Containment and Eradication Strategies Quiz

5 questions Pass: 70% +25 pts

Quiz covering Incident Response Planning

Containment and Eradication Strategies Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which of the following is the primary goal of the 'Containment' phase in the Incident Response Lifecycle?

  2. 2

    You have identified a workstation infected with ransomware that is attempting to communicate with a Command and Control (C2) server. What is the most effective immediate containment strategy?

  3. 3

    During the Eradication phase, why is it critical to perform a vulnerability assessment after removing malicious artifacts?

  4. 4

    When dealing with a high-profile, sophisticated threat, why might an organization choose 'Short-term Containment' over 'Long-term Containment' initially?

  5. 5

    A threat actor has established persistence via a compromised service account. During eradication, which combination of actions is mandatory to ensure the account cannot be used again?