An EDR agent installed on a critical workstation flags a suspicious process spawned by a administrative command tool attempting to inject code into a system process. The threat actor is actively attempting lateral movement across the internal segment. Which of the following capabilities of the EDR system should be utilized FIRST to contain the threat while preserving telemetry for investigation?
- Initiate network isolation of the host from the EDR management console to block peer-to-peer communication while maintaining agent connection.Answer
- BUpdate the perimeter firewall rule base to block all inbound traffic destined for the internal subnet where the host resides.
- CDistribute a updated legacy static signature file to all perimeter security gateways across the organization.
- DReclassify the affected machine as a compensating control within the enterprise asset management inventory.
Answer
Initiate network isolation of the host from the EDR management console to block peer-to-peer communication while maintaining agent connection.
Host network isolation capability in an EDR platform allows security operations teams to logically segment a compromised endpoint from all internal and external network resources instantly. The EDR agent maintains a dedicated communication channel to the cloud or on-premise EDR console, permitting analysts to collect forensic artifacts and execute remediation playbooks without risking lateral spread.
Step-by-Step Solution
Key Concept
Endpoint Containment and Host Isolation in EDR
Estimated Time:1m 30s