During security monitoring, an analyst detects unauthorized data exfiltration via DNS tunneling originating from an internal web application server. The incident response team validates the threat and confirms the incident response playbook needs to be executed immediately. According to standard incident response lifecycle frameworks, which of the following actions should the responder take FIRST during the containment phase?
- Isolate the affected web server from the network while keeping it powered on.Cevap
- BRemove the malicious persistence scripts and restore system files from clean backups.
- CReconfigure the edge firewall to block all inbound and outbound UDP port 53 traffic enterprise-wide.
- DConvene a post-incident review meeting with stakeholders to update the incident playbook.
Cevap
Isolate the affected web server from the network while keeping it powered on.
Isolating the affected host from the network immediately halts active data exfiltration via DNS tunneling while preserving volatile memory (RAM) needed for digital forensics. Following standard IR frameworks (such as NIST SP 800-61), containment must occur before eradication or recovery steps begin.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Containment Strategy