Soru

Zorluk: OrtaIncident Response Process and Playbooks

A Security Operations Center (SOC) analyst detects an active, verified security incident where an adversary is utilizing a compromised internal jump server to maintain an unauthorized encrypted SSH tunnel to an external command-and-control IP address. The analyst has confirmed that sensitive data is actively being transferred across this channel. According to standard incident response lifecycle frameworks, which of the following actions should the analyst take FIRST?

  1. Disconnect or isolate the compromised jump server from the network segment to halt active data exfiltration.Cevap
  2. B
    Re-image the operating system of the jump server and restore system configurations from clean backup images.
  3. C
    Conduct a post-incident lessons learned review with executive stakeholders to update remote access policy standards.
  4. D
    Reconfigure SIEM alert threshold rules to generate detective notifications upon future SSH tunneling attempts.

Cevap

Disconnect or isolate the compromised jump server from the network segment to halt active data exfiltration.
Isolating the compromised host from the network represents the containment phase of the NIST incident response framework. When an active data exfiltration channel is identified, the immediate objective is to stop further loss of sensitive information and prevent lateral movement before proceeding to eradication and remediation steps.

Adım Adım Çözüm

1
Identify the current phase of the Incident Response (IR) lifecycle.
The incident has been detected and validated, and an ongoing breach with active data exfiltration is occurring.
Once an incident is confirmed, the immediate priority shifts from Analysis to Containment to limit scope and damage.
2
Select the appropriate action matching the Containment phase.
Network isolation of the jump server stops the active SSH tunnel and outbound exfiltration.
Containment actions must take precedence over Eradication (re-imaging) and Recovery steps.

Anahtar Kavram

Incident Response Lifecycle Phase Order (NIST SP 800-61 Rev. 2)
Tahmini Süre:1m 30s
Bu soruyu puanla