Soru

Zorluk: OrtaIncident Response Process and Playbooks

During operational security monitoring, a SOC analyst receives an automated alert indicating that an administrative workstation has established unauthorized command-and-control (C2) communications following the execution of a malicious macro from a spear-phishing email. According to standard incident response playbooks for initial containment and evidence preservation, which of the following immediate steps should the analyst perform? (Select TWO.)

  1. Disconnect or isolate the affected workstation from the local network using host-level Endpoint Detection and Response (EDR) controls.Cevap
  2. Capture volatile system memory (RAM) and current network state artifacts prior to powering down or rebooting the endpoint.Cevap
  3. C
    Immediately wipe the local storage drive and re-image the host operating system to remove all malicious binaries.
  4. D
    Deploy a corrective firewall filter designed specifically to intercept Cross-Site Scripting (XSS) reflection payloads on internal domain controllers.

Cevap

The analyst should isolate the host network access using EDR controls and capture volatile memory (RAM) before taking hardware offline.
Isolating the endpoint via EDR controls effectively stops lateral movement and active C2 communication while preserving the live machine state. Collecting volatile memory (RAM) ensures sensitive volatile evidence is captured prior to system modification or shutdown.

Adım Adım Çözüm

1
Identify the primary objectives of the Containment phase in the Incident Response Lifecycle.
Containment limits the spread of the security breach while maintaining system state for evidence preservation.
Stopping lateral movement and C2 communications without destroying volatile evidence is required before eradication begins.
2
Evaluate containment actions against forensic preservation requirements (Order of Volatility).
Isolating the network interface stops C2 traffic; dumping RAM captures volatile artifacts before shutdown.
Powering off or re-imaging prematurely destroys transient memory evidence required to analyze the attack.

Anahtar Kavram

Incident Response Containment Phase and Forensic Order of Volatility
Bu soruyu puanla