SSCP Incident Response and Recovery Practice Question
A security analyst receives an alert from the SIEM about a possible malware infection on a workstation. The analyst confirms the infection and begins containment. Which of the following actions BEST aligns with the containment phase of the NIST SP 800-61 incident response lifecycle?
⚠ Common exam trap
Many exam-takers confuse eradication actions like reimaging with containment, which is about stopping the spread.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network by disabling its switch port.
Containment aims to limit the damage and prevent further spread of the incident. Isolating the infected workstation from the network achieves this by cutting off communication, which can stop lateral movement and command-and-control traffic. Other actions like reimaging or scanning are part of later phases such as eradication or recovery, and documentation, while necessary, does not contain the threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Isolate the workstation from the network by disabling its switch port.
Why this is correct
Isolating the workstation from the network prevents the malware from spreading to other systems, which is a primary goal of containment. Disabling the switch port effectively cuts off network communication while preserving the system state for later forensic analysis. This action directly limits the scope and impact of the incident, aligning with NIST SP 800-61 containment strategies.
- ✗
Immediately reimage the workstation to remove the malware.
Why it's wrong here
Reimaging is an eradication and recovery step, not containment. Performing it during containment would destroy potential evidence and might not prevent the malware from spreading if other systems are already compromised. Containment focuses on stopping the spread, not on removing the malware, which comes later in the incident response lifecycle.
- ✗
Run a full antivirus scan on the workstation.
Why it's wrong here
Running an antivirus scan is part of detection and analysis or eradication, not containment. It does not isolate the system, so the malware could continue to communicate with command-and-control servers or spread laterally. Containment requires active measures to limit the incident's scope, such as network isolation, rather than scanning.
- ✗
Document the incident in the ticketing system.
Why it's wrong here
Documentation is important throughout the incident response process, but it is not a containment action. Documenting the incident does not stop the malware from spreading or limit its impact. Containment involves technical controls to isolate affected systems, whereas documentation is an administrative task that supports the overall response.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.