Soru

Zorluk: KolayIncident Response and Chain of Custody

An IT technician detects suspicious network traffic originating from a workstation on the corporate network. Arrange the basic incident response steps in the correct chronological order from first to last according to standard CompTIA procedures.

  1. 1Identify and confirm the security incident.
  2. 2Report the incident to the designated security team or management.
  3. 3Isolate the affected workstation from the network.
  4. 4Preserve evidence and document the chain of custody.

Cevap

The correct order of incident response steps is: 1. Identify and confirm the security incident, 2. Report the incident to the designated security team or management, 3. Isolate the affected workstation from the network, and 4. Preserve evidence and document the chain of custody.
According to standard CompTIA incident response guidelines, a first responder must first identify that an incident is taking place. Once identified, the technician reports the incident to appropriate supervisors or incident response management. Next, the affected system is isolated from the network to prevent further damage or data exfiltration. Finally, evidence preservation and chain of custody documentation are performed to maintain legal integrity.

Adım Adım Çözüm

1
Identify the incident
The initial security anomaly is detected and verified.
Incident response begins by identifying an event as a security incident.
2
Report the incident
Security personnel and management are informed.
Reporting ensures proper authorization and escalation protocols are followed.
3
Isolate the system
The device is disconnected from network communication.
Isolation contains the incident and prevents lateral movement of threats.
4
Preserve evidence and log custody
Digital evidence is secured and logged for forensic analysis.
Preservation must occur in a controlled manner after the system is contained.

Anahtar Kavram

Standard First Responder Incident Response Lifecycle
Bu soruyu puanla