During an ongoing incident investigation, a security analyst suspects that a compromised workstation is executing fileless commands in memory and attempting to persist across reboots. Which of the following capabilities and telemetry sources provided by an Endpoint Detection and Response (EDR) solution should the analyst utilize to contain the threat and investigate the attack? (Select TWO)
- Initiating network isolation of the affected host while preserving agent-to-management console communicationCevap
- Capturing real-time process execution lineage and parent-child relationship logsCevap
- CUpdating edge firewall stateless packet filtering rules to block internal host memory access calls
- DRelying strictly on scheduled static file signature updates to identify in-memory code injection
Cevap
The correct response actions are isolating the affected host from the network while maintaining agent console connectivity, and collecting real-time process lineage telemetry to trace parent-child process execution.
Isolating the endpoint stops network-based propagation while maintaining EDR agent communication for analysis. Furthermore, process lineage logs provide behavioral visibility into parent-child process relationships, allowing analysts to detect fileless execution patterns.
Adım Adım Çözüm
Anahtar Kavram
Endpoint Detection and Response (EDR) Containment and Telemetry