Case 153B26 · Blue team / DFIR · L3 Applied
Containment vs Eradication
Practise as: Explain it · Interview
Interview questionWhat is the difference between containment and eradication, and when do you contain?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Containment stops the bleeding (isolate hosts, disable accounts, block C2) while preserving evidence.
- Eradication removes the foothold: malware, persistence, backdoor accounts, and the root-cause vulnerability.
- Contain too early and the attacker may pivot or detonate; too late and they exfiltrate. Scope first when possible.
- Coordinate remediation as one event so the actor cannot re-enter via a missed persistence mechanism.
- After domain compromise: reset krbtgt twice, rotate privileged and service creds, rebuild rather than clean.
If the interviewer pushes back
- When would you deliberately leave a compromised host online and monitored, and what are the risks?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.