A security analyst confirms that an active remote access Trojan (RAT) is running on an internal finance server and establishing outbound connections to an external command-and-control server. According to standard incident response lifecycle frameworks, which of the following actions should the analyst perform NEXT?
- Isolate the finance server from the network to halt communication with the external server.Answer
- BRe-image the server operating system and restore data from the latest system backup.
- CConduct a post-incident review with leadership to update incident response playbooks.
- DRun anti-malware cleanup tools on the server to remove the malicious files.
Answer
Isolate the finance server from the network to halt communication with the external server.
Network isolation of the affected host is the primary action during the containment phase. Following incident detection and confirmation, containment must occur immediately to prevent the attacker from exfiltrating data or expanding their reach across the network.
Step-by-Step Solution
Key Concept
Incident Response Phase Order (Containment First)
Estimated Time:1m 0s