Govur University Logo
--> --> --> -->
...

A security team sees a bad login on a computer. The first person checks and confirms it's a real attack. What is the very next big step they take to fix the problem, and who on the team usually does the actual work to stop the bad guy right away?



After a security team confirms a bad login is a real attack, the very next big step they take to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized access, or data exfiltration. This involves taking immediate actions to stop the a....

Log in to view the answer



Community Answers

Sign in to open profiles and full community answers.

Kattunga Kumar Soma Sekhar

“after confriming a real attack, the very next big step the step the security team takes to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized acess or data exfliltration by immediatly stopping the attackers activity and preventing them from spreading within the environment common containment actions include isolating the compromised system from the network, disabling the breached user account, or blocking the attackers IP address at the firewall. the individuals on the team who usually do the actual technical work to stop the bad guy right away are a security analyst or an incident responder. A security analyst monitors security system role focused on activity managing and resolving incidents through direct technical intervention to mitigate threats immediately”

100.0%

Hunter Saenz

“after confiming a real attack, the very next big step the seucirty team takes to fix the problem is contaiment. Containment is the process of limiting the scope andimpact of a security incident to prevent further damage, unauthoriszed access or data exflitration by immediately stopping the attackers acrivitiy and preventing them from spreading within the enviroment common containment actions include isolating the compromised system from the network, disabling the breached user account, or blocking the attackers IP address at the firewall. The indiviudals on the team who usually do theactual technical work to stop the bad guy right away are the security analyst or an incident responder. A security analyst monitors security system role focused on sactively managing and resolving incidents through direct technical intervention to mitgate threats immediately.”

100.0%

Ismail Mahbuub

“after confirming a rel attack, the very next big step the security team takes to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized acess or data exfliltration by immediatly stopping the attackers activity and preventing them from spreading within the environment common containment actions include isolating the compromised system from the network, disabling the breached user account, or blocking thr attackers IP address at the firewall. the individuals on the team who usually do the actual technical work to stop the bad guy right away are a security analyst or an incident Ressponder. A security analyst monitors security system role focused on actively managing and resolving incidents through direct technical intervention to mitigate threats immediately.”

100.0%

Layba Hamid Khan

“1. Containment: After the security team confirms that a suspicious login is a real security incident, the next major step is containment. Containment is the process of limiting the scope and impact of a cyberattack to prevent the attacker from causing further damage, gaining additional access, or stealing more data. During this phase, the team takes immediate actions such as isolating the compromised computer from the network, disabling the affected user account, blocking the attacker's IP address, or restricting access to sensitive systems. The primary goal of containment is to stop the attack from spreading while preserving evidence for further investigation. 2. Security Analyst or Incident Responder: The technical actions required to stop the attacker are ususally performed by a Security Analyst or Incident Responder. A Security Analyst is responsible for monitoring security systems, detecting threats, analyzing security alerts, and carrying out initial response actions. An Incident Responder is a cybersecurity specialist who manages and resolves security incidents by performing technical tasks such as isolating infected systems, removing the attacker's access, collecting forensic evidence, and coordinating recovery efforts. Their immediate objective is to neutralize the threat, minimize its impact, and ensure the organization can safely proceed to the eradication and recovery phases of incident response.”

100.0%

Adewale Ibrahim

“A security team confirms the attack. The next big thing is to fix thing is to fix the problem through a proces called containment. The steps involved in containment involces limiting the scope and impact of the security incident to prevenet further damage, unauthorized access aor data exfiltration by stopping the current activity of the attacker so that it does not spread to other environment. another instance could be by isolating the affected systerm to avoid further speread across the network or by blocking the attachers IP address at the firewall. The member of the security team whose actual work is to spread of the attacher is called a securit analyst. The security analyst is also responsible for monitoring the security system , dectecting threats and executing inititial response actions over the incident detected.”

100.0%

Siddhi Mishra

“after a security team confirms a bad login is real attack , the very big step thay can take to fix the problem is containment it is the process of limiting the scope and impact of a d security incident to prevent furhter damage , unauthorzed access or data exfiltration . common containment actions include isolating the compromised system from the network , disabling the breached user account or blocking the attackers ip address at the firewall. the individual on the team who usually does the actual work to stop the attacker right away by executing these technical containment actions is typically a security analysts or an incident reponders . a security analysts is responsible for monitoring security systems detecting threats and executing initials response actions. an incidents responder is a more specialized role., focused on actively managing and resolving security incidents through direct technical interventions to mitigate threats immedeiately”

98.0%

Oleksandr Musiienko

“After the initial analyst checks the suspicious login and confirms that it is a genuine security incident, the next major step is containment. The purpose of containment is to stop the attacker's current activity, prevent further unauthorized access, and keep the incident from spreading to other accounts or computers. The security team must act quickly, but it should also avoid destroying valuable evidence. Depending on the situation, containment actions may include: disabling or temporarily locking the compromised user account terminating the attacker's active sessions resetting the user's password and revoking authentication tokens isolating the affected computer from the network blocking the malicious IP address, domain or network connection disablihg compromised credentials, API keys, or remote-access methods applying temporary firewall or access-control rules increasing monitoring for related activity elsewhere in the environment The actual technical containment work is normally performed by a Security Analyst or an Incident Responder. A Security Analyst often performs the initial investigation and may execute standard containment actions according to an approved playbook. An Incident Responder is usually responsible for more serious or compex incidents and coordintates the technical actions requires to control and resolve the attack. Containment does not necessarily remove the attacker permanently. It is the immediate step used to control the situation. After containment, the team continues wuth eradication, during which malicious files, persistence mechanisms, compromised credentials and the root cause are removed. This is followed by recovery, when clean systems and accounts are safely returned to normal operation”

92.0%

Harsh Bhaskar

“After a Security team confirms a bad login is a real attack, the very next big step they take to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized access or data exfiltration. This involves taking immediate actions to stop the attacker's current activity and prevent them from spreading within the environment. For instance, common containment actions include isolating the comporomised system from the network, disabling the breached user account, or blocking the attacker's IP address at the firewall. The indivisual on the team who usually does the actual work to stop the bad guy right away by executing these technical containment actions is typically a security analyst or an incident responder. A security Analyst is responsible for monitering security systems, detecting threats and executing initial response actions. An incident Responder is a more specialixed role, focused on actively managing and resolving security incidents through direct technical intervention to mitigate threats immediately.”

87.0%

Celia Aitseddik

“Once the initial alert has been investigated and confirmed as a genuine security incident the next major step is containment , the objective is to limit the attacker's access prevent lateral movement and minimize further damage while preserving evidence for subsequent investigation the incident response or soc response team typically involving Tier 2/tier 3 analysts incident responders or security engineers usually performs the immediate containment actions such as isolating the compromised accounts blocking malicious IP addresses or domains and terminating active attacker sessions this phase is critical because it stops the threats before proceeding to eradica”

87.0%

Dimas Agung Prakasa

“after confirming the suspicious login is a real attack, the next major step is incident response and containment. the goal is to limit the damage and prevent the attacker from continuing their activities. The team members who usually perform the immediate actions to stop the attacker are the incident responders(often tier2/tier3 soc analyst or the incident response team). examples of containment actions include: - isolating the affected computer from the network - disabling compromised user accounts - blocking malicious ip address or domains - terminating malicious process in short: wrong login confirmed as an attack --> next step”

85.0%

Mostafa Mahmoud Khatab Tarad

“after the malicious login is confirmed as a real incident ,the next major step is containment .the goal pf containment is to stop the attackers activity ,limit the impact and prevent lateral movement or further unauthorized access . Typical containment actions include isolating the compromised host ,disabling the affected account ,blocking malicious ip adresses and terminating suspicious sessions These actions are usually preformed by a tier2 sic analyst or incident responders after the intial alert has been validated and escalated by tier 1 the respondder then proceeds toward eradication and recovery once the threat contained”

84.0%

Mohamed Malek Toumi

“After confirming that a bad login is a real security incident, the next major step is containment. Containment is the process of limiting the scope and impact of an attack to prevent further damage, unauthorized access, or data exfiltration. Common containment actions include isolating the compromised system from the network, disabling the affected user account, or blocking the attacker's IP address. The team member who usually performs these technical actions is a Security Analyst or an Incident Responder. They work to immediately stop the attacker's activity and reduce the impact of the incident.”

80.0%

GĂĽven Ada

“After a security team confirms a bad login is a real attack, the very next big step they take to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized access, or data exfiltration. This involves taking immediate actions to stop the attacker's current activity and prevent them from spreading within the environment. For instance, common containment actions include isolating the compromised system from the network, disabling the breached user account, or blocking the attacker's IP address at the firewall. The individual on the team who usually does the actual work to stop the bad guy right away by executing these technical containment actions is typically a Security Analyst or an Incident Responder. A Security Analyst is responsible for monitoring security systems, detecting threats, and executing initial response actions. An Incident Responder is a more specialized role, focused on actively managing and resolving security incidents through direct technical intervention to mitigate threats immediately.”

80.0%

Ganesh

“After a security team confirms a bad login is a real attack, the very next big step they take to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized access, or data exfiltration. This involves taking immediate actions to stop the attacker's current activity and prevent them from spreading within the environment. For instance, common containment actions include isolating the compromised system from the network, disabling the breached user account, or blocking the attacker's IP address at the firewall. The individual on the team who usually does the actual work to stop the bad guy right away by executing these technical containment actions is typically a security analyst or an incident responder. A securiy analyst is responsible for monitoring security incidents through direct technical intervention to mitigate threats immediately.”

79.0%

Rohan Adhikari

“After a security team confirms a bad login is a real attack, the very next big step they take to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent further damage, unauthorized access, or data exfiltration. This involves taking immediate actions to stop the attacker's current activity and prevent them from spreading within the environment. For instance, common containment ffirewall. The individual on the team who usually does the actual work to stop the bad guy right away by executing these technical containment actions is typically a Security Analyst or an Incident Responder. A Security Analyst is responsible for monitoring security systems, detecting threats, and executing initial response actions. An incident responder is a more specialized role, focused on actively managing and resolving security incidents through direct technical intervention to mitigate threats immediately.”

78.0%

Malikejder

“After confirming that the suspicious login is a real security incident, the next critical step is containment. The goal of containment is to immediately limit the attack's impact by isolating compromised systems, disabling affected accounts, blocking malicious IP addresses, and preventing lateral movement or data exfiltration. The technical containment actions are typically performend by an incident responder, or in some SOC environments by a security analyst, who executes the immediate response to stop the attacker and stabilize the environment before eradication and recovery begin.”

78.0%

Ghofrane Horchani

“after confirming that the bad login is a real attack, the next major step is containment. The security team works to limit the impact of the incident and prevent the attacker from continuing or spreading throught the environment. This can include isolating the compromised computer from the network, disabling the affected user account, or blocking the attacker's IP address. The person who usually performs these immediate technical actions is a Security Analyst or an Incident Responder, whose role is to stop the attacker and reduce the damage as quickly as possible.”

76.0%

Senewirathna Amith Nilupul

“once a security team confirms a real attack, the immediate next step is Containment, which focuses on isolating the compromiused system from the network and disabling affected user credentials to prevent the attacker from spreading laterally or stealing data. This immidiate action is typically carries out by an incident responder, who executes software isolation controls, blocks malicious IPs or hashes across endpoint security tools, and neutralizes active sessions to halt the threat before moving on to .complte eradications and recovery.”

72.0%

Umamaheswara Rao K

“containment- This means taking immediate actions to limit the attacker's access and stop the attack from spreading. An incident responder or soc analyst is typically responsible for quickly carrying out these steps. examples of immediate containment actions: -disable the comprimised user account so the attacker can't use it anymore. -disconnect the affected computer from the network to prevent further spread . -change passwords for affected accounts. -block suspicious IP addresses or network connections linked to the attack.”

70.0%

Elvin Shirazov

“After comming a real attack, the very next big step the security team takes to fix the problem is containment. Containment is the process of limiting the scope and impact of a security incident to prevent futher damage, unauthorized access, or data exfiltration by immediately stopping the attacker's activity and preventing them from spreading withing the enviroment. Comon containment actions include isolating compromised system from the network , disabling the breached user account or blocking the attacker;s IP address”

70.0%

Suat Aliu

“Next big step: Containment - isolating the affected system so the attacker can't spread further or do more damage (e.g., disconnecting the machine from the network, disabling the compromised account, blocking malicious IPs). Who does it: The Incident Responder (often part of the Incident Response/IR team, sometimes called a Tier 2/3 analyst or IR specialist) usually carries out this immediate containment work - while the person who first confirmed the atack (the tier 1 analyst/triage analyst) hands it off to them.”

69.0%

Shan Devinda

“The next step after confirming a real attack is containment: isolating the compromised system, disabling the breached account or blocking the attacker's IP to stop the damage from spreding, The actual technical work of executing these containment actions is typically caried out by a Security Analyst or an Insident Responder with the Insident Responder being the more specialized role focused on directly intervening to mitigate the threat right away.”

60.0%

Ahmed Nabeel Alobaidi

“after confirming a real attack, the immediate next step is contaiment the goal is to stop the damage by isolating the infected device, disabling the compromised account, and revoking the active sessions the person who performs this work is actually a SOC analyst or an incident responder who acts quickly to quarantine the threat while the rest of the team prepares for the further investigation”

52.0%

Mishaal Anwar

“After confirming a real attack, the very next big step the security team takes is containment, which involves isolating the compromised computer from the network to prevent the threat from spreading or stealing more data. the professional who usually does the actual work to stop the attacker right away is the Incident Responder. Acting like a digital firefighter, the execu”

43.0%

Alok Verma

“The next big step is containment. The team immediately works to contain the attack by isolating the affected system, disabling the compromised account, or blocking the attacker's access. The person who typically performs these immediate technical actions is a security analyst or an Incident Responder.”

39.0%

Bakht Sanan Khan

“after confirming the atatck, the next step is containment, which isolates the affected system to prevent futher damage. The incident responder (IR) analyst typically performs the immediate actions to stop the attacker, such as isolating the device, blocking malicious and preserving evidence”

38.0%

Lahiru

“A tire 1 security analyst first confirm that the bad login is a real attack. the next step is containment where the affected system is isolated to stop the attack form spreding. this work is usually handles by a tire 2 security anslyst or an incident responsder, who quickly blocks the limits the damage”

36.0%

Md. Sheikh Farid

“The next major step is containment, where the team quickly isolates the affected computers or account to stop the attacker from causing more damage. The Incident Responder or Tier 2/ Tier 3 SOC analist usally performs the hands-on actions to contain and stop the attack.”

36.0%

Zwe Wai Yan Bhone Myint

“After confirming the attack, the next step is containment to prevent furture damage The incident responder or security analyst typically performs the immediate actions such as isolating the effected system disabling compromised accounts or blocking malicious activity”

35.0%

Ferid Mehtiyev

“After understanding the attack is real, the SOC L2 firstly blocks the attackers IP address to stop additional attacks. Then the account is blocked and checked for any backdoors / misconfigurations. If no problem is found, the new stricter password is created for account”

30.0%

Jaire Carthens

“the next step is containment , the team members that normally handle this are incident responders usually tier 2-3 SOC analysts. the incident response workflow is usually starts woth detection/analysis then containment then eradication then recovery amd finally documentaion and lessons learned”

27.0%

Names

“after a security team confirm a bad login is a real attack , the very next bug step they take to fix the problem is containment . containment is the process of limiting the scope and the impac of a security incident to prevent further damage, unauthorized access, or data exfiltration .”

25.0%

Kaustubh

“the two "who does it" answes are really the same reality described with different labels,so here's how they map: securoty analyst(the hint's term) Tier 1 (the term I used )-monitors alerts, does the initial triage/confirmation Incident Responder Tier 2- the one with EDR/AD access who actually pulls the trigger: isolates the host,disables the account,blocks the IP”

24.0%

Eeshan Garg

“the very first step is to block the attacker Ip. and securing the account by a strong password. the Tier 2 Analyst or IR team handles the work”

16.0%

Gayatri Sudhakar Hire

“After confirming a bad login is a real attack, the next big step is containment and the person who usually performs the immediate technical actions to stop the attacker is security analyst or incident responder.”

16.0%

Flávio Andrade

“Containment, usually carried out by a Security Analyst or Incident Responder.”

10.0%

Teng Samnang

“the very next big step they take to fix the problem is containment and who usually does thr actual work to stop the bad guy right a way is typically a Security Analyst or an Incident Responder”

9.0%

Victor Samuel Da Paixao

“Containment, performed by the Incident Response Team (Incident Responder).”

9.0%

Arunank

“Containment is the next step and it is usually carried out by a Tier 2 SOC Analyst”

8.0%

Anmol Kumar

“The next big step is Containment and it is usually executed by an Incidenct Responder”

7.000000000000001%

Boswell Mtambo

“The first big step is containment . The person on the team who usually does the actual work to stop the bad guy is called the Incident Responder.”

5.0%

Nikulkumar Suthar

“a security team see a bad login on a computer the first person check and confirm it is a real attack what is the very next big step they take to fix the problem and who on the team usually does the actual work to stop the bed”

5.0%

Md Yousuf Ali

“Containment, Incident Responder”

4.0%

Anirban Ghosh

“Containment and Level 2 SOC analyst”

4.0%

Seda Avagyan

“The very nest big step is containment.”

2.0%

Kabo Sekoto

“CONTAINMENT”

1.0%

Naga Pratyusha Vandrangi

“Security Analyst”

1.0%

Mr. Vatsal U. Choksi

“None”

0.0%

Luis Antonio Gulcochia Sanchez

“contencion analista soc”

0.0%

Tlili Wijden

“1. contamination, 2. eradication, 3. recovery, 4. lesson learned”

0.0%

David Neves De Oliveira

“Estatuto internaciaonal do sigilo bruxo”

0.0%

Leopoldo Jr Tapang

“None”

0.0%

Redundant Elements