Master the NIST Incident Response lifecycle. Learn how to immediately halt lateral movement during an active breach scenario.
A high-severity alert just triggered in the SOC. A financial controller's workstation (WS-FIN-042) has been compromised. The attacker has bypassed local AV and is currently using compromised credentials to scan and connect to internal file shares and domain controllers.
As the primary incident handler, you have confirmed the threat is real and active. The immediate priority is stopping the bleeding before the attacker accesses sensitive financial data or deploys ransomware across the network.
Review the SIEM and EDR telemetry. The attacker is actively pivoting.
Which of the following steps of incident handling and response process focus on limiting the scope and extent of an incident?
The SOC has detected active lateral movement originating from WS-FIN-042. The attacker is using WMI and NTLM authentications to move from the initially compromised host to Domain Controllers and File Shares. The incident is currently unfolding in real-time.
Containment is the phase of the NIST Incident Response lifecycle strictly focused on limiting the scope and extent of an incident. In this scenario, containing the threat means isolating WS-FIN-042 from the network (e.g., using CrowdStrike's "Network Contain" feature) to physically and logically prevent the attacker from reaching FS-FINANCE-SHARE or the Domain Controller. You stop the bleeding first.
In a real SOC, hesitation during the Containment phase leads to full domain compromise. Junior analysts often spend too much time trying to figure out *how* the attacker got in (Identification/Forensics) while the attacker is actively encrypting servers. As a Senior Analyst, my rule is: If you confirm a host is compromised and beaconing/pivoting, **isolate it immediately**. You can always investigate an isolated machine, but you cannot un-encrypt a file share.
The NIST SP 800-61r2 framework defines the IR lifecycle as Preparation, Detection & Analysis (Identification), Containment, Eradication, & Recovery, and Post-Incident Activity.
Containment is often split into two sub-phases:
Improve your threat detection and IR planning skills with more hands-on scenarios.
Explore more CSA simulations