Soru

Zorluk: OrtaIncident Response Process and Playbooks

An enterprise Security Operations Center (SOC) detects unauthorized execution of encryption software across several internal host systems. Place the following incident response playbook actions in the correct chronological order according to NIST SP 800-61 guidelines, starting from initial detection.

  1. 1Validate the initial alert by analyzing system logs and telemetry to confirm indicators of compromise and scope.
  2. 2Isolate the affected network subnet and disallow outgoing communication from impacted hosts to prevent lateral spread.
  3. 3Terminate malicious processes, delete unauthorized scheduled tasks, and purge malware artifacts from affected systems.
  4. 4Restore host operating systems and data from clean, uncompromised backups and reintroduce systems into production.
  5. 5Hold a post-incident review meeting with key stakeholders to document lessons learned and update response playbooks.

Cevap

The correct order of incident response lifecycle steps is: 1) Validate initial alert and scope, 2) Isolate affected network subnet, 3) Terminate processes and purge artifacts, 4) Restore hosts from clean backups, and 5) Hold a post-incident review meeting.
According to standard NIST SP 800-61 guidelines, incident response follows a strict linear sequence: Detection and Analysis (scoping the incident), Containment (isolating affected network segments), Eradication (purging malicious binaries and persistence hooks), Recovery (restoring systems from clean backups), and Post-Incident Activity (documenting lessons learned).

Adım Adım Çözüm

1
Analyze telemetry and validate the incident.
Confirm indicators of compromise and scope of affected host systems.
Accurate scope identification ensures containment measures target all affected systems without prematurely interrupting unaffected services.
2
Implement network containment controls.
Prevent active encryption threats from spreading laterally.
Stopping lateral movement and C2 communication limits potential operational damage.
3
Execute eradication actions.
Eliminate malware binaries, malicious persistence hooks, and unauthorized access.
Systems cannot be restored safely until threat actor access mechanisms and malware are completely removed.
4
Perform system recovery.
Rebuild or restore endpoints from verified, uncompromised backups.
Restoring validated clean states ensures business continuity without reintroducing hidden compromise.
5
Conduct post-incident review.
Document lessons learned and update Incident Response playbooks.
Analyzing response performance identifies procedural gaps and prevents recurrence of similar incidents.

Anahtar Kavram

NIST SP 800-61 Incident Response Lifecycle Phases
Bu soruyu puanla