What is the primary goal of containment?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

What is the primary goal of containment?

Explanation:
Containment is about stopping the attacker from progressing and reducing the damage by degrading their ability to achieve their objectives. In practice, this means actions like isolating affected systems, blocking malicious traffic and command-and-control channels, revoking or restricting compromised credentials, and segmenting networks to prevent spread. The aim is to reduce risk and buy time for investigation and remediation, not to restore operations immediately or to collect data as the primary goal, and certainly not to punish attackers. By limiting attacker capabilities and opportunities, containment effectively curtails the incident’s impact while you determine the full scope and proceed with recovery.

Containment is about stopping the attacker from progressing and reducing the damage by degrading their ability to achieve their objectives. In practice, this means actions like isolating affected systems, blocking malicious traffic and command-and-control channels, revoking or restricting compromised credentials, and segmenting networks to prevent spread. The aim is to reduce risk and buy time for investigation and remediation, not to restore operations immediately or to collect data as the primary goal, and certainly not to punish attackers. By limiting attacker capabilities and opportunities, containment effectively curtails the incident’s impact while you determine the full scope and proceed with recovery.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy