Soru

Zorluk: KolayEndpoint Detection and Response (EDR)

Place the following steps of an Endpoint Detection and Response (EDR) automated containment and incident investigation workflow in the correct sequential order from initial event detection to host restoration.

  1. 1The EDR agent continuously collects host telemetry and flags suspicious process creation with anomalous network connections.
  2. 2An automated security playbook triggers network isolation on the compromised endpoint to prevent potential lateral movement.
  3. 3A security analyst inspects the process lineage tree, file hashes, and behavioral telemetry in the EDR console.
  4. 4The security analyst executes remediation actions to kill malicious artifacts and restores host network connectivity.

Cevap

The correct order follows the standard incident containment lifecycle: telemetry detection of suspicious activity, automated network isolation, analyst investigation of process lineage telemetry, and final threat remediation followed by network restoration.
The workflow begins with continuous behavioral detection by the EDR agent. Once an alert triggers, automated playbooks isolate the endpoint from the network to block lateral spread while keeping memory intact. Next, a SOC analyst reviews the rich process lineage and telemetry gathered by the sensor to determine root cause. Finally, remediation scripts eradicate the threat and host network connectivity is safely restored.

Adım Adım Çözüm

1
Identify initial threat detection
The local EDR sensor flags anomalous behavior via host telemetry monitoring.
Detection must occur before any containment or investigation actions can be initiated.
2
Execute immediate automated containment
Network isolation is automatically applied to the affected endpoint.
Isolating the endpoint stops lateral movement across the enterprise network while preserving host volatility.
3
Conduct analyst telemetry investigation
The analyst examines process trees and parent-child execution paths in the central EDR console.
Investigation must take place on the isolated endpoint's collected data to understand the attack scope.
4
Perform threat remediation and host restoration
Malicious items are cleaned and full network connectivity is reinstated.
Remediation and reconnecting the system to normal operations is the final step in resolving an endpoint incident.

Anahtar Kavram

EDR Incident Containment and Response Lifecycle
Tahmini Süre:1m 0s
Bu soruyu puanla