mediumMultiple Choice
Isolate Server Before Investigating Unusual Outbound Traffic
A security analyst detects unusual outbound traffic from a server that normally communicates only with internal systems. The firewall logs show connections to an external IP address on port 443/tcp. Which incident response step should the analyst perform FIRST?
Quick Answer
Isolating the server from the network is the correct first step because the situation described, a server that normally talks only to internal systems suddenly making outbound connections to an external IP on port 443, is a textbook sign of a command-and-control channel, and the immediate priority in incident response once a compromise is suspected is containment, not investigation or cleanup. Isolating the host achieves containment while preserving the system in its current running state, which matters because the server's memory, active processes, and other volatile evidence are still intact at this moment; anything that changes that state risks destroying evidence needed to understand what happened. This is precisely why shutting the server down or immediately running an antivirus scan would be the wrong first move: powering off wipes volatile memory where malware often resides only in RAM, and an AV scan can quarantine or delete files before they've been examined, both of which violate the order-of-volatility principle that governs evidence preservation. Isolation strikes the right balance, stopping the bleeding without destroying what the investigation still needs. When a scenario presents signs of active compromise and asks for the FIRST response step, default to the option that contains the threat while disturbing the system as little as possible, rather than options that shut down, remediate, or scan before containment has happened.
⚠ Common exam trap
ISC2 often tests the misconception that immediate shutdown or antivirus scanning is the correct first step, but the trap here is that containment (isolation) must precede any destructive or investigative actions to preserve evidence and limit damage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the server from the network.
The unusual outbound traffic to an external IP on port 443/tcp from a server that normally only communicates internally indicates a potential compromise, such as a command-and-control (C2) channel. The first priority in incident response is containment to prevent further data exfiltration or lateral movement, and isolating the server from the network achieves this without destroying volatile evidence. Shutting down the server or running an antivirus scan could destroy memory-resident malware or forensic artifacts, violating the order of volatility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the server.
Why it's wrong here
A full antivirus scan is slow, signature-based and may miss fileless or living-off-the-land activity, delaying investigation of the outbound connection. It is tempting because scanning is routine host hygiene, and it would be reasonable once malware is confirmed on the server.
- ✓
Isolate the server from the network.
Why this is correct
Isolating the server contains the suspected compromise, preventing further command-and-control communication or data exfiltration to the external IP on port 443. Containment precedes analysis and eradication, so it is the first step before investigating the anomalous outbound traffic.
- ✗
Immediately shut down the server.
Why it's wrong here
Shutting down the server wipes volatile memory, losing running processes and network connections needed to identify the cause. It is tempting as decisive containment, and would be justified if the host were actively destroying data or spreading ransomware across the estate.
- ✗
Disconnect the entire network segment.
Why it's wrong here
Disconnecting the whole segment destroys evidence and disrupts unrelated production systems before the traffic is even confirmed malicious. It is tempting as containment when a confirmed, actively spreading compromise threatens many hosts, but the first step here is scoping and validating the alert.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst detects unusual outbound traffic from a server to a known malicious IP. The server is running a critical business application. What should the analyst do FIRST?
medium- A.Block all traffic from that server
- B.Run antivirus on the server
- ✓ C.Disconnect the server from the network
- D.Alert the system administrator
Why C: The FIRST action in an active compromise involving outbound C2 traffic is containment — disconnecting the server from the network stops the exfiltration and prevents lateral movement while preserving the server's memory and disk for forensics. Blocking only the malicious IP (Option A) leaves other channels open, and running antivirus (Option B) can destroy volatile evidence. Containment precedes eradication, recovery, and notification.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.