An IT security analyst is responding to an active security incident involving a server suspected of exfiltrating sensitive database records across an encrypted tunnel. The analyst arrives at the server console, which remains powered on and logged in. Which TWO actions must the analyst take FIRST to contain the breach while adhering to forensic order of volatility and strict chain of custody protocols? (Select TWO.)
- Disconnect the network cable from the network interface card to isolate network traffic while keeping the system powered on to preserve volatile RAM state.Answer
- Document the date, time, physical location, system status, and handler credentials on the chain of custody tracking log before evidence transfer.Answer
- CInitiate an immediate hard power-down by pulling the power cable to prevent the attacker from triggering a remote memory wipe.
- DOpen the user profile directory to manually inspect and verify which sensitive files were altered prior to creating the forensic image.
Answer
The analyst must isolate the network connection to stop exfiltration while preserving live RAM evidence, and log all relevant system details, timestamps, and handler information on the chain of custody form.
Disconnecting the network cable immediately isolates the compromised server to prevent further data exfiltration while keeping the machine powered on so volatile RAM data remains intact for forensic capture. Simultaneously logging handler details, timestamps, location, and system state on the chain of custody form establishes the required legal paper trail before any equipment is moved or imaged.
Step-by-Step Solution
Key Concept
Incident Containment and Chain of Custody Maintenance
Estimated Time:2m 0s