Courseiva

SSCP Incident Response and Recovery Practice Question

During a malware outbreak, a security analyst needs to contain the spread. The affected systems are on the same VLAN as critical servers. Which of the following containment actions should be performed FIRST to minimize impact?

⚠ Common exam trap

The SSCP exam emphasizes that containment must occur at the network layer first, not at the host or user layer. The trap here is that candidates mistakenly choose to reboot or disable accounts, thinking they are stopping the infection, when in fact they are ignoring the immediate lateral spread risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the affected systems by applying VLAN quarantine or ACLs

Isolating the affected systems by applying VLAN quarantine or ACLs is the correct first action because it immediately stops the malware from spreading laterally across the same VLAN to critical servers, while preserving forensic evidence. This network-level containment is faster and less disruptive than account or system-level changes, and it prevents the outbreak from propagating before any remediation begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable user accounts associated with the infected systems

    Why it's wrong here

    Disabling user accounts does not sever the network path between infected hosts and critical servers on the same VLAN, so lateral movement continues. Account disablement suits credential-compromise scenarios where revoking access stops an attacker, not active malware propagating host-to-host across a shared segment.

  • ✓

    Isolate the affected systems by applying VLAN quarantine or ACLs

    Why this is correct

    VLAN quarantine or ACLs sever network reachability between the infected hosts and the critical servers sharing that VLAN, halting lateral spread without powering systems off and destroying volatile evidence. This directly satisfies the stem's requirement to minimise impact on the co-located critical servers first.

  • ✗

    Reboot the affected systems to clear malware from memory

    Why it's wrong here

    Rebooting may clear volatile memory but does not isolate the host, so the malware can re-infect from persistent storage and continue spreading across the shared VLAN to critical servers. Reboots are tempting as a quick remediation for transient in-memory infections, but containment demands network isolation first.

  • ✗

    Restore the affected systems from backup

    Why it's wrong here

    Restoring from backup is remediation, not containment; infected systems remain live on the VLAN and keep spreading malware to critical servers during the restore. Backup restoration is the right step after isolation, once the threat is contained and the clean image is verified.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.