Soru

Zorluk: ZorIncident Response and Chain of Custody

An enterprise security operations center detects unauthorized remote shell access on a database server containing sensitive customer records. As the initial incident responder, in what sequence should you execute the following response and forensic preservation actions?

  1. 1Report the security incident to the designated response manager and record initial system indicators.
  2. 2Disconnect the server from wired and wireless networks while maintaining system power.
  3. 3Capture the volatile system RAM to an external, write-blocked storage drive.
  4. 4Fill out a chain-of-custody log detailing equipment serial numbers, exact timestamp, and handler credentials.
  5. 5Secure the server in a tamper-evident bag and transport it to a lockable forensic evidence room.

Cevap

The correct sequence of actions is: 1) Report the security incident and record initial system indicators, 2) Disconnect the server from networks while keeping system power on, 3) Capture volatile system RAM, 4) Fill out the chain-of-custody log with timestamps and signatures, and 5) Secure the server in a tamper-evident bag and transport it to a lockable evidence room.
First responder protocol requires immediate reporting and baseline logging, followed by host network isolation while keeping power enabled. Following the order of volatility, volatile evidence in RAM must be captured next. After evidence collection is complete, chain-of-custody documentation must be recorded before physical hardware is packed into tamper-evident containers and stored in a secure evidence vault.

Adım Adım Çözüm

1
Report and Document Initial Findings
Escalation pathways are activated and initial indicators of compromise are logged.
Official incident response policies dictate immediate notification to authority figures before making unauthorized system changes.
2
Isolate the Host
Network communication is terminated while system power remains uninterrupted.
Quarantining network access prevents data exfiltration and further attacker movement while preserving volatile evidence.
3
Preserve Volatile Memory
Active RAM contents are dumped to external media.
Following the order of volatility, transient data in RAM is destroyed when power is lost, making RAM capture a top priority before shutdown.
4
Establish Chain of Custody
A complete custody form is created with exact time, date, location, and handler identity.
Legal defensibility requires continuous accounting of evidence handling before physical transportation or transfer of responsibility.
5
Secure Physical Hardware
Device is sealed in tamper-evident packaging and stored securely.
Protects physical evidence against unauthorized access, tampering, or loss prior to formal forensic analysis.

Anahtar Kavram

First Responder Incident Handling Sequence and Chain of Custody
Tahmini Süre:2m 0s
Bu soruyu puanla