After initial isolation of a compromised workstation, an analyst rotates service credentials, segments affected VLANs, and enables enhanced monitoring while forensic imaging continues. Which incident response phase is being performed?
Select an answer to reveal the explanation.
Short Explanation
Think of containment as building a fence: short-term isolation stops the bleeding, then rotating creds and segmenting keeps the attacker from moving laterally. That is long-term containment, not eradication, because you are still limiting spread while evidence stays intact. You are holding the situation steady, not cleaning it out.
Full Explanation
Long-term containment follows initial isolation when the analyst needs to keep an incident from spreading without destroying evidence. Rotating credentials removes the attacker's ability to reuse access, segmenting affected systems reduces lateral movement paths, and enhanced monitoring lets the team observe residual activity while forensic collection proceeds. These actions constrain the environment, so they fit containment rather than cleanup. Eradication would involve removing the malware, deleting persistence mechanisms, and eliminating the root cause, which can alter evidence before it is captured. Recovery to normal operations would occur after eradication and validation, when systems are restored to production with confidence that the threat is gone. Identification of affected systems happens earlier, when logs, EDR telemetry, and asset data are used to determine scope and impact; it is not the act of applying controls to stop movement. Exam caveat: when a scenario describes ongoing restrictions such as segmentation, credential rotation, or monitoring during evidence handling, choose containment even if the controls feel remedial. Operational check: confirm the ticket records isolation, credential rotation, segmentation changes, monitoring exclusions, and evidence preservation status before moving to eradication.