A security analyst detects active data exfiltration originating from a compromised database server. Which of the following incident response steps should be taken first?
- Isolate the affected server from the network to stop the data transfer.Cevap
- BReformat the hard drives and reinstall the operating system.
- CRestore the database contents from a known clean backup baseline.
- DHold a lessons learned meeting to review security incident documentation.
Cevap
Isolate the affected server from the network to stop the data transfer.
Isolating the affected server immediately contains the active incident by terminating ongoing exfiltration channels and preventing lateral movement across the internal network.
Adım Adım Çözüm
Anahtar Kavram
Incident Response Lifecycle Order