During an ongoing incident investigation, a security analyst detects that an unauthorized rogue laptop is actively transmitting encrypted data across an internal enterprise network. According to standard incident response frameworks, which of the following actions should the analyst perform FIRST?
- Disconnect the rogue laptop from the network to contain the incident.Answer
- BFormat the hard drive of the rogue laptop and restore the system image.
- CSchedule a lessons-learned meeting with the incident response team.
- DImplement preventive firewall rules for web application SQL injection attacks.
Answer
Disconnect the rogue laptop from the network to contain the incident.
Disconnecting the rogue laptop immediately contains the threat by severing active network communication, preventing further unauthorized data exfiltration in accordance with standard incident response lifecycle guidelines.
Step-by-Step Solution
Key Concept
Incident Response Lifecycle - Containment Phase