mediumMultiple Select
Appropriate Actions During the Containment Phase of Incident Response
Which TWO actions are appropriate during the containment phase of incident response?
Quick Answer
Blocking malicious IP addresses at the firewall is a core containment action because containment's entire purpose is to stop an incident from getting worse while the investigation continues, and cutting off communication with known attacker infrastructure does exactly that at the network level. Once malicious IPs are identified, typically the addresses associated with command-and-control servers or the attacker's point of origin, blocking them at the firewall immediately denies the attacker further access to affected systems and prevents ongoing data exfiltration or remote command execution, without requiring the incident to be fully investigated first. This pairs naturally with isolating the affected system from the network, since both actions share the same containment goal of severing the attacker's channels: isolating the host stops it from spreading laterally to other internal systems, while blocking the IP stops external communication regardless of which internal host the attacker might reach next. Containment actions are deliberately fast, in contrast to eradication steps like removing malware or patching vulnerabilities, which come later once the scope of the incident is better understood. When a question asks what belongs in the containment phase specifically, look for actions that immediately cut off attacker access or communication, such as network isolation, IP blocking, or disabling compromised accounts, rather than actions that clean up or prevent recurrence, which belong to eradication and recovery.
⚠ Common exam trap
ISC2 often tests the distinction between containment, eradication, and recovery phases, and the trap here is that candidates mistakenly classify malware removal or root cause analysis as containment actions, when they actually belong to later phases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolating the affected system from the network
During the containment phase of incident response, the primary goal is to stop the incident from spreading and to limit damage. Isolating the affected system from the network (Option C) immediately prevents lateral movement of the threat and further data exfiltration. Blocking malicious IP addresses at the firewall (Option D) is another containment action that cuts off communication with known command-and-control servers or attack sources, effectively containing the network-level impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restoring data from backups
Why it's wrong here
Restoring data from backups belongs to eradication and recovery, after the threat is fully removed and systems are clean. It is tempting because backups are the ultimate restoration mechanism, but that is precisely why they are reserved for recovery, not containment, where the priority is isolating affected systems to stop lateral spread.
- ✗
Removing malware from the system
Why it's wrong here
Removing malware is eradication, performed after containment has stopped the spread and before recovery. It is tempting because malware removal feels urgent, yet containment requires isolating the host first; deleting the sample prematurely can also destroy forensic evidence needed to scope the incident.
- ✓
Isolating the affected system from the network
Why this is correct
Isolating the affected system from the network severs the attacker's access path and prevents lateral movement to other hosts. This is a containment action because it stops the incident spreading while evidence is preserved for later analysis.
- ✓
Blocking malicious IP addresses at the firewall
Why this is correct
Blocking malicious IP addresses at the firewall stops ongoing attacker traffic from reaching the environment, limiting spread while investigation proceeds. This is a containment action because it restricts the adversary's access without yet eradicating the threat.
- ✗
Analyzing the root cause of the incident
Why it's wrong here
Root-cause analysis is a post-incident activity, conducted after recovery to prevent recurrence. It is tempting because understanding the cause feels central to handling an incident, but during containment the priority is limiting damage and preserving evidence, not determining why the compromise occurred.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions are part of the containment phase of incident response?
medium- A.Restoring from backups
- B.Analyzing root cause
- ✓ C.Applying temporary patches
- ✓ D.Isolating affected systems
- E.Preserving evidence
Why C: During the containment phase of incident response, the immediate priority is to stop the incident from spreading or causing further damage. Applying temporary patches (C) can quickly close a vulnerability that is being exploited, while isolating affected systems (D) prevents lateral movement and further compromise. Both actions are short-term measures to contain the threat before eradication and recovery begin.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.