During a routine audit, a Security Operations Center (SOC) analyst detects an unauthorized rogue wireless access point bridged directly into an isolated network segment containing sensitive customer databases. Forensic monitoring confirms that an external threat actor is actively exfiltrating live database traffic across this rogue wireless link. According to standard incident response lifecycle frameworks, which of the following actions should the incident response team perform FIRST?
- Disable the switch port connected to the rogue access point to isolate the wireless bridge and stop active data transfer.Answer
- BRe-image the compromised database servers and restore all system files from offline backups.
- CDeploy wireless honeypots throughout the facility to monitor and capture the threat actor's ongoing attack techniques.
- DConvene a post-incident review meeting to update enterprise wireless containment playbooks and security policies.
Answer
Disable the switch port connected to the rogue access point to isolate the wireless bridge and stop active data transfer.
According to NIST SP 800-61 and ISO/IEC 27035 frameworks, once an active breach with exfiltration is detected, the immediate priority is Containment. Disabling the physical switch port stops ongoing exfiltration over the rogue wireless bridge without altering volatile memory on the target database servers.
Step-by-Step Solution
Key Concept
Incident Response Lifecycle - Containment Strategy
Estimated Time:2m 0s