Courseiva
mediumMultiple SelectObjective-mapped

Appropriate Actions During the Containment Phase of Incident Response

Which TWO actions are appropriate during the containment phase of incident response?

Quick Answer

Blocking malicious IP addresses at the firewall is a core containment action because containment's entire purpose is to stop an incident from getting worse while the investigation continues, and cutting off communication with known attacker infrastructure does exactly that at the network level. Once malicious IPs are identified, typically the addresses associated with command-and-control servers or the attacker's point of origin, blocking them at the firewall immediately denies the attacker further access to affected systems and prevents ongoing data exfiltration or remote command execution, without requiring the incident to be fully investigated first. This pairs naturally with isolating the affected system from the network, since both actions share the same containment goal of severing the attacker's channels: isolating the host stops it from spreading laterally to other internal systems, while blocking the IP stops external communication regardless of which internal host the attacker might reach next. Containment actions are deliberately fast, in contrast to eradication steps like removing malware or patching vulnerabilities, which come later once the scope of the incident is better understood. When a question asks what belongs in the containment phase specifically, look for actions that immediately cut off attacker access or communication, such as network isolation, IP blocking, or disabling compromised accounts, rather than actions that clean up or prevent recurrence, which belong to eradication and recovery.

⚠ Common exam trap

ISC2 often tests the distinction between containment, eradication, and recovery phases, and the trap here is that candidates mistakenly classify malware removal or root cause analysis as containment actions, when they actually belong to later phases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolating the affected system from the network

During the containment phase of incident response, the primary goal is to stop the incident from spreading and to limit damage. Isolating the affected system from the network (Option C) immediately prevents lateral movement of the threat and further data exfiltration. Blocking malicious IP addresses at the firewall (Option D) is another containment action that cuts off communication with known command-and-control servers or attack sources, effectively containing the network-level impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restoring data from backups

    Why it's wrong here

    Restoration is recovery phase.

  • Removing malware from the system

    Why it's wrong here

    Removal is eradication phase.

  • Isolating the affected system from the network

    Why this is correct

    Isolation prevents spread.

  • Blocking malicious IP addresses at the firewall

    Why this is correct

    Blocking IPs limits attacker access.

  • Analyzing the root cause of the incident

    Why it's wrong here

    Root cause analysis is part of eradication and recovery, not containment.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions are part of the containment phase of incident response?

medium
  • A.Restoring from backups
  • B.Analyzing root cause
  • C.Applying temporary patches
  • D.Isolating affected systems
  • E.Preserving evidence

Why C: During the containment phase of incident response, the immediate priority is to stop the incident from spreading or causing further damage. Applying temporary patches (C) can quickly close a vulnerability that is being exploited, while isolating affected systems (D) prevents lateral movement and further compromise. Both actions are short-term measures to contain the threat before eradication and recovery begin.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.