A security handler confirms that a cloud administrator host is actively exporting database backups to an unapproved external storage endpoint using hijacked API credentials. Following standard incident response procedures, which of the following actions should the security handler take FIRST?
- Revoke the compromised API credentials and restrict the host's network connectivity.Cevap
- BReimage the host operating system and restore database files from verified offline backups.
- CDeploy a web application firewall rule designed to block cross-site scripting attack payloads.
- DInitiate network-wide antivirus scanning to remove self-replicating network worm components.
Cevap
Revoke the compromised API credentials and restrict the host's network connectivity.
In standard incident response frameworks (such as NIST SP 800-61), once an active breach or exfiltration event is detected, containment is the immediate priority. Revoking compromised API keys and isolating the affected system prevents further data loss without altering offline forensic evidence.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle - Containment Phase