SSCP Incident Response and Recovery Practice Question
During a malware outbreak, a security analyst needs to contain the spread. The affected systems are on the same VLAN as critical servers. Which of the following containment actions should be performed FIRST to minimize impact?
⚠ Common exam trap
The SSCP exam emphasizes that containment must occur at the network layer first, not at the host or user layer. The trap here is that candidates mistakenly choose to reboot or disable accounts, thinking they are stopping the infection, when in fact they are ignoring the immediate lateral spread risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the affected systems by applying VLAN quarantine or ACLs
Isolating the affected systems by applying VLAN quarantine or ACLs is the correct first action because it immediately stops the malware from spreading laterally across the same VLAN to critical servers, while preserving forensic evidence. This network-level containment is faster and less disruptive than account or system-level changes, and it prevents the outbreak from propagating before any remediation begins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable user accounts associated with the infected systems
Why it's wrong here
Disabling user accounts does not sever the network path between infected hosts and critical servers on the same VLAN, so lateral movement continues. Account disablement suits credential-compromise scenarios where revoking access stops an attacker, not active malware propagating host-to-host across a shared segment.
- ✓
Isolate the affected systems by applying VLAN quarantine or ACLs
Why this is correct
VLAN quarantine or ACLs sever network reachability between the infected hosts and the critical servers sharing that VLAN, halting lateral spread without powering systems off and destroying volatile evidence. This directly satisfies the stem's requirement to minimise impact on the co-located critical servers first.
- ✗
Reboot the affected systems to clear malware from memory
Why it's wrong here
Rebooting may clear volatile memory but does not isolate the host, so the malware can re-infect from persistent storage and continue spreading across the shared VLAN to critical servers. Reboots are tempting as a quick remediation for transient in-memory infections, but containment demands network isolation first.
- ✗
Restore the affected systems from backup
Why it's wrong here
Restoring from backup is remediation, not containment; infected systems remain live on the VLAN and keep spreading malware to critical servers during the restore. Backup restoration is the right step after isolation, once the threat is contained and the clean image is verified.
Visual reference
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.