Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

Security telemetry on a corporate workstation detects a suspicious living-off-the-land binary attempting to dump process memory and establish outbound command-and-control communication. Which feature of an Endpoint Detection and Response (EDR) agent should be executed FIRST to prevent potential lateral movement while preserving remote investigation capabilities?

  1. Apply host network isolation via the EDR agent consoleCevap
  2. B
    Add a perimeter firewall rule to drop traffic destined for the external IP address
  3. C
    Push an updated static signature file to the endpoint antivirus engine
  4. D
    Reboot the affected endpoint into safe mode using centralized device management

Cevap

Apply host network isolation via the EDR agent console
Host network isolation restricts all network traffic on the endpoint except for encrypted communication between the EDR agent and the management console. This effectively stops lateral movement and outbound command-and-control channels without interrupting live response triage capabilities.

Adım Adım Çözüm

1
Analyze the security alert requirements.
The goal is to stop lateral movement and command-and-control traffic immediately while maintaining remote administrative access for triage.
Threat containment must prioritize stopping attack propagation without losing live analysis capabilities.
2
Evaluate EDR endpoint isolation capabilities.
EDR host isolation drops non-essential inbound and outbound traffic at the endpoint agent level while keeping the EDR control plane active.
This provides containment while preserving volatile memory and analyst access.

Anahtar Kavram

EDR Host Isolation and Incident Containment
Bu soruyu puanla