A system administrator notifies the incident response team after discovering that a critical internal database server containing confidential customer records is actively opening outbound connections to an unknown remote IP address. Endpoint monitoring confirms an unauthorized background process executing with administrative privileges and sending encrypted data packages outside the enterprise network boundary. According to standard incident response frameworks, which of the following actions should the team take FIRST?
- Isolate the affected database server from the network segment to halt active data exfiltration.Cevap
- BRe-image the database server operating system and restore data from the latest clean offline backup.
- CDeploy a detective intrusion detection rule to observe and log future unauthorized database connections.
- DExecute a full antivirus scan to neutralize self-replicating network worm components across adjacent hosts.
Cevap
Isolate the affected database server from the network segment to halt active data exfiltration.
According to the NIST SP 800-61 Incident Response framework, once an incident involves active data exfiltration or command-and-control activity, the immediate next phase is Containment. Isolating the server from the network stops active data exfiltration while preserving system state and volatile RAM for digital forensic analysis.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Phase
Tahmini Süre:1m 30s