Soru

Zorluk: OrtaIncident Response Process and Playbooks

During off-hours monitoring, a Security Operations Center (SOC) analyst receives an automated alert indicating that a newly created cloud IAM access key assigned to a staging service account is actively issuing bulk API requests to download objects from a production database backup S3 bucket to an unrecognized external IP address. After verifying that the API calls originate from unauthorized external sources and represent active data exfiltration, which of the following actions should the analyst take FIRST according to standard incident response playbooks?

  1. Revoke the compromised IAM access key and apply an temporary explicit deny policy to the service account.Cevap
  2. B
    Restore the affected cloud storage bucket from a known-good backup and rotate the master KMS encryption key.
  3. C
    Deploy a detective inline web application firewall sensor to analyze incoming cloud API call patterns.
  4. D
    Draft an incident post-mortem report detailing how the staging IAM account obtained production access.

Cevap

Revoke the compromised IAM access key and apply an temporary explicit deny policy to the service account.
When an active incident involving credential compromise and ongoing data exfiltration is confirmed, the immediate priority in standard incident response frameworks (such as NIST SP 800-61) is containment. Revoking the compromised access key immediately halts the unauthorized API sessions and stops ongoing exfiltration.

Adım Adım Çözüm

1
Identify the current phase of the NIST Incident Response Lifecycle.
The incident is actively occurring with ongoing exfiltration, placing the response squarely in the Containment, Eradication, and Recovery phase, specifically requiring immediate Containment.
Containment limits the scope and impact of an active breach before further damage occurs.
2
Select the action that directly mitigates active exfiltration without skipping containment.
Disabling or revoking the active vector (the compromised IAM credential) immediately halts unauthorized API requests.
Revoking the access key breaks the attacker's active session and stops ongoing data loss instantly.

Anahtar Kavram

Incident Response Containment Phase
Bu soruyu puanla