Assess whether the incident is contained or still lateral (2725ee)
August 31, 2026
SITUATION Cloud-security architect in a law firm with a client-matter data store has one working extract — phishing kit targeting finance wire clerks — after an EDR agent uninstalled on the domain controller. If phishing kit targeting finance wire clerks cannot support the incident is contained, the only defensible Cybersecurity output is hold.
DECISION Cloud-security architect in a law firm with a client-matter data store must choose The incident is contained / Still lateral using phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller.
HYPOTHESES TO TEST 1. Cloud-security architect can defend The incident is contained from phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller in a Cybersecurity challenge. 2. Cloud-security architect cannot defend The incident is contained from phishing kit targeting finance wire clerks; Still lateral is what the extract actually supports after an EDR agent uninstalled on the domain controller. 3. An EDR agent uninstalled on the domain controller never reached the population in phishing kit targeting finance wire clerks — reopen intake, do not close the incident is contained. 4. Two facts in phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller conflict for cloud-security architect; hold this Exposure Management file.
ANALYSIS REQUIRED 1. Test whether access is still live, already rotated, or only written as closed. 2. Check SIEM or identity logs in phishing kit targeting finance wire clerks for reuse after an EDR agent uninstalled on the domain controller. 3. Separate a scoped exception from an unbounded exposure a law firm with a client-matter data store has not measured. 4. For this Cybersecurity Exposure Management file, read phishing kit targeting finance wire clerks against an EDR agent uninstalled on the domain controller and write the one fact that would move the incident is contained for cloud-security architect.
RECOMMENDATION Choose The incident is contained / Still lateral on this Cybersecurity / Exposure Management packet (phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller). Lead with the Cybersecurity option phishing kit targeting finance wire clerks can support after an EDR agent uninstalled on the domain controller, then the two facts that force it, then the Monday action for cloud-security architect in a law firm with a client-matter data store.
COMMAND RETURNS - Bottom-line Cybersecurity option on the incident is contained, then the evidence in phishing kit targeting finance wire clerks, then the action for cloud-security architect - Hypothesis scorecard against phishing kit targeting finance wire clerks: supported / rejected / untestable - Missing page in phishing kit targeting finance wire clerks after an EDR agent uninstalled on the domain controller, if any - Regulatory or exam hook Exposure Management would cite
Explore more
More Cybersecurity prompts
- Assess whether to pay, restore, or rebuild from known-good (a7ac4a)
- Assess whether the incident is contained or still lateral (30025b)
- Assess whether attribution is good enough to name an actor (40fd82)
- Assess whether legal hold and forensics must precede reboot (c43fcb)
- Assess whether privileged access should be rotated enterprise-wide (0ae80a)
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

