SSCP Incident Response and Recovery Practice Question
A security team detects lateral movement within the network. Which containment strategy should be applied first to limit the spread of the threat?
⚠ Common exam trap
ISC2 often tests the misconception that blocking external IPs or disabling accounts is sufficient for containment, when in fact internal lateral movement requires immediate network-level isolation of the compromised host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the affected systems by disconnecting them from the network.
Isolating affected systems by disconnecting them from the network is the immediate priority because it physically or logically severs the attacker's ability to propagate laterally via SMB, RDP, or other network protocols. This containment step stops the spread without destroying forensic evidence, which would be lost if systems were reimaged or powered off prematurely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable user accounts associated with compromised systems.
Why it's wrong here
Disabling user accounts removes authentication for those identities but leaves established sessions and non-credential-based attacker channels, such as existing malware callbacks, active on compromised hosts. It is tempting because credential abuse often drives lateral movement, yet isolating the affected systems at the network layer first halts spread.
- ✓
Isolate the affected systems by disconnecting them from the network.
Why this is correct
Disconnecting affected systems from the network immediately severs the attacker's command-and-control and lateral movement channels, satisfying the requirement to limit spread first. Isolation precedes eradication or credential resets because every minute of connectivity lets the adversary pivot to additional hosts.
- ✗
Block the attacker's IP addresses at the perimeter firewall.
Why it's wrong here
Blocking external IP addresses at the perimeter does not stop internal east-west traffic, which is where lateral movement occurs; the attacker is already inside and may use internal addresses. It is tempting because perimeter blocking is a familiar response, but network isolation of affected hosts is required first.
- ✗
Reimage all compromised systems immediately.
Why it's wrong here
Reimaging is part of recovery, not initial containment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.