A Security Operations Center (SOC) analyst receives an alert showing that a user workstation is executing a suspicious PowerShell script attempting lateral movement across the network. Which of the following capabilities provided by an Endpoint Detection and Response (EDR) solution should the analyst execute immediately to contain the threat while preserving management access?
- Isolate the host from the network using the EDR consoleCevap
- BModify the perimeter edge firewall rules to block external outbound traffic from the local subnet
- CInitiate a full disk signature-based scan using traditional antivirus software across all workstations
- DAllow the workstation to remain online while relying on internal network trust settings to restrict access
Cevap
Isolate the host from the network using the EDR console
The correct action is to isolate the host from the network using the EDR console. EDR host network isolation instantly restricts network communication to and from the infected endpoint, cutting off lateral propagation paths while maintaining administrative connection to the EDR agent for forensic collection and containment.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Containment and Host Isolation in EDR
Tahmini Süre:45s