Soru

Zorluk: OrtaIncident Response Process and Playbooks

A Security Operations Center (SOC) analyst detects suspicious internal SMB traffic and administrative share creation originating from an HR workstation after business hours. Further inspection reveals that the host is actively communicating with an external command-and-control (C2) server. According to standard incident response frameworks, which of the following actions should the incident response team perform during the Containment phase? (Select TWO.)

  1. Disconnect the host from the network by disabling its network interface or isolating its switch port.Cevap
  2. B
    Re-image the host operating system immediately and restore data from the latest clean backup.
  3. Apply temporary network access control rules to block outbound traffic from the workstation to the suspected C2 IP address.Cevap
  4. D
    Reconfigure perimeter firewall rules to block all inbound HTTP and HTTPS connections across the enterprise.

Cevap

The incident response team should disconnect the host from the network by disabling its network interface or isolating its switch port, and apply temporary network access control rules to block outbound traffic from the workstation to the suspected C2 IP address.
During the Containment phase of incident response, the primary goal is to isolate affected systems and prevent lateral movement or data exfiltration while preserving system state for volatile memory capture. Disabling the workstation network connection and blocking outbound connections to the external C2 address accomplish effective, targeted containment.

Adım Adım Çözüm

1
Identify the target phase of the incident response lifecycle required by the scenario.
The question specifically requests immediate next steps for the Containment phase.
Containment focuses on limiting the scope, impact, and blast radius of an active security incident while preventing ongoing threat actor activity.
2
Evaluate technical actions that restrict attacker C2 activity and internal lateral movement without destroying evidence.
Isolating the workstation switch port/interface and blocking the specific C2 IP address at the firewall achieve containment.
These steps isolate the compromised system and cut off external communication while leaving volatile RAM intact for forensic analysis.
3
Eliminate options representing out-of-order IR phase actions or improper control scoping.
Re-imaging belongs in Eradication/Recovery, while blocking all enterprise HTTP/HTTPS traffic is an inappropriate control scope.
Wiping systems prematurely destroys forensic evidence, and global web blocks cause unnecessary business disruption.

Anahtar Kavram

Incident Response Containment Strategies
Bu soruyu puanla