An enterprise security operations center detects unauthorized remote shell access on a database server containing sensitive customer records. As the initial incident responder, in what sequence should you execute the following response and forensic preservation actions?
- 1Report the security incident to the designated response manager and record initial system indicators.
- 2Disconnect the server from wired and wireless networks while maintaining system power.
- 3Capture the volatile system RAM to an external, write-blocked storage drive.
- 4Fill out a chain-of-custody log detailing equipment serial numbers, exact timestamp, and handler credentials.
- 5Secure the server in a tamper-evident bag and transport it to a lockable forensic evidence room.
Answer
The correct sequence of actions is: 1) Report the security incident and record initial system indicators, 2) Disconnect the server from networks while keeping system power on, 3) Capture volatile system RAM, 4) Fill out the chain-of-custody log with timestamps and signatures, and 5) Secure the server in a tamper-evident bag and transport it to a lockable evidence room.
First responder protocol requires immediate reporting and baseline logging, followed by host network isolation while keeping power enabled. Following the order of volatility, volatile evidence in RAM must be captured next. After evidence collection is complete, chain-of-custody documentation must be recorded before physical hardware is packed into tamper-evident containers and stored in a secure evidence vault.
Step-by-Step Solution
Key Concept
First Responder Incident Handling Sequence and Chain of Custody
Estimated Time:2m 0s