Open cardosec

Case 153B26 · Blue team / DFIR · L3 Applied

Containment vs Eradication

Practise as: Explain it · Interview

Interview questionWhat is the difference between containment and eradication, and when do you contain?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Containment stops the bleeding (isolate hosts, disable accounts, block C2) while preserving evidence.
  2. Eradication removes the foothold: malware, persistence, backdoor accounts, and the root-cause vulnerability.
  3. Contain too early and the attacker may pivot or detonate; too late and they exfiltrate. Scope first when possible.
  4. Coordinate remediation as one event so the actor cannot re-enter via a missed persistence mechanism.
  5. After domain compromise: reset krbtgt twice, rotate privileged and service creds, rebuild rather than clean.

If the interviewer pushes back

  • When would you deliberately leave a compromised host online and monitored, and what are the risks?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.