A security analyst monitoring a SOC console receives a high-severity alert from an Endpoint Detection and Response (EDR) agent on an enterprise workstation. The alert details rapid unauthorized file encryption and concurrent attempts at internal lateral movement. Which of the following containment actions should the analyst execute FIRST directly within the EDR console to minimize risk to the enterprise?
- Isolate the affected workstation from the network using the EDR agent isolation capability.Answer
- BUpdate the perimeter firewall ruleset to block outbound traffic originating from the workstation's IP address.
- CReconfigure local host Operating System Access Control Lists (ACLs) to restrict write permissions on user folders.
- DInitiate an automated full antimalware eradication scan across the host local storage.
Answer
Isolate the affected workstation from the network using the EDR agent isolation capability.
Isolating the host via the EDR console instantly restricts network traffic from the host, preventing the spread of ransomware and lateral movement while maintaining an operational connection between the SOC analyst and the EDR agent for telemetry analysis.
Step-by-Step Solution
Key Concept
Host Network Isolation in Endpoint Detection and Response