ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While monitoring logs for a moderate-impact FISMA system, the security team detects an internal web server actively exfiltrating sensitive data to an unknown external IP address. According to the incident handling guidance in NIST SP 800-61, which action should the team take first to contain the incident while preserving compliance requirements?
Permit the connection to continue but enable full packet capture to gather additional evidence on the gateway.
Immediately disconnect the affected server from the network and capture its volatile memory before powering it down.
Notify the Inspector General and wait for formal guidance before taking any technical action.
Sanitize the server's storage and restore the operating system and data from a trusted backup.
NIST SP 800-61 recommends that once an incident is confirmed, the handler's first priority in the containment phase is to limit further damage as quickly as possible while also preserving evidence for later analysis. Isolating the compromised host from the network stops additional data loss and, if done properly, still allows responders to capture volatile memory before shutting the system down for forensics. Wiping or re-imaging the server is an eradication step that destroys evidence; delaying action to await external notification risks continued data loss; and continuing to allow exfiltration for evidence collection conflicts with the objective of rapid containment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-61?
Open an interactive chat with Bash
Why is capturing volatile memory important during incident handling?
Open an interactive chat with Bash
What does the containment phase involve in incident response?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .