SSCP Incident Response and Recovery Practice Question
A security analyst receives an alert from the EDR system indicating that a workstation has been communicating with a known malicious IP address. The analyst confirms the alert and notes that the user is still logged in. Which immediate containment action should the analyst take FIRST?
⚠ Common exam trap
The trap is confusing 'containment' with 'eradication' or 'evidence collection' — candidates often pick forensic imaging or firewall blocking because those sound thorough, but the question asks for the FIRST immediate containment action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation using the EDR agent's network isolation capability
Network isolation via the EDR agent is the fastest, least disruptive containment action that stops the active command-and-control channel while preserving volatile memory and forensic artifacts on the host. It cuts the malicious traffic immediately without tipping off the attacker through account lockouts or firewall changes that might be noticed. This aligns with the containment phase of incident response, where speed and evidence preservation are both prioritized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the workstation using the EDR agent's network isolation capability
Why this is correct
EDR network isolation severs the workstation's connections while preserving the agent's management channel and volatile evidence, halting command-and-control traffic and potential lateral movement. This contains the confirmed compromise immediately, before the still-logged-in user or malware can cause further damage.
- ✗
Create a full forensic image of the hard drive
Why it's wrong here
Imaging preserves volatile and disk evidence but performs no containment, leaving the attacker communicating while acquisition runs. Forensic imaging is tempting because it is the standard first step in evidence collection, and it would be correct once the host is isolated and the incident moves to investigation, not during active containment.
- ✗
Disable the user's Active Directory account
Why it's wrong here
Disabling the directory account revokes authentication but does not terminate the workstation's existing session or running malicious process, so the attacker retains execution. Account disablement is tempting because it is fast and centralised, and it fits credential-compromise cases, yet here containment must target the infected host itself.
- ✗
Block the malicious IP address at the firewall
Why it's wrong here
Blocking the IP at the firewall stops one observed channel but leaves the compromised session and any other command-and-control paths active, so the threat persists. Firewall blocks are tempting because they are quick and low-impact, and they suit blocking known-bad infrastructure during broader network defence, not isolating an actively compromised endpoint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.