Place the following steps of an Endpoint Detection and Response (EDR) automated containment and incident investigation workflow in the correct sequential order from initial event detection to host restoration.
- 1The EDR agent continuously collects host telemetry and flags suspicious process creation with anomalous network connections.
- 2An automated security playbook triggers network isolation on the compromised endpoint to prevent potential lateral movement.
- 3A security analyst inspects the process lineage tree, file hashes, and behavioral telemetry in the EDR console.
- 4The security analyst executes remediation actions to kill malicious artifacts and restores host network connectivity.
Cevap
The correct order follows the standard incident containment lifecycle: telemetry detection of suspicious activity, automated network isolation, analyst investigation of process lineage telemetry, and final threat remediation followed by network restoration.
The workflow begins with continuous behavioral detection by the EDR agent. Once an alert triggers, automated playbooks isolate the endpoint from the network to block lateral spread while keeping memory intact. Next, a SOC analyst reviews the rich process lineage and telemetry gathered by the sensor to determine root cause. Finally, remediation scripts eradicate the threat and host network connectivity is safely restored.
Adım Adım Çözüm
Anahtar Kavram
EDR Incident Containment and Response Lifecycle
Tahmini Süre:1m 0s