During a routine operational review of corporate laptops, endpoint telemetry detects a malicious script executing directly in volatile memory and initiating unauthorized outbound traffic to a known adversary infrastructure. To stop lateral movement and data exfiltration immediately while retaining live memory context for incident investigation, which of the following EDR capabilities should be executed?
- Initiating agent-based network host isolationCevap
- BModifying internal perimeter firewall access control lists (ACLs)
- CDeploying an emergency static signature update to legacy antivirus software
- DApplying an operating system patch to mitigate the underlying execution vulnerability
Cevap
Initiating agent-based network host isolation is the correct capability because it disconnects the host from the internal network while keeping EDR communication open and preserving volatile memory.
Initiating agent-based network isolation enables security analysts to halt all unauthorized network communications to and from the endpoint instantly while preserving system state and volatile memory for forensic response.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) Host Isolation