An enterprise system administrator identifies suspicious administrative tool execution on a human resources endpoint. EDR telemetry reports that an unauthorized process is actively attempting lateral movement across internal subnets using compromised domain credentials. Which of the following actions should the security engineer take FIRST using the EDR platform to stop the attack while maintaining investigation capabilities?
- Initiate host isolation on the affected endpoint through the EDR agent consoleAnswer
- BModify perimeter firewall rules to block inbound connections to the endpoint subnet
- CPush updated static signature definitions to clean the legitimate administrative binaries from disk
- DReclassify the host's asset criticality level in the configuration management database to detective mode
Answer
Initiate host isolation on the affected endpoint through the EDR agent console.
Executing network host isolation directly through the EDR console immediately disconnects the compromised endpoint from all internal network resources, neutralizing lateral movement while maintaining EDR agent connectivity for SOC analysis and forensic triage.
Step-by-Step Solution
Key Concept
Endpoint Containment and Host Isolation