Courseiva

SSCP Incident Response and Recovery Practice Question

During incident response, a team needs to isolate an infected workstation that is part of a critical manufacturing network. Which containment method is MOST appropriate to minimize disruption while preventing the spread of malware?

⚠ Common exam trap

Candidates often choose 'physically unplug the network cable' because it seems like the most definitive containment, but they overlook the requirement to minimize disruption in a critical manufacturing network where sudden disconnection can halt production or cause safety hazards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the workstation into a quarantine VLAN via switch configuration

Placing the workstation into a quarantine VLAN via switch configuration is most appropriate because it logically isolates the infected host from the rest of the network at Layer 2, preventing lateral spread of malware while allowing the manufacturing network to continue operating. This method uses 802.1Q VLAN tagging and access control lists (ACLs) on the switch to restrict traffic without physically disconnecting the device, which could disrupt time-sensitive manufacturing processes. It also preserves the ability to remotely manage or forensically image the workstation if needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Place the workstation into a quarantine VLAN via switch configuration

    Why this is correct

    A quarantine VLAN isolates the workstation at the switch port while leaving the manufacturing network's routing and production traffic intact. This contains malware spread with minimal disruption, unlike disabling the switch port or powering off, which would halt critical operations.

  • ✗

    Apply a host-based firewall rule to block all inbound traffic

    Why it's wrong here

    Blocking only inbound traffic leaves the infected host's outbound connections open, so malware still reaches command-and-control and lateral targets. It is tempting because inbound filtering genuinely protects a server from external scanning and exploitation attempts while preserving its outbound service dependencies.

  • ✗

    Physically unplug the network cable

    Why it's wrong here

    Pulling the cable severs all connectivity, including the manufacturing line's control traffic, causing the disruption the scenario forbids. It is tempting because physical disconnection is the definitive isolation method for a standalone, non-critical endpoint where total loss of network function is acceptable.

  • ✗

    Disable the user's Active Directory account

    Why it's wrong here

    Disabling the account blocks authentication, not the workstation's existing network sessions, so malware keeps spreading from the running host. It is tempting because account lockout genuinely contains credential-based intrusions, such as a compromised user login, where revoking access stops the attacker's authenticated activity.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.