Soru

Zorluk: ZorIncident Response Process and Playbooks

A Security Operations Center (SOC) analyst receives a high-severity alert indicating that an industrial control system (ICS) building automation gateway has initiated unauthorized outbound encrypted connections to a known malicious external IP address. The analyst confirms that unauthorized administrative access occurred and malicious code is actively running on the gateway. According to the NIST Incident Response Framework, which action should the responder perform FIRST?

  1. Apply an isolated quarantine VLAN profile to the connected switch port to halt external communications.Cevap
  2. B
    Flash the gateway with vendor-certified firmware and restore system settings from a verified backup.
  3. C
    Conduct a post-incident lessons learned session to update the facility access control incident playbook.
  4. D
    Power off the physical gateway immediately to ensure evidence is locked in permanent storage.

Cevap

Apply an isolated quarantine VLAN profile to the connected switch port to halt external communications.
According to the NIST Incident Response Framework (SP 800-61), once an incident is detected and confirmed, responders must immediately move to the Containment phase. Placing the switch port into an isolated quarantine VLAN stops command-and-control (C2) communication and lateral movement while keeping the system powered on so volatile memory can be preserved for forensics.

Adım Adım Çözüm

1
Identify the current incident phase based on the scenario
Detection and analysis are complete; an active compromise with C2 outbound traffic is confirmed.
Once an incident is confirmed active, the immediate next phase in NIST SP 800-61 is Containment.
2
Select the proper containment strategy for an active network attack
Apply network-level isolation (quarantine VLAN) to block C2 traffic.
Network containment prevents lateral movement and external data exfiltration while preserving powered-on system state for volatile memory capture.

Anahtar Kavram

NIST Incident Response Lifecycle (Containment Phase)
Bu soruyu puanla