Soru

Zorluk: KolayEndpoint Detection and Response (EDR)

A Security Operations Center (SOC) analyst receives an alert showing that a user workstation is executing a suspicious PowerShell script attempting lateral movement across the network. Which of the following capabilities provided by an Endpoint Detection and Response (EDR) solution should the analyst execute immediately to contain the threat while preserving management access?

  1. Isolate the host from the network using the EDR consoleCevap
  2. B
    Modify the perimeter edge firewall rules to block external outbound traffic from the local subnet
  3. C
    Initiate a full disk signature-based scan using traditional antivirus software across all workstations
  4. D
    Allow the workstation to remain online while relying on internal network trust settings to restrict access

Cevap

Isolate the host from the network using the EDR console
The correct action is to isolate the host from the network using the EDR console. EDR host network isolation instantly restricts network communication to and from the infected endpoint, cutting off lateral propagation paths while maintaining administrative connection to the EDR agent for forensic collection and containment.

Adım Adım Çözüm

1
Identify the primary operational requirement in an active containment scenario
The goal is to immediately halt lateral movement across the internal network.
Preventing the compromise of additional host systems is the top priority during incident response.
2
Evaluate EDR endpoint control features against traditional perimeter or antivirus controls
EDR host isolation disconnects host-to-host and host-to-internet network traffic while keeping agent telemetry operational.
Isolation stops internal attack propagation without shutting down the endpoint or severing management connectivity.

Anahtar Kavram

Endpoint Containment and Host Isolation in EDR
Tahmini Süre:45s
Bu soruyu puanla