03. Incident Containment Methods (484) Flashcards
1
Q
Incident Containment Methods
The steps taken to prevent an incident spreading further
484
A
Differs to eradication.
Containment, the threat still exists but cannot spread further during to be contained
2
Q
Containment activities, DR and BCP
Security incident response is split into 2 channels;
1. Security Incident Response
2. Disaster Recovery
485
A
3
Q
Containment activities, DR and BCP
Containment may make systems unavailable and disrupt businsess processes.
This may require the execution of disaster recovery plans
If DR cannot recover systems rapidly, BCP plans may be executed
485
A