Soru

Zorluk: ZorEndpoint Detection and Response (EDR)

A security analyst in a Security Operations Center (SOC) receives a high-severity telemetry alert on a database server containing highly sensitive customer data. Analysis of the process execution lineage reveals that an attacker successfully loaded a vulnerable signed kernel driver (BYOVD attack) to blind local auditing tools and disable host firewall rules, subsequently initiating outbound C2 connections over non-standard encrypted ports. Which of the following actions leveraging Endpoint Detection and Response (EDR) features should the analyst execute FIRST to contain the active breach while preserving forensic evidence?

  1. Apply host network isolation via the EDR management console while leaving the EDR agent communication channel intact.Cevap
  2. B
    Deploy a custom static antivirus signature update across the enterprise to automatically identify and delete the vulnerable kernel driver file.
  3. C
    Update perimeter firewall rules to block the external destination IP address identified in the outbound encrypted network connection.
  4. D
    Initiate an automated corrective script to re-enable local host firewall rules and restore local auditing services.

Cevap

The analyst should apply host network isolation via the EDR management console while preserving agent communication channels.
Applying host network isolation via the EDR console immediately blocks all incoming and outgoing network traffic at the host level while leaving the EDR control plane active. This isolates the threat, prevents lateral movement and exfiltration, and maintains volatile memory intact for incident investigation.

Adım Adım Çözüm

1
Identify the immediate operational objective
Contain active adversary activity and prevent lateral movement or C2 exfiltration without destroying volatile memory.
Active adversary activity must be contained immediately before eradication or detailed investigation takes place.
2
Evaluate EDR containment mechanisms
EDR network isolation drops all non-essential endpoint traffic while preserving low-level EDR agent communications to the cloud/management console.
This allows incident responders to execute remote forensic triage and live response scripts without allowing the attacker to communicate outward or move laterally.
3
Select the optimal response action
Enforce host isolation via the EDR console.
Host isolation meets both containment and evidence preservation requirements.

Anahtar Kavram

EDR Host Isolation and Telemetry Containment
Bu soruyu puanla