A high-severity alert suggests ransomware is spreading across file shares. The triage analyst confirms malicious activity and recommends isolating affected hosts. Who should authorize containment before the response team acts?
Select an answer to reveal the explanation.
Short Explanation
Think of containment like stopping a car: the person in the driver's seat decides, not the passenger pointing out the hazard. You can let the triage analyst investigate and recommend, but don't hand the containment call to the analyst when the incident manager owns the big decision. That keeps the response coordinated instead of chaotic.
Full Explanation
During a high-severity incident, the incident manager owns overall coordination and formal authorization for containment because containment can disrupt business operations and requires a single accountable decision point. The triage analyst's job is to validate the alert, investigate the scope, preserve evidence, and recommend an action, not to make the operational containment decision alone. A threat hunter contributes hunting results, hypotheses, and indicator correlation, but hunting is investigative and does not confer authority to isolate systems. A SOC manager or staffing lead may be notified for escalation, resourcing, or process improvement, yet that role is not the incident command authority unless formally designated as incident manager. A service desk or business owner may be consulted for operational impact, but that consultation does not replace the incident manager's containment authorization. Exam caveat: CompTIA often separates the investigating role from the coordinating role, so look for the person accountable for the incident decision. Operational check: In the incident ticket, require the incident manager to record approval, scope, and time for containment before automated isolation is executed.