A security analyst confirms that an internal user workstation is infected with active malware that is attempting to communicate with an external command-and-control server. According to standard incident response lifecycle frameworks (such as NIST SP 800-61), which of the following actions should the analyst take immediately after confirming the incident?
- Isolate the compromised workstation from the local network segment.Cevap
- BRe-image the workstation hard drive to remove all malicious files.
- CRestore missing user data files from the most recent secure backup.
- DSchedule a lessons-learned meeting with key business stakeholders.
Cevap
Isolate the compromised workstation from the local network segment.
Isolating the affected system from the network is the essential initial containment step. It prevents lateral movement and external command-and-control communication while preserving system state for analysis.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Phase Order (NIST SP 800-61)