Soru

Zorluk: OrtaIncident Response Process and Playbooks

During a late-night monitoring shift, a security analyst identifies an active outbound socket connection transferring encrypted data from a CI/CD build node to an unrecognized external IP address. Initial investigation confirms that an unauthorized process is exfiltrating proprietary code repositories. According to standard incident response lifecycle frameworks, which of the following actions should the analyst perform FIRST?

  1. Isolate the CI/CD build node from the network to halt active exfiltration while preserving volatile system memory.Cevap
  2. B
    Terminate the unauthorized exfiltration process and delete the associated persistence mechanisms from the host.
  3. C
    Reimage the build node using a verified gold master deployment image to restore development pipeline services.
  4. D
    Configure perimeter routers to operate as detective controls by auditing all subsequent developer outbound traffic.

Cevap

Isolate the CI/CD build node from the network to halt active exfiltration while preserving volatile system memory.
Isolating the compromised host from the network represents the containment phase of incident response. Once an active threat and exfiltration attempt are identified, containment must occur immediately to prevent further data loss and limit damage while keeping system memory intact for volatile forensic data collection.

Adım Adım Çözüm

1
Analyze the incident state and identify the current lifecycle phase.
The incident is actively occurring with ongoing exfiltration confirmed during detection and analysis.
Determining the active phase dictates the next mandatory phase in standard incident response frameworks.
2
Select the immediate next phase according to NIST/ISO incident response standards.
The immediate next phase after confirming an active breach is Containment.
Containment limits the scope of damage and prevents further data exfiltration.
3
Identify the proper containment action among the available options.
Isolating the host from the network stops active data transfer while keeping RAM evidence intact.
Disconnecting or segmenting the device achieves containment without executing premature eradication or recovery steps.

Anahtar Kavram

Incident Response Lifecycle Phase Order (Containment)
Tahmini Süre:1m 30s
Bu soruyu puanla