Soru

Zorluk: KolayIncident Response and Chain of Custody

An IT technician discovers a workstation infected with ransomware on the corporate network. Arrange the initial incident response actions in the correct chronological order from first step to last step.

  1. 1Identify the security incident and confirm the threat.
  2. 2Report the incident to the designated supervisor or incident response team.
  3. 3Isolate the compromised system from the network.
  4. 4Preserve system evidence and document the chain of custody.

Cevap

The correct sequence of incident response steps is: First, identify the security incident and confirm the threat; Second, report the incident to the designated supervisor or incident response team; Third, isolate the compromised system from the network; Fourth, preserve system evidence and document the chain of custody.
Under standard CompTIA first responder procedures, the chronological order of operations is identification, reporting to proper authorities, isolating the system to contain the threat, and preserving evidence along with chain of custody documentation.

Adım Adım Çözüm

1
Identify the incident
Confirmed ransomware infection on the workstation.
Incident identification must occur first to understand the scope and nature of the issue.
2
Report the incident
Escalated details to the security and management team.
Reporting immediately ensures organizational response protocols and communication channels are activated.
3
Isolate the system
The machine is quarantined from the network.
Isolating the system contains the threat and prevents the ransomware from spreading to shared files or other machines.
4
Preserve evidence and document chain of custody
Volatile memory and logs are secured with handler details recorded.
Preserving evidence maintains data integrity and ensures forensic evidence remains admissible and verifiable.

Anahtar Kavram

First Responder Incident Response Sequence
Bu soruyu puanla