Soru

Zorluk: OrtaIncident Response Process and Playbooks

During an ongoing security investigation into an automated build system, a security analyst discovers that an attacker compromised a CI/CD service account's API token and created unauthorized secondary deployment keys to maintain persistent access. The incident response team is currently executing the Containment phase of the NIST incident response lifecycle. Which of the following technical actions should the team perform immediately as part of containment? (Select TWO.)

  1. Revoke the compromised API token and immediately invalidate all secondary deployment keys created by the attacker.Cevap
  2. B
    Re-image the CI/CD build server operating system and restore all code repositories from a verified clean offline backup.
  3. Apply temporary network access control rules to restrict API gateway endpoints strictly to trusted internal management subnets.Cevap
  4. D
    Reclassify the organization's credential rotation policy from a detective security control to a deterrent security control.

Cevap

The correct containment actions are revoking the compromised API token along with any secondary keys generated by the attacker, and applying temporary network access control rules to restrict API gateway endpoints strictly to trusted internal subnets.
During the Containment phase of an incident response process, the priority is to isolate affected systems and revoke compromised access vectors to prevent further damage. Revoking the compromised API token and secondary keys directly terminates the attacker's administrative access. Restricting API gateway ingress via network access control rules prevents unauthorized external connections. Both actions isolate the impact while preserving system state for ongoing forensic analysis.

Adım Adım Çözüm

1
Identify the active incident response phase and objective.
The scenario specifies the team is in the Containment phase of the NIST Incident Response Framework, focusing on limiting incident damage and scope.
Containment measures prevent further unauthorized access while allowing forensic analysis to continue safely.
2
Evaluate identity and credential containment options.
Disabling compromised API credentials and removing secondary persistence keys immediately revokes the attacker's authorization to access API resources.
Credential revocation stops ongoing malicious API operations without wiping forensic state.
3
Evaluate network and infrastructure isolation containment options.
Applying restrictive network rules at the API gateway blocks external access vectors utilized by the threat actor.
Network isolation isolates access vectors to prevent additional remote unauthorized API calls.

Anahtar Kavram

Incident Response Lifecycle - Containment Phase Actions
Bu soruyu puanla