During a supply-chain credential compromise, your SOC confirms an attacker reused a service-account credential from a SaaS vendor to access hybrid workloads. The SaaS tenant is outside your direct administrative control. What is the required incident response process step?
Select an answer to reveal the explanation.
Short Explanation
Think of a shared incident like a two-car accident: you can’t just fix your side and call it done. Coordinate containment with the vendor through their incident response process. If you skip that, you’re guessing about systems you don’t control.
Full Explanation
In incidents where part of the affected environment is vendor-controlled, the required process step is coordinated containment through the vendor’s incident response process. The organization still owns detection, evidence collection, and internal containment, but eradication and access revocation depend on the third party’s administration plane. A defined communication channel, escalation contact, and shared responsibility matrix determine what can be isolated, reset, or preserved without destroying shared evidence. Full forensic imaging of a vendor-controlled SaaS tenant is usually not available to the customer and may violate provider policy; preservation must be requested through the vendor’s process. Resetting internal credentials and isolating accounts is necessary but incomplete because it ignores the external control plane and the vendor’s role in eradication. Escalating to law enforcement before containment is premature; law enforcement may be notified later, but containment and evidence preservation remain the operational priority. Exam caveat: CompTIA expects you to identify the process step that matches the responsibility boundary, not to invent a technical action the customer cannot perform. Operational check: Confirm the vendor’s incident contact, preservation request path, and approved containment window before the next shared-service incident.