Question

Difficulty: MediumIncident Response Process and Playbooks

During an on-site physical security review of a remote branch office, a security analyst discovers an unauthorized rogue wireless access point plugged into an active wall jack. The rogue device is actively broadcasting a duplicate corporate SSID to intercept wireless client credentials. Following standard incident response playbooks, which of the following immediate containment actions should the incident response team perform? (Select TWO.)

  1. Disable the specific network switch port where the rogue access point is physically attached.Answer
  2. Apply a quarantine access control list (ACL) to isolate traffic from the affected network segment.Answer
  3. Re-image the enterprise core switch operating system to remove potential malicious persistence.Answer
  4. Clear the switch MAC address table and volatile system logs to reset network state.Answer

Answer

The correct containment actions are disabling the connected switch port and applying a quarantine ACL to isolate traffic from the affected segment.
Disabling the physical switch port immediately blocks the rogue access point from transmitting data across the wired enterprise network. Concurrently, applying a quarantine access control list (ACL) isolates traffic on the affected segment, preventing unauthorized lateral movement. Both steps fulfill containment objectives by isolating the threat without destroying evidence.

Step-by-Step Solution

1
Identify the primary operational objective of the containment phase in incident response.
The containment phase focuses on limiting the scope and impact of an incident without destroying forensic evidence.
Containment prevents threat expansion while allowing responders time to collect volatile evidence and plan eradication.
2
Evaluate actions that immediately restrict rogue access point network traffic.
Disabling the switch port cuts off network connectivity at the access layer, and applying a quarantine ACL prevents lateral movement on the segment.
Both measures effectively isolate the threat without altering evidence on the rogue hardware or erasing infrastructure logs.
3
Differentiate containment phase actions from premature eradication or destructive evidentiary steps.
Re-imaging switch firmware belongs in the eradication phase, while clearing volatile system logs violates evidence preservation principles.
Proper lifecycle execution ensures evidence integrity and prevents operational disruption prior to full investigation.

Key Concept

Incident Response Containment Phase for Physical Security Incidents
Estimated Time:1m 30s
Rate this question