ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization runs its production microservices on a managed Kubernetes cluster in a public cloud. The SOC's SIEM triggers an alert showing hundreds of failed SSH attempts in the last five minutes against the bastion host that administrators use to reach worker nodes. According to standard incident-response workflow, which immediate action best represents the containment phase while still preserving evidence for possible forensics?
Shut down and delete the entire virtual network that contains the Kubernetes cluster to guarantee the attacker is removed.
Immediately file a breach notification with the relevant data-protection regulator and await further instructions.
Increase SIEM log retention from 30 to 90 days to gather more historical context before acting.
Create a temporary deny rule for the offending IP address in the bastion host's cloud network security group and begin a forensic disk and memory snapshot of the host.
In the containment phase, responders act quickly to limit the attacker's ability to continue or expand the intrusion, but without destroying or altering evidence that investigators will later need. Adding a high-priority deny rule in the cloud network security group that blocks the single malicious IP meets this goal: it immediately stops further brute-force traffic yet keeps the bastion host and cluster online so analysts can capture volatile memory and disk images. Simply increasing SIEM log retention is a detection/analysis enhancement, not a containment control, and it will not halt the active attack. Filing a breach notification may be required by regulation, but it belongs to the communication phase and does not mitigate the live threat. Shutting down and deleting the entire virtual network is an eradication/recovery action that causes needless downtime and eliminates evidence.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the containment phase in incident response?
Open an interactive chat with Bash
What is a bastion host and why is it important?
Open an interactive chat with Bash
What is a cloud network security group and how does it work?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .