A technician identifies an active malware infection on an enterprise desktop. To stop lateral movement without losing volatile memory evidence, the technician uses the Endpoint Detection and Response (EDR) console. Which of the following capabilities should the technician execute?
- Perform host network isolation via the EDR agentCevap
- BApply a perimeter firewall block rule for the infected host IP address
- CRemotely power off the machine to stop malicious process execution
- DEnable a detective packet logging filter on the local network switch
Cevap
Perform host network isolation via the EDR agent
Performing host network isolation directly through the EDR agent prevents the endpoint from communicating with any local or remote network resources, halting lateral malware propagation while maintaining machine power so security responders can harvest volatile RAM memory.
Adım Adım Çözüm
Anahtar Kavram
EDR Host Isolation and Volatile Evidence Preservation