Soru

Zorluk: Çok zorEndpoint Detection and Response (EDR)

During an ongoing threat hunting investigation within a Linux database cluster, an automated Endpoint Detection and Response (EDR) agent alerts on suspicious ptrace system calls initiating in-memory execution of anonymous memory segments from an unprivileged web server process. To immediately mitigate lateral movement and preserve essential volatile evidence for detailed analysis, which TWO of the following actions should the SOC analyst initiate directly through the EDR management platform? (Select TWO.)

  1. Enable software-based host network isolation while preserving persistent administrative agent command-and-control channels.Cevap
  2. Trigger remote volatile memory acquisition and endpoint telemetry log collection before terminating suspect process lineages.Cevap
  3. C
    Reconfigure edge network firewall access control lists (ACLs) to drop inbound traffic destined for internal database subnets.
  4. D
    Deploy a SOAR playbook that executes an immediate hard system reboot across all cluster nodes upon alert trigger.

Cevap

The SOC analyst should enable software-based host network isolation while maintaining EDR agent management connectivity, and trigger remote volatile memory acquisition alongside telemetry log collection before terminating processes.
Enabling host network isolation directly through the EDR agent isolates network adapters to halt lateral movement while preserving the out-of-band management link. Simultaneously acquiring volatile RAM evidence before killing suspect processes ensures forensic artifacts associated with fileless memory injection are retained intact.

Adım Adım Çözüm

1
Isolate the compromised host at the endpoint software layer using EDR network containment.
Network traffic to and from the host is restricted to prevent lateral propagation while keeping management channels alive.
Prevents attacker movement while allowing security analysts to conduct remote investigation.
2
Perform remote volatile memory (RAM) and endpoint process telemetry acquisition.
In-memory fileless payloads and execution artifacts are captured prior to process disruption.
Preserves transient evidence following proper digital forensic order of volatility.

Anahtar Kavram

Endpoint Detection and Response (EDR) Host Containment and Volatile Evidence Preservation
Bu soruyu puanla