Courseiva

SSCP Incident Response and Recovery Practice Question

An analyst detects suspicious outbound traffic from a workstation to a known command-and-control IP. Which IoC blocking method is MOST appropriate as an immediate containment measure?

⚠ Common exam trap

The trap is that candidates may focus on endpoint remediation (e.g., deleting files or removing malware) rather than immediate containment through network-level blocking, which is the priority in incident response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block the IP address at the perimeter firewall

Blocking the IP address at the perimeter firewall is the most appropriate immediate containment measure because it directly cuts the outbound communication channel to the known command-and-control (C2) server. This stops data exfiltration and prevents the attacker from issuing further commands, buying time for deeper analysis. Firewall ACLs or blackhole routes can be applied in seconds without altering the endpoint, which is critical when the malware may have persistence mechanisms or anti-forensic capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the malicious files from the system

    Why it's wrong here

    Deleting files does not terminate the running process or block the command-and-control IP, so beaconing continues until the malware reinfects or reloads. File deletion belongs to eradication once containment has stopped the traffic; blocking the IoC address is the immediate containment step.

  • ✗

    Remove the malware from the workstation using EDR

    Why it's wrong here

    EDR remediation cleans the host but leaves the command-and-control channel reachable, so the compromised endpoint can re-establish contact or beacon again. It is tempting because malware removal feels like containment, yet it would be correct only after network-level blocking has severed the active exfiltration path.

  • ✓

    Block the IP address at the perimeter firewall

    Why this is correct

    Blocking the command-and-control IP at the perimeter firewall immediately severs the workstation's outbound channel, halting data exfiltration and further instruction. This satisfies the containment constraint by stopping active communication fast, before deeper host remediation begins.

  • ✗

    Disable the user's account

    Why it's wrong here

    Disabling the account does not sever the workstation's existing outbound connection to the command-and-control IP, since the malware runs in the user's session or as a service independent of authentication. Account disablement fits credential-compromise containment, not network-level IoC blocking.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.