During an on-site physical security review of a remote branch office, a security analyst discovers an unauthorized rogue wireless access point plugged into an active wall jack. The rogue device is actively broadcasting a duplicate corporate SSID to intercept wireless client credentials. Following standard incident response playbooks, which of the following immediate containment actions should the incident response team perform? (Select TWO.)
- Disable the specific network switch port where the rogue access point is physically attached.Answer
- Apply a quarantine access control list (ACL) to isolate traffic from the affected network segment.Answer
- Re-image the enterprise core switch operating system to remove potential malicious persistence.Answer
- Clear the switch MAC address table and volatile system logs to reset network state.Answer
Answer
The correct containment actions are disabling the connected switch port and applying a quarantine ACL to isolate traffic from the affected segment.
Disabling the physical switch port immediately blocks the rogue access point from transmitting data across the wired enterprise network. Concurrently, applying a quarantine access control list (ACL) isolates traffic on the affected segment, preventing unauthorized lateral movement. Both steps fulfill containment objectives by isolating the threat without destroying evidence.
Step-by-Step Solution
Key Concept
Incident Response Containment Phase for Physical Security Incidents
Estimated Time:1m 30s