Soru

Zorluk: OrtaEndpoint Detection and Response (EDR)

A Security Operations Center (SOC) analyst receives an EDR behavioral alert indicating an unauthorized persistence script running on an internal database host. In what order should the analyst execute the following actions to effectively contain, triage, and remediate the incident using EDR capabilities?

  1. 1Apply host network isolation via the EDR management console while preserving agent-to-cloud control communications.
  2. 2Terminate active malicious parent and child process trees associated with the persistence script execution.
  3. 3Collect volatile RAM and system artifacts remotely through the EDR forensic collector module.
  4. 4Analyze process tree lineage and historical EDR endpoint telemetry to determine root cause and initial entry point.
  5. 5Update global EDR policy with custom Indicators of Compromise (IOCs) and block rules enterprise-wide.

Cevap

The correct operational sequence begins with isolating the endpoint network traffic, stopping active malicious processes, collecting volatile forensic data, conducting root-cause process tree analysis, and deploying enterprise-wide IOC block rules.
The standard incident response containment sequence for EDR workflow mandates immediate host-level network isolation (to stop lateral spread), followed by process termination (to stop active execution), volatile evidence capture (for forensics), root-cause analysis via process lineage telemetry, and enterprise policy updating (to enforce long-term mitigation).

Adım Adım Çözüm

1
Isolate the compromised endpoint from the network via EDR.
Prevents lateral movement and C2 traffic while maintaining EDR management channels.
Containment is the primary objective upon identifying active endpoint compromised activity to limit blast radius.
2
Terminate malicious process lineage.
Stops ongoing execution of payload and persistence scripts.
Halting execution prevents further system alteration or memory dumping attempts.
3
Capture live memory and volatile forensic artifacts.
Gathers live memory dump and volatile state evidence.
Preserving volatile evidence prior to analysis ensures complete forensic coverage.
4
Perform root cause analysis using EDR telemetry.
Identifies initial execution vector and compromised user context.
Tracing process lineage reveals how the threat bypassed initial controls.
5
Distribute updated EDR policy rules and block lists enterprise-wide.
Enforces enterprise hardening against identified hashes and behavioral indicators.
Prevents identical attacks across other endpoints in the organization.

Anahtar Kavram

EDR Incident Containment and Investigation Lifecycle
Tahmini Süre:1m 30s
Bu soruyu puanla