When breach happens, incident response contains damage: prepare, detect, contain, eradicate, recover, learn.
First hours
- Activate incident channel and lead
- Preserve logs—do not wipe evidence hastily
- Contain (disable creds, isolate instances)
- Assess scope (what data accessed?)
- Notify legal/comms per regulatory rules
Post-incident
Blameless postmortem, fix root cause, update runbooks.
Important interview questions and answers
- Q: Containment example?
A: Rotate secrets, block attacker IP, take affected service offline. - Q: GDPR breach?
A: May require notification within 72 hours—know your obligations.
Self-check
- List three IR steps.
- Why preserve logs first?
Tip: Keep incident contact list and runbook URL in README internal wiki.
Interview prep
- Containment?
Limit ongoing damage—disable creds, isolate systems.