Question

Difficulty: Very hardIncident Response and Chain of Custody

An IT security analyst is responding to an active security incident involving a server suspected of exfiltrating sensitive database records across an encrypted tunnel. The analyst arrives at the server console, which remains powered on and logged in. Which TWO actions must the analyst take FIRST to contain the breach while adhering to forensic order of volatility and strict chain of custody protocols? (Select TWO.)

  1. Disconnect the network cable from the network interface card to isolate network traffic while keeping the system powered on to preserve volatile RAM state.Answer
  2. Document the date, time, physical location, system status, and handler credentials on the chain of custody tracking log before evidence transfer.Answer
  3. C
    Initiate an immediate hard power-down by pulling the power cable to prevent the attacker from triggering a remote memory wipe.
  4. D
    Open the user profile directory to manually inspect and verify which sensitive files were altered prior to creating the forensic image.

Answer

The analyst must isolate the network connection to stop exfiltration while preserving live RAM evidence, and log all relevant system details, timestamps, and handler information on the chain of custody form.
Disconnecting the network cable immediately isolates the compromised server to prevent further data exfiltration while keeping the machine powered on so volatile RAM data remains intact for forensic capture. Simultaneously logging handler details, timestamps, location, and system state on the chain of custody form establishes the required legal paper trail before any equipment is moved or imaged.

Step-by-Step Solution

1
Perform immediate network isolation.
Exfiltration of sensitive data over the encrypted tunnel is halted instantly.
Disconnecting the network interface stops malicious traffic without losing volatile evidence stored in RAM.
2
Document system condition and initiate chain of custody log.
An authoritative record of physical location, timestamps, system status, and initial handler details is established.
Chain of custody requires continuous tracking of evidence from the moment of discovery to maintain legal integrity.

Key Concept

Incident Containment and Chain of Custody Maintenance
Estimated Time:2m 0s
Rate this question