isolate the VM by removing it from the network
The FIRST action when a VM is confirmed to be communicating with a known command-and-control (C2) server is to isolate it from the network to prevent further data exfiltration, lateral movement, or remote control by the attacker. Isolation via network removal or quarantine stops the active threat immediately while preserving the VM's state for later forensic analysis. This aligns with incident response best practices of containment before eradication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Immediately isolate the VM by removing it from the network
Why this is correct
Network isolation severs the command-and-control channel immediately, halting data exfiltration and preventing lateral movement while evidence is preserved. Containment is the first incident response step for a confirmed compromised IaaS workload, satisfying the stem's demand for the initial action.
- ✗
Run an antivirus scan on the VM to remove the malware
Why it's wrong here
Running an antivirus scan addresses filesystem malware, not the live command-and-control channel already established with the attacker. The stem demands immediate containment of that outbound communication. Scanning suits routine hygiene or post-incident cleanup once isolation is confirmed, but here it leaves the C2 link active while the scan runs.
- ✗
Terminate the VM and create a new one from a clean image
Why it's wrong here
Terminating the VM destroys volatile evidence — memory-resident malware, running processes and network connections — before forensic capture, and the attacker may persist elsewhere. It is tempting because rebuilding from a clean image is the standard remediation for confirmed, fully-scoped compromise. Here, containment via network isolation must precede eradication, preserving evidence for investigation.
- ✗
Analyze the traffic logs to determine the scope of the compromise
Why it's wrong here
Log analysis is a containment-adjacent investigative step, but the first action must stop active exfiltration by isolating the VM from the network. Analysis is tempting because scoping is essential, yet leaving a compromised workload communicating with command-and-control lets the attacker persist or pivot while logs are reviewed.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.