Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

An enterprise system administrator identifies suspicious administrative tool execution on a human resources endpoint. EDR telemetry reports that an unauthorized process is actively attempting lateral movement across internal subnets using compromised domain credentials. Which of the following actions should the security engineer take FIRST using the EDR platform to stop the attack while maintaining investigation capabilities?

  1. Initiate host isolation on the affected endpoint through the EDR agent consoleCevap
  2. B
    Modify perimeter firewall rules to block inbound connections to the endpoint subnet
  3. C
    Push updated static signature definitions to clean the legitimate administrative binaries from disk
  4. D
    Reclassify the host's asset criticality level in the configuration management database to detective mode

Cevap

Initiate host isolation on the affected endpoint through the EDR agent console.
Executing network host isolation directly through the EDR console immediately disconnects the compromised endpoint from all internal network resources, neutralizing lateral movement while maintaining EDR agent connectivity for SOC analysis and forensic triage.

Adım Adım Çözüm

1
Analyze the EDR behavioral alert
Identified active lateral movement attempts originating from the endpoint
Immediate containment is required to prevent compromise of adjacent systems on the internal network.
2
Select the appropriate EDR response action
Apply network host isolation via the EDR platform agent
Host isolation disables internal endpoint networking while maintaining the management control channel for security analysis.

Anahtar Kavram

Endpoint Containment and Host Isolation
Bu soruyu puanla