During an active incident investigation, a security analyst confirms that an employee's workstation is currently communicating with an external command-and-control (C2) server following a malware infection. According to standard incident response lifecycle guidelines, which of the following actions should the analyst take FIRST?
- Isolate the compromised workstation from the internal network.Cevap
- BRe-image the workstation operating system and restore clean data backups.
- CUpdate the enterprise acceptable use policy to forbid clicking unknown email links.
- DExecute a full network scan to clean self-replicating worm code from all file servers.
Cevap
Isolate the compromised workstation from the internal network.
Isolating the compromised system from the network is the primary immediate containment action. Containment prevents data exfiltration and restricts the threat actor from moving laterally across the network while incident responders prepare eradication and forensic analysis steps.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Phase Order (Containment First)