Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

A security analyst detects suspicious fileless activity on an enterprise endpoint, where a legitimate administrative process is spawned to run encoded PowerShell scripts that attempt lateral movement across the internal subnet. The analyst must halt all network communication to and from the compromised host to stop lateral movement, while maintaining active command-and-control connectivity between the endpoint agent and the EDR management console for live forensic investigation. Which of the following Endpoint Detection and Response (EDR) actions should the analyst take?

  1. Initiate host network isolation through the EDR console agentCevap
  2. B
    Apply updated egress filtering rules on the perimeter edge firewall
  3. C
    Run a traditional signature-based antivirus full system disk scan and quarantine the binary
  4. D
    Issue an out-of-band remote hard power-off command to shutdown the physical host

Cevap

Initiate host network isolation through the EDR console agent
The correct action is to initiate host network isolation via the EDR agent console. Host isolation blocks network adapter communication to restrict lateral movement across the enterprise while preserving the EDR agent's control link so SOC analysts can maintain remote command capabilities and capture volatile system memory.

Adım Adım Çözüm

1
Analyze the scenario requirements
Identified the double constraint: stop lateral network movement while preserving the SOC management tunnel and volatile RAM data for investigation.
Containment must prevent the threat actor from pivoting to other internal systems while allowing responders to analyze the system state.
2
Evaluate host-level containment capabilities offered by EDR solutions
EDR agents provide software-defined host isolation.
Host network isolation drops standard inbound/outbound IP packets while maintaining an explicit whitelist for EDR agent-to-cloud/console telemetry traffic.
3
Compare against alternate network and system controls
Disqualified perimeter firewalls, static antivirus scans, and host power-offs.
Perimeter firewalls ignore internal subnet traffic, static AV fails on memory-resident script execution, and powering off the machine wipes volatile forensic memory.

Anahtar Kavram

EDR Host Isolation and Telemetry Preservation
Bu soruyu puanla