An IT technician responds to an active security incident where a workstation is suspected of transmitting sensitive customer files to an unauthorized external server. Which of the following represents the correct chronological sequence of initial incident response and evidence collection procedures the technician should perform?
- 1Report the suspected incident to the designated Incident Response Team or corporate security officer.
- 2Isolate the compromised system by disconnecting Ethernet cables and disabling wireless adapters.
- 3Preserve volatile system evidence, including system memory (RAM), while the machine remains powered on.
- 4Extract the storage drive and document the chain of custody log with timestamps, location, and handler signatures.
Answer
The correct sequence starts with reporting the incident to proper authorities, followed by isolating the workstation from the network, preserving volatile RAM memory, and finally logging the chain of custody upon drive extraction.
The standardized first responder framework dictates reporting the breach first, containing the threat via network isolation second, capturing volatile memory (RAM) third in compliance with the order of volatility, and establishing chain of custody documentation fourth during evidence collection.
Step-by-Step Solution
Key Concept
First Responder Incident Response Sequence and Order of Volatility