During a routine operational review of corporate laptops, endpoint telemetry detects a malicious script executing directly in volatile memory and initiating unauthorized outbound traffic to a known adversary infrastructure. To stop lateral movement and data exfiltration immediately while retaining live memory context for incident investigation, which of the following EDR capabilities should be executed?
- Initiating agent-based network host isolationAnswer
- BModifying internal perimeter firewall access control lists (ACLs)
- CDeploying an emergency static signature update to legacy antivirus software
- DApplying an operating system patch to mitigate the underlying execution vulnerability
Answer
Initiating agent-based network host isolation is the correct capability because it disconnects the host from the internal network while keeping EDR communication open and preserving volatile memory.
Initiating agent-based network isolation enables security analysts to halt all unauthorized network communications to and from the endpoint instantly while preserving system state and volatile memory for forensic response.
Step-by-Step Solution
Key Concept
Endpoint Detection and Response (EDR) Host Isolation