Soru

Zorluk: OrtaIncident Response Process and Playbooks

A system administrator notifies the incident response team after discovering that a critical internal database server containing confidential customer records is actively opening outbound connections to an unknown remote IP address. Endpoint monitoring confirms an unauthorized background process executing with administrative privileges and sending encrypted data packages outside the enterprise network boundary. According to standard incident response frameworks, which of the following actions should the team take FIRST?

  1. Isolate the affected database server from the network segment to halt active data exfiltration.Cevap
  2. B
    Re-image the database server operating system and restore data from the latest clean offline backup.
  3. C
    Deploy a detective intrusion detection rule to observe and log future unauthorized database connections.
  4. D
    Execute a full antivirus scan to neutralize self-replicating network worm components across adjacent hosts.

Cevap

Isolate the affected database server from the network segment to halt active data exfiltration.
According to the NIST SP 800-61 Incident Response framework, once an incident involves active data exfiltration or command-and-control activity, the immediate next phase is Containment. Isolating the server from the network stops active data exfiltration while preserving system state and volatile RAM for digital forensic analysis.

Adım Adım Çözüm

1
Identify the current phase of the Incident Response lifecycle based on the scenario.
The incident is actively occurring with ongoing data exfiltration detected.
Determining the phase ensures appropriate incident response playbook procedures are followed.
2
Select the immediate response priority following Detection and Analysis.
Containment must be executed prior to eradication or recovery.
The primary objective during active exfiltration is to minimize damage and prevent further unauthorized data transfer.
3
Determine the containment action that halts network communication without destroying volatile forensic evidence.
Network isolation detaches the compromised host from the network while preserving RAM and system logs.
Disconnecting or isolating network access stops malicious C2/exfiltration traffic while keeping volatile evidence intact for investigators.

Anahtar Kavram

Incident Response Containment Phase
Tahmini Süre:1m 30s
Bu soruyu puanla