A security analyst monitoring enterprise systems confirms an active unauthorized access alert on an internal workstation. The compromised workstation is currently transmitting unauthorized network traffic to an external IP address. According to standard incident response lifecycle frameworks, which action should the analyst take immediately after confirming this detection?
- Isolate the compromised workstation from the network to prevent further lateral movement and data exfiltration.Cevap
- BRe-image the operating system and restore files from clean backups.
- CConvene a post-incident review meeting with management to document lessons learned.
- DUpdate the organization's incident response policy and firewall baseline configurations.
Cevap
Isolate the compromised workstation from the network to prevent further lateral movement and data exfiltration.
According to established incident response standards (such as NIST SP 800-61), the phase immediately following Detection & Analysis is Containment. Isolating the workstation from the network stops active malicious external communication, preventing further exfiltration and lateral movement while preserving evidence.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Phase Ordering (Containment)