A Security Operations Center (SOC) analyst detects an active, verified security incident where an adversary is utilizing a compromised internal jump server to maintain an unauthorized encrypted SSH tunnel to an external command-and-control IP address. The analyst has confirmed that sensitive data is actively being transferred across this channel. According to standard incident response lifecycle frameworks, which of the following actions should the analyst take FIRST?
- Disconnect or isolate the compromised jump server from the network segment to halt active data exfiltration.Cevap
- BRe-image the operating system of the jump server and restore system configurations from clean backup images.
- CConduct a post-incident lessons learned review with executive stakeholders to update remote access policy standards.
- DReconfigure SIEM alert threshold rules to generate detective notifications upon future SSH tunneling attempts.
Cevap
Disconnect or isolate the compromised jump server from the network segment to halt active data exfiltration.
Isolating the compromised host from the network represents the containment phase of the NIST incident response framework. When an active data exfiltration channel is identified, the immediate objective is to stop further loss of sensitive information and prevent lateral movement before proceeding to eradication and remediation steps.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Phase Order (NIST SP 800-61 Rev. 2)
Tahmini Süre:1m 30s