Which statement best describes the primary objective of containment/active defense?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

Which statement best describes the primary objective of containment/active defense?

Explanation:
Containment/active defense centers on preventing or slowing attacker access while you observe what’s happening and gather evidence. The aim is to limit further damage and keep critical assets safe during the monitoring and collection window, giving defenders time to eradicate the threat and recover cleanly. Full-scale monitoring is part of detection, not the containment goal. Bit mangling describes destructive actions that aren’t appropriate containment practice. Data decoy is a deception tactic, which may support an incident response strategy, but it isn’t the primary objective of containment. So the best description is to prevent or slow additional access during the monitoring and collection phase.

Containment/active defense centers on preventing or slowing attacker access while you observe what’s happening and gather evidence. The aim is to limit further damage and keep critical assets safe during the monitoring and collection window, giving defenders time to eradicate the threat and recover cleanly. Full-scale monitoring is part of detection, not the containment goal. Bit mangling describes destructive actions that aren’t appropriate containment practice. Data decoy is a deception tactic, which may support an incident response strategy, but it isn’t the primary objective of containment. So the best description is to prevent or slow additional access during the monitoring and collection phase.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy