Courseiva
mediumMultiple ChoiceObjective-mapped

Data Exfiltration Containment: Isolate Affected System First

A security team is investigating a potential data exfiltration incident. They notice that a large amount of data was transferred to an external IP address during off-hours. What should be the first step?

Quick Answer

The answer is to isolate the affected system from the network. This is the correct first step because data exfiltration containment relies on immediately severing the communication channel to the external IP address, stopping the ongoing data transfer and preventing further loss. By isolating the system, you preserve its volatile state for forensic analysis, which is critical for understanding the attack vector and scope of the breach. On the Systems Security Certified Practitioner SSCP exam, this scenario tests your understanding of the NIST SP 800-61 incident response lifecycle, where containment must always precede eradication and recovery. A common trap is to jump to eradication, such as deleting files or reimaging the system, which destroys evidence. Remember the memory tip: “Contain before you clean” — always isolate first to stop the bleed, then investigate.

⚠ Common exam trap

Candidates often choose to block the external IP (Option B) thinking it stops the attack, but the correct first step is to isolate the affected system at the host level to prevent the attacker from pivoting or using alternate C2 channels, and to preserve forensic evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the affected system from the network.

The immediate priority in a suspected data exfiltration incident is to contain the threat and prevent further data loss. Isolating the affected system from the network stops ongoing communication with the external IP address, preserving the system state for forensic analysis. This aligns with the NIST SP 800-61 incident response lifecycle, where containment precedes eradication and recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Notify senior management of the incident.

    Why it's wrong here

    Notification is important but does not stop the active exfiltration.

  • Block the external IP address at the firewall.

    Why it's wrong here

    Blocking the IP may stop exfiltration but the system remains compromised.

  • Analyze the data transfer logs to determine the scope.

    Why it's wrong here

    Analysis should follow containment to avoid further loss.

  • Isolate the affected system from the network.

    Why this is correct

    Isolation stops the exfiltration immediately.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A university's IT department manages a network used by students and faculty. The security team notices an unusual increase in outbound traffic from the student dormitory network during late hours. Upon investigation, they discover that several student laptops are infected with malware that is attempting to connect to external command-and-control (C2) servers. The team needs to contain the incident quickly while minimizing impact on legitimate users. Which of the following is the BEST immediate containment measure?

easy
  • A.Shut down the entire dormitory network
  • B.Disconnect the infected laptops from the network and take them offline for remediation
  • C.Block all outbound traffic from the dormitory subnet
  • D.Update the antivirus definitions on the infected laptops

Why B: Isolating the infected devices from the network stops the C2 communication and prevents further spread, while allowing other users to continue working. Option A may block all students; C is disruptive to everyone; D does not stop communication.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.