Containment

Limiting the spread or impact of an active incident.

Containment is the fourth step of the SY0-701 incident response process (after preparation, detection, and analysis) and aims to stop the bleeding before eradication. Short-term containment isolates the affected host or segment immediately; long-term containment applies temporary fixes that let business continue while preserving evidence for forensics. Common moves include network isolation, account disablement, and credential rotation — balanced against tipping off an attacker who may then destroy data.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Security Operations