Soru

Zorluk: OrtaIncident Response Process and Playbooks

An enterprise Security Operations Center (SOC) detects anomalous, high-volume outbound UDP port 53 traffic originating from an automated internal build server. Log inspection reveals structured base64-encoded strings appended to DNS queries sent to an external, unclassified domain, indicating active DNS tunneling and data exfiltration. Which TWO of the following actions should the incident response team perform FIRST to contain the threat while preserving evidence? (Select TWO.)

  1. Apply network-level isolation controls or move the build server interface to a quarantine VLAN.Cevap
  2. B
    Immediately power down or reboot the build server to stop running malicious exfiltration scripts.
  3. Capture a volatile memory image of the host before executing destructive remediation tasks.Cevap
  4. D
    Re-image the server operating system using a gold baseline image to restore clean functionality.

Cevap

The incident response team should apply network-level isolation controls (or move the interface to a quarantine VLAN) and capture a volatile memory image (RAM) of the host before performing destructive remediation.
In accordance with standard incident response frameworks (NIST SP 800-61 / ISO 27035), containment must isolate the compromised asset from the network while preserving volatile digital evidence. Isolating the build server via firewall/VLAN adjustments blocks C2 and exfiltration channels immediately. Capturing physical RAM satisfies the order of volatility, ensuring volatile evidence is captured prior to system changes.

Adım Adım Çözüm

1
Isolate the host at the network layer.
Stops ongoing data exfiltration via DNS tunneling while preserving system execution state.
Containment limits the blast radius without modifying system artifacts or losing volatile memory.
2
Preserve volatile evidence according to the order of volatility.
Captures running processes, memory-resident tools, and active network connections stored in RAM.
Volatile memory is lost if the machine is powered off, rebooted, or modified during eradication.

Anahtar Kavram

Incident Response Containment and Forensic Order of Volatility
Tahmini Süre:1m 30s
Bu soruyu puanla