Soru

Zorluk: KolayIncident Response Process and Playbooks

A security analyst monitoring enterprise systems confirms an active unauthorized access alert on an internal workstation. The compromised workstation is currently transmitting unauthorized network traffic to an external IP address. According to standard incident response lifecycle frameworks, which action should the analyst take immediately after confirming this detection?

  1. Isolate the compromised workstation from the network to prevent further lateral movement and data exfiltration.Cevap
  2. B
    Re-image the operating system and restore files from clean backups.
  3. C
    Convene a post-incident review meeting with management to document lessons learned.
  4. D
    Update the organization's incident response policy and firewall baseline configurations.

Cevap

Isolate the compromised workstation from the network to prevent further lateral movement and data exfiltration.
According to established incident response standards (such as NIST SP 800-61), the phase immediately following Detection & Analysis is Containment. Isolating the workstation from the network stops active malicious external communication, preventing further exfiltration and lateral movement while preserving evidence.

Adım Adım Çözüm

1
Identify current incident response phase
The incident has been identified and confirmed, placing the team at the end of Detection & Analysis.
Standard frameworks (NIST SP 800-61) mandate that after confirming an active threat during Detection & Analysis, containment must immediately follow.
2
Select immediate containment action
Network isolation of the impacted workstation restricts unauthorized outbound communication.
Containment limits the scope and impact of an active incident before proceeding to eradication or recovery.

Anahtar Kavram

Incident Response Lifecycle Phase Ordering (Containment)
Bu soruyu puanla