During a late-night monitoring shift, a security analyst identifies an active outbound socket connection transferring encrypted data from a CI/CD build node to an unrecognized external IP address. Initial investigation confirms that an unauthorized process is exfiltrating proprietary code repositories. According to standard incident response lifecycle frameworks, which of the following actions should the analyst perform FIRST?
- Isolate the CI/CD build node from the network to halt active exfiltration while preserving volatile system memory.Cevap
- BTerminate the unauthorized exfiltration process and delete the associated persistence mechanisms from the host.
- CReimage the build node using a verified gold master deployment image to restore development pipeline services.
- DConfigure perimeter routers to operate as detective controls by auditing all subsequent developer outbound traffic.
Cevap
Isolate the CI/CD build node from the network to halt active exfiltration while preserving volatile system memory.
Isolating the compromised host from the network represents the containment phase of incident response. Once an active threat and exfiltration attempt are identified, containment must occur immediately to prevent further data loss and limit damage while keeping system memory intact for volatile forensic data collection.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Phase Order (Containment)
Tahmini Süre:1m 30s