A helpdesk technician suspects that a desktop computer on the corporate network is actively compromised by malware attempting to spread across the network. Which immediate action should the technician take first to contain the incident while preserving volatile system memory for analysis?
- Disconnect the network cable and disable all wireless connections on the systemAnswer
- BImmediately unplug the power cord to force a complete system shutdown
- CMove the physical workstation tower into a locked storage room
- DRun an antivirus scan to determine whether the infection originated from a phishing email
Answer
Disconnect the network cable and disable all wireless connections on the system
Disconnecting network interfaces immediately isolates the system to prevent malware from spreading across the network or exfiltrating data, while keeping the machine powered on so volatile evidence in RAM remains preserved for analysis.
Step-by-Step Solution
Key Concept
Incident Response First Responder Priorities: Isolation and Preservation
Estimated Time:45s