Soru

Zorluk: ZorEndpoint Detection and Response (EDR)

A Security Operations Center (SOC) team is responding to a fileless attack on an enterprise server, where an adversary is executing malicious commands directly in RAM by abusing legitimate process handles spawned by a web daemon. The SOC analyst must leverage Endpoint Detection and Response (EDR) platform capabilities to detect ongoing malicious behavior and execute host containment without destroying volatile RAM evidence. Which of the following actions should the analyst implement using the EDR solution? (Select TWO.)

  1. Enable process lineage tracking and behavioral monitoring to analyze parent-child process relationships and API execution patterns in real time.Cevap
  2. Execute software-based host isolation through the EDR agent to quarantine the server from network communication while keeping system power on.Cevap
  3. C
    Update edge perimeter firewall Access Control Lists to block incoming IP traffic destined for the web daemon service.
  4. D
    Initiate an automated system reboot and immediately restore the operating system from a pristine golden disk image.

Cevap

The analyst should enable process lineage tracking and behavioral monitoring to identify anomalous in-memory process execution, and perform host-level isolation via the EDR agent to cut network communications while preserving volatile RAM.
Process lineage tracking provides real-time visibility into process tree creation and API activity, allowing SOC analysts to identify unauthorized command shells spawned in RAM by web services. Host isolation issued via EDR disconnects network interface communications while keeping the machine powered, effectively halting lateral movement and C2 traffic while preserving volatile RAM for incident response forensics.

Adım Adım Çözüm

1
Identify the EDR detection mechanism suitable for fileless memory execution.
Process lineage and API telemetry capture parent-child execution paths, revealing malicious sub-processes launched by web daemons.
Fileless memory attacks bypass traditional static file signatures, necessitating behavioral process tracing.
2
Select the host containment method that preserves volatile system state.
Host-level software network isolation quarantines network interfaces at the OS driver level while leaving power intact.
Host isolation blocks lateral movement and C2 traffic without clearing volatile RAM evidence needed for forensic investigation.
3
Evaluate invalid distractor controls against incident response principles.
Perimeter network rules fail to contain internal host actions, and rebooting wipes RAM prior to evidence collection.
Incident response workflows require host isolation before eradication and recovery activities.

Anahtar Kavram

EDR Behavioral Telemetry & Host-Level Network Isolation
Bu soruyu puanla