During an on-site physical security review of a remote branch office, a security analyst discovers an unauthorized rogue wireless access point plugged into an active wall jack. The rogue device is actively broadcasting a duplicate corporate SSID to intercept wireless client credentials. Following standard incident response playbooks, which of the following immediate containment actions should the incident response team perform? (Select TWO.)
- Disable the specific network switch port where the rogue access point is physically attached.Cevap
- Apply a quarantine access control list (ACL) to isolate traffic from the affected network segment.Cevap
- Re-image the enterprise core switch operating system to remove potential malicious persistence.Cevap
- Clear the switch MAC address table and volatile system logs to reset network state.Cevap
Cevap
The correct containment actions are disabling the connected switch port and applying a quarantine ACL to isolate traffic from the affected segment.
Disabling the physical switch port immediately blocks the rogue access point from transmitting data across the wired enterprise network. Concurrently, applying a quarantine access control list (ACL) isolates traffic on the affected segment, preventing unauthorized lateral movement. Both steps fulfill containment objectives by isolating the threat without destroying evidence.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Phase for Physical Security Incidents
Tahmini Süre:1m 30s