Soru

Zorluk: OrtaIncident Response Process and Playbooks

A security analyst monitoring identity provider logs identifies anomalous administrative API activity originating from an untrusted external IP address. Investigation reveals that a high-privilege user's OAuth refresh token was stolen via a session hijacking attack. The unauthorized actor is actively using this token to query and exfiltrate sensitive cloud database backups. Which of the following actions should the incident response team take FIRST to contain the breach?

  1. Revoke the compromised OAuth token and invalidate all active sessions associated with the user account across the identity provider.Cevap
  2. B
    Re-image the user's primary endpoint computer and re-install all baseline enterprise applications.
  3. C
    Draft an updated access control policy mandating FIDO2 hardware tokens for all future user authentication.
  4. D
    Schedule a post-incident lessons-learned meeting with executive management to review response metrics.

Cevap

Revoke the compromised OAuth token and invalidate all active sessions associated with the user account across the identity provider.
The correct response prioritizes immediate containment during an active incident. Revoking the compromised OAuth token and terminating active identity sessions immediately severs the attacker's access to the cloud environment, preventing further data exfiltration as prescribed in the containment phase of standard incident response frameworks.

Adım Adım Çözüm

1
Analyze the active threat vector described in the scenario
Identified that an attacker is actively using a stolen OAuth token to exfiltrate cloud database backups.
Understanding the current phase of the breach determines which lifecycle stage must be prioritized.
2
Determine the required phase of the Incident Response lifecycle
The immediate priority is Containment to prevent further unauthorized exfiltration.
Per NIST SP 800-61 frameworks, active threats must be contained before attempting eradication or post-incident activities.
3
Select the action that immediately stops the active threat mechanism
Revoking the OAuth token and invalidating active sessions stops the unauthorized API access instantly.
Token revocation cuts off the attacker's active access window without waiting for longer host-remediation workflows.

Anahtar Kavram

Incident Response Containment Phase Actions
Tahmini Süre:1m 30s
Bu soruyu puanla