Soru

Zorluk: KolayIncident Response and Chain of Custody

A helpdesk technician suspects that a desktop computer on the corporate network is actively compromised by malware attempting to spread across the network. Which immediate action should the technician take first to contain the incident while preserving volatile system memory for analysis?

  1. Disconnect the network cable and disable all wireless connections on the systemCevap
  2. B
    Immediately unplug the power cord to force a complete system shutdown
  3. C
    Move the physical workstation tower into a locked storage room
  4. D
    Run an antivirus scan to determine whether the infection originated from a phishing email

Cevap

Disconnect the network cable and disable all wireless connections on the system
Disconnecting network interfaces immediately isolates the system to prevent malware from spreading across the network or exfiltrating data, while keeping the machine powered on so volatile evidence in RAM remains preserved for analysis.

Adım Adım Çözüm

1
Identify the primary incident response objective for an active network security incident
Containment of the threat is the immediate priority to prevent lateral spread.
Active malware on a network-connected host poses an immediate risk to other systems.
2
Select the appropriate isolation technique that preserves digital evidence
Unplugging network cables or turning off Wi-Fi/Bluetooth disconnects network traffic.
Network isolation stops data exfiltration and network propagation without shutting down the system, preserving volatile RAM.

Anahtar Kavram

Incident Response First Responder Priorities: Isolation and Preservation
Tahmini Süre:45s
Bu soruyu puanla