InterviewStack.io LogoInterviewStack.io

Incident Response and Containment Questions

Managing security incidents from detection through recovery. Covers incident response process and playbooks, containment and remediation, data-breach investigation methodology, data-exfiltration detection and analysis, root-cause and post-incident analysis, and fraud and complex-attack investigation. The operational 'a compromise is happening, now what' discipline, distinct from broader production-outage incident management.

HardTechnical
38 practiced

You are the lead responder for a multi-stage compromise: initial access via phishing or a public exploit, privilege escalation, lateral movement using living-off-the-land binaries or custom loaders, and staged data exfiltration. Draft a comprehensive containment, eradication, and recovery plan: prioritized containment options and their trade-offs, techniques to scope which hosts and accounts are affected, removal of cross-platform persistence, and validation that the attacker cannot re-establish access before declaring the incident closed.

HardTechnical
54 practiced

You confirm a Pass-the-Hash, Golden Ticket, or Kerberoasting attack in an Active Directory environment (forged Kerberos tickets granting persistent domain access). Outline detection and validation, containment of active misuse, remediation including the KRBTGT account reset and enterprise-wide credential rotation, replication considerations, and how you validate that forged tickets can no longer be reused before restoring trust.

HardTechnical
53 practiced

During an authorized penetration test, you unexpectedly discover evidence of an active, unrelated compromise by a real attacker. What are your immediate obligations: how do you preserve evidence, what are your legal and ethical responsibilities given your engagement scope, how and when do you notify the client, and how do you coordinate with their incident response team without compromising either the finding or your own engagement's integrity?

MediumTechnical
39 practiced

You receive a high-severity alert (for example: a spike of failed logins followed by a successful admin login, or an encoded PowerShell command on a production host) indicating possible lateral movement or credential compromise. Within the first 15 to 30 minutes, walk through your triage: which logs and telemetry you check first and in what order, what you capture as evidence, initial containment actions you take, and which teams you notify.

That is every published Incident Response and Containment question for Penetration Tester so far. Browse the other topics in this category, or practice this one interactively.