During a ransomware response, an analyst identifies a compromised domain controller and knows immediate isolation is needed, but isolation of production directory services exceeds their documented authority. What should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of escalation like a pilot calling for clearance: you see the hazard, but you don't yank controls outside your authority. Report the impact, your options, and the approval you need so management can decide fast. The trap is mistaking urgency for permission.
Full Explanation
Escalation reporting exists to preserve decision rights when technical necessity conflicts with documented authority. In this scenario, the analyst should package the facts needed by management: confirmed impact, business risk of delay, viable containment options, required action, and a clear approval request. That allows a rapid, accountable decision without the analyst overstepping or leaving leadership uninformed. Immediate isolation is wrong because the action exceeds authority and can disrupt authentication or replication; the analyst must not substitute urgency for authorization. Technical-only notification is wrong because management needs business impact and approval, not just a technical handoff. Waiting for the next change window is wrong because incident response can require emergency change procedures, and deferral risks lateral movement or encryption. Exam caveat: choose the response that matches policy-defined authority and communicates risk, not the fastest technical action. Operational check: before escalation, include affected systems, evidence, severity or business impact, containment options, time sensitivity, and the exact approval needed.