Lab Simulation Active

Incident Handling Containment

EC-Council CCT — Incident Handling & Response Lab

🔬

Lab Environment — Scenario

Warren, a member of IH&R team at an organization, was tasked with handling a malware attack launched on one of servers connected to the organization's network. He immediately implemented appropriate measures to stop the infection from spreading to other organizational assets and to prevent further damage to the organization.
🛡

Incident Response Simulation

01Preparation
02Detection
03Triage
04Containment
05Eradication
06Recovery
incident-response.log
[14:22:03] ALERT — Malware detected on SRV-PROD-04
[14:22:15] IH&R — Warren assigned to incident #2847
[14:23:01] ACTION — Isolating SRV-PROD-04 from network
[14:23:08] ACTION — Blocking lateral movement on VLAN-12
[14:23:22] ACTION — Firewall rules updated — outbound C2 traffic blocked
[14:23:45] CONTAINED — Infection isolated — spread prevented
[14:24:00] STATUS — Containment measures active — no further propagation
🔒 Containment stops the threat from spreading while preserving evidence for analysis

Identify the IH&R step performed by Warren in the above scenario.

A Containment
B Recovery
C Eradication
D Incident triage