An Endpoint Detection and Response (EDR) agent on a critical enterprise macOS host generates a high-priority alert indicating that an unprivileged process is attempting direct system calls to read sensitive memory structures, bypassing user-mode security hooks. Which of the following actions performed via the EDR administration console is the most appropriate immediate step to contain the incident while preserving volatile forensic evidence?
- Initiate network-level host isolation of the endpoint through the EDR console.Cevap
- BSend a remote hard shutdown command to the host to terminate malicious process execution.
- CUpdate perimeter firewall rules to block inbound and outbound traffic for the host's IP address.
- DDeploy an updated signature definition database to the endpoint legacy antivirus software.
Cevap
Initiate network-level host isolation of the endpoint through the EDR console.
Initiating network-level host isolation via the EDR console immediately disconnects the endpoint from external network communications and internal lateral movement vectors. Crucially, host isolation allows the OS to remain powered on so security analysts can remotely collect volatile memory (RAM) and EDR telemetry for forensic investigation.
Adım Adım Çözüm
Anahtar Kavram
EDR Host Isolation and Telemetry Preservation
Tahmini Süre:2m 0s