Soru

Zorluk: KolayIncident Response Process and Playbooks

A Security Operations Center (SOC) analyst receives a high-priority alert indicating that an employee workstation is actively encrypting local files and attempting outbound communication with a malicious command-and-control server. According to standard incident response procedures, which of the following steps should the analyst perform FIRST?

  1. Disconnect the workstation from the local network to isolate the threat.Cevap
  2. B
    Reimage the workstation using a standard enterprise baseline image.
  3. C
    Schedule a lessons-learned meeting with the incident response team.
  4. D
    Deploy an emergency patch across all enterprise endpoints to remediate the flaw.

Cevap

Disconnect the workstation from the local network to isolate the threat.
Isolating the workstation from the network is the critical first step during the containment phase of incident response. Disconnecting network access halts communication with command-and-control servers and prevents lateral movement to other enterprise endpoints.

Adım Adım Çözüm

1
Determine the current phase of the incident response lifecycle.
The scenario describes an active malware infection requiring immediate containment.
An ongoing incident must be contained immediately to limit scope and prevent further damage.
2
Select the appropriate action for host containment.
Isolating the system from the network halts command-and-control traffic and stops lateral propagation.
Network disconnection prevents the spread of ransomware/malware while leaving system state intact for initial analysis.

Anahtar Kavram

Incident Response Containment Phase
Bu soruyu puanla