A security analyst monitoring identity provider logs identifies anomalous administrative API activity originating from an untrusted external IP address. Investigation reveals that a high-privilege user's OAuth refresh token was stolen via a session hijacking attack. The unauthorized actor is actively using this token to query and exfiltrate sensitive cloud database backups. Which of the following actions should the incident response team take FIRST to contain the breach?
- Revoke the compromised OAuth token and invalidate all active sessions associated with the user account across the identity provider.Cevap
- BRe-image the user's primary endpoint computer and re-install all baseline enterprise applications.
- CDraft an updated access control policy mandating FIDO2 hardware tokens for all future user authentication.
- DSchedule a post-incident lessons-learned meeting with executive management to review response metrics.
Cevap
Revoke the compromised OAuth token and invalidate all active sessions associated with the user account across the identity provider.
The correct response prioritizes immediate containment during an active incident. Revoking the compromised OAuth token and terminating active identity sessions immediately severs the attacker's access to the cloud environment, preventing further data exfiltration as prescribed in the containment phase of standard incident response frameworks.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Containment Phase Actions
Tahmini Süre:1m 30s