Match containment to the evidence, and escalate the business decision rather than making it alone. If there are signs of active hands on keyboard activity, credential theft or staging, isolate now and inform the incident commander, because a short interruption costs less than a domain wide compromise. If the activity looks dormant, apply partial containment (block command and control, revoke sessions, force credential reset) and schedule full isolation.
Why interviewers ask this
This is a judgment question dressed as a technical one. The interviewer wants a defensible threshold, evidence that you escalate rather than unilaterally disconnecting a senior stakeholder, and knowledge that partial containment options exist between doing nothing and pulling the cable. How you plan to communicate the action matters here as much as the technical decision itself.
How to structure your answer
- State your containment threshold before you decide.
- Offer the partial containment options that buy time.
- Name who owns the business decision and how fast you reach them.
- Say how you would communicate it to the person affected.
Example answer
My threshold is evidence of active operator activity or credential access. If I see interactive command execution, credential dumping or data being staged, I isolate now and apologize later, because the gap between a compromised laptop and a compromised domain can be ten minutes. I would not just yank it silently though. I call the incident commander, give the evidence in one sentence and my recommendation, and let them make the business call while I stage the action so it can happen the second they say go. If it looks dormant, say a beacon that has not checked in for hours, I take the middle path: sinkhole the command and control domain, revoke the account sessions and refresh tokens, block the process hash, and keep full telemetry on the host so I can watch it. Then isolate when the meeting ends. For the conversation itself I go through the executive assistant with a short factual line and no jargon, because a panicking executive in a board meeting helps nobody.
Walking into this interview soon? GhostPilot listens to your live call, spots the question the moment it is asked, and puts a structured answer on your screen in real time. Try it on your next mock, or grab a $29 Session Pass, no subscription, for the real thing.
See how it worksFollow-up questions to expect
- What evidence would make you isolate without waiting for approval?
- How do you keep watching the host once it is isolated?
- Who do you tell, and when, if regulated data is involved?
Related cybersecurity analyst questions
Your interviewer will ask their own version of this. Paste your actual job description into the free Question Predictor and get the 20 questions that role is most likely to ask, with what each one is really probing.
Predict my questions