easyMultiple Choice
Data Exfiltration Containment: Isolate Affected System First
A university's IT department manages a network used by students and faculty. The security team notices an unusual increase in outbound traffic from the student dormitory network during late hours. Upon investigation, they discover that several student laptops are infected with malware that is attempting to connect to external command-and-control (C2) servers. The team needs to contain the incident quickly while minimizing impact on legitimate users. Which of the following is the BEST immediate containment measure?
⚠ Common exam trap
SSCP often tests the misconception that broader containment (shutting down the whole network or subnet) is always better, when the BEST answer balances containment speed with minimal impact on legitimate users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the infected laptops from the network and take them offline for remediation
Disconnecting the infected laptops and taking them offline for remediation is the most targeted containment measure: it stops C2 communication immediately while leaving the rest of the dormitory network operational for legitimate users. This satisfies the requirement to contain quickly with minimal impact on unaffected users. It also preserves the infected hosts for forensic analysis before remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shut down the entire dormitory network
Why it's wrong here
Shutting the whole dormitory network removes the C2 traffic but also disconnects every legitimate student, violating the requirement to minimise impact. It is tempting because full isolation is the fastest, bluntest containment action, and would suit a scenario where the entire segment is confirmed compromised and availability is expendable.
- ✓
Disconnect the infected laptops from the network and take them offline for remediation
Why this is correct
Isolating the infected laptops halts their outbound C2 connections at the endpoint, containing the incident without disrupting the wider dormitory or faculty network. Remediation then proceeds offline, so legitimate users retain connectivity while the malware's command-and-control channel is severed.
- ✗
Block all outbound traffic from the dormitory subnet
Why it's wrong here
Blocking all outbound dormitory traffic severs the C2 channel but equally prevents legitimate internet use by unaffected students, breaching the minimise-impact requirement. It is tempting because subnet-level egress filtering is quick and centralised, and would be correct if the whole subnet were hostile rather than a few infected laptops.
- ✗
Update the antivirus definitions on the infected laptops
Why it's wrong here
Updating antivirus definitions only improves future detection; it neither blocks the existing C2 connections nor prevents ongoing data exfiltration, so containment is not achieved. It suits routine hygiene or post-incident remediation, not immediate containment of active malware callbacks.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.