Following an alert indicating that an unauthorized process attempted to dump LSASS memory on a corporate workstation, a security analyst needs to prevent the compromised host from communicating with internal network assets while preserving the host's active connection to the central EDR console for remote incident triage. Which of the following capabilities should the analyst execute?
- Host network isolationAnswer
- BEdge firewall rule modification
- CStatic antivirus signature update
- DDeception honeypot deployment on the local subnet
Answer
Host network isolation is the appropriate EDR capability to stop lateral movement while retaining agent communication for incident triage.
Host network isolation configures the local software driver or agent to block all network traffic to and from the host, with an exception for the encrypted control channel to the EDR management platform. This effectively stops lateral movement across the enterprise while enabling security analysts to perform remote triage, memory dumps, and remediation actions.
Step-by-Step Solution
Key Concept
Endpoint Detection and Response (EDR) Host Network Isolation
Estimated Time:1m 0s