Courseiva

SSCP Incident Response and Recovery Practice Question

A security analyst is reviewing alerts and sees that a user's workstation has begun encrypting files with a new extension, and a ransom note has appeared on the desktop. The analyst confirms this is an active ransomware infection. According to NIST SP 800-61, which action should the analyst take FIRST during the containment phase?

⚠ Common exam trap

The trap here is assuming that shutting down the machine or running antivirus is the fastest way to stop ransomware, when in fact network isolation must come first to prevent spread and preserve evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately disconnect the workstation from the network by unplugging the Ethernet cable or disabling Wi-Fi.

During an active ransomware incident, the first containment action is to isolate the infected system from the network to prevent lateral spread and further encryption of shared resources. This aligns with NIST SP 800-61, which emphasizes limiting the scope of the incident before eradication and recovery. Disconnecting the network preserves volatile evidence while stopping the malware's communication and propagation. Other actions like scanning, shutting down, or paying the ransom do not address immediate containment and may hinder forensic efforts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Immediately disconnect the workstation from the network by unplugging the Ethernet cable or disabling Wi-Fi.

    Why this is correct

    Isolating the infected workstation from the network is the immediate priority in the containment phase to prevent the ransomware from spreading to shared drives and other systems. Disconnecting the network stops lateral movement and further encryption of network resources, while preserving the local state for later forensic analysis. This aligns with NIST SP 800-61 guidance to limit the scope and magnitude of the incident before proceeding with eradication and recovery.

  • ✗

    Shut down the workstation immediately to stop the encryption process.

    Why it's wrong here

    Shutting down the workstation can destroy volatile evidence in memory, such as encryption keys, running processes, and network connections that are critical for forensic analysis and potential decryption. It may also not stop the ransomware if it has already spread to other systems. The correct first step is to isolate the system from the network without powering it off, preserving both containment and evidence.

  • ✗

    Pay the ransom to obtain the decryption key and restore files quickly.

    Why it's wrong here

    Paying the ransom is strongly discouraged because it does not guarantee file recovery, encourages further criminal activity, and may violate organizational policies or legal regulations. It also does not address containment or prevent the malware from spreading to other systems. The immediate priority is to contain the incident, not to negotiate with attackers, which is a decision for management and law enforcement, not the analyst's first action.

  • ✗

    Run a full antivirus scan on the workstation to remove the ransomware.

    Why it's wrong here

    Running an antivirus scan does not address the immediate threat of active encryption and network propagation. The ransomware may already have disabled or bypassed antivirus, and scanning could take time during which the malware continues to encrypt files and spread. Containment must come first; eradication and recovery follow only after the incident is contained and evidence is preserved.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.