Soru

Zorluk: OrtaIncident Response Process and Playbooks

A security analyst receives a critical Endpoint Detection and Response (EDR) alert showing an unauthorized process attempting to dump LSASS memory on a key workstation in the finance department. The alert confirms that the malicious process is actively attempting to establish command-and-control (C2) communications. According to standard NIST SP 800-61 incident response guidelines, what is the immediate next action the analyst should take?

  1. Isolate the infected finance workstation from the network to prevent lateral movement and C2 traffic.Cevap
  2. B
    Re-image the workstation operating system and restore data files from a verified offline backup.
  3. C
    Conduct a post-incident review meeting with management to document lessons learned and update playbooks.
  4. D
    Deploy a perimeter firewall rule to block all outbound traffic across non-standard network ports.

Cevap

Isolate the infected finance workstation from the network to prevent lateral movement and C2 traffic.
In standard incident response frameworks (such as NIST SP 800-61), once an active threat or compromise is detected, the immediate priority is Containment. Network isolation of the compromised host prevents the adversary from pivoting laterally within the enterprise network, executing further commands, or exfiltrating harvested credentials while keeping volatile memory intact for analysis.

Adım Adım Çözüm

1
Identify the current lifecycle phase of the incident response process based on the EDR alert.
The incident is actively occurring in real time on a live host, placing the response in the Containment, Eradication, and Recovery phase.
Immediate containment is required first to limit damage and prevent active threat propagation.
2
Determine the proper initial response action for an active endpoint compromise.
Network isolation (host quarantine) stops C2 communication and lateral movement without destroying volatile RAM evidence.
Containment must precede eradication actions like wiping or re-imaging.

Anahtar Kavram

Incident Response Containment Phase Procedures
Bu soruyu puanla