Following the detection of suspicious command-and-control beaconing, an enterprise incident response team completes short-term network isolation of a compromised hypervisor host managing critical cloud workloads. The analyst verifies that lateral movement has been halted and containment boundaries are holding. According to standard NIST incident response lifecycle guidelines, which action should the incident response team execute NEXT before initiating eradication procedures?
- Acquire volatile memory dumps and cryptographic forensic images of the host to preserve digital evidence.Answer
- BImmediately purge rogue persistence mechanisms, malicious services, and compromised administrative accounts.
- CRebuild the hypervisor cluster from golden images and restore guest workloads from offline backups.
- DDeploy network intrusion prevention signature updates as the primary corrective control to eliminate host malware.
Answer
Acquire volatile memory dumps and cryptographic forensic images of the host to preserve digital evidence.
Under NIST SP 800-61 (Handling Computer Security Incidents), once an infected host is isolated to contain an incident, the team must preserve volatile memory (RAM) and generate forensic disk images before modifying host state. This ensures digital evidence is retained for root-cause analysis and potential legal proceedings prior to starting eradication.
Step-by-Step Solution
Key Concept
NIST Incident Response Lifecycle (Containment & Evidence Preservation Order)