SSCP Incident Response and Recovery Practice Question
During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?
⚠ Common exam trap
Candidates often choose 'physically unplug the network cable' because it seems like the most definitive containment, but they overlook the requirement to minimize disruption in a critical manufacturing network where sudden disconnection can halt production or cause safety hazards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the workstation into a quarantine VLAN via switch configuration
Placing the workstation into a quarantine VLAN via switch configuration is most appropriate because it logically isolates the infected host from the rest of the network at Layer 2, preventing lateral spread of malware while allowing the manufacturing network to continue operating. This method uses 802.1Q VLAN tagging and access control lists (ACLs) on the switch to restrict traffic without physically disconnecting the device, which could disrupt time-sensitive manufacturing processes. It also preserves the ability to remotely manage or forensically image the workstation if needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place the workstation into a quarantine VLAN via switch configuration
Why this is correct
A quarantine VLAN isolates the workstation at the switch port while leaving the manufacturing network's routing and production traffic intact. This contains malware spread with minimal disruption, unlike disabling the switch port or powering off, which would halt critical operations.
- ✗
Apply a host-based firewall rule to block all inbound traffic
Why it's wrong here
Blocking only inbound traffic leaves the infected host's outbound connections open, so malware still reaches command-and-control and lateral targets. It is tempting because inbound filtering genuinely protects a server from external scanning and exploitation attempts while preserving its outbound service dependencies.
- ✗
Physically unplug the network cable
Why it's wrong here
Pulling the cable severs all connectivity, including the manufacturing line's control traffic, causing the disruption the scenario forbids. It is tempting because physical disconnection is the definitive isolation method for a standalone, non-critical endpoint where total loss of network function is acceptable.
- ✗
Disable the user's Active Directory account
Why it's wrong here
Disabling the account blocks authentication, not the workstation's existing network sessions, so malware keeps spreading from the running host. It is tempting because account lockout genuinely contains credential-based intrusions, such as a compromised user login, where revoking access stops the attacker's authenticated activity.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.