CSA (312-39) SOC Simulation Lab

Master the fundamental phases of Incident Handling and Response (IH&R). In this simulation, you will step into the shoes of a Tier 3 analyst bringing order to a chaotic, out-of-sequence incident response initiated by a junior team member.

Scenario Context

You are the Lead Incident Responder on shift. A high-severity alert fired indicating ransomware behavior on a critical database server. A junior analyst reacted immediately to the alert, but their response was scattered, poorly documented, and severely out of order—risking the destruction of forensic evidence and business continuity.

You must step in, halt their actions, and enforce the strict incident handling framework required by industry standards (NIST/EC-Council).

Security Environment

SOC Collaboration Chat (MS Teams Excerpt):

[14:02:11] SIEM-BOT: CRITICAL ALERT: CrowdStrike - Ransomware behavior on SRV-DB01. [14:03:00] JrAnalyst: I see the alert! I'm wiping the server completely so it doesn't spread! [14:04:15] SrAnalyst (You): STOP. Did you even isolate the host from the network first? Did you dump memory? [14:04:45] JrAnalyst: No, I just started formatting the C:\ drive. Let me go create a Jira ticket now so we have a record. [14:05:10] SrAnalyst (You): You are executing the response completely backwards. What does our Ransomware Playbook say? [14:06:00] JrAnalyst: Playbook? Do we have one? Where are those kept? I wasn't ready for this! [14:06:30] SrAnalyst (You): We need to review the standard IH&R flow immediately...

Question

Which of the following is a correct flow of the stages in an incident handling and response (IH&R) process?
SOC Lead Hint: Think logically about the timeline. Playbooks and tool configurations must be established before an incident ever occurs. Furthermore, you can't eradicate an attacker from a network if you haven't first contained them.

Expert Insight

1. What is happening

The junior analyst is reacting to a critical alert entirely out of phase. By attempting eradication (wiping the drive) before containment (network isolation) and triage (understanding the scope), they destroyed forensic evidence. Moreover, they failed to ensure preparation (playbooks) and incident recording (ticketing) were handled prior to taking destructive actions.

2. Why the correct answer is correct

B. Preparation -> Incident Recording -> Incident Triage -> Containment -> Eradication -> Recovery -> Post-Incident Activities

This is the definitive EC-Council / standard industry IH&R flow. Preparation establishes policies and tools. When an event fires, it is Recorded (ticketed/logged) so the SOC has a chain of custody. It is then Triaged to determine severity and true positive status. Only then do you move to Containment (stopping the bleeding), followed by Eradication (removing the threat), and finally Recovery and Post-Incident review.

3. Why other options are wrong

A, C, & D: All these options place "Preparation" somewhere in the middle of an active incident. Preparation is a continuous phase that must occur before an attack. Additionally, these options frequently place Eradication before Containment. You cannot effectively eradicate an adversary if you haven't closed their backdoor accesses (Containment) first—they will just reinfect the host.

5. MINI LESSON: Triage vs. Containment vs. Eradication

SOC analysts frequently confuse the middle stages of the IH&R process. Keep these strict definitions in mind:

  • Triage: "Is this real and how bad is it?" Analyzing the alert, gathering initial evidence, and prioritizing the incident. No changes are made to the endpoint.
  • Containment: "Stop the bleeding." Isolating the host via EDR (e.g., CrowdStrike Network Containment), blocking IPs on the firewall, or disabling compromised AD accounts. Evidence is preserved.
  • Eradication: "Remove the threat." Deleting malicious files, terminating rogue processes, rebuilding systems from bare metal, and patching the initial vulnerability.
Ready to refine your Incident Response methodologies?
Explore more CSA simulations at ExamRange