Soru

Zorluk: KolayIncident Response Process and Playbooks

A security analyst in a Security Operations Center (SOC) receives a high-confidence alert that a finance department workstation is infected with worm-like malware actively attempting to spread to adjacent hosts on the local subnet. According to standard incident response playbooks, which of the following actions should the analyst perform first?

  1. Disconnect the infected workstation from the network to isolate it from surrounding systems.Cevap
  2. B
    Format the primary hard drive and reinstall the workstation operating system from a clean image.
  3. C
    Schedule a lessons-learned meeting with stakeholders to update the emergency response plan.
  4. D
    Deploy a web application firewall rule to block Cross-Site Scripting payloads on the public gateway.

Cevap

Disconnect the infected workstation from the network to isolate it from surrounding systems.
Disconnecting the infected workstation from the network is a primary containment action. In standard incident response frameworks (such as NIST SP 800-61), once an active threat is identified, containment must occur immediately to prevent the incident from expanding and causing further damage across the enterprise network.

Adım Adım Çözüm

1
Identify the current phase of the incident response process based on the scenario indicators.
An active malware infection spreading across the local subnet indicates an ongoing, uncontained threat.
Determining the active IR phase guides the priority of subsequent actions.
2
Apply the standard Incident Response framework lifecycle order (Preparation -> Identification -> Containment -> Eradication -> Recovery -> Lessons Learned).
The immediate objective after identification is Containment.
Containment limits the scope of damage and stops potential lateral movement.
3
Select the action corresponding to the Containment phase.
Disconnecting the machine isolates the threat from spreading further.
Network isolation prevents the worm from compromising additional hosts on the subnet.

Anahtar Kavram

Incident Response Lifecycle - Containment Phase Priority
Bu soruyu puanla