Weekly CISSP Exam Questions
Scenario: Your SOC has identified an ongoing data exfiltration attempt from an internal network to an external IP. What should be your immediate action?
A. Block the external IP
B. Disconnect the affected workstation
C. Monitor the data being sent
D. Notify law enforcement
Answer: A
Explanation:
In a situation where an ongoing data exfiltration attempt is detected, the immediate priority is to stop the unauthorized data transfer to contain the damage. Blocking the external IP associated with the data exfiltration would terminate the ongoing unauthorized transfer, making it the most immediate action you should take. Here's why the other options are less immediate or ideal:
Disconnect the affected workstation: While this is also a strong measure, it may be too drastic and could hamper the ability to gather further evidence. Blocking the external IP is a more focused immediate action.
Monitor the data being sent: While monitoring can provide valuable information about what data is being exfiltrated, the immediate priority is to stop the exfiltration. Monitoring can come after the immediate threat is blocked.
Notify law enforcement: While it might become necessary to involve law enforcement, that is usually a later step that comes after containment and after gathering evidence and understanding the extent of the breach.
Therefore, the most immediate action to take would be to block the external IP to halt the unauthorized data transfer.

Podcasts
Check out my weekly podcasts that delve deep into the relevant topics related to each of CISSP domains. In addition, I will go over specific questions and they can be interpreted and answered.

CISSP Cyber Training Academy
Tired of not knowing how to study for the CISSP Exam?
Check out the CISSP Cyber Training Academy to help you on your journey!

CISSP Cyber Training - YouTube
Check out my video collection on YouTube discussing all the details needed to help you pass the CISSP exam.