A desktop support technician responds to a report that a Finance department computer is infected with active ransomware that is currently attempting to encrypt shared network drives over a wired connection. System memory and processes are still active. Which TWO actions should the technician perform first to contain the incident while adhering to forensic evidence preservation guidelines?
- Unplug the network cable from the computer's network interface cardAnswer
- Capture a digital copy of the active system memory (RAM)Answer
- CReboot the system into Safe Mode with Networking to execute a full antimalware scan
- DOpen File Explorer to inspect and copy affected files onto a USB flash drive
Answer
The technician should unplug the network cable to isolate the infected computer from the network and capture a digital copy of the active system RAM before taking any reboot or shutdown actions.
Unplugging the network cable isolates the host to prevent ransomware propagation across network shares while keeping system state intact. Capturing system RAM preserves highly volatile evidence, such as running malware routines and memory-resident keys, before any system state changes occur.
Step-by-Step Solution
Key Concept
First Responder Incident Isolation and Order of Volatility