Soru

Zorluk: OrtaIncident Response Process and Playbooks

A security analyst confirms that an active remote access Trojan (RAT) is running on an internal finance server and establishing outbound connections to an external command-and-control server. According to standard incident response lifecycle frameworks, which of the following actions should the analyst perform NEXT?

  1. Isolate the finance server from the network to halt communication with the external server.Cevap
  2. B
    Re-image the server operating system and restore data from the latest system backup.
  3. C
    Conduct a post-incident review with leadership to update incident response playbooks.
  4. D
    Run anti-malware cleanup tools on the server to remove the malicious files.

Cevap

Isolate the finance server from the network to halt communication with the external server.
Network isolation of the affected host is the primary action during the containment phase. Following incident detection and confirmation, containment must occur immediately to prevent the attacker from exfiltrating data or expanding their reach across the network.

Adım Adım Çözüm

1
Determine the current phase of the incident response process.
An active intrusion with command-and-control traffic has been verified, transitioning the response from detection to containment.
According to standard frameworks (such as NIST SP 800-61), active threats must be contained immediately to minimize damage.
2
Select the action that restricts impact while protecting evidence.
Network isolation prevents lateral movement and exfiltration while keeping RAM and volatile storage intact for forensic collection.
Containment limits the scope of an incident prior to starting eradication or recovery steps.

Anahtar Kavram

Incident Response Phase Order (Containment First)
Tahmini Süre:1m 0s
Bu soruyu puanla