Soru

Zorluk: OrtaIncident Response Process and Playbooks

During routine operational monitoring of a Linux web application server hosting a customer portal, a security analyst identifies an unauthorized web shell script placed in the web root. Log entries confirm an external attacker is currently executing remote commands through the web shell to perform local privilege escalation. According to standard incident response procedures, which of the following actions should the security analyst take FIRST?

  1. Isolate the web application server from the network to prevent further unauthorized command execution and lateral movement.Cevap
  2. B
    Remove the unauthorized web shell script from the web directory and patch the file upload vulnerability.
  3. C
    Restore the server operating system and application files from the most recent verified backup.
  4. D
    Install an inline Web Application Firewall (WAF) to inspect incoming traffic for Cross-Site Scripting (XSS) attacks.

Cevap

Isolate the web application server from the network to prevent further unauthorized command execution and lateral movement.
In standard incident response frameworks (such as NIST SP 800-61), once an active incident is detected and analyzed, the immediate next step is Containment. Isolating the server from the network stops the attacker from continuing active remote command execution and prevents lateral movement into adjacent subnets.

Adım Adım Çözüm

1
Analyze the scenario state within the Incident Response lifecycle framework.
The incident has been detected and analyzed; an active web shell is executing commands in real time.
Determining the current phase of the incident establishes the required sequence of technical actions.
2
Identify the immediate operational priority for an active compromise.
Containment must be executed immediately to restrict attacker access, stop ongoing command execution, and prevent lateral movement.
According to NIST SP 800-61 guidelines, containment limits incident damage before moving to root-cause removal.
3
Select the action that aligns with the containment phase.
Isolating the server from the network halts active attacker sessions while preserving system state for analysis and subsequent remediation.
Network isolation prevents external command and control traffic while keeping volatile evidence intact.

Anahtar Kavram

Incident Response Lifecycle Phase Ordering (Containment prior to Eradication and Recovery)
Tahmini Süre:1m 30s
Bu soruyu puanla