Triage BoardGet the app

Concept · Incident response process

Containment vs eradication vs recovery

Containment stops an incident from spreading, eradication removes its cause, and recovery puts the systems back into production and watches them. They are steps four, five and six of the seven-step process in objective 3.2 of the CS0-004 exam objectives, and a typical question hands you one action and asks which step it belongs to.

  • Exam code CS0-004
  • Tickets here 8

Sort this ticket

ticketAction log of a fictional incident, INC-3307: which step is each entry?
INC-3307  host fin-ws-14 (10.20.4.14)  severity: high09:12  EDR alert: credential-theft tool running on fin-ws-1409:18  fin-ws-14 network-isolated through EDR, power left on09:20  egress firewall blocks 203.0.113.77 (C2 destination)09:31  memory image of fin-ws-14 captured, SHA-256 recorded09:40  user jdoe: password reset, all sessions revoked10:55  local admin account 'svc_bkp' created by attacker: deleted11:30  fin-ws-14 re-imaged from gold image12:10  exploited agent patched on all finance hosts13:05  fin-ws-14 released from isolation13:05  enhanced monitoring on fin-ws-14 for 14 days

Lines 3, 4 and 6 are containment, lines 7 to 9 eradication, lines 10 and 11 recovery. Line 5 is evidence work, and it had to happen before line 8 wiped the disk.

Reading the log step by step

Containment is everything that limits the damage while the cause is still present. Isolating the workstation through endpoint detection and response (EDR), blocking the command-and-control (C2) address and revoking the user's sessions all cut the attacker off without destroying anything. Containment is deliberately reversible and keeps the evidence in place.

Eradication removes what the attacker left and the way they got in: the rogue account, the compromised disk (by re-imaging) and the unpatched agent. The CS0-004 objectives call the fix remediation and pair it with verification in objective 3.3, so eradication ends only when you have checked that the foothold is gone.

Recovery returns the host to normal use. Objective 3.3 names two techniques here that candidates mix up: release from isolation, the moment the host rejoins the production network, and performing restoration, rebuilding data and services. Recovery is the phase; restoration is work done inside it. The extra monitoring on line 11 belongs to recovery as well, because it confirms the cause stayed gone.

The memory image on line 5 is why order matters. Capture volatile evidence before anything destructive, following the order of volatility, and log each artifact with a hash so the chain of custody holds.

Where the three sit in the seven steps

PreparationDetectionAnalysisContainmentEradicationRecoveryPost-incident
The seven steps of CS0-004 objective 3.2. NIST SP 800-61r2 grouped the highlighted three into one phase; NIST SP 800-61r3 (April 2025) maps response to the CSF 2.0 functions instead.

Action to step

Common response actions and the step they belong to
ActionStepWhy
Move a host to a quarantine VLANContainmentLimits spread, keeps the host for evidence
Sinkhole a C2 domain at DNSContainmentCuts the attacker's channel
Delete attacker-created accountsEradicationRemoves a foothold
Re-image from a known-good imageEradicationRemoves the malware with the old disk
Patch the exploited flawEradicationCloses the way back in
Reconnect the host to productionRecoveryRelease from isolation
Watch the host closely for weeksRecoveryConfirms the cause is gone
Lessons-learned meetingPost-incidentComes after all three

The fix that destroys the evidenceTrap

Re-imaging, wiping or powering off a host before anyone has captured memory and hashed the disk ends the incident faster and loses the evidence. When an option does the destructive step first, it is in the wrong order, however efficient it sounds.

Contain, eradicate or recover

The queue runs from the first alert to the host going back into production, sometimes asking for one action and sometimes for the whole sequence.

Ticket 1 / 8

0 right

INC-001

Data wiping, resetting filesystems, and hardware destruction are all examples of what phase in an incident response procedure?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AMonitoring is ongoing observation before and after an incident, not the removal of the threat.
  2. BContainment limits spread, for example by isolating a host, and keeps systems intact for analysis instead of wiping them.
  3. CCorrect: Wiping data, resetting filesystems, and destroying hardware remove the threat from affected systems, which is eradication.
  4. DValidation checks that systems are clean and patched before return to service; it follows the cleanup.

INC-002

What is the PRIMARY goal of the containment phase in incident response?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Containment limits the damage and stops the incident from spreading, for example by isolating hosts or blocking malicious addresses.
  2. BRestoring systems to operation is recovery, which comes after eradication.
  3. CDocumenting lessons learned happens in post-incident activity.
  4. DIdentifying the source is part of analysis; containment can begin before the source is fully known.

INC-003

Triage identified scheduled tasks, malicious services, and registry autoruns. Which eradication sequence best removes persistence mechanisms and verifies removal?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AReimaging without documenting persistence loses evidence and the indicators needed to hunt for the same artifacts on other hosts.
  2. BA reboot does not delete scheduled tasks; they persist and run again.
  3. CCorrect: Each persistence method (tasks, services, autoruns) is removed in turn, then a re-scan and file hashing confirm nothing remains.
  4. DDisabling services leaves tasks and registry autoruns that can bring the malware back, and relying on endpoint protection is not verified removal.

INC-004

After containment of a ransomware incident, which remediation sequence minimizes reintroduction risk while allowing phased recovery?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ARestoring user access before patching lets the original weakness be exploited again.
  2. BCorrect: Confirming eradication first, then recovering in phases with rollback plans, prevents bringing infected systems back and limits the damage if something fails.
  3. CReimaging and restoring without validating the backups can restore the malware or the same vulnerability.
  4. DSkipping validation risks reinfection when systems come back online.

INC-005

Which sequence of actions best follows containment→eradication→recovery for a ransomware outbreak in a segmented network?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ABlocking outbound traffic alone does not stop spread inside the network, and restoring from any backup risks restoring infected data.
  2. BReimaging before isolating segments lets the ransomware keep spreading while hosts are rebuilt.
  3. CPowering off hosts destroys volatile evidence, and restoring without hash checks may bring back compromised images.
  4. DCorrect: Isolating segments contains the outbreak, verifying image hashes ensures clean sources, and restoring in controlled windows completes recovery in order.

INC-006

Which of the following is considered a technique for security incident containment and NOT an investigation technique?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. ALog review is an investigation technique used to work out what happened.
  2. BNetwork monitoring gathers evidence and watches for further activity, which is investigation, not containment.
  3. CForensic analysis examines evidence to reconstruct an incident; it does not stop the threat.
  4. DCorrect: Isolation cuts the affected system off to stop the threat from spreading, which makes it a containment technique.

INC-007

Which recovery strategy is MOST appropriate for a ransomware incident?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Restoring from clean, tested backups, after the threat is eradicated, returns systems to a known-good state without relying on the attacker.
  2. BRebuilding from scratch without backups loses data and takes far longer when good backups exist.
  3. CPublic decryptors work only for some ransomware families, so they are a possible extra step, not a reliable recovery strategy.
  4. DNegotiating or paying funds criminals, may break sanctions rules, and gives no guarantee the data will be decrypted.

INC-008

A server in your organization has been identified as the source of a DDoS attack. As a security analyst, you decided to restrict all network access to and from this server to prevent further damage. What is this method known as?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Cutting off all network traffic to and from the compromised server is isolation, a containment technique.
  2. BNetwork flow analysis studies traffic patterns to investigate; it does not block traffic.
  3. CReverse engineering analyzes malware to understand how it works; it does not stop the attack.
  4. DSegmentation divides a network into zones as a design decision; cutting off a single host completely is isolation.

Shift tally

0 / 0

Edge cases

Should I file patching under containment or eradication?

Usually eradication, because it removes the way in; objective 3.3 of CS0-004 calls it remediation and verification. A temporary block on the vulnerable service while the patch waits is containment.

When can I release a contained host?

Once you have verified eradication: the foothold removed, the flaw fixed, a clean scan or hash comparison on record. Release from isolation is a named CS0-004 technique, and closer monitoring should follow it.

Should I learn the NIST or the SANS phases?

Neither, for this exam. The CS0-004 objectives give seven steps: preparation, detection, analysis, containment, eradication, recovery, post-incident. SANS uses six phases and NIST SP 800-61r2 used four; the current NIST SP 800-61r3 (April 2025) replaces the cycle with the CSF 2.0 functions. All seven steps are walked through on the incident response process page.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.