A security analyst confirms that an employee workstation has been infected with self-propagating malware that is actively scanning the local subnet for vulnerable hosts. According to standard incident response frameworks, which action should the analyst take FIRST?
- Disconnect the workstation from the network to isolate itAnswer
- BReimage the workstation's hard drive to completely remove the malware
- CRestore the workstation files from the latest secure offline backup
- DConvene a post-incident review meeting to document lessons learned
Answer
Disconnect the workstation from the network to isolate it
Isolating the affected system from the network is the immediate containment action required by NIST and ISO incident response playbooks. Containment stops the active spread of malware and lateral movement while preserving the current state for further analysis.
Step-by-Step Solution
Key Concept
Incident Response Process Order (Containment Phase First)