A security analyst discovers that a workstation on the corporate network is actively communicating with a known malicious command-and-control server following a phishing incident. Which of the following actions should the analyst perform as part of the containment phase? (Select TWO).
- Disconnect the compromised workstation from both wired and wireless network interfaces.Cevap
- BRe-image the workstation operating system to eliminate malicious artifacts.
- Disable the user account associated with the compromised workstation.Cevap
- DConduct a post-incident review meeting with key operational stakeholders.
Cevap
Disconnecting the compromised workstation from all network interfaces and disabling the associated user account are the appropriate immediate containment steps.
During the containment phase, the primary goal is to isolate affected systems and accounts to prevent further spread or data exfiltration. Disconnecting the endpoint from wired/wireless networks halts external communication and lateral movement. Disabling the compromised user account prevents stolen credentials from being reused elsewhere across the domain.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Phase Actions