Soru

Zorluk: KolayIncident Response Process and Playbooks

During an active incident investigation, a security analyst confirms that an employee's workstation is currently communicating with an external command-and-control (C2) server following a malware infection. According to standard incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?

  1. Isolate the compromised workstation from the internal network.Cevap
  2. B
    Re-image the workstation operating system and restore clean data backups.
  3. C
    Update the enterprise acceptable use policy to forbid clicking unknown email links.
  4. D
    Execute a full network scan to clean self-replicating worm code from all file servers.

Cevap

Isolate the compromised workstation from the internal network.
Isolating the compromised system from the network is the primary immediate containment action. Containment prevents data exfiltration and restricts the threat actor from moving laterally across the network while incident responders prepare eradication and forensic analysis steps.

Adım Adım Çözüm

1
Identify the current phase of the incident response process.
The incident has been detected and verified, moving the response directly into the Containment phase.
Once an active compromise (such as active C2 communication) is detected, immediate action must be taken to limit damage.
2
Select the immediate containment step.
Network isolation of the host disconnects C2 channels and stops network spread.
Containment must occur prior to performing eradication (removing malware/re-imaging) or recovery (restoring operations).

Anahtar Kavram

Incident Response Lifecycle Phase Order (Containment First)
Bu soruyu puanla