During routine network monitoring, a security operations center (SOC) analyst confirms the presence of an unauthorized rogue wireless access point connected directly to a wall port in the enterprise building. Following standard incident response procedures, which of the following actions should the analyst perform first?
- Disable the switch port associated with the rogue wireless access point.Cevap
- BReimage all client workstations located within the immediate physical floor section.
- CConduct a post-incident lessons learned session to revise physical security controls.
- DConfigure an external perimeter firewall rule to block inbound remote management traffic.
Cevap
Disable the switch port associated with the rogue wireless access point.
Disabling the switch port isolates the rogue device from the network immediately, satisfying the requirement to contain the incident before executing recovery or post-incident activities.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Containment Phase